39 ms·
Let's guess what Google requires in 14 days or they kill our extension
- daveidol 6y agoThanks for posting this publicly. I’m all for the general idea of reigning in unnecessary data collection/prioritizing user privacy, but sometimes you just need certain features to make things work!
- Guzba 6y agoAgreed. I really did see benefit to the changes I made that reduced our permissions requested based on the initial email we received from Google. When even that was rejected though, I kind of got slammed with a "well.... what do I do now?".
- dasm 6y agoAs a daily Pushbullet user, thank you for posting this! It's maddening that the best way to escalate a Google customer service issue is social media.
- deepender99 6y agoWell this is my favorite Extension, If Google kills it then how will users gets its pushbullet chat data back.
- tiborsaas 6y agoWhat's more is that chat history is broken, I can't see tons of messages on the web interface. You can still access some on the web. But your best option is to do a GDPR request to export you all your data.
- meraku 6y agoAnother happy PushBullet user here. Extremely useful for receiving text messages from my phone while on my laptop, especially for web apps that insist on sending security codes that way instead of TOTP. This sort of behavior from Google really is infuriating. How they can just decide to boot an app from the Chrome Store that is installed by over a million users is mind-boggling. It's a pity that Chrome doesn't allow extensions to be installed from the new Edge store, like Microsoft allow Edge to install extensions from the Chrome store. With both built on Chromium, that could've potentially been a workaround (though you may want to consider adding this extension to the Edge store anyway). Hopefully someone from Google will see this and stop the madness or be able to provide more details on exactly what needs to be done, though I wouldn't bet on it.
- kyriakos 6y agoI switched to Edge chromium when the first production release came out and I am extremely happy. I use all my extensions including unlock origin straight from chrome Web store and it feels a bit snappier than chrome itself.
- driverdan 6y ago> It's a pity that Chrome doesn't allow extensions to be installed from the new Edge store Why would anyone want to do that? What's a real pity is that they make every effort to block users from installing their own extensions. App stores are terrible.
- Spivak 6y agoNo, they make every effort to ensure that installing extensions outside the store is annoying so that you can't push your malware by just having users download and install it. This kind of malware plagued Firefox for years until they made extension signing mandatory
- saurik 6y agoIf I am in a position to install random shit into Firefox I am also in a position to just modify Firefox, so that doesn't accomplish anything at all except remove functionality from users.
- enedil 6y agoExcept most targets won't modify their Firefox.
- saurik 6y agoI think I am not understanding your use of the word "target" here, as I would have expected that to be the person being targeted by the malware install, but that person isn't someone who by definition even knows what is going on: it is the attacker who is choosing to install something into Firefox without the express knowledge of the target, and so it is the attacker whom I am noting is able to choose to instead modify Firefox; if the target were making the decision to install the extension then clearly they should be allowed to do whatever they legitimately want to do with their software.
- jyfzbj 6y agoThis is concerning. Shouldn’t Google’s store have a dedicated support rep for extensions above a certain threshold?
- tbodt 6y agohttps://twitter.com/dotproto https://twitter.com/dotproto
- raybb 6y agoThis is awful. I'm going to send GCP support a message with the small hope that someone can flag it up to the right team.
- snazz 6y agoGCP and the rest of Google are separated from each other similarly to how YouTube and Google are separated. Unfortunately, the odds of that technique working are very low.
- raybb 6y agoWell they responded saying: > Although I am sure that this is not the correct place to reach out, I have reached out to the Chrome privacy team to see if they can give us some advice for PushBullet. Though I posted this before this article was on the front page of HN.
- sming 6y agothe corporate gorilla beats its chest, demanding you comply! But with what, it does not say ¯\_(-_-)_/¯
- deleted 6y ago[deleted]
- crankylinuxuser 6y agoThe answer is to run a campaign to work with Firefox and Safari only, and convert all users to either platform. Seriously, fuck google. I'm just done with them.
- Seb-C 6y agoThere are no WebExtensions on Safari
- crankylinuxuser 6y agoWhelp... That shows just how little I know about Mac.
- Baeocystin 6y agoAnother long-term PushBullet customer here. Anyone at Google who is listening- this kind of behavior kills my desire to continue using your products dead. I need functionality, of the type PushBullet has provided for years, to do my work. The recent nerfing of ublock origin has already had me feeling iffy on things. Behavior like this is simply unacceptable. If you want people to use your services, you need to have some way to communicate. Period. "If you use our tools, we can kill your livelihood at any time for any reason and tough shit if you want a why" doesn't exactly inspire, you know?
- nikanj 6y agoGoogle is the new Microsoft. Using it is mandatory, liking it is optional.
- unknown2374 6y agoUsing it is not mandatory, using it is convenient.
- p2t2p 6y agoTo me it is far less convenient. I have to establish some kind of system that makes regular backups in case google elects into banning me. With Apple ecosystem that is not a problem because every single cloud tool they have supports “download everything locally” option
- ilrwbwrkhv 6y agoSwitch to Firefox. It has gotten much better.
- yorwba 6y agoAnd there's also a Pushbullet add-on for Firefox: https://addons.mozilla.org/en-US/firefox/addon/pushbullet/ https://addons.mozilla.org/en-US/firefox/addon/pushbullet/ Not sure whether the functionality is the same.
- jaredandrews 6y agoSlightly related, Google is also tightening up Android 11 location permissions (with good reason). In this blog post[0] they outline a process for getting approval that was supposed to be underway by the start of May. So far I have not been able to locate this form nor have I been able to find any Android developers who have. If anyone here knows where it is or what the deal is, please let me know. [0] https://android-developers.googleblog.com/2020/02/safer-location-access.html https://android-developers.googleblog.com/2020/02/safer-loca...
- Mindwipe 6y agoThe SMS access process never worked after it was introduced in a similar way several years ago now. Google even put some minority groups in significant danger to their safety as a result. Nobody at Google gave a shit and it was never fixed.
- factsaresacred 6y agoHave been through a similar experience. Developing extensions for Google Chrome is a particular form of masochism. They really don't seem to care. And things took a turn for the worst last December when the approval process went from hours to weeks. Check out the Chrome Google group for a sample of the lost souls who hitched their wagon to the Chrome platform and now cry futilely into the abyss for support: https://groups.google.com/a/chromium.org/forum/#!forum/chromium-extensions https://groups.google.com/a/chromium.org/forum/#!forum/chrom...
- yorwba 6y agoThis one looks particularly relevant: https://groups.google.com/a/chromium.org/forum/#!topic/chromium-extensions/uo1HZWfHiFU https://groups.google.com/a/chromium.org/forum/#!topic/chrom... It seems like all extension developers play the same game of guess-and-check to find out which permissions they should remove, and the unlucky ones get banned for trying too often.
- thatguy0900 6y agoWhen I read something like this I have to assume Google is just trying to kill off extensions, it's such a glaringly obvious problem there's no way any human has seen and okay'd it with good intentions.
- aaanotherhnfolk 6y agoI'm the person at $dayjob who has to chart a course through the recent chrome web store changes and this is honestly my conclusion too. These extensions don't make any money at all for Google, in fact some of them lose money for Google (privacy oriented extensions, ironically.) They are a security nightmare for Google, capable of side channel browser attacks or direct abuse via a permission (all_urls permission can read your emails to grandma.) Google doesn't want extensions to exist, and they also can't outright kill them without creating a new foothold for their competitors in the browser wars. So we get this intentionally masochistic process change. Jump this high or we'll ban you. Now jump higher but with your eyes closed. Okay, now backflip or you're banned. The extension developers have absolutely no power to fight back.
- renewiltord 6y agoThis is sad but they're just responding to market hysteria on permissions.
- luckylion 6y agoThe general idea of "please limit the permissions you request", maybe. The secrecy about what they don't like isn't part of that, that's just Google's preference for keeping things vague.
- danShumway 6y ago> but they're just responding to market hysteria on permissions. And responding poorly. What the market wants is for companies to lay out understandable policies that protect their privacy. People I know want more clarity about what's happening in the extension store and on their devices, not less. As a consumer, it doesn't make me feel any better for Google to say in vague terms, "we booted off an app that doesn't respect your privacy." Okay, what was it doing? Are there other apps I should be concerned about? How bad did the app need to get before you booted it off? Are there exceptions to these standards? Are they being applied to internal apps as well? My feeling is that Google's inability to communicate with developers and users is its own problem; it's not the market's fault. Tech companies in general have had difficulty with customer support for a while, even before the media started picking up on privacy issues. Nothing has really changed, Google just happens to be notably bad at this.
- rurp 6y agoI'm not mad about them increasing scrutiny on permissions, that seems fine. What sucks is Google giving a short deadline, no details, and zero response to the developer's repeated communication attempts; all with the threat of Google nuking every single Google resource tied to the developer if they step over some invisible line.
