Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

41–50 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#41

Stallman calls autoupdates a "universal backdoor".

Stallman is almost always right but nothing he says is particularly surprising or useful.

Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.

Re: Barcode scanner app on Google Play infects 10M users with one update

#42
post #38
post #34

Earlier quoted context omitted.

Apple does not let you back out an update you made and regret. Apple does not block apps from using the network or give you any way to find out what they are doing and who they are talking to. In fact, apple does the opposite - it blocks apps that let you firewall your phone.

Applications like Charles [1] allow you monitor network connections and data closely. Apple do not actively prevent this. You can also setup a VPN to route traffic and strictly firewall. [1] https://www.charlesproxy.com

Charles must have some wild carveout from apple. All other apps that do that have been shut down. I still run a very old version of adblockios that starts a vpn (proxy) at 127.0.0.1 and blocks traffic that way. mostly.

Re: Barcode scanner app on Google Play infects 10M users with one update

#43
post #33

Stallman calls autoupdates a "universal backdoor".

He is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?

There's a third possibility, and I think it's Stallman's ideal computing landscape: all users care deeply about the code running on their machines and they are competent in applying and vetting patches, building from source, etc. It's unrealistic, sure, but it sounds nice right about now.

Re: Barcode scanner app on Google Play infects 10M users with one update

#44
post #41

Stallman calls autoupdates a "universal backdoor".

Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.

But if you were slow updating you could avoid a malware once it was known.

Re: Barcode scanner app on Google Play infects 10M users with one update

#45
post #30

Earlier quoted context omitted.

The short answer is "when the benefits outweigh the risks"; i.e. if there's a huge bugfix or new feature you need, but something like a barcode scanner is something whose change frequency should be very close to zero. The "update culture" has unfortunately trained users to obediently "bend over and take it", which is horrible from both the security and change-management point of view; but is the dream of those who wa…

Your dogmatic approach to updating would prevent you from installing a version _without_ malware attached. For example, a version of Xcode circulated in China was infected with malware and once Apple had detected it, they asked all developers to recompile and update their apps immediately. https://www.zdnet.com/article/how-malware-finally-infected-a... With your attitude, you wouldn't have necessarily seen the effica…

Every Google Play update prompt in My Apps has a description provided by the publisher. If there is an urgency to update and they don't say so, I'm not going to blithely accept every update.

Ior example, had there not been the exploit risk, I would have left Chrome at the older version, as their new tabgroup implementation is horrible, and it doesn't even allow you to open a new tab without creating a group or going incognito!

Re: Barcode scanner app on Google Play infects 10M users with one update

#46
post #27

Earlier quoted context omitted.

I wonder if there's a coordinated effort to exploit barcode reader apps, because (at least where I'm from) its becoming a government mandated Covid tracing thing to use a QR code to "check in" to certain classes of businesses/venues? I bet there's a _huge_ increase in use of QR code scanning apps compared to this the last year...

Its kind of amazing that there isnt an official qr code scanner app preinstalled on phones given how ubiquitous QR codes are.

I think Android 9 and up has QR code scanning built into the camera app, same as similarly recent vintage iOS. iOS is somewhat less problematic given that ~98% of devices are running current or one version old OSes, where the Android fleet has a huge install base who won't or can't upgrade from pre Android 9 versions. Last time I looked it was still over 40% of all Android devices.

I've side loaded LineageOS into a few old old Android devices, Galaxy S3 and S4s, but my S6Edge is still running the Android7 OS it has when Samsung abandoned it. My similar vintage 2015 iPhones 6S is running fully current iOS14 - but it is the oldest Apple device that'll run it. (To be fair, my Samsung S3 vintage iPhone 5 can't run anything newer that iOS10.3).

Re: Barcode scanner app on Google Play infects 10M users with one update

#47
post #36

When the Apple App Store contained malware compiled by unsuspected Chinese developers using a local cache of Xcode [1], Apple emailed the developers to prompt them to update their application immediately and removed them from sale. Apple also contacted users directly to alert them of whatever apps they had purchased on the App Store were compromised so they could monitor for updates, or remove the app entirely. Has G…

Apple has this ability, but they have not used it: https://iphone-services.apple.com/clbl/unauthorizedApps

Re: Barcode scanner app on Google Play infects 10M users with one update

#48
post #44
post #41

Earlier quoted context omitted.

Stallman is almost always right but nothing he says is particularly surprising or useful. Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.

But if you were slow updating you could avoid a malware once it was known.

Who will detect the malware if we are all slow to update?

Re: Barcode scanner app on Google Play infects 10M users with one update

#50

Stallman calls autoupdates a "universal backdoor".

I didn’t know that automatic app updates could be turned off until I just tried it now in iOS, thanks! Just a side note but think that Google and Apple took way too long to provide built in apps for using your phone as a flashlight or scanning a QR code. They allowed this malware cottage industry to flourish.
Post reply on HN