Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Banning it first is fine. banning it first, then not giving a reply to the concerns they have is not. Even if they have reasonable believe or proof that droidscript is indeed malware, it looks like at least a chunk of their userbase uses it for legitimate usecases and the devs, who likely invested at least a few hundred hours of work in it, deserve at least some communication.


I used to work at Google, and a friend reached out to me for help – his company's app was in a similar situation, with similar communication from Google. This was a good friend from high school, so I pressed the issue using internal channels. The person handling it on Google's side was very assertive about them violating a policy, and after some back and forth I received a _vague hint_ about what was the supposed violation. I passed the hint along, and after some digging, lo and behold, it turned out one of their people had lifted someone else's images without permission, violating copyright (kudos to Google for figuring it out). My friend apologized profusely to me, to the support rep, his boss, and let the culprit go. They purged the app's assets, changed their processes, and eventually the app was reinstated.

Now, this was a special situation. I had a personal relationship with the developer, and I was happy to vouch for their honesty. Yet it still turned out Google had been right all along. Now, it's a shame Google couldn't let them know what was the issue. However, it's a safe assumption that the vast majority of people Google support deals with are spammers. And there's a lot of them. If Google gave a detailed explanation to all of them it would mean a ton of additional work – which would create an unsustainable situation at this scale.


> However, it's a safe assumption that the vast majority of people Google support deals with are spammers. If Google gave a detailed explanation to all of them it would mean a ton of additional work – which would create an unsustainable situation at this scale.

You describe a situation where Google was going to put a whole company out of business -- probably ending your friend's job, as well as that of many other honest people -- rather than give them the information they needed to fix the problem. And you think this is reasonable, because it would be "a ton of additional work" for Google? We just have to accept people losing their livelihoods as collateral damage in the war on spammers?

Imagine if we applied the same logic to the government. If they think you committed a crime, they just toss you in jail and don't have to tell you why. They could catch a lot more criminals if they didn't have to waste time prosecuting them!

No, we need a Habeas Corpus for tech companies. If you are banned, you have to be told why. Make it a law. I don't care if it results in more spam.


I liked all of your comment, but this passage in particular:

> No, we need a Habeas Corpus for tech companies. If you are banned, you have to be told why. Make it a law. I don't care if it results in more spam.

The whole ordeal seems like an attempt to educate app developers by whipping, where the victims have to guess what they did wrong.


“The opaque email responses will continue until morale improves.”


Yes, and: Efficient markets require fair & impartial courts, tort, transparency, accountability. Etc.


.. and P=NP


> Now, it's a shame Google couldn't let them know what was the issue. However, it's a safe assumption that the vast majority of people Google support deals with are spammers. And there's a lot of them. If Google gave a detailed explanation to all of them it would mean a ton of additional work – which would create an unsustainable situation at this scale.

I don't think that's reasonable. What if most are spammers ? Better let a few spammers in than treat someone unjustly. Why would it become unsustainable ? I've seen this argument repeated ad nauseam, but have yet to see proper proof.

In this particular example, a copyright violation was detected in a image, so an automated response "someone else's image was used without permission, violating copyright" seems entirely plausible.


Google has the scale to do this, but they also have a large enough monopoly where they don't have to, so they won't. It's not that it's unsustainable, it's that it is entirely sustainable to continue doing things this way.


Can you elaborate? I can see how Google can scale this automatically. But I don't see how Google can terminate, say, one million apps a day, if each termination entitles the spammer a one hour conversation with a technical representative.


Why does it need to cost them an hour conversation?!

Look at the tone-deaf example this employee just shared. All they had to do was say in the same email that they used to ban someone "you have copyrighted images".

The moment they find an infraction they could literally take a screenshot, say "the problem is X" and email it, which would incur the 5 seconds it takes to add a screenshot and say the problem you already identifies, but make a world of difference for developers.

This nonsense about "it's to stop spammers" isn't about the cost, the laughably bad logic Google uses is that by identifying what rules you broke, spammers will get better at not doing stuff Google catches...

As if the spammers don't already know what they did to get caught!


Make the person but the hour, say $100. It's a very different value proposition for some one saving their business vs some one trying to game a system.


> In this particular example, a copyright violation was detected in a image, so an automated response "someone else's image was used without permission, violating copyright" seems entirely plausible.

Google should not be enforcing copyright in the first place without at least a report of infringement by the copyright holder - and in that case they should pass the report along to the developer.


Caveat: I work at Google but know nothing about this area and my opinion here is entirely personal.

> which would create an unsustainable situation at this scale.

Financial sustainability may have something to do with it, but I suspect the larger issue is that providing too much detail essentially trains malware authors to route around the company's defenses.

