14 ms·
Google has removed Conversations_im from the Play Store
- bertman 3y agoDeveloper: "Google has just removed #Conversations_im from the Play Store because they think we are uploading the user’s contact list. We don’t." and "To be clear: They didn’t just reject an update. They outright removed the app entirely. Otherwise my plan B would have been to remove the contacts permission which is used to display the name and profile picture locally if the XMPP address matches an entry in the users address book."
- HeckFeck 3y agoNever fear, I'm sure someone from Google support will be only too happy to help.
- miroljub 3y ago> Never fear, I'm sure someone from Google support will be only too happy to help. /s * *) For that one person that thinks this is not a sarcasm.
- carstenhag 3y agoTalk with Google, usually this stuff can be resolved. Their bots flag stuff because of reasons. Yes, sometimes it's BS, but often there's something that you have missed to clarify.
- axelthegerman 3y agoLol this must be a bigger joke than the app being removed in the first place. I never heard of anyone who was able to talk to anyone at Google. HN is full of folks getting apps suspended, locked out of their Google account and so on... Not being able to talk to someone is sometimes actually the only problem (though we all know the app store has much more issues than just that)
- carstenhag 3y agoI also really like to joke about Google Play and their policies. But: Often it does help to simply write them! Yesterday at 16:56 our update got rejected, at 17:51 I submitted an appeal and at 18:33 they accepted the appeal and the update got approved. https://i.imgur.com/a5L8D9g.png https://i.imgur.com/a5L8D9g.png
- qingcharles 3y agoIf you have an ads account they cold call you and email you constantly lol. Can they help me get back into my gmail account that I have the username/password/recovery email for? No.
- HumblyTossed 3y agoIf only there was a real person at Google to talk to. The only way to sometimes get stuff like this resolved is to make the front page of HN, Twitter, etc.
- feitingen 3y agoThat's a bit funny since i get notifications on my phone from google assistant (which I've disabled) about birthdays of my contacts, and I've explicitly disabled contacts access for all google apps on my phone. Feels like a slap in the face every time.
- PurpleRamen 3y agoMy guess, the contacts are synced to the cloud, and the message came from Gmail or the Google Contact-Webservice and Assistant is just the icon in the middle.
- petters 3y agoI wonder why Truecaller is allowed then? It builds a database of users’ contacts. Probably in violation of GDPR but they have a constitutional exception for that in Sweden (“utgivningsbevis”).
- cranberryturkey 3y ago[flagged]
- MattJ100 3y agoI hear you, but not a magic solution: "Apple drops PWA support on iOS for EU users" https://news.ycombinator.com/item?id=39299007 https://news.ycombinator.com/item?id=39299007
- dathinab 3y agowhich makes it very clear that the only reason PWA where still allowed by apple was to try to avoid monopoly marked regulations the fact that they seem to remove them without any warning make it clear how much they care about they users (i.e. not at all, it's all about money, which should be obvious but needs to be said in case of apple as they managed to convince people otherwise)
- deleted 3y ago[deleted]
- phyzome 3y agoAre PWAs able to speak XMPP?
- wiktor-k 3y agoFor servers that enabled web sockets that's possible and XMPP JavaScript libraries support that.
- MattJ100 3y agoYes, Movim and Converse.js are two web-based XMPP apps that support installation as a PWA. XMPP supports running over websockets (or even long-polling HTTP, but that's thankfully less necessary these days).
- MattJ100 3y agoThis has been happening to a bunch of XMPP apps recently, and as a maintainer of another one (which closely based on Conversations) I'm fearing the worst next time I submit an update. The worst part is the lack of communication from Google about what they think the problem is. There are plenty of apps that do actually upload contact lists to servers (hi WhatsApp, etc.), and they are still listed on the store. Many XMPP apps do request the contacts permission, but this is to (on the client side only) allow storing XMPP addresses in your phone's address book and reusing your existing contact pictures, etc. This is explained within the app, and granting the permission is entirely optional.
