Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

51–60 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#51
post #31

The only reason this was detected was very overt behavior - opening AD popups. So I guesstimate for each one of these we have 10 that go undetected. This means the whole ecosystem is broken, as there is no reason this will happen only for updates and not for new apps as well. Apple's ecosystem is somewhat better, but I can't imagine they go through every line of code in each package, so most of their review is probab…

This happened on ios for me years ago. I had two apps that radically changed their business model (owner?) through updates with no recourse. I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remi…

School tried to make me use camscanner, glad I took the extra effort to do something else. Thanks for the anecdote.

Re: Barcode scanner app on Google Play infects 10M users with one update

#52
post #44
post #41

Earlier quoted context omitted.

Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.

But if you were slow updating you could avoid a malware once it was known.

Also if you were slow updating, you could avoid critical security patches (and many people did)

Re: Barcode scanner app on Google Play infects 10M users with one update

#53
post #36

When the Apple App Store contained malware compiled by unsuspected Chinese developers using a local cache of Xcode [1], Apple emailed the developers to prompt them to update their application immediately and removed them from sale. Apple also contacted users directly to alert them of whatever apps they had purchased on the App Store were compromised so they could monitor for updates, or remove the app entirely. Has G…

Google can disable apps on the users' devices.

https://developers.google.com/android/play-protect/client-pr...

Re: Barcode scanner app on Google Play infects 10M users with one update

#54
post #52
post #44

Earlier quoted context omitted.

But if you were slow updating you could avoid a malware once it was known.

Also if you were slow updating, you could avoid critical security patches (and many people did)

Yeah and missing security updates was WAY more common, autoupdates is the lesser of the two evils by far ...

Re: Barcode scanner app on Google Play infects 10M users with one update

#55
post #52
post #44

Earlier quoted context omitted.

But if you were slow updating you could avoid a malware once it was known.

Also if you were slow updating, you could avoid critical security patches (and many people did)

Which affect the OS mostly and not individual apps. Funnily enough OS updates are usually not automatic. Which I think is a good thing because vendors keep mixing them with "feature updates" which end up making things worse (looking at you Samsung).

I'd love for Google to take away the security update channel from the phone vendors and auto-update ONLY security-related things through that.

Re: Barcode scanner app on Google Play infects 10M users with one update

#56
post #42
post #38

Earlier quoted context omitted.

Applications like Charles [1] allow you monitor network connections and data closely. Apple do not actively prevent this. You can also setup a VPN to route traffic and strictly firewall. [1] https://www.charlesproxy.com

Charles must have some wild carveout from apple. All other apps that do that have been shut down. I still run a very old version of adblockios that starts a vpn (proxy) at 127.0.0.1 and blocks traffic that way. mostly.

I think the parental control app Circle does something similar (faux-vpn proxy). When I tried using Circle, it seemed a bit convoluted to me, so we ended up uninstalling it. So, I’m not sure how unique this method is. But, I’m not sure I can think of another way for a network blocking/security app to work on iOS.

Re: Barcode scanner app on Google Play infects 10M users with one update

#57
post #27

Earlier quoted context omitted.

I wonder if there's a coordinated effort to exploit barcode reader apps, because (at least where I'm from) its becoming a government mandated Covid tracing thing to use a QR code to "check in" to certain classes of businesses/venues? I bet there's a _huge_ increase in use of QR code scanning apps compared to this the last year...

Its kind of amazing that there isnt an official qr code scanner app preinstalled on phones given how ubiquitous QR codes are.

There is, on Android point the camera at a QR code and it will scan/read it.

Re: Barcode scanner app on Google Play infects 10M users with one update

#58
post #43
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

There's a third possibility, and I think it's Stallman's ideal computing landscape: all users care deeply about the code running on their machines and they are competent in applying and vetting patches, building from source, etc. It's unrealistic, sure, but it sounds nice right about now.

I think back when he posted it, it might have been possible for sufficiently motivated and talented individuals to do such vetting, albeit even then it would have been a stretch. Nowadays the amount of code running on various devices in a single home has increased so dramatically...

Think of TV remotes. They used to work with infrared. Nowadays, there are bluetooth remotes (not sure how widely deployed they are, but at least some vendors offer them instead of IR remotes). An infrared device can be send only. No way to hack it even if you have an infrared sender in range. The pattern transmitted was quite simple. The bluetooth protocol however requires both sending and receiving ability. Bluetooth stack is in the tens of thousands of lines range. There will be a security bug somewhere...

Re: Barcode scanner app on Google Play infects 10M users with one update

#59
post #19

Earlier quoted context omitted.

I don’t think my past two phones (one Android, one iOS) have built in QR scanning, or at least it’s not very discoverable. No fun to have to find something in an App Store when it all looks like 7 year old malware.

You can point the builtin Camera app on iOS to any QR code, it will pick it up just fine.

Same with Android

Re: Barcode scanner app on Google Play infects 10M users with one update

#60
post #6

The OG Barcode Scanner app is getting absolutely throttled with negative reviews. But this posting seems to be about a clone app by a different developer. https://en.wikipedia.org/wiki/Barcode_Scanner_(application) https://play.google.com/store/apps/details?id=com.google.zxi...

Yeah it's a really bad idea that they just called the app "Barcode Crossing" instead of "Zebra Crossing" or whatever. Completely generic and impossible to defend the brand.
Post reply on HN