Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

81–90 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#81

Earlier quoted context omitted.

So you realize your anecdotal usage doesn’t scale well to the general population, right?

I'm not sure what we're arguing about. I'm professionally involved in the field, I understand the risks when I press "download" or invoke a third-party script. I run things in temporary VMs. I only have Facebook, WhatsApp and Uber on my personal phone (those may be fraudulent, but on a whole other level). General population is vulnerable to all sorts of malware and social engineering. I've personally witnessed people…

How does this:

That's why I'm pro-walled-garden, as I've expressed in the original response.

Jibe with this?

"I would strongly prefer having a free-for-all platform"

Re: Google Play has been spreading advanced Android malware for years

#82
post #8

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

> There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sources of varying quality and convenience.

No they haven't. Given a fair choice customers have opted for the alternative the vast majority of the time.

The walled garden models have only worked when companies have engaged in anti-competitive behaviour.

Re: Google Play has been spreading advanced Android malware for years

#83
post #34

Why haven't antitrust lawsuits made it mandatory that you can chose your app store after first use like it happened with browsers?

They likely will eventually, but the browser verdict took a long time.

It's also unhelpful that many politicians have realised in retrospect that they quite like having single choke points that can be used to enact legislative control over the public.

Re: Google Play has been spreading advanced Android malware for years

#84

Earlier quoted context omitted.

I'm not sure what we're arguing about. I'm professionally involved in the field, I understand the risks when I press "download" or invoke a third-party script. I run things in temporary VMs. I only have Facebook, WhatsApp and Uber on my personal phone (those may be fraudulent, but on a whole other level). General population is vulnerable to all sorts of malware and social engineering. I've personally witnessed people…

How does this: That's why I'm pro-walled-garden, as I've expressed in the original response. Jibe with this? "I would strongly prefer having a free-for-all platform"

The original post was against the review process imposed by the platform owners. I wrote that while not perfect, it helps with security. Then there was one subjective statement on what I'd like for myself. I have limited knowledge of the language; I could have expressed that a little more clearly.

Re: Google Play has been spreading advanced Android malware for years

#85

Earlier quoted context omitted.

So would you have possibly side loaded an app from a trusted vendor like Epic? https://www.theguardian.com/games/2018/aug/10/fortnite-on-an... Back in the day would you have installed an app from a supposed trustworthy source like SourceForge? https://www.information-age.com/hotbed-malware-another-blow-... Or even further back, would you have trusted downloading software from CNet owned Download.com? https://malware.…

No, I only use Facebook and WhatsApp at the moment. I used to downloads lots of malware from porn sites back when I was much younger though.

So instead of lots of malware you just stick to one.

Re: Google Play has been spreading advanced Android malware for years

#86
post #68

Earlier quoted context omitted.

The user decides if an app has access to his location.

Yes, but the permission is per-app. Let’s say I approve location for the app because the app’s function requires it: the third party spying SDKs embedded in the app send that location data off to third parties without notifying me or permitting me to stop it. Apple permits this behavior in the App Store. Furthermore, IP address is coarse location even if you don’t grant the app permission, via GeoIP databases. Long s…

That's not how it works. If you install the app you are giving permission to the app to use your location however they want. It is pretty explicit.

From a legal perspective they are supposed to indicate as such in their terms and conditions, which you are supposed to read.

Re: Google Play has been spreading advanced Android malware for years

#87
post #68

Earlier quoted context omitted.

The user decides if an app has access to his location.

Yes, but the permission is per-app. Let’s say I approve location for the app because the app’s function requires it: the third party spying SDKs embedded in the app send that location data off to third parties without notifying me or permitting me to stop it. Apple permits this behavior in the App Store. Furthermore, IP address is coarse location even if you don’t grant the app permission, via GeoIP databases. Long s…

If an app's function requires location, how is it Apple's fault that the user decides it's better to enable that app to spy on him? If I use Waze do I expect privacy from it when it's essential that it knows my location?

Furthermore, on iPhone you get a warning when an app abuses the location permission, unlike Android.

At least on iPhones you have per app control, on Android it's either "location on" or "location off"

Re: Google Play has been spreading advanced Android malware for years

#88
post #65

Earlier quoted context omitted.

> developers in China were using a hacked version of XCode Can you give us more details on this? Interested.

https://unit42.paloaltonetworks.com/novel-malware-xcodeghost...

Oh, I remember this. I forgot it too easily. Fun times.

Re: Google Play has been spreading advanced Android malware for years

#89
post #67

Earlier quoted context omitted.

Clearly the iPhone is a massive failure and everyone is getting rid of theirs. In what country are you seeing this?

I never said it was a massive failure, but many people have switched over the years to some form of Android after getting fed up.

>>I'd say that they are more than moderate failures.

So... major failure? Is that what's in between moderate and massive?

If so, I'd love to have a major failure. :)

Re: Google Play has been spreading advanced Android malware for years

#90

Oh yeah, they can spread malware for months, but I submit one fucking app that allows you create signs for your business for COVID-19 and all of a sudden I get a 'Sensitive Events Violation Suspension' and get a ding on my Google Play account. Google has become Apple except worse because at least Apple is reachable.

Apple is pretty much the same, I've been trying to create a developer account for three entire weeks and it still shows as "pending" without info. I saw on the forums that for some people it can take months. It looks like some bureaucratic government body from the 90s. I now advise my friends to switch to Android if they want to see the app, there's a limit on what I can put with. These companies should just be broke…

i learned that you call them and it gets done immediately. submit, wait 24h, call. easy
Post reply on HN