Live data from Hacker News

CamScanner, a malicious Android app with more than 100M downloads in Google Play

kaspersky.com

121–130 of 155 posts

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#121

Earlier quoted context omitted.

This is clearly not the case. Not only is Android’s permission system more permissive, most Android phones don’t get updates as frequently and definitely not as far long as iOS.

In modern Android phones, the core system is updated one a month [if needed - which is often the case during the first year]. Android applications (including things like mail and browser) and a large part of the OS is updated immediately via the store. The permission system is being updated and apps are being rejected for bad user of permissions (check Reddit for the SMS permission stories)

And as far as the parts of the OS that don’t get updates?

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#122
post #35

I've been using this app for years and also telling other people to use it, so this sucks. If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

It's amazing to me that so few people are not aware of the excellent scanning apps from Google. They work better, you're not expanding your privacy risk ... and they're free and integrated with Google docs etc. * namely, Drive Scan and Photoscan

I use Google Docs all the time and need those and have never heard of them. Google is so frustrating sometimes.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#124

PlayProtect is not detecting and warning users about CamScanner even when it has been removed from the Playstore. I've tested it via manual scan on PlayProtect as well, no dice. Isn't that what it is supposed to do? Has anyone ever got any app flagged by PlayProtect? If it's useless, then rather I would disable it than to give it access to all my installed apps. Google Engineers here, please ping your Google Play tea…

Play Protect is not a malware scanner, it's a green check mark designed to lead people to believe they are protected.

https://www.av-test.org/en/antivirus/mobile-devices/

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#125
post #34

> So a dropper might be used to install malware that steals banking credentials or generates fake advertising clicks or signs up for fake subscriptions. This is basically wrong, you can't modify a browser or charge someone's card without breaking out of the sandbox. Worst case they could burn your cellular data or encrypt your photos and such if you gave it permission. Is there any evidence they maliciously used this…

> without breaking out of the sandbox.

Every Android Security Advisory I looked at contained at least one often multiple Elevation of Privilegues or straight Remote Code Execution holes - my Android One smartphone usally gets the updates 20-35 days after the release of the Advisory - I'm the only one in my wider family that even got a smartphone that still receives monthly security updates at all. Most of them are stuck on an old Android version with years old patch-levels. So I doubt this is hard at all. I have no idea if there are public exploits for these issues but they probably exist.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#126
post #123

Ironically this is right next to "Google just deleted my nearly 10-year-old free and open-source Android app" on the front page. False negatives and false positives.

At a sufficiently large scale, even rare events happen constantly.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#128
post #98

Earlier quoted context omitted.

That is and for many, always an issue. Adverts help pay for content, be that a game or website - people literally make a living that way that it has become a bit of a defacto approach. But when you are tied to including some code that goes off to a site that you have no or very little control over, you are outsourcing part of your company (web or app) into the hands of another in which, if they mess up. You are the t…

(sorry to be picky about an irrelevance but this one grates on me. "Ad" is an abbreviation not an acronym or initialisation - so no need to capitalize it as "AD". Same for "app" over "APP". Makes things hard to read for me as it sounds like someone shouting occasional words in an otherwise normal sentence!)

I normally wouldn't do this, but it's initialism not initialisation

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#129
Malicious code found in ad networks, but I still get downvoted every time I complain that a given website was unusable by me because after trying to enable some (hopefully safe) javascript domains it still wouldn't render in a usable form.

There is a problem here. Trying to protect yourself from third-party malware running on your machine breaks half the damn web because of our over-reliance on javascript frameworks and ad networks. We have to find a better way.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#130
post #123

Ironically this is right next to "Google just deleted my nearly 10-year-old free and open-source Android app" on the front page. False negatives and false positives.

IOW, Google is clearly failing to keep up and accurately monitor it's Play Store.

It is not an easy job to do even at small scales, and their scale is massive. But, it is the job they signed up for, and they need to properly provide resources for it (and it isn't like Google or Apple are short of resources).

Post reply on HN