- sitkack 3y agoMaybe Eric Schmidt is returning to Google.
- rob74 3y agoThen I'd argue that the actual problem is only having a permission to access the contacts, and not limiting what the app can do with them. Of course, limiting what an app can do with data that it already has access to is an interesting technical problem (and AFAIK not one Android is currently set up to handle)...
- carstenhag 3y agoEspecially tiktok is still live, and there it's super obvious they upload the contact list. First: they ask you. More importantly though: you don't even need to search for someone or someone's phone. You open the app and get 3 people suggested you never even knew had a tiktok account. Really really creepy when you just exchanged numbers with someone and you can see all their 50 tiktoks. Happened to me with a girl I matched online - funny for me to see her videos, for her it was super creepy.
- madeofpalk 3y agoThis happens the other way around as well (and is why, imho, both Android and iOS should flat out remove the capability from their platforms) - if TikTok knows your phone number for whatever reason, and the OTHER person uploads their contacts with you in it, that's enough to create the connection and start prompting you to friend them.
- doublerabbit 3y ago[flagged]
- gear54rus 3y agoAt least we are still able to install apps from somewhere else.
- thimp 3y agoHey all you have to do is persuade yourself you like drinking from your overlord's fountain of blood!
- tenebrisalietum 3y agoWell if you can get punch cards over smoke signals connected to a serial port somehow, you could do UUCP over it. > I'm waiting until you have fees to open a jpg. Pay-per jpeg. PPJ Imagine a future where all video is cloud based and is rendered by remote GPU farms and you are charged per pixel rendered (PPR). Moving your mouse will incur changes.
- paulcarroty 3y agoOut of curiosity, where's xmpp still popular?
- anta40 3y agoFor example, to implement chat within your app.
- SamWhited 3y agoIt's used by a lot of the big commercial platforms because it's well understood and has libraries for every system and language ever invented just about. Eg. Zoom and Jitsi both use XMPP (Zoom for Chat, Jitsi for chat and signaling), WhatsApp used to just have their entire backend be an off the shelf XMPP server, Cisco Jabber which is still popular in "enterprise" uses it, etc. And for other individuals just wanting to talk with their parents it's just a chat app, they don't care if it's XMPP or not, Conversations is just really nice to use.
- zaik 3y agoWith privacy minded folks and people who think we should just agree on using the IETF internet standard for instant messaging instead of 5 different proprietary messaging apps and 3 apps based on experimental "open" protocols (which are ultimately controlled by a single entity and never standardized).
- zajio1am 3y agoTo be fair, IETF standardization of XMPP was somewhat afterthought, and further extensions (XEPs), which are necessary for modern clients, are not IETF standardized.
- zaik 3y agoStandardizing the core concepts + the extensibility of XMPP was absolutely necessary to achieve the necessary protocol agility I think. Requirements have changed a LOT since 1998 and we still have innovative and modern XMPP clients, maintained by the community, mostly in their free time without any need for millions of dollars of VC money. Without standardization, there can be no interoperability and without agility any IM protocol will soon be outdated. I think XMPP is a success story because it realized this, but it's a success story that isn't told very often.
- Dibby053 3y agoI use an open source SPAM call blocker (Yet another call blocker), which works fairly OK by querying a local spam phone number database. Recently Google Play decided to display a permanent notification prompting me to uninstall that "dangerous" app because it could "damage" my device. It's impossible to disable this notification. This app hasn't been updated in years. It has no ads. The only network request it makes is a GET to update the local DB. My theory is that Google has decided to take into account generated revenue in their risk assessment algorithm. That would explain why FOSS apps are getting the axe while the dodgy commercial call blockers that upload your call history to their servers are still up.
