Live data from Hacker News

Barcode scanner app on Google Play infects 10M users with one update

blog.malwarebytes.com

411–420 of 465 posts

Re: Barcode scanner app on Google Play infects 10M users with one update

#411
post #337

Earlier quoted context omitted.

These app stores are a terrible software distribution model. Every day we hear about another reason they harm users far more than community maintained repositories and only protect the interests of the OS vendor.

App stores are no more terrible than the previous software distribution model where you Google the name of the software you want to install, find some site that "mirrors" the download, realize they've repackaged the original app with extra ads and toolbars, keep searching, find the official download link, scroll past all the misleading ads containing download buttons, download the package, and then hope the download…

Would you call it the "previous" software distribution model? I still Google software for Mac and Windows, but I can't remember the last time i had to use a dodgy mirror site. Storage and bandwidth are cheap and plentiful now, most everything has an official source.

Re: Barcode scanner app on Google Play infects 10M users with one update

#412

Android doesn't actually need a 3rd party barcode scanner app. Google Lens supports barcodes.

Average users don't know the default capabilities of their own phones and instinctively go to the app stores to find their one purpose ad filled apps. I've seen flashlight, basic camera, weather, clock apps that are inferior to default apps of the phones installed on many client devices.

Inferior and probably filled with ads, tracking and now malware. Too bad Google doesn't try to let users know the feature already exist on their phone when users search for these apps.

Re: Barcode scanner app on Google Play infects 10M users with one update

#413

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

This review fraud has got way out of hand. Right now, it would be better to remove reviews entirely and for consumers to make a decision based on the product page alone. The consumer trust in reviews is at such a low that it’s adding friction to purchase decisions and starving honest businesses from being able to invest in quality products.

One solution might be to only publish reviews/ratings from accounts with a minimum spend threshold and unique active payment details. This would effectively price out the scammers.

Re: Barcode scanner app on Google Play infects 10M users with one update

#414
post #413

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

This review fraud has got way out of hand. Right now, it would be better to remove reviews entirely and for consumers to make a decision based on the product page alone. The consumer trust in reviews is at such a low that it’s adding friction to purchase decisions and starving honest businesses from being able to invest in quality products. One solution might be to only publish reviews/ratings from accounts with a mi…

Fake reviews are not that hard to spot. Why don't we focus on educating people on how to evaluate what they read, and making informed decisions, rather than taking information (even if misinformation) away from them? It would help with fake news as well.

Re: Barcode scanner app on Google Play infects 10M users with one update

#415
post #413

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

This review fraud has got way out of hand. Right now, it would be better to remove reviews entirely and for consumers to make a decision based on the product page alone. The consumer trust in reviews is at such a low that it’s adding friction to purchase decisions and starving honest businesses from being able to invest in quality products. One solution might be to only publish reviews/ratings from accounts with a mi…

Even non fake reviews suck.

The sheer scale of situations where the top review is negative describes something that ... is not a bug, is actually supposed to be that way, is how the dang app works by design for good reason ... is bonkers.

It seems like reviews are driven by people who don't know, and respond reviews by to people who don't know who describe what sounds like fundamentally broken things... so they give it a thumbs up and they're both completely ignorant.

The volume of people who do know the app and would see / write a review seems like it is MUCH smaller.

I had a game app update recently. I went to update it (one of the few times I go directly to the play store app). There at the top is a review that described how they saw opposing players "just disappear" during the game and raged about that 'bug'. But it's not a bug the game has some fog of war and view distance type mechanic. It's entirely expected / appropriate.... but there it is the top review.

Re: Barcode scanner app on Google Play infects 10M users with one update

#416

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

The ZXing Barcode Scanner (which is the "official barcode/QR code scanner for Android, as far as _I_ am concerned) is also available on f-droid.org. There's no absolute guarantee that F-Droid apps are malware-free but they have at least been looked at by a competent team of humans, something that is not true of the Play Store.

https://f-droid.org/en/packages/com.google.zxing.client.andr...

Re: Barcode scanner app on Google Play infects 10M users with one update

#417
post #300

I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads. Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it…

Two words for you: Buy iPhone. I know some people hate Apple but these type of things never happen or so rare. I hear android malware very often though.

Three words:

Buy Nokia 3310.

These types of things literally never happen.

Or maybe people have a lot of reasons for why they chose what they chose and this isn't productive.

Re: Barcode scanner app on Google Play infects 10M users with one update

#418
post #397
post #300

I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads. Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it…

So just to be aware, what was the root cause of this incident? Was it permission settings? How did it slip through the release process on Google Play, or is there none at all? What does this mean for other apps with overreaching permissions?

This app only had the basic permissions of camera and to open web links - pretty much exactly what you need to scan a QR code and open a web page. The software author (or more likely someone they sold it to) pushed a new version of the app that would just keep opening links to various ads.

The key here is that the author had a properly working, trusted, non-invasive application for years and then they pushed an updated version that was less so. Fortunately, it was an app with minimal permissions - it could only open web pages. In my case, running ublock, those pages came up blank. But for others not running an ad filter, they got pop-ups prompting them to install even more malware.

As for Google Play release process, I can't speak on that too much. They do scan for malicious code, but this code may not be malicious enough. If part of an application's purpose is to open web links, more code that opens links would not be as noticeable. Apple has a more intensive process to review new apps, and they spot-check app updates, but it's going to be somewhat similar. We hear about Apple pulling existing applications all the time for random reasons, but it's often after an update or report. Google pulled some of these apps after they were reported, but it was also after.

I'm not defending Google Play - they have a more relaxed review process than Apple, relying more on automation. But both have "legitimate" apps pulled for obscure reasons (and the only recourse seems to be getting attention on HN/Twitter/other), and both have let scam apps through. Apple seems to catch more of the "bad" apps, but also drops more legitimate apps that compete with Apple's business interest.

Re: Barcode scanner app on Google Play infects 10M users with one update

#419

Earlier quoted context omitted.

> they just aren't included in the base OS Both a QR-capable camera and a flashlight in the notification bar are in all my Android phones, and they've been for a very long time. I know the Nexus One didn't include it, but those will have problems with modern TLS anyway. The problem is likely elsewhere. It wouldn't surprise me if many of these users are tricked into installing these apps. It is quite popular for malwa…

Discoverability is just as much an issue as feature including. If you have to go into a special QR mode (which a lot of cameras did), you’re never going to use the feature, and it’s hard to break those mental models if the feature gets silently added in later iterations; you’re always going to remember that first encounter where something didn’t work seamlessly.

Indeed it is. It wasn't at all obvious on my phone that I could put a flashlight toggle on my notification bar, so for a long time I still kept the old Motorola DroidLight app, which, despite being unmaintained for a very long time, worked beautifully.

Re: Barcode scanner app on Google Play infects 10M users with one update

#420

This is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an…

The ZXing Barcode Scanner (which is the "official barcode/QR code scanner for Android, as far as _I_ am concerned) is also available on f-droid.org. There's no absolute guarantee that F-Droid apps are malware-free but they have at least been looked at by a competent team of humans, something that is not true of the Play Store. https://f-droid.org/en/packages/com.google.zxing.client.andr...

Does F-Droid compile the binaries themselves? Or do they just take a look at my github and then trust the .apk I build myself and send them?

I mean, I could very well make an open source app and then load some malware in the apk in addition to the well behaved thing... Are they immune from this attack?

Post reply on HN