Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

181–190 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#182
post #93
post #26

Earlier quoted context omitted.

Stuff like this happens on iOS all the time and everyone just ignores it because it's mostly sandboxed. Apple is terrible at stopping malware until it ends up in the news.

Source? Or you just made that up?

Here's an example of 18 such apps from 2019: https://www.wired.com/story/apple-app-store-malware-click-fr...

Another from 2018: https://www.zdnet.com/article/top-mac-anti-adware-software-i...

Re: Barcode scanner app on Google Play infects 10M users with one update

#183

Oh wow, one hundredth of a user. People really need to start respecting m=milli and M=mega.

The m in the title doesn't stand for mega, it stands for million, and lower-case m is a proper abbreviation:

https://www.lexico.com/definition/m

Re: Barcode scanner app on Google Play infects 10M users with one update

#184
post #166

Quote from Malwarebytes site: "Peter V. Jaspers-Fayer - Why does this article not contain the publisher and the icon of the app in question? There are many called "Barcode Scanner", and by omitting this information, you have caused unwarranted panic by users of innocent apps of the same name." The fact that Google allows applications on Google Play to have identical/duplicate names is a significant ongoing problem as…

There is also a unique application ID string but unfortunately that's not displayed, probably in the name of "user friendliness". Just showing that in the play store alongside the app name would go a long way.

Yeah, I know but most don't bother to check including myself, and that's the trouble. I'm reasonably careful but I've only just gone through the process with this app since this alert.

You're right, displaying the fact would solve most things. The question is why such an obvious matter—which also would have been even more obvious to Google—wasn't enacted as such.

Re: Barcode scanner app on Google Play infects 10M users with one update

#186

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

It is 2021 and Android still doesn't have a QR code scanner by default.

the camera app scans qr codes on my pixels.

Re: Barcode scanner app on Google Play infects 10M users with one update

#187
post #131

I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged. few QR code apps from F-Droid. https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...

Open source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-Droid apps blindly, and more importantly, refrain from blanket advocating F-Droid apps as a security / privacy panacea.

What I do instead is monitor Android's traffic with a LittleSnitch-esque firewall and block all apps I don't use. Also, I've disabled auto-updates on non-essential apps. Only Photos, Maps, Chrome, and Firefox are allowed to auto update on my Android.

Re: Barcode scanner app on Google Play infects 10M users with one update

#188
post #67
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Basically all phones are behind a NAT/firewall. You can't connect to them directly.

Until they turn on ADB, then it's a free for all.

https://www.bleepingcomputer.com/news/security/tens-of-thous...

Re: Barcode scanner app on Google Play infects 10M users with one update

#189

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

Most apps never need to be updated, problem solved. Especially stuff like barcode scanners, authenticator apps and other apps that I'd call phone infrastructure can just be static from the time of install.

Re: Barcode scanner app on Google Play infects 10M users with one update

#190

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

I'm terrified of browser extensions for this very same reason (and yes, I still use them). I wish the browser vendors supported some kind of pinning to source code for open source extensions. Right now I have at least 2 extensions running that I know could access my passwords on any website as I enter them. One of those is Lastpass, which I use for storing/generating those passwords anyway, and the other is AdBlock P…

Given the reputation of ABP, I'd be worried too.
Post reply on HN