Live data from Hacker News

Popular Google Play store apps are abusing permissions and committing ad fraud

buzzfeednews.com

121–130 of 178 posts

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#121
post #101

Earlier quoted context omitted.

> it was that there was no separation between programs, so that any random program you installed could add toolbars to your browser, steal all your passwords, etc. And for Linux or Windows this is still true.

I believe it's not true for UWP Windows Store apps?

True, but nobody uses them and there are few examples of useful UWP programs. App-Store on macOS isn't a success story and rightly so.

macOS = useful; iOS = nope

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#122

the locked in store model has completely failed. both for ios and android it is a terrible experience compared to PC. you are stuck with only the search tools the hardware maker gives you, often designed in a user hostile way (ios brings up ads) and no way to bail out to a different store. as well the monoculture leads to a race to the bottom with garbage programs shoving their way to the top via misleading a dishone…

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

The locked in store model in iOS also forces you in to a specific and rather puritanical morality when it comes to the apps you can choose from.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#123

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

The solution is what has been suggested earlier: allow users to choose their own 'store', don't lock them to a single vendor. This is already possible with Android where F-Droid is a good example of a 'store' where the chance of being exposed to these shenanigans is close to zero. Currently iOS users lack this option so for them the only way out is to change platform.

> This is already possible with Android where F-Droid is a good example of a 'store' where the chance of being exposed to these shenanigans is close to zero.

There are many other stores where the chance of being exposed to these shenanigans is close to 1. Think of the article recently about super-shady app stores for iOS that misused enterprise certificates to sideload apps [0].

If alternate app stores were to be allowed on iOS, all that would happen is a great proliferation of these scumware stores, full of knockoffs, fakes and outright malware.

It's going to be almost impossible for a lot of people to distinguish between legit good quality, legit crap quality and non-legit harmful app stores, resulting in waves of malware and privacy theft that will make the old Windows XP days look like a panacea.

While it has its problems, the curated nature of iOS' App Store is a distinct positive for users.

[0] https://www.theverge.com/2019/2/20/18232583/apple-ios-develo...

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#124
post #103

Earlier quoted context omitted.

I actually can't believe this. How in the name of all the is holy are we letting them get away with this. Sure, we talk about the problem a lot. But we need to take action. It seems every big corporation are abusing the trust we give them in some form or another. Please, for the love of God, can anybody prove me wrong. Are there any companies than don't abuse our trust?

Microsoft, for all their other flaws, usually keeps out of the business of selling their consumers. Perhaps it's because they have better (internal) monetization possibilities.

Microsoft sells your browsing and installed apps data to companies

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#125
post #36

Earlier quoted context omitted.

Its too bad its still flakey at updating apps. I've been using it for a few apps for many years, and I'd say easily half of app updates simply fail for non-obvious reasons. Its been this way across multiple devices and countless versions of Android, so I'm left to believe the problem is with F-droid itself.

I also heavily heavily hate the idea that they sign everything, the app stores must not be trusted. They should only be signing over packages already reproducibly compiled.

What are you expecting them to do, not host non-reproducible builds at all? Android will not run unsigned apps. This would result in F-Droid having exactly 3 apps. They're working on getting more reproducible builds but the build system is not exactly great for it.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#126
post #57

Earlier quoted context omitted.

Hi! I'm the author of the story and want to note that I only asked Google why it wasn't removing the apps after their investigation confirmed a major policy infraction. By then their investigation was close to a week old. Google confirmed that these apps were committing ad fraud, and told me that ad fraud is against Play store policy. Yet the company was going to keep the apps in the store. That didn't make sense to…

Did you ask why those companies (Cheetah mobile, Du group,...) which caught red-handed still allow to distribute apps in Google Play store?

I did. I also asked the same Q when I helped catch Cheetah Mobile and Kika Tech doing ad fraud: https://www.buzzfeednews.com/article/craigsilverman/android-...

And when I busted a large ad fraud scheme of dozens of apps: https://www.buzzfeednews.com/article/craigsilverman/how-a-ma...

In all cases Google basically said it takes action against specific apps found violating policy. It seems unwilling to take action against a developer as a whole and ban them. I would also add that I suspect the Play store is not equipped to enforce a ban. People can easily create a newco and get back into the store. This is definitely a much larger issue. So I think that among other things these stories show that you can be a clear bad actor and still do business in the Play store.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#127
post #120

I did my Master Thesis on this kind of stuff. There are many Apps among the top 100 free ones that ask permissions completely unrelated to their functionality. Yeah I know, not surprising. What surprised me at the time was that Android gives away much information "for free". For example, if I recall correctly, GET_ACCOUNTS was granted automatically and it allowed to get the "title" of every account on the phone as sh…

I'm the author of this article and I'd love to learn more about what you found in your research. You can reach me at craig dot silverman at buzzfeed.com.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#128
post #49

Earlier quoted context omitted.

I would find it acceptable if side loading apps was allowed by default but sideloaded apps are blocked from the dangerous permissions like device admin and draw over screen. Apps that really do require this have to be checked by a maintainer or require the device to be in developer mode. This way almost everyone is happy because most apps don't really require anything other than internet, camera and GPS which can be…

This. Google and Apple should make it easy for computer literate people to use something more advanced. Have the unwashed massed version sure, but then let us override it in a graceful manner instead of having to jump through hoops. Would lead to all kinds of free innovation etc. that they could then take over and profit from. Use the computer literate! WE WILL FIX IT FOR YOU

And everyone says they are an above average driver.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#129
One of the things that is really troubling about the Google Android Play store is the ease that an app developer can develop an app and remain totally anonymous unless you are forced to file a lawsuit or subpoena to Google to reveal information.

I own and operate a fairly popular audio streaming platform, and I've had to deal with numerous instances of unscrupulous app developers who steal API keys from our licensed developers, release apps wrapped in tons of ads, and are able to remain totally anonymous by:

1) Setting up what is presumably a fictitious company

2) Privacy policy link that directs to pastebin

3) Email address for support where nobody responds

These apps steal tens of thousands of dollars of ad revenue from my business monthly, and I have absolutely zero recourse. Filing DCMA and other complaints with Google typically goes into a black hole, and when they do respond or address the issue its typically "we don't see the need to take any action here" - presumably because these apps are generating enough revenue for AdMob and the Play Store that Google has zero incentive to take action.

How often does this happen in the Apple App Store, almost never.

It's absolutely infuriating.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#130
post #51

Earlier quoted context omitted.

Cheaper labor, I suppose. I bet Eastern Europe is also represented.

Are chinese really cheap labor though? Their tech companies are quickly eclipsing that of western companies. I don't think it's fair to say it's just a cheap labor thing.

Not utterly cheap, but likely not as expensive as Silicon Valley.

Also, I suspect that those who concentrate on adding spyware and ad fraud, repackaging, etc are not the top talent.

Post reply on HN