Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

111–120 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#111

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

"a bureaucracy isn't trustworthy"

This kind of rhetoric has been popular in California at least since the 1970s and it has consistently played the same role, which has been to disguise reality. Bureaucracy is expanding because complex societies need complex bureaucracies. This isn't new. You can trace this far back in history. In some sense, the era of bureaucracy began around 3,300 BC when the first Pharaohs wanted to put up the first pyramids and found that they need hundreds of scribes to keep track of all the material, and payments for the material. And bureaucracy has gotten a lot bigger since that time. There are some totally legitimate criticisms that you can make about civilization, especially the way a complex civilization necessarily infringes on some of our basic rights, and the fact that there is a certain kind of inefficiency to bureaucracy. All the same, bureaucracy also has a kind of efficiency to it, especially when organizing things of immense scale. Lazy libertarianism is popular but it is not an accurate guide to the changes happening in our society or our economy.

Re: Google Play has been spreading advanced Android malware for years

#112
post #89
post #67

Earlier quoted context omitted.

I never said it was a massive failure, but many people have switched over the years to some form of Android after getting fed up.

>>I'd say that they are more than moderate failures. So... major failure? Is that what's in between moderate and massive? If so, I'd love to have a major failure. :)

Meaning the central stores they attempt to force on us, not the devices themselves.

Re: Google Play has been spreading advanced Android malware for years

#113
post #95

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

And yet Apple's walled garden is stronger and hasn't had anywhere near the malware problem that Google's has? I don't understand your point. Privacy is where these companies' interests might not be aligned with users; when it comes to security , they very much are. It's just that for Google that's limited to their own services; they don't care so much when it comes to Android as a broader platform. But even then thei…

Why are you shilling for AAPL shareholders? All megacorps are regulated by the same lack of rules other than maximizing their limited liability profits.

Re: Google Play has been spreading advanced Android malware for years

#114
post #87
post #68

Earlier quoted context omitted.

Yes, but the permission is per-app. Let’s say I approve location for the app because the app’s function requires it: the third party spying SDKs embedded in the app send that location data off to third parties without notifying me or permitting me to stop it. Apple permits this behavior in the App Store. Furthermore, IP address is coarse location even if you don’t grant the app permission, via GeoIP databases. Long s…

If an app's function requires location, how is it Apple's fault that the user decides it's better to enable that app to spy on him? If I use Waze do I expect privacy from it when it's essential that it knows my location? Furthermore, on iPhone you get a warning when an app abuses the location permission, unlike Android. At least on iPhones you have per app control, on Android it's either "location on" or "location of…

> If an app's function requires location, how is it Apple's fault that the user decides it's better to enable that app to spy on him

Apple makes the iOS SDK and writes all the app store policies. They could deny apps that embed third party location data mining/spying that is nonessential to the app’s functionality, just as they do that now for checkouts/payments of subscription services that don’t use App Store IAPs.

Apple has taken an aggressive stance regarding the curation (alternately, censorship) of the App Store. Everything that is or isn’t in it is “Apple’s fault”.

They let App Store apps spy and harvest data for shady data and location miner companies.

Re: Google Play has been spreading advanced Android malware for years

#115
post #95

Earlier quoted context omitted.

And yet Apple's walled garden is stronger and hasn't had anywhere near the malware problem that Google's has? I don't understand your point. Privacy is where these companies' interests might not be aligned with users; when it comes to security , they very much are. It's just that for Google that's limited to their own services; they don't care so much when it comes to Android as a broader platform. But even then thei…

This used to be true. But both Google and Apple release badware numbers and independent analysts do as well. Badware rates are similar on both stores and have been for several years. Play used to be considerably worse than the Apple store, but that is no longer the case. Being late to take security seriously has harmed google though, since this idea is now out there in the wild and keeps getting repeated regardless o…

Of badware they know about. The linked article shows that isn't exactly a useful metric.

Re: Google Play has been spreading advanced Android malware for years

#116

Earlier quoted context omitted.

You don't need a walled garden for that, a unified update api would suffice.

