Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

331–340 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#331
post #329

Earlier quoted context omitted.

Yeah, be careful doing anything like that on the Play Store. You can get your account randomly locked out with no explanation (I haven't been able to review apps, leave comments or contact the developer for like 3 years, and I never got an email or notice about this)

If you have a gsuite account, that might be the reason. This started somewhere in 2018.

Oh, that explains it! Mystery solved, thanks :-)

Re: Barcode scanner app on Google Play infects 10M users with one update

#332
post #262

Earlier quoted context omitted.

FWIW I've not had an Android phone lacking a flashlight in the OS since... ever, I think. At a guess, the apps are preying on customers not aware of the OS-level functionality. QR scanning seems a little more complicated. FF for Android integrates a QR scanner, but chrome does not. Google's default camera also opens links, if you allow Google Lens.

About four years ago, when I had a low end Android phone, some kind of "make the screen white" app was really useful. I remember the play store being scary but I think there was something in fdroid. I am not so sure on this, but I do not recall my nexus 5 having flashlight in the OS.

I have a Nexus 5, and I can confirm the flashlight is available in the system tray icon. This is true for all Google phones since at least Nexus 4. It is my understanding that AOSP as well as Google's Android implementation has always exposed access to the flashlight hardware (although somebody mentioned this not being the case with Nexus One).

Re: Barcode scanner app on Google Play infects 10M users with one update

#333

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=25492855 and https://news.ycombinator.com/item?id=25263876

why is nebulo not on fdroid?

It is on the main developer's f-droid repo: https://github.com/Ch4t4r/Nebulo#f-droid

Re: Barcode scanner app on Google Play infects 10M users with one update

#334

Earlier quoted context omitted.

Yeah, it's always in the flashlights, the barcode scanners, the background packs. They all address super basic functionality that many, many people seem to want (if I could just set a ringtone from YouTube, it'd save me from going through a bunch of shady apps, if I ever needed a ringtone that is). Yet they just aren't included in the base OS (or weren't always, my lineage OS has a flashlight currently). Therefore, t…

> Yeah, it's always in the flashlights, the barcode scanners, the background packs. Why are Google afraid to release a free non-harmful version of those popular apps. Is it to keep the illusion the app-store is a vibrant market place where tons of developers get rich? It just seems nuts to allow all those harmful apps (that does virtually nothing) to float among the top downloads.

> Why are Google afraid to release a free non-harmful version of those popular apps.

They already did; these have both been built-in for years. The flashlight was added in Android 5.0 (https://www.androidauthority.com/android-5-0-lollipop-offici... I'm having a harder time figuring out when the barcode scanner was added, but my phone does it automatically in the camera app now.

(Disclosure: I work for Google, speaking only for myself)

Re: Barcode scanner app on Google Play infects 10M users with one update

#335
My first ever mobile app was an experimental bit of Android Malware. It got demo'd by my colleague at Blackhat [1]. I'm definitely not a hacker, but with a few basic tricks I was able to create a pretty effective trojan which we then injected into a popular game (again only for experimental purposes, it was never released in the wild). In our lab we had literally millions of samples of Android malware, but for iOS we had only two (which only worked on jailbroken phones). Fun times.

1. https://www.softwaretalks.io/v/4047/black-hat-usa-2013-how-t...

Re: Barcode scanner app on Google Play infects 10M users with one update

#336

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

On android (and I think iPhone too) you can scan barcodes with the camera app. It's not obvious, but I learned this from servers this year.

When we sit down they just say, "use your camera app to scan the barcode". It seemed to work for everyone at the table. Samsung, Pixel, and iPhone.

Re: Barcode scanner app on Google Play infects 10M users with one update

#337

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

These app stores are a terrible software distribution model. Every day we hear about another reason they harm users far more than community maintained repositories and only protect the interests of the OS vendor.

Re: Barcode scanner app on Google Play infects 10M users with one update

#338

Earlier quoted context omitted.

I'm terrified of browser extensions for this very same reason (and yes, I still use them). I wish the browser vendors supported some kind of pinning to source code for open source extensions. Right now I have at least 2 extensions running that I know could access my passwords on any website as I enter them. One of those is Lastpass, which I use for storing/generating those passwords anyway, and the other is AdBlock P…

Alas the Great Suspender just fell prey to malware after its creator sold it off: https://news.ycombinator.com/item?id=25846504 I think Apple have the right idea with app review on browser extensions for Safari.

The other nice thing about Safari’s approach is that for common extension functionality it is just a set of rules that are executed. So no malware can be run because extension code isn’t actually reading the dom. Nor does it have access to load remote resources.

Re: Barcode scanner app on Google Play infects 10M users with one update

#339
post #329

Earlier quoted context omitted.

Yeah, be careful doing anything like that on the Play Store. You can get your account randomly locked out with no explanation (I haven't been able to review apps, leave comments or contact the developer for like 3 years, and I never got an email or notice about this)

If you have a gsuite account, that might be the reason. This started somewhere in 2018.

I have the same problem - paying Google customer, so I'm not allowed to leave ratings or reviews on Google's app store. Support's ignored my requests on this.

Re: Barcode scanner app on Google Play infects 10M users with one update

#340

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

"Google creates barcode scanning app, replacing popular app with 10m+ downloads". Platform providers are also criticized when natively offering features that apps offer. You sort of can't win.

the platform should accept the criticism, because it doesn't hurt them. they have no feelings.

People doing low effort apps can only just whinge when the floor shifts under them. i have no sympathy - they just need to adapt and improve, and create new value to sell.

Post reply on HN