7 ms·
It is about a DMCA notice. The GPP said "the developer of the original app had been trying to get Google to remove the offending apps for more than a week." He
by trotsky 16y ago
It is about a DMCA notice. The GPP said "the developer of the original app had been trying to get Google to remove the offending apps for more than a week." He wasn't complaining about trojans, he didn't know about them, he was complaining about copyright infringement. I'd be very surprised if they would have remained for long at all if he had submitted a DMCA compliant complaint correctly.
Once they were reported as trojans they were pulled the same day.
I'm not sure what is expected from google here:
Clearly they need to get a better handle on licensees pushing minor updates. That privesc has been around forever, and it's still there on my phone and that's super shitty - updating is android's achilles heel. But even if they get real good at that there will still be some exploits out there, every platform has them.
Do people expect google should be able to make it so no malicious code can ever be run? Seems like that's a battle nobody has won. Do people expect google to switch to a curated, only google approved apps marketplace? I'd sure be unhappy if they did. Do people expect google to pull apps from the marketplace on copyright complaints even if they aren't submitted/sworn correctly and potentially let all kinds of fraudulent takedown mayhem occur (because the submitter wouldn't be liable)? Seems unwise.
Do people expect google to do automated scans and blocks of suspicious code on the marketplace? Sounds like what they are planning on doing.
- spiffworks 16y agoThis is actually an extremely interesting technical problem though, isn't it? Given all the computational power Google has, I'm sure they could dedicate one emulator per new submission, and run continuous checks on the app without ever resorting to manually reviewing the apps the way that Apple does. My guess is that the Android team is the most overworked team inside Google, and they're struggling to keep up with their own growth, so they've had to deprioritize some things like the market, and focus on simply getting Honeycomb out of the door. By my theory, the Market should see some real improvements in the coming months. We'll see, I guess.
- trotsky 16y agoI agree that it's an interesting problem, unfortunately client security is also a very hard one. While an emulator check sounds like a neat approach, it is hard to prevent things like that from ending as just another cat and mouse game. They'd have to run every major+minor version, and then what if the author just set it to not infect the first 1000 installs, or to only activate if another semi-common app was installed, or simply included a chrome frame that pulled an exploit only if the client was on a major mobile network, etc. Most (though not all) malware detection, be it signature or behavioral relies on an engineer having analyzed it or a close relative in the past. When you have a sandbox model like Android, you really need to focus on getting exploits fixed on all your clients as a first priority. Until you get that straight you're never going to be doing much more than sticking your finger in the dike. Right now every 2.2.x or older client is wide open to a drive by compromise when using chrome lite. So focusing too much on the marketplace may not be rational. All recent mobile Safari builds are vulnerable to a similar webkit exploit as well. Both issues were cleared in Chromium last year.