Google took three months to remove scam app that stole over $5M
theblock.co
theblock.co
I think google should be held accountable for not removing a malicious app from their app store within a reasonable amount of time, but I'm less sure that Google should be on the hook for the money scammers take. Google can and should do a lot more to prevent malicious apps on their platform, and they should be required to respond quickly when the ones they failed to detect are reported to them, but a play store that only allowed/contained apps that Google was 100% confident could never be used to scam another person wouldn't be very useful.
It’s like shopping at a grocery store thinking that recalled foods are de-shelved within hours of a notice but they actually kept selling them for weeks. Much different risk profile.
Number of reports vs installs on Android devices?
[1] https://www.justice.gov/opa/pr/google-forfeits-500-million-g...
Either they are abusing market position to prevent competition on the store (eg. linking to custom payment providers) or they are doing it to guarantee customer experience (Apple fanboys are really big on this line) - in which case they are liable and it's priced in.
There's no reason to believe, and much reason to believe that it's not the case, that this woman was the very first to complain about this app. Perhaps Google had already received thousands of complaints about the app before she ever downloaded it. That info will presumably come out as the lawsuit proceeds.
She used the app for 5-6 months, presumably with other people having been scammed repeatedly in the past and having reported the app. Then after she reported it to the CFPB (which is an independent government agency dedicated to preventing these types of scams and other abuses of customers), the CFPB spent 3 months of back and forth with Google before they were willing to take it down.
So the argument is that the app was up for several months with the US government directly reaching out to Google and pushing for them to take the app down for being a scam but they ignored that as long as they could and likely ignored plenty of other reports in the past.
At least personally I'd argue that's gross negligence.
Then separately, Google should pay penalties to the CFPB for failing to act in a timely manner.
Nobody should be trusting Google or Apple to be protecting them. Certainly not for a $1M+ USD deposit.
That the app stores are illegal monopolies shouldn't opine on someone suffering the consequences for their own poor decisions.
I agree with you, I wouldn't give someone 10 euros if not vetting, but if google puts "Verified by Play Protect" , restrict me to do anything, talk about their stores as a safe and vetted place, then it must be kept accountable
1. Dealing with Google's failure to remove in a timely manner
2. Dealing with the fraud
Comingling them creates a slippery slope ("I drove my car into a lake because Maps told me to...") that erodes normal expectations of personal responsibility.
What should she have done to vet?
Go to the website of the party she's transferring the money to and verify the app from their end?
That doesn't seem much to expect for a multi-million dollar personal risk.
"It was in the store" seem an unreasonably low bar for personal responsibility.
A financial guarantee seems the least I'd require for that, personally.
It was in the store seems a reasonably level bar for the app has been vetted to show it works for its intended purpose.
How is selling fake investment apps different to selling fake sneakers?
To pretend otherwise is insane. (Even by appealing to app store monopolies or fees, which are immaterial to due diligence responsibility here)
This wasn't a case of the lady giving $5M to Google for fake crypto.
It was more like Google selling her a phone, then her dialing one of the preset numbers on that phone and getting scammed.
Google and Apple operate monopolistic app stores with predatory fees.
This lady did something foolish.
Redressing the former by removing responsibility for the latter doesn't make sense.
I'm all for fining Google over this, but the money shouldn't go to the victim.
Are you sure?
Didn't that coffee lady originally request just hospital expenses, and then her lawyer told the jury to award punitive damages equal to one day's worth of coffee sales? (Or was it one day's coffee profits?)
Seems rather fitting that Google might pay one day's worth of app profits, if punitive damages are applied to their 3-month delay.
As far as customers are concerned, google verified that the app does what it says it does. If that were the case and she just lost money from bad crypto investments, that would be a complete non-story. However, that is not at all the case.
Someone struggling to put a deposit together for their own home isn't going to make bank out of flipping houses and contributing to the shit housing sector. It really is true that all it takes to make money is money, it's almost effortless.
Though I guess that kind of undermines my initial idea that you needed to have a brain for it.
Yobit is an long standing exchange, not one I would use
Yobit Pro was a scam app pretending to be related to that exchange
Crypto returns can be quite fast. If you have $4 million and its not really absurd to take that an order of magnitude higher, and be used to the volatility of it going lower.
There are plenty of “random crypto apps” that work fine for any amount of money
Don't let your own paranoia get in the way
“Not your keys, not your coin” remains true for “Yobit Pro”, FTX and established players like Coinbase
Plenty of random crypto apps are self custody apps that work fine
The people running Yobit Pro are probably using similar levels of OPSEC, and just have a lot more crypto now. This PvP aspect of crypto keeps it going.
