Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

461–465 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#461
post #424

Earlier quoted context omitted.

Fake reviews are not that hard to spot. Why don't we focus on educating people on how to evaluate what they read, and making informed decisions, rather than taking information (even if misinformation) away from them? It would help with fake news as well.

> Fake reviews are not that hard to spot. This statement seems very suspect to confirmation bias. How would you get to know if what you think is genuine was actually fake? This part of feedback loop is completely missing, and hence I find your above statement hard to believe.

I disagree. Still you didn't answer the question

Re: Barcode scanner app on Google Play infects 10M users with one update

#462

Earlier quoted context omitted.

App stores are no more terrible than the previous software distribution model where you Google the name of the software you want to install, find some site that "mirrors" the download, realize they've repackaged the original app with extra ads and toolbars, keep searching, find the official download link, scroll past all the misleading ads containing download buttons, download the package, and then hope the download…

> And community-maintained repositories aren't a solution, that's just the app store model but on a smaller scale so it's less of a Target for bad actors. If ubuntu's universe repo had to suffer the same amount of abuse as the play store does, it would crumble in a day. I disagree strongly. Most community supported Linux distributions have fairly arduous processes by which members of the community become trusted user…

>you would have to methodically worm your way into a community over time, participating on IRC, helping contribute innocuous changes to other packages, training new users, and so on. You'd then have to apply for the ability to upload, having demonstrated both skill and the ability to work with other members of the community, as well as the need for permission to upload a specific package. This process would take months or years.

sure. or you find somebody who's already done that and pay them some money.

Re: Barcode scanner app on Google Play infects 10M users with one update

#463
post #71
post #61

Earlier quoted context omitted.

I had this one (by ZXing Team) and never noticed any negative behaviour, but given that the default camera app now supports QR Code scanning I don't see a reason to keep the Barcode Scanner app.

Which default camera app? From which version? (The proliferation of manufacturer camera apps is one of the worst things about android)

Good point. Whatever the default is for a Samsung S10e. I agree that the forking by all the manufacturers is a PITA.

Re: Barcode scanner app on Google Play infects 10M users with one update

#464

Earlier quoted context omitted.

> And community-maintained repositories aren't a solution, that's just the app store model but on a smaller scale so it's less of a Target for bad actors. If ubuntu's universe repo had to suffer the same amount of abuse as the play store does, it would crumble in a day. I disagree strongly. Most community supported Linux distributions have fairly arduous processes by which members of the community become trusted user…

>you would have to methodically worm your way into a community over time, participating on IRC, helping contribute innocuous changes to other packages, training new users, and so on. You'd then have to apply for the ability to upload, having demonstrated both skill and the ability to work with other members of the community, as well as the need for permission to upload a specific package. This process would take mont…

And then, even if they're tempted by the large amount of money, they probably get caught pretty quickly and get banned. Again, even if you can use another person's account to reputation launder, it's still a very transparent platform that's hard to pull stuff like this on.

The usual process for this with mobile apps is not to pay someone a lot of money to ship malware, but rather to buy the person's account, app, and the source code outright. This has the advantage of not having to be explicit about what you're up to, gives the original developer plausible deniability, and gives you way more control. Plus it makes reputation laundering way easier and since the app is still closed source you can make any changes you want without anyone being the wiser.

All of this is completely different from how community supported repositories are run.

Re: Barcode scanner app on Google Play infects 10M users with one update

#465
post #360

Earlier quoted context omitted.

Wow great phone what is the model

It is this one: https://www.gsmarena.com/xiaomi_redmi_note_9_pro-10217.php

i had xiaomi redmi note 4. Best affordable phone when u just bought it but dont last long.
Post reply on HN