‹ BackHN Continuity

Thread

The Google Play app review process now regularly takes longer than a week

374 points · 352 comments · inputmice

  1. Gareth321 · · focus · HN ↗
    MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past due for regulation in this space. The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.

    And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.

    1. setgree · · focus · HN ↗
      And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?

      I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.

      1. Maskawanian · · focus · HN ↗
        How about treating people like adults for a start? How about starting public awareness campaigns about proper digital hygiene. Not everything has to be nanny state garbage.
        1. pjmlp · · focus · HN ↗
          Many of us have routinely cleaned computers from adults that installed several Ask Jeeves and Yahoo toolbars.
          1. compass_copium · · focus · HN ↗
            At some point computers need to stop being treated as magical boxes that no reasonable person can learn how to use safely. We expect people who use cars to learn how to use them safely, we expect people who use lawnmowers to not stick their fingers in them. Computers have been a part of daily life for normies for decades at this point, it's infantilizing to suggest that average, non-tech savvy people can't learn to use (not necessarily build, repair, etc.) them properly and need to be protected from them.
            1. pjmlp · · focus · HN ↗
              People have to successfully get through a state exam in order to drive cars in first place, can be jailed, get fined when not driving them safely, or forbidden for life to ever drive again.

              People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.

              What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.

              1. voakbasda · · focus · HN ↗
                Do you hate open source and want only projects where their authors can afford liability insurance and are willing to put themselves in the firing line of a legal system that can be both arbitrary and capricious? Because that’s what you seem to want.
                1. pjmlp · · focus · HN ↗
                  Even people selling on the street or doing charity work have to account for liability of their actions.

                  Lets stop talking about open source as special snowflakes where everything is excused.

                  1. voakbasda · · focus · HN ↗
                    And that’s how you prevent bake sales, lemonade stands, and more. You create a barrier to entry that gets raised little by little until only the biggest players can afford the game. Software liability would end all small open source projects.
                    1. pjmlp · · focus · HN ↗
                      Bake sales and lemonade stands are perfectly fine as long as people don't land on hospital urgency, due to careless work on preparing them with spoiled ingredients or lack of hygiene.

                      Lets strive for quality in software.

                      1. Dylan16807 · · focus · HN ↗
                        Now do that again without careless work or spoiled ingredients. Do you still want them punished or facing so much regulation they can't exist? Because you'll definitely get that with software; even really good development will have flaws, and single flaws can lead to a thousand or million hacks.
                        1. pjmlp · · focus · HN ↗
                          All humans face scrutiny in their interactions with others.

                          Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.

                          1. Dylan16807 · · focus · HN ↗
                            I dunno, people seem to accept most kinds of tool being fussy or flaky.

                            But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.

                            1. pjmlp · · focus · HN ↗
                              Thankfully industry is changing,

                              - <a href="https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;?uri=CELEX:32019R0881" rel="nofollow">https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;?uri=CELEX:32...

                              - <a href="https:&#x2F;&#x2F;www.nsa.gov&#x2F;Press-Room&#x2F;News-Highlights&#x2F;Article&#x2F;Article&#x2F;4523810&#x2F;five-eyes-cyber-security-agencies-statement" rel="nofollow">https:&#x2F;&#x2F;www.nsa.gov&#x2F;Press-Room&#x2F;News-Highlights&#x2F;Article&#x2F;Artic...

                              And I could keep listing several other world regions.

                  2. esikich · · focus · HN ↗
                    The problem is it&#x27;s literally speech. Selling something isn&#x27;t speech, you do not have the right to do charity work or run a business. It goes even beyond speech, it&#x27;s closer to pure math&#x2F;logic and I feel very uncomfortable about regulating that. I also think it&#x27;s literally impossible.
                    1. pjmlp · · focus · HN ↗
                      Speech is subject to laws in most jurisdictions.
              2. dml2135 · · focus · HN ↗
                &gt;People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.

                Anyone is allowed to sue the lawnmower company. Did they win?

