Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

61–70 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#61
post #6

The OG Barcode Scanner app is getting absolutely throttled with negative reviews. But this posting seems to be about a clone app by a different developer. https://en.wikipedia.org/wiki/Barcode_Scanner_(application) https://play.google.com/store/apps/details?id=com.google.zxi...

I had this one (by ZXing Team) and never noticed any negative behaviour, but given that the default camera app now supports QR Code scanning I don't see a reason to keep the Barcode Scanner app.

Re: Barcode scanner app on Google Play infects 10M users with one update

#62
post #38
post #34

Earlier quoted context omitted.

Apple does not let you back out an update you made and regret. Apple does not block apps from using the network or give you any way to find out what they are doing and who they are talking to. In fact, apple does the opposite - it blocks apps that let you firewall your phone.

Applications like Charles [1] allow you monitor network connections and data closely. Apple do not actively prevent this. You can also setup a VPN to route traffic and strictly firewall. [1] https://www.charlesproxy.com

Charles is great, but it can't view the data for any app running pinned certificates.

Re: Barcode scanner app on Google Play infects 10M users with one update

#64
post #33

Stallman calls autoupdates a "universal backdoor".

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

> He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software.

We are not talking about patching. We are talking about updating.

> They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Yes. Vendors do not patch their SW. For the average SW developer fixing bugs is like castor oil. Remember the forced transition from Win 7 to Win 10 when a good OS was replaced by an abomination ? And no, 10 is not better securitywise than 7. There are lot of RCEs in 10. Did you ever play an EA game ? With Origin doing a 4GB update before playing ? On a 25 Mbps internet connection ?

So for me if you have a security patch for your sw i will apply it. Maybe after some buffer period in the case of known offenders (MS) depending on severity. If it's "performance and usability improvements" just forgetit. If you did't bother to write a changelog for your SW i will not waste my time and money (an internet connection is not free ) updating it.

Re: Barcode scanner app on Google Play infects 10M users with one update

#65
post #45
post #30

Earlier quoted context omitted.

Your dogmatic approach to updating would prevent you from installing a version _without_ malware attached. For example, a version of Xcode circulated in China was infected with malware and once Apple had detected it, they asked all developers to recompile and update their apps immediately. https://www.zdnet.com/article/how-malware-finally-infected-a... With your attitude, you wouldn't have necessarily seen the effica…

Every Google Play update prompt in My Apps has a description provided by the publisher. If there is an urgency to update and they don't say so, I'm not going to blithely accept every update. Ior example, had there not been the exploit risk, I would have left Chrome at the older version, as their new tabgroup implementation is horrible, and it doesn't even allow you to open a new tab without creating a group or going…

> Every Google Play update prompt in My Apps has a description provided by the publisher.

I hate to reply like this but, the vast majority of Google Play app updates go something like this:

"Updates."

"Fixes"

"..."

Having genuine changelogs would be glorious.

Apple and Google should require proper source and issue management, they could then generate changelogs automatically. Having that, they could then use machine learning against the code commits and issue titles to ensure that what people say are happening, are actually happening in the code.

I mean we've got ML that can generate code from natural language, I'm sure the bright sparks at Google and Apple could use some ML to, with a high degree of probability, say that the code does what the comment/issue says it does.

Re: Barcode scanner app on Google Play infects 10M users with one update

#66
post #63

So why aren't we hearing about someone being arrested? Google knows who their devs are. Law enforcement can demand they give up that info.

They are most likely Chinese. I’ve been getting asked by Chinese accounts on LinkedIn to let them use my account to submit their apps on the Google Play Store for a fraction of their revenue. I’m guessing there’s a similar scam going on here too.

Re: Barcode scanner app on Google Play infects 10M users with one update

#67
post #33

Stallman calls autoupdates a "universal backdoor".

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Basically all phones are behind a NAT/firewall. You can't connect to them directly.

Re: Barcode scanner app on Google Play infects 10M users with one update

#69
post #6

The OG Barcode Scanner app is getting absolutely throttled with negative reviews. But this posting seems to be about a clone app by a different developer. https://en.wikipedia.org/wiki/Barcode_Scanner_(application) https://play.google.com/store/apps/details?id=com.google.zxi...

It is also open source: https://github.com/zxing/zxing and hasn't had an update since 2019.

So will google fix these reviews like they did with RH? These are clearly wrong unlike RH...

Re: Barcode scanner app on Google Play infects 10M users with one update

#70
post #63

So why aren't we hearing about someone being arrested? Google knows who their devs are. Law enforcement can demand they give up that info.

Computer crime is so very rarely traced and prosecuted, like most white collar crime.
Post reply on HN