- realusername 3y agoIt's just a PR game of shifting blame. Who's responsible of all those privacy issues on mobile? Google's own ad machine powered by the GMS running as privileged user or the apps? They chose quickly. Both companies response to the press has been to blame the apps again and again hoping that it would be enough to continue what they are doing. Occasionally they even blame the users directly, the play store page on install displays "Safety starts with understanding how developers collect and share your data"
- pawelmurias 3y agoPer the amount of access they have some shit tier third parties will steal more privacy as they won't give a damn about it. Most people don't mind the ad company measuring your general profile of interests but really don't want people to read their messages.
- realusername 3y agoGoogle does both, the amount of stuff collectively harvested by GMS would make any app doing the same rejected on the play store.
- malfist 3y agoCheck out the Aurora store, it's a drop in replacement for the play store withot the Google nonsense. I started using it after Google refused to let me install watch faces, because the apps hadn't been updated for foldable phones.
- dathinab 3y agoMy guess is it's a fully automatized decision which at best upholds the pretense of being appealable but in practice is not. I.e. they checked 1. uses contact permission 2. doesn't have in their privacy policy that they process/upload/store the contacts => must be malicious so kick it. probably they don't want to bother to have to consider if contacts are actually uploaded or not and just blindly assume they are problem with that is a lot of privacy friendly apps do exactly that, access contacts for convenience features but not upload it
- richardwhiuk 3y agoAGB?
- dathinab 3y agoupdated the post, that acronym was in the wrong language (ToS would have been the correct acronym, through privacy policy is more precise)
- the_third_wave 3y agoConversations is on F-Droid so there is no reason to get it from the Play store. This goes for all free software apps, get them from F-Droid or similar free software repos and free yourself from the manipulations by the likes of Google/Apple/Microsoft/Amazon/etc. Yes, I understand this limits the reach to those who know about F-Droid (et al) but given the way XMPP has been pushed out by the aforementioned corporate entities it is likely that those who use XMPP already know about and use F-Droid.
- MattJ100 3y agoThe Conversations developer also highlighted that a significant portion of his income comes from Play store. So a reminder that F-Droid features donation links on app listings that support it (including Conversations), allowing you to discover how to donate directly to the developer (no percentage fee is taken by Google that way, too).
- zaik 3y agoI have my whole family on XMPP, most of them do not know about F-Droid.
- the_third_wave 3y agoTell them about F-Droid then. Tell them they can find a bunch of apps which are less likely to sell their soul to the highest bidder. I did tell mine, all of them installed F-Droid - it is just another app after all - and most use a number of apps from there, things like Nextcloud and DavX and, yes, Conversations.
- arendtio 3y agoI am not entirely sure, but I believe the F-Droid version uses a different push technology, which can lead to slightly different app behavior/compatibility/battery usage. I used it for some years, but I switched to the Play Store version at some point. Maybe someone else remembers better?
- the_third_wave 3y ago
- kaptainscarlet 3y agoXMPP as a protocol is pretty much dead on Android with all the battery optimisations in the newer versions. You can't get a decent user experience unless you integrate it with Firebase.
- eurekin 3y agoPardon for a tangent! I've been so full of missing and delayed notifications I just bought an iPhone, which has zero issues with it, with zero configuration. Still, as I made a few really small android apps in the past, this has been a sticking point for me for years. Is it possible to write an app that can notify at ANY time? Let's say I want to monitor my self-hosted infrastructure. On an iPhone I get e-mail alerts right away. On Android, some ring exactly at the time I pick up the cursed phone. I checked for every possible consumer facing configuration option (deep sleep exclusion, background service allowed, etc.) and I found zero reliable options.
- Dibby053 3y agoNtfy.sh seems to work perfectly on stock Android without firebase/GSF. I do have "unrestricted" enabled in app settings but it doesn't seem to impact battery life in a noticeable way. I never missed any notifications. Once you leave AOSP-land it can be more tricky, https://dontkillmyapp.com/ https://dontkillmyapp.com/ has more info if you're interested.