So much this. Linux distros with popular package managers offer official and 3rd party sources through one API. It's a dream compared to Windows and Mac IMO

Homebrew on macOS is nice though, both for installing tools as well as apps (homebrew cask [0]).

---

[0]: https://formulae.brew.sh/cask/

Re: Google Play has been spreading advanced Android malware for years

#117
post #53

Earlier quoted context omitted.

I'd say that they are more than moderate failures. I've heard from many acquaintances who aren't as tech literate as myself that one of the major reasons they got rid of their iPhone was not being able to install applications from outside sources. Myself, I would never want to trust anything centralized.

> Myself, I would never want to trust anything centralized. How is that different from trusting multiple sources? You'd just be multiplying your concerns. Any of them could slip in some malware. The only advantage I can think of is censorship resistance, or access to older versions and discontinued products.

It enables competition, which keeps everyone honest. If Amazon had an app store which was known to be full of malware then people would stop trusting them, but when there is real competition they need that trust to make money, so they would put in more effort to prevent that. If you find that your platform's app store is full of malware today when there is no competition, what is your alternative? Throw away your phone? Never install any apps?

The exposure is also not any worse when the people you trust are equally trustworthy. If you install ten apps from one distributor or ten apps from ten distributors and all of the distributors are equally trustworthy, the chance of an app you installed being approved even though it was malware is the same. It may even be lower because the distributors have to worry more about their reputations when there is competition.

And it also applies the other way. Right now they can reject apps that you want not because the apps are malicious but because they compete with the distributor's own. If there were five other trustworthy distributors then you could install it from any of them. So you could always get e-readers that compete with Amazon from Google, search apps that compete with Google from Microsoft, web browsers that compete with Apple from Mozilla and so on, no matter what kind of device you have.

Re: Google Play has been spreading advanced Android malware for years

#118
post #105

Earlier quoted context omitted.

HTTPS has multiple authorities. do you use HTTPS?

That's not a good analogy for OS sandboxing: • Will third-parties have the same standards for checking if an app uses only the authorized APIs and gating privacy/resource access? • What happens when Apple/Google introduce new OS APIs, will those third-party signing authorities update their standards at the same time? • What if a third-party goes rogue and starts signing malicious apps? How and how soon will we know?

> Will third-parties have the same standards for checking if an app uses only the authorized APIs and gating privacy/resource access?

You get to choose who the third parties are, so choose ones who do. Some of them may even have higher standards than the platforms do.

> What happens when Apple/Google introduce new OS APIs, will those third-party signing authorities update their standards at the same time?

This was solved decades ago. You introduce new APIs with new operating system versions and provide development releases to developers ahead of time so they're ready by the time the new system is released to the general public.

> What if a third-party goes rogue and starts signing malicious apps? How and how soon will we know?

Presumably the same way you know when Google or Apple does it.

Re: Google Play has been spreading advanced Android malware for years

#119

Earlier quoted context omitted.

> There is no coffin, the walled gardens are not dying, and have long since become the norm, which happened because the people found them to be better than the alternative: getting apps (and manually updating them) from many different sources of varying quality and convenience. No they haven't. Given a fair choice customers have opted for the alternative the vast majority of the time. The walled garden models have on…

> Given a fair choice customers have opted for the alternative the vast majority of the time. As in, Steam versus... Buying and downloading directly from the publishers' websites? The Xbox and PlayStation stores? The Nintendo eShop?

The stores of the console makers use the same anti-competitive platform lock-in as Apple and Google.

Steam is the alternative where you get to choose where to install things from -- one of those places is Steam. Installing Steam doesn't prevent you from installing other software from the developer's website or the Linux package manager or Windows store or wherever you like.

Re: Google Play has been spreading advanced Android malware for years

#120
post #9

Earlier quoted context omitted.

But security is not binary. They (especially Apple) are doing something to limit the amount of fraudulent apps on their platform. I would strongly prefer having a free-for-all platform because I have some basic knowledge of information security. Most people don't.

How is your “knowledge” going to help you? Are you capable of vetting every app you install?

You don't vet the app, you vet the distributor. This in no way requires there to be exactly one distributor.
Post reply on HN