Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

261–270 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#261

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

On last point, Firefox/Chrome and derivatives have scanning built in. It would be very simple to have an app that links to Chrome.

Re: Barcode scanner app on Google Play infects 10M users with one update

#262

Earlier quoted context omitted.

> Yeah, it's always in the flashlights, the barcode scanners, the background packs. Why are Google afraid to release a free non-harmful version of those popular apps. Is it to keep the illusion the app-store is a vibrant market place where tons of developers get rich? It just seems nuts to allow all those harmful apps (that does virtually nothing) to float among the top downloads.

FWIW I've not had an Android phone lacking a flashlight in the OS since... ever, I think. At a guess, the apps are preying on customers not aware of the OS-level functionality. QR scanning seems a little more complicated. FF for Android integrates a QR scanner, but chrome does not. Google's default camera also opens links, if you allow Google Lens.

About four years ago, when I had a low end Android phone, some kind of "make the screen white" app was really useful.

I remember the play store being scary but I think there was something in fdroid.

I am not so sure on this, but I do not recall my nexus 5 having flashlight in the OS.

Re: Barcode scanner app on Google Play infects 10M users with one update

#263

Earlier quoted context omitted.

The 21,000 dead here in Canada would like to argue that it is much, much better but, well, they can't. I literally can not believe you are arguing it's not better.

Believe it or not but not everybody believes that human rights like privacy are always optional when lives are at stake. Ever heard of the phrase "the end doesn't justify the means"?

exactly, how are you going to visit the mistress(es) if government tracks everything and eventually will be leaked? (a bit of sarcasm but the point stands, privacy shouldn't be optional)

Re: Barcode scanner app on Google Play infects 10M users with one update

#264
post #131

I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged. few QR code apps from F-Droid. https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...

Open source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-…

It's manually curated and generally flags such things as anti-features if found, and I'd believe them more than some tensorflow_script_to_detect_malware.py

Re: Barcode scanner app on Google Play infects 10M users with one update

#265

Earlier quoted context omitted.

The 21,000 dead here in Canada would like to argue that it is much, much better but, well, they can't. I literally can not believe you are arguing it's not better.

Believe it or not but not everybody believes that human rights like privacy are always optional when lives are at stake. Ever heard of the phrase "the end doesn't justify the means"?

What about the people on deaths doors human rights. I'd say they take precedence over being upset on sharing you location.

Re: Barcode scanner app on Google Play infects 10M users with one update

#266
post #43
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

There's a third possibility, and I think it's Stallman's ideal computing landscape: all users care deeply about the code running on their machines and they are competent in applying and vetting patches, building from source, etc. It's unrealistic, sure, but it sounds nice right about now.

Not everybody needs to do that, but then you need to rely on people you can trust. Of course we already do that to some extent in app stores: I don't install something from unknown developers that requires all sorts of permissions it shouldn't need, I do install from developers I think I can trust. But if I don't trust them, I lack the ability to inspect their code. That's indeed the big thing that's lacking.

Re: Barcode scanner app on Google Play infects 10M users with one update

#267

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. Wouldn't that be anti-competitive? Similar situation when Microsoft was including IE on their system that made them a quasi monopolist with subpar product. I'd rather have Google having stricter rules when it comes to malware.

You’re right. How dare Microsoft abuses their monopoly and ships Windows with a clock in the taskbar! And why stop here? We should open the market for TCP implementations. The status quo is anti-competitive and stifles innovation!

I'm just about old enough to remember the versions of Windows which didn't ship with TCP and you had to install "Trumpet Winsock" to get on the Internet. This was silly.

The key to understanding the browser case is that, as MS wanted it, it would have tied client and server and rich application development together, all of which would have necessitated Windows. IE was a threat because of ActiveX.

Re: Barcode scanner app on Google Play infects 10M users with one update

#268
post #260

Earlier quoted context omitted.

Alas the Great Suspender just fell prey to malware after its creator sold it off: https://news.ycombinator.com/item?id=25846504 I think Apple have the right idea with app review on browser extensions for Safari.

I hear that a lot of companies are doing unethical things. Maybe the government should only grant corporations to form which are headed by approved people? /s

Not a bad idea, even if sarcastic.

Re: Barcode scanner app on Google Play infects 10M users with one update

#269

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

Yeah, it's always in the flashlights, the barcode scanners, the background packs. They all address super basic functionality that many, many people seem to want (if I could just set a ringtone from YouTube, it'd save me from going through a bunch of shady apps, if I ever needed a ringtone that is). Yet they just aren't included in the base OS (or weren't always, my lineage OS has a flashlight currently). Therefore, t…

> (if I could just set a ringtone from YouTube, it'd save me from going through a bunch of shady apps, if I ever needed a ringtone that is)

I don't like that example of utilitarian because it fights the youtube platform which does not want you downloading videos. Anything that sidesteps some sort of security fence or functionality is shady to begin with; even if you think it's fair use. Plus there's the whole copyright minefield.

Re: Barcode scanner app on Google Play infects 10M users with one update

#270

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

I'm terrified of browser extensions for this very same reason (and yes, I still use them). I wish the browser vendors supported some kind of pinning to source code for open source extensions. Right now I have at least 2 extensions running that I know could access my passwords on any website as I enter them. One of those is Lastpass, which I use for storing/generating those passwords anyway, and the other is AdBlock P…

AdBlock Plus is owned by a company who is selling ads. Use uBlock Origin instead, please.
Post reply on HN