Post mortem: Thanks and lessons learned
elnorr.com
elnorr.com
So the flashlight app then goes and monitors my phone calls, intercepts them to display ads (at no point is it clear that the app is responsible for that) and probably relays my called numbers to PingJam?
Are you fucking kidding me? It's straight malware and you should be fined triple for every dollar you ever made. Google should fire whoever inside their organization enabled you to run this scam for longer than a month.
(Anyone still have the SDK or an app that used this? I'd love to see if it leaked caller ids to them. Holy privacy invasion.)
I would not knowing install app that does that.
If only I could filter playstore by permissions. That would make it that much more usable. As it is now, it take too much time to scroll down till first app that does not require too many of them.
Or control better what kind of data applications see. Anything would be better then current "we pretend you are in control, but will make it as hard as possible for you to exercise that control."
End of rant.
You fucking kidding me? And you paid money for this phone?
It's up to users to not install apps that request permissions they don't agree with, although that is indeed not presented ideally.
From the post, it sounds like Google is itself running this "scam":
> FTA: I don’t know whether we got kicked out because 24 hours before banning our apps Google launched an almost identical feature in Android 4.4 or if it’s something else.
[Can anyone confirm?]
There's no screenshot of the type of ads I'm going to get and the actions are not clear whether I'm "OK"ing acknowledgment or if I am enabling the ads. To an average user who doesn't want to read, I would expect them to just press OK because it seems like a standard first time user startup screen. Would "cancel" close the app? I wouldn't be surprised if most opt-ins were not truly intentional.
To me this is a dark pattern. The notification should have clearly asked "Would you like to enable caller ads?" and "Yes" or "No".
Pingjam was a monetization solution for Android app developers
...
Google Play kicked out over 1,000 apps that worked with us from their app store
this whole article paints Google in the usual HN-friendly light of 'big bad unapproachable Google being evil', without giving any detail on what this 'monetization solution' actually was, and why Google wasn't being entirely reasonable to kick it to the kerb.edit: yeah, thought so. they push contextual ads based on who you're calling. no surprises that got killed.
On the other hand looking at links like https://angel.co/pingjam I have to admit that they were doing something that was going to feel a lot like privacy invasion. Knowing who you were calling, and using that to target relevant ads?
Pingjam seemed to have gone the extra mile, by seeking close cooperation with Google, also in terms of EULA. I can imagine them feeling hard done-by Google.
I must admit am not in any position to judge the Google license agreement and their possible non-compliance.
Google has been accused of being "evil" in recent years, but I find it strange that they'd pull 1,000 apps with no forewarning and no explanation as to why. Surely they must have given you advance notice, perhaps a chance to change your service? Either that or your service was doing something unethical or clearly against Google's terms, and it was just a matter of time until they killed it.
Something doesn't add up here...
Edit: after looking at the site (http://pingjam.com/), I have no idea what kind of advertising service this is, but it looks pretty nasty (in call popup ads?). Site itself is also very, very vague, providing little information on the service itself, and lots of fluff.
tl;dr - we made a shitty service and Google killed it.
Sorry, but it is correct that google kick you out.
And i cant believe that app users understand what they installed in background. I think many users complained about the ads and thats why google react.
Is there some place where these are gathered for common benefit? Maybe get into more depth with interviews, because this post-mortem for instance leaves a lot of questions unanswered.
The top Google link is a CBinsights blog post, but that does not really cover it. I would consider starting this as a side-project. Would this be interesting?
Of course it would! but make sure to create a profile for each company, what they are trying to achieve, how, etc..
And then all the biography of the company.. what events ocurred.. also analisys could be collected from bright folks of what they were doing right and wrong.. just some ideas :)
We can learn much more from failures compared to the successful enterprises.. we dont hear much from the failed side of the trench. and thats a shame..
Look at Zynga => they relied on FB
Look at Angry Birds (initially) => they relied on Apple
Look at Moz => they relied on Google (scraping rankings)
Look at Xobni => they relied on Microsoft
Look at Rapportive => they relied on Google/Gmail
Look at TweetDeck (before acquisition) => they relied on Twitter
It's not black and white. Sometimes you just get unlucky. Sometimes you get lucky.
This is the most important part that most don't seem to grab
This has caused several people to go under. Another company doesn't owe you nothing, be that Linkedin, Twitter, Facebook, Google
If your product rests on only one base, you are under a great risk
That really says it all. As another commenter pointed out, yeah, sometimes you get lucky... but I say "why tempt fate"? Some people go to Vegas and bet their life's savings on the roulette wheel and come out with a bundle. Most people that go to Vegas come back with their wallets lighter than when the went.
Some people bet on a platform that they don't control, with no SLA or contractual agreements to protect themselves, and subject themselves to the capricious whims and foibles of Google, Apple, Microsoft, IBM, Twitter or whoever, and some of them succeed wildly. That doesn't mean it's a good idea to do this.
There's an old saw that says the two worst strategic mistakes you can make are "launching a ground invasion of Russia in the winter, and partnering with Microsoft". I'd like to offer up a new version of that:
"The three worst strategic mistakes you can make are launching a ground invasion of Russia in the winter, partnering with Microsoft, and tying your app to a single-source platform you have no control over".
Monitoring call records and targeting ads based on them sounds very close to what the NSA has been exploiting in mobile apps (c.f. revelations a couple days ago). Atrocious. I blame both Pingjam and the app developers for callously abusing end-user trust and integrating with such a shady third-party.
This also reminds me of top comment on the $50,000 Twitter name social engineering attack article[1]: setup a list of vendors that have pathetic security practices, but in this case the list would be of apps that integrate shady third-parties.
I'm not sure if these guys are super-slick sheisters or legitimately clueless. This 'woe-is-us' blog post, written in the style of the humble lean innocent entrepreneur, certainly strikes me as disingenuous.
The intent of the post was to share experiences and lessons, not to promote what we did at Pingjam. We already went through that discussion several months ago when we were working to get Pingjam accepted by developers. Some developers (including very respectable apps) liked our service and tried us out, some did not. To each their own. Since I don't think it's useful to discuss what we did - I'll refrain from fully explaining what we did, why we thought it was a good thing, the value that the service provided to users or how we made sure to follow best practices on opt-ins, opt-outs, privacy, etc'. You are welcome to think what you want about our service.
Regardless of whether you like the service we provided or not, we went through a certain set of experiences that can be useful to others. If you choose to take anything from that - I hope it helps you in whatever you are doing.
I'm seeing this a lot lately. Paraphrasing UK driving test examiners, it should be "You didn't FAIL; you just didn't succeed this time."
There is a lot of talk about what went wrong, but I think this is the most transferable lesson spanning startups of every kind.