¯\_(ツ)_/¯
That has nothing to do with crypto and everything to do with this fake exchange scam, and even with a real exchange it has to do with consumer education on using non custodial apps
It’s downright weird that you have this other mental category for things that say crypto where your mental processing power throttled to the conclusion is “its crypto so let me blame the victim instead and ignore who chose to create a victim while they sent her death threats on whatsapp”
Obviously it sucks for the lady, but to some extend it certainly deserves a financial darwin award.
That sector has plenty of things that follow the expected social contract of all parties, which can and does support balances of $4 million and far higher.
Your unwillingness to see that is not really a productive conversation here, although you’re in like company right now on this forum, you shouldn't be.
Turns out if you never actually earned the money you tend to think you are untouchable.
I've worked with CEOs who were born into money, and those who have earned it, you can tell the difference immediately.
You should never be surprised what Florida Man/Woman will do.
As a former resident, there's an uncharacteristically high number of seemingly well-adjusted but actually batshit-crazy folks there.
Look up Florida school board meetings on YouTube.
One consequence of Trump pulling a lot of newcomers into politics was their naivety at how political processes actually work.
As in, if you don't get everything you want, you aren't immediately justified to escalate and go nuclear.
I’m not all that enthused about watching a bunch of school board meetings that are probably 97% boring in the hope that I’ll find the exciting 3%.
To be fair, the time I lived there was immediately after COVID (so masks and then directly into culture wars over the bête noire du jour).
In less sarcastic news, I'm legitimately surprised it was dropped in only 3 months. That's a better than average outcome.
Also, I don't think it should fall onto Google to protect users from scams. They already provide tools against it, such as reviews on the app's page. It would be like saying the gov is responsible for my losses in a ponzi scheme because the company was registered officially.
Unless Google assertively promises users they are protected against scams on the Play Store, they aren't responsible in any way (other then that they try to make it safe because this increases revenue down the line, of course). Falling for a scam is personal responsibility.
Google also claims the 30% they skim off every legitimate transaction (which is insane) is necessary because they make sure the app store only has legit apps. They should be held to that claim.
And I don't think I've since them claim such a thing. It would be strange of them to do so, as it opens them to lawsuits such as this.
I am pretty much all-in on more government regulation of Google. Not less. There should be a non-negotiable access path to ask why things happen and an appeals process to their lockouts for end users too. Mandatory human-in-the-loop review.
While such power can be theoretically socially beneficial when granted to truly benevolent agencies under non-corrupt democratic regimes, allow me to introduce you to the Russian Internet watchdog Roskomnadzor as an example how wrong things could get if the agency is not so benevolent.
And the issue with regimes is that they can get corrupt. Even the good ones.
I get where you're coming from, but federal agencies in other domains have an ability to tell companies what to do. They can obligate them to do things.
You're opposed to this on principle? Or just the internet?
It's only about the media, because the such shortcut in the ability to tell companies what to do could be abused in a way harmful to free speech - and I think free speech is more important than enforcing quick scam app takedowns.
However, I thought about this, and what FCC could probably do is enforce content labeling for questionable apps (I think it's in spirit of how their safe harbor rule works) and immediately require marketplaces to mark application as potentially harmful ASAP. That would limit impact to the consumers, but won't let this be directly abused too much, e.g., against activist apps.
https://play-lh.googleusercontent.com/0kI_n_a9ntn9iiispSqN-Y...
I got no returns when I wanted to take it out. Just fake UI showing it was going up when it wasn't.
It was a great reminder, that crypto is full of scam. It's not even a great asset to hedge against inflation as it's heavily speculated on. I took all my crypto out and went back to good ol stocks, bonds and gold.
Soooooooooooooo much crypto scam.
The article says "at least five other users of the app had similar experiences", so the lower bound is 5 users in 3 months.
While they aren't outright fraud, they are right there. And those apps probably make billions a year.
But let's not pretend Apple doesn't see pay-to-win games and IAPs as a massive massive cash cow, too. That's not a Google exclusive.
(And I say that as someone who has had only iPhones since the Lumia 920.)
"Also" is not a deflection of "What about".
But if we want to go that way, Google doesn't play selective moral arbiter. "Porn on iOS? Never." "Gambling and PTW on iOS? Hmm. 30% cut. Okay."
But if you took out all the scammy apps out of Google or Meta ecosystems, they will be worth far less
Maybe I should shove up my ideals and principles where the sun doesn't shine, and ramp up a LLM game generator factory trained on a wiki of dark patterns... I will have pangs of conscience, but if it works I'll also have my own place to live and some basic financial security that may suffice if^W when my health degrades. And surely a good therapist would be able to fix the conscience later.
