Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

451–460 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#451

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> This can have a big impact for end users. Imagine an authenticator app ending service to all their users in such a scheme and how you will be cut out from all your accounts by this. How many authenticator apps do you have to use in parallel to mitigate this risk of a single point of failure? This right here is a big reason, apart from actual restorable backups, why I root my Android device. Sure it is not required…

I, like many other HNers, simply store the secret passphrase & QR code in a separate keypass database.

Recently Google Authenticator app added the ability to move all codes to next phone by displaying multiple sequence of QR codes, but I coded a simple no internet just local storage & javascript app to to utilize otpauth:// protocol to eadily readd the codes on new phone https://spa.bydav.in/otp.html

Re: Barcode scanner app on Google Play infects 10M users with one update

#452

Earlier quoted context omitted.

Such mechanisms have already existed and never needed OS-level sanction. It’s pretty clear that Apple is employing the strategy of “embrace, extend, extinguish” against tracking and privacy compromising dark patterns. In other words, force developers to use a special API, then give consumers the ability to block it. The current stoush with Facebook is only the most formidable hurdle Apple has encountered so far.

That is the usual argument, but I don't see how it stands up to scrutiny. Either there are alternative ways to track a user of an Apple device without IDFA or there are not. If there are, then it is reasonable to assume that unethical advertisers will return to using them if their access to IDFA is gated. So, whether or not IDFA exists, the only robust way to protect users is to block apps from having access to anyth…

> I don't see how it stands up to scrutiny.

That would be premature. Nobody is in a position to know how the "extinguish" portion of the plan will turn out because it hasn't happened yet. All we can say is that the plan looks quite robust in theory and would be a significant coup for Apple if they can pull it off.

Obviously there will always be some unethical operators, but that is true of all major platforms. Apple has the benefit of top-down control and some amount of market incentive to get it right.

> For example, in the web browser ecosystem

...there is precious little to block effective fingerprinting of 99%+ of installs and little prospect of that changing.

Re: Barcode scanner app on Google Play infects 10M users with one update

#454

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

"Apps" and "algorithms" seem to be driving literally everything about society now. I don't think this is a good thing, nor do I see the trend reversing. These giant black boxes now control the levers of modern society, and the companies that own them get to hide behind their "terms of service" to avoid any responsibility for the damage being done. Every significant review system is being gamed to the point of being u…

The platforms these companies provide have been so useful and successful that they have both become oligopolies and are a big part of how society operates nowadays. Think like electrical grid or roads.

But it's still not stabilized, society has not yet found out how to deal with all this.

It's like when there were no speed limits for cars or standard signage. There was more freedom but it was way more dangerous and unpredictable and also as a result, not yet as useful as it could be.

It's not necessarily anybody's fault. A company like Google maybe sees itself as a company but it's way past that. It really provides quite essential platforms for people, families, cities, you name it. And also the platform for content creators and developers and businesses. Many of these don't have a proper contract with the platform. It doesn't scale to have lawyers to be involved in every point to point dealing either.

My assumption is that there is going to be maturation of these platforms, common rules and terms. Governments and WTO could be involved.

Re: Barcode scanner app on Google Play infects 10M users with one update

#455
post #413

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

This review fraud has got way out of hand. Right now, it would be better to remove reviews entirely and for consumers to make a decision based on the product page alone. The consumer trust in reviews is at such a low that it’s adding friction to purchase decisions and starving honest businesses from being able to invest in quality products. One solution might be to only publish reviews/ratings from accounts with a mi…

Or go into trust-circle reviews. None of the trust circle using it means the product is untrusted, having to be more careful.

Re: Barcode scanner app on Google Play infects 10M users with one update

#456
post #262

Earlier quoted context omitted.

About four years ago, when I had a low end Android phone, some kind of "make the screen white" app was really useful. I remember the play store being scary but I think there was something in fdroid. I am not so sure on this, but I do not recall my nexus 5 having flashlight in the OS.

I have a Nexus 5, and I can confirm the flashlight is available in the system tray icon. This is true for all Google phones since at least Nexus 4. It is my understanding that AOSP as well as Google's Android implementation has always exposed access to the flashlight hardware (although somebody mentioned this not being the case with Nexus One).

Since it's not an app, but hidden under edit in the pull down notification tray, people may still end up looking for a flaslight app. Perhaps a warning in the Play store that "You already have a flashlight, it's here..." would be a good comprimise? Although that might be considered "MS pushing IE", because the Flashy flashlight app has features(tm) (omg blink S.O.S., gotta have that :s).

