Earlier quoted context omitted.
These app stores are a terrible software distribution model. Every day we hear about another reason they harm users far more than community maintained repositories and only protect the interests of the OS vendor.
App stores are no more terrible than the previous software distribution model where you Google the name of the software you want to install, find some site that "mirrors" the download, realize they've repackaged the original app with extra ads and toolbars, keep searching, find the official download link, scroll past all the misleading ads containing download buttons, download the package, and then hope the download…
Barcode scanner app on Google Play infects 10M users with one update
411–420 of 465 posts
Re: Barcode scanner app on Google Play infects 10M users with one update
#412Android doesn't actually need a 3rd party barcode scanner app. Google Lens supports barcodes.
Average users don't know the default capabilities of their own phones and instinctively go to the app stores to find their one purpose ad filled apps. I've seen flashlight, basic camera, weather, clock apps that are inferior to default apps of the phones installed on many client devices.
Re: Barcode scanner app on Google Play infects 10M users with one update
#413This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…
One solution might be to only publish reviews/ratings from accounts with a minimum spend threshold and unique active payment details. This would effectively price out the scammers.
Re: Barcode scanner app on Google Play infects 10M users with one update
#414This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…
This review fraud has got way out of hand. Right now, it would be better to remove reviews entirely and for consumers to make a decision based on the product page alone. The consumer trust in reviews is at such a low that it’s adding friction to purchase decisions and starving honest businesses from being able to invest in quality products. One solution might be to only publish reviews/ratings from accounts with a mi…
Re: Barcode scanner app on Google Play infects 10M users with one update
#415This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…
This review fraud has got way out of hand. Right now, it would be better to remove reviews entirely and for consumers to make a decision based on the product page alone. The consumer trust in reviews is at such a low that it’s adding friction to purchase decisions and starving honest businesses from being able to invest in quality products. One solution might be to only publish reviews/ratings from accounts with a mi…
The sheer scale of situations where the top review is negative describes something that ... is not a bug, is actually supposed to be that way, is how the dang app works by design for good reason ... is bonkers.
It seems like reviews are driven by people who don't know, and respond reviews by to people who don't know who describe what sounds like fundamentally broken things... so they give it a thumbs up and they're both completely ignorant.
The volume of people who do know the app and would see / write a review seems like it is MUCH smaller.
I had a game app update recently. I went to update it (one of the few times I go directly to the play store app). There at the top is a review that described how they saw opposing players "just disappear" during the game and raged about that 'bug'. But it's not a bug the game has some fog of war and view distance type mechanic. It's entirely expected / appropriate.... but there it is the top review.
Re: Barcode scanner app on Google Play infects 10M users with one update
#416This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…
https://f-droid.org/en/packages/com.google.zxing.client.andr...
Re: Barcode scanner app on Google Play infects 10M users with one update
#417I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads. Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it…
Two words for you: Buy iPhone. I know some people hate Apple but these type of things never happen or so rare. I hear android malware very often though.
Buy Nokia 3310.
These types of things literally never happen.
Or maybe people have a lot of reasons for why they chose what they chose and this isn't productive.
Re: Barcode scanner app on Google Play infects 10M users with one update
#418I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads. Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it…
So just to be aware, what was the root cause of this incident? Was it permission settings? How did it slip through the release process on Google Play, or is there none at all? What does this mean for other apps with overreaching permissions?
The key here is that the author had a properly working, trusted, non-invasive application for years and then they pushed an updated version that was less so. Fortunately, it was an app with minimal permissions - it could only open web pages. In my case, running ublock, those pages came up blank. But for others not running an ad filter, they got pop-ups prompting them to install even more malware.
As for Google Play release process, I can't speak on that too much. They do scan for malicious code, but this code may not be malicious enough. If part of an application's purpose is to open web links, more code that opens links would not be as noticeable. Apple has a more intensive process to review new apps, and they spot-check app updates, but it's going to be somewhat similar. We hear about Apple pulling existing applications all the time for random reasons, but it's often after an update or report. Google pulled some of these apps after they were reported, but it was also after.
I'm not defending Google Play - they have a more relaxed review process than Apple, relying more on automation. But both have "legitimate" apps pulled for obscure reasons (and the only recourse seems to be getting attention on HN/Twitter/other), and both have let scam apps through. Apple seems to catch more of the "bad" apps, but also drops more legitimate apps that compete with Apple's business interest.
Re: Barcode scanner app on Google Play infects 10M users with one update
#419Earlier quoted context omitted.
> they just aren't included in the base OS Both a QR-capable camera and a flashlight in the notification bar are in all my Android phones, and they've been for a very long time. I know the Nexus One didn't include it, but those will have problems with modern TLS anyway. The problem is likely elsewhere. It wouldn't surprise me if many of these users are tricked into installing these apps. It is quite popular for malwa…
Discoverability is just as much an issue as feature including. If you have to go into a special QR mode (which a lot of cameras did), you’re never going to use the feature, and it’s hard to break those mental models if the feature gets silently added in later iterations; you’re always going to remember that first encounter where something didn’t work seamlessly.
Re: Barcode scanner app on Google Play infects 10M users with one update
#420This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…
The ZXing Barcode Scanner (which is the "official barcode/QR code scanner for Android, as far as _I_ am concerned) is also available on f-droid.org. There's no absolute guarantee that F-Droid apps are malware-free but they have at least been looked at by a competent team of humans, something that is not true of the Play Store. https://f-droid.org/en/packages/com.google.zxing.client.andr...
I mean, I could very well make an open source app and then load some malware in the apk in addition to the well behaved thing... Are they immune from this attack?