> So if you as an app developer include such a 3rd party SDK in your app to make some money — you are part of the problem and I think you should be held responsible for delivering malware to your users, making them botnet members. I suspect that this goes for many different SDKs. Personally, I am really, really sick of hearing "That's a solved problem!", whenever I mention that I tend to "roll my own," as opposed to…
"Bad actors love the dependency addiction of modern developers" Brings a new meaning to dependency injection.
The Web Is Broken – Botnet Part 2
31–40 of 301 posts
Re: The Web Is Broken – Botnet Part 2
#32Earlier quoted context omitted.
"Bad actors love the dependency addiction of modern developers" Brings a new meaning to dependency injection.
I mean, as far as patterns go, dependency injection is also quite bad.
Re: The Web Is Broken – Botnet Part 2
#33Re: The Web Is Broken – Botnet Part 2
#34Maybe it's less convenient and more expensive and onerous. Do good things require hard work? Or did we expect everyone to ignore incentives forever while the trillion-dollar hyperscalers fought for an open and noble internet and then wrapped it in affordable consumer products to our delight?
It reminds me of the post here a few weeks ago about how Netflix used to be good and "maybe I want a faster horse" - we want things to be built for us, easily, cheaply, conveniently, by companies, and we want those companies not to succumb to enshittification - but somehow when the companies just follow the game theory and turn everything into a TikToky neural-networks-maximizing-engagement-infinite-scroll-experience, it's their fault, and not ours for going with the easy path while hoping the corporations would not take the easy path.
Re: The Web Is Broken – Botnet Part 2
#35We are working on an open‑source fraud prevention platform [1], and detecting fake users coming from residential proxies is one of its use cases.
Re: The Web Is Broken – Botnet Part 2
#36Has anyone tried to compile a list of software that uses these libraries? It would be great to know what apps to avoid
[1] https://reports.exodus-privacy.eu.org/en/trackers/ [2] https://f-droid.org/packages/com.aurora.store/
Re: The Web Is Broken – Botnet Part 2
#37What is the point of app stores holding up releases for review if they don't even catch obvious malware like this?
Re: The Web Is Broken – Botnet Part 2
#38I’m really struggling to understand how this is different than malware we’ve had forever. Can someone explain what’s novel about this?
Re: The Web Is Broken – Botnet Part 2
#39Re: The Web Is Broken – Botnet Part 2
#40I thought the closed-garden app stores were supposed to protect us from this sort of thing?
Once again this demonstrate that closed gardens only benefit the owners of the garden, and not the users. What good is all the app vetting and sandbox protection in iOS (dunno about Android) if it doesn't really protect me from those crappy apps...
If you treat platforms like they are all-powerful, then that's what they are likely to become...