Earlier quoted context omitted.
Yeah, it's always in the flashlights, the barcode scanners, the background packs. They all address super basic functionality that many, many people seem to want (if I could just set a ringtone from YouTube, it'd save me from going through a bunch of shady apps, if I ever needed a ringtone that is). Yet they just aren't included in the base OS (or weren't always, my lineage OS has a flashlight currently). Therefore, t…
> they just aren't included in the base OS Both a QR-capable camera and a flashlight in the notification bar are in all my Android phones, and they've been for a very long time. I know the Nexus One didn't include it, but those will have problems with modern TLS anyway. The problem is likely elsewhere. It wouldn't surprise me if many of these users are tricked into installing these apps. It is quite popular for malwa…
Barcode scanner app on Google Play infects 10M users with one update
401–410 of 465 posts
Re: Barcode scanner app on Google Play infects 10M users with one update
#402Earlier quoted context omitted.
> Yeah, it's always in the flashlights, the barcode scanners, the background packs. Why are Google afraid to release a free non-harmful version of those popular apps. Is it to keep the illusion the app-store is a vibrant market place where tons of developers get rich? It just seems nuts to allow all those harmful apps (that does virtually nothing) to float among the top downloads.
> Why are Google afraid to release a free non-harmful version of those popular apps. They already did; these have both been built-in for years. The flashlight was added in Android 5.0 ( https://www.androidauthority.com/android-5-0-lollipop-offici... I'm having a harder time figuring out when the barcode scanner was added, but my phone does it automatically in the camera app now. (Disclosure: I work for Google, speaki…
[1] https://medium.com/turunen/built-in-qr-reader-on-android-696...
Re: Barcode scanner app on Google Play infects 10M users with one update
#403The same goes for Chrome Extensions which have been removed from the Chrome Web Store. In that case, they get removed automatically from the browser, which is somewhat ok. I would prefer that they would get disabled without me being able to enable it again, and get labeled as malicious. Because how else can I verify that I once installed an extension or an app which then turned malicious?
Currently I know that either one of my or my dad's devices has something malicious on it, because I got an HTTP GET request to a URL whose full path is only known to our devices (and only via HTTPS).
Re: Barcode scanner app on Google Play infects 10M users with one update
#404Earlier quoted context omitted.
> We are at a point where auto-updates are more risky than the security flaw itself - especially since iOS has a pretty good sandbox, especially since its impossible for one app to access the data of another. Additionally, the App usually connects to a pretty limited set of servers, and is not publicly reachable. So the attack vector is pretty small. I'd have to say that most apps now connect to a rather large number…
> there's no outbound traffic filtering to check the system isn't leeching user data and/or device identifiers But there is the iOS sandbox FS. So if an App gets exploited, it can only every leech the data from exactly THAT app. Just the same as an auto-update might just start to leech and upload that data. Given the real-world practices, I think it is more likely an App creator choses to upload the data, than some m…
I fear however that the majority of "regualar users" are being coerced into giving consent without realising what is happening - seeing the number of people end up in a FOMO-induced panic to join Clubhouse (or whatever the next big popular phone number based app is), a simple "give access to your contacts to invite a friend" masks the fact the app uploads your contacts to the server every time you open the invite tab.
It feels we need to address coercive practices or at least try to do some kind of taint analysis to allow iOS to alert that it believes the memory buffer about to go into a networking API originates from a permission-protected memory buffer, and are you sure you want to let the app upload your contacts... But I suspect we just end up shifting the problem, and they coerce users again, ad infinitum, until they harvest their social graph (illegally, at least in Europe/UK).
Re: Barcode scanner app on Google Play infects 10M users with one update
#405Earlier quoted context omitted.
> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…
> To make matters worse, scanning a barcode when you enter a store/cafe (to register your location), is now begin done everywhere in order to track potential covid19 spreaders. This forces anyone without an iPhone to install at least one of these potentially harmful apps. Our (New Zealand) Covid tracing app scans QR codes itself. What jurisdictions are requiring to scan an arbitrary QR code using random apps? https:/…
Re: Barcode scanner app on Google Play infects 10M users with one update
#406Re: Barcode scanner app on Google Play infects 10M users with one update
#407Earlier quoted context omitted.
F-droid flags apps that have known anti-features. Using Open source software is a very significant security solution.
(F)OSS by itself is not a security solution. Largely because you can't "solve" security. There are plenty of insecure open source apps. To deny that would be to deny tons of security-related CVEs. Yes, open source software is easier to audit, but does nothing to a) make those audits actually happen (frequently enough), nor b) improves the quality of those audits. i.e. just because I have access to information does no…
The same can't be said about 'free' (or sometimes even paid) proprietary apps from play store.
Re: Barcode scanner app on Google Play infects 10M users with one update
#408This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…
I knew nothing of ZXing Barcode Scanner other than it was super simple and "just works." Nice to know that it's open source! I've been happily using on all my android phones since I started with the HTC Dream so many years ago.
https://play.google.com/store/apps/details?id=com.srowen.bs....
Re: Barcode scanner app on Google Play infects 10M users with one update
#409I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads. Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it…
Buy iPhone.
I know some people hate Apple but these type of things never happen or so rare. I hear android malware very often though.
Re: Barcode scanner app on Google Play infects 10M users with one update
#410Android doesn't actually need a 3rd party barcode scanner app. Google Lens supports barcodes.