Live data from Hacker News

Popular Google Play store apps are abusing permissions and committing ad fraud

buzzfeednews.com

51–60 of 178 posts

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#51
post #2

> As noted earlier in this thread, I didn't go looking for Chinese developers for this story. But if you go hunting for permissions-abusing apps, this is where you might end up. … https://twitter.com/CraigSilverman/status/111862075124903936...

Cheaper labor, I suppose.

I bet Eastern Europe is also represented.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#52
post #33

Earlier quoted context omitted.

The solution is what has been suggested earlier: allow users to choose their own 'store', don't lock them to a single vendor. This is already possible with Android where F-Droid is a good example of a 'store' where the chance of being exposed to these shenanigans is close to zero. Currently iOS users lack this option so for them the only way out is to change platform.

Another nice thing about F-Droid is that it uses Linux style "repositories" meaning that individuals/companies can setup repos for apps without needing to build their own custom app store. There are also multiple independent implementations of the F-droid client: https://gitlab.com/gdroid/gdroidclient/ https://github.com/SkyzohKey/M-Droid

I am told thses software repos are super useful for the 3rd world because phone stores can run a local app repo and people can download apps without using their very limited internet data. Fdroid also allows local app transfers to people near you.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#53

It's not just ad fraud, they've been copying information like whatsapp phone number, reddit username, telegram username etc. https://www.reddit.com/r/miband/comments/8eqtve/why_did_mifi...

I don't know what to make of MiFit copying all such information. I had assumed they copy it to show notifications on the watch. Does Lumen reveal that Xiaomi is sending that data to their own servers?

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#54
There are several app categories which become breeding ground for malware.

- battery booster - phone cleaner - anti virus - note taking app - file manager - ···

For risk management from getting banned, those adware companies, will usually register multiple accounts, with offshore address in Hong Kong or Singapore.

This is a good starting move by Google, but not enough still. We still see companies like Cheetah mobile, Du group being active in Google Play Store.

Those companies (and their associated accounts which distributes malware) who caught red-handed, should be banned permanently.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#55
post #5

> Google confirmed it found fake ad clicking on all 6 apps, and said ad fraud was against Play store policy. So why aren't you removing the apps, I asked. They said they banned them from ad products and were still investigating. Really? Finally, not long ago, Google removed them. What's wrong with this guy? Does he not understand what investigating means? God forbid Google actually investigates claims of malfeasance.

Hi! I'm the author of the story and want to note that I only asked Google why it wasn't removing the apps after their investigation confirmed a major policy infraction. By then their investigation was close to a week old.

Google confirmed that these apps were committing ad fraud, and told me that ad fraud is against Play store policy. Yet the company was going to keep the apps in the store. That didn't make sense to me. Fortunately, they reversed their position.

(Also, in case it matters, I didn't submit my story here. But I always appreciate the interesting threads on my ad fraud stories.)

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#56
post #21

the locked in store model has completely failed. both for ios and android it is a terrible experience compared to PC. you are stuck with only the search tools the hardware maker gives you, often designed in a user hostile way (ios brings up ads) and no way to bail out to a different store. as well the monoculture leads to a race to the bottom with garbage programs shoving their way to the top via misleading a dishone…

I feel the problem is the complexity of permissions models. Rather than expose many fine-grained permissions, apps ask for wide ranging permissions. Good apps and Bad apps. because the good apps are written naievely from days past and didn't know there is now a specific APP_PERMISSION_THIS_THING rather than 'all files' Because even good apps ask for all things, It cannot be used as a filter to determin bad apps.

With physical consumer products this used to be solved by the distributor and retail buyer chain.

Company makes a product and provides samples to the distributors buyers who then run it through the wringer. If it's crap then they don't order any. If it's 'good' then they'll market it to the retail buyers who place orders if they think they can sell it (and it's not crap).

None of that exists in the 'app market'. If it did then you'd submit an app to a distributor who would notice you're sending private user data to a Chinese website and they'll not only not market it, they'll never touch any of your stuff again.

The downside of that system is 99.99% of apps out there would never get installed on a phone in the wild.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#57
post #5

> Google confirmed it found fake ad clicking on all 6 apps, and said ad fraud was against Play store policy. So why aren't you removing the apps, I asked. They said they banned them from ad products and were still investigating. Really? Finally, not long ago, Google removed them. What's wrong with this guy? Does he not understand what investigating means? God forbid Google actually investigates claims of malfeasance.

Hi! I'm the author of the story and want to note that I only asked Google why it wasn't removing the apps after their investigation confirmed a major policy infraction. By then their investigation was close to a week old. Google confirmed that these apps were committing ad fraud, and told me that ad fraud is against Play store policy. Yet the company was going to keep the apps in the store. That didn't make sense to…

Did you ask why those companies (Cheetah mobile, Du group,...) which caught red-handed still allow to distribute apps in Google Play store?

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#58
post #56
post #21

Earlier quoted context omitted.

I feel the problem is the complexity of permissions models. Rather than expose many fine-grained permissions, apps ask for wide ranging permissions. Good apps and Bad apps. because the good apps are written naievely from days past and didn't know there is now a specific APP_PERMISSION_THIS_THING rather than 'all files' Because even good apps ask for all things, It cannot be used as a filter to determin bad apps.

With physical consumer products this used to be solved by the distributor and retail buyer chain. Company makes a product and provides samples to the distributors buyers who then run it through the wringer. If it's crap then they don't order any. If it's 'good' then they'll market it to the retail buyers who place orders if they think they can sell it (and it's not crap). None of that exists in the 'app market'. If i…

When the app is free, there's no incentive for the consumer to check like they would for white goods.

What's really needed is the abolishment of ad driven revenue model. If the user derives value from the app, they ought to pay for it. This way, the app developer is incentivized to make the app better for the consumer, rather than attempt to generate revenue thru illicit/anti-user means.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#59

THIS, among many other reasons, is why I (and my wife), switched to the iPhone.

That is a not a cure-all solution. It may be better as Apple has a higher barrier of entry into their store but those apps still exist. And Apple doesn't remove these apps right away either, for instance it took Apple one month to remove the app that was sending browser data to China.

https://www.macrumors.com/2018/09/07/adware-doctor-stealing-...

https://www.forbes.com/sites/bernardmarr/2015/10/20/data-thi...

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#60
post #49
post #41

Earlier quoted context omitted.

The problem with early 2000's-style software delivery wasn't that you could choose which software to install, it was that there was no separation between programs, so that any random program you installed could add toolbars to your browser, steal all your passwords, etc. If iOS or Android made it easier to install apps outside the store, I highly doubt you'd see anywhere near the same level of problems, since everyth…

I would find it acceptable if side loading apps was allowed by default but sideloaded apps are blocked from the dangerous permissions like device admin and draw over screen. Apps that really do require this have to be checked by a maintainer or require the device to be in developer mode. This way almost everyone is happy because most apps don't really require anything other than internet, camera and GPS which can be…

Isn’t that what native web apps are for, where you Share > Home Screen and they store themselves in local storage in the browser cache?
Post reply on HN