Live data from Hacker News

Google Play has been spreading advanced Android malware for years

arstechnica.com

121–127 of 127 posts

Re: Google Play has been spreading advanced Android malware for years

#121
post #95

Let this be another nail in the coffin of the "walled garden" farce. We learn this lesson again and again. People want someone to trust, but a bureaucracy isn't trustworthy. It has its own agenda and values inconsistent with yours. They take 30% from everybody whether they approve malware or not, and whether they reject legitimate apps or not. Trust doesn't come from size. If you want someone to vet your apps, it has…

And yet Apple's walled garden is stronger and hasn't had anywhere near the malware problem that Google's has? I don't understand your point. Privacy is where these companies' interests might not be aligned with users; when it comes to security , they very much are. It's just that for Google that's limited to their own services; they don't care so much when it comes to Android as a broader platform. But even then thei…

What about Facebook's API? It is basically at the same level of malware as the apps mentioned in the article

Re: Google Play has been spreading advanced Android malware for years

#122
post #115

Earlier quoted context omitted.

This used to be true. But both Google and Apple release badware numbers and independent analysts do as well. Badware rates are similar on both stores and have been for several years. Play used to be considerably worse than the Apple store, but that is no longer the case. Being late to take security seriously has harmed google though, since this idea is now out there in the wild and keeps getting repeated regardless o…

Of badware they know about. The linked article shows that isn't exactly a useful metric.

Of course it is of badware they know about. This is why 3rd party analyst reports are useful, since you get a second datapoint. This same issue is present for iOS too, so I don't see why it should lead us to believe that Play is worse.

Re: Google Play has been spreading advanced Android malware for years

#123

Earlier quoted context omitted.

That's not a good analogy for OS sandboxing: • Will third-parties have the same standards for checking if an app uses only the authorized APIs and gating privacy/resource access? • What happens when Apple/Google introduce new OS APIs, will those third-party signing authorities update their standards at the same time? • What if a third-party goes rogue and starts signing malicious apps? How and how soon will we know?

> Will third-parties have the same standards for checking if an app uses only the authorized APIs and gating privacy/resource access? You get to choose who the third parties are, so choose ones who do. Some of them may even have higher standards than the platforms do. > What happens when Apple/Google introduce new OS APIs, will those third-party signing authorities update their standards at the same time? This was so…

> You introduce new APIs with new operating system versions and provide development releases to developers ahead of time so they're ready by the time the new system is released to the general public.

Even major companies still haven't implemented something as trivial as Dark Mode in all of their apps by now, I wouldn't count on them to keep up with more complex changes.

Google still hasn't implemented Picture-in-Picture on iPads. Others still don't support split-view multitasking. Both these features have been out for years.

Re: Google Play has been spreading advanced Android malware for years

#124

Earlier quoted context omitted.

> Will third-parties have the same standards for checking if an app uses only the authorized APIs and gating privacy/resource access? You get to choose who the third parties are, so choose ones who do. Some of them may even have higher standards than the platforms do. > What happens when Apple/Google introduce new OS APIs, will those third-party signing authorities update their standards at the same time? This was so…

> You introduce new APIs with new operating system versions and provide development releases to developers ahead of time so they're ready by the time the new system is released to the general public. Even major companies still haven't implemented something as trivial as Dark Mode in all of their apps by now, I wouldn't count on them to keep up with more complex changes. Google still hasn't implemented Picture-in-Pict…

My impression was that you were talking about API changes that actually require the developer to use them, e.g. because the old thing doesn't work with the new system anymore. Then you give them some notice and they're ready with the new thing because they want their app to keep working.

The things you're listing are optional features. That doesn't require some kind of coordinated effort. If one distributor requires support for Dark Mode on day one and another gives developers a year and another never requires it at all, so what? If you really love Dark Mode you can decline to install apps from distributors who don't require it. Or just decline to install apps that don't have it, which you could do regardless of what any distributors allow.

Re: Google Play has been spreading advanced Android malware for years

#125
post #87
post #68

Earlier quoted context omitted.

Yes, but the permission is per-app. Let’s say I approve location for the app because the app’s function requires it: the third party spying SDKs embedded in the app send that location data off to third parties without notifying me or permitting me to stop it. Apple permits this behavior in the App Store. Furthermore, IP address is coarse location even if you don’t grant the app permission, via GeoIP databases. Long s…

If an app's function requires location, how is it Apple's fault that the user decides it's better to enable that app to spy on him? If I use Waze do I expect privacy from it when it's essential that it knows my location? Furthermore, on iPhone you get a warning when an app abuses the location permission, unlike Android. At least on iPhones you have per app control, on Android it's either "location on" or "location of…

This argument is very much the same as saying “just don’t install spyware” and literally proves the point that neither store is trustworthy.

On Android you too have this featureset, though the settings app is very limited and also has the same problem as OP mentioned. Just look at whatsapp, constantly trying to launch all other facebook apps in the background (verify this with a freezing app).

On Android (or AOSP, Omni, Lineage and the like) you at least have fdroid as an alternative.

Re: Google Play has been spreading advanced Android malware for years

#126
post #53

Earlier quoted context omitted.

> which happened because the people found them to be better than the alternative Walled garden only exists because mobile devices make self-install alternatives very difficult or impossible to get on purpose, otherwise they would not be able to compete in any ways. Case in point, the Mac App Store and the Windows Store are both moderate failures despite a lot of technical & marketing push.

I'd say that they are more than moderate failures. I've heard from many acquaintances who aren't as tech literate as myself that one of the major reasons they got rid of their iPhone was not being able to install applications from outside sources. Myself, I would never want to trust anything centralized.

> acquaintances who aren't as tech literate as myself that one of the major reasons they got rid of their iPhone was not being able to install applications from outside sources

Which applications did they want to install from outside sources? Which sources?

Where does something advertise itself as an iPhone app but not available on the App Store?

Re: Google Play has been spreading advanced Android malware for years

#127

Earlier quoted context omitted.

But then all banking apps stop working (including the 2FA apps "required" for using credit cards from some EU Banks; for EC cards you luckily still can use ChipTAN). Also mobile payment will stop working, normally I wouldn't care about that but currently paying without touching anything is nice. Then some apps you need for work might stop working. Not even speaking about hounded of other apps. The problem is to many…

Not true. With things like magisk and systemless root, the banking apps continue to work. At least my 4-5 banking/payment/credit card apps all work, with lineageos and magisk.

Thanks, I will look into it.

But how do you replace FCM? I mean most apps which where not intentional distributed over alternate app stores will just try to send notification through it.

Also I'm not so sure how legal it is to side load a app which is only meant to be distributed over google play.

Post reply on HN