Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

141–150 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#141

The only reason this was detected was very overt behavior - opening AD popups. So I guesstimate for each one of these we have 10 that go undetected. This means the whole ecosystem is broken, as there is no reason this will happen only for updates and not for new apps as well. Apple's ecosystem is somewhat better, but I can't imagine they go through every line of code in each package, so most of their review is probab…

> The problem with both platforms is that they don't provide run of the mill users the option of installing an effective firewall and security solutions.

Google does allow no-root firewalls on the PlayStore which rely on VPN APIs. Here are some open source ones: https://www.reddit.com/r/androidapps/comments/jhtvn4/a_list_...

Re: Barcode scanner app on Google Play infects 10M users with one update

#142

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Imagine an authenticator app I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good. I will also imagine that when people install authenticators, they would NOT trust one from HenryBemis but only from sources that they recognize (Google, Microsoft, Yubikey, etc.) It always amazes me how come all smartphone OS creators switch every connectivity…

> I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good.

Dear HenryBemis,

As a CEO of TRC, I would like to extend you an offer to purchase source and distribution rights to your app, SummerChildAuthenticator, to the form of $500,000 (five hundred thousand US dollars). We are a fast growing SV startup that wants to make it easier for people to secure their papers and money on-line. We have developed a streamlined, easy-to-use, user interface for authenticator applications and are looking for a way to quickly put it in front of a wide audience. We believe that your SummerChildAuthenticator, with its established base of over 50 000 users, is the gateway we are looking for.

If you are interested in this offer, please reply to this e-mail.

Sincerely yours,

TeMPOraL, CEO, TRC

Temporal's Rackets and Cons is a startup registered in Southern Vescillo, Arstotzka.

--

You think to yourself: "this is a good deal! The app is unlikely to grow more, it isn't making you any money anyway. Here is this hot new startup with great ideas, what's the worst that could happen? They'll just inject an ad here and there. Meanwhile, I have medical expenses, and..."

So you agree, and I take your app, and run a "growth hacking" campaign on Reddit to blow its userbase up to 500 000 people, and then proceed with my main business plan, which is selling access to OTP codes to the mob running phishing scams.

(Oh, dear reader, you've noticed Arstotzka and thought I'll be selling data to evil government? Nope, we registered there only because it'll make it mighty hard for anyone to sue us.)

Re: Barcode scanner app on Google Play infects 10M users with one update

#143

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place.

This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual barcode scanning).

To make matters worse, scanning a barcode when you enter a store/cafe (to register your location), is now begin done everywhere in order to track potential covid19 spreaders. This forces anyone without an iPhone to install at least one of these potentially harmful apps.

Re: Barcode scanner app on Google Play infects 10M users with one update

#144
post #56
post #42

Earlier quoted context omitted.

Charles must have some wild carveout from apple. All other apps that do that have been shut down. I still run a very old version of adblockios that starts a vpn (proxy) at 127.0.0.1 and blocks traffic that way. mostly.

I think the parental control app Circle does something similar (faux-vpn proxy). When I tried using Circle, it seemed a bit convoluted to me, so we ended up uninstalling it. So, I’m not sure how unique this method is. But, I’m not sure I can think of another way for a network blocking/security app to work on iOS.

https://firewalla.com is another one.

Re: Barcode scanner app on Google Play infects 10M users with one update

#145
post #78
post #23

I found this behavior in the Barcode Scanner app by "the space team" That was not one that was mentioned by the article It's url: https://play.google.com/store/apps/details?id=com.qrcodescan... (See the reviews)

I also found this pop-up add behaviour Saturday (6th) morning. I distinctly remember looking at this app last year when a different barcode scanner had an issue and it was not owned by "the space team" then,maybe a takeover? App now uninstalled

The one I remember being popular before on Android was the "zxing" one: it's still on the Play Store but has tons of recent reviews complaining about adware... confused users (and/or competitors taking advantage) leaving reviews on the wrong one?

The zxing one seems to not have been updated in years (plus it's still on the store).

Re: Barcode scanner app on Google Play infects 10M users with one update

#146
post #127

I recently noticed that the "Barcode Scanner" app by ZXing ( https://play.google.com/store/apps/details?id=com.google.zxi... ) was being review-bombed with 1* reviews. People were talking about the "recent update", even though the last update is from February 2019. As far as I know, that app is open source and never contained ads. (Of course, without reproducible builds, we'll never know for sure.) Was ZXing also hit…

Probably the people responsible for the malware barcode scanner have other scanner apps in the game and trying to prevent user from their app from installing the Foss app and live happily ever after.

Yep, fake reviews by malware-ridden competitors was also one of my thoughts. But there's this motto "don't attribute to malice what can be attributed to stupidity".

It could also be both of course.

Re: Barcode scanner app on Google Play infects 10M users with one update

#147
post #31

The only reason this was detected was very overt behavior - opening AD popups. So I guesstimate for each one of these we have 10 that go undetected. This means the whole ecosystem is broken, as there is no reason this will happen only for updates and not for new apps as well. Apple's ecosystem is somewhat better, but I can't imagine they go through every line of code in each package, so most of their review is probab…

This happened on ios for me years ago. I had two apps that radically changed their business model (owner?) through updates with no recourse. I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remi…

Camscanner was a blatant bait and switch. When I first started using it, I paid for a license to get full functionality with no ads/watermarks/etc. Magically, years later I got reverted to the ad-supported/free version, and my license was nowhere to be found. This was at the same time they moved to "cloud features" and a subscription model. Their reviews are littered with people having the same issue and the developer copy-pasting some response that doesn't work.

Re: Barcode scanner app on Google Play infects 10M users with one update

#148
post #125

QR Reader are load of everything. I went mad to find one a decent one for my parents’ android phone and apparently it doesn’t exists. So in a weekend I’ve created one without any kind of tracking, ads, permission, whatever. Here it is if you guys need one -> https://play.google.com/store/apps/details?id=com.prof18.sec...

But this is the classic cycle don't you see? They almost always start as "here is an app I threw together, no ads, don't be evil".

But then a lot of people like your app, and ask for a small extra feature. You support it, and then get a bit annoyed by all the features people are asking for. Then you have to update it for the latest release... then suddenly fix it when some obscure version of Android breaks on it.

Then someone offers you £60k for a small ad no-one will even see and you think.. don't you deserve a bit of credit?

Maybe you'll be the good one who doesn't take it, but the free model is generally unsustainable.

Re: Barcode scanner app on Google Play infects 10M users with one update

#149
post #74
post #64

Earlier quoted context omitted.

> He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. We are not talking about patching. We are talking about updating. > They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software? Yes. Vend…

What stops them bundling something malicious into the “security patch” and then not writing it into the change log?

Traditionally, when someone deliberately does something that causes significant harm to someone else, we address that by giving them a chance to defend their actions in court and if their defence is not acceptable we penalise them. It is strange how easily we forget normal behaviour as soon as technology comes into the picture.

If you had a shower fan/light that broke, and the manufacturer supplied a new model to replace it that had a working fan but no light and also an undisclosed camera and connectivity that sent everything it saw home to the manufacturer, no-one would be debating the situation. People would be going to jail.

Re: Barcode scanner app on Google Play infects 10M users with one update

#150

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

It is 2021 and Android still doesn't have a QR code scanner by default.
Post reply on HN