Live data from Hacker News

Android wallpaper app that steals your data was downloaded by millions

mobile.venturebeat.com

41–50 of 60 posts

Re: Android wallpaper app that steals your data was downloaded by millions

#41
post #3

If this is true, I'm disturbed by the fact that: 1. Google has failed to tell any of us this, 2. I don't even know if I had any of the vendor's applications in the past, as they have been removed entirely, AND 3. Google has failed to tell any of us this! I mean what the hell, at least send us an email telling us that because we downloaded AppXYZ, our data has been compromised by some low-life(s) in China. I'm going t…

Does Android have the ability to remotely kill applications like iOS? If so, perhaps they did that, so your app just disappeared if you had it. I was going to say "I can't imagine Google hushing up a security issue", but it does have the potential to get thrown in their face by Apple, "See, our walled garden is a good thing." (Not that I believe for an instant that Apple's approval would catch something like this.)

> Does Android have the ability to remotely kill applications like iOS?

Yes, and they already used it a few weeks back: http://android-developers.blogspot.com/2010/06/exercising-ou...

Re: Android wallpaper app that steals your data was downloaded by millions

#42
post #30

Earlier quoted context omitted.

Because this wasn't some random APK downloaded directly from the internet and thrown onto a phone after the 'APKs from the internet might harm your security' message. It was uploaded to Android Market and provided by Google, who as an arbiter of content, should realize that 'collect phone data' isn't an appropriate permission for a wallpaper.

So, Google has a responsibility to check each and every app for malicious intent by the uploader? I really think that goes one step too far, that's exactly what apple does with their market place and I think that is a big part of the problem. The ultimate responsibility of what you run on your computers lies with you, not with some entity providing you with a convenient way to get at a catalogue of stuff. This applic…

> So, Google has a responsibility to check each and every app for malicious intent by the uploader?

Yes, that's very much the point of an official, curated application store. Especially when you can sideload applications or use third-party store, the official first-party store being loose and un-trustable makes it not very useful.

> The ultimate responsibility of what you run on your computers lies with you

Most users have absolutely no sense of IT responsibility, and barely even understand how the thing is supposed to work.

> Pushing the responsibility to Google is utterly unfair

Not really. It's their store, branded by themselves. To regular users, they're the trusted authority/overseer.

Re: Android wallpaper app that steals your data was downloaded by millions

#43
post #23
post #2

so what were the security permissions requested by this app at the time of installation? i have to imagine that if it was taking web browsing history that it would have needed more permissions than just "uses network data". android's fine-grained security permissions, where the author has to explicitly request each type (network use, prevent the screen from turning off, etc.) and the user is shown the list of permiss…

Again since the article doesn't mention which app was malicious it's hard to say but when I looked up the wallpaper apps developed by "jackeey,wallpaper" I see the apps requiring the following permissions: android.permission.ACCESS_COARSE_LOCATION android.permission.ACCESS_NETWORK_STATE android.permission.INTERNET android.permission.READ_PHONE_STATE android.permission.SET_WALLPAPER android.permission.WRITE_EXTERNAL_S…

A wallpaper app is likely to need the ability to download new wallpapers. I'm not sure why it would need your location though.

Re: Android wallpaper app that steals your data was downloaded by millions

#44
post #3

If this is true, I'm disturbed by the fact that: 1. Google has failed to tell any of us this, 2. I don't even know if I had any of the vendor's applications in the past, as they have been removed entirely, AND 3. Google has failed to tell any of us this! I mean what the hell, at least send us an email telling us that because we downloaded AppXYZ, our data has been compromised by some low-life(s) in China. I'm going t…

Does Android have the ability to remotely kill applications like iOS? If so, perhaps they did that, so your app just disappeared if you had it. I was going to say "I can't imagine Google hushing up a security issue", but it does have the potential to get thrown in their face by Apple, "See, our walled garden is a good thing." (Not that I believe for an instant that Apple's approval would catch something like this.)

http://android-developers.blogspot.com/2010/06/exercising-ou...

Re: Android wallpaper app that steals your data was downloaded by millions

#45
post #34

Earlier quoted context omitted.

The tricky part for Google is they have pulled apps in the past so they're not entirely absolving themselves of responsibility for the Market.

As I'm sure they'll pull these when the right people at google are alerted to the problem. But there will be more instances of this and I think that there simply ought to be a strict procedure to report malware so it can be responded to quickly rather than to lay the blame with google. Then if such a procedure is in place and if google would consistently refuse to pull clearly identified malware you'd get in to a sit…

Having anything submitted to the 'Themes' category not include the permission to view your call history is automatable.

> I'm sure they'll pull these when the right people at google are alerted to the problem.

I've ported about 15 different apps to Google which were blatant cases of IP theft, and one of search results gaming. They're all still there, with zero response. They might be better with handling malware but I doubt it.

Re: Android wallpaper app that steals your data was downloaded by millions

#46
So the iPhone is too closed, and Android is too open.