- boomboomsubban 6y agoDoes chrome already offer features like PushBullet? Firefox somewhat does with Pocket, so I assume chrome has something similar. If they do offer something of the sort, or start to shortly, this seems like a perfect antitrust case.
- beastman82 6y agoZero chance this will happen without a much bigger party involved
- pkilgore 6y agoUnder the Clayton Act, the Sherman Act, or both? Is this a legal realism commentary on the comparative cost-benefit of civil antitrust litigation in modern America? Or are you just pretending you know things to feel good on the internet.
- beastman82 6y agoI was going to respond in earnest, but then I read the second paragraph. If you want a civil discussion you might hold the insults next time.
- deepender99 6y agoyes they offer https://messages.google.com/ https://messages.google.com/
- patwalls 6y agoChrome extension developer here. Google ripped my Chrome extension off the app store about a month ago. I got a similar cryptic message, and then I scrambled to fix it, like you're doing now. Somehow my extension reappeared the next day. Email me pat [at] trypigeon [dot] co and I can send you some of the things I did that maybe have helped. Tweeting my support as well: https://twitter.com/thepatwalls/status/1260638967793242113 https://twitter.com/thepatwalls/status/1260638967793242113
- jonny_eh 6y ago> Email me pat [at] trypigeon [dot] co and I can send you some of the things I did that maybe have helped. Please post here so everyone else can learn too.
- celticninja 6y agoI assume GP is trying not to help those the automated system intends to catch
- komali2 6y agoThat's a lot of good faith you're giving these automated systems...
- tomsmeding 6y agoOr, of course, said poster would like the maintainers of the automated system not to realise the workarounds for their system. :)
- patwalls 6y agoHaha, my "workarounds" consisted of being persistent with a few different support emails I found, posting on the Chromium support forums, and a few other things. Pretty boring stuff, and I'm not really sure that it even worked. Weeks or months from now, I'm sure someone will get their extension removed from the store, and may come across this post scrambling for a solution. If that's you, please reach out to me and I can send you the support emails and everything I tried.
- pkaye 6y agoWhat kind of people make these decision at Google? Engineers? Or did they automate everything with "machine learning"?
- snazz 6y agoIt's very automated, especially during the pandemic when many of the content moderators can't go to work.
- grwthckrmstr 6y agoYikes! I've used PushBullet for since several years and I can't imagine not using it. I can understand why Google is doing this though. They have a "Send to device" feature in Chrome. Killing the top 3rd party app is the perfect way to grow adoption of their new & in-built feature. "Do no evil"
- jerf 6y agoYou know, at the very least it would be nice to get something a bit more direct, like, "We are no longer permitting extensions that do X on our marketplace", or heck, even just a "We're permanently rejecting this for unspecified reasons." But if that's what you're doing, don't claim that the extension is being rejected for "overbroad permissions". I understand that Google may not literally come out and say "We've decided to eat your extension's functionality and you can just burn." But don't lie about why it's being rejected... however much you may wrap the result up in marketingspeak, don't actively lie about the reason for rejection, so that someone can burn the candle at both end for two weeks futilely trying to appease the lying error message. As for the fact it may not look that great no matter how much marketing-speak it gets wrapped up in for Google to just eat some functionality and kill all competition... yeah, well, suck it up Google. Don't lie about it. I mean, you can always spin it as security security blah blah security if nothing else, which ought to be enough of a fig leaf.
- TheAdamAndChe 6y agoOutright admitting this may cause issues with antitrust laws.
- philsnow 6y agoNeither here nor there but it was "Don't be evil", never "Do no evil". The latter evokes the Hippocratic Oath and sounds virtuous, but the former is a somewhat tongue-in-cheek reference to the (at the time) megacorps they wanted Google to not be like. (Mind, they're arguably not complying with the "Don't be evil" version either, especially lately.)
- MattGaiser 6y agoAny reason that Google doesn't give reasons and ways to comply? I haven't ever had to deal with a Google person regarding Android development, but when I built stuff for Blackberry (miss that company), they always provided nice and detailed feedback. Blackberry famously let legal influence design, so I would be surprised if it was a cover your ass thing.
- patwalls 6y agoBecause they are attempting to automate all of it. This message is generic and based on some analysis of the "manifest.json". They have also turned off all reviews in the Chrome Web Store: https://news.ycombinator.com/item?id=22935092 https://news.ycombinator.com/item?id=22935092
- gowld 6y agoHuh? They turned off reviews because a worldwide pandemic eliminated their ability to maintain staff to moderate reviews. That's the opposite of "automating it".
- 29083011397778 6y ago> Blackberry famously let legal influence design, Do you have a source or link for this at all for further reading? A quick search doesn't turn up anything, but it sounds like a great read
- 6y ago
- Crazyontap 6y agoThis is a good extension but here is a cool hack I've discovered that let's you do this anywhere without any chrome extensions: - Create a new whatsgroupp called 'ping self' and add your friend to it. - Then kick your friend out from this group - Open web.whatsapp.com and now you can access your messages, files, photos across any device anywhere, anytime! (telegram also does this and allows file up to 1gb)
- djannzjkzxn 6y agoFor the more limited use case of “get a link from a desktop to my phone right now” I have really enjoyed using an extension on the desktop browser that pops up a QR code linking to the current tab. Then I just point my phone camera at the QR code on the monitor to open the link on my phone. I like this setup because it doesn’t require any pre-configuration to link the desktop and the phone. Your friend sitting next to you can scan the QR code too. I’m not linking to any specific QR code extension because I haven’t audited them for privacy but it’s easy to find one that claims to generate the QR code locally.
- majewsky 6y agoI use wl-paste | qrencode -s 20 -o - | display - for this purpose. Shows the contents of the current Wayland clipboard as a QR code. For X11, replace `wl-paste` with `xsel -b`.
- jmiserez 6y agoOooh nice. Better yet, you can show that QR code directly in the terminal: qrencode -t ansiutf8 google.com Looks identical. In WSL, you can use 'powershell.exe Get-Clipboard': powershell.exe Get-Clipboard | qrencode -t ansiutf8
- Shounak 6y agoI use Slack for this, using a chat window with myself.
- jeromegv 6y ago
- popup21 6y agoChrome extension developers should start hosting them on Github. I use a flavor of Chrome called Ungoogled Chrome (https://ungoogled-software.github.io/ https://ungoogled-software.github.io/) and the only way to install plugins is to manually install the CRX file.
- GuB-42 6y agoIt is a common theme with Google, what they do makes sense, but communication is impossible. I don't know if it is an artifact of overusing machine learning "our neural network trained on a variety of malware gives your app a score of 4.3, you have 15 days to get it down to 4.0". How is that calculated? No one knows, maybe you shouldn't use the location permission if your icon is red and your domain is not in .org, or something like that. Or maybe it is a form of security by obscurity. Or maybe they just don't want to pay for people to support you. Who knows?
- shadowgovt 6y agoIt's that last one. Chrome Extensions, as a whole, are a value-add to Chrome. Individual Chrome extensions have negligible added value. As long as Chrome isn't killing extensions "everyone cares about," their system can bias pretty far towards making it had to get an extension accepted and maintained in the store without killing the whole ecosystem.
- Florin_Andrei 6y ago> It is a common theme with Google, what they do makes sense, but communication is impossible. You could say the same about some machine learning algorithms.
- danpalmer 6y agoAs much as we can criticise Google's handling of this situation, the fact that the developer was able to reduce permissions from accessing data on _all websites_ down to _their website_, as well as tighten up a few other permissions, shows that Google is correct that the extension is asking for more than it needs. I hope the developer finds another load of permissions they can tighten up, resubmits, and is approved. As long as it results in permissions being more correct this is a very positive thing for users because for every PushBullet there's hundreds of attempts at malicious Chrome extensions that are abusing permissions.
- Guzba 6y agoI really did try to call out the benefits that happened when I was told to "give permissions another look". Like all software, needs change and I was able to make a great improvement. The issue I have is that it's not clear if I'm even addressing the correct issue(s). If I don't make the Correct change, all other changes are irrelevant since they'll never get published.
- danpalmer 6y agoYeah, it's crap that they didn't give you guidance, although it seems like you managed to find plenty of issues quickly so perhaps the guidance is less necessary than it might seem. Ultimately you know your extension, codebase, and use-case, far better than Google does, so it may not really be possible for them to give you the detail that you're looking for – you may be the only person who can do that. I hope that they provide the support you need in understanding the problem to the point where the extension can continue to live on the Chrome store.
- duxup 6y agoPermissions seem to be a pretty empty metric if you don't' know what the result is... What was the impact of fewer permissions? Let's assume PushBullet was doing something bad with some of those permissions and gathering data? Do they no longer have access to that data? I'm not sure that's the case, permissions alone don't determine that. If PushBullet wasn't doing anything bad, did anything change? Is it a positive thing for users when the extension disappears in a few days?
- narrator 6y agoI can't wait till Google starts running contract tracing.
