Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

271–280 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#271
post #118

Earlier quoted context omitted.

I use iOS and have App auto-updates disabled (not the system update). We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small.…

> We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small. I'd have to say that most apps now connect to a rather large number…

> there's no outbound traffic filtering to check the system isn't leeching user data and/or device identifiers

But there is the iOS sandbox FS. So if an App gets exploited, it can only every leech the data from exactly THAT app. Just the same as an auto-update might just start to leech and upload that data. Given the real-world practices, I think it is more likely an App creator choses to upload the data, than some malicious hacker doing it.

> It's trivial to make an app that leeches a user's contacts regularly to a server

On iOS this is not possible - either the App requests access to the contacts list then I have to consent via iOS sandbox features, or it doesn't get access. And if I didn't give this consent, any security hole that exploits the App will need to get that consent too (at which I will not give it).

Re: Barcode scanner app on Google Play infects 10M users with one update

#272
post #63

So why aren't we hearing about someone being arrested? Google knows who their devs are. Law enforcement can demand they give up that info.

There is a difference between ‘infects’ and ‘shows pop-up ads’. Annoying? Sure. Comparable to a complete security breach? No.

It's not a data breach, but it is fraud and should be treated as such.

Re: Barcode scanner app on Google Play infects 10M users with one update

#273
post #230

Earlier quoted context omitted.

Is there anything you guys in New Zealand haven't done better during this pandemic? :-)

"Better" is certainly a point of view here. Having to tell the government all of your whereabouts when you already live on an Island with no spreading is an overreach, IMO.

We have a similar system is AU. It’s not really enforced all that well. But most people cooperate and life is generally back to normal. You also only need to do it in enclosed areas like shops. Mask wearing is still mandatory on public transport.

Unfortunately very low cases doesn’t mean the virus is gone. Occasionally there is a case and if you want to clamp that down as fast as possible, you need contact tracing. Which means we need to know where you are.

For most people, no extra information is being leaked. Facebook and google already know where they are and they are far more malicious than the AU or NZ government. The tin foil hatters like you can take extra measures I’m sure.

The US has over 25million cases and over 400k dead. That’s literally the entire population of Australia infected. So I’d argue that NZ and AU are objectively better and we shouldn’t worry about “overreach” just yet.

Re: Barcode scanner app on Google Play infects 10M users with one update

#274
post #67
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

Basically all phones are behind a NAT/firewall. You can't connect to them directly.

On my home WiFi, my phone is on IPv6, and therefore not behind NAT (it is on a NAT address for IPv4, though). I've not done any super-geeky things to enable this, it's a standard router from a mainstream internet provider.

Pinging the IPv6 address from outside doesn't seem to work - I guess there is some sort of firewalling going on.

Re: Barcode scanner app on Google Play infects 10M users with one update

#275
post #58
post #43

Earlier quoted context omitted.

There's a third possibility, and I think it's Stallman's ideal computing landscape: all users care deeply about the code running on their machines and they are competent in applying and vetting patches, building from source, etc. It's unrealistic, sure, but it sounds nice right about now.

I think back when he posted it, it might have been possible for sufficiently motivated and talented individuals to do such vetting, albeit even then it would have been a stretch. Nowadays the amount of code running on various devices in a single home has increased so dramatically... Think of TV remotes. They used to work with infrared. Nowadays, there are bluetooth remotes (not sure how widely deployed they are, but…

This TV Remote exactly clearly gets to the point: What do you think is more likely, a malicious hacker driving a van and parking in front of your house? Just to exploit the TV remote via Bluetooth, a device that has no sensitive data, is not connected to the internet and can only be used to make TV inputs like switching channels? Or rather that your TV vendor like Samsung or LG decide one day that they offer a firmware "update" that will log what you watch on the TV, upload screenshot of the device and installed App to the cloud and sell to 3rd parties? My bet is on the later, and it exactly makes the point that auto-update is more dangerous than having a security flaw in a bluetooth TV remote.

Re: Barcode scanner app on Google Play infects 10M users with one update

#276
post #33

Earlier quoted context omitted.

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

We need a culture that distinguishes between truly necessary updates like security ones and general updates that change functionality and interfaces. One type is essential and we want to encourage everyone to install those promptly. The other should always be optional and the changes being made should always be transparent. Bundling the two is a common but user-hostile behaviour. This separation should be the price o…

This would be nice, but a developer could still publish a malicious update as an important security fix.

Also it gets very hard for developers to keep track of past versions and apply new fixes to them, when they also have to apply fixes to the new versions.

Re: Barcode scanner app on Google Play infects 10M users with one update

#277

Earlier quoted context omitted.

> Fear of anti-competition lawsuits and complaints. They could just create an open source variant that suddenly shows up top when people search for QR or barcode scanner. It would be in their best interest, and it would not violate any anti-competition laws, nobody can demand to see how these apps are ranked I guess?

Manipulating the search results so blatantly? How are they going to do this without generating more criticism? It’s better to bake it into the OS and push an update. But then you’d have to get an OS update to heaps of phones.

> How are they going to do this without generating more criticism?

From the people who make those crummy apps; criticism surely cannot hurt Google all that much?

> But then you’d have to get an OS update to heaps of phones.

That's not a viable option, this requires tons of work from OEM's that Google would have to pay for. I've rarely ever gotten any OS updates at all on Android - apart from my latest phone. But I think the only reason I get OS updates now is due to the fact that Nokia just ships stock Android under the "android_one" brand.

Re: Barcode scanner app on Google Play infects 10M users with one update

#279

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

The ability to read QR codes should be added to Android's Compatibility Test Suite (CTS) default camera app, this way vendors would need to ensure their camera app are all equipped with this if they want to ship with Google Play Store.

Re: Barcode scanner app on Google Play infects 10M users with one update

#280
post #55
post #52

Earlier quoted context omitted.

Also if you were slow updating, you could avoid critical security patches (and many people did)

Which affect the OS mostly and not individual apps. Funnily enough OS updates are usually not automatic. Which I think is a good thing because vendors keep mixing them with "feature updates" which end up making things worse (looking at you Samsung). I'd love for Google to take away the security update channel from the phone vendors and auto-update ONLY security-related things through that.

So what happens if you are on an old version, a security issue is discovered, but they only fix it in the new version?
Post reply on HN