Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

31–40 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#31

Earlier quoted context omitted.

It happened because developers in China were using a hacked version of XCode. The apps never escaped the sandbox. I have no idea how Apple makes money by collecting location data.

I separate their concept of the sandbox (app permissions) from the walled garden (the App Store & the lockdown of user install). You can totally have a sandbox without a walled garden. It seems that in this case, the walled garden did not help in any ways.

This is all the apps could do.

The malware removes information off the device like the device’s name, country, and unique identifiers.

This part is complete conjecture.

According to Palo Alto Networks, it may also have the ability to push dialogue boxes to your iPhone or iPad’s screen. Theoretically, a bad guy could use one of these dialogues to steal your username and password or other personal information. The malware may also be able to open websites in your mobile browser, which could be used for a variety of malicious purposes again including phishing and installing other potentially malicious software.

Re: Google Play has been spreading advanced Android malware for years

#32
post #8

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

You misinterpreted. OP was saying that "Apple has walled garden while Google is open" farce is dying and this another confirmation.

Sadly people in general can't be trusted to make good decisions because of lack of knowledge and preference of short term gratification over long term well-being.

Re: Google Play has been spreading advanced Android malware for years

#33

Earlier quoted context omitted.

At least Apple doesn’t serve you malware or harvest your personal data for profit.

On the contrary, Apple has served malware to far more users than Google despite having far fewer total users. https://blog.lookout.com/xcodeghost-apps Apple also uses your GPS data to update its location service (for profit), and unlike Android offers no way to opt out — if you want to get your location on an iDevice, Apple will get it, too. If you want to do something crazy like write apps for your own device withou…

>unlike Android offers no way to opt out — if you want to get your location on an iDevice, Apple will get it, too.

As far as I know there is not a way to opt out of this in (Googlified) Android. If you have Play Services installed (which you do, unless you've taken unreasonable steps to avoid it such as rooting and installing a 3rd party ROM), you get a dialog box popup whenever you enable location services which informs you that Google will be watching (it's framed as a consent dialog, but if you decline then location services will not be enabled). And you need location services even to use the GPS.

Re: Google Play has been spreading advanced Android malware for years

#36
post #22
post #11

The wording of the title is interesting - how it puts all the responsibility onto Play store and none of it onto the people actually developing the software. We truly live in an age where the mass media demands that corporations censor and police everything we see and use. I wonder when they'll start targeting Linux and Windows for allowing you to download and run malicious programs without any corporation approving…

It's not the media, that's the stance Google themselves adopt with Google Play by acting as non-neutral gatekeepers. Few people lack the intuitive understanding of the difference between free platforms and controlled ones. People don't blame Google Search for linking to Stormfront, but they would blame Facebook for hosting it. People don't blame Linux and Windows for allowing you to install malicious apps, because th…

>People don't blame Linux and Windows for allowing you to install malicious apps, because these allow you to install any apps.

Ah you've really put your finger on something there. The entire concept of an app store, gatekept through a series of hoops to jump through and from which the company takes n% of profit where n is some shockingly large percentage, is a highly costly departure from the traditional model of "obtain software from third party, install". The justification for this mafia-like intercession between vendor and customer has always been "for your protection". If they don't provide any protection, why do we tolerate this racket at all?

Re: Google Play has been spreading advanced Android malware for years

#37
post #8

Earlier quoted context omitted.

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

> which happened because the people found them to be better than the alternative Walled garden only exists because mobile devices make self-install alternatives very difficult or impossible to get on purpose, otherwise they would not be able to compete in any ways. Case in point, the Mac App Store and the Windows Store are both moderate failures despite a lot of technical & marketing push.

Which is why with every macOS and Windows release there is some small fine tuning to drive the herd into the sandboxing model.

Like frogs cooking in water, macOS and Windows users will be eventually realize that all their apps are store based as well.

And for everything else they get Web apps, including AAA games.

Re: Google Play has been spreading advanced Android malware for years

#38

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

Google play != Apple App Store

Good comment, I was just about to confuse them.

Re: Google Play has been spreading advanced Android malware for years

#40
post #8

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

The authority isn't trustworthy though. They're a direct conduit to malware. That's the point here.

And try not to conflate walled gardens with software repositories. The benefits of the latter are available without the wall. The wall is significant because it stops you making your own trust judgements.

Post reply on HN