- majewsky 6y agoGood news! They won't. They're only providing an API to give everyone who needs to run contact tracing access to the Bluetooth Beacon system. EDIT: /me wonders what "contract tracing" is going to be
- Animats 6y agoIt's inherent in what Pushbullet is doing that Google would not like it. It aggregates user data from multiple sources, including SMS, notifications, and chat, sends it to the Pushbullet servers, and sends it back out again. Only Google is allowed to aggregate data like that. Fuhrer command! Suffer us to obey!
- FriendlyNormie 6y agoMeanwhile the Honey extension is fearlessly purchased for 4 billion dollars. Something smells like shit here.
- ChrisMarshallNY 6y agoI am the proud recipient of many Apple rejection notices from the App Store (I have been releasing iOS apps since 2012). I have not had an app pulled, but I have had many rejections to submitted apps (the latest were received yesterday). In all of the notices, Apple is usually quite explicit in what the problem is, including attaching screengrabs, and they will respond, if I ask them for further clarification.
- victorvation 6y agoI've seen cases where Apple will actually decompile/debug your app and point you the exact feature / method / line that they find unacceptable. Despite all of my other complaints about iOS ecosystem, they _do_ keep their App Store walled garden fairly well tended.
- hutzlibu 6y agoOut of curiosity, where those big name apps, or small ones? I assume that level of service is reserved or more important apps?
- victorvation 6y agoNot a tiny app by any means, but we were definitely small enough that we were surprised at the level of depth in their analysis.
- ChrisMarshallNY 6y agoSmall ones. Most are free. Over the years, I've had over twenty apps in the store, but most are retired. I'm down to seven: https://littlegreenviper.com/AppDocs/ https://littlegreenviper.com/AppDocs/
- ashtonkem 6y agoI had Apple point out that I hadn’t yet added a TOS for a trivia app I was making; they’re very thorough.
- dapids 6y agoThe fact that this team realized so simply that they shouldn't be reading data on every site the user visits while the extension is installed is deserving of a vague response from google. Sad really.
- devit 6y agoThe fact that they were requesting https://*/* https://*/* and http://*/* http://*/* (i.e. full control over all your accounts) without it being absolutely necessary reflects terribly on them. Still not clear why localhost (which can mean root access to the local machine since it may have localhost-only services that enable that) and cookies access is needed, also http://*.pushbullet.com http://*.pushbullet.com is unnecessary since they should always use HTTPS. If they had properly implemented the extension they may not have this problem now.
- gowld 6y agoWhy doesn't Google notify all extension devs about these issues, to get it fixed, instead of sending vague threats?
- KCUOJJQJ 6y agoDoes Google send this message to random developers ([1]) and then look at the changes that developers make to get a list of things that developers apparently think are not so good? [1] https://en.wikipedia.org/wiki/Thirty-Six_Stratagems#Stomp_the_grass_to_scare_the_snake https://en.wikipedia.org/wiki/Thirty-Six_Stratagems#Stomp_th...
- jeromegv 6y agoNobody is against enforcing better behaviors from developers, the issue is that they are not telling anyone what those issues are. I don't know why you can always count on someone to defend a multi-billion corporation against small companies, is there no empathy left?
- jholman 6y ago> I don't know why you can always count on someone to defend a multi-billion corporation against small companies, is there no empathy left? I don't have empathy for companies, I (try to) have empathy for people. Small companies are made up of people. Large companies are made up of people. I try (and often fail, alas) to have empathy for the people in both cases.
- aendruk 6y agoWe had a similar interaction with the Chrome Web Store out of the blue. After a few maddening rounds of requests for clarification and nonsensical canned responses, I finally just gave up and accused them of gaslighting me. Our extension was restored the next day, of course with no explanation for the ordeal.
- throwawayext 6y agoDifferent extension developer here. The Chrome Extension store ecosystem has become a nightmare for developers over the past year. Some items: - Extension review times have gone from 1 hour to a variable amount of time ranging from 1 minute to 3 weeks or longer (try to plan a release or spot fix an issue when you have no idea how long it will take for a deploy to reach users) - User reviews of extensions have been disabled (how are you supposed to build an audience or build up trust without reviews?) - Manifest v3 was announced (this was actually longer than a year ago) which will completely break many types of extensions. Over a year later, it is still on the horizon but the beta releases of it are buggy so it is hard to even try to adapt to it at this point. - Persistent extension related bugs in Chrome are not being fixed and new regressions are being introduced breaking previously working extensions (which you then need to rush out a fix for but good luck with that when the reviewers may take weeks to approve the update) - Chrome is exploring hiding extensions by default so they no longer will show up automatically by the omnibar when you install them (say hello to a huge amount of confused users who don't know where your extension went) I understand the Chrome team is trying to address a user trust and fraud issue with extensions and we are grateful for that. However, the Google extension team appears to be massively understaffed and are having huge issues managing and evolving the ecosystem.
- xg15 6y ago> Chrome is exploring hiding extensions by default so they no longer will show up automatically by the omnibar when you install them (say hello to a huge amount of confused users who don't know where your extension went) Haven't heard about this change (more info at [1] for anyone interested) - wow! I really wonder if those are the first steps of the roadmap to get rid of extensions altogether. [1] https://www.theregister.co.uk/2020/04/07/chrome_hiding_extensions/ https://www.theregister.co.uk/2020/04/07/chrome_hiding_exten...
- t0mas88 6y agoChrome on Android already doesn't have extensions. That made me switch to Firefox on Android and within a week my laptop was also on Firefox because it's nice to have tab syncing etc between devices. If enough users do this I think Google will review their policy on extensions and specifically adblockers. Can't browse without one anymore after having used it for a while.
- seanwilson 6y agoFor people focusing their comments on this particular extension + the permissions it asks for, please take a quick look at the numerous recent posts in the official forum for Chrome extension developers to see it's not an isolated issue: https://groups.google.com/a/chromium.org/forum/#!forum/chromium-extensions https://groups.google.com/a/chromium.org/forum/#!forum/chrom... It's a systematic issue that isn't specific to anything Pushbullet is doing and it's been like this before the pandemic: - Reviews can take up to 3 weeks. This in alone would be crazy enough if you have an urgent bug to fix. - Rejection emails are vague and don't tell you what to fix. - After you guess at what to fix, you've then got to join the up to 3 weeks review queue again. - If you try too many times, your extension gets pulled. - On top of this, they've recently disabled new Chrome Web Store paid items, and user reviews. Can anyone from Google escalate this and help extension developers? I can't speak for everyone but there's lots of complaints in the forum and little action beyond "we hear you and are looking to improve things".
- dilandau 6y ago>We hear you and are eagerly looking to improve things. Joking aside, isn't this just what people should come to expect from the company that has always tried to normalize the "no support and no service" model? If these antics start causing GOOG to lose share in the browser market then they may review these policies, but I highly doubt it. At the end of the day GOOG is an ad company and publicly-traded at that. They have a bottom-line and a lot of shareholders watching it. Support channels/forums are probably not the way to go, in other words. Stop using their browser, stop using their search. That's probably the only way they will be incentivized to change.
- core-questions 6y ago> Stop using their browser, stop using their search. The more people that do this in general, the better. We've given Google entirely too much power to control what people see and read (and it follows, control over what they say and think). They don't have our best interests at heart, they have financial interests at heart, and everything else flows from there. I'm not saying this is evil, but it's certainly not _good_.
- brazzy 6y ago> clipboardRead I bet that this is it. Clipboard data is extremely sensitive, as it can often contain passwords.
- thorum 6y agoDoes your browser extension really need to access localhost/* - as in, port 80 on my local machine? That would make me very uncomfortable about installing the extension. Would it be possible to restrict the extension to accessing a specific port or endpoint that is used by PushBullet?
- raegis 6y agoRight, this suggests the app either (1) runs a web server on the client device, or (2) wants to access a third party webserver on the client device. I don't know if this is common. Or maybe I don't know/understand why this is needed. Also, isn't allowing access to the app's website the same as allowing access to any website? Can't you just redirect?
- shadowgovt 6y agoRedirects shouldn't compromise the CORS / XSRF security model, which is the key item of concern from a Chrome Extension standpoint. Like if pushbullet.com redirects to foo.com, the crex is now looking at the foo.com page and its permissions will apply accordingly.
- lostinroutine 6y agoMaybe I'm naive but what if pushbullet.com was just running a server-side fetch and returning the result? That would bypass CORS, essentially acting as a proxy server.
- wolfgang42 6y agoPushbullet doesn’t need a Chrome extension to tell their server to make a web request. But, their server doesn’t have your cookies, so there’s no security concern.
