Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

311–320 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#311
post #131

I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged. few QR code apps from F-Droid. https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...

Same here. The first one is also installable from Google Play with a different package name however : https://play.google.com/store/apps/details?id=org.barcodesca... It also uses the ZXing library. It does not contain any tracking or ad SDK's per the exodus report : https://reports.exodus-privacy.eu.org/en/reports/org.barcode...

The second one too:

https://play.google.com/store/apps/details?id=com.secuso.pri...

Re: Barcode scanner app on Google Play infects 10M users with one update

#312

We are the same guys want every app to be free. Do you expect bread to be free or coffee to be free? Why we expect apps to be free even from google? How do you think small app developers earn money by displaying ads? But we want ads to be blocked and don’t want to pay money

Ads within the app are fine, and I don't think many people who download a free app expect to have zero ads unless it says it.

THIS app, however, displayed ads outside of the application when the phone was unlocked. It's not the same thing, and it's not ok.

Re: Barcode scanner app on Google Play infects 10M users with one update

#313

Earlier quoted context omitted.

Yeah, it's always in the flashlights, the barcode scanners, the background packs. They all address super basic functionality that many, many people seem to want (if I could just set a ringtone from YouTube, it'd save me from going through a bunch of shady apps, if I ever needed a ringtone that is). Yet they just aren't included in the base OS (or weren't always, my lineage OS has a flashlight currently). Therefore, t…

Yeah, on Pixel phones you can just scan the barcode from the camera app, or from Google Lens

Same on iOS; the camera will recognize QR codes and offer to open.

Re: Barcode scanner app on Google Play infects 10M users with one update

#314

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

I reported a bunch as spam, but it probably netted me some negative reputation by their AI though.

Re: Barcode scanner app on Google Play infects 10M users with one update

#315

Earlier quoted context omitted.

> Yeah, it's always in the flashlights, the barcode scanners, the background packs. Why are Google afraid to release a free non-harmful version of those popular apps. Is it to keep the illusion the app-store is a vibrant market place where tons of developers get rich? It just seems nuts to allow all those harmful apps (that does virtually nothing) to float among the top downloads.

FWIW I've not had an Android phone lacking a flashlight in the OS since... ever, I think. At a guess, the apps are preying on customers not aware of the OS-level functionality. QR scanning seems a little more complicated. FF for Android integrates a QR scanner, but chrome does not. Google's default camera also opens links, if you allow Google Lens.

[deleted]

Re: Barcode scanner app on Google Play infects 10M users with one update

#316

Earlier quoted context omitted.

It's manually curated and generally flags such things as anti-features if found, and I'd believe them more than some tensorflow_script_to_detect_malware.py

I wouldn't depend on F-Droid or FOSS as a measure of security. Of course, I get that F-Droid is run by volunteers, but I hope no one is spreading the notion that the F-Droid apps are magically uber secure and private or anything.

I wasn't clear. What I told was comparative.

Re: Barcode scanner app on Google Play infects 10M users with one update

#317

Earlier quoted context omitted.

> Yeah, it's always in the flashlights, the barcode scanners, the background packs. Why are Google afraid to release a free non-harmful version of those popular apps. Is it to keep the illusion the app-store is a vibrant market place where tons of developers get rich? It just seems nuts to allow all those harmful apps (that does virtually nothing) to float among the top downloads.

> Why are Google afraid to release a free non-harmful version of those popular apps. Fear of anti-competition lawsuits and complaints. They're seeing what happens when Apple integrates stuff into iOS / OS X core that previously were third party provided, or the flak that Amazon gets for pushing AmazonBasics products.

QR scanning is already built into the camera app. So, not this has nothing to do integration, it's already integrated.

Those QR code scanner apps are basically taking advantage of people not knowing they don't need one.

Re: Barcode scanner app on Google Play infects 10M users with one update

#318
post #127

I recently noticed that the "Barcode Scanner" app by ZXing ( https://play.google.com/store/apps/details?id=com.google.zxi... ) was being review-bombed with 1* reviews. People were talking about the "recent update", even though the last update is from February 2019. As far as I know, that app is open source and never contained ads. (Of course, without reproducible builds, we'll never know for sure.) Was ZXing also hit…

To be clear : "the December 2020 build was infected with malware" only refers to the lavabird barcode scanner and not other apps (that use ZXing library or not).

Re: Barcode scanner app on Google Play infects 10M users with one update

#319

Earlier quoted context omitted.

I'm terrified of browser extensions for this very same reason (and yes, I still use them). I wish the browser vendors supported some kind of pinning to source code for open source extensions. Right now I have at least 2 extensions running that I know could access my passwords on any website as I enter them. One of those is Lastpass, which I use for storing/generating those passwords anyway, and the other is AdBlock P…

At least with LastPass you know they have a commercial model and reputation to incentivise better behaviour. If you download something that is free then that pressure doesn't exist.

have you read their privacy policy? They layout they can spy on everything and share with anyone they want.

You'd think if they were serious about privacy their privacy policy would just say "we spy on nothing and collect nothing and share with no one". 1password effectively has that privacy policy, lastpass does not.

https://www.logmeininc.com/legal/privacy/us

https://1password.com/jp/legal/privacy/

Re: Barcode scanner app on Google Play infects 10M users with one update

#320

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

[deleted]
Post reply on HN