Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

101–110 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#101
It's emotionally difficult to find out about flaws in something you trust. I think humans really like black and white thinking, and crave association with people and institutions with blemish-free reputations. But the truth is that nothing and no-one is blemish free, especially if you zoom in on them enough. If you let it, then this truth can make you feel like you can't trust anything or anyone.

But its not true. You can trust. Although blemishes are universal, the scale of the blemishes are not. The key to trusting again in a world of flaws and faults is perspective. Is the flaw large or small? Does the agent accept it and want to fix it, or do they deny it exists (a much worse problem!)?

Everything has flaws, everyone makes mistakes, often people behave badly. That is never going to change. The thing we have to judge is whether the self-corrective systems in place are doing their jobs to acknowledge and repair the damage. IOW, making a mistake shouldn't determine trust, but failing to address the mistake should. One might call it "second-order trust". If you accept that, then the missing piece of this story is Google's response -- although they removed the offending malware from the Play Store, the journalist didn't apparently contact Google for anything else, like what steps they are taking (if any) to prevent this sort of thing from happening again. Ars didn't say anything about contacting Google, so I'd say that is an indication of lazy journalism, itself a sad but endemic problem in a world where we all have another false belief, that useful screens should be free (as in beer).

Re: Google Play has been spreading advanced Android malware for years

#102

Tin foil hat on. We had these iOS zero days and now conveniently we get something about Android security.

If you think this is the only news article that has ever talked negatively about Android security, I'd recommend reading the news more often.

Re: Google Play has been spreading advanced Android malware for years

#103
post #8

Earlier quoted context omitted.

I would still prefer to have to trust just one authority for my platform than a multitude of random developers. > Let this be another nail in the coffin of the "walled garden" farce. There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sour…

> There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sources of varying quality and convenience. No they haven't. Given a fair choice customers have opted for the alternative the vast majority of the time. The walled garden models have on…

> Given a fair choice customers have opted for the alternative the vast majority of the time.

As in, Steam versus... Buying and downloading directly from the publishers' websites?

The Xbox and PlayStation stores? The Nintendo eShop?

Re: Google Play has been spreading advanced Android malware for years

#104
post #95

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

And yet Apple's walled garden is stronger and hasn't had anywhere near the malware problem that Google's has? I don't understand your point. Privacy is where these companies' interests might not be aligned with users; when it comes to security , they very much are. It's just that for Google that's limited to their own services; they don't care so much when it comes to Android as a broader platform. But even then thei…

This used to be true. But both Google and Apple release badware numbers and independent analysts do as well. Badware rates are similar on both stores and have been for several years. Play used to be considerably worse than the Apple store, but that is no longer the case.

Being late to take security seriously has harmed google though, since this idea is now out there in the wild and keeps getting repeated regardless of the current evidence.

Re: Google Play has been spreading advanced Android malware for years

#105
post #92

Earlier quoted context omitted.

> I would still prefer to have to trust just one authority for my platform than a multitude of random developers. These are not the only two options. What about multiple authorities, but not random individual developers? That's basically how it works with e.g. game stores on PC (though Steam is certainly the largest), or package repositories on Linux. Like you, I like being able to trust an authority to vet the softw…

When it comes to the system's core sandboxing mechanism, only one authority can sign the certificates and provision capabilities etc. If multiple authorities can sign apps, it sort of defeats the point and makes the sandboxing less trustworthy. Right now, I can either: Rest assured that an app is sandboxed (via the App Store or macOS Notarization) or choose to let it run anyway (on macOS.) A dev could notarize their…

HTTPS has multiple authorities. do you use HTTPS?

Re: Google Play has been spreading advanced Android malware for years

#106

Earlier quoted context omitted.

> which happened because the people found them to be better than the alternative Walled garden only exists because mobile devices make self-install alternatives very difficult or impossible to get on purpose, otherwise they would not be able to compete in any ways. Case in point, the Mac App Store and the Windows Store are both moderate failures despite a lot of technical & marketing push.

Most of the apps on my Mac are from the App Store and I wish all of them were. The Mac App Store is not a failure from the user side, it's where users would look first. Nobody wants to have to go to different websites/repositories every N days to update all of their apps/drivers, or put up with spam from 10 different update notification mechanisms. I still remember that hell from barely 12 years ago. Why do you think…

You don't need a walled garden for that, a unified update api would suffice.

Re: Google Play has been spreading advanced Android malware for years

#107
post #52

Earlier quoted context omitted.

The ones being served by Stadia, xCloud, GeForce NOW and PS Now. Plenty to choose from.

I don't know anybody nor recall seeing more than a handful of mentions online of anyone getting their playtime via those services.

The only demographic that matters in the long run is the youngest demographic, and that demographic is the most likely to own/use very underpowered hardware (Since they don't have their own money to spend on nicer hardware. Often they use hardware issued to them by their schools, or hand-me-down hardware from older siblings or their parents.) The specific implementations of Stadia/etc may not prove successful, but eventually I expect a service like this to overtake the alternatives for very young users, and subsequently, achieve dominance when those young users come to view those services as normal and familiar.

Re: Google Play has been spreading advanced Android malware for years

#108

Earlier quoted context omitted.

Most of the apps on my Mac are from the App Store and I wish all of them were. The Mac App Store is not a failure from the user side, it's where users would look first. Nobody wants to have to go to different websites/repositories every N days to update all of their apps/drivers, or put up with spam from 10 different update notification mechanisms. I still remember that hell from barely 12 years ago. Why do you think…

You don't need a walled garden for that, a unified update api would suffice.

So much this. Linux distros with popular package managers offer official and 3rd party sources through one API. It's a dream compared to Windows and Mac IMO

Re: Google Play has been spreading advanced Android malware for years

#109
post #105

Earlier quoted context omitted.

When it comes to the system's core sandboxing mechanism, only one authority can sign the certificates and provision capabilities etc. If multiple authorities can sign apps, it sort of defeats the point and makes the sandboxing less trustworthy. Right now, I can either: Rest assured that an app is sandboxed (via the App Store or macOS Notarization) or choose to let it run anyway (on macOS.) A dev could notarize their…

HTTPS has multiple authorities. do you use HTTPS?

That's not a good analogy for OS sandboxing:

• Will third-parties have the same standards for checking if an app uses only the authorized APIs and gating privacy/resource access?

• What happens when Apple/Google introduce new OS APIs, will those third-party signing authorities update their standards at the same time?

• What if a third-party goes rogue and starts signing malicious apps? How and how soon will we know?

Re: Google Play has been spreading advanced Android malware for years

#110
post #17

Oh yeah, they can spread malware for months, but I submit one fucking app that allows you create signs for your business for COVID-19 and all of a sudden I get a 'Sensitive Events Violation Suspension' and get a ding on my Google Play account. Google has become Apple except worse because at least Apple is reachable.

why would anyone need an app to print a text stating their business is closed? probably someone was just looking for any reason to get rid of this.

Not closed... it's an app to generate signs from your phone about social distancing and other measures that are the law in some states.
Post reply on HN