- shadowgovt 6y agoThat's a great question, and it's not limited to Chrome extensions. In general, for any resources that don't require credentials to access, pushbullet could hypothetically serve them at like pushbullet.com/proxy/gmail.com/favicon or something. But resources requiring credentials are another thing entirely. In general, the thing that prevents a third-party server from MITM'ing your interactions with a target server is a combination of domain names and SSL certificate. That doesn't prevent a site from trying to get you to let it act as a MITM, but it prevents the site from acting as the MITM while claiming it's something else. As a concrete example, let's imagine pushbullet.com wanted to act as MITM for your GMail account. If it has your username and password, then (handwaving here; GMail's authentication model is complex) it could do that; it could forge well-crafted requests that look like they come from your browser, and get proper responses back. But if it doesn't have your username and password, there's not a lot it can do. Your browser won't give pushbullet.com cookies scoped to gmail.com, and if pushbullet tries to ask you for your password, they can only do so much to make it look like GMail's the one asking (SSL certs make it hard for pushbullet to try and forge a GMail front-page with a gmail.com domain). It can still happen, but "user was tricked into ignoring the domain name and gave their password to another service" isn't something web security models can fix.
- cirwin 6y agoWe went through the same problem at Superhuman (and as I write our latest extension update has been pending review for 2 weeks, so maybe we're about to hit it again). Simeon on the mailing list was quite re-assuring, and I would recommend reaching out to him, though there are limits to what he can help with. That said we found that the review process is quite arbitrary, resubmitting may work simply because you get a different reviewer. (We've seen identical copies of the extension with different version numbers where one was approved and one rejected). We've also observed that they use some kind of automated code-analysis to tell whether or not you're making use of the permission; so you may want to check that it's obvious from the code included in the extension bundle that you need the permissions you're asking for. We've also hypothesized that they apply different standards to extensions depending on the number of users – our staging extension (~50 users) usually gets approved quickly, but our production extension usually takes a while and is less likely to be approved. (This may just be luck of the draw coupled with arbitrariness though)
- sevencolors 6y agoDamn that sounds like crazymaking :( Dunno why they can't be more explicit which part of the code is the issue
- BFatts 6y agoIt says, in the email provided, exactly what must be done: Change the required permissions - your scope is too broad.
- yawniek 6y agoi guess removing plaintext http and localhost should fix this.
- Guzba 6y agoWe never use plaintext http so that is a reasonable thing to remove for our first-part domain (pushbullet.com). We use localhost to communicate with our desktop application. An example is preventing both our extension and desktop apps from showing notifications on the same computer (our apps are all about notifications so this would get unacceptable very fast). Maybe if we limit it to just the local port we use? Seems like it can't hurt to try that too.
- frei 6y agoYou could try that. Long term, it should also be possible to route this communication through the internet, or use the Chrome/Firefox/WebExtension NativeMessaging API [0][1]. 0. https://developer.chrome.com/apps/nativeMessaging https://developer.chrome.com/apps/nativeMessaging. 1. https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Native_messaging https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
- OJFord 6y agoI stopped using pushbullet because I realised its access made me a bit uncomfortable, but had I had the 'So, can we cut any of these permissions?' paragraph to read at the time, that may have reassured me. Nice to see it not only being investigated (even if it took Google's vague threat to spur it on) but positively so; seen as 'A big win!'.
- komali2 6y ago> This may also result in the suspension of related Google services associated with your Google account. Get all your emails off gmail ASAP, pushbullet developers. It may be more than your extension that gets nuked.
- Shorel 6y agoNo Chrome, no Google search and no Gmail as default email here. Hopefully, many others will follow.
- chrischen 6y agoWe spend a quite a bit on Google Ads yet they seem to refuse devoting even a few minutes of a knowledgable support staff’s time to our account—even when we’re trying to figure out how to give them more money. For 1-2 years our product shopping ads never displayed and we couldn’t get anyone to tell us why. One day, it just started working by itself (perhaps some engineer pushed a fix). Contrast this with their sales strategy of aggressively making a human call me every quarter to try to up my budgets. I’m not sure why they are so against helping people succeed with their products... It’s like they are allergic to manual human processes (unless it’s sales).
- x86_64Ubuntu 6y agoI was using Google Ads for a pet project of mine. I lost the password to one account, and then decided to set up another. Using the same CC (which is also my personal CC) on both accounts triggered something and they killed my account. I explained what happened, and told them to check the first account access patterns as they had abruptly stopped due to the loss of the password. They didn't care in the least.
- PopeDotNinja 6y agoHave you tried telling the salesperson?
- chrischen 6y agoYes I in fact did. One of the only reasons I took the call. He said he would check internally. Nothing came of that. Technically they weren't sales but were doing a free account review (but purely focused on how to increase my spend).
- foobarbazetc 6y agolol. We have the same problem, but on the Google Play Store. We have an brand name app used by millions of people. We uploaded an update where the only change was a new Firebase library. Google rejected the update for vague reasons (“violation of Google Play policies” but not telling us which one). Appealing the rejection, the CSR just pasted the vague policy thing back at us. We asked for more information and they just closed the ticket. So we took the exact build that was accepted, incremented the version number, and uploaded that. Rejected again. And there’s no real human to talk to. No idea what’s going on at Google.
- Florin_Andrei 6y ago> No idea what’s going on at Google. It's like trying to troubleshoot a machine learning algorithm.
- PopeDotNinja 6y agoNow that you mention it, it does sound like an adversarial network!
- Florin_Andrei 6y agoNo, you're the adversarial network! /joke
- thelibrarian 6y agoIt is trying to troubleshoot a machine learning algorithm. Google is quite proud of the fact that most of their support is handled by machines.
- sudoit 6y agoHad the same problem when I made a fairly successful app in university. Whole account got deleted for a “3rd strike” meaning “3rd resubmission.” I’ve made a new account and their AI black box still doesn’t realize it’s me...
- 6y ago
- crazygringo 6y agoI understand that with many spam-related heuristics, a company like Google chooses not to share exactly why a site or e-mail server is blacklisted -- because an actual spammer can evade that metric and still get away with everything. But I don't believe that thinking applies whatsoever to apps or extensions. There are far fewer of them and parties need to work together. It's unfathomable to me why Google doesn't point out which specific permissions a reviewer has flagged as suspect, or given an option for the developer to give the justification specific to each option.
- nikolay 6y agoGoogle are cutting the branch they are sitting on. I only use Chrome because certain extensions are not available on Firefox. During all these years, they've become impossible to deal with. I open Chrome with 10 tabs and after a couple of hours it's using gigabytes of RAM. From a thin client, it became the thickest client in the visible universe. It's time to consider options... not that there are many.
- yellowapple 6y ago> I only use Chrome because certain extensions are not available on Firefox. Which extensions? Especially now that Firefox has moved to WebExtensions, it should (in theory at least) be straightforward for someone to port them over. Like, if anything it's usually the other way around (Chrome not supporting extensions that Firefox supports).
- shklnrj 6y agoI just started using Brave and most extensions are available. Pretty good from privacy point of view as well. Check it out.
- nikolay 6y agoStill the same memory hog under the hood. I mean, how can a browser use 10+ GB of memory unless they are a doing a million things wrong?
- softwarejosh 6y agoeven mozilla is terrible in this regard, its a losers game.
- 51Cards 6y agoLONG term Pushbullet user here, big proponent of their services. I use it on Firefox myself so this doesn't affect me personally but still there are few services I will strongly advocate for. Pushbullet is one of them. Google, if you're listening this is going to make a lot of users very unhappy.
- Wowfunhappy 6y ago> The other opportunity is the tabs permission. This permission lets extensions see what tabs are open. Pushbullet uses this permission to avoid opening new tabs for websites that are already open when mirrored notifications are clicked. This is a small sacrifice to make to let go of a big permission. Let’s let it go! No, that "small sacrifice" sounds super annoying! I don't use Pushbullet, but if I did and this got removed in an update, I'd be pissed off! At least leave it behind an optional checkbox.
- Guzba 6y agoThanks for the feedback here. It strikes me as a little crazy I may be infuriating you with a change and never even know if that was something I had to do? An optional permission seems 100% reasonable.
- Wowfunhappy 6y ago> It strikes me as a little crazy I may be infuriating you with a change and never even know if that was something I had to do? Oh, for sure! Just to be clear, I didn't intend my comment as a criticism. It's nuts that you, as the developer, actually went so far as to remove features in your first pass, and Google still rejected that attempt without additional instruction.
- pgrote 6y agoIs there a replacement for pushbullet? Long time user of pushbullet since I like to be able to text from the desktop. Google has released messages.google.com, which is a nightmare to use among various desktops. Microsoft released their Phone app, which disconnects so frequently it is unusable. I have no confidence Google will allow pushbullet back. Is there a replacement that allows notifications and texts from the desktop?
- jlevers 6y agoThis happened to me, too. After emailing customer support several times asking for clarification, and getting the same uninformative answer every time, I decided to take down the (free) extension (which had 20,000+ users) rather than risk having my developer account deactivated for uploading a rejected extension too many times. I use Pushbullet every day, and would be gutted if it were killed for such a ridiculous reason as this.
