Live data from Hacker News

New 'unremovable' xHelper malware has infected 45,000 Android devices

zdnet.com

101–110 of 110 posts

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#101
post #10
post #8

Earlier quoted context omitted.

AV vendors have multiple conflicts of interest and should not be trusted.

Can you elaborate?

Yes, AV is in a position where a) it needs regular full priv access to your files and unencrypted web traffic, b) is in a highly competitive, low-margin field where the players are literally attacking each other on your machine [1] to stay even, and c) have enormous motivation to seek other funding sources based on their desktop position [2-5].

I didn't say they created malware, no, but they certainly wave that flag when someone finds some. And it's certainly in their interest to pursue all of these alternatives, or even have a bad third party violate THEM to do so. The money is on the table. Do they take it? They'd be foolish not to.

1. http://www.techradar.com/us/news/software/security-software/...

2. https://news.ycombinator.com/item?id=13079569

3. https://www.wsj.com/articles/russian-hackers-scanned-network...

4. https://wiki.mozilla.org/CA:Symantec_Issues

5. https://www.howtogeek.com/199829/avast-antivirus-was-spying-...

etc...

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#102
post #48

I'm really confused. How is it possible something like this survives a factory reset? To be fair, I have a very limited knowledge of hardware like this, but my assumption is a factory reset should remove EVERYTHING that didn't come on the phone put of the box. Some other comments are questioning weather this is happeneing to 'budget' devices sold by sketchy manufacturers. Would that explain something like this. I sur…

>but my assumption is a factory reset should remove EVERYTHING that didn't come on the phone put of the box A simple proof that this isn't the case is the fact that factory resets do not revert your phone back to the same OS version as it came with out of the box and it does not download an OS image to install. The only device I know that does this is macbooks have a built in recovery which can be used to download a…

I'm not sure this is the case. I have a Samsung Note 5. Its been a while since I factory reset, but Im almost positive it was back to the old android version. I always remember having to upgrade again.

Maybe my memory is incorrect, but I'd be surprised if it did not revert back. I'm thinking of reseting soon, so if I do I'll report back :)

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#103
post #33

Earlier quoted context omitted.

> that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. So very realistic then? Or have you not encountered the numerous incidents where cops plant and manufacture evidence to frame people for various reasons such as increasing their numbers for a promotion or bad culture leading to quotas for arrests/tickets/etc.?

Now imagine a wholly for-profit police force.

> imagine a wholly for-profit police force.

https://www.newyorker.com/humor/daily-shouts/l-p-d-libertari...

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#104
post #100

Earlier quoted context omitted.

That doesn't feel like the same thing at all . A shady developer tricking people into a subscription because they don't know any better is way different from malware that reinstalls itself even after a factory reset. People have to agree to pay for the subscription from an OS-level prompt in the first instance. They don't have a choice in the 2nd.

> A shady developer tricking people into a subscription because they don't know any better is way different from malware that reinstalls itself even after a factory reset. A shady developer tricking people and a shady website tricking people result in bad things. To get this trojan I'd need to go into settings and tick this box: https://q3fb03rfy3f4ahuzu2uy6e11-wpengine.netdna-ssl.com/wp-... Then go to the dodgy webs…

>I assume an Apple user like yourself wouldn't know about

Yes, truly... because there's no way that someone who uses an iPhone might know about the existence of Android/Windows/Linux/macOS or any other system that allows for sideloading and/or installing un-certed apps.

The point is, even if Apple allowed sideloading, there's no way that the iOS sandbox model would allow for what's being described here. The comparison wasn't accurate.

Your condescension and ignorance doesn't help that argument at all.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#105

Earlier quoted context omitted.

The analogy isn't useful because you're comparing a government to a corporation.

Of course it's not the same but it comes down to a party that wants to restrict your freedom in order to protect you.

One crucial difference is whether you can opt-out. Another big difference is the stated intention of the party/entity: i.e. Apple is not a company "of the people, by the people, and for the people".

My objection is that it's not that useful to only look at whether a party wants to restrict freedom. Personally, I don't think that's a very useful dimension at all -- I don't consider the existence of a road limiting to my freedom to drive wherever I feel like it.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#106
post #100

Earlier quoted context omitted.

That doesn't feel like the same thing at all . A shady developer tricking people into a subscription because they don't know any better is way different from malware that reinstalls itself even after a factory reset. People have to agree to pay for the subscription from an OS-level prompt in the first instance. They don't have a choice in the 2nd.

> A shady developer tricking people into a subscription because they don't know any better is way different from malware that reinstalls itself even after a factory reset. A shady developer tricking people and a shady website tricking people result in bad things. To get this trojan I'd need to go into settings and tick this box: https://q3fb03rfy3f4ahuzu2uy6e11-wpengine.netdna-ssl.com/wp-... Then go to the dodgy webs…

> And you can talk about how great Apple's security is but to fix this issue all Google has to do is remove that tick box in settings so no more sideloading apps.

And yet, they don’t.

> But that also comes back with drawbacks that I assume an Apple user like yourself wouldn't know about, because all you know is a walled garden.

Funny how Android users keep saying that. I’m an Android developer by profession, which is why I use an iPhone as my personal phone and would never recommend an Android device even to my worst enemy. I’ve seen how the sausage is made and it isn’t pretty. The best thing you can say about Android is that it’s free, which correctly reflects what it’s worth.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#107

Earlier quoted context omitted.

Of course it's not the same but it comes down to a party that wants to restrict your freedom in order to protect you.

One crucial difference is whether you can opt-out. Another big difference is the stated intention of the party/entity: i.e. Apple is not a company "of the people, by the people, and for the people". My objection is that it's not that useful to only look at whether a party wants to restrict freedom. Personally, I don't think that's a very useful dimension at all -- I don't consider the existence of a road limiting to…

From my point of view, I can't "opt-out" from Apple. Neither in business nor in private. And I tried.

Of course, you can always use another road or go completly off track. Like living in the woods?

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#108
post #89

>According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan. Ok, maybe don't do that?

You never had to deal with an untechnical user, had you?

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#109

Earlier quoted context omitted.

Sure, except that once you get past the idea of trusting others for your security, and instead learning and securing stuff yourself, you quickly realize that "tightly controlled" is just a synonym for "you don't really own your device, we just let you use it how we see fit". As so recently demonstrated by Apples ability to remove the HKmap.live app. In general really wonder why people still defend Apple these days. E…

So how do you “secure yourself” - besides having a device that runs an OS that doesn’t allow these types of exploits in the first place?

You pay attention to what you install, and take advantage of things like unlocking/rooting to remove apps or use a firewall app to limit access of other apps.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#110

Earlier quoted context omitted.

So how do you “secure yourself” - besides having a device that runs an OS that doesn’t allow these types of exploits in the first place?

You pay attention to what you install, and take advantage of things like unlocking/rooting to remove apps or use a firewall app to limit access of other apps.

That sounds like a lot of trouble to go through just to use a phone.

Do you also suggest defragging and do you have any tips for editing my himem.sys and config.sys files so I can play Doom?

Post reply on HN