Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

381–390 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#381

Earlier quoted context omitted.

Yeah, on Pixel phones you can just scan the barcode from the camera app, or from Google Lens

I just tried the camera app with a QR code (on a Pixel 5) and nothing happened.

Its provided by Google Lens suggestions, so you'll need to have that enabled in the Camera settings for it to appear. It also seems a little slow sometimes, give it a few seconds for it to show up a small suggestion bubble at the bottom of the viewfinder.

I'm using Google Camera version 8.1 on a fully updated Pixel 4a and it works for me.

Re: Barcode scanner app on Google Play infects 10M users with one update

#382
post #337

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

These app stores are a terrible software distribution model. Every day we hear about another reason they harm users far more than community maintained repositories and only protect the interests of the OS vendor.

App stores are no more terrible than the previous software distribution model where you Google the name of the software you want to install, find some site that "mirrors" the download, realize they've repackaged the original app with extra ads and toolbars, keep searching, find the official download link, scroll past all the misleading ads containing download buttons, download the package, and then hope the download runs on your machine.

Anybody complaining about app stores has forgotten how bad the alternatives are. And community-maintained repositories aren't a solution, that's just the app store model but on a smaller scale so it's less of a Target for bad actors. If ubuntu's universe repo had to suffer the same amount of abuse as the play store does, it would crumble in a day.

Re: Barcode scanner app on Google Play infects 10M users with one update

#383

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

Don't assume malice when it can be explained by stupidity; it is probably a confusion as there are many apps with very similar names and in the phone the publisher is usually not listed (I checked mine), so people with the malware app gave reviews to other apps.

Re: Barcode scanner app on Google Play infects 10M users with one update

#384

Earlier quoted context omitted.

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

"Google creates barcode scanning app, replacing popular app with 10m+ downloads". Platform providers are also criticized when natively offering features that apps offer. You sort of can't win.

There probably could be some backlash, but it would be easy for Google to brush this off by listing harmful features they removed in the process.

They have done more drastic things in the past. They have even removed apps entirely from Android phones due to very harmful features, and nobody cared when they heard about the horrid things these apps did in the background.

Re: Barcode scanner app on Google Play infects 10M users with one update

#385
post #364

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

Gotta love that those bogus 1-star reviews stay up, but Google instantly came to the rescue of Robinhood when it was getting flooded by 1-star reviews that had an actual legitimate basis.

Robinhood's app has a 1.2 star rating at the moment.

https://play.google.com/store/apps/details?id=com.robinhood....

Re: Barcode scanner app on Google Play infects 10M users with one update

#386
post #303

Meanwhile they block the Terraria developer's Google account, after which he's decided to cancel his game's port to Stadia. How are they so bad at this? Literally driving away legitimate developers while letting scammers run wild.

What's easy to do for a thousand apps is impossible to do for a million apps.

Large scale is not a new quantity, it's a new quality.

Re: Barcode scanner app on Google Play infects 10M users with one update

#387

Earlier quoted context omitted.

> Imagine an authenticator app I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good. I will also imagine that when people install authenticators, they would NOT trust one from HenryBemis but only from sources that they recognize (Google, Microsoft, Yubikey, etc.) It always amazes me how come all smartphone OS creators switch every connectivity…

> I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good. Dear HenryBemis, As a CEO of TRC, I would like to extend you an offer to purchase source and distribution rights to your app, SummerChildAuthenticator, to the form of $500,000 (five hundred thousand US dollars). We are a fast growing SV startup that wants to make it easier for people to s…

I hear you.

Any developer knows/understands if the offer comes from a legit source or scumbag. I cannot make other people's choices for them. My answer would be 'no' even for 100k, BUT I am in HN and I suggest people get off facebook and google because they are privacy nightmares (also certified in a couple of audit/security areas - so there's that). Btw I did have an app on Apple store, target audience was children (3-6 years old), it did OK, I just didn't have the time to keep it around (for the little revenue it was bringing). It worked 100% offline, no tracking, no ads, no nothing. I have a free version as a sample and the full version at $0.99. I chose to sell than help the ad beast grow bigger and track children more.

But that is just me. $50k is a serious amount but it won't make me or break me. For some other parts of the world, where a monthly salary may be $200.....

Re: Barcode scanner app on Google Play infects 10M users with one update

#388

Earlier quoted context omitted.

Switch to Google Lens in the Camera app. It's way less reliable but it usually gets the job done.

What do you mean by way less reliable? While Google will not start any overly obnoxious ad-serving, who tells you they will not upload all or a bit more stealthily some pictures for some AI user profiling thingie? Cannot happen? They collected WiFi access points when doing Streetview back when their motto was "Don't be evil".

Sometimes it decides that I'm actually searching for pictures of QR codes and gives me Google Search results for similar pictures of QR codes, which is kind of useless.

As for the second part, that's your personal risk tolerance so I'm going to leave that to you. Google is generally a high-trust brand in America, so most people will find the risk tolerable. If you don't find it tolerable, you shouldn't use it.

Re: Barcode scanner app on Google Play infects 10M users with one update

#389

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

I reported a bunch as spam, but it probably netted me some negative reputation by their AI though.

It’s doubtful that any AI is involved, but I wouldn’t be surprised if Google have an algorithm that decides thay X number of negative reviews must be spam, without considering the quality and correctness of the review.

Re: Barcode scanner app on Google Play infects 10M users with one update

#390
post #364

Earlier quoted context omitted.

Gotta love that those bogus 1-star reviews stay up, but Google instantly came to the rescue of Robinhood when it was getting flooded by 1-star reviews that had an actual legitimate basis.

Robinhood's app has a 1.2 star rating at the moment. https://play.google.com/store/apps/details?id=com.robinhood....

Google was well known to have removed about 100k low rating reviews during the peak: https://www.theverge.com/2021/2/1/22261178/robinhood-google-...
Post reply on HN