Hacker News new | ask | show | jobs
by Ajedi32 2531 days ago
It seems like at least some of these apps might be using these vulnerabilities without even being aware of it, as the offending code is in third party libraries. Game devs grabbing mac addresses via Unity's API, for example, may not know that that information is supposed to be restricted on Android.
6 comments

Who cares how accidental it was? If you don't vet what happens in your application and why, you have no right to put it on someone else's computer.
> some of these apps might be using these vulnerabilities without even being aware of it, as the offending code is in third party libraries

I'll assume by vulnerabilities you meant to say exploits. Given that: True but so what. This is criminal behavior. Using criminal libraries makes you complicit and a co-conspirator.

Vet your dependencies. I have no mercy for people who put crap on my phone.
Some might be using them without being aware of but the rest can be nicely permabanned.
How would you go about reliably and efficiently determining which category each falls into?
They aren't reliably determining violations of current absurd rules and people's apps get hit all the time for no good reason, so basically they could just continue doing what they've done so far.
If you use a library that engages in criminal activity, you are legitimately a criminal as well and should be held accountable.
If these apps get banned because they use poor dependencies, maybe better dependencies will become popular, and developers will also have a reason to be more aware of what code they are using.
And that excuses them how?

Ignorantia legis non excusat