Live data from Hacker News

Popular Google Play store apps are abusing permissions and committing ad fraud

buzzfeednews.com

151–160 of 178 posts

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#151
post #40

Earlier quoted context omitted.

The solution is what has been suggested earlier: allow users to choose their own 'store', don't lock them to a single vendor. This is already possible with Android where F-Droid is a good example of a 'store' where the chance of being exposed to these shenanigans is close to zero. Currently iOS users lack this option so for them the only way out is to change platform.

That doesn’t seem like much of an improvement: if it became popular, you’d see the same social attacks switch from getting people to install apps to enabling a new store. F-Droid is safer because it’s much smaller and mostly free software: that’s good for people who don’t want anything else but it seems unlikely to satisfy mainstream demand or survive a motivated attack.

Linux survived these attacks. Debian survived them. Ubuntu did. More or less all Linux distributions have been attacked but survived, many of them thrive.

Yes, this is free software. Being less susceptible to these problems has been one of the stated advantages of using such for a long time. Alternative 'stores' carrying 'pirated' non-free software do not have this advantage and can easily turn into dark places so the solution does not lie there.

Will people choose a 'boring' free software 'store' over a 'cool pirate store' (Arrrrr!)? Some will, some won't. Those who will will end up being mostly silent as the thing just works. Those who won't will be susceptible to the whims of those who put up those 'stores' and are likely to come home with a bit more than they asked for.

Some 'stores' will get a good reputation along the lines of that of F-Droid, some will get the reputation of being the place to go to get the latest craze but also the latest infection. Users will start making conscious decisions based on those reputations, just like they already do elsewhere.

Will opening up closed platforms like iOS for third-party software repositories get rid of these problems? No, it won't, it will even raise the average level of problematic software on that platform. The difference between closed systems and more open ones is not that the closed ones are inferior, it is that they limit the user's choice to get something which is better as well as worse than what the walled garden offers. In this context better can mean software which does not come with tracking, analytics, profiling and other such privacy-invading nonsense. I can get the source code and build it myself, I can host my own repository, only time limits where I can go. This is not true for the Google Play Store or the Apple Appstore, nor is it true for the Amazon equivalent or any of those Chinese alternatives. That is why I chose to use something like F-Droid.

By the way, there is nothing keeping e.g. Facebook or Twitter from releasing a free software version of their apps. Their value - and most of their profiling proficiency - lies in their platforms, not in the apps used to access them. They might lose any additional venues for leaching the user of data but they would gain some believability when they state that they're not up to no good. Of course there are plenty of alternative apps for these services so they don't really need to but they could if they wanted to.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#152

Earlier quoted context omitted.

Im generally not a fan of web apps but this is incorrect. https://developer.mozilla.org/en-US/docs/Web/API/Geolocation

I should have been more specific but my app needs to record GPS with the screen off and with the app not focused which web apps can't do.

I guess your app is Android only - I can't imagine this working well on any iOS device, regardless of being a native app.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#153
post #139

Earlier quoted context omitted.

I actually can't believe this. How in the name of all the is holy are we letting them get away with this. Sure, we talk about the problem a lot. But we need to take action. It seems every big corporation are abusing the trust we give them in some form or another. Please, for the love of God, can anybody prove me wrong. Are there any companies than don't abuse our trust?

Abuse your trust? The better question is why are you trusting them in the first place? If you actually read the TOS of a service, you'd know that they are usually quite forthright with what they are going to do. If a murderer knocks on your door, informs you that if you let them in they're going to brutally murder you, but you choose to ignore that because they brought you free stuff, you don't get to complain about…

That is a stupid analogy which I hope I don't even need to explain.

A terms of service is not a free pass to do whatever the fuck you want. Just because I agreed to Apple's terms of service doesn't mean they can turn me into a human centiPad, even if it says so in the small print.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#154

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

I'd say that the sandboxing introduced by mobile OSes today solves the vast majority of the problem. By isolating applications and introducing permissions, malware that can steal or encrypt user data isn't possible even for people installing those pirated APKs.

Don't trust Android or iOS or macOS sandbox. Google invests huge amounts of development time and research into Google Chrome JavaScript sandbox. It is the real wild west, there are malicious actors who want to break that sandbox. There are multiple layers of protection. Yet there are successful attacks. Much less people trying to break Android or iOS sandbox, because you can just ask for permission from Android and because Apple can kick bad app from the store and prevent infestation. It means that security of those sandboxes is worse, there are many undiscovered (or undisclosed) holes.

