Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

101–110 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#102

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> This can have a big impact for end users. Imagine an authenticator app ending service to all their users in such a scheme and how you will be cut out from all your accounts by this. How many authenticator apps do you have to use in parallel to mitigate this risk of a single point of failure?

This right here is a big reason, apart from actual restorable backups, why I root my Android device. Sure it is not required nowadays but it does give a sense of control if thats the right word.

So many times I had to restore older copies of apps like Chess or even Yoga app. The older apps allowed a functionality (downloadable content for offline view) which was straightup removed in newer versions.

Same for Authenticator or any other app which does things locally.

Re: Barcode scanner app on Google Play infects 10M users with one update

#103
post #31

The only reason this was detected was very overt behavior - opening AD popups. So I guesstimate for each one of these we have 10 that go undetected. This means the whole ecosystem is broken, as there is no reason this will happen only for updates and not for new apps as well. Apple's ecosystem is somewhat better, but I can't imagine they go through every line of code in each package, so most of their review is probab…

This happened on ios for me years ago. I had two apps that radically changed their business model (owner?) through updates with no recourse. I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remi…

yeah this is one reason why I can't take mobile app end to end encryption, or client side only, claims seriously. a single update at any time could undermine all of that

and secondly, they or an analytics package can just read everything client side and upload it to a server anyway

doesn't matter if its whatsapp, or signal, or some protonmail client if such a thing exists

I just don't use them with that assurance in mind, I use them for other things.

Re: Barcode scanner app on Google Play infects 10M users with one update

#104
post #76

Earlier quoted context omitted.

Maybe I'm a luddite but updates are not always necessary. It's a barcode app, what updates does it need? Is there a cve that needs to be patched? No? Then I don't need a new version

I’m usually like this. Then my bank’s app refused to launch until I updated. They re-designed it. When I went to click my usual “schedule payment” button on a bill payment, it just said “Coming Soon”. I wasn’t a happy person about it. Big Canadian bank too. US$65b mkt cap.

I never use my bank app because I don't fully trust my phone but they redesigned their website to be more mobile friendly. Now I can only see 10 operations at once instead of 30 before, and I can no longer sort by amount...

When I complained 2 years ago about it my banker told me to participate in their feedback program... Now they send me market research polls about future products and features, no way to report usability issues, it's not even run by the bank itself...

Re: Barcode scanner app on Google Play infects 10M users with one update

#106

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

You can write down the code for all authenticator entries upon scanning the installation code with a barcode reader app for later reuse :) (I suggest to use fdroid versions for both barcode reader and authenticator anyway to mitigate the issue)

Re: Barcode scanner app on Google Play infects 10M users with one update

#107

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Imagine an authenticator app

I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good.

I will also imagine that when people install authenticators, they would NOT trust one from HenryBemis but only from sources that they recognize (Google, Microsoft, Yubikey, etc.)

It always amazes me how come all smartphone OS creators switch every connectivity option to ON by default on every new app installation. It would take a use another 3-4 seconds per app installation to prompt the user whether they want this app to access Wifi/Data/Background/Roaming. In the same sense than the OS asks you whether you allow access to Calendar, Contacts, Camera, etc. At least half my apps on my Android do NOT need access to the internet to function. They may 'want', but definitely not need.

Re: Barcode scanner app on Google Play infects 10M users with one update

#108
post #101

I'm glad that Firefox on Android now has a built-in QR code scanner. This is the best UI and security improvement they added in the last 5 years.

The iPhone stock camera app also scans QR codes btw, guess most people just don't know since it isn't advertised heavily

Re: Barcode scanner app on Google Play infects 10M users with one update

#110
post #33

Stallman calls autoupdates a "universal backdoor".

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

And even when you choose to only manually upgrade, carefully looking at the changelog, but it just says "Bugs fixed."

The Play Store doesn't give enough information to really judge if the upgrade is necessary.

Post reply on HN