In my opinion, they should have a quality assured Market, but keep the ability to load .apk files whenever you want (and also the ability for others to create their own marked).

Quality assurance on market should mainly be about maliciousness of applications.

It sounds stupid arguing for android to be more closed, but really Google is very slack with their Market.

Re: Android wallpaper app that steals your data was downloaded by millions

#47
post #45

Earlier quoted context omitted.

As I'm sure they'll pull these when the right people at google are alerted to the problem. But there will be more instances of this and I think that there simply ought to be a strict procedure to report malware so it can be responded to quickly rather than to lay the blame with google. Then if such a procedure is in place and if google would consistently refuse to pull clearly identified malware you'd get in to a sit…

Having anything submitted to the 'Themes' category not include the permission to view your call history is automatable. > I'm sure they'll pull these when the right people at google are alerted to the problem. I've ported about 15 different apps to Google which were blatant cases of IP theft, and one of search results gaming. They're all still there, with zero response. They might be better with handling malware but…

That's pretty damn sloppy of them.

Re: Android wallpaper app that steals your data was downloaded by millions

#48

Earlier quoted context omitted.

So, Google has a responsibility to check each and every app for malicious intent by the uploader? I really think that goes one step too far, that's exactly what apple does with their market place and I think that is a big part of the problem. The ultimate responsibility of what you run on your computers lies with you, not with some entity providing you with a convenient way to get at a catalogue of stuff. This applic…

> So, Google has a responsibility to check each and every app for malicious intent by the uploader? Yes, that's very much the point of an official, curated application store. Especially when you can sideload applications or use third-party store, the official first-party store being loose and un-trustable makes it not very useful. > The ultimate responsibility of what you run on your computers lies with you Most user…

I thought the main point was to provide a centralised repository, not to have a 'stamp of approval' and a guarantee of being 'malware free'.

For the life of me I can't see how google could begin to put a dent in evaluating each and every application at that level.

Do they refuse applications according to some publicised rule set ?

Each and every one of the closed source downloads that has ever been done from download.com could turn out to be malware tomorrow morning, I find it hard to believe we should hold download.com as the place where we 'got it' responsible for stuff like that.

In the end, you should trust the creator of the software, emphatically not the place where you downloaded the code. Whether it's a big site maintained by a big name or a smaller one, if it isn't open source you basically can't trust it.

Re: Android wallpaper app that steals your data was downloaded by millions

#49
post #24
post #21

Earlier quoted context omitted.

If a wallpaper app requests access to your contacts and millions of users install it anyways that is a flaw in Android's security model. After a while you become conditioned to just hitting Install without even looking at the permissions being requested. Just because users are lazy or even stupid is not an excuse for leaving them vulnerable.

I agree it's a flaw. I do think it is better than iOS but it is still a huge problem. It is one of simultaneously too much and too little granularity. If you provide too much granularity it overwhelms users, while if you provide too little it forces people to approve too wide a scope. For example, the music app I just installed wants access to the phone state and identity. At first I baulked and said WTF does a music…

No, it's a problem in the model.

User testing has shown, over and over again, that users do not read pop-up boxes. Why would anyone expect security warnings would be any different than error messages? MS dialed down granularity from Vista to 7 and the UAC is still a joke.

What's needed is something different. I don't know what that thing is, but pop-up boxes are not it.

My pet theory atm is "services". When an app installs, it can register as knowing what to do with certain data. Say, GPS coordinates or contacts.

If a user wants their wallpaper to have access to that data, they'll open their GPS, or contacts app and explicitly allow the behavior.

That way, an app only has access to those data sources if the user explicitly sets out to grant it to them. If it's a conscious multi-step process, it should be pretty hard for people to accidentally grant a wallpaper access to all their personal data.

And given the competitiveness of mobile app stores, I doubt any app would survive that sits functionless and nagging until the user explicitly grants it a half-dozen permissions. So they'd quickly end up asking for less, or at least delivering as much as they can with as little as they're given.

I know "services" hardly goes all the way. But my point remains that no level of granularity will make the pop-up approach 'work'.

Re: Android wallpaper app that steals your data was downloaded by millions

#50

Earlier quoted context omitted.

> So, Google has a responsibility to check each and every app for malicious intent by the uploader? Yes, that's very much the point of an official, curated application store. Especially when you can sideload applications or use third-party store, the official first-party store being loose and un-trustable makes it not very useful. > The ultimate responsibility of what you run on your computers lies with you Most user…

I thought the main point was to provide a centralised repository, not to have a 'stamp of approval' and a guarantee of being 'malware free'. For the life of me I can't see how google could begin to put a dent in evaluating each and every application at that level. Do they refuse applications according to some publicised rule set ? Each and every one of the closed source downloads that has ever been done from download…

> Do they refuse applications according to some publicised rule set ?

Yes. The Android Market Developer Distribution Agreement, here: http://www.android.com/us/developer-distribution-agreement.h.... Section 4.3 in particular.

Post reply on HN