Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

81–90 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#81
post #45

Earlier quoted context omitted.

Every Google Play update prompt in My Apps has a description provided by the publisher. If there is an urgency to update and they don't say so, I'm not going to blithely accept every update. Ior example, had there not been the exploit risk, I would have left Chrome at the older version, as their new tabgroup implementation is horrible, and it doesn't even allow you to open a new tab without creating a group or going…

> Every Google Play update prompt in My Apps has a description provided by the publisher. I hate to reply like this but, the vast majority of Google Play app updates go something like this: "Updates." "Fixes" "..." Having genuine changelogs would be glorious. Apple and Google should require proper source and issue management, they could then generate changelogs automatically. Having that, they could then use machine…

"performance improvements and bug fixes".

I just looked at the messages for the last ten or so updates on my phone and the last three were worthless like the above, but the rest were relatively detailed and informative. I imagine they are more motivated to give details when it's for new features.

Re: Barcode scanner app on Google Play infects 10M users with one update

#82
post #63

So why aren't we hearing about someone being arrested? Google knows who their devs are. Law enforcement can demand they give up that info.

They are most likely Chinese. I’ve been getting asked by Chinese accounts on LinkedIn to let them use my account to submit their apps on the Google Play Store for a fraction of their revenue. I’m guessing there’s a similar scam going on here too.

This is also very common on freelance sites like Upwork.

Re: Barcode scanner app on Google Play infects 10M users with one update

#84
post #76
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Maybe I'm a luddite but updates are not always necessary. It's a barcode app, what updates does it need? Is there a cve that needs to be patched? No? Then I don't need a new version

I’m usually like this. Then my bank’s app refused to launch until I updated.

They re-designed it. When I went to click my usual “schedule payment” button on a bill payment, it just said “Coming Soon”.

I wasn’t a happy person about it.

Big Canadian bank too. US$65b mkt cap.

Re: Barcode scanner app on Google Play infects 10M users with one update

#85
post #76
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Maybe I'm a luddite but updates are not always necessary. It's a barcode app, what updates does it need? Is there a cve that needs to be patched? No? Then I don't need a new version

[deleted]

Re: Barcode scanner app on Google Play infects 10M users with one update

#86
post #33

Stallman calls autoupdates a "universal backdoor".

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

I use iOS and have App auto-updates disabled (not the system update). We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small.

Another point is the often complete change in UI or app behavior and you only find out about when you want it the least. I once had the case where I came out of a bar in the middle of a cold night, tired, had some beers and just wanted to use my Bikesharing app to unlock a freefloating bike to get home - whilst the app decided that it had to introduce a completely new UI and forced me to take an unskippable "guided tour" through the new features right at the spot.

Re: Barcode scanner app on Google Play infects 10M users with one update

#87
post #79
post #67

Earlier quoted context omitted.

Basically all phones are behind a NAT/firewall. You can't connect to them directly.

They can connect to whatever they want, it's more than enough.

Plus many services can send push messages to the phone. E.g. Whatsapp. Bezos for example was hacked through a Whatsapp message containing an exploit.

Re: Barcode scanner app on Google Play infects 10M users with one update

#88
post #76
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Maybe I'm a luddite but updates are not always necessary. It's a barcode app, what updates does it need? Is there a cve that needs to be patched? No? Then I don't need a new version

Better scanning in low light, better error correction in code recognition, ability to recognise codes from a further distance, faster capture of codes, more options of what to do with the resulting data, reduced power usage while scanning, better user interface choices (e.g. updating to support more devices or matching new platform UI), ability to interface with external barcode scanners, better privacy protections for the user, reduction in overall package size, etc etc etc.

There’s always more things you can do to a product to improve it for its users.

Re: Barcode scanner app on Google Play infects 10M users with one update

#89

This is precisely why I have auto-updates turned off. No minor security or bug updates are worth getting an all-out infection(or unexpectedly losing features).

How do you decide when it is safe to update?

Probably never. I mean, I am on iOS and as a developer I know how hard it is to get your code to run on iOS. Heck, security flaws that jailbreak an iOS device just via network/OTA is paid serious money for, there is no need to implement this.

I seriously ask the question what damage could a potential malicious app on iOS cause? There is no running in the background, so no exploiting while I don't use the app, no being part of a botnet when the app is closed. There is a FS sandbox that will not let you access another Apps data without being able to jailbreak etc. I think an auto-update is more risky on iOS than to live with an older version of the app that does its job (you never know what an update changes/breaks for you, and downgrading is not an option in the appstore).

Re: Barcode scanner app on Google Play infects 10M users with one update

#90
post #76

Earlier quoted context omitted.

Maybe I'm a luddite but updates are not always necessary. It's a barcode app, what updates does it need? Is there a cve that needs to be patched? No? Then I don't need a new version

Better scanning in low light, better error correction in code recognition, ability to recognise codes from a further distance, faster capture of codes, more options of what to do with the resulting data, reduced power usage while scanning, better user interface choices (e.g. updating to support more devices or matching new platform UI), ability to interface with external barcode scanners, better privacy protections f…

[deleted]
Post reply on HN