Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

371–380 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#371

Earlier quoted context omitted.

Open source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-…

F-droid flags apps that have known anti-features. Using Open source software is a very significant security solution.

(F)OSS by itself is not a security solution. Largely because you can't "solve" security.

There are plenty of insecure open source apps. To deny that would be to deny tons of security-related CVEs.

Yes, open source software is easier to audit, but does nothing to a) make those audits actually happen (frequently enough), nor b) improves the quality of those audits.

i.e. just because I have access to information does not validate that information. Work still has to be done.

Re: Barcode scanner app on Google Play infects 10M users with one update

#372
post #350
post #343

Earlier quoted context omitted.

It really is pathetic. Looks more mafia-like every day - they grab control of a choke point, ensuring they get their vig, but otherwise show no interest in providing real security. It is just 'protection'.

What you describe is actually worse than the mafia. They would offer protection to some extent against third party rip-off.

Yeah, people from areas that used to be run by the mob often say they ran things better than the government did. Mobs require some form of community support to operate from what I understand.

The "real" government is really just another mob anyway. Pay your [protection money/taxes] or get your shop [busted up/shut down] and have other bad things happen to you.

Re: Barcode scanner app on Google Play infects 10M users with one update

#373

Earlier quoted context omitted.

Samsung phones have it in the camera, so I guess most Android users do have a barcode scanner built-in.

Why are Android users installing all these apps then? https://play.google.com/store/search?q=QR%20scanner&c=apps&h...

Personally, when I installed the app, there wasn't one built in. I just still had it lying around.

Re: Barcode scanner app on Google Play infects 10M users with one update

#374

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Don’t be naive, the majority will accept the money and gladly.

I wouldn't accept it to sneak the change in, but I'd probably be

Re: Barcode scanner app on Google Play infects 10M users with one update

#375

Earlier quoted context omitted.

> I trust them You literally mentioned a company that betrayed trust so bad a government tried to call them to account.

Are people capable of enough nuance to distinguish between issues that large tech firms are likely trustworthy on and issues that they aren't? When they stand to make billions from breaking my trust I'm sceptical. When they stand to make a penny and ruin their entire product, then no I' not. The problem in question here, that rogue developers sell out their product to third parties, is not an issue that Facebook, Goo…

Your whole premise is based on a very arbitrarily low value of collecting your plain text data? From a company that is a machine built for monetizing this specific thing? And that they wont because their users care about trust too much, users of Facebook products but specifically whatsapp? And you think the rest of us arent compartmentalizing our issues with that company enough?

this is.... I’m speechless, I ran out of words for this absurdity

Re: Barcode scanner app on Google Play infects 10M users with one update

#376

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

Apps that offer what should have been offered by the OS vendor in the first place.

Bundling can be seen as bad in terms of competition [0], but it can also be good for the user experience. I wonder if these apps go unimplemented for fear of regulation. It might be silly to think of a barcode scanner (or other small utility) in that way, but, if the app is so silly, then is it really worth the risk (not just from regulation, but from having to deal with bugs)?

0 - https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor....

Re: Barcode scanner app on Google Play infects 10M users with one update

#377

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

See https://github.com/zxing/zxing/issues/1345 and https://android.stackexchange.com/questions/233322/finding-a...

TL;DR someone apparently cloned ZXing Barcode Scanner, added annoying ads, uploaded it to the Play Store with the same name. Soon enough the malicious clone got taken down. Legitimately pissed off people who installed the malicious clone are leaving angry reviews for the non-malicious original (presumably because the malicious clone is gone from the Play Store).

Re: Barcode scanner app on Google Play infects 10M users with one update

#378

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Don’t be naive, the majority will accept the money and gladly.

I wouldn't accept it to sneak the change in, but I'd probably be perfectly willing to take their hand off and sell rights to the product. Assuming of course I didn't just delete the message assuming it was some sort of phishing scam or other rather than a genuine offer.

I'd feel obligated to make it known that I'd done this, perhaps via a notification in the app prior to hand-over and in its README. Something along the lines of a normal change of ownership message (copyright has been transferred to X, contact them for further information, future official releases will come from their fork, of course existing open source releases remain open source even if they change licencing arrangements for future releases, yadda yadda). Though we all know how often people just click through notifications, so I'm not sure how much difference that would really make - so if I were a robot I might be considered culpable under the second half of the first law...

If the buyer would walk away if I didn't agree to a more silent sale then I wouldn't touch it. It is a thin line that I won't cross, but still a line I like to think wouldn't cross. Then again I have the luxury of being relatively comfortable at this point in my life (decent day job at a company which is weathering the current collection of world crises pretty well, the little flat's mortgage near paid), for many others out there the financial incentive would be much harder to ignore. I'm not sure that I like that I wouldn't draw my line in a different place, but I'd be dishonest if I tried to claim that I would.

Re: Barcode scanner app on Google Play infects 10M users with one update

#379
post #334

Earlier quoted context omitted.

> Why are Google afraid to release a free non-harmful version of those popular apps. They already did; these have both been built-in for years. The flashlight was added in Android 5.0 ( https://www.androidauthority.com/android-5-0-lollipop-offici... I'm having a harder time figuring out when the barcode scanner was added, but my phone does it automatically in the camera app now. (Disclosure: I work for Google, speaki…

> these have both been built-in for years. If Android has a built-in QR scanner now, that must be something that came with Android 11, but September 8 2020 cannot qualify as "for years". It takes a while for OEM's to catch up as well. There are certainly Android phones that ships with this feature (QR-scanner), but stock Android 10 does not. (Google lens != Standard Photo app). If you know about it, you can start "Go…

I have a Pixel 3a, and I'm pretty sure it's done this since it was new (Spring 2019). I also thought my previous phone (Pixel 1) did it, though I don't have anymore and can't check.

Re: Barcode scanner app on Google Play infects 10M users with one update

#380
post #154

Earlier quoted context omitted.

But this is the classic cycle don't you see? They almost always start as "here is an app I threw together, no ads, don't be evil". But then a lot of people like your app, and ask for a small extra feature. You support it, and then get a bit annoyed by all the features people are asking for. Then you have to update it for the latest release... then suddenly fix it when some obscure version of Android breaks on it. The…

If the OP open sources his QR code reader app then the "free" model is absolutely sustainable.

The op did (it's in the description on the app store, but was unfortunately (considering the context and audience) left out from they comment:

https://github.com/prof18/Secure-QR-Reader

Post reply on HN