Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

121–130 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#121

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Imagine an authenticator app I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good. I will also imagine that when people install authenticators, they would NOT trust one from HenryBemis but only from sources that they recognize (Google, Microsoft, Yubikey, etc.) It always amazes me how come all smartphone OS creators switch every connectivity…

You cannot trust established players either. For instance, cheaper Samsung phones ship with a lot of shady software, as I found out helping relatives.

And a lot of reputable software companies have sold out to peddling adware. Adobe is one, and there are a lot of others. Abandoned shareware or open source often resurface with adware installers.

Re: Barcode scanner app on Google Play infects 10M users with one update

#122
One can say that the solution to this is more control/power for the app store, but te opposite, the solution for this problem on computer was solved decades ago:

Open source software and more open and transparent platforms!

Today users of common brands of Android and Apple devices are really restricted in control of their devices, so there is very few ways to check what the system or apps are doing, inspect, firewall/limit things, go tinker inside the apps.

And as said by other people, most of the time you have auto updates forced on users and so app developer does not even have to really justify what changed and why.

Re: Barcode scanner app on Google Play infects 10M users with one update

#123
post #105
post #101

I'm glad that Firefox on Android now has a built-in QR code scanner. This is the best UI and security improvement they added in the last 5 years.

It has? How does one use it?

When you open a new tab, it is right above the search bar.

Re: Barcode scanner app on Google Play infects 10M users with one update

#124
post #70
post #63

So why aren't we hearing about someone being arrested? Google knows who their devs are. Law enforcement can demand they give up that info.

Computer crime is so very rarely traced and prosecuted, like most white collar crime.

It's still a massive issue if the crime crosses borders; if the entity behind the malware is from, say, Russia, what can a prosecutor in the US do? This is why internet crime is such an issue.

Re: Barcode scanner app on Google Play infects 10M users with one update

#125
QR Reader are load of everything. I went mad to find one a decent one for my parents’ android phone and apparently it doesn’t exists. So in a weekend I’ve created one without any kind of tracking, ads, permission, whatever. Here it is if you guys need one ->

https://play.google.com/store/apps/details?id=com.prof18.sec...

Re: Barcode scanner app on Google Play infects 10M users with one update

#126
post #15

I don't get why no barcode scanner app is shipped with Android. It's such a basic functionality. Edit: apparently it IS shipped on iOS and at least my Lineage OS default camera app has a QR code reader too.

Switch to Google Lens in the Camera app. It's way less reliable but it usually gets the job done.

What do you mean by way less reliable?

While Google will not start any overly obnoxious ad-serving, who tells you they will not upload all or a bit more stealthily some pictures for some AI user profiling thingie? Cannot happen? They collected WiFi access points when doing Streetview back when their motto was "Don't be evil".

Re: Barcode scanner app on Google Play infects 10M users with one update

#127
I recently noticed that the "Barcode Scanner" app by ZXing (https://play.google.com/store/apps/details?id=com.google.zxi...) was being review-bombed with 1* reviews. People were talking about the "recent update", even though the last update is from February 2019. As far as I know, that app is open source and never contained ads. (Of course, without reproducible builds, we'll never know for sure.)

Was ZXing also hit by some issue, or is that just confused people that mistook the ZXing barcode scanner for the Lavabird barcode scanner?

In the comments of the article, someone wrote:

> The Zxing project is the flagship open source barcode scanner project for many years, and the December 2020 build was infected with malware. That bad build has been removed, of course, but the damage to the project continues.

Is there any further information on this?

Re: Barcode scanner app on Google Play infects 10M users with one update

#128

Earlier quoted context omitted.

yeah this is one reason why I can't take mobile app end to end encryption, or client side only, claims seriously. a single update at any time could undermine all of that and secondly, they or an analytics package can just read everything client side and upload it to a server anyway doesn't matter if its whatsapp, or signal, or some protonmail client if such a thing exists I just don't use them with that assurance in…

>yeah this is one reason why I can't take mobile app end to end encryption, or client side only, claims seriously. If it's a large company like Facebook that values these products like Whatsapp at billions I trust them at least on this issue. I'm pretty sure they're not going to put junk third party malware for 50k into the Whatsapp client. This is mostly an issue for apps done by individual developers who have huge…

They've been sideloading with React Native, allowing updates even for people without automatic updates enabled, and have abused enterprise/privileged developer keys which allows access to additional parts of the system. I just don't see how you can draw that conclusion.

I use the apps for other things, not for any assurance of privacy.

Re: Barcode scanner app on Google Play infects 10M users with one update

#129
post #15

I don't get why no barcode scanner app is shipped with Android. It's such a basic functionality. Edit: apparently it IS shipped on iOS and at least my Lineage OS default camera app has a QR code reader too.

Switch to Google Lens in the Camera app. It's way less reliable but it usually gets the job done.

The problem is that not all the people knows that. And I don't know why Google does not "advertise" it.

Anyway, for my parents' old phone I built one simply QR Reader without any crap. If you need one -> https://play.google.com/store/apps/details?id=com.prof18.sec...

Re: Barcode scanner app on Google Play infects 10M users with one update

#130
post #33

Stallman calls autoupdates a "universal backdoor".

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

We need a culture that distinguishes between truly necessary updates like security ones and general updates that change functionality and interfaces. One type is essential and we want to encourage everyone to install those promptly. The other should always be optional and the changes being made should always be transparent. Bundling the two is a common but user-hostile behaviour.

This separation should be the price of admission for software developers who want to use online updates, and by now there is probably a need for real laws to regulate the industry since firstly it is very clear that it will not regulate itself effectively and secondly it is no longer just random applications but essentials like operating systems, web browsers and even the software controlling your car that are being treated in this cavalier way.

Post reply on HN