Earlier quoted context omitted.
"Better" is certainly a point of view here. Having to tell the government all of your whereabouts when you already live on an Island with no spreading is an overreach, IMO.
The New Zealand government doesn't learn "all your whereabouts" by default. The app is storing locally what it has learned about places you visited by scanning QR codes, and comparing that to information it is being sent over the Network (by the government) to discern if you went anywhere that the government says warrants special action - if so you get notified. For most Kiwis this means a bunch of QR code data is st…
Barcode scanner app on Google Play infects 10M users with one update
431–440 of 465 posts
Re: Barcode scanner app on Google Play infects 10M users with one update
#432Earlier quoted context omitted.
Two words for you: Buy iPhone. I know some people hate Apple but these type of things never happen or so rare. I hear android malware very often though.
Three words: Buy Nokia 3310. These types of things literally never happen. Or maybe people have a lot of reasons for why they chose what they chose and this isn't productive.
Re: Barcode scanner app on Google Play infects 10M users with one update
#433Arguably manual curation doesn't scale to google play store or apple app store size and automated scanning only gets you so far.
You have several possible threats.
1. Apps that are malicious from the start.
Best addressed by better automated testing.
2. Apps that become malicious particularly when the app changes hands.
Best addressed by making this impossible. James/foo should never be transferred ownership should result in Jane/foo which users would have to download.
3. Apps that aren't malicious but include a component that is user hostile. Virtually always included for money.
Best addressed by just forbidding apps with ads. We wont do this but not much of value would be lost.
4. Apps that include a component that isn't malicious but itself becomes malicious later.
Requires due diligence by the developer. Arguably one could imagine better automated enumeration of the constituent components to discern what might have been compromised so that developers could have their apps automatically pulled and informed that they were compromised. One could also imagine a statutory fine for paid that earn developer revenue wherein their product harms users. This couldn't accrue to free apps without making foss impossible. Eliminating apps paid for with ads would eliminate a gray area.
An interesting point for those who presently avoid ad laden apps is whether your paid for apps are infected with the same potential malware vectors as the ad supported version as whether or not to show ads may be solely a function of an in app purchase you have made. Your paid for app might therefore be just as vulnerable.
What reasonable measures would one expect Google to actually take? Probably only reactive measures like removing this particular app while making no meaningful moves to correct any systemic problems. In the longer term one might expect them to do a better job of finding malware automatically.
If you value not getting hacked in the longer term it looks like this is insufficient. If for example Fdroid is insufficient in scope of applications then perhaps we should work on improving this situation as Google is unlikely to fix this for us.
Re: Barcode scanner app on Google Play infects 10M users with one update
#434Earlier quoted context omitted.
Here's an example of 18 such apps from 2019: https://www.wired.com/story/apple-app-store-malware-click-fr... Another from 2018: https://www.zdnet.com/article/top-mac-anti-adware-software-i...
The first didn't cause any user issues as I'm reading it except extra data usage. I don't think it even did it in the background but only when the app was running. So I wouldn't even call it malware. Unlike this Android app which showed ads to users outside the app. The second is Mac not iOS which had a much more relaxed security model.
A Forbes article on the same incident also reports that data was exfiltrated from the infected devices:
> the trojan [...] sent data from the infected device to an external command and control server.
Re: Barcode scanner app on Google Play infects 10M users with one update
#435Re: Barcode scanner app on Google Play infects 10M users with one update
#436Re: Barcode scanner app on Google Play infects 10M users with one update
#437I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads. Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it…
Were you using the app from ZXing team https://play.google.com/store/apps/details?id=com.google.zxi... app? Because this app was last updated in 2018, has a generic name Barcode Scanner, & has attracted hundreds of reviews like yours saying App was updated recently, & now causes Web Ads. For a counter point, I am also using this app since 2016, & have all apps on auto update, & have never received any web add popup o…
It took me a bit of digging to make the distinction. I have both of them listed in my App Library, and both with the same name. At some point, I believe I went to install ZXing on a new phone and Android warned me that the app may be incompatible, so I went to the space team one. It makes sense that if people aren't looking directly in their app library that they can get these mixed up and leave the bad reviews.
However, since the space team version got infected, I did try the ZXing app - no pop-ups, and it works just fine (despite the age warning).
https://play.google.com/store/apps/details?id=com.qrcodescan...
Re: Barcode scanner app on Google Play infects 10M users with one update
#438Re: Barcode scanner app on Google Play infects 10M users with one update
#439Guess this is why some walled gardens look a lot nicer from the inside...
Re: Barcode scanner app on Google Play infects 10M users with one update
#440The only reason this was detected was very overt behavior - opening AD popups. So I guesstimate for each one of these we have 10 that go undetected. This means the whole ecosystem is broken, as there is no reason this will happen only for updates and not for new apps as well. Apple's ecosystem is somewhat better, but I can't imagine they go through every line of code in each package, so most of their review is probab…
This happened on ios for me years ago. I had two apps that radically changed their business model (owner?) through updates with no recourse. I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remi…
Neither of the 2 scenarios you describe are even remotely what's happened here. Not sure how you got from 'malicious ad popups' to 'app added cloud feature'.