Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

21–30 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#21

Earlier quoted context omitted.

At least Apple doesn’t serve you malware or harvest your personal data for profit.

On the contrary, Apple has served malware to far more users than Google despite having far fewer total users. https://blog.lookout.com/xcodeghost-apps Apple also uses your GPS data to update its location service (for profit), and unlike Android offers no way to opt out — if you want to get your location on an iDevice, Apple will get it, too. If you want to do something crazy like write apps for your own device withou…

That's interesting to know, I was originally convinced by their marketing claiming the walled garden was at least helping a bit for security purpose but even that seems false.

Re: Google Play has been spreading advanced Android malware for years

#22
post #11

The wording of the title is interesting - how it puts all the responsibility onto Play store and none of it onto the people actually developing the software. We truly live in an age where the mass media demands that corporations censor and police everything we see and use. I wonder when they'll start targeting Linux and Windows for allowing you to download and run malicious programs without any corporation approving…

It's not the media, that's the stance Google themselves adopt with Google Play by acting as non-neutral gatekeepers.

Few people lack the intuitive understanding of the difference between free platforms and controlled ones. People don't blame Google Search for linking to Stormfront, but they would blame Facebook for hosting it. People don't blame Linux and Windows for allowing you to install malicious apps, because these allow you to install any apps.

Re: Google Play has been spreading advanced Android malware for years

#24
post #8

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

> which happened because the people found them to be better than the alternative

Walled garden only exists because mobile devices make self-install alternatives very difficult or impossible to get on purpose, otherwise they would not be able to compete in any ways.

Case in point, the Mac App Store and the Windows Store are both moderate failures despite a lot of technical & marketing push.

Re: Google Play has been spreading advanced Android malware for years

#25

Earlier quoted context omitted.

On the contrary, Apple has served malware to far more users than Google despite having far fewer total users. https://blog.lookout.com/xcodeghost-apps Apple also uses your GPS data to update its location service (for profit), and unlike Android offers no way to opt out — if you want to get your location on an iDevice, Apple will get it, too. If you want to do something crazy like write apps for your own device withou…

That's interesting to know, I was originally convinced by their marketing claiming the walled garden was at least helping a bit for security purpose but even that seems false.

It happened because developers in China were using a hacked version of XCode. The apps never escaped the sandbox.

I have no idea how Apple makes money by collecting location data.

Re: Google Play has been spreading advanced Android malware for years

#26

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

I never here users complain - just developers.

Re: Google Play has been spreading advanced Android malware for years

#27
post #11

The wording of the title is interesting - how it puts all the responsibility onto Play store and none of it onto the people actually developing the software. We truly live in an age where the mass media demands that corporations censor and police everything we see and use. I wonder when they'll start targeting Linux and Windows for allowing you to download and run malicious programs without any corporation approving…

Google advertises their store has "Google Play Protect" which promises to ensure no malware in the apps you download from them. Of course Google is going to get the blame when they make promises like that.

Re: Google Play has been spreading advanced Android malware for years

#28
post #9

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

But security is not binary. They (especially Apple) are doing something to limit the amount of fraudulent apps on their platform. I would strongly prefer having a free-for-all platform because I have some basic knowledge of information security. Most people don't.

How is your “knowledge” going to help you? Are you capable of vetting every app you install?

Re: Google Play has been spreading advanced Android malware for years

#29

Earlier quoted context omitted.

That's interesting to know, I was originally convinced by their marketing claiming the walled garden was at least helping a bit for security purpose but even that seems false.

It happened because developers in China were using a hacked version of XCode. The apps never escaped the sandbox. I have no idea how Apple makes money by collecting location data.

I separate their concept of the sandbox (app permissions) from the walled garden (the App Store & the lockdown of user install). You can totally have a sandbox without a walled garden. It seems that in this case, the walled garden did not help in any ways.

Re: Google Play has been spreading advanced Android malware for years

#30

Oh yeah, they can spread malware for months, but I submit one fucking app that allows you create signs for your business for COVID-19 and all of a sudden I get a 'Sensitive Events Violation Suspension' and get a ding on my Google Play account. Google has become Apple except worse because at least Apple is reachable.

App stores are a trap. As developers we should be doing everything we can to keep the web alive. Every power you cede to a third party gets abused sooner or later.
Post reply on HN