Imagine the Play Store as a castle which has both good townsfolk coming and going as well as being perpetually under siege by a malicious lord. Sometimes, the castle's defenses inadvertently prevent a townsperson from getting to market to sell their onions. When the townsperson is like, "Hey, I can't get in to sell my onions." it's helpful for the castle defenses to be like, "Well, we have the portcullis raised from 9am-11am on Tuesdays and the gatekeepers listen for your accent to decide if you're a local or an enemy."

But that's, like, exactly not what you want to say if the "townsperson" you're talking to is actually an enemy spy taking notes.


Say it with me now:

>"Rough consensus, and running code. We are not the Protocol Police."

Half the problems we have nowadays is because we have manufacturers playing "the Program Police", which leads inevitably to the point you just made.

You are now, like it or not, adversarial to any User looking to do anything you find unconformant with your bottom line. You cannot solve these issues by whitelisting, just like you can't solve the problem of crime by whitelisting, and hiding the conformance suite. If you can't know the test, you can spend infinite cycles changing the wrong thing to comply with it, and I do not find that to be a tenable state-of-affairs to push on users, even if intentionally aimed at the malicious ones. This is the same problem we have in meatspace with our overly byzantine legal system; but nobody accepts that secret laws are a good idea because if everyone can read the law, it's a national security risk. At least no one without some serious conflicts of interest.

Do you really think that your company is going to nail down a good solution to a problem that society at large can't even handle reasonably? I mean, think about it. This really is a subset of the general question of how to keep everybody doing something productive. I don't even need an answer. I just want to encourage people to think.


> >"Rough consensus, and running code. We are not the Protocol Police."

This model absolutely does not work when it comes to creating spaces where humans interact. There are bad actors and someone has to police them or they will abuse other users.

If you run a bar, you have to hire bouncers. It's simply part of the cost of hosting a safe venue.


I suspect the larger issue is that providing too much detail essentially trains malware authors to route around the company's defenses.

Perhaps so, but it seems not unreasonable to have SOME ability to work with the creator of an app that's been on the store for years with a substantial number of ongoing users and (speculating) a non troublesome patten of installs and purchases.

Nobody believes that Google is technically out financially unable to do this, which leaves the other option - at a corporate level not giving a shit enough to even bother trying.

Google will often do the right thing whether by plan or by happenstance, but it pays to be aware that when it does the wrong thing there is no recourse and will be no correction.


I'm sorry, but the "security" excuse is BS. You don't have to tell users what automated tool flagged them or how their violation was discovered.

You do have an ethical obligation to inform them of what policy was violated with sufficient detail that a good actor has a reasonable chance of complying with your policy.

I think that this should be required of any company that to provides publicly available goods/services, not just Google. This doesn't just help with monopolies, but also makes it harder to hide racism and censorship behind opaque policies.


That doesn't seem to be a problem in this case? Telling spammers they are blocked due to copyrighted images trains them not to upload copyrighted images. Win-win.


picking up copyrighted images is another indicator that user X is a spammer, providing that info would eliminate the signal


Well, this is the essence of discrimination and we wouldn't tolerate it for a whole range of indicators (you're black, gay, if a particular race, etc etc). My guess is the real reason they won't tell people is that they would end up in court pretty quick.


so, in you mind, detecting copyrighted images and using that as a metric to detect spammers is discrimination? Are antivirus programs discriminating too??

I bet you indent your code in an inclusive way


From a definitional point of view yes. Using an attribute to place someone in a class and then making decisions on a class basis without actual evidence they possess the other attributes of the class is discriminatory behavior.


How can google even decide that a copyrighted image was used in an illegitimate way? They’d need to check back with the copyright owner to confirm that there is no license and they’d need to confirm that none of the various exemptions apply. This is also a matter that’s entirely between the copyright holder and the author of the app. I could understand if the problem was that the copyright holder explicitly notified google, but then that complaint could just be forwarded to the app owner with no information about any secret sauce being revealed.


i disagree about unsustainability. there are real people on the other side of the business among these bots and spammers and if you ignore them because they might be bots and spammers, they'll leave and tell other real people that google can't be reasoned with because they assume everyone is a bot and a spammer.

you see exactly this happening all the time here on HN. the sentiment for the past few years is abysmal. google is actively blowing up their power user/developer customer base. looks like a metric somewhere got optimized a bit too well.


I think so as well. As a duopoly Google and Apple owe it to their customers and 3rd party developers to know why something gets banned. Being in that position requires special consideration to hold that much power. Government has to do it, why don't huge corps?


If proper support is unsustainable due to the model, it is the model that has to change.


> Yet it still turned out Google had been right all along.

No they weren't. It was not right to terminate the entire app because someone used an image wrong.


> It's a safe assumption that the vast majority of people police deal with are criminals. And there's a lot of them. If they gave a detailed explanation of why they are under arrest it would mean a ton of additional work - which would create an unsustainable situation at this scale.

But it's all good, Google is a private company™ and can do whatever they want®.


Actually Google is a public corporation, not a private company.


They mean private in the sense of private sector vs. public sector, not equity trading.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: