6 ms·
SourMint Malicious SDK
- swiley 6y agoSo glad the App Store prevents malware.
- breakfastduck 6y agoIt certainly helps. If a heavily sandboxed, walled-garden App Store is still vulnerable on its smaller attack surface, then the open-for-all alternative will be absolutely plagued. What is the point you're trying to make?
- swiley 6y agoNo. Because if we didn’t depend on someone getting funded and paying apple yearly we could use community maintained software. Are there any open source SFTP clients for the iPhone? (For example) Using SSH and SFTP via anything other than ish really creeps me out honestly. Linux doesn’t have an “App Store” instead you have to engage with the community and publish your app source code if you want it easily installed by most users. I guess that’s still not quite a “free for all” (although there’s nothing stopping users from installing whatever they want) but it’s certainly not as strict as what apple does.
- deleted 6y ago[deleted]
- _qulr 6y agoCounterintuitively, the walled garden may make the problem worse. The App Store is a single target. It makes "discovery" easier for malware. Imagine if these apps had to get users the "old fashioned" way, one-by-one, word-of-mouth, etc. It also requires less initial setup for malware developers, as opposed to having to develop their own software distribution infrastructure. Every claim about the App Store making things easier for developers also applies to malware. Moreover, the App Store race to the bottom undermined the previous paid upfront software model in favor of everything being free, supported either by ads or by "cash cow" manipulative IAP.
- mschuster91 6y ago> Moreover, the App Store race to the bottom undermined the previous paid upfront software model in favor of everything being free, supported either by ads or by "cash cow" manipulative IAP. Microtransactions were a thing even before the App Store race - remember Farmville, MafiaWars and the other host of Zynga's Facebook games?
- _qulr 6y agoI didn't say microtransactions weren't a thing. But clearly the App Store vastly expanded these practices. Pointing to Facebook just proves the point. Facebook is a walled garden, but does anyone think Facebook is a "healthy software ecosystem" for developers and users?
- KONAir 6y agoAncient GSM services were the starting point for those, from daily horroscope subs to java applet games sales... Apple is still eating the "take that out of GSM menus and sms orders and put it on its own dedicated internet app" cake (with same rate of tax of those ancient provider app stores took from 3rd parties).
- breakfastduck 6y agoThis is a valid point & well made. I would argue that the race to the bottom is caused more by Apples gratuitous 30% cut than anything else, though. Totally agree the free by default model causes more harm than good in the grand scheme of things when it comes to these app stores.
- stefan_ 6y agoIt isn't open for all? F-Droid, surely one of the most popular 3rd party app stores has vastly stronger requirements than the Play store: https://f-droid.org/en/docs/Inclusion_Policy/ https://f-droid.org/en/docs/Inclusion_Policy/ The Play store is such an unimaginable cesspit of crap that I've now stopped using it entirely except for official company apps, and then it will still suggest me malware clones every time. Like I wanted a battery display for my AirPods and the choice was stuffed with ads, battery draining IAP from the Play store or a simple, free OSS one from F-Droid: https://github.com/adolfintel/OpenPods https://github.com/adolfintel/OpenPods Of course, go figure, this app had to itself be modified to prevent scam artists from loading it up with advertisements and malware and putting it onto Play, where license violations are widespread and go entirely undetected.
- breakfastduck 6y agoI wasn't aiming my 'open-for-all' comment at any particular alternative. It was more if you've got one walled and protected store and that's compromised, a free open alternative would be more likely suffer the same issues on a larger scale. Certainly agree with your assessment of the Play Store
- social_quotient 6y agoIf we all agreed that free apps (and services) come at a real cost either in data or subversive practices. Then started paying money for apps that provide value. Do we think this sort of stuff would stop?
- lancesells 6y agoI think we should seriously consider and study whether advertising is bad for our health, both as individuals and as a society.
- guerrilla 6y agoAnd when it's concluded that it is, we can reclassify it as assault or psychological abuse.
- indymike 6y agoActually, this is a case where the ad SDK is behaving badly. No one signed up for that.
- paranorman 6y agoWould the Ad SDK have less developer interest (and as a result be a less likely target for this) if ads weren’t as attractive a source of income?
- gargs 6y agoAbsolutely! Every minute spent on fine-tuning an ad SDK is a minute not spent on making the app better for paying customers. Most of these SDKs are not just drag and drop, either; developers have to spend a lot of time configuring the attribution schemes and to update them periodically.
- nrjames 6y agoThere's a huge international market of potential app users that tolerate ads but would never pay to purchase an app. Even in affluent areas, many people balk at a $0.99 app but are totally fine with ads. This, of course, is the entire business model of Facebook, Instagram, etc. The billion dollar question is: how do you monetize non-paying users, at scale, without ads?
- filleokus 6y ago> Mintegral SDK uses a technique called method swizzling to replace implementations of the UIApplication openURL and SKStoreProductViewController loadProductWithParameters methods at runtime Naive swizzling of system API's will be detected/stopped by App Review, right? Or perhaps only if it's private methods?
- alyssam_infosec 6y agoI've been looking but haven't found a good systematic way to review code to find this. In the case of Mintegral, there were a number of obfuscations to make it difficult to recognize. Swizzling, while a bad practice in general, can be done for legitimate reasons. So you need to be able to detect what method they're looking up with _method_getImplementation and changing with _method_setImplementation which is the part that can be difficult. So far, I've found one old project in GitHub from 2016 that was designed to do this. However it's stale and I haven't had a chance to review it yet to see how effective it is.
- whizzter 6y agoDepends, as the article states the swizzling is only activated unless there is debuggers,etc or the app being in the "wrong" region. Not entirely sure how Apple's review-process works but if a majority of it is done in Mountain View there's a large chance that most reviewer devices aren't well spread out w/r/t to setting them to other regions.
- ChrisMarshallNY 6y ago> Mintegral SDK uses a technique called method swizzling to replace implementations of the UIApplication openURL and SKStoreProductViewController loadProductWithParameters methods at runtime, as well it registers a custom NSURLProtocol class. That's really clever. It looks like it uses ObjC dynamic linking to swap out calls[0]. When I read stuff like this, I'm glad that I'm a "dependency curmudgeon." I'm not sure I would have figured this out, if I had vetted the dependency (Actually, I'm pretty sure I would have missed it). I'm wondering if Apple would be able to detect this behavior, in their review process. There are certainly legitimate uses for it, but I like to avoid these types of hacks, in my shipping apps. [0] https://nshipster.com/method-swizzling/ https://nshipster.com/method-swizzling/
- woadwarrior01 6y agoMethod swizzling has been well known and used for as long as Objective C has been around. It's essentially Objective C's flavor of what other dynamic languages call monkey patching. I'm surprised that the App store review process didn't catch this, especially if the SDK was used by 1200 apps on the app store. It reminds of something I'd done to get past the App store review a long time ago. This was when the iPad had just come out and UISplitViewController was super buggy. I found that the only way to get the universal app I was building to work satisfactorily on both the iPad and the iPhone was to use one of their undocumented methods. We submitted the app for review and as I'd half expected, it was rejected for using an undocumented API. The work around was to rot-13 the selector for the undocumented method and to decode it at runtime, dynamically call the method with performSelector. That made it pass the review. And that's when I learnt that the reviewers were probably just running strings (the unix program) and grep to find apps using undocumented APIs. That was a long time ago, I hope things have gotten better by now. :)
- alyssam_infosec 6y agoIt is a bit surprising but at the same time Mintegral did go through a number of steps to obfuscate the code to make it harder to see that it was impacting standard iOS SDK methods.
- 6y ago
- untog 6y agoI feel like it’s been accepted wisdom for a long time that native apps are more secure than the web. In the last few months I’ve found myself wondering if that’s actually true. They both have their own, different security problems.
- alyssam_infosec 6y agoThe challenge here is with SDKs, just like with other open source libraries and packages, once you introduce someone else's code into your app, it becomes infinitely harder to get visibility into what your app is doing and ensure that third-party code isn't doing something nefarious (or including a sub-dependency that does something nefarious).
- untog 6y agoTrue, but at least on the web I can inspect what network requests it sends, what the code is (even if it's obfuscated). Native SDKs are just a black hole.
- syspec 6y agoIn this case the SDK was ripping off the developer, by attributing watched ads to its own network by pinging the ad provider after it detected a ping from a different ad SDK in the running app. For the end user they were still watching ads just the same
- sloshnmosh 6y agoThis is very typical of mobile adware/malware to avoid triggering detection by the Apple App Store or Google play store. Sometimes when looking for signs of malware the easiest thing to observe is either it’s use of Persistance or its checks for root/jailbreak rather than the malicious code itself. I know there are many legitimate reasons for an app to obfuscate its code or to check if the device is rooted or running through a MITM proxy (such as banking apps for example) but I would think that if an app were submitted with these checks it should get flagged for further review at least.
- josephcsible 6y ago> I know there are many legitimate reasons for an app to obfuscate its code or to check if the device is rooted or running through a MITM proxy (such as banking apps for example) There's an argument to be made that even those aren't legitimate, since you can do online banking from a desktop computer where you have root. I'd be in favor of app stores banning root checks from apps that don't need root.