(Or does the lion's share of that money goes to the lawyers, haha?)
This has nothing to do with scams, only you disapproving of a monetization model you don't understand while making wildly incorrect estimates.
Honestly, this person must really be well off to be able to send $5M at any time and then be able to keep a lawyer on retainer to litigate against big G
Example: There are many apps that will only let you use the functionality if you agree to a 7 day free trial, which automatically starts billing you some exorbitant weekly fee as soon as that trial ends. Google will typically not refund this when a scammed user complains, since they technically agreed to the terms.
But IMO this is absolute bullshit. $50/week for a stupid flashlight app is not reasonable anywhere. It shows that the only intent of the app is to trick people. No real user would consider paying that much for what the app offers.
But Google benefits from this, so they do absolutely nothing about it, and the play store is full of such crap. The Google/Apple tax on every purchase you make on their platforms is pure profit, none of it is used to make the store better for the customers or genuine sellers.
I will avoid spending a single ₹ on these platforms as a result, and will try to avoid ever writing code for their platforms. Either my app succeeds on the open web, or it doesn't succeed at all. I'm willing to give up on the entire mobile market due to this, I'll not be part of a system that exists majorly to trick people into parting with their money and data.
This is just another day for some people.
fall for scams all the time too.
High IQ does not make you immune to scams. I believe that thinking you're immune to scams because you have a high IQ only makes you more likely to fall for one some day.
In this case, the app looks to be a classic pig butchering scheme, acting as if it were a real cryptocurrency marketplace, letting people trade and exchange cryptocurrencies in a virtual environment. They may have even tranferred small amounts of money out of the "accounts" to make the whole scam more believeable. Once you transfer back and forth a couple thousand dollars, you'd probably think the app is legit, after all, and invest those millions into the lucrative money making app. Only when people try to get all of their profits out, or when the app goes down, do people find out that they've been scammed, but the money is long gone by then.
When you think of a scam victim you should think not of an idiot but a reasonably smart person who is distracted, gets greedy, or thinks that they're immune to scams.
You don't need to actively scam idiots, you just offer them bad deals. Do it well enough and you get a bonus for improving shareholder value.
Is impersonation fundamentally unpatchable? How does one ever really 'know for certain' that an app, website, etc, is legit? Could this be fixed, once-and-for-all, with something like a hardware device issued to all citizens with early education around scams? Or would scammers still find ways around it with things like misspellings, subtle details in presentation, or what-ever have you.
It's almost like Google is suicidal and these are calls for help.
To be sure, they should be called out for abuses on both sides of the equation, but it's understandable that it's going to happen.
Everybody is fallible, and that's okay, but only if you own up to it and fix it and make the victims of it whole. If you don't do that, you're fallible and an asshole.
I’ve noticed a huge uptick in spam emails getting through to my mailbox over the last year
The subject is always either 'Order Confirmation' or 'Payment Confirmation.'
They always have a number at the bottom of email or the PDF to call for support/order cancellation. My best guess is that they want people call in rightly claiming they didn't make an order, then the phishing begins?
I've pasted one below, sans PDF. This one is a phone, but it seems to often be an antivirus subscription .
Notice it always comes from a personal name that doesn't even match the email address, not some fake company. That's why I don't understand why Gmail isn't blocking these!
--
From: Mark Kiehn <stevendouglas8689@gmail.com> Subject: Payment Confirmation
Need Help? (815) X (570) X (9159) Congrats on getting your new device! We trust you're enjoying your purchase and exploring all its amazing features.
Invoice ID: INV//#<8 digit number>
Product: OnePlus 10T Ref: #<8 digit number> Purchase Date: AUGUST 15, 2024 Total Amount: $397.24 Return Policy If you're not satisfied with your device, you can get a full refund within 48 hours of purchase. For assistance or to start a return, contact our support team.
Need Help? (815) X (570) X (9159)
If GMail is getting worse, I can imagine that other, smaller mail services are getting much worse. The best explanation that I have read about why Google (and other major providers) are so good at spam filtering: They can observe a huge portion of the world's email, so they have the best training sets.
It is interesting that we never hear from GMail folks on HN. You see all kinds of Googlers pop-up into discussions with interesting insights about how the sausage is made. However, I cannot recall anyone from GMail appearing on HN to share some interesting behind-the-scenes stories.
Google can't create a good spam filter, because enough users actually want to receive spam.
A machine can't distinguish between male enhancement pill spam and a newsletter recommending alex jones' supplements.
