Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

71–80 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#71
post #11

The wording of the title is interesting - how it puts all the responsibility onto Play store and none of it onto the people actually developing the software. We truly live in an age where the mass media demands that corporations censor and police everything we see and use. I wonder when they'll start targeting Linux and Windows for allowing you to download and run malicious programs without any corporation approving…

Besides what other comments noted there is the problem that sometimes Google knowingly tolerates software incompatible with their AGBs and through this endangering the privacy of users.

If I remember correctly TickTock was such a case.

Re: Google Play has been spreading advanced Android malware for years

#72
post #64

Earlier quoted context omitted.

That's a pretty loose definition of a web app, but I agree that those services are pretty poor.

Well, one needs a browser to access them....

I guess I’m splitting hairs. At least these systems aren’t the only delivery method for games, but who knows what will happen in the future.

Re: Google Play has been spreading advanced Android malware for years

#73
post #34

Why haven't antitrust lawsuits made it mandatory that you can chose your app store after first use like it happened with browsers?

I currently have F-Droid installed on my stock phone and Google did nothing to stop me other than a single "unknown app" warning.

Also, that's not how it works with browsers. You have one browser installed. I don't think I've ever seen windows or mac (or any linux distro I've tried) ask which browser should be installed. There's just the default one and the choice to install anything else.

Re: Google Play has been spreading advanced Android malware for years

#74

Earlier quoted context omitted.

So would you have possibly side loaded an app from a trusted vendor like Epic? https://www.theguardian.com/games/2018/aug/10/fortnite-on-an... Back in the day would you have installed an app from a supposed trustworthy source like SourceForge? https://www.information-age.com/hotbed-malware-another-blow-... Or even further back, would you have trusted downloading software from CNet owned Download.com? https://malware.…

No, I only use Facebook and WhatsApp at the moment. I used to downloads lots of malware from porn sites back when I was much younger though.

So you realize your anecdotal usage doesn’t scale well to the general population, right?

Re: Google Play has been spreading advanced Android malware for years

#75
post #65

Earlier quoted context omitted.

It happened because developers in China were using a hacked version of XCode. The apps never escaped the sandbox. I have no idea how Apple makes money by collecting location data.

> developers in China were using a hacked version of XCode Can you give us more details on this? Interested.

https://unit42.paloaltonetworks.com/novel-malware-xcodeghost...

Re: Google Play has been spreading advanced Android malware for years

#76
post #37

Earlier quoted context omitted.

Which is why with every macOS and Windows release there is some small fine tuning to drive the herd into the sandboxing model. Like frogs cooking in water, macOS and Windows users will be eventually realize that all their apps are store based as well. And for everything else they get Web apps, including AAA games.

Which AAA games are web apps?

Kantai Collection ? ;-)

Re: Google Play has been spreading advanced Android malware for years

#77

Earlier quoted context omitted.

No, I only use Facebook and WhatsApp at the moment. I used to downloads lots of malware from porn sites back when I was much younger though.

So you realize your anecdotal usage doesn’t scale well to the general population, right?

I'm not sure what we're arguing about. I'm professionally involved in the field, I understand the risks when I press "download" or invoke a third-party script. I run things in temporary VMs. I only have Facebook, WhatsApp and Uber on my personal phone (those may be fraudulent, but on a whole other level).

General population is vulnerable to all sorts of malware and social engineering. I've personally witnessed people dear to me fall for the Clean you Mac javascript scams. That's why I'm pro-walled-garden, as I've expressed in the original response.

Re: Google Play has been spreading advanced Android malware for years

#78
post #8

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

> I would still prefer to have to trust just one authority for my platform than a multitude of random developers.

Single point of failure.

> > Let this be another nail in the coffin of the "walled garden" farce.

> There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sources of varying quality and convenience.

No. The people have no alternative. How many people are able to install F-Droid on theyr phone ?

Re: Google Play has been spreading advanced Android malware for years

#79
post #55

Earlier quoted context omitted.

Apps in the iOS App Store are allowed to embed silent spying that you can't disable (also known as spyware) that upload your location and activity data to third parties without your consent. You're deemed to have agreed to this as a user based on the App Store Terms of Service. Don't buy Apple's lies about privacy. It's just marketing.

The user decides if an app has access to his location.

The user isn’t assumed to be male. So in your sentence the preferred phrasing is “their location.”

Re: Google Play has been spreading advanced Android malware for years

#80
post #8

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

[deleted]
Post reply on HN