- eurekin 3y agoThank you! This actually looks very relevant [1]: > Even disabling the system battery restrictions does not save the app from being killed. Let's find out, if it is a bug or a feature... Here you can read more details I have Samsung s21; after years of fighting it (3 samsungs) I'm welcome to a bug explanation - [1] https://dontkillmyapp.com/samsung#:~:text=Even%20disabling%20the%20system%20battery%20restrictions%20does%20not%20save%20the%20app%20from%20being%20killed.%20Let%27s%20find%20out%2C%20if%20it%20is%20a%20bug%20or%20a%20feature...%20Here%20you%20can%20read%20more%20details https://dontkillmyapp.com/samsung#:~:text=Even%20disabling%2...
- alwayslikethis 3y agoLuckily, it's not like iOS and you can still download an APK or use F-Droid. My impression is that most people who are using these rather obscure communication methods would be able to find the app somewhere else.
- yu_ni 3y agoThe developer relies on the income from Goolge Play Store to keep working on it though: "I understand that most of my audience here on Mastodon is more ideology aligned with F-Droid but the app sales on Google Play store have contributed significantly to me working (almost) full time on #Conversations_im. Without the revenue from Google Play I can’t afford this." -- https://gultsch.social/@daniel/111929678072451151 https://gultsch.social/@daniel/111929678072451151
- knightoffaith 3y agoPretty surprising that you can make money off of a free software app like this, I always thought almost nobody would actually pay for it on Google Play store. I hope he can work it out with Google. Conversations is the best Android XMPP client I know of.
- alwayslikethis 3y agoI'm using a fork but it is the best XMPP client out there. Even the ones on Linux are riddled with bugs and usability issues.
- PurpleRamen 3y agoAnother datapoint for the enshitification of Android. Recently, I have encountered problems with Tasker, because Google has removed another set of abilities from Android for the sake of "security". Which for means there is less and less reason to use Android, which kinda sucks..
- devaiops9001 3y agoGoogle Play is cancer that belongs in a sandbox or better yet running only in a secondary user profile. https://grapheneos.org/usage#sandboxed-google-play https://grapheneos.org/usage#sandboxed-google-play
- rcbdev 3y agoOr just completely removed from the device. I've been using my phone without any GApps for almost 10 years now - no issues.
- alias_neo 3y agoThey did the same thing to our messaging app where I work. Claimed we were uploading contacts and removed our app; we definitely don't upload contacts, that's a fact; the infra is also self-hosted so where would we be uploading them to? They only way we got them to allow it back was to add a privacy-policy notice to say that we upload contacts and why, despite the fact we actually don't...
- xd1936 3y agoWhat a terrible outcome.
- ndr 3y agoHow do you know none of your sdk/deps doesn't either?
- ryandrake 3y agoYours is a good question, and probably one of the places I'd look first. It doesn't deserve to be downvoted. Too many developers just yeet rando dependencies into their app without even remotely vetting/auditing them.
- ndr 3y agoIt's a sad truth, and extremely hard for small devs. Google and Apple are well positioned to help everyone do better here, but the game-theory doesn't make being transparent any easier.
- alias_neo 3y agoI work for the kind of employer, who has the kind of customers who won't allow us to leave this sort of thing up to chance. I can't be more specific, as I'm not authorised to speak on behalf of, or represent my employer; my words/opinions are my own etc. We know, because we have to know.
