Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

341–350 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#341

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

My S21 Ultra has a QR scanner built in, but no barcode. Are the old ones still used for such purposes? I've only seen QR codes used for eg contact tracing.

Re: Barcode scanner app on Google Play infects 10M users with one update

#342

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

My Android phone has the barcode scanner app built in.

Also FM Radio, screen recorder and IR remote control.

Re: Barcode scanner app on Google Play infects 10M users with one update

#343
post #337

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

These app stores are a terrible software distribution model. Every day we hear about another reason they harm users far more than community maintained repositories and only protect the interests of the OS vendor.

It really is pathetic. Looks more mafia-like every day - they grab control of a choke point, ensuring they get their vig, but otherwise show no interest in providing real security.

It is just 'protection'.

Re: Barcode scanner app on Google Play infects 10M users with one update

#344
What I don't understand is why the internet permission (one of the most dangerous permissions in my opinion) is assumed to be always requested and not even reported when downloading an app. Sure, most apps need it (most of them for ads though) but at least warn me before installing like you do with other permissions like calls and sms.

But wait, there is more, that permission (and some others) are considered so harmless that if you install an app without it, and then the developer publish an update with it, play store will automatically update it without even asking! Remember this doesn't happen with 'dangerous' permissions, so apparently Google thinks accessing the internet is not dangerous at all.

Re: Barcode scanner app on Google Play infects 10M users with one update

#345
post #329

Earlier quoted context omitted.

Yeah, be careful doing anything like that on the Play Store. You can get your account randomly locked out with no explanation (I haven't been able to review apps, leave comments or contact the developer for like 3 years, and I never got an email or notice about this)

If you have a gsuite account, that might be the reason. This started somewhere in 2018.

Wait... why?! I can't think of a single reason Google would do this.

Re: Barcode scanner app on Google Play infects 10M users with one update

#346

Earlier quoted context omitted.

hopefully Apple will require consent soon for the ID for advertisers Just think through the implications of that phrase for a moment, though. Your own device comes with a built-in mechanism specifically designed for advertisers to track you. Why was that ever a good idea in the first place?

Such mechanisms have already existed and never needed OS-level sanction. It’s pretty clear that Apple is employing the strategy of “embrace, extend, extinguish” against tracking and privacy compromising dark patterns. In other words, force developers to use a special API, then give consumers the ability to block it. The current stoush with Facebook is only the most formidable hurdle Apple has encountered so far.

That is the usual argument, but I don't see how it stands up to scrutiny.

Either there are alternative ways to track a user of an Apple device without IDFA or there are not. If there are, then it is reasonable to assume that unethical advertisers will return to using them if their access to IDFA is gated.

So, whether or not IDFA exists, the only robust way to protect users is to block apps from having access to anything about the host device that implicitly provides a unique method of identifying the user.

This is what other platforms have been trying to achieve. For example, in the web browser ecosystem, software has been restricting programmatic access to features that can be used for fingerprinting or deliberately reducing the level of detail exposed by some APIs.

With control of the entire ecosystem, why is Apple not better placed to adopt this strategy than anyone else, and whether or not Apple is technically capable of achieving the perfect result, how does introducing IDFA make any difference?

Re: Barcode scanner app on Google Play infects 10M users with one update

#347

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

While Google Lens does the job for the most part, we created a free privacy minded security first app - https://dhiway.com/seqr/ This app plugs in to Google's anti-malware lookup service to flag harmful content from making it to the device.

Re: Barcode scanner app on Google Play infects 10M users with one update

#348

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

I knew nothing of ZXing Barcode Scanner other than it was super simple and "just works." Nice to know that it's open source! I've been happily using on all my android phones since I started with the HTC Dream so many years ago.

Re: Barcode scanner app on Google Play infects 10M users with one update

#349

Earlier quoted context omitted.

yeah this is one reason why I can't take mobile app end to end encryption, or client side only, claims seriously. a single update at any time could undermine all of that and secondly, they or an analytics package can just read everything client side and upload it to a server anyway doesn't matter if its whatsapp, or signal, or some protonmail client if such a thing exists I just don't use them with that assurance in…

>yeah this is one reason why I can't take mobile app end to end encryption, or client side only, claims seriously. If it's a large company like Facebook that values these products like Whatsapp at billions I trust them at least on this issue. I'm pretty sure they're not going to put junk third party malware for 50k into the Whatsapp client. This is mostly an issue for apps done by individual developers who have huge…

>If it's a large company like Facebook that values these products like Whatsapp at billions I trust them at least on this issue. I'm pretty sure they're not going to put junk third party malware for 50k into the Whatsapp client.

Zuck: They "trust me"

Zuck: Dumb fucks.

Re: Barcode scanner app on Google Play infects 10M users with one update

#350
post #343
post #337

Earlier quoted context omitted.

These app stores are a terrible software distribution model. Every day we hear about another reason they harm users far more than community maintained repositories and only protect the interests of the OS vendor.

It really is pathetic. Looks more mafia-like every day - they grab control of a choke point, ensuring they get their vig, but otherwise show no interest in providing real security. It is just 'protection'.

What you describe is actually worse than the mafia. They would offer protection to some extent against third party rip-off.
Post reply on HN