Live data from Hacker News

CamScanner, a malicious Android app with more than 100M downloads in Google Play

kaspersky.com

111–120 of 155 posts

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#111
post #98

Earlier quoted context omitted.

That is and for many, always an issue. Adverts help pay for content, be that a game or website - people literally make a living that way that it has become a bit of a defacto approach. But when you are tied to including some code that goes off to a site that you have no or very little control over, you are outsourcing part of your company (web or app) into the hands of another in which, if they mess up. You are the t…

Here it sounds like the malicious code was in the advertising SDK itself, so ad blocking at the network level wouldn't necessarily have helped.

Yes and I can't think of one single developer who has had to include AD's, ever scrutinising the code they are offered (though I'd bet one that they are out there and hopefully comment back), let alone been able to change it due to the terms such AD requirements impose.

Maybe, Google et all need to make sure APP's have an even more granular control of permissions in that you can seperate the APP from the 3rd party AD's. that would only help more, but alas I suspect that may never happen as that would enable AD control much more accessible at a level that goes against their revenue stream.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#112

PlayProtect is not detecting and warning users about CamScanner even when it has been removed from the Playstore. I've tested it via manual scan on PlayProtect as well, no dice. Isn't that what it is supposed to do? Has anyone ever got any app flagged by PlayProtect? If it's useless, then rather I would disable it than to give it access to all my installed apps. Google Engineers here, please ping your Google Play tea…

> Has anyone ever got any app flagged by PlayProtect?

Yes, it started flagging all the apps my company distributes internally for testing purposes. Getting it to stop seemed impractical, so my company's guidance is now to disable Play Protect on any test device.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#113

Earlier quoted context omitted.

Any speculation why they would only leave in the malicious code for about a month? Changed their mind? Done without full knowledge? Achieved some high value heist and rolled it back?

An update to an ad library is what caused the malicious code in the first place. Presumably either the infected library was updated again or the developers switched libraries. The developers behind this app did not add any malicious code they wrote themselves. The attack either came from the ad library or the ad library was hacked.

If it's the case that it was accidental I feel bad that the app was pulled rather than only vulnerable versions forced off. Although I suppose it would be hard to find assurances that it won't happen again.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#114
post #110

Nice advert by Kaspersky in partnership with CamScanner

I seriously doubt that CamScanner wanted that kind of publicity. As for Kaspersky, they are like gun makers, selling you a false/real sense of security depending on who you ask.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#115

Earlier quoted context omitted.

I don't know this particular case, but "malware" seems to be used to describe "adware" these days by some blogs to generate more clicks. Android is just as secure/unsecure as iOS. Some recent "malware" campaigns targeted both platforms but in general Apple silently removes them while Android gets scrutinized to death. Edit: to answer your questions, these apps still operate within the limits of the sandbox. Which is…

This is clearly not the case. Not only is Android’s permission system more permissive, most Android phones don’t get updates as frequently and definitely not as far long as iOS.

In modern Android phones, the core system is updated one a month [if needed - which is often the case during the first year]. Android applications (including things like mail and browser) and a large part of the OS is updated immediately via the store.

The permission system is being updated and apps are being rejected for bad user of permissions (check Reddit for the SMS permission stories)

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#116
post #32
post #7

Just to clarify the headline: the app didn't have malware when most of the users installed it. A recent update added the malware.

in regard to iOS: When tencent bought the iOS version, the "user contract" was grossly changed. Just uninstall it and use the native iOS Notes app to scan your .pdf documents.

This functionality can be accessed by tapping the plus sign (with a circle around it) when editing a new note in the iOS Notes app.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#117
post #98

Guess what - this was caused by a third-party ad network: https://twitter.com/CamScanner/status/1166733219841986561/ph...

That is and for many, always an issue. Adverts help pay for content, be that a game or website - people literally make a living that way that it has become a bit of a defacto approach. But when you are tied to including some code that goes off to a site that you have no or very little control over, you are outsourcing part of your company (web or app) into the hands of another in which, if they mess up. You are the t…

(sorry to be picky about an irrelevance but this one grates on me. "Ad" is an abbreviation not an acronym or initialisation - so no need to capitalize it as "AD". Same for "app" over "APP". Makes things hard to read for me as it sounds like someone shouting occasional words in an otherwise normal sentence!)

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#118
post #106

Earlier quoted context omitted.

I too wish they should stop using their resources to find security problems Apple should have found themselves. But I very much disagree this is about embarrassing Apple. In fact, Google is doing them a huge favor. (The iMessage bug for example could have been turned into a worm and infected ALL iPhones on the planet in matter of minutes if it was found by blackhat hackers instead. Apple should be thankful)

Project Zero is doing Apple a huge favor. Google isn’t a single organism; Project Zero isn’t taking away resources from the Android division. And it’s not like Project Zero doesn’t look for Android vulnerabilities, it’s just that iOS is a much more interesting target from a security standpoint because it’s widely considered to be actually secure (not to mention that people actually run the latest version of it). I th…

If we only consider security, Fuchsia is another horrible use of resources. How many Android issues are due to kernel bugs?? Of those, how many are due to Google using is own heavily modifed version of an outdated kernel?

Agreed on humans, Google needs more humans and fewer robots.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#119

Is this just a non issue on iOS? If so, why?

I had the CamScanner app on my iPhone for quite some time, then uninstalled when I launched it and saw (IIRC) Chinese text appear. I'm assuming that ownership changed around that time, and if the Android and iOS apps have the same owner, I wouldn't trust it either. An iOS trojan would have slightly more limited impact, but if (for example) you gave the app "Access to your Photos" in order to save something, the app w…

I guess its time to disclose transfers and sales of mobile apps and browser extensions to end users.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#120

Earlier quoted context omitted.

This is clearly not the case. Not only is Android’s permission system more permissive, most Android phones don’t get updates as frequently and definitely not as far long as iOS.

> most Android phones don’t get updates as frequently and definitely not as far long as iOS. This is irrelevant. Most phones period don't get updates frequently. Does that mean you shouldn't buy any phone? No, you should buy a phone that does get updated, and there are plenty of Android options.

IOS 12 supports devices back to 2013. How many Android devices get support that far back?

Apple also released an OS update in July of this year for iPhones back to the iPhone 4S from 2011.

https://iphone.appleinsider.com/articles/19/07/22/apple-issu...

Post reply on HN