Or between "join our MLM today" and emails from recruiters.
Or between sales people sending cold emails and social engineering.
Google should ban both, but if they did, there'd be a huge outrage from idiots that actually want to receive content that's basically indistinguishable.
When pre-Musk Twitter tried to reduce the wave of fake news, they actually had to explicitly whitelist republican accounts because
> Most fake news on Twitter is spread by […] Republican, middle-aged White women residing in three conservative states, Arizona, Florida, and Texas
> It's almost like Google is suicidal and these are calls for help.
No no. They are fine.
Companies like Google, Apple, Microsoft, Amazon etc could they all this because they know the game is rigged in their favour in this world where everything is "legal" and not "justice" and with their resources they can legally take on many countries put together, let alone individuals. That's why they do what they do and they don't do what they don't do.
It is a pain to install apps and use an Android phone with play services installed but not logged in.
...or just create another Google account in a fake name.
You seriously think that the company that knows more about you than most intelligence agencies can't tell if you're hoodwinking them?
We know it happens at governments. Why don’t we think it can happen at corporations?
There's a verbatim mode?! That sounds incredible!
There is a specific reason for this.
The scammers are repeat players. They have a thousand accounts, three quarters of them get shut down, they look at the other 250 to see what's different, make 1000 more accounts that look more like the ones that didn't get shut down, now only half of them get shut down and they get even more data on how to avoid getting banned.
Meanwhile the ordinary user has only one account, maybe two or three for small businesses and things. If one account gets shut down their life is disrupted and they have no idea why it happened or what to do about it or how to avoid it happening again.
Google have to shut down 1000 accounts for this one scammer and if they get 999 of them right and 1 of them wrong, the scammer still has an account and the honest user doesn't.
The real problem here is that we're expecting Google to do this instead of law enforcement. Is there a scammer? Arrest them. They can't make 1000 more accounts from prison and then Google don't have to play whack a mole while clobbering tons of innocent people.
That would be ideal, but getting 195 countries on the same page on cybercrime just isn't going to happen. As it is we have multiple countries where the government actively sponsors internet scammers.
Corporations are only efficient when they have corporate responsibilities. Corporations do only efficiency and can select customers. Government must guarantee equality and rights for everyone. Even criminals are citizens with rights.
Let me demonstrate. This is how Google would do it:
(1) Algorithm captures 90% of all criminals (it's a good algorithm)
(2) 5% (1/20) change that flagged account is a criminal (95% false positives)
(3) 0.01% (1/10000) of all accounts are flagged.
There are around 246 million unique Google users in the US. Closing just 24,600 accounts removes 90% of criminals. 90% change of capture is a good deterrent.
Google also removes 23,370 innocent accounts.
GOOGLE DOES THIS ALREADY. It's efficient and well-run (actual numbers may vary) but also brutal and unjust. Legacy government institutions do their job better than Google would.
With Google you can only post complaint to HN and wish that someone working in Google notices, or that there is enough publicity to shame them.
I think Americans have forgotten what the government is. It's the job of the people to fix and constantly maintain the government because if they don't own it, someone else will.
It seems like Reaganism never left America. People from right to left have adopted the talking points and the attitude. If there are problems in the government, it's suddenly all bullshit and good for nothing. Talk in a passive voice where the government just happens.
Also probably not quite as hard as you make out in practice, as 27 of those countries share membership of a super-national government whose specific purpose is to make trade easier by streamlining legislative differences between them, and that block plus two other single countries constitute about 60% of the world's GDP.
Though random small-time scammers may regardless have a hard time selling in China an app made outside, and vice-versa, as even just the language barrier can be quite intense — I've played a game where the decently resourced western publisher didn't notice (or noticed but didn't fix) the fact that the "choose your name" box only had room for one character, and thus I was the only player who had an interesting name like '狐' rather than 'M'.
You don't even need an extradition treaty. Just require some collateral for selling outside your own country. Then people selling within their own country (i.e. probably most people) don't have to post anything but are automatically in the same jurisdiction as the victim. Whereas scammers from other countries forfeit their collateral, the amount of which is set based on the amount of scams coming out of their country.
How can a scammer make 1000 accounts? Don't they need to give Google Store some gov ID, credit card number? If this are too easy for scammers to get then ask for more documents that a legit company or developer would have. And you can make this more strict stuff optional, if you do not provide this documents your activity and reports are treated 100x more seriously.
My suspicion is that companies are using AI crap to handle user reports, some devs very exited to work on this cool new tech where they can replace even more people in support and QA with scripts.
I am beginning to think someone is not 100% truthful to me.
