Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

281–290 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#281

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. Wouldn't that be anti-competitive? Similar situation when Microsoft was including IE on their system that made them a quasi monopolist with subpar product. I'd rather have Google having stricter rules when it comes to malware.

You’re right. How dare Microsoft abuses their monopoly and ships Windows with a clock in the taskbar! And why stop here? We should open the market for TCP implementations. The status quo is anti-competitive and stifles innovation!

> And why stop here? We should open the market for TCP implementations.

_Re-open_. There were, indeed, commercial TCP/IP stacks available for various operating systems until the operating systems started including them.

If we do a comparison with the browser situation, then it would be quite sufficient to allow people to install 3rd party TCP/IP stacks. Does Microsoft prevent that? I honestly don't know myself since I don't really use Windows. :D

Re: Barcode scanner app on Google Play infects 10M users with one update

#282
post #267

Earlier quoted context omitted.

You’re right. How dare Microsoft abuses their monopoly and ships Windows with a clock in the taskbar! And why stop here? We should open the market for TCP implementations. The status quo is anti-competitive and stifles innovation!

I'm just about old enough to remember the versions of Windows which didn't ship with TCP and you had to install "Trumpet Winsock" to get on the Internet. This was silly. The key to understanding the browser case is that, as MS wanted it, it would have tied client and server and rich application development together, all of which would have necessitated Windows. IE was a threat because of ActiveX.

It wasn't silly. It was third-party software which provided functionality that the OS simply lacked.

Re: Barcode scanner app on Google Play infects 10M users with one update

#283

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

Yeah, it's always in the flashlights, the barcode scanners, the background packs. They all address super basic functionality that many, many people seem to want (if I could just set a ringtone from YouTube, it'd save me from going through a bunch of shady apps, if I ever needed a ringtone that is). Yet they just aren't included in the base OS (or weren't always, my lineage OS has a flashlight currently). Therefore, t…

> they just aren't included in the base OS

Both a QR-capable camera and a flashlight in the notification bar are in all my Android phones, and they've been for a very long time. I know the Nexus One didn't include it, but those will have problems with modern TLS anyway.

The problem is likely elsewhere. It wouldn't surprise me if many of these users are tricked into installing these apps. It is quite popular for malware to disguise itself as a legitimate app as to not raise suspicion.

Re: Barcode scanner app on Google Play infects 10M users with one update

#284

Earlier quoted context omitted.

Open source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-…

It's manually curated and generally flags such things as anti-features if found, and I'd believe them more than some tensorflow_script_to_detect_malware.py

I wouldn't depend on F-Droid or FOSS as a measure of security. Of course, I get that F-Droid is run by volunteers, but I hope no one is spreading the notion that the F-Droid apps are magically uber secure and private or anything.

Re: Barcode scanner app on Google Play infects 10M users with one update

#285
post #125

QR Reader are load of everything. I went mad to find one a decent one for my parents’ android phone and apparently it doesn’t exists. So in a weekend I’ve created one without any kind of tracking, ads, permission, whatever. Here it is if you guys need one -> https://play.google.com/store/apps/details?id=com.prof18.sec...

Obligatory XKCD: https://xkcd.com/927/

But in this case, there is only one standard, and lots of imitators: https://play.google.com/store/apps/details?id=com.google.zxi...

But fallout from the bad app, or possibly deliberate actions by the malware maker have caused hundreds of bad reviews. It might be that removing the malware app from the store means people search for Barcode Scanner, find ZXing instead of the bad one, then post their bad review there. Or maybe the bad app is deliberately telling people "Click here to review the app", and pointing to the wrong app.

There's also reports of some sort of malware doing fishy things with intents to make it look like the ZXing software is bad https://github.com/zxing/zxing/issues/1345#issuecomment-7590....

I'd like to see a proper investigation by someone at Google Play. The original Barcode scanner is not needed for QR codes any more - almost any camera app will recognise those, as will Google's lens application, but it is still useful for scanning other barcode formats and for generating barcodes by sharing data with it from other apps, without needing to upload to a server or anything.

Re: Barcode scanner app on Google Play infects 10M users with one update

#286

Earlier quoted context omitted.

We need a culture that distinguishes between truly necessary updates like security ones and general updates that change functionality and interfaces. One type is essential and we want to encourage everyone to install those promptly. The other should always be optional and the changes being made should always be transparent. Bundling the two is a common but user-hostile behaviour. This separation should be the price o…

This would be nice, but a developer could still publish a malicious update as an important security fix. Also it gets very hard for developers to keep track of past versions and apply new fixes to them, when they also have to apply fixes to the new versions.

Also it gets very hard for developers to keep track of past versions and apply new fixes to them, when they also have to apply fixes to the new versions.

Then maybe they release too often?

I have been developing software professionally for a long time, much of it code that needed to be high quality. I have never worked on such a team that couldn't keep track of its own software, often over a period of years or even decades, and backport fixes when necessary.

Yes, it's less convenient for the developers than just having a single version that users are forced to update constantly if they want fixes. But it is achievable if you drop the pretence that every minor change in functionality or appearance must be pushed into production instantly through some CD system, which is of course a luxury that only those running hosted software have anyway.

Re: Barcode scanner app on Google Play infects 10M users with one update

#287

Earlier quoted context omitted.

Believe it or not but not everybody believes that human rights like privacy are always optional when lives are at stake. Ever heard of the phrase "the end doesn't justify the means"?

What about the people on deaths doors human rights. I'd say they take precedence over being upset on sharing you location.

https://fallacyinlogic.com/the-appeal-to-emotion-fallacy-wit...

Re: Barcode scanner app on Google Play infects 10M users with one update

#288
post #230

Earlier quoted context omitted.

Is there anything you guys in New Zealand haven't done better during this pandemic? :-)

"Better" is certainly a point of view here. Having to tell the government all of your whereabouts when you already live on an Island with no spreading is an overreach, IMO.

Well, when the users already give the government access to their location 24/7 with that app, at least they include a barcode/QR scanner.

But privacy is clearly one of the victims of this pandemic. At least some countries are now opening up the source-code of the front and back-end of their apps. They had to do that here in Norway (they had to replace the whole app actually) when the original closed source version was demonstrated to contain harmful features...

Re: Barcode scanner app on Google Play infects 10M users with one update

#289
post #259

Earlier quoted context omitted.

This is why I get all of these kinds of apps from F-Droid instead of the Play Store. Here's the QR code scanner I use: https://f-droid.org/en/packages/de.t_dankworth.secscanqr/

Anything wrong with binary eye? https://f-droid.org/packages/de.markusfisch.android.binaryey... I'm very happy with it

Binary Eye can also be found on the Play store - I personally check to see if apps are on both to add a bit of confidence, its not a negative if they're not but a positive +1 if they are co-listed when I'm deciding which widget to use.

Re: Barcode scanner app on Google Play infects 10M users with one update

#290
post #131

I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged. few QR code apps from F-Droid. https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...

Open source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-…

What app are you talking about specifically?
Post reply on HN