25 ms·
Barcode scanner app on Google Play infects 10M users with one update
- kmeisthax 6y agoI had fullscreen ads on unlock with another barcode scanner app - IDK if it was this one or another one, but I remember blaming several other apps before figuring out it was a barcode scanner and removing it. The really frustrating part was that trying to open the app switcher to find out what app this was coming from would also dismiss the ad somehow.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- ravenstine 6y agoThis is precisely why I have auto-updates turned off. No minor security or bug updates are worth getting an all-out infection(or unexpectedly losing features).
- IgorBog61650384 6y agoHow do you decide when it is safe to update?
- userbinator 6y agoThe short answer is "when the benefits outweigh the risks"; i.e. if there's a huge bugfix or new feature you need, but something like a barcode scanner is something whose change frequency should be very close to zero. The "update culture" has unfortunately trained users to obediently "bend over and take it", which is horrible from both the security and change-management point of view; but is the dream of those who want to exert control over "the sheeple".
- ntSean 6y agoYour dogmatic approach to updating would prevent you from installing a version _without_ malware attached. For example, a version of Xcode circulated in China was infected with malware and once Apple had detected it, they asked all developers to recompile and update their apps immediately. https://www.zdnet.com/article/how-malware-finally-infected-apple-ios-apps-xcodeghost/ https://www.zdnet.com/article/how-malware-finally-infected-a... With your attitude, you wouldn't have necessarily seen the efficacy in updating the apps and could still be infected to this day.
- DrScump 6y agoEvery Google Play update prompt in My Apps has a description provided by the publisher. If there is an urgency to update and they don't say so, I'm not going to blithely accept every update. Ior example, had there not been the exploit risk, I would have left Chrome at the older version, as their new tabgroup implementation is horrible, and it doesn't even allow you to open a new tab without creating a group or going incognito!
- stedaniels 6y ago> Every Google Play update prompt in My Apps has a description provided by the publisher. I hate to reply like this but, the vast majority of Google Play app updates go something like this: "Updates." "Fixes" "..." Having genuine changelogs would be glorious. Apple and Google should require proper source and issue management, they could then generate changelogs automatically. Having that, they could then use machine learning against the code commits and issue titles to ensure that what people say are happening, are actually happening in the code. I mean we've got ML that can generate code from natural language, I'm sure the bright sparks at Google and Apple could use some ML to, with a high degree of probability, say that the code does what the comment/issue says it does.
- unishark 6y ago"performance improvements and bug fixes". I just looked at the messages for the last ten or so updates on my phone and the last three were worthless like the above, but the rest were relatively detailed and informative. I imagine they are more motivated to give details when it's for new features.
- littlecranky67 6y agoProbably never. I mean, I am on iOS and as a developer I know how hard it is to get your code to run on iOS. Heck, security flaws that jailbreak an iOS device just via network/OTA is paid serious money for, there is no need to implement this. I seriously ask the question what damage could a potential malicious app on iOS cause? There is no running in the background, so no exploiting while I don't use the app, no being part of a botnet when the app is closed. There is a FS sandbox that will not let you access another Apps data without being able to jailbreak etc. I think an auto-update is more risky on iOS than to live with an older version of the app that does its job (you never know what an update changes/breaks for you, and downgrading is not an option in the appstore).
- TeMPOraL 6y agoSame here. Every now and then some app stops working or politely asks me to update, so an update it'll get (and at that point I have time to look it over and rethink whether I even need the app). Last time I went on an "update spree" and updated everything I tend to use frequently, I got the new Firefox mobile update, which is frankly utter garbage, and now I regret it. (Why it's utter garbage? It's much more laggy across the board, and there are issues getting uBlock Origin to work on it. And this tends to be the story with updates - I haven't seen the app that got leaner, or faster, or more ergonomic with an update. Not a single one.)
- lvs 6y agoThe OG Barcode Scanner app is getting absolutely throttled with negative reviews. But this posting seems to be about a clone app by a different developer. https://en.wikipedia.org/wiki/Barcode_Scanner_(application) https://en.wikipedia.org/wiki/Barcode_Scanner_(application) https://play.google.com/store/apps/details?id=com.google.zxing.client.android https://play.google.com/store/apps/details?id=com.google.zxi...
- owijfoewiwid 6y agoThis is a very important distinction.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- bigiain 6y agoI wonder if there's a coordinated effort to exploit barcode reader apps, because (at least where I'm from) its becoming a government mandated Covid tracing thing to use a QR code to "check in" to certain classes of businesses/venues? I bet there's a _huge_ increase in use of QR code scanning apps compared to this the last year...
- admax88q 6y agoIts kind of amazing that there isnt an official qr code scanner app preinstalled on phones given how ubiquitous QR codes are.
- bigiain 6y agoI think Android 9 and up has QR code scanning built into the camera app, same as similarly recent vintage iOS. iOS is somewhat less problematic given that ~98% of devices are running current or one version old OSes, where the Android fleet has a huge install base who won't or can't upgrade from pre Android 9 versions. Last time I looked it was still over 40% of all Android devices. I've side loaded LineageOS into a few old old Android devices, Galaxy S3 and S4s, but my S6Edge is still running the Android7 OS it has when Samsung abandoned it. My similar vintage 2015 iPhones 6S is running fully current iOS14 - but it is the oldest Apple device that'll run it. (To be fair, my Samsung S3 vintage iPhone 5 can't run anything newer that iOS10.3).
- LordOfWolves 6y agoApple’s (often critical) review process for app updates is shining right now! Edit: /s
- deleted 6y ago[deleted]
- m463 6y agoApple does not let you back out an update you made and regret. Apple does not block apps from using the network or give you any way to find out what they are doing and who they are talking to. In fact, apple does the opposite - it blocks apps that let you firewall your phone.
- ntSean 6y agoApplications like Charles [1] allow you monitor network connections and data closely. Apple do not actively prevent this. You can also setup a VPN to route traffic and strictly firewall. [1] https://www.charlesproxy.com https://www.charlesproxy.com
- m463 6y agoCharles must have some wild carveout from apple. All other apps that do that have been shut down. I still run a very old version of adblockios that starts a vpn (proxy) at 127.0.0.1 and blocks traffic that way. mostly.
- mbreese 6y agoI think the parental control app Circle does something similar (faux-vpn proxy). When I tried using Circle, it seemed a bit convoluted to me, so we ended up uninstalling it. So, I’m not sure how unique this method is. But, I’m not sure I can think of another way for a network blocking/security app to work on iOS.
- ignoramous 6y ago
- em3rgent0rdr 6y agoStallman calls autoupdates a "universal backdoor".
- est31 6y agoHe is right in a sense, and cases like this give him proof, but on the other hand, most people don't see the point in patching their software. They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?
- macksd 6y agoThere's a third possibility, and I think it's Stallman's ideal computing landscape: all users care deeply about the code running on their machines and they are competent in applying and vetting patches, building from source, etc. It's unrealistic, sure, but it sounds nice right about now.
- TeMPOraL 6y agoI don't think it was ever Stallman's point. He is smart enough to recognize most users aren't going to be technically competent. He's also smart enough to recognize is that most people are going to have someone technically competent in their circle of friends, or within few minutes of walking distance. So people need a set of rights that will allow them to ask or hire someone else to care for their computing. In this sense, Free Software is like Right to Repair - it isn't about making individuals technically competent; it's about enabling local markets of specialists.
- est31 6y agoI think back when he posted it, it might have been possible for sufficiently motivated and talented individuals to do such vetting, albeit even then it would have been a stretch. Nowadays the amount of code running on various devices in a single home has increased so dramatically... Think of TV remotes. They used to work with infrared. Nowadays, there are bluetooth remotes (not sure how widely deployed they are, but at least some vendors offer them instead of IR remotes). An infrared device can be send only. No way to hack it even if you have an infrared sender in range. The pattern transmitted was quite simple. The bluetooth protocol however requires both sending and receiving ability. Bluetooth stack is in the tens of thousands of lines range. There will be a security bug somewhere...
- RavlaAlvar 6y agoThis, is why I am going to buy more apple stock tomorrow.
- marcinzm 6y agoThinking about it, Apple seems like they'd have better dealt with this sort of issue in four ways: * Stricter review process to catch this preemptively * Stricter app isolation to limit impact without a vulnerability explicit * Longer maintained and more forceful operating system updates to minimize the number of phones running with known exploits * Likely removing/disabling app from phones and not just the app store
- mcpeepants 6y agoI think you mean Google, but also noting that #4 is possible (supposedly) through Google Play Protect
- swiley 6y agoStuff like this happens on iOS all the time and everyone just ignores it because it's mostly sandboxed. Apple is terrible at stopping malware until it ends up in the news.
- ship_it 6y agoSource? Or you just made that up?
- joshuaissac 6y agoHere's an example of 18 such apps from 2019: https://www.wired.com/story/apple-app-store-malware-click-fraud/ https://www.wired.com/story/apple-app-store-malware-click-fr... Another from 2018: https://www.zdnet.com/article/top-mac-anti-adware-software-in-apple-app-store-steals-your-browsing-history/ https://www.zdnet.com/article/top-mac-anti-adware-software-i...
- marcinzm 6y agoThe first didn't cause any user issues as I'm reading it except extra data usage. I don't think it even did it in the background but only when the app was running. So I wouldn't even call it malware. Unlike this Android app which showed ads to users outside the app. The second is Mac not iOS which had a much more relaxed security model.
- IgorBog61650384 6y agoThe only reason this was detected was very overt behavior - opening AD popups. So I guesstimate for each one of these we have 10 that go undetected. This means the whole ecosystem is broken, as there is no reason this will happen only for updates and not for new apps as well. Apple's ecosystem is somewhat better, but I can't imagine they go through every line of code in each package, so most of their review is probably done with some combination of automatic static and dynamic analysis, and these can be fooled. The problem with both platforms is that they don't provide run of the mill users the option of installing an effective firewall and security solutions.
- m463 6y agoThis happened on ios for me years ago. I had two apps that radically changed their business model (owner?) through updates with no recourse. I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remind you of upcoming maintenance. One day, I updated the app and all my local data was uploaded to the cloud. Another app I updated was camscanner from tencent that basically did the same thing. Think of all the PDFs you scan going to their cloud.
- chordalkeyboard 6y agoSchool tried to make me use camscanner, glad I took the extra effort to do something else. Thanks for the anecdote.
- dotancohen 6y agoI absolutely love Camscanner, and I have been for over a year on the old version because I refuse to update to the new version which requires network permissions. I exactly suspected this is why it needs those permissions. To what did you switch? Camscanner is otherwise an excellent app, especially for combining multiple images and straightening them out.
- rajveermalviya 6y agoCan't Google remove apps like Rocket Cleaner, that participate in these ads?
- est31 6y agoI don't get why no barcode scanner app is shipped with Android. It's such a basic functionality. Edit: apparently it IS shipped on iOS and at least my Lineage OS default camera app has a QR code reader too.
- the_only_law 6y agoI don’t think my past two phones (one Android, one iOS) have built in QR scanning, or at least it’s not very discoverable. No fun to have to find something in an App Store when it all looks like 7 year old malware.
- deleted 6y ago[deleted]
- srgpqt 6y agoYou can point the builtin Camera app on iOS to any QR code, it will pick it up just fine.
- astura 6y agoSame with Android
- other_herbert 6y agoTry your plain camera... this seems like such a hidden anti-feature though... no one I know has tried just the camera
- shadowofneptune 6y agoI discovered this week when fooling around with QR code makers that the Android camera app, at least the one released on Samsung phones, does not read QR codes. That was very surprising to me.
- lstamour 6y agoOn iOS, you can use the Camera app on your iPhone or enable the Code Scanner button on the Control Panel: https://support.apple.com/en-ca/guide/iphone/iphe8bda8762/ios https://support.apple.com/en-ca/guide/iphone/iphe8bda8762/io... It would be interesting if Apple added support articles or how-to videos for built-in features to their App Store search results though…
- monksy 6y agoI found this behavior in the Barcode Scanner app by "the space team" That was not one that was mentioned by the article It's url: https://play.google.com/store/apps/details?id=com.qrcodescanner.barcodescanner&showAllReviews=true https://play.google.com/store/apps/details?id=com.qrcodescan... (See the reviews)
- hulunon 6y agoI also found this pop-up add behaviour Saturday (6th) morning. I distinctly remember looking at this app last year when a different barcode scanner had an issue and it was not owned by "the space team" then,maybe a takeover? App now uninstalled
- zerocrates 6y agoThe one I remember being popular before on Android was the "zxing" one: it's still on the Play Store but has tons of recent reviews complaining about adware... confused users (and/or competitors taking advantage) leaving reviews on the wrong one? The zxing one seems to not have been updated in years (plus it's still on the store).
- jsmith45 6y agoRight. Space Team's app was a fork of the zxing demo app updated to newer SDK versions, but with the same name and basically identical interface. It had a malicious version uploaded recently, and was nuked by Google. People then found the original, that looks the same, and started leaving negative reviews, attacking the "maintainer" (who does not really maintain it anymore, since Google no longer pays him to do so and it is no longer possible to update for the play store without some substantial code changes to target the newer android API versions) on Github, etc.
- squealish 6y agoGlad you brought this one up. I also had the app you mentioned installed and noticed pop-up ads in Chrome. I immediatly uninstalled the app and left a review. Like many other negative reviews I received some copy-pasted response stating they only have some in app ads. It is beyond me that the developers just lie about including malware in their app while it is so obvious they are.
- ntSean 6y agoWhen the Apple App Store contained malware compiled by unsuspected Chinese developers using a local cache of Xcode [1], Apple emailed the developers to prompt them to update their application immediately and removed them from sale. Apple also contacted users directly to alert them of whatever apps they had purchased on the App Store were compromised so they could monitor for updates, or remove the app entirely. Has Google done the same? Neither Apple or Google have the ability to directly remove apps on a users device, but simply removing it from the store and then having users rely on a solution like MalwareBytes seems like Google is abnegating their responsibility of a safe marketplace. [1] https://en.wikipedia.org/wiki/XcodeGhost https://en.wikipedia.org/wiki/XcodeGhost
- saagarjha 6y agoApple has this ability, but they have not used it: https://iphone-services.apple.com/clbl/unauthorizedApps https://iphone-services.apple.com/clbl/unauthorizedApps
- slezyr 6y agoGoogle can disable apps on the users' devices. https://developers.google.com/android/play-protect/client-protections https://developers.google.com/android/play-protect/client-pr...
- vultour 6y ago"Can" Play protect is a complete joke, it can't even detect malicious chinese apps that request every single permission that exists.
- jk7tarYZAQNpTQa 6y ago> Neither Apple or Google have the ability to directly remove apps on a users device I'm pretty sure both can. But it's a legal problem, not a technical one.
- Animats 6y agoSo why aren't we hearing about someone being arrested? Google knows who their devs are. Law enforcement can demand they give up that info.
- layoutIfNeeded 6y agoThey are most likely Chinese. I’ve been getting asked by Chinese accounts on LinkedIn to let them use my account to submit their apps on the Google Play Store for a fraction of their revenue. I’m guessing there’s a similar scam going on here too.
- Farbklex 6y agoThis is also very common on freelance sites like Upwork.
- pjc50 6y agoComputer crime is so very rarely traced and prosecuted, like most white collar crime.
- _AzMoo 6y agoRight, which is a massive problem. If these people and those like them were prosecuted then we'd have far less of a problem.
- Cthulhu_ 6y agoIt's still a massive issue if the crime crosses borders; if the entity behind the malware is from, say, Russia, what can a prosecutor in the US do? This is why internet crime is such an issue.
- deleted 6y ago[deleted]
- tinus_hn 6y agoThere is a difference between ‘infects’ and ‘shows pop-up ads’. Annoying? Sure. Comparable to a complete security breach? No.
- timdaub 6y agoHEY THIS IS THE PERFECT MOMENT TO PLUG MY SUPER MINI PROJECT: https://scan.lol https://scan.lol Excuse my caps!
- deleted 6y ago[deleted]
- protoman3000 6y agoEven legitimate app developers have no incentive to keep their apps sterile. Someone just has to approach you with your 10+ million users barcode scanner app and offer you +50,000$ in order to install some automated ad clicker for them. Don’t be naive, the majority will accept the money and gladly. I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtake. Apps that offer what should have been offered by the OS vendor in the first place. Why should the app developer refuse the money if what their app offers will be incorporated in a next OS update by anyways? Why defend your mini-adapter-app in an ocean of mini-adapter-apps, with yours becoming so large just because of a random seed and path dependency? This can have a big impact for end users. Imagine an authenticator app ending service to all their users in such a scheme and how you will be cut out from all your accounts by this. How many authenticator apps do you have to use in parallel to mitigate this risk of a single point of failure?
- iKevinShah 6y ago> This can have a big impact for end users. Imagine an authenticator app ending service to all their users in such a scheme and how you will be cut out from all your accounts by this. How many authenticator apps do you have to use in parallel to mitigate this risk of a single point of failure? This right here is a big reason, apart from actual restorable backups, why I root my Android device. Sure it is not required nowadays but it does give a sense of control if thats the right word. So many times I had to restore older copies of apps like Chess or even Yoga app. The older apps allowed a functionality (downloadable content for offline view) which was straightup removed in newer versions. Same for Authenticator or any other app which does things locally.
- davchana 6y agoI, like many other HNers, simply store the secret passphrase & QR code in a separate keypass database. Recently Google Authenticator app added the ability to move all codes to next phone by displaying multiple sequence of QR codes, but I coded a simple no internet just local storage & javascript app to to utilize otpauth:// protocol to eadily readd the codes on new phone https://spa.bydav.in/otp.html https://spa.bydav.in/otp.html
- lucioperca 6y agoI stopped using apps from companies or projects I don't know some time ago. Which left basically small local companies, the big global ones and FOSS-projects. This of course is not perfect but at least leaves some sort of accountability.
- curiousgal 6y agoThis is why I root my phone. I block internet access to any new app that shouldn't need it, if it refuses to work, I uninstall it.
- laurent92 6y agoAll my employees use a JSON formatter on Chrome. Such apps require permissions to view all sites... I require them to create 2 profiles in Chrome (and a 3rd for personal purposes), one for dev and one for official purposes, but I know that, in remote work, they get less serious. It’s a major security problem. I’m wondering whether I should purchase the Chrome extension’s source code and deploy it myself on the store.
- dolmen 6y agoThe title says "Barcode scanner", but this is a QR Code scanner app from qrcodescanner.com
- dolmen 6y agoI'm glad that Firefox on Android now has a built-in QR code scanner. This is the best UI and security improvement they added in the last 5 years.
- jabl 6y agoIt has? How does one use it?
- nanagojo 6y agoThe iPhone stock camera app also scans QR codes btw, guess most people just don't know since it isn't advertised heavily
- tambeb 6y agoGoogle's stock camera app supports QR codes.
- dagurp 6y agoVivaldi just added one too. I'll never undertand why Google didn't include one from the start. They finally added it to the camera app but very few people know about it.
- deleted 6y ago[deleted]
- tuco86 6y agoI noticed the package name com.qrcodescanner.barcodescanner. and went to https://qrcodescanner.com/ https://qrcodescanner.com/ which advertises another very popular barcode scanner wescan. they also offer an sdk of their own for including a barcode scanner into your app. https://github.com/WeTransfer/WeScan https://github.com/WeTransfer/WeScan I'm not really sure they are connected (package names don't verify domain names AFAIK). Just curious.
- greatgib 6y agoOne can say that the solution to this is more control/power for the app store, but te opposite, the solution for this problem on computer was solved decades ago: Open source software and more open and transparent platforms! Today users of common brands of Android and Apple devices are really restricted in control of their devices, so there is very few ways to check what the system or apps are doing, inspect, firewall/limit things, go tinker inside the apps. And as said by other people, most of the time you have auto updates forced on users and so app developer does not even have to really justify what changed and why.
- deleted 6y ago[deleted]
- mpol 6y agoAgreed. The only way reviews can be done is by stores doing the review based on source code, and have submitting source code be mandatory with automated builds before review. That is not something companies like Apple or Google would even care about, it is not in their interest, since it is not their problem. The phone market is a duopoly, Google and Apple have the market shared between them. There is no need to really improve this situation for end-users. For me it feels like Windows XP all over again. I am a happy user of a Linux phone. I very much enjoy and support Jolla and Sailfish OS, while also hoping for the Pinephone and the Librem 5 to take off and be available as an option for daily use.
- prof18 6y agoQR Reader are load of everything. I went mad to find one a decent one for my parents’ android phone and apparently it doesn’t exists. So in a weekend I’ve created one without any kind of tracking, ads, permission, whatever. Here it is if you guys need one -> https://play.google.com/store/apps/details?id=com.prof18.secureqrreader https://play.google.com/store/apps/details?id=com.prof18.sec...
- moritonal 6y agoBut this is the classic cycle don't you see? They almost always start as "here is an app I threw together, no ads, don't be evil". But then a lot of people like your app, and ask for a small extra feature. You support it, and then get a bit annoyed by all the features people are asking for. Then you have to update it for the latest release... then suddenly fix it when some obscure version of Android breaks on it. Then someone offers you £60k for a small ad no-one will even see and you think.. don't you deserve a bit of credit? Maybe you'll be the good one who doesn't take it, but the free model is generally unsustainable.
- welly 6y agoIf the OP open sources his QR code reader app then the "free" model is absolutely sustainable.
- e12e 6y agoThe op did (it's in the description on the app store, but was unfortunately (considering the context and audience) left out from they comment: https://github.com/prof18/Secure-QR-Reader https://github.com/prof18/Secure-QR-Reader
- prof18 6y agoI'll never do that, because I've done it without any kind of profit in mind. I've done it just to help people and the community. I think that if the app is open source, it's harder to hide such behavior.
- kuschku 6y ago
- dbrgn 6y agoI recently noticed that the "Barcode Scanner" app by ZXing (https://play.google.com/store/apps/details?id=com.google.zxing.client.android https://play.google.com/store/apps/details?id=com.google.zxi...) was being review-bombed with 1* reviews. People were talking about the "recent update", even though the last update is from February 2019. As far as I know, that app is open source and never contained ads. (Of course, without reproducible builds, we'll never know for sure.) Was ZXing also hit by some issue, or is that just confused people that mistook the ZXing barcode scanner for the Lavabird barcode scanner? In the comments of the article, someone wrote: > The Zxing project is the flagship open source barcode scanner project for many years, and the December 2020 build was infected with malware. That bad build has been removed, of course, but the damage to the project continues. Is there any further information on this?
- lucioperca 6y agoProbably the people responsible for the malware barcode scanner have other scanner apps in the game and trying to prevent user from their app from installing the Foss app and live happily ever after.
- dbrgn 6y agoYep, fake reviews by malware-ridden competitors was also one of my thoughts. But there's this motto "don't attribute to malice what can be attributed to stupidity". It could also be both of course.
- aasasd 6y agohttps://github.com/zxing/zxing/issues/1345 https://github.com/zxing/zxing/issues/1345 The dev says the app hasn't been updated since 2019.
