Live data from Hacker News

Popular Google Play store apps are abusing permissions and committing ad fraud

buzzfeednews.com

41–50 of 178 posts

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#41

the locked in store model has completely failed. both for ios and android it is a terrible experience compared to PC. you are stuck with only the search tools the hardware maker gives you, often designed in a user hostile way (ios brings up ads) and no way to bail out to a different store. as well the monoculture leads to a race to the bottom with garbage programs shoving their way to the top via misleading a dishone…

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

The problem with early 2000's-style software delivery wasn't that you could choose which software to install, it was that there was no separation between programs, so that any random program you installed could add toolbars to your browser, steal all your passwords, etc. If iOS or Android made it easier to install apps outside the store, I highly doubt you'd see anywhere near the same level of problems, since everything is so isolated from each other.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#42

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

The solution is what has been suggested earlier: allow users to choose their own 'store', don't lock them to a single vendor. This is already possible with Android where F-Droid is a good example of a 'store' where the chance of being exposed to these shenanigans is close to zero. Currently iOS users lack this option so for them the only way out is to change platform.

You still have fragmentation though, which creates surfaces for security and privacy issues that the 'wild west' of the 2000s had. OS providers could enforce standards for these 'stores' as a fix, but then they'll be accused of unfairly regulating competition.

Part of one of the antitrust suits against Google was that it required Play Services to be preinstalled by manufacturers on Android phones before the Play Store could be preinstalled - but the latter needs the former to work.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#43
They're mixing so many issues and confusing the matter. They have discovered ad fraud, which is interesting, but doesn't actually directly harm the user (right?), just the advertisers and Google. But then to make sure they are propagating fear, they bring in the completely unrelated issue of data being sent to China. And there is some confusion there too - is it only through the (unnecessary) permissions that users approve (a much different problem) or are they able to send unexpected data also without the permissions? I wish the world didn't have this sensationalism arms race to get their articles read.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#44

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

The solution is what has been suggested earlier: allow users to choose their own 'store', don't lock them to a single vendor. This is already possible with Android where F-Droid is a good example of a 'store' where the chance of being exposed to these shenanigans is close to zero. Currently iOS users lack this option so for them the only way out is to change platform.

Anything that became popular would be targeted just the same. The solution is more secure OSes, not distribution filtering. I should be able to put a gelatinous abomination from hell on my phone and be okay. Mobile OS sandboxing is better than older PC OSes but it's still not perfect.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#45

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

I'd say that the sandboxing introduced by mobile OSes today solves the vast majority of the problem. By isolating applications and introducing permissions, malware that can steal or encrypt user data isn't possible even for people installing those pirated APKs.

But the type of malware described in the article obviously is possible, given that it’s possible even on the Play Store. The OP posed switching to a decentralized model as a solution to that, and it’s hard to see how that makes any sense.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#46
In an ideal world, OS maintainers, instead of running a software store with a client-end on consumer devices, would run just a repository, with version control, metadata and downloadable packages for apps submitted to and supported on their platform, but allowed any third party to link to their repositories for fetching information or downloads. This would allow external review hosting, discovery, competing marketplaces, or even users directly fetching the application without navigating marketplaces if they knew what they wanted.

Of course, there's nothing in this approach financially for the maintaining company, so this was not going to happen.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#47

It's not just ad fraud, they've been copying information like whatsapp phone number, reddit username, telegram username etc. https://www.reddit.com/r/miband/comments/8eqtve/why_did_mifi...

As far as I know (and can find online) DU group and Xiaomi are unrelated. However, this is a really interesting discovery in it's own right. I am a Xiaomi phone owner and have the App MiFit.

Would it be possible for me to reproduce what you have found? and if so, how can I do so?

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#48
post #5

> Google confirmed it found fake ad clicking on all 6 apps, and said ad fraud was against Play store policy. So why aren't you removing the apps, I asked. They said they banned them from ad products and were still investigating. Really? Finally, not long ago, Google removed them. What's wrong with this guy? Does he not understand what investigating means? God forbid Google actually investigates claims of malfeasance.

If we take the paragraph at its word, Google had already “found” fake ad clicking, with a high enough level of confidence that they both “confirmed” it to a journalist and banned the apps from ad products. It was reasonable to wonder why the same level of confidence was not enough to remove the apps. There are some potential valid answers to that question, to be sure (e.g. want to be more careful before taking actions that affect users), but also potential invalid ones (they just didn’t care much about ad fraud and only removed the apps due to the pressure).

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#49
post #41

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

The problem with early 2000's-style software delivery wasn't that you could choose which software to install, it was that there was no separation between programs, so that any random program you installed could add toolbars to your browser, steal all your passwords, etc. If iOS or Android made it easier to install apps outside the store, I highly doubt you'd see anywhere near the same level of problems, since everyth…

I would find it acceptable if side loading apps was allowed by default but sideloaded apps are blocked from the dangerous permissions like device admin and draw over screen. Apps that really do require this have to be checked by a maintainer or require the device to be in developer mode.

This way almost everyone is happy because most apps don't really require anything other than internet, camera and GPS which can be denied by the user.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#50

They're mixing so many issues and confusing the matter. They have discovered ad fraud, which is interesting, but doesn't actually directly harm the user (right?), just the advertisers and Google. But then to make sure they are propagating fear, they bring in the completely unrelated issue of data being sent to China. And there is some confusion there too - is it only through the (unnecessary) permissions that users a…

If the ad fraud runs in the background as claimed, it harms the user by wasting their battery.
Post reply on HN