- calmchaos 6y agoThose rejection emails are most likely sent by an AI. If you reply back and ask them to specify exactly what is wrong, you'll get the same generic email back. Ask again, and they'll send the same generic response without any details or comments written by a human. They simply can't specify the problem at all. That's how you know you are talking with an AI, not a human. The correct way to respond to those rejection emails is to ask for a "human being" (this is the keyword that works) to review the case. Also explain in the email why there isn't anything more you can do (if you have done every possible fix already). As a side note, when AI systems get more common, this will be a common nightmare for regular people. When an AI makes an incorrect decision regarding you, no-one can check the code why it happened because the code doesn't exist. All we may have are some weighted matrices and neural network data as bunch of numbers.
- necovek 6y agoI am pretty confident there is no AI involved, but just a regular deterministic code analysis tool that flags potential discrepancies between code and demanded permissions. We usually simply call those bots (there can be AI bots too, but there seems to be no indication that this is one).
- solidasparagus 6y ago> when AI systems get more common, this will be a common nightmare for regular people I'm not sure. We've had automated phone customer service systems forever, but companies that in any way care about their customers still let you escalate to a human.
- couchand 6y ago... and those phone systems are a common nightmare for regular people.
- PopeDotNinja 6y agoThat's like when I keep saying "pharmacist" when I call Walgreens to get a prescription filled.
- 6y ago
- imhoguy 6y ago2020 and our browser privacy handling is like MS-DOS. Why the hell I can't disable all extensions when I enter my bank account or insurance page? As far as I know Firefox containers are close but still no fine grained control over extensions.
- AlphaWeaver 6y agoI'm also an extension developer, and Google has done this to me a few times too. We request permissions specifically for what we need, and our extension is unlisted and can only be installed from our website. Google is a bully, and they use their size and the threat of permanently removing access to your Google Account (and family photos) to terrorize small players without cause. How many people would Google need to hire to provide email support for extension review for extensions above a certain size? It can't be a huge dent in their budget.
- blihp 6y agoNot going to happen. This is an issue people have been raising for at least the better part of a decade... don't expect anything to change now. A more productive approach would be to focus on web browsers that allow you to do what you need to and let Google fix what they need to encourage you back. I know, most extension developers will say 'we can't do that because it's where the users/customers/whoever are'. But as long as you encourage their bad behavior by supporting the platform, expect the bad behavior to continue since it's not hurting Google. As a result, it's just a cost of doing business on Google's platform which is unlike to change for the better.
- AlphaWeaver 6y agoAre you making a good faith suggestion that it's possible to build a business around a browser extension and not support Google Chrome? They have something like 70% market share dude...
- qznc 6y agoI believe the suggestion is to incorporate this "bully risk" in your business plan. Some business models might not be profitable anymore if you do this. Others just need additional diversification or more risk capital.
- hedora 6y agoChrome’s market share would drop if extension authors moved to an alternative. As it is, it sounds like Google’s doing this itself by breaking popular extensions.
- FpUser 6y agoAside of youtube and search I am not using Google at all. And Chrome is on my computer only for testing.
- poopyKnoopers 6y agoNah, dude. Fuck that localhost access. Sorry, but I wouldn't install something that's running listeners on localhost:80 (or any other port) just because they want to route data from a browser extension to an installed program. That's a pretty bootleg hack, to be quite honest. Would you dare touch my /etc/hosts mappings too? Guess again, Mark Shuttleworth! You wouldn't ever even get installed in the first place. You DON'T have root. Not anymore. [0] Google is correct to reject you. Localhost belongs to the individual. [0] http://security.stackexchange.com/questions/44512 http://security.stackexchange.com/questions/44512
- mgeyer 6y agoWait can some one please simply explain to me whats gong on here? I'm new to this but I absolutely love it! and I paid for it too. Why do all good things have to be taken away?
- wegs 6y agoI just want to mention this is why I believe Google will never be able to compete with AWS, or otherwise be credible in the B2B space. You're relying on automated systems which can take down your business on a whim, with no recourse. Where I work uses Office 365, which is a horrible, horrible technology compared to Google Suite, but I can't, in good faith, argue for switching to Google. It's not a company I'd ever rely on in a business setting.
- rossjudson 6y agoInvoiced billing is available for businesses. https://cloud.google.com/billing/docs/how-to/invoiced-billing https://cloud.google.com/billing/docs/how-to/invoiced-billin...
- Baeocystin 6y agoI had a terrible, deep-history bug cause problems with one of my Office 365-using clients about six months ago. It was a genuine PITA to troubleshoot. Once we figured out the source of the problem, I was on the phone with someone from Microsoft who knew exactly what I was talking about, and the available workarounds, within the hour. My clients continue to use Office 365.
- tonystubblebine 6y agoI'd been in a similar issue on the Android store and found that the best solution was to try to game whatever bot is flagging you. Support was completely unable to provide clarity and getting escalated by internal Google employees just led to more unhelpful emails from higher levels of support. I was positive that I was in compliance but I could also see that a bot was flagging something. So I kept tweaking code and resubmitting. Eventually what worked was taking the offending code block and hiding it at the server level. It's such a face palm. I literally call out to the server to run some logic that should be completely safe to run in the app.
- ridewinter 6y agoAs the developer of an exposure notification app put on ice by Apple-Google, it's due time to take back the freedom of the internet that made it so powerful in the beginning. Is there anything happening around an all-web app phone? Seems like all the pieces are there..like native functionality in JavaScript with certain extensions.
- gnicholas 6y agoConsider yourself lucky that your extension wasn’t pulled after 1 day. I received a 7-day notice on a Sunday and complied same-day. My extension was pulled the next day, and I received an email stating that 7 days had elapsed. I managed to get reinstated because I know people on Chrome’s accessibility team who promote my extension, but even with that assistance it was still months before I could push a new version without going into purgatory. FWIW, I’ve had even more issues on Firefox. It’s like they’re in a competition with the App Store for “most opaque review process”.
- therealmarv 6y agoRobots are in control here, follow their rules and get your accounts permanently deleted if you don't understand the robots rules and mindset...
- ajhurliman 6y agoI had a friend who went through a similar, onerous process with Google which ended up killing his entire chrome extension (which had 400,000+ MAU). This iron-fisted control of the extension marketplace is not becoming to Google.
- maartn 6y agoI think that reading all of a users' cookies from all websites is pretty privacy invading...
- qwertox 6y agoTrue, that was the way before they removed the "http(s):///" permission. That is a tremendous permission to ask for and would be a huge red flag in any case. Now they limited it to ".pushbullet.com", but even then they don't need that permission since ".pushbullet.com" is a server controlled by them, so they are free to set and read those cookies anyway. The cookies permission is only needed if you want to read cookies from a domain you don't own. The extension has no need to modify the cookies, and if Pushbullet wants to set or change them, for example to set session cookies, it can do so in a non-extension tab. The extension can then send those cookies in their API request automatically without needing to access them.
- fourzs 6y agoWhen I was sixteen years I received the exact same email from Google, and was then permanently banned from the chrome web store.
- Kikawala 6y agoI've been using Pushbullet in FF and on my iOS devices for years, but need to find a replacement as the app was removed[1] from the App Store. [1]https://www.reddit.com/r/PushBullet/comments/eirc1m/not_available_on_ios/ https://www.reddit.com/r/PushBullet/comments/eirc1m/not_avai...
- moxylush 6y agoYou are the victim of an algorithm. No people and no accountability, thats how they roll.
- extesy 6y agoI'm in the same boat. My open source chrome extension[1] has just been taken down[2] after several years of no complaints because it apparently violated content policies related to nudity and pornography. Say what? Well, I guess you could view _any_ image using my extension, including nudes. Isn't that the problem with most other extensions which could be used on porn sites, like editing cookies, etc? I've submitted it for re-review but I'm not holding much hopes. [1] https://github.com/extesy/hoverzoom https://github.com/extesy/hoverzoom [2] https://github.com/extesy/hoverzoom/issues/512 https://github.com/extesy/hoverzoom/issues/512
- __s 6y agoOnly perverts use binoculars
- yellowapple 6y agoI mentioned this in the GitHub issue thread (howdy!), but I strongly suspect it has to do with specific references to pornographic sites in the extension's manifest. If only Google would mind its own business instead of playing mommy-knows-best and dictating its morality on grown adults.
- teruakohatu 6y agoIt is also a fork of an extension that contained malware, so an automated code review tool trained on malware might be catching it.
- ehsankia 6y agoI was actually gonna ask, isn't hoverzoom a malware? But I guess this is a fork of it. I've since switched to Imagus but I do miss HoverZoom.
- yellowapple 6y agoThat's a possibility, too, but the email specifically mentioned pornographic content or extensions that might "drive traffic" to pornographic sites so that seemed like the more likely reason.
- mehrdadn 6y agoMy guess is 'cookies'. You really shouldn't need access to (say) the user's Google cookies. I don't expect Google likes extensions doing that without good reason.