We had the case with Elon Musk complaining about bots and after the took over I read that he is fine with bots now,especially the ones that pay for the blue check mark.
I also wish police would do more in the cases of impersonation, where scammers impersonate people or institution, if this people are from a different country and that country does not collaborate then sanction them.
Stolen credit cards and other stuff.
People also complain that creating an account of arduous (especially in developing markets) if you have to do too much to create an account.
> My suspicion is that companies are using AI crap to handle user reports, some devs very exited to work on this cool new tech where they can replace even more people in support and QA with scripts.
The complaint is from early 2023. I suspect that whatever anti-abuse systems exist on Google Play hadn't deeply integrated LLMs at this point, as this is just like a few months after the initial launch of ChatGPT.
Google had an AI before ChatGPT, remember that there was some Google developer that made a lot of noise that Google created artificial live and enslaved it or something like that ? And I said AI not LLM
Which in turn make it that much easier for scammer.
> The real problem here is that we're expecting Google to do this instead of law enforcement. Is there a scammer? Arrest them.
What a joke how can you believe that international justice will be fast enough to handle the issue of scammer spamming apps ...
In the end those app are probably against the store TOS and if Google can't manage to correctly enforce their own TOS you can argue it's partially on them.
The penalties for violating terms of service generally have no teeth (they close your account, they don't sue you for damages), and you don't want it to be otherwise because ordinary people are constantly violating the terms as well, which are written specifically with the intent that everyone is constantly violating them so the company can always claim that anyone is in violation.
But if you close a scammer's account they just make a new one. Which is why violations of the law need to be handled by law enforcement, who have to prove the crime beyond a reasonable doubt but then can impose a penalty that actually acts as a deterrent.
The justice system should eventually track down and lock up the people responsible, but the service providers (Google, Apple, etc.) are the only ones who can - and should be obligated to - stop actively facilitating financial crimes.
But this is the same problem. They're using some unreliable heuristics to detect this sort of thing and they have false positives. So you're proposing that they authoritatively assert that something is a scam and destroy the reputation of untold innocent people on the basis of some unreliable machine learning algorithm. The innocent people would sue them and it would be hard to blame them.
> the service providers (Google, Apple, etc.) are the only ones who can - and should be obligated to - stop actively facilitating financial crimes.
Except that they can't, because they don't have a fact finding apparatus that can accurately determine if a crime is being committed or not.
> Except that they can't, because they don't have a fact finding apparatus that can accurately determine if a crime is being committed or not.
I want them to hire people who actually do the job and clean up their own mess. They need to perform extensive background checks on any application dealing with finance, which they apparently don't do at all.
If you open their website [1], you're immediately presented with an offer to make over $4000 just by registering. As soon as you click that, they even show you a 5 minute timer to put you under time pressure. This is extremely low hanging fruit in the world of obvious and less obvious scams.
> Pichai joined Google in 2004, where he led the product management and innovation efforts for a suite of Google's client software products, including Google Chrome and ChromeOS, as well as being largely responsible for Google Drive. In addition, he went on to oversee the development of other applications such as Gmail and Google Maps.
That is quite a list. I have not accomplished even 1% as much!they kill off smaller apps because they make little money for them
scam apps need to be proven they're a scam for them to be remvoed.
There's a reason Google is paying radio ads in the EU to convince everybody that they are helping small businesses, anybody who ran the figures on the mobile store knows that it wouldn't survive scrutiny.
They just pulled up another lie on my app that I record some forbidden device id and I just hesitate to shut everything down this time. Building a mobile app isn't worth the effort. The play store and the appstore are better suited to casino games and scams than real apps.
Everyone short of those capable of practically building portable devices from scratch is stuck with it.
This may be closer to the truth than many people think. In an analysis from 3 months ago [1,2] it was alleged that Google search sucks so badly not just because of AI and whatnot, but because control of the search division was finally handed to the revenue people in 2019, who promptly rolled back important spam filtering in an effort to drive up searches. Deliberate use of dark patterns to increase "user engagement" is nothing new, of course, but I was still surprised that Google would sink this low. Don't be evil, bwa-ha-ha-ha.
[1] https://www.wheresyoured.at/the-men-who-killed-google/ [2] HN discussion: https://news.ycombinator.com/item?id=40133976
With real money one could go after the money mule (or dumb scammer) through their bank account. Maybe Google could be liable if the victim paid through Google Pay, but I somewhat doubt that Google Pay will let you transfer half a million. In this case, the victim's choice of virtual currency makes it very difficult to find the criminals. I don't see why Google would need to pay up for that.
I suppose it's always worth a try to sue Google, because there's nobody else to sue.