- pieter_mj 6y agoTo be clear : "the December 2020 build was infected with malware" only refers to the lavabird barcode scanner and not other apps (that use ZXing library or not).
- aq3cn 6y agoI stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged. few QR code apps from F-Droid. https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCodeScanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...
- uzakov 6y agoAdditionally you can have two/three separate phones, linked to separate accounts for different purposes. I keep one phone separate for phone gaming.
- haspok 6y agoBoth recommended apps use the ZXing library. So it is a small world, and if someone overtakes ZXing (assuming that it is not malicious right now), then all apps become infected. Otherwise no security and bugfixes, no improvements, no version upgrades... who knows how long this library will work?
- ignoramous 6y agoOpen source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-Droid apps blindly, and more importantly, refrain from blanket advocating F-Droid apps as a security / privacy panacea. What I do instead is monitor Android's traffic with a LittleSnitch-esque firewall and block all apps I don't use. Also, I've disabled auto-updates on non-essential apps. Only Photos, Maps, Chrome, and Firefox are allowed to auto update on my Android.
- krageon 6y agoIt would be more compelling if you actually mentioned what app you've found that's so naughty.
- lukeitup 6y agoSimple scanner turns evil.. these kind of apps should have been offered by the respective OS, as a standard app. If the money involved are correct, then are the developers to blame?! I'm not sure to be honest.
- estomagordo 6y agoOh wow, one hundredth of a user. People really need to start respecting m=milli and M=mega.
- tiagod 6y agoThe m in the title doesn't stand for mega, it stands for million, and lower-case m is a proper abbreviation: https://www.lexico.com/definition/m https://www.lexico.com/definition/m
- hilbert42 6y agoQuote from Malwarebytes site: "Peter V. Jaspers-Fayer - Why does this article not contain the publisher and the icon of the app in question? There are many called "Barcode Scanner", and by omitting this information, you have caused unwarranted panic by users of innocent apps of the same name." The fact that Google allows applications on Google Play to have identical/duplicate names is a significant ongoing problem as it causes considerable confusion. I'm not against apps that have similar functions having identical (duplicate) filenames as this stops developers having to dream up ridiculous names that have little or no bearing to an app's function but it would make sense to separate the apps in some simple way that users could easily identify. For instance, apps with identical names could be flagged in many ways such as, say, Google providing a sequence number to the end of the filename. And I'm sure there are many other suitable ways I've not thought of. As for the fact that Google lets malware onto Google Play and that it has happened many times demonstrates the fact that Google doesn't consider the matter of highest importance. That's to say, keeping malware off users' Android phones is not as important as making money from its advertisers. If keeping malware off apps were equally important to Google then this is malware would have unlikely escaped Google's monitoring, as Google has just about every technical measure at its disposal to monitor apps for malware—and I'd venture to say that even its AI technology could be brought bear. Clearly, if both issues aren't of equal importance in Google's eyes then it raises questions as to why Google keeps changing or adding certain features to its Android operating system in the name of security but which annoy users (and in effect violate their privacy—in that users' data, etc are even more transparent to Google whether the user likes it or not). Day by day, Google is proving itself to everyone to be more of a worry. — Note: I'm one of those who have an app on my phone named 'Barcode scanner' and it took me a while to determine (fortunately) that the one I have installed is not the app in question.
- unixhero 6y agoAnother episode of Stallman was right.
- svara 6y agoI was affected by this. Funny how Malwarebytes wants to turn this into positive PR about how they reacted "quickly". I installed just about every Android anti-malware app that I could find in late January, and none detected the bad app. Finally by googling some of the ad domains that kept popping up, I found the forum discussion that they mention. In other words it took them about two months to react! Edit: either it took forever or there are multiple barcode scanner apps that are affected and they didn't find all of them.
- phendrenad2 6y agoWhy is a barcode scanner app able to open a web browser and navigate to a page without user interaction (just by being installed)? That's the real question here.
- scns 6y agoI use this one from F-Droid: https://f-droid.org/en/packages/com.secuso.privacyFriendlyCodeScanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo... you can directly download the APK from that site, don't need an F-Droid client. If you want an F-Droid client, i recommend Foxy Droid. Unfortunately lacks some features of the official one but way faster and nicer to use. https://f-droid.org/en/packages/nya.kitsunyan.foxydroid/ https://f-droid.org/en/packages/nya.kitsunyan.foxydroid/
- herendin2 6y agoThe developer's street address, as shown in the malwarebytes screenshot, is obviously either incomplete or bogus. There's no city or country, and a weird unit number. Is Google Play really approving apps from such dubious sources? Or does Google have the full address? Seems unlikely
- meibo 6y agoYou don't need to provide this publicly if you do not have any billing in your app, so no IAP or paid apps. They might just not verify it though. Google has it, since publishing requires a $15 one-time fee. Of course, you can put bogus into the billing info for that as well.
