Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

131–140 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#131
I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged.

few QR code apps from F-Droid.

https://f-droid.org/en/packages/com.example.barcodescanner/

https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...

Re: Barcode scanner app on Google Play infects 10M users with one update

#132
post #118

Earlier quoted context omitted.

I use iOS and have App auto-updates disabled (not the system update). We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small.…

> We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small. I'd have to say that most apps now connect to a rather large number…

hopefully Apple will require consent soon for the ID for advertisers

Just think through the implications of that phrase for a moment, though. Your own device comes with a built-in mechanism specifically designed for advertisers to track you. Why was that ever a good idea in the first place?

Re: Barcode scanner app on Google Play infects 10M users with one update

#133

Earlier quoted context omitted.

School tried to make me use camscanner, glad I took the extra effort to do something else. Thanks for the anecdote.

I absolutely love Camscanner, and I have been for over a year on the old version because I refuse to update to the new version which requires network permissions. I exactly suspected this is why it needs those permissions. To what did you switch? Camscanner is otherwise an excellent app, especially for combining multiple images and straightening them out.

I just continue to use the brother scanner in the other room. I don’t recommend brother, they updated the software and somehow took away features.

Re: Barcode scanner app on Google Play infects 10M users with one update

#135
post #127

I recently noticed that the "Barcode Scanner" app by ZXing ( https://play.google.com/store/apps/details?id=com.google.zxi... ) was being review-bombed with 1* reviews. People were talking about the "recent update", even though the last update is from February 2019. As far as I know, that app is open source and never contained ads. (Of course, without reproducible builds, we'll never know for sure.) Was ZXing also hit…

Probably the people responsible for the malware barcode scanner have other scanner apps in the game and trying to prevent user from their app from installing the Foss app and live happily ever after.

Re: Barcode scanner app on Google Play infects 10M users with one update

#136

Earlier quoted context omitted.

I’m usually like this. Then my bank’s app refused to launch until I updated. They re-designed it. When I went to click my usual “schedule payment” button on a bill payment, it just said “Coming Soon”. I wasn’t a happy person about it. Big Canadian bank too. US$65b mkt cap.

I never use my bank app because I don't fully trust my phone but they redesigned their website to be more mobile friendly. Now I can only see 10 operations at once instead of 30 before, and I can no longer sort by amount... When I complained 2 years ago about it my banker told me to participate in their feedback program... Now they send me market research polls about future products and features, no way to report usa…

Financial services companies do seem to be particularly bad when it comes to UIs for their customers. Both awful apps and broken "mobile-first" sites seem to be par for the course these days. A few do try to do better, but the reality is that most people don't change banks for much more serious reasons than this, so the banks have a financial incentive to just throw some mostly workable junk together and ship it as cheaply as possible. :-(

Re: Barcode scanner app on Google Play infects 10M users with one update

#137
post #101

I'm glad that Firefox on Android now has a built-in QR code scanner. This is the best UI and security improvement they added in the last 5 years.

Vivaldi just added one too.

I'll never undertand why Google didn't include one from the start. They finally added it to the camera app but very few people know about it.

Re: Barcode scanner app on Google Play infects 10M users with one update

#138
post #127

I recently noticed that the "Barcode Scanner" app by ZXing ( https://play.google.com/store/apps/details?id=com.google.zxi... ) was being review-bombed with 1* reviews. People were talking about the "recent update", even though the last update is from February 2019. As far as I know, that app is open source and never contained ads. (Of course, without reproducible builds, we'll never know for sure.) Was ZXing also hit…

https://github.com/zxing/zxing/issues/1345

The dev says the app hasn't been updated since 2019.

Re: Barcode scanner app on Google Play infects 10M users with one update

#139

One can say that the solution to this is more control/power for the app store, but te opposite, the solution for this problem on computer was solved decades ago: Open source software and more open and transparent platforms! Today users of common brands of Android and Apple devices are really restricted in control of their devices, so there is very few ways to check what the system or apps are doing, inspect, firewall…

[deleted]

Re: Barcode scanner app on Google Play infects 10M users with one update

#140
post #41

Earlier quoted context omitted.

Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.

Give a user a choice though, and they dismiss the update notification because it's naggy and annoying and usually involves restarting your app or OS (I'm mainly thinking of operating systems here). Microsoft went in hard / aggressively and are forcing update installs and restarts, which IMO is going the wrong direction. Wasn't there a Linux project where they could update the OS / kernel without a restart? I feel lik…

> Wasn't there a Linux project where they could update the OS / kernel without a restart?

Ubuntu? Last time I updated, they asked me if I wanted to start using Livepatch, so it seems pretty integrated: https://ubuntu.com/security/livepatch

(though I'm horrible at noticing the critical battery warnings so I get frequent reboots for free – but that method wouldn't work on Windows which installs updates on shutdown!)

Post reply on HN