Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

111–120 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#111
post #31

Earlier quoted context omitted.

This happened on ios for me years ago. I had two apps that radically changed their business model (owner?) through updates with no recourse. I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remi…

yeah this is one reason why I can't take mobile app end to end encryption, or client side only, claims seriously. a single update at any time could undermine all of that and secondly, they or an analytics package can just read everything client side and upload it to a server anyway doesn't matter if its whatsapp, or signal, or some protonmail client if such a thing exists I just don't use them with that assurance in…

>yeah this is one reason why I can't take mobile app end to end encryption, or client side only, claims seriously.

If it's a large company like Facebook that values these products like Whatsapp at billions I trust them at least on this issue. I'm pretty sure they're not going to put junk third party malware for 50k into the Whatsapp client.

This is mostly an issue for apps done by individual developers who have huge incentive to take these deals, like the barcode scanner in question.

Re: Barcode scanner app on Google Play infects 10M users with one update

#112

Earlier quoted context omitted.

School tried to make me use camscanner, glad I took the extra effort to do something else. Thanks for the anecdote.

I absolutely love Camscanner, and I have been for over a year on the old version because I refuse to update to the new version which requires network permissions. I exactly suspected this is why it needs those permissions. To what did you switch? Camscanner is otherwise an excellent app, especially for combining multiple images and straightening them out.

Adobe Scan is a solid option as well.

Re: Barcode scanner app on Google Play infects 10M users with one update

#113
post #44

Earlier quoted context omitted.

But if you were slow updating you could avoid a malware once it was known.

Who will detect the malware if we are all slow to update?

The early adopters. There are always people that will weight that risk of latest & greatest and vs buggy differently, it should be a choice. Especially for apps that don't have a beta testing or early bird channel.

Re: Barcode scanner app on Google Play infects 10M users with one update

#114
post #74
post #64

Earlier quoted context omitted.

> He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. We are not talking about patching. We are talking about updating. > They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software? Yes. Vend…

What stops them bundling something malicious into the “security patch” and then not writing it into the change log?

App review... maybe? But the review (especially on Android) would have to be much more careful than it is nowadays...

Re: Barcode scanner app on Google Play infects 10M users with one update

#115
I noticed the package name com.qrcodescanner.barcodescanner. and went to https://qrcodescanner.com/ which advertises another very popular barcode scanner wescan.

they also offer an sdk of their own for including a barcode scanner into your app. https://github.com/WeTransfer/WeScan

I'm not really sure they are connected (package names don't verify domain names AFAIK). Just curious.

Re: Barcode scanner app on Google Play infects 10M users with one update

#116

I stopped using apps from companies or projects I don't know some time ago. Which left basically small local companies, the big global ones and FOSS-projects. This of course is not perfect but at least leaves some sort of accountability.

This is why I root my phone. I block internet access to any new app that shouldn't need it, if it refuses to work, I uninstall it.

Re: Barcode scanner app on Google Play infects 10M users with one update

#117
post #41

Stallman calls autoupdates a "universal backdoor".

Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.

Give a user a choice though, and they dismiss the update notification because it's naggy and annoying and usually involves restarting your app or OS (I'm mainly thinking of operating systems here).

Microsoft went in hard / aggressively and are forcing update installs and restarts, which IMO is going the wrong direction.

Wasn't there a Linux project where they could update the OS / kernel without a restart? I feel like this is what all OSes should aim for. I like to think Android is going in one direction, moving shared libraries (Play Services) outside of the core OS so it can be updated independently.

Re: Barcode scanner app on Google Play infects 10M users with one update

#118
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

I use iOS and have App auto-updates disabled (not the system update). We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small.…

> We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small.

I'd have to say that most apps now connect to a rather large number of hosts/servers, and it's getting increasingly untenable to not offer users proper control of this. I get that Apple wants to be "friendly computers", but looking at my firewall logs I'm seeing:

- third party audience segmenting - third party analytics - third party static content being fetched - third party ad networks - first or third party generic cloud server connections

I think the attack vector on apps is quite significant if you consider the app itself to have been built to monetize data - there's no outbound traffic filtering to check the system isn't leeching user data and/or device identifiers (the latter getting better and hopefully Apple will require consent soon for the ID for advertisers).

It's trivial to make an app that leeches a user's contacts regularly to a server, then does anything the developer feels like to build a social graph. See clubhouse. I fear the biggest issue for most users' privacy are the "legitimate" apps they use simply not being built with incentives aligned with their interests, and having access to phone home to any server with anything they can access.

Re: Barcode scanner app on Google Play infects 10M users with one update

#119
post #72

Can't Google remove apps like Rocket Cleaner, that participate in these ads?

Not a good idea - I can pay for an ad for an app I don't like and it will be removed.

Apps and websites running ads they don't know about or don't vouch for is another problem. It's like a propaganda backdoor.

Re: Barcode scanner app on Google Play infects 10M users with one update

#120

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Imagine an authenticator app I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good. I will also imagine that when people install authenticators, they would NOT trust one from HenryBemis but only from sources that they recognize (Google, Microsoft, Yubikey, etc.) It always amazes me how come all smartphone OS creators switch every connectivity…

Sadly, the permissions-by-default problem is not unique to Android. I bought a new iPhone a couple of years ago and spent nearly an hour straight away just turning off all the junk I didn't want. That is now the way of the world, if all you want is a phone for communications and running a small number of essential apps because too many organisations now assume everyone will have a smartphone.

I suppose I should be grateful that I can turn off a lot of permissions for apps at all these days, unlike the malware built into recent versions of the major desktop operating systems. :-(

Post reply on HN