Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

161–170 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#161
post #41

Earlier quoted context omitted.

Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.

Give a user a choice though, and they dismiss the update notification because it's naggy and annoying and usually involves restarting your app or OS (I'm mainly thinking of operating systems here). Microsoft went in hard / aggressively and are forcing update installs and restarts, which IMO is going the wrong direction. Wasn't there a Linux project where they could update the OS / kernel without a restart? I feel lik…

> Give a user a choice though, and they dismiss the update notification because it's naggy and annoying and usually involves restarting your app or OS (I'm mainly thinking of operating systems here).

...or because it doesn't justify its right to be there. As a user, the updates mean to me a high probability of getting more bloated, less usable app with important functionality moved or missing. The security implications are abstract. The usability impact is real.

Re: Barcode scanner app on Google Play infects 10M users with one update

#162

Earlier quoted context omitted.

It is 2021 and Android still doesn't have a QR code scanner by default.

It's built into the camera app

There is no "the camera app"; the manufacturer often provides their own. It may well be in recent versions of GCam, but quite often it requires you to bail out to Google Lens for some reason.

Android is like Forrest Gump's box of chocolates: you never quite know what you're going to get. And sometimes it's stale.

Re: Barcode scanner app on Google Play infects 10M users with one update

#163
post #125

QR Reader are load of everything. I went mad to find one a decent one for my parents’ android phone and apparently it doesn’t exists. So in a weekend I’ve created one without any kind of tracking, ads, permission, whatever. Here it is if you guys need one -> https://play.google.com/store/apps/details?id=com.prof18.sec...

I find https://appsco.pe/app/qrsnapper a simple pwa that works fine for me

Re: Barcode scanner app on Google Play infects 10M users with one update

#164
post #131

I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged. few QR code apps from F-Droid. https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...

Both recommended apps use the ZXing library. So it is a small world, and if someone overtakes ZXing (assuming that it is not malicious right now), then all apps become infected. Otherwise no security and bugfixes, no improvements, no version upgrades... who knows how long this library will work?

Re: Barcode scanner app on Google Play infects 10M users with one update

#165

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

It is 2021 and Android still doesn't have a QR code scanner by default.

Actually they do if they have Google Assistant, which I imagine anyone with Android 7 or later will. If you use the Google Lens feature it will decode barcodes and QR codes. But unfortunately this feature is pretty much self-discovery rather than a publicised function

Re: Barcode scanner app on Google Play infects 10M users with one update

#166

Quote from Malwarebytes site: "Peter V. Jaspers-Fayer - Why does this article not contain the publisher and the icon of the app in question? There are many called "Barcode Scanner", and by omitting this information, you have caused unwarranted panic by users of innocent apps of the same name." The fact that Google allows applications on Google Play to have identical/duplicate names is a significant ongoing problem as…

There is also a unique application ID string but unfortunately that's not displayed, probably in the name of "user friendliness". Just showing that in the play store alongside the app name would go a long way.

Re: Barcode scanner app on Google Play infects 10M users with one update

#167

This is precisely why I have auto-updates turned off. No minor security or bug updates are worth getting an all-out infection(or unexpectedly losing features).

Same here. Every now and then some app stops working or politely asks me to update, so an update it'll get (and at that point I have time to look it over and rethink whether I even need the app).

Last time I went on an "update spree" and updated everything I tend to use frequently, I got the new Firefox mobile update, which is frankly utter garbage, and now I regret it.

(Why it's utter garbage? It's much more laggy across the board, and there are issues getting uBlock Origin to work on it. And this tends to be the story with updates - I haven't seen the app that got leaner, or faster, or more ergonomic with an update. Not a single one.)

Re: Barcode scanner app on Google Play infects 10M users with one update

#168
post #125

QR Reader are load of everything. I went mad to find one a decent one for my parents’ android phone and apparently it doesn’t exists. So in a weekend I’ve created one without any kind of tracking, ads, permission, whatever. Here it is if you guys need one -> https://play.google.com/store/apps/details?id=com.prof18.sec...

But this is the classic cycle don't you see? They almost always start as "here is an app I threw together, no ads, don't be evil". But then a lot of people like your app, and ask for a small extra feature. You support it, and then get a bit annoyed by all the features people are asking for. Then you have to update it for the latest release... then suddenly fix it when some obscure version of Android breaks on it. The…

I'll never do that, because I've done it without any kind of profit in mind. I've done it just to help people and the community.

I think that if the app is open source, it's harder to hide such behavior.

Re: Barcode scanner app on Google Play infects 10M users with one update

#169

Earlier quoted context omitted.

> Imagine an authenticator app I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good. I will also imagine that when people install authenticators, they would NOT trust one from HenryBemis but only from sources that they recognize (Google, Microsoft, Yubikey, etc.) It always amazes me how come all smartphone OS creators switch every connectivity…

You cannot trust established players either. For instance, cheaper Samsung phones ship with a lot of shady software, as I found out helping relatives. And a lot of reputable software companies have sold out to peddling adware. Adobe is one, and there are a lot of others. Abandoned shareware or open source often resurface with adware installers.

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...

> When inserted into a computer, the CDs installed one of two pieces of software which provided a form of digital rights management (DRM) by modifying the operating system to interfere with CD copying. Neither program could easily be uninstalled, and they created vulnerabilities that were exploited by unrelated malware. One of the programs would install and "phone home" with reports on the user's private listening habits - even if the user refused its end-user license agreement (EULA), while the other was not mentioned in the EULA at all. Both programs contained code from several pieces of copylefted free software in an apparent infringement of copyright, and configured the operating system to hide the software's existence, leading to both programs being classified as rootkits.

> on about 22 million CDs

https://en.wikipedia.org/wiki/Superfish

> The installation included a universal self-signed certificate authority; the certificate authority allows a man-in-the-middle attack to introduce ads even on encrypted pages. The certificate authority had the same private key across laptops; this allows third-party eavesdroppers to intercept or modify HTTPS secure communications without triggering browser warnings by either extracting the private key or using a self-signed certificate.

Re: Barcode scanner app on Google Play infects 10M users with one update

#170

Stallman calls autoupdates a "universal backdoor".

I didn’t know that automatic app updates could be turned off until I just tried it now in iOS, thanks! Just a side note but think that Google and Apple took way too long to provide built in apps for using your phone as a flashlight or scanning a QR code. They allowed this malware cottage industry to flourish.

iOS these days also grants Apple full automatic OS updates by default, too.

You can turn it off, but you have to dig in settings. During initial iOS 14 setup it has a screen telling you it's turning autoupdates on, but you're not allowed to opt out there.

Unattended upgrades are a remote code execution vulnerability.

Post reply on HN