- varispeed 6y agoMost apps on Android behave like a malware. The most annoying ones are those who randomly take over the screen and play ads with annoying music and you have no way to close it quickly and you don't know which app is displaying those. Only solutions so far is to actually disable apps one by one and see if the problem appear. I think Google should remove all apps that do that. My friend's phone who is not IT literate, essentially looks as the IE6 back in the day.
- secondcoming 6y agoDoes any know what SDK they were using? I work in adtech and would like to review traffic from this SDK and potentially block it. Edit: Seems they're using MoPub and AdMob
- marcodiego 6y agoConsidering I'm not dependent on any Google Play only app, is there a good reason not to use f-droid instead?
- Farbklex 6y agoThis is even worse when the app in question comes preinstalled on your Samsung tablet and can't be uninstalled (but afaik it can be stopped and downgraded). https://fossbytes.com/peel-remote-use-remove-smart-remote/ https://fossbytes.com/peel-remote-use-remove-smart-remote/ "Truth be told, Peel Remote has been scrutinized for more than a year because of the company desperate measure to gain revenue. In 2017, the app introduced a malign ad practice of unethical lock screen ads and overlays." My girlfriends tablet just started turning the screen on at random times. It took some time to find out which app causes this.
- wooptoo 6y agoThis is possibly tied to the recent assault on the ZXing Barcode scanner app[1]. This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus. It takes a special kind of scum to slander an open source project in order to push malware. [1]: https://play.google.com/store/apps/details?id=com.google.zxing.client.android https://play.google.com/store/apps/details?id=com.google.zxi...
- Avamander 6y agoI reported a bunch as spam, but it probably netted me some negative reputation by their AI though.
- kevingadd 6y agoYeah, be careful doing anything like that on the Play Store. You can get your account randomly locked out with no explanation (I haven't been able to review apps, leave comments or contact the developer for like 3 years, and I never got an email or notice about this)
- consp 6y agoIf you have a gsuite account, that might be the reason. This started somewhere in 2018.
- ytjohn 6y agoI was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads. Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it goes away for a day or so. I originally attributed it to an open tab, or some site that I had inadvertently enabled notifications for. It took me a few days of seeing these and checking browsers to realize it was more, so I started checking apps recently installed. I even installed malwarebytes to do a scan, found nothing. There were three recently updated, including barcode scanner. I opened that and malwarebytes immediately flagged it. So the scanner seemed to know about it at that time, but couldn't detect it until you actually opened the application. I used to have Theft Aware before it got bought by Avast, and I tried Lookout some years ago. But it was this incident that finally convinced me to install and keep anti-malware app on my phone. I've also disabled app updates from the play store. EDIT: Mine was by "The Space Team", not the one listed in the article. Seems like a number of barcode scanner apps were targeted recently.
- f430 6y agoSo just to be aware, what was the root cause of this incident? Was it permission settings? How did it slip through the release process on Google Play, or is there none at all? What does this mean for other apps with overreaching permissions?
- ytjohn 6y agoThis app only had the basic permissions of camera and to open web links - pretty much exactly what you need to scan a QR code and open a web page. The software author (or more likely someone they sold it to) pushed a new version of the app that would just keep opening links to various ads. The key here is that the author had a properly working, trusted, non-invasive application for years and then they pushed an updated version that was less so. Fortunately, it was an app with minimal permissions - it could only open web pages. In my case, running ublock, those pages came up blank. But for others not running an ad filter, they got pop-ups prompting them to install even more malware. As for Google Play release process, I can't speak on that too much. They do scan for malicious code, but this code may not be malicious enough. If part of an application's purpose is to open web links, more code that opens links would not be as noticeable. Apple has a more intensive process to review new apps, and they spot-check app updates, but it's going to be somewhat similar. We hear about Apple pulling existing applications all the time for random reasons, but it's often after an update or report. Google pulled some of these apps after they were reported, but it was also after. I'm not defending Google Play - they have a more relaxed review process than Apple, relying more on automation. But both have "legitimate" apps pulled for obscure reasons (and the only recourse seems to be getting attention on HN/Twitter/other), and both have let scam apps through. Apple seems to catch more of the "bad" apps, but also drops more legitimate apps that compete with Apple's business interest.
- Pxtl 6y agoMeanwhile they block the Terraria developer's Google account, after which he's decided to cancel his game's port to Stadia. How are they so bad at this? Literally driving away legitimate developers while letting scammers run wild.
- DenisM 6y agoWhat's easy to do for a thousand apps is impossible to do for a million apps. Large scale is not a new quantity, it's a new quality.
