8 ms·
My perception is also that malware ends up in the Google Play Store with much higher frequency than the App Store. Just do a news search for "Google Play Store
by nnutter 9y ago
My perception is also that malware ends up in the Google Play Store with much higher frequency than the App Store. Just do a news search for "Google Play Store malware" and "App Store malware" and compare.
Also, one can sideload apps, if you have a Mac, onto iOS. Obviously, that's not anywhere as integrated but maybe that's a good thing. Heck, maybe Apple even added that so people in China could sideload VPNs. Maybe iOS VPNs are good enough (no root, no TOR?)?
- lern_too_spel 9y agoAdd up all the malicious app installs on Google Play Store, and it doesn't even come close to the 500 million[1] (conservative estimate) users affected by XCodeGhost. It looks worse when you consider that the 500 million is on an order of magnitude smaller total iOS userbase vs. Play Store userbase and when you consider that Google allows third party security researchers to investigate and publish research on the Play Store while Apple does not, so XCodeGhost is likely to be the tip of the iceberg.[2] [1] https://www.google.com/amp/s/www.macrumors.com/2015/09/20/xcodeghost-chinese-malware-faq/amp/ https://www.google.com/amp/s/www.macrumors.com/2015/09/20/xc... [2] https://www.google.com/amp/s/www.cultofmac.com/128577/apple-kicks-security-researcher-out-of-app-store-and-developer-program-after-ios-vulnerability-demonstration/amp/ https://www.google.com/amp/s/www.cultofmac.com/128577/apple-...
- evgen 9y agoLOL, let's start with StageFright (1 billion+ pwned with just a text message), move on to StageFright2 (because patching is hard...), and then just keep running down the list of malware in the Play store that is still there months after being discovered. XCodeGhost OTOH, seemed to have hit around 40 apps so that would probably not even get it into the top-100 list of Google Play malware families. Malware families. The Play store is such a shitshow that you can actually have different strains of malware running around in fake apps, like some sort of digital syphillus spreading through the brothel that Google forces everyone to visit if they want the shiny apps...
- lern_too_spel 9y agoThe number of people actually affected by StageFright malware from Google Play Store (which is what we were discussing) is very likely to be zero. It simply blocks the payload. We know for a fact that 500 million+ were actually affected by XCodeGhost, an order of magnitude more than the sum total from all malware seen in the Play Store. Don't conflate unpatched Linux systems with the Play Store. Anybody who uses Android and cares about the security of their device (like anybody who uses a Linux-based router and cares about the security of their network) uses vendors who deploy timely security updates.