                1. lightedman · · focus · HN ↗
                  The amount of &quot;Do not put hands here&quot; labels I&#x27;ve seen on lawnmowers would suggest that, yes, someone did sue and win (or at the least got a settlement) and thus the lawyers forced the companies to put disclaimers and warnings on the lawnmower, directly on the top of the deck in plain sight.
              3. close04 · · focus · HN ↗
                On power tools, appliances, etc. the safety features are at the user&#x27;s latitude to bypass. They are usually a hint (don&#x27;t microwave your dog), not a hard barrier (&quot;I&#x27;m sorry, Dave. I&#x27;m afraid I can&#x27;t do that&quot;). A spinning blade is covered by a grill you can trivially remove without permission from anyone.

                I agree that the defaults should be secure, but you can&#x27;t force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.

                At some point users have to take responsibility and be accountable for their actions. We can&#x27;t just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn&#x27;t punish every user for the sake of some of them.

                The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I&#x27;m really starting to suspect that their goal is actually only the control. And all those people defending it with &quot;but people don&#x27;t know better, they need a hand to guide them&quot; were equally misled. What do you think?

                1. pjmlp · · focus · HN ↗
                  Yes, and when they fail to do so, there are laws in place for liability of third party, or when their own irresponsible actions affects others.
            2. marcosdumay · · focus · HN ↗
              Well, computers first stop being magical machines that no person can learn how to use safely, then.

              And, honestly, if you think the endpoint safety problem doesn&#x27;t apply to you, you are part of the problem.

              1. compass_copium · · focus · HN ↗
                The endpoint safety problem obviously applies to me and every person connected to the World Wide Web, but the grandparent was talking about The Olds who install the AskJeeves and the Yahoo! toolbars and Bonzi Buddy and...

                If computers aren&#x27;t safe enough that a reasonably competent user, who doesn&#x27;t open random files they found online and obvious spear-phishing emails, can&#x27;t use one without losing their 401k, then maybe we need to just reevaluate modern life and go back to bank tellers.

            3. misnome · · focus · HN ↗
              Using a computer wrong doesn&#x27;t kill people.
              1. jprjr_ · · focus · HN ↗
                Yes and no.

                The computer itself won&#x27;t really do anything. But I&#x27;m sure suicides go up when people lose all their money, or get personal private details leaked, and so on.

              2. pjmlp · · focus · HN ↗
                Depends on what those computers are responsible for.
              3. m4rtink · · focus · HN ↗
                ehm: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Therac-25" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Therac-25
                1. anonymars · · focus · HN ↗
                  &gt; &quot;One [software fault] was when the operator incorrectly selected X-ray mode then in 8 seconds quickly changing to electron mode, which allowed the electron beam to be set for X-ray mode without the X-ray target being in place&quot;

                  Therac-25 is an important software-development case study but a torturous stretch of &quot;Using a computer wrong&quot;

                  1. [deleted] · · focus · HN ↗

                    [deleted]

                2. misnome · · focus · HN ↗
                  You are right! Computer use should be taught, tested and licensed exactly the same way of steering several tons of metal at 70mph are!
                3. [deleted] · · focus · HN ↗

                  [deleted]

              4. esikich · · focus · HN ↗
                I&#x27;m sure you can think of many examples where it does though.
          2. sunaookami · · focus · HN ↗
            And e.g. browsers cracked down on it, removed toolbar support and powerful add-on support AND enforced signing meaning everything goes through their gatekept extension store and these problems still persist (e.g. addons changing the search provider, new tab page or homepage). Locking everything down does not help.
            1. pjmlp · · focus · HN ↗
              More a problem of those stores still not being properly validated rather a dumping ground for extensions, than anything else.
              1. sunaookami · · focus · HN ↗
                A problem that can&#x27;t be solved, you can&#x27;t check every single program out there much like you can&#x27;t check every single human ever even with cameras installed everywhere.
                1. pjmlp · · focus · HN ↗
                  Just because some people still die with seatbelts, does not mean they aren&#x27;t safer without them.

                  Yes you can check every single program out there, when digital stores are the only acquisition mechanism.

                  Or as alternative, signed binaries.

                  Coupled with liability like anything else in our societies.

            2. no-name-here · · focus · HN ↗
              &gt; does not help

              Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that&#x27;s even with the current situation not being what I&#x27;d call fully locked down.

              1. sunaookami · · focus · HN ↗
                Nope.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.