Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

321–330 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#321
post #93

Earlier quoted context omitted.

Source? Or you just made that up?

Here's an example of 18 such apps from 2019: https://www.wired.com/story/apple-app-store-malware-click-fr... Another from 2018: https://www.zdnet.com/article/top-mac-anti-adware-software-i...

The first didn't cause any user issues as I'm reading it except extra data usage. I don't think it even did it in the background but only when the app was running. So I wouldn't even call it malware. Unlike this Android app which showed ads to users outside the app.

The second is Mac not iOS which had a much more relaxed security model.

Re: Barcode scanner app on Google Play infects 10M users with one update

#322
post #267

Earlier quoted context omitted.

I'm just about old enough to remember the versions of Windows which didn't ship with TCP and you had to install "Trumpet Winsock" to get on the Internet. This was silly. The key to understanding the browser case is that, as MS wanted it, it would have tied client and server and rich application development together, all of which would have necessitated Windows. IE was a threat because of ActiveX.

It wasn't silly. It was third-party software which provided functionality that the OS simply lacked.

agreed, I lived through those times, TCP/IP was not a thing, until it was. There was no reason for it to be in the OS until it actually became popular and therefor useful

I used various competing systems before that in Windows/DOS

Re: Barcode scanner app on Google Play infects 10M users with one update

#323

Earlier quoted context omitted.

What app are you talking about specifically?

https://news.ycombinator.com/item?id=25492855 and https://news.ycombinator.com/item?id=25263876

why is nebulo not on fdroid?

Re: Barcode scanner app on Google Play infects 10M users with one update

#324

Earlier quoted context omitted.

I'm terrified of browser extensions for this very same reason (and yes, I still use them). I wish the browser vendors supported some kind of pinning to source code for open source extensions. Right now I have at least 2 extensions running that I know could access my passwords on any website as I enter them. One of those is Lastpass, which I use for storing/generating those passwords anyway, and the other is AdBlock P…

At least with LastPass you know they have a commercial model and reputation to incentivise better behaviour. If you download something that is free then that pressure doesn't exist.

[deleted]

Re: Barcode scanner app on Google Play infects 10M users with one update

#326

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

I reported a bunch as spam, but it probably netted me some negative reputation by their AI though.

Yeah, be careful doing anything like that on the Play Store. You can get your account randomly locked out with no explanation (I haven't been able to review apps, leave comments or contact the developer for like 3 years, and I never got an email or notice about this)

Re: Barcode scanner app on Google Play infects 10M users with one update

#327

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

My Android 10 phone from Samsung has both the flashlight and the QR code scanner icons in the drop down notification bar. I don't know if it is a standard Android feature or something from Samsung.

It's Samsung, though many other vendors also offer it.

Re: Barcode scanner app on Google Play infects 10M users with one update

#328

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

"Google creates barcode scanning app, replacing popular app with 10m+ downloads".

Platform providers are also criticized when natively offering features that apps offer. You sort of can't win.

Re: Barcode scanner app on Google Play infects 10M users with one update

#329

Earlier quoted context omitted.

I reported a bunch as spam, but it probably netted me some negative reputation by their AI though.

Yeah, be careful doing anything like that on the Play Store. You can get your account randomly locked out with no explanation (I haven't been able to review apps, leave comments or contact the developer for like 3 years, and I never got an email or notice about this)

If you have a gsuite account, that might be the reason. This started somewhere in 2018.

Re: Barcode scanner app on Google Play infects 10M users with one update

#330
post #325

This is why Ubuntu's forced auto-updates policy for snaps is crazy.

Google Chrome extensions are like this too. Not a coincidence that they've had multiple identical incidents where extensions were sold to malicious third parties or had malware added in.
Post reply on HN