Live data from Hacker News

The Web Is Broken – Botnet Part 2

jan.wildeboer.net

21–30 of 301 posts

Re: The Web Is Broken – Botnet Part 2

#21
post #14

I thought the closed-garden app stores were supposed to protect us from this sort of thing?

Once again this demonstrate that closed gardens only benefit the owners of the garden, and not the users.

What good is all the app vetting and sandbox protection in iOS (dunno about Android) if it doesn't really protect me from those crappy apps...

Re: The Web Is Broken – Botnet Part 2

#23
post #18

I have some success in catching most of them at https://visitorquery.com

Checked my connection via VPN by Google/Cloudflare WARP: "Proxy/VPN not detected"

Could be, I don't claim 100% success rate. I'll have a look at one of those and see why I missed it. Thank you for letting me know.

Re: The Web Is Broken – Botnet Part 2

#24

> So if you as an app developer include such a 3rd party SDK in your app to make some money — you are part of the problem and I think you should be held responsible for delivering malware to your users, making them botnet members. I suspect that this goes for many different SDKs. Personally, I am really, really sick of hearing "That's a solved problem!", whenever I mention that I tend to "roll my own," as opposed to…

That may be true but I think you're missing the point here. The "network sharing" behavior in these SDKs is the sole purpose of the SDK. It isn't being included as a surprise along with some other desirable behavior. What needs to stop is developers including these SDKs as a secondary revenue source in free or ad-supported apps.

> I think you're missing the point here

Doubt it. This is just one -of many- carrots that are used to entice developers to include dodgy software into their apps.

The problem is a lot bigger than these libraries. It's an endemic cultural issue. Much more difficult to quantify or fix.

Re: The Web Is Broken – Botnet Part 2

#27
post #21
post #14

I thought the closed-garden app stores were supposed to protect us from this sort of thing?

Once again this demonstrate that closed gardens only benefit the owners of the garden, and not the users. What good is all the app vetting and sandbox protection in iOS (dunno about Android) if it doesn't really protect me from those crappy apps...

At the very least, Apple should require conspicuous disclosure of this kind of behavior that isn't just hidden in the TOS.

Re: The Web Is Broken – Botnet Part 2

#28

> So if you as an app developer include such a 3rd party SDK in your app to make some money — you are part of the problem and I think you should be held responsible for delivering malware to your users, making them botnet members. I suspect that this goes for many different SDKs. Personally, I am really, really sick of hearing "That's a solved problem!", whenever I mention that I tend to "roll my own," as opposed to…

"Bad actors love the dependency addiction of modern developers"

Brings a new meaning to dependency injection.

Post reply on HN