Check out history of Java sandbox with its numerous vulnerabilities. I have no reasons to expect anything different from built-in sandboxes. It's like relying on unix user permissions and allow to run anything under untrusted user. Works in theory, but you'll be owned pretty soon, because local root escalation vulnerabilities are not that rare.

In those days the only sandbox I would trust is JavaScript one. It's battle tested.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#155

Earlier quoted context omitted.

> These apps steal tens of thousands of dollars of ad revenue from my business monthly Avoiding ads is not stealing. Neither is wrapping someone else's content in ads.

> Neither is wrapping someone else's content in ads. What the hell are you talking about? If I take Office 2016, create custom launcher which will just pop ads here and there, offer it to companies, I can't possibly claim this as legal business anywhere where copyright law can be upheld

I'm not saying it's legal or anything of the sort. It's probably some kind of fraud or copyright infringement, but it's not theft.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#156

Earlier quoted context omitted.

> Neither is wrapping someone else's content in ads. What the hell are you talking about? If I take Office 2016, create custom launcher which will just pop ads here and there, offer it to companies, I can't possibly claim this as legal business anywhere where copyright law can be upheld

I'm not saying it's legal or anything of the sort. It's probably some kind of fraud or copyright infringement, but it's not theft.

Why not? You can't just someone else app and use it as if it was yours.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#157
post #40

Earlier quoted context omitted.

That doesn’t seem like much of an improvement: if it became popular, you’d see the same social attacks switch from getting people to install apps to enabling a new store. F-Droid is safer because it’s much smaller and mostly free software: that’s good for people who don’t want anything else but it seems unlikely to satisfy mainstream demand or survive a motivated attack.

Linux survived these attacks. Debian survived them. Ubuntu did. More or less all Linux distributions have been attacked but survived, many of them thrive. Yes, this is free software. Being less susceptible to these problems has been one of the stated advantages of using such for a long time. Alternative 'stores' carrying 'pirated' non-free software do not have this advantage and can easily turn into dark places so th…

> Linux survived these attacks. Debian survived them. Ubuntu did. More or less all Linux distributions have been attacked but survived, many of them thrive.

Really? Is there a huge market of mainstream consumer Linux software which I've missed in the past 3 decades of using it?

The answer is, of course, no. Linux distributions have mostly been used by developers and other IT people and there's never been the equivalent of the mainstream mobile app ecosystem used by people who are asked to make critical security decisions which they don't know how to answer. If there was an equivalent, there would be the same sleazy sites pushing free porn, games, taking successful apps and repackaging them, etc. that we see in the mobile/Windows desktop world, and normal people would routinely be socially-engineered to get access to free stuff, just as Linux users have for years been fooled into running binaries or installing packages. This isn't more widespread because there's not much money in it but if that were to change it would immediately require the same kind of hardening which every other consumer OS has had to make.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#158

Earlier quoted context omitted.

> Neither is wrapping someone else's content in ads. What the hell are you talking about? If I take Office 2016, create custom launcher which will just pop ads here and there, offer it to companies, I can't possibly claim this as legal business anywhere where copyright law can be upheld

I'm not saying it's legal or anything of the sort. It's probably some kind of fraud or copyright infringement, but it's not theft.

Accessing a paid service by taking the API key out of another app without the consent of the service provider would be theft of services. In most US states theft of services falls under the same law as theft of personal property.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#159

Earlier quoted context omitted.

I'm not saying it's legal or anything of the sort. It's probably some kind of fraud or copyright infringement, but it's not theft.

Why not? You can't just someone else app and use it as if it was yours.

Sure you can, that is what this post is about, it's just not legal to do so. But just because something is against the law doesn't make it theft anymore then it makes it murder.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#160
post #36

Installing f-droid and using more simple and open source apps is one of the best things I've done lately.

Its too bad its still flakey at updating apps. I've been using it for a few apps for many years, and I'd say easily half of app updates simply fail for non-obvious reasons. Its been this way across multiple devices and countless versions of Android, so I'm left to believe the problem is with F-droid itself.

I've had problems with YALP store suddenly being unable to find su and then no longer working. F-Droid is in the same boat where it gives you the choice of a few different methods to install apps, because it's still trying to find where it fits in.

IMHO that place is sideload as system app when you first install the OS. Which was my solution to the YALP issue.

(YALP store is not on my actual phone - that only has F-Droid)

Post reply on HN