Re: Barcode scanner app on Google Play infects 10M users with one update

#457
post #94

Earlier quoted context omitted.

I absolutely love Camscanner, and I have been for over a year on the old version because I refuse to update to the new version which requires network permissions. I exactly suspected this is why it needs those permissions. To what did you switch? Camscanner is otherwise an excellent app, especially for combining multiple images and straightening them out.

Not OP, but I switched to using Microsoft Office Lens.

Thank you! This one seems to have the features of Camscanner that I use: straightening documents and combining multiple images into a single PDF.

Re: Barcode scanner app on Google Play infects 10M users with one update

#458
post #337

Earlier quoted context omitted.

These app stores are a terrible software distribution model. Every day we hear about another reason they harm users far more than community maintained repositories and only protect the interests of the OS vendor.

App stores are no more terrible than the previous software distribution model where you Google the name of the software you want to install, find some site that "mirrors" the download, realize they've repackaged the original app with extra ads and toolbars, keep searching, find the official download link, scroll past all the misleading ads containing download buttons, download the package, and then hope the download…

> And community-maintained repositories aren't a solution, that's just the app store model but on a smaller scale so it's less of a Target for bad actors. If ubuntu's universe repo had to suffer the same amount of abuse as the play store does, it would crumble in a day.

I disagree strongly.

Most community supported Linux distributions have fairly arduous processes by which members of the community become trusted users / MOTUs / etc. It is not simply a matter of deciding to upload something, creating an account, and clicking a button. To deliberately upload a malicious package into Universe (or similar repos in other distributions), you would have to methodically worm your way into a community over time, participating on IRC, helping contribute innocuous changes to other packages, training new users, and so on. You'd then have to apply for the ability to upload, having demonstrated both skill and the ability to work with other members of the community, as well as the need for permission to upload a specific package. This process would take months or years.

And then, you'd have to keep any changes you made pretty cleverly hidden. Anything obviously phoning home or popping up full screen ads would instantly blow your cover, wasting the whole effort you put into it. It's simply not worth it. And that's before you realize how extensively open source the build pipelines for most distributions tend to be. (I can - and have - examined the actual build process used by multiple Arch Linux packages.)

This is completely incomparable to the process for uploading to Google Play. At best you're going to have to pass some automated checks. But it's an ecosystem built around closed-source (so no peer review) software, quasi-anonymous developers, and software funded by advertising. It's infinitely easier to sneak something into an app store, get a bunch of users, and get away with it (temporarily) than it is to put malware in the repositories of a modern Linux distribution.

Re: Barcode scanner app on Google Play infects 10M users with one update

#459
post #415
post #413

Earlier quoted context omitted.

This review fraud has got way out of hand. Right now, it would be better to remove reviews entirely and for consumers to make a decision based on the product page alone. The consumer trust in reviews is at such a low that it’s adding friction to purchase decisions and starving honest businesses from being able to invest in quality products. One solution might be to only publish reviews/ratings from accounts with a mi…

Even non fake reviews suck. The sheer scale of situations where the top review is negative describes something that ... is not a bug, is actually supposed to be that way, is how the dang app works by design for good reason ... is bonkers. It seems like reviews are driven by people who don't know, and respond reviews by to people who don't know who describe what sounds like fundamentally broken things... so they give…

> It seems like reviews are driven by people who don't know, and respond reviews by to people who don't know who describe what sounds like fundamentally broken things... so they give it a thumbs up and they're both completely ignorant

Heh. One of Google's featured reviews for ZXing is a one star review from someone who said they started getting popup ads, and looked up the issue on a web forum which said it was ZXing's fault. It has 30+ thumbs up.

Absolutely pathetic.

Re: Barcode scanner app on Google Play infects 10M users with one update

#460

Earlier quoted context omitted.

>If it's a large company like Facebook that values these products like Whatsapp at billions I trust them at least on this issue. I'm pretty sure they're not going to put junk third party malware for 50k into the Whatsapp client. Zuck: They "trust me" Zuck: Dumb fucks.

That's a one dimensional way to think. You may not be able to trust facebook with your privacy, but you can trust them not to install a malware that swipes your bitcoins. That being said, I despise the current state of affairs with cellphones. I don't like needing to trust any corp. I'm jumping to a Linux native phone when my current device dies.

>you can trust them not to install a malware that swipes your bitcoins

Sure, they might not take malware that swipes my crypto, but I wouldn't put it past them to take malware that uses my resources to mine for crypto. What is the downside for them?

Post reply on HN