Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

71–80 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#71
post #61
post #6

The OG Barcode Scanner app is getting absolutely throttled with negative reviews. But this posting seems to be about a clone app by a different developer. https://en.wikipedia.org/wiki/Barcode_Scanner_(application) https://play.google.com/store/apps/details?id=com.google.zxi...

I had this one (by ZXing Team) and never noticed any negative behaviour, but given that the default camera app now supports QR Code scanning I don't see a reason to keep the Barcode Scanner app.

Which default camera app? From which version?

(The proliferation of manufacturer camera apps is one of the worst things about android)

Re: Barcode scanner app on Google Play infects 10M users with one update

#73
post #70
post #63

So why aren't we hearing about someone being arrested? Google knows who their devs are. Law enforcement can demand they give up that info.

Computer crime is so very rarely traced and prosecuted, like most white collar crime.

Right, which is a massive problem. If these people and those like them were prosecuted then we'd have far less of a problem.

Re: Barcode scanner app on Google Play infects 10M users with one update

#74
post #64
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

> He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. We are not talking about patching. We are talking about updating. > They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software? Yes. Vend…

What stops them bundling something malicious into the “security patch” and then not writing it into the change log?

Re: Barcode scanner app on Google Play infects 10M users with one update

#76
post #33

Stallman calls autoupdates a "universal backdoor".

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Maybe I'm a luddite but updates are not always necessary. It's a barcode app, what updates does it need? Is there a cve that needs to be patched? No? Then I don't need a new version

Re: Barcode scanner app on Google Play infects 10M users with one update

#77
post #64
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

> He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. We are not talking about patching. We are talking about updating. > They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software? Yes. Vend…

> We are not talking about patching. We are talking about updating.

No, he's talking about all auto updates. Here's the interview with the quote in question: https://archive.org/details/LundukeHourApril14RMS

Re: Barcode scanner app on Google Play infects 10M users with one update

#78
post #23

I found this behavior in the Barcode Scanner app by "the space team" That was not one that was mentioned by the article It's url: https://play.google.com/store/apps/details?id=com.qrcodescan... (See the reviews)

I also found this pop-up add behaviour Saturday (6th) morning. I distinctly remember looking at this app last year when a different barcode scanner had an issue and it was not owned by "the space team" then,maybe a takeover? App now uninstalled

Re: Barcode scanner app on Google Play infects 10M users with one update

#79
post #67
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Basically all phones are behind a NAT/firewall. You can't connect to them directly.

They can connect to whatever they want, it's more than enough.

Re: Barcode scanner app on Google Play infects 10M users with one update

#80
post #76
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Maybe I'm a luddite but updates are not always necessary. It's a barcode app, what updates does it need? Is there a cve that needs to be patched? No? Then I don't need a new version

"is there a CVE" is not a question that regular people can, will, or in my opinion even should ask.

I mean, if they do, all the better, but my point is that advanced enough tech knowledge should not be a requirement for a safe system.

Post reply on HN