- bvandewalle 6y agoIf you are an engineer those type of stories should make you rethink your usage of Google Chrome. Chrome having so many users empower them to implement those type of nonsensical policies. As said in other comments it is trivially easy to switch to Firefox (or any other browser you feel that fits your needs better).
- Medicalidiot 6y agoI left Android for iOS because of this type of behavior. Google is fickle with what it's policies and goals are.
- Arcsech 6y agoThis kind of thing just keeps. Coming. Up. from Google and between ML black boxes making arbitrary judgements and random product shutdowns, a hard requirement for any personal projects of mine is "no Google dependency", because it might vanish at any time, with zero notice or recourse.
- ernsheong 6y agoFar from arbitrary, Pushbullet is just wielding far too many permissions.
- consultSKI 6y agoIs that why universal cut & paste has been flakey? I am dropping all Google stuff. They recently killed my Alexa Skill on Android (Samsung S9). With everything google deleted or permissions denied on my phone, they still hijack the word "contact." Try saying, "Alexa launch Contact Ski Man." Still works with Alexa on iPhone, but how do you use a smartphone without back button? We have reached the point where it is time to throw the baby out with the dirty water. Say, "Hey FireFox!"
- saltedonion 6y agoI too have deGoogled as much as I can, but I’m hesitant to jump on the hate wagon for this one. Consider the counter factual - what if google was highly specific about the changes required? Clarifing the boundaries of what’s allow is prone to abuse. This is the same reason why the search algorithms are not explicitly published, but only the spirit is explained. I would say this is the best solution when there are no perfect solutions. Perhaps the 14 day period could be longer, but that’s another point of contention.
- elwell 6y agoI've had a Chrome extension removed from the store before, I suspect because it conflicted with Google's business model. I would be very wary of building a business on a foundation that another company controls.
- gregsadetsky 6y agoI went through the same hell a year ago [0]. My extension [1] now has 60k users (covid added 10k users in 1 month) and I'm also afraid that any insignificant update would trigger this hell. I'll contact PushBullet with a possible way forward (PB, if you're reading this -- contact me). Anyone else in this situation: my email is in my profile. [0] https://news.ycombinator.com/item?id=20186915 https://news.ycombinator.com/item?id=20186915 [1] https://chrome.google.com/webstore/detail/dictation-for-gmail/eggdmhdpffgikgakkfojgiledkekfdce?hl=en-US https://chrome.google.com/webstore/detail/dictation-for-gmai...
- binaryfour 6y agoThis literally just happened to me today...
- mtnGoat 6y agoI know Google employees that have had their accounts on various Google Services shutdown and they couldn't even get them back themselves. The place is very siloed, something needs to give because these nightmare scenarios keep happening over and over.
- janee 6y agoIronic reading this today. Got locked out of an old gsuite we manage for someone on Monday because I typed the recovery mail wrong 3 times...omg what a crazy battle to follow their recovery process. Sent them sooo much proof, answers, cname changes, invoices, emails, etc etc, but still get the same canned response back. The weird thing is I never got a single notification on the recovery mail that unauthorized access was attempted and that the account got locked. Honestly I feel like such a dumb ass for making our company use gsuite now. I don't think I'll ever recommend a google product to anyone again.
- sebastianconcpt 6y agoWe at Pushbullet have received some bad news from Google. It appears our extension will be removed from the Chrome Web Store if we don’t make required changes within 14 days. Not good! The bigger problem? Google hasn’t told us what those required changes are. The Pushbullet Chrome extension has been on the Chrome Web store for over 6 years, currently has over 1,000,000 users, and has a 4.5 star average rating.
- madrox 6y agoStuff like this makes me wonder why Chrome's security model allows things if it can be scanned and deemed unsafe. Isn't it preferable to bake such restrictions into the extension API if Google didn't want PushBullet to go beyond it? Why does this need to be enforced by an app store?
- ggm 6y agoDon't they call this a "marketplace"? If so,the Regulator is the FTC not the FCC. If they walk like a duck and call it a duck then talk to the duck hunting authority?
- geza 6y agoI got the same notification yesterday morning for my own open-source extension HabitLab ( https://habitlab.stanford.edu/ https://habitlab.stanford.edu/ ) - same vague request for "you're not using the minimal set of permissions" without mentioning what permissions they want me to stop using (HabitLab is already using the minimal set of permissions for the features it implements - any removal of permissions would have to be done at the expense of reduced functionality). Emailing just results in them sending me a link to the policy. So this is definitely not an isolated case.
- brigandish 6y agoHave you considered writing a short blog post (even a tweet) about it and submitting it to HN? Momentum is a good thing.
- dathinab 6y agoI'm always surprised that such a in-transparent behavior is even legal for the operator of a custom marked place (or whatever you call it). (I think the same about Google Play, the iOs App Store etc.)
- throw1234651234 6y agoI just want to take this opportunity to complain about trying to send a gmail email from a service account, which required us to use G-Suite, and still doesn't work because it can't generate a token.
- ThePowerOfFuet 6y ago> Once you have made these changes you may submit and publish a new draft in the Chrome Web Store Developer Dashboard. > Your draft will then be reviewed for policy compliance. If the outcome of the review is successful, your existing store listing will get replaced by the approved draft. However, if the new draft fails to comply with our policies, both the draft and the existing store listing will be removed. Please note that the rectification window expires the moment a new draft is submitted. After this point, you will not be able to make iterative changes regardless of the days remaining in the warning period. Holy fuck, that's insane. You get one shot; if you miss, game over.
- inopinatus 6y agoCounterpoint: there is a team within Google that got it right at least once. We have live import/export integration with Google Sheets and this requires additional OAuth scopes. The request for justification they sent was polite, specific about the scopes of concern (and why), and with no hard deadline. Our response was handled politely and promptly. I realise the GCP API team may not be dealing with as big of a swamp as a consumer-facing apps group, but it was nevertheless one of those few occasions when Google left me with an impression other than overwhelming hubris. It was more like talking to AWS service teams, or Cisco TAC when you have a CCIE on staff.
- duncan_bayne 6y agoFrom a comment by Baeocystin: "If you use our tools, we can kill your livelihood at any time for any reason and tough shit if you want a why" It has always been thus with proprietary tools and platforms. Back in 2011 I switched careers from developing software on proprietary stacks - at the time C# 4.0, Silverlight, and MS Windows - to developing on open source stacks, starting with Ruby on Rails and JavaScript. A short time after I switched away from Silverlight, I found a bug in the open source XML library my team was using. I then submitted a PR to fix it, which was merged (with some revision :)) after a few days. The experience was a revelation after the combination of magic 8 ball and years-long wait times for non-critical bug fixes on Visual Studio. It looks like the younger generation is busy rediscovering the vulnerability and helplessness of proprietary systems themselves.
- typenil 6y agoAnother reason to use Firefox.
- geofft 6y agoUh, yikes: > As I looked at the permissions and what our extension actually needs to operate, I noticed a great opportunity to reduce our permissions requests. We do not need to request access to data on https://*/* https://*/* and http://*/* http://*/*. Instead, we can simply request data access for https://*.pushbullet.com/* https://*.pushbullet.com/*, http://*.pushbullet.com/* http://*.pushbullet.com/*, and http://localhost/* http://localhost/*. This is a huge reduction in the private data our extension could theoretically access. A big win! While I agree with the larger part about the lack of transparency of what they want you to fix, this is an amazingly huge oversight, and the fact that the extension review process got an established, popular extension to go "Wait, we don't actually need to request access to every website ever" is a point in favor of the review process - and, unfortunately, a (weak) argument in favor of the review process taking the attitude that they get lots of crap and don't have the time to explain to all the authors of crap what they're doing wrong. How did the extension ever ask for this in the first place? Also why do you need http://localhost/ http://localhost/? Is the extension running a web server on localhost with native code? If so, can you use the specific mechanism/permission for communicating with native code via a subprocess (because it turns out communicating with a web server on localhost is very hard to do securely)? If not, what's it for? I'm sympathetic to the broader argument here, but given the provided information, all of this is consistent with an extension that should be kicked off the app store within 14 days. (Among other things, if you have an approved extension with https://*/* https://*/* permissions and active users, malware authors will offer to buy your extension for a very high price. So it's definitely in the public interest to make sure there are as few of those as possible and that they're only in the hands of people who have the ability to understand why the friendly person offering them way too much money for their extension isn't just being nice.)
- deleted 6y ago[deleted]
- friedman23 6y ago>Uh, yikes Agreed I wish we could send everyone that thinks this kind of response from a megacorporation is good to a kafkaesque alternate universe.
- davesque 6y agoIt seems like everyone in here suggesting a switch to Firefox is missing the point. The Pushbullet team has already stated that having this Chrome extension pulled might mean the end of Pushbullet. So I'm going to trust that they know their own business well enough to make that statement. I actually already use Firefox and their Firefox extension. But it won't matter that I'm savvy enough to do this if losing enough users from having the Chrome extension killed is enough to kill the larger business.
