Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

291–300 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#291
post #230

Earlier quoted context omitted.

Is there anything you guys in New Zealand haven't done better during this pandemic? :-)

"Better" is certainly a point of view here. Having to tell the government all of your whereabouts when you already live on an Island with no spreading is an overreach, IMO.

The New Zealand government doesn't learn "all your whereabouts" by default. The app is storing locally what it has learned about places you visited by scanning QR codes, and comparing that to information it is being sent over the Network (by the government) to discern if you went anywhere that the government says warrants special action - if so you get notified.

For most Kiwis this means a bunch of QR code data is stored on their phone and, months or years from now when the emergency is over (depending on how incompetent other countries are) that data is deleted. There is no NZ department of health MySQL database full of geo data of every New Zealand citizen and never will be.

If you're a case (remembering that New Zealand has elimination, so rather than cases being millions of people as in the US for example, they're very rare) then you can choose to help the contact tracers by giving them your data and in that case they do get all the data because you gave it to them. Because New Zealand has elimination contact tracing is something done by a handful of experts.

I would guess that like most countries New Zealand's contact tracing experts worked previously with sexually transmitted infections - so they already understand the sensitivity of this work. COVID-19 is actually less awkward, because at least you don't have to admit to fucking somebody you claim you're not sexually attracted to, just that you were in the same room as them for a period of time.

But of course none of what I wrote above matters much because those are merely facts, and for so many Americans mere facts can't oppose a Truth they have become certain of despite all evidence to the contrary. Not that Mother Nature gives a damn whether you believe her.

Re: Barcode scanner app on Google Play infects 10M users with one update

#292

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> How many authenticator apps do you have to use in parallel to mitigate this risk of a single point of failure?

Just one, together with alternative forms of 2 factor auth, such as a Yubikey (U2F token) or printed backup codes.

Re: Barcode scanner app on Google Play infects 10M users with one update

#293

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

I'm terrified of browser extensions for this very same reason (and yes, I still use them). I wish the browser vendors supported some kind of pinning to source code for open source extensions. Right now I have at least 2 extensions running that I know could access my passwords on any website as I enter them. One of those is Lastpass, which I use for storing/generating those passwords anyway, and the other is AdBlock P…

> I wish the browser vendors supported some kind of pinning to source code for open source extensions.

Chrome used to. You used to be able to just download the source code of an extension, point Chrome at it, and done you are.

Well, you still can. But Chrome will CONSTANTLY nag you about it and try to forget you added that extension using source, like it's some vile crime.

They removed it because of "security", which is a hilarious reason because it just made everything so much worse.

Re: Barcode scanner app on Google Play infects 10M users with one update

#294

Even legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtak…

> Apps that offer what should have been offered by the OS vendor in the first place. This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual b…

A great argument for installing F-Droid in my eyes.

Re: Barcode scanner app on Google Play infects 10M users with one update

#295
This is even worse when the app in question comes preinstalled on your Samsung tablet and can't be uninstalled (but afaik it can be stopped and downgraded).

https://fossbytes.com/peel-remote-use-remove-smart-remote/ "Truth be told, Peel Remote has been scrutinized for more than a year because of the company desperate measure to gain revenue. In 2017, the app introduced a malign ad practice of unethical lock screen ads and overlays."

My girlfriends tablet just started turning the screen on at random times. It took some time to find out which app causes this.

Re: Barcode scanner app on Google Play infects 10M users with one update

#296
This is possibly tied to the recent assault on the ZXing Barcode scanner app[1].

This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus.

It takes a special kind of scum to slander an open source project in order to push malware.

[1]: https://play.google.com/store/apps/details?id=com.google.zxi...

Re: Barcode scanner app on Google Play infects 10M users with one update

#297
post #53
post #36

When the Apple App Store contained malware compiled by unsuspected Chinese developers using a local cache of Xcode [1], Apple emailed the developers to prompt them to update their application immediately and removed them from sale. Apple also contacted users directly to alert them of whatever apps they had purchased on the App Store were compromised so they could monitor for updates, or remove the app entirely. Has G…

Google can disable apps on the users' devices. https://developers.google.com/android/play-protect/client-pr...

"Can"

Play protect is a complete joke, it can't even detect malicious chinese apps that request every single permission that exists.

Re: Barcode scanner app on Google Play infects 10M users with one update

#298
post #131

I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged. few QR code apps from F-Droid. https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...

Open source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-…

Were the trackers already labeled in F-droid? They maintain a list of these anti features for all apps. If not, when you reported your findings to F-Droid, did they flag the app as having trackers at that time?

Nobody said blanket trust anything. F-Droid is a community project with a framework that allows for disclosing user hostile behavior in apps. By using it and paying attention, we can all make it even better - the exact opposite of Google, whose incentives do not align at all with these goals.

Re: Barcode scanner app on Google Play infects 10M users with one update

#299
post #257
post #125

QR Reader are load of everything. I went mad to find one a decent one for my parents’ android phone and apparently it doesn’t exists. So in a weekend I’ve created one without any kind of tracking, ads, permission, whatever. Here it is if you guys need one -> https://play.google.com/store/apps/details?id=com.prof18.sec...

Nice. Once you have a million users, are you open to selling it? ;-)

Nope. Because I truly believe in community and open source. I'd not be able to sleep on night and I'd prefer to shut it down rather than selling.

Re: Barcode scanner app on Google Play infects 10M users with one update

#300
I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads.

Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it goes away for a day or so. I originally attributed it to an open tab, or some site that I had inadvertently enabled notifications for. It took me a few days of seeing these and checking browsers to realize it was more, so I started checking apps recently installed. I even installed malwarebytes to do a scan, found nothing. There were three recently updated, including barcode scanner. I opened that and malwarebytes immediately flagged it. So the scanner seemed to know about it at that time, but couldn't detect it until you actually opened the application.

I used to have Theft Aware before it got bought by Avast, and I tried Lookout some years ago. But it was this incident that finally convinced me to install and keep anti-malware app on my phone. I've also disabled app updates from the play store.

EDIT: Mine was by "The Space Team", not the one listed in the article. Seems like a number of barcode scanner apps were targeted recently.

Post reply on HN