- ndr 3y ago
- NoImmatureAdHom 3y agoRelevant copypasta: Fellow humans, there are alternatives to Google and Apple! Your neck need not be under anyone's boot! You don't even need to give up any functionality: Data service: The simplest thing is to buy a prepaid SIM and top it off with cash. The lovely people over at /r/nocontract maintain a big spreadsheet so you can filter by various properties of the available contracts. Another way to go is to pay for a postpaid plan with a virtual credit card (VCC) like at privacy.com. It won't be linked to your name at the telco, but of course privacy.com knows who you are. There is also Abine Blur, and some others. Yet a third way to go, which is nascent, is buy an eSIM with crypto. You can also buy prepaid VCCs with crypto. An interesting new choice is PGPP https://invisv.com/pgpp/ https://invisv.com/pgpp/ who rotate your IMSI and do some other cool stuff. It works by e-sims. All these methods make you /pseudo/nymous, but obviously you're still identifiable by subscriber number and possibly IMEI, to put aside correlational things like your traffic profile. You can help this problem by routing everything through a VPN. Then you're pseudonymous but the cell carrier knows nothing about you other than that you use a VPN. Pay for the VPN with crypto. Of course now the VPN provider knows your traffic, but you're much more anonymous to them than you are to a telco. You make your choices. Defense in depth. Etc. OS: GrapheneOS: https://grapheneos.org/ https://grapheneos.org/ Very much like Calyx, but extra-hardened and with no MicroG. No involvement with Google at all by default. You can make a secondary profile in which you install Google Play Services to set up an environment where you can run unprivileged Play services + whatever crapware you need that requires them. Unprivileged here means it's like any other app: if you don't give it access to your location, it won't know where you are. If you end the profile session when you leave, Play Services stops running and stops talking to Google. CalyxOS: https://calyxos.org/ https://calyxos.org/ Privacy-respecting Android distribution that replaces Google spyware with MicroG, so you can have your cake and eat it too. Most everything will work as you're used to, but it does still talk to Google to make that happen. LineageOS: https://lineageos.org/ https://lineageos.org/ The successor to CyanogenMod, will work with many different phones. More privacy and control than stock Android. There are also many others: Sailfish, Replicant, e Hardware: CalyxOS and GrapheneOS run best on Pixels. The path of least resistance is to get one of these phones and run GrapheneOS with Google Services installed in one profile or other. You could also buy a Librem 5 https://puri.sm/products/librem-5/ https://puri.sm/products/librem-5/ If privacy and security and hacking are really important to you. Or a pinephone: https://www.pine64.org/pinephone/ https://www.pine64.org/pinephone/ Neither work very well by regular standards, but they're cool :-)
- riedel 3y agoIMHO we clearly need more nonprofits that take up those cases and cover legal costs. At least get on their nerves, like the guy who singlehandedly sued Instagram because they canceled his restaurant. Noyb successfully showed how this can work for GDPR, we need something similar for digital markets and platforms. All those platforms only can make so much money because AI makes critical decisions and they can even claim not to be liable. If they make so much money with you it would at least seem reasonable that you get a human contact.
- doublerabbit 3y ago[flagged]
- lavl 3y agoAlthough it will only be fully in force as of March 6th, this sounds like an obvious violation of the European Union's new Digital Markets Act to me. Article 6.12 states: "The gatekeeper shall apply fair, reasonable, and non-discriminatory general conditions of access for business users to its software application stores", whereas nothing about their decision is fair & reasonable. Furthermore: "For that purpose, the gatekeeper shall publish general conditions of access, including an alternative dispute settlement mechanism.", while it sounds like no serious appeals procedure was offered. Now, how to actually enforce this in a procedure that won't take years to complete is a different question..
- syncio 3y ago[dead]
- petre 3y agolist.Good thing I have FDroid installed. They should totally remove WhatsApp as well then. Last time I tried to install it it did not even work without access to the contact list.
- iamleppert 3y agoHow long before Google just completely locks all third party developers out? That seems like a likely outcome at this point. It’s only a matter of time before they start rent seeking on their developers, like Twitter and other tech companies in decline.
- butz 3y agoWhat is most infuriating, that when you actually want to remove app from app store - you cannot do it easily from Google Play Console. As far as I read you have to contact support and jump through other hoops. It's probably easiest way to add malware and hope Google removes your app much faster.
- sequoia_in 3y ago[flagged]
- nerdyadventurer 3y agoNot related does anyone know how to block promotional SMS from marketing services where there is not a number to block?