Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

61–70 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#61
post #51

Earlier quoted context omitted.

Do you really expect it to say “Google Play Protect is infallible”? It’s obviously pitched as anti-malware and the fact that it’s not working is an issue despite them not saying it’s perfect.

The fact that it's failed to stop this particular attack does not mean this anti-malware solution is "not working".

I'm not really sure what you're arguing. An anti-malware system letting through malware is definitely not working as intended and should be fixed.

Re: Google Play has been spreading advanced Android malware for years

#62
post #37

Earlier quoted context omitted.

> which happened because the people found them to be better than the alternative Walled garden only exists because mobile devices make self-install alternatives very difficult or impossible to get on purpose, otherwise they would not be able to compete in any ways. Case in point, the Mac App Store and the Windows Store are both moderate failures despite a lot of technical & marketing push.

Which is why with every macOS and Windows release there is some small fine tuning to drive the herd into the sandboxing model. Like frogs cooking in water, macOS and Windows users will be eventually realize that all their apps are store based as well. And for everything else they get Web apps, including AAA games.

The sandbox isn't the problem.

The missing authority the user has over it is.

E.g. you can have no wallet gardens but still sandbox every single application (which btw. I would prefer).

Re: Google Play has been spreading advanced Android malware for years

#63
post #52

Earlier quoted context omitted.

Which AAA games are web apps?

The ones being served by Stadia, xCloud, GeForce NOW and PS Now. Plenty to choose from.

I don't know anybody nor recall seeing more than a handful of mentions online of anyone getting their playtime via those services.

Re: Google Play has been spreading advanced Android malware for years

#64
post #52

Earlier quoted context omitted.

The ones being served by Stadia, xCloud, GeForce NOW and PS Now. Plenty to choose from.

That's a pretty loose definition of a web app, but I agree that those services are pretty poor.

Well, one needs a browser to access them....

Re: Google Play has been spreading advanced Android malware for years

#65

Earlier quoted context omitted.

That's interesting to know, I was originally convinced by their marketing claiming the walled garden was at least helping a bit for security purpose but even that seems false.

It happened because developers in China were using a hacked version of XCode. The apps never escaped the sandbox. I have no idea how Apple makes money by collecting location data.

> developers in China were using a hacked version of XCode

Can you give us more details on this? Interested.

Re: Google Play has been spreading advanced Android malware for years

#66
post #33

Earlier quoted context omitted.

>unlike Android offers no way to opt out — if you want to get your location on an iDevice, Apple will get it, too. As far as I know there is not a way to opt out of this in (Googlified) Android. If you have Play Services installed (which you do, unless you've taken unreasonable steps to avoid it such as rooting and installing a 3rd party ROM), you get a dialog box popup whenever you enable location services which inf…

If you don't like Google, installing a community ROM that doesn't violate your privacy would be perfectly reasonable. If you want a megacorp service but not from a megacorp, I think you won't find that anywhere.

But then all banking apps stop working (including the 2FA apps "required" for using credit cards from some EU Banks; for EC cards you luckily still can use ChipTAN).

Also mobile payment will stop working, normally I wouldn't care about that but currently paying without touching anything is nice.

Then some apps you need for work might stop working.

Not even speaking about hounded of other apps.

The problem is to many app depend strongly on Google services which are not part of Android itself but shipped with every Google Android phone.

And to many institutions except you to either have a Google Android phone or a iPhone.

I could get away most of the time with a non Google Android phone but I will would need a second Google Android phone like 5 times a month or so.

Re: Google Play has been spreading advanced Android malware for years

#67
post #53

Earlier quoted context omitted.

I'd say that they are more than moderate failures. I've heard from many acquaintances who aren't as tech literate as myself that one of the major reasons they got rid of their iPhone was not being able to install applications from outside sources. Myself, I would never want to trust anything centralized.

Clearly the iPhone is a massive failure and everyone is getting rid of theirs. In what country are you seeing this?

I never said it was a massive failure, but many people have switched over the years to some form of Android after getting fed up.

Re: Google Play has been spreading advanced Android malware for years

#68
post #55

Earlier quoted context omitted.

Apps in the iOS App Store are allowed to embed silent spying that you can't disable (also known as spyware) that upload your location and activity data to third parties without your consent. You're deemed to have agreed to this as a user based on the App Store Terms of Service. Don't buy Apple's lies about privacy. It's just marketing.

The user decides if an app has access to his location.

Yes, but the permission is per-app. Let’s say I approve location for the app because the app’s function requires it: the third party spying SDKs embedded in the app send that location data off to third parties without notifying me or permitting me to stop it.

Apple permits this behavior in the App Store.

Furthermore, IP address is coarse location even if you don’t grant the app permission, via GeoIP databases.

Long story short, Apple allows apps in the store to embed silent, nonconsensual spyware that you can’t disable.

Re: Google Play has been spreading advanced Android malware for years

#69
post #51

Earlier quoted context omitted.

Do you really expect it to say “Google Play Protect is infallible”? It’s obviously pitched as anti-malware and the fact that it’s not working is an issue despite them not saying it’s perfect.

The fact that it's failed to stop this particular attack does not mean this anti-malware solution is "not working".

Except this isn't the first time happening; Google Store was fulled with malware forever. The techies will of course say it doesn't mean anti-malware solution, while greater masses will say it's deff an anti-virus of some sort by looking at it.

Re: Google Play has been spreading advanced Android malware for years

#70

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

[deleted]
Post reply on HN