- aeyes 6y agoIf Google doesn't want extensions to have a certain permission, why don't they just kill it globally in Chrome? And if some apps can have permission X but others can't, there should be clear guidelines.
- metreo 6y agoThe hypocrisy is tangible and bitter sweet.
- Cymen 6y agoI went through this on a side project and just let them kill off my public listing for now. I had the same thought process in terms of what I could change however my extension made use of InboxSDK and had access to GMail and I'm still concerned it might not make it through review... Anyone else using InboxSDK in a Chrome extension and didn't get killed off by this change? My extension hooks up the address book from a SaaS project (school information system) to GMail so faculty/staff can quickly look up parent contact information or send to special group email addresses that broadcast out to part or all of the school. The people using it were very happy to have it but I could conceivably go back to a private chrome extension if that is still allowed.
- metreo 6y agoAhh the hypocrisy
- saadalem 6y agoA little bit meta here but these words are true even today : Suddenly, 20% meant half-assed. Google Labs was shut down. App Engine fees were raised. APIs that had been free for years were deprecated or provided for a fee. As the trappings of entrepreneurship were dismantled, derisive talk of the “old Google” and its feeble attempts at competing with Facebook surfaced to justify a “new Google” that promised “more wood behind fewer arrows.” …The old Google made a fortune on ads because they had good content. It was like TV used to be: make the best show and you get the most ad revenue from commercials. The new Google seems more focused on the commercials themselves. — James Whittaker, Why I left Google
- grayfaced 6y agoI wonder if they got caught up in google removing "creepware" recently and notification mirroring might count. "CreepRank algorithm can identify apps with features that can be abused to extract SMS messages from a device, spoof another user's identity in IM/SMS chats." https://www.zdnet.com/article/google-removed-813-creepware-apps-from-the-android-play-store/ https://www.zdnet.com/article/google-removed-813-creepware-a...
- nojito 6y agoGood. It’s clear that pushbullet has never put thought into what permissions it needs and just asked for everything
- djyaz1200 6y agoCan anyone at Google even pretend they aren't evil any more?
- kinkrtyavimoodh 6y agoSo Google is evil for asking that an extension not request permissions it doesn't need to use? If this were Apple we would be celebrating how privacy-forward they were.
- stevage 6y agoWhy does it require http?
- eating555 6y agoSame thing happens on Google Play Store. They ask us to comply the privacy policy without giving us any guideeline :(
- wprapido 6y agoAvoiding Google and looking into the alternatives is what took a significant part of my working hours and spare time as of the last 2-3 years.
- dnissley 6y agoThis situation looks even worse considering Google runs a competing service (Android messages for web)
- jboydyhacker 6y agoI think folks are drastically missing the forest for the trees here. This is just one minor example of the INSANE process that is now the Chrome Approval Process. I've seen extensions go for many months getting random rejections with no reason given. This forces developers to GUESS as to what is wrong. Want to try and develop according to a roadmap or timeline- forget about it. There is no "app store" approval process that conducts itself in this way. Fact is Chrome is 80% of the market so Google doesn't worry about competition. If Google Chrome is broken- then the internet is broken. It harms new entrants trying to develop and innovation. After the 2nd or 3rd rejection- have a HUMAN intervene. Explain what is wrong. Devs are more than happy to make the changes. But you can't do this "make you guess" bullshit. DOJ and EU need to get involved. Someone at Google with their wits about them and revamp the whole process. It's a travesty against the developer community and should be fixed ASAP. Also from what I hear they need to start with new LEADERSHIP.
- pensatoio 6y agoI appreciate the correct use of travesty. (and I agree with all of your points.)
- unnouinceput 6y agoAfter 2nd to 3rd rejection if it will require a human to intervene Google will have to hire half the earthlings to deal with crappy spammers that will simply spam google store with their extensions. The answer is not human interaction, the answer is automation tool to give more details as what was detected and didn't pass.
- wtetzner 6y agoThe answer is probably to stop using Chrome.
- deleted 6y ago[deleted]
- unnouinceput 6y ago
- slaw 6y agoDon't work for free for Google. Don't write extensions for Chrome.
- squarepluto 6y agoThey don't give shit about your 4.5 star rating. Your 4.5 star rating doesn't mean you are the most private or most secure over there. Facebook got 4+ rating on all there apps with 1B+ users, that doesn't mean they need access to those call logs,messages and everything on your phone. Keep you permission to the minimum, for both security and privacy. Chrome team doesn't give shit about people like you.
- jboydyhacker 6y agoGoogle has 70% market share. If Chrome is broken- innovation nd the internet is broken. If we really want to fix this. 1. Use Survey Monkey to collect info from other developers having issues (which is like all of them). 2. Isolate instances of severe delays, inability to innovate, harm to business, negligence etc. 3. Send to DOJ and EU Antitrust
- ajayyy 6y agoI have made an extension and am getting the exact same complaint whenever I submit updates. Luckily, old versions are still up though. Link: https://chrome.google.com/webstore/detail/mnjggcdmjocbbbhaepdhchncahnbgone https://chrome.google.com/webstore/detail/mnjggcdmjocbbbhaep... It only has access to 2 domains, it doesn't have the tabs permission and it uses optional permissions for everything else. I think it is just an automated issue due to covid-19, and I guess I might just have to wait until then.
- cycomanic 6y agoI think the interpretation that Google does this because it does not want to compromise the review process to malicious extension authors is a very generous one. As others pointed out, a motivated enough entity could very well be probing the system using multiple submissions (sure it gets your account banned, just use several accounts). No what is really going on is that Google wants the ability to reject an app for any reason without actually having to give the reasons. To for example protect a business interest. The only reason for not making a transparent decision process is because you want to keep the ability to make decisions that don't follow the rules you set. To the people saying that we should keep rules secret so that malware authors can't work around the rules, I ask: the same argument applies to laws, but most people agree that we want transparency. So what makes this different in principle? (I understand that Google might not have an obligation, but you are saying that they do the right thing)
- TheKarateKid 6y agoExactly. It's also completely contradictory to Google's Project Zero, where they expose security flaws in great detail publicly with the intention to educate users and devs to fix the issue and prevent it from happening again. At the very least, Google should provide a way to contact an actual human - especially if the developer has 1M+ users.
- jchook 6y agoCritical to realize that Google gets all the permissions afforded to extensions and uses them for objectionable self-interest.
- highlysyntropic 6y agodon't create extensions. create browser controllers. you can release them as binaries. anyone can download them. They instrument chrome using the remote devtools API. an oss example here: https://github.com/dosyago/22120 https://github.com/dosyago/22120 and an idea I have for a browse controllers store here. https://github.com/dosyago/browsercontrollers.store https://github.com/dosyago/browsercontrollers.store
- 6y ago
- spajus 6y agoThis is also why I will never publish to Android Play Store. Experience is very similar, it constantly demands random changes.
- pdonis 6y agoIf Douglas Adams were still around, he'd put "Get actual assistance from a human at Google" on the list of "Recreational Impossibilities" in the Hitchhiker's Guide, right after "Get the Brantisvogan Civil Service to acknowledge a change of address card".
- tomaszs 6y agoUnfortunately this is a fancy new way of communication of tech corporations. Facebook, Apple, Google. Name one. Do please us sir. Three times you shall try. I would not consider any company that takes that approach as a reliable business partner. Maybe it will be possible to please the platform this time. But this is a strong hint the business should not depend on the Google extension platform. Escape it while you can
- kishansagathiya 6y agoThis dude has written crappy, inefficient code and is now complaining for it. If just permissions are so inefficiently written one can only imagine, what would be the state of rest of the codebase. Badly written apps can also generate traction. Users don't see the code quality. They rarely know the first thing about privacy and security. It's not Google's job to teach someone to how to write good code. Good compiler can tell you what is the error, it won't pop out a solution as well.
- ezoe 6y agoDon't relies on the Google to distribute the browser extension.
- crispyporkbites 6y agoA bit late to this thread but this is happening to my chrome extension right now. No idea why, I have 10,000+ users and the chrome support team just keeps emailing me the same statement with different items highlighted in bold, saying it doesn't work and the description isn't accruate. a) It does work b) The description is accurate I have no idea what they want me to do and I don't have time to try and guess. I don't get paid for my extension, so I'm just going to redirect everyone to the FireFox version now. The Chrome store will be poorer without it and that's on them.
- vldr 6y agoI love pushbullet and I'm happy it works fine on firefox. And that's at least partially the fix - install firefox, depend less on google chrome. Hopefully that will give a signal to google that make them cherish the developers that create great functionality for them a bit more.
- lihaciudaniel 6y agoI'm not a very big fan of Push Bullet, what utility to they make? become more distracted?
