3 ms·
While I don't want to minimize the pain of having your app copied and republished, I'd be very surprised if the author had submitted a properly sworn DMCA taked
by trotsky 16y ago
While I don't want to minimize the pain of having your app copied and republished, I'd be very surprised if the author had submitted a properly sworn DMCA takedown notice, which is the correct way to get action on these matters. I submitted a DMCA notice for the Android market in november, and the offending application was gone within 24 hours. I'm fairly sure apple requires a DMCA takedown notice to pull copyrighted content from the app store as well.
http://www.google.com/support/bin/request.py?contact_type=lr_dmca&product=androidmarket http://www.google.com/support/bin/request.py?contact_type=lr...
- nexneo 16y agoThis isn't about DMCA notice. I'm not android developer but user and I don't like Trojan stay on official market for entire week until it went to public. That means if original author didn't cared this will stay on market forever.
- trotsky 16y agoIt is about a DMCA notice. The GPP said "the developer of the original app had been trying to get Google to remove the offending apps for more than a week." He wasn't complaining about trojans, he didn't know about them, he was complaining about copyright infringement. I'd be very surprised if they would have remained for long at all if he had submitted a DMCA compliant complaint correctly. Once they were reported as trojans they were pulled the same day. I'm not sure what is expected from google here: Clearly they need to get a better handle on licensees pushing minor updates. That privesc has been around forever, and it's still there on my phone and that's super shitty - updating is android's achilles heel. But even if they get real good at that there will still be some exploits out there, every platform has them. Do people expect google should be able to make it so no malicious code can ever be run? Seems like that's a battle nobody has won. Do people expect google to switch to a curated, only google approved apps marketplace? I'd sure be unhappy if they did. Do people expect google to pull apps from the marketplace on copyright complaints even if they aren't submitted/sworn correctly and potentially let all kinds of fraudulent takedown mayhem occur (because the submitter wouldn't be liable)? Seems unwise. Do people expect google to do automated scans and blocks of suspicious code on the marketplace? Sounds like what they are planning on doing.
- spiffworks 16y agoThis is actually an extremely interesting technical problem though, isn't it? Given all the computational power Google has, I'm sure they could dedicate one emulator per new submission, and run continuous checks on the app without ever resorting to manually reviewing the apps the way that Apple does. My guess is that the Android team is the most overworked team inside Google, and they're struggling to keep up with their own growth, so they've had to deprioritize some things like the market, and focus on simply getting Honeycomb out of the door. By my theory, the Market should see some real improvements in the coming months. We'll see, I guess.
- trotsky 16y agoI agree that it's an interesting problem, unfortunately client security is also a very hard one. While an emulator check sounds like a neat approach, it is hard to prevent things like that from ending as just another cat and mouse game. They'd have to run every major+minor version, and then what if the author just set it to not infect the first 1000 installs, or to only activate if another semi-common app was installed, or simply included a chrome frame that pulled an exploit only if the client was on a major mobile network, etc. Most (though not all) malware detection, be it signature or behavioral relies on an engineer having analyzed it or a close relative in the past. When you have a sandbox model like Android, you really need to focus on getting exploits fixed on all your clients as a first priority. Until you get that straight you're never going to be doing much more than sticking your finger in the dike. Right now every 2.2.x or older client is wide open to a drive by compromise when using chrome lite. So focusing too much on the marketplace may not be rational. All recent mobile Safari builds are vulnerable to a similar webkit exploit as well. Both issues were cleared in Chromium last year.
- credo 16y agoTo reiterate (1) The security problem existed for more than a week. (2) Google's post makes no mention of (1). Instead it talks about how the issue didn't impact certain Android versions and about how they removed the malicious apps "within minutes" Regardless of your views on how many i's you'd like dotted and how many ts you'd like crossed for a DMCA form, ...... do you think that a "security update" post should suppress information about the duration of the security problem and just talk about "Within minutes of becoming aware" ?
- deleted 16y ago[deleted]
- trotsky 16y agoI guess I just don't read it the same way. Maybe it's just because I already knew about the issue, but it seems obvious the security issue existed before they were informed of it. A security issue that was fixed within minutes of its creation wouldn't be getting device wiped, cleaners pushed, market changes made. When you get security alerts from other vendors, do yours typically include the first known date of vulnerability or do they include the date it was first reported, or just the CVE assignment date? When redhat/apple/microsoft push a security update do they list the sites or programs that were known to be abusing the bugs? Not that I've seen. Hell it is rare to see anyone even listing the first date that they were being actively exploited. All of that would be better, of course, but it hardly seems reasonable to call google out when they're acting at least as responsibly as all their competitors.
- deleted 16y ago[deleted]
- anon1385 16y agoOne of the developers claims he did file a DMCA notice: http://www.reddit.com/r/Android/comments/fvepu/someone_just_ripped_off_21_popular_free_apps_from/c1ixf5w http://www.reddit.com/r/Android/comments/fvepu/someone_just_... >I'm the developer of the original Guitar Solo Lite. I noticed the rogue app a bit more than a week ago (I was receiving crash reports sent from the pirated version of the app). I notified Google about this through all the channels I could think of: DMCA notice, malicious app reporting, Android Market Help...they have yet to respond.
- trotsky 16y agoWow. They should get in touch with a lawyer - if they submitted correctly google would appear to be in clear violation of Title II, leaving them liable for the copyright infringement. Google has the responsibility to "upon receiving notice from copyright owners or their agents, act expeditiously to remove the purported infringing material". Expeditiously hasn't been directly tested in court, but the general belief is that it's somewhere between 6 and 24 hours. That liability includes up to $30,000 in damages per infringement (download). http://en.wikipedia.org/wiki/Online_Copyright_Infringement_Liability_Limitation_Act http://en.wikipedia.org/wiki/Online_Copyright_Infringement_L...
- 16s 16y agoGoogle are only obligated to respond to proper DMCA notices. They have safe harbor, they cannot be sued. A proper DMCA notice requires certain information and must be sent to the Google registered DMCA agent. http://www.copyright.gov/onlinesp/agents/g/google.pdf http://www.copyright.gov/onlinesp/agents/g/google.pdf It amazes me that developers (who hold a lot of copyright) know so little about the federal law (DMCA) designed to protect it.
- trotsky 16y agoSafe harbor is only granted conditionally, contingent on, among other things, the organization having "an effective policy" [1] and that they "act expeditiously to remove the purported infringing material" [2]. Liability also requires "actual and constructive knowledge of specific and identifiable infringements of individual items" [3] which a proper DMCA notice provides. So in this case, where they are said to have been properly informed, and either lacked an effective policy and/or failed to respond expeditiously they wouldn't be protected by safe harbor. Organizations need to be liable at some point or else you could just register a DMCA agent, and run a pirate site with impunity while failing to act on notices. [1] http://www.pillsburylaw.com/index.cfm?pageid=34&itemid=39708 http://www.pillsburylaw.com/index.cfm?pageid=34&itemid=3... [2] http://en.wikipedia.org/wiki/Online_Copyright_Infringement_Liability_Limitation_Act#Safe_Harbor_Provision_for_Online_Storage_-_.C2.A7_512.28c.29 http://en.wikipedia.org/wiki/Online_Copyright_Infringement_L... [3] http://msl1.mit.edu/furdlog/?p=8165 http://msl1.mit.edu/furdlog/?p=8165