Google Update Goes Open Source
google-opensource.blogspot.com
google-opensource.blogspot.com
They do the same thing on a Mac and this is why I've blocked it and removed the daemon. Google's explanation for doing it is complete BS. They should do what every other app does: check for updates when you start the app.
I don't like having to wait for, say, firefox, to install new updates when it starts up. Why not have it update itself when its not in use?
On windows Google Chrome does something similar, you don't even need administrative right to install chrome it sits in the application data area. It can update and operate all without explicit permission. It makes me a little wary.
That said, automatic updates that interfere with normal work -- e.g. restarting Windows, or forcing the update in certain situations, can be more problematic.
Say I'm at a coffee shop with wi-fi or using my notebook through a cellular 3G/EDGE network and this update starts downloading a large Google Earth update that I never asked for. Why should I be paying for the charges because Google wants to update their software without telling me?
Another issue is versioning. If I'm working in one version of the software and don't want to use the newer version until others thoroughly test it and fix the critical bugs, why should i be forced to upgrade? I've used a lot of newer versions of software and many were actually worse than their older versions. Again, why should they force users to upgrade? Why not ask?
This Google Update is bad news all around. It installed itself like a virus rootkit on my machine with Google Earth installation and I was never notified (yeah, a note is probably buried deep in a TOC somewhere). Luckily, LittleSnitch told me about it and I removed it from the Launch Daemons... and I also removed Google Earth because of it.
Finally, why should Google get updates about my location at all times? Every time this thing pings their server, my IP is inevitably transmitted to them.
Sparkle does this perfectly. You can completely disable update checking or allow it to check on periodic intervals. And when it finds an update, it informs you with an update window and shows you exactly why it is updating and what was fixed and what more you get. This Ohama thing gives you none of these options and it also runs at all times like a virus.
If MS did this, people would be all over MS. But when Google does it, people defend them.
Any software that adopts this Omaha crap will be blocked from my machine as well.
Making it open source is definitely the right direction. If it gets modified so that there is a control panel of sorts so that you an control the updates I think it will be considerably better for people.If it is set up as it is now (Updating at some time of low computer usage), with options that can be changed to only update through a specific connection, to only update when the computer has been idle for X amount of time, and similar times.
Look at the recent Conficker worm. There are estimates that over 10 million computers were infected with it (and are now having that annoying fake antivirus software downloaded onto it), because they hadn't installed a security update that was published in October. If they would just push the update after 1-2 months (Assuming that no major problems have been reported) to all Windows computers, much of the spread and potential damage would have been avoided. Since you use a Mac, you might not be used to this kind of problem. Windows always has some sort of a security hole, which is constantly being exploited. Anyone in IT can tell you how much of their time would be saved if Microsoft would stop nagging users about the security updates and just install them after they've been verified as stable. At the end of March we lost quite a bit of time having to scan all of the machines, and then going out and removing it from the one that had been infected, all because a higher up had heard about Conficker and was worried about what might happen on 4/1.
I agree with your overall point that Google went about this wrong if they're trying to be on the up-and-up. The same thing happens with Firefox on startup. I don't think people really consider the implications of that either.
> Any software that adopts this Omaha crap will be blocked from my machine as well.
Well, it looks like Omaha could be made to be a lot more up-front and has some modular bits that could be pretty handy. Don't penalize people who use parts of the code (I'm considering it for pieces) unless they do the same sort of disrespectful practices (e.g. hidden inclusion).
The one thing I can say is that I'd rather see Google open source this than not. It's a step in the right direction of making this less opaque and less mysterious, even if it's insufficient to pardon their behavior.
Firefox updates on start up may be bad, but Sparkle handles this better -- it asks me to update the app I'm using, and downloads it in background.
By the way, Google's update framework for Mac has been there for a few months: http://code.google.com/p/update-engine/. But -- please -- don't use it.
Of course, you'd need to figure out some standard way of locating available updates. Is there anyone out there doing this sort of thing?