- rergaerg 6y agoFor one, I think this is good news. I work in a field that exposes me to a lot of dubious ways to collect peoples data. Especially what they are doing in their browser. You would not believe how many pieces of software you are using daily that do this. A lot of these are chrome extensions. If you are honest, then I do feel for your situation. But, I am also happy to see that Google are finally stepping this up and looking after their users by not exposing them to potentially malicious services.
- nojvek 6y agoGoogle really sucks at customer service. Like they either don’t get it or they’re so far up their arses that they think fancy AI algorithms will magically fix it. They are the most inhuman tech company I have dealt with out of the big 3 clouds. I have a similar experience. I am trying to get an oauth consent screen approved. It’s a simple thing. It takes up to a week for someone on their side to reply and it’s mostly one vague sentence. They don’t give a full list of what needs to be done. I’ve been at it for more than a month. It’s like they really don’t give a shit about how much time you’re sinking to make things work with their services. I have a love/hate relationship with Google. On one side they know how to keep things reliable like google search, on the other side they need to stop doing a 100 million things and do 10 things really well and maintain it for eternity. If someone eats Google’s Search lunch, they are done for.
- scoot_718 6y agoDoesn't matter. Chrome has become unusable anyway.
- henearkr 6y agoJust remove access to http://localhost http://localhost. This is a huge overreach in permissions, and honestly as a user I would feel violated by that. I have shitloads of things that I can lauch myself on localhost on custom ports, and no-thank-you I do not need to open them to some app.
- _rrnv 6y agoFunny, very funny. Not your keys, not your coins. Not your store, not your clients. Not your playground, not your rules. etc. etc. I sympathise, but discourage cooperating with Google.
- tobyhinloopen 6y agoWe tried to create an android app and we never were able to got it submitted. We never figured out why and just gave up. I’ll never again try to create a business around an environment outside our control. Both Google and Apple are complete black boxes.
- SparklingCotton 6y agoI'm in exactly the same situation. It's impossible to know what they are after and my extension has a fraction of the permissions that you have.
- tripzilch 6y agoThis is just completely disingenuous from Google. > - Request access to the narrowest permissions necessary to implement your product’s features or services. > - If more than one permission could be used to implement a feature, you must request those with the least access to data or functionality. > - Don't attempt to "future proof" your product by requesting a permission that might benefit services or features that have not yet been implemented. My first thought was "oh it would be NICE if G actually enforced these". But the truth is that they're not. One glance at the Android Play store, and it's abundantly clear that Google is letting shitty apps request whatever unnecessary permissions left and right. Literally the top flash light app requires "full network access", GPS precise and approx location, "view network connections" and "receive data from internet". It's complete bullshit, Google isn't policing these permissions at all, but just using it as an arbitrarily enforced rule. It's pretty clear what the incentives are. Android already has a flashlight, but this one has ads, harvests and sells your data, and uses Google Play Billing Service. Win for Google. On the other hand, there's PushBullet, which gives users more control and this is key, the option to use a platform that is not controlled by Google. It has nothing to do with user privacy. And the whole nice thing about these permissions is that they are granular, this means it should be trivial to point out which one is wrong or better and why, like an error message. That is not "gaming the system", it's literally what these permissions are for. This is also clearly not an automated scanning process that PushBullet accidentally got hit by. Because it would have to have been a very slow running process, given the heaping amounts of trash in the Play Store. And then it just happened to pick PushBullet instead of the Flashlight app that has 50 times more downloads??
- throw_m239339 6y agoIt's classic google. Now that they are a monopoly, they don't have to compete for developer's attention. That's why I will never give a cent to Google Cloud, I know too well how it's going to end up if they ever become a major force in the cloud, I'm not going to invest anything with them and strongly suggest any business I work in to minimize their exposure to Google product. They all end up the same way.
- max___ 6y agoHow about removing the permissions for HTTP and keeping the HTTPS permissions? If the problem is "User Privacy Safety" as the rejection suggests, this seems to be the obvious choice.
- maehwasu 6y agoI’m surprised Google et al. haven’t been forced to make more contractual disclosures at the time of a user submitting an extension or app. Absent blaring warnings like “you understand that if you build any type of business on this platform we reserve the right to destroy it at any time for any reason”, it’s pretty hard to see how users had any ability to understand the implicit and explicit contracts they were entering into. This isn’t much different than “Nathan for You” style hiding of onerous terms deep in hilariously small fine print, and judges tend not to look fondly on such games.
- qwertox 6y agoI wonder why the cookies permission is requested. It's not needed to communicate with .pushbullet.com, as in that case the normal cookies which have been set by Pushbullet will be sent along in the extension's requests to .pushbullet.com. It is only needed to access 3rd party cookies.
- katzgrau 6y agoI have an app that was falsely flagged as malvertising by Google Ad Manager. Also got a generic message with no insight into the specific problem. It was only because I had a point of contact at Google with actual influence that I was able to resolve the issue (and they did, miraculously). If you don't know a human, Google's automated systems can more or less destroy your app or business for Google product users, which is pretty much everybody. G is a big, multi-headed beast. Not evil, but worse - indifferent.
- fsckboy 6y agoI went to look at what pushbullet does since I'm not familiar with it--in this day and age, "bullet" is a fearsome term so I wanted to make sure that wasn't the cause of google's alarm. The personal information security concern I had is that it seems that pushbullet shovels all sorts of data from Chrome to the pushbullet server and then routes it to, pushbullet says, my other devices while respecting my privacy. While I don't doubt that pushbullet is an honest broker of my data, it's doing all this outside of google's purview. For somebody to spy on my data, they wouldn't need to break into google's ecosystem, they'd just need to break into pushbullet's. I'm not disagreeing with all the other comments here about big bad google, I already think they are bigger and badder than everybody else here does. And I'm not at all sure that what I'm pointing out has anything to do with google's motivation here (I liked the comment that said that this app is a threat to their walled garden), I'm just pointing out my impression to try to be helpful to OP in figuring this out.
- KIFulgore 6y agoThis is scarily reminiscent of Facebook's App Review process. We submitted 8 identical Apps that, functionally, are just webhooks for Messenger events. All required documentation, justification for the two permissions we needed, screen casts, and test login credentials were submitted for the reviewers. 3 were approved. 5 were rejected - all for different reasons. Re-submitted the 5 with no changes; 2 more got approved. Two were rejected again. One was rejected with a firm reprimand for making an identical submission (must have hit the same reviewer). Shuffled some words, re-recorded a couple videos - 2 more approvals, 1 rejection. Re-submitted the last outlier without changes - Approved. We are very weary of playing Facebook App Review whack-a-mole.
- awinter-py 6y agodid you write this up somewhere?
- KIFulgore 6y agoI haven't written a blog about it, but it's a common experience for those building B2B integrations with Facebook. Also common is feature deprecation with replacement functionality gated (read: withheld) behind a closed beta program. They're difficult to join and often can only be entered if you commit to supporting other Facebook APIs and features (those they wish to publicize).
- beders 6y agoIt seems perfectly clear to me: Google doesn't want what pushbullet provides. They are pulling an "Apple" on this one.
- jimnotgym 6y agoNormally in a lucrative but restricted market there is a regulator or ombudsman one can appeal to if one feels they have been unfairly pushed out. App stores need regulators.
- pembrook 6y agoThe lesson here: Building a business off someone else’s platform is easier because it provides a built-in distribution channel. However, when you don’t own your distribution, it means your business can be shut down by the decision of one person at X company. It turns out, all decisions have trade-offs. If you want to have a real business, don’t do the above, or only do the above while getting started. Developers hate having to deal with distribution. Platforms exploit this by creating these fantasy worlds where developers don’t have to think about it. This is a mirage. You have not created an “easier” business. You’ve simply sold your soul to the devil.
- tony-allan 6y agoSimilar story published around the same time as this one... (https://news.ycombinator.com/item?id=23183742 https://news.ycombinator.com/item?id=23183742) https://joaoapps.com/join-chrome-extension-in-jeopardy-google-wont-tell-me-why/ https://joaoapps.com/join-chrome-extension-in-jeopardy-googl...
- aws_ls 6y agoThese folks also do the same thing for Adsense on sites. For a site, I am running for a long time. 10+ years. And earned multiples of 100ks worth of revenue from it. They sent a vague email, regarding violation and suspended Ad serving. Never ever had any issue before. I can only suspect that their policies have changed because of the current pandemic. But isn't it disingenuous, in that case. Similar to laying off an employee, and cooking up a shady reason for it. They will only make me kill the business, which in turn will stop payments (reduce significantly) to AWS. Thereby enabling more slow down. Very very unhappy with them.
- Too 6y agoI haven't used Pushbullet in depth but on first glance it doesn't seem like a browser extension at all. It looks more like a standalone chat app that happens to be running in the browser. It has nothing to do with enhancing the browsing experience, except for a share-link feature? Google might not want to make Chrome the browser into an OS. If i were Google i would also be skeptical when such standalone apps wants to read my browser cookies or access my http://localhost http://localhost. Actually i think cookies is the violating permission here.