I think the interpretation that Google does this because it does not want to compromise the review process to malicious extension authors is a very generous one. As others pointed out, a motivated enough entity could very well be probing the system using multiple submissions (sure it gets your account banned, just use several accounts).
No what is really going on is that Google wants the ability to reject an app for any reason without actually having to give the reasons. To for example protect a business interest.
The only reason for not making a transparent decision process is because you want to keep the ability to make decisions that don't follow the rules you set.
To the people saying that we should keep rules secret so that malware authors can't work around the rules, I ask: the same argument applies to laws, but most people agree that we want transparency. So what makes this different in principle? (I understand that Google might not have an obligation, but you are saying that they do the right thing)
Exactly. It's also completely contradictory to Google's Project Zero, where they expose security flaws in great detail publicly with the intention to educate users and devs to fix the issue and prevent it from happening again.
At the very least, Google should provide a way to contact an actual human - especially if the developer has 1M+ users.
don't create extensions. create browser controllers. you can release them as binaries. anyone can download them. They instrument chrome using the remote devtools API.
No what is really going on is that Google wants the ability to reject an app for any reason without actually having to give the reasons. To for example protect a business interest.
The only reason for not making a transparent decision process is because you want to keep the ability to make decisions that don't follow the rules you set.
To the people saying that we should keep rules secret so that malware authors can't work around the rules, I ask: the same argument applies to laws, but most people agree that we want transparency. So what makes this different in principle? (I understand that Google might not have an obligation, but you are saying that they do the right thing)