5 ms·
Tales from the spam filter of an Android app developer
- mfatica 7y agoWhy does it need to be?
- saagarjha 7y agoThey’re built on a model of providing curated, safe content, as opposed to the “wild west” of installing random software from the internet?
- mfatica 7y agoAre they though? Last I checked that describes Apple's App store not Android
- FussyZeus 7y agoYou're not wrong, but it's one of the many reasons that the Play store has become a complete sewer in terms of quality, safety, and legality of the products offered. Like Facebook, Twitter, etc. Google built the Play store (and Android at large, really) as a barn with all the doors open, and have been slowly closing them when users get too angry about a given (ridiculous for a multi-billion dollar corporation) problem. Apple, on the other hand, built a walled garden and added doors to it as needed, and occasionally has taken some away too. You can use the cynical read and say this is to further their position in the market as the "pro privacy" alternative to Google, or you can say it's part of their core company ethos, but the result is the same either way: buying an app off the App Store carries little/no risk, and Apple strongly favors users during any issues that may arise. Play store on the other hand can be 100% safe or extremely risky, with little/no way to tell beforehand, and Google's end user support is notoriously terrible.
- saagarjha 7y agoI don’t see why this is specific to the Play Store? Surely the App Store has the same issues (point of contact, “free with ads” model, tracking SDKs)?
- mirimir 7y agoDoes the App Store do a better job of policing truly malicious malware?
- saagarjha 7y agoApp Store apps in general have significantly fewer ways to be “truly malicious”, and App Store review is somewhat more stringent than Google’s process from what I’ve heard. However, run-of-the-mill tracking SDKs are commonplace on both stores.
- on_and_off 7y agoIn my experience, about the same. Both stores use automatic detection for malware, the manual testing used by _both_ store is mostly there for business reasons in my experience. Google used to be laxer about what you could do with its APIs, but it has started to become way stricter one or two years ago. It always cause some drama in the dev community when they stop apps from misusing an API (even if the misuse was not shady) but it is mostly for the best.
- aasasd 7y agoTBF, the author doesn't say that this is specific to the Play Store from the set of {Play Store, App Store}.
- nodamage 7y agoThe Play Store requires each developer to include a contact email address, which is then published in the store listing for each app. This makes it very easy for someone to scrape all the store listings to collect all of the contact emails to spam. By contrast, the App Store only requires a support URL to be included in the listing, not an email address.
- 7y ago
- nneonneo 7y agoSite's being hugged to death, archive here: http://archive.is/tx2oF http://archive.is/tx2oF The gist is that spammers message the publishers of Play apps looking for willing developers to (a) integrate random tracking/advertising/analytics "SDKs", (b) integrate dubious/malicious software like cryptocurrency miners, P2P relays, or (c) sell their app outright. The idea is that, at any given time, you don't know whether an app you've downloaded from the Play store has done any of these things, and the spammers probably know they can keep such "infected" apps on the Play store for long enough to turn a profit.
- Causality1 7y agoToo many good apps fall victim to the temptation. For example, ES File Explorer. It went from a great app to one with too many ads to outright malicious and now the developer is banned from the app store entirely. I still haven't found a file manager that let's you manage mtiple tabs of file folders with windows shared folders with the same level of elegance.
- deogeo 7y agoHaving to use a non-FOSS app for something as basic as a file explorer is a symptom of a very sick ecosystem.
- nneonneo 7y agoI wouldn’t say so - even if the built in file explorer works well, if someone built a really slick one with features I wanted, I would probably just use that. It’s like why many people might choose, for example, iTerm2 over Terminal.app, even though the latter is provided with the OS and works well enough for most purposes.
- saagarjha 7y agoiTerm2 is GPLv2, though: this situation the opposite of the one presented above.
- 7y ago
- HillaryBriss 7y agoit comes down to a criticism of: 1. Google Play Store's requirement that app devs publicly post a contact email address 2. Google's failure to invest more into eliminating bad apps from the App Store (somehow) 3. Google's scorched earth policy with regards to sucking all of the money out of the ecosystem for itself and a very small number of app dev winners -- leaving most of the app devs in the poverty zone Google could partially address #1 by creating a mail relay which filters out the bad library actors. App devs could use an address into the relay instead of publicly posting their own address and being left to fend for themselves. Of course, that would mean even more of a developer's customer communication would be routed through Google. So that's not exactly optimal either.
- iamnotacrook 7y agoThe argument is the Play Store is unsafe/untrustworthy because developers get spam emails. Is that it? Is there anything to discuss here?