- codesternews 6y agoWe are the same guys want every app to be free. Do you expect bread to be free or coffee to be free? Why we expect apps to be free even from google? How do you think small app developers earn money by displaying ads? But we want ads to be blocked and don’t want to pay money
- Rooster61 6y agoAds within the app are fine, and I don't think many people who download a free app expect to have zero ads unless it says it. THIS app, however, displayed ads outside of the application when the phone was unlocked. It's not the same thing, and it's not ok.
- curt15 6y agoThis is why Ubuntu's forced auto-updates policy for snaps is crazy.
- kevingadd 6y agoGoogle Chrome extensions are like this too. Not a coincidence that they've had multiple identical incidents where extensions were sold to malicious third parties or had malware added in.
- drderidder 6y agoMy first ever mobile app was an experimental bit of Android Malware. It got demo'd by my colleague at Blackhat [1]. I'm definitely not a hacker, but with a few basic tricks I was able to create a pretty effective trojan which we then injected into a popular game (again only for experimental purposes, it was never released in the wild). In our lab we had literally millions of samples of Android malware, but for iOS we had only two (which only worked on jailbroken phones). Fun times. 1. https://www.softwaretalks.io/v/4047/black-hat-usa-2013-how-to-build-a-spyphone https://www.softwaretalks.io/v/4047/black-hat-usa-2013-how-t...
- jk7tarYZAQNpTQa 6y agoApple's iOS is way more secure than Android in several aspects. The best example is their 5 years of guaranteed security (and features!) updates, versus 2-3 tops in Android (even <1 with Chinese cheap brands than are very common in Europe, such as Xiaomi).
- TrianguloY 6y agoWhat I don't understand is why the internet permission (one of the most dangerous permissions in my opinion) is assumed to be always requested and not even reported when downloading an app. Sure, most apps need it (most of them for ads though) but at least warn me before installing like you do with other permissions like calls and sms. But wait, there is more, that permission (and some others) are considered so harmless that if you install an app without it, and then the developer publish an update with it, play store will automatically update it without even asking! Remember this doesn't happen with 'dangerous' permissions, so apparently Google thinks accessing the internet is not dangerous at all.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- waiseristy 6y agoCrazy to see this on HN. I was affected by this malware earlier this month and have both reported the app via the app store phone UI and submitted a full report w/ screenshots via the play stores web interface. Absolutely insane that I can still download this app from the play store and the devs account hasn't been nuked.
- f430 6y agoWhen did you first notice it?
- waiseristy 6y agoThe app was updated Jan 29th. I noticed probably on the 1st or 2nd of February. I had a hard time tracking down where the spam tabs were coming from, but the app luckily gave me a spam notification from which I was able to see the app name and uninstall it.
- f430 6y agoI just don't understand how Google Play could've let this slip. Was this like the cyberattack now to long ago where they were able to infiltrate the CI/CD process to slip in updates? Is this the fault of the developers not securing it or is this willful neglect or incompetence at Google Play store level?
- jboydyhacker 6y agoWe've built a QR Code and Barcode Scanner that is fully privacy compliant. It focuses on product search and providing local and online prices but the QR code Scanning is incredibly fast here: https://play.google.com/store/apps/details?id=com.biggu.shopsavvy&hl=en_US&gl=US https://play.google.com/store/apps/details?id=com.biggu.shop... If you guys have any features you'd like to see in a stand alone QR code Reader, let us know.
- qwertox 6y agoI wish Google would inform the users when they remove an app from Google Play due to it containing malware. I'm not sure if they also remove it remotely from the devices, I think they don't, because I once had an affected file explorer which then got removed from Google Play but not from my device. The same goes for Chrome Extensions which have been removed from the Chrome Web Store. In that case, they get removed automatically from the browser, which is somewhat ok. I would prefer that they would get disabled without me being able to enable it again, and get labeled as malicious. Because how else can I verify that I once installed an extension or an app which then turned malicious? Currently I know that either one of my or my dad's devices has something malicious on it, because I got an HTTP GET request to a URL whose full path is only known to our devices (and only via HTTPS).
- wnevets 6y agoAndroid doesn't actually need a 3rd party barcode scanner app. Google Lens supports barcodes.
- system2 6y agoAverage users don't know the default capabilities of their own phones and instinctively go to the app stores to find their one purpose ad filled apps. I've seen flashlight, basic camera, weather, clock apps that are inferior to default apps of the phones installed on many client devices.
- wnevets 6y agoInferior and probably filled with ads, tracking and now malware. Too bad Google doesn't try to let users know the feature already exist on their phone when users search for these apps.
- mickotron 6y agoBinary Eye is a QR scanner for android that is open source, and available on Google Play and F-Droid.
- michaelmrose 6y agoThere are so many different issues here. Arguably manual curation doesn't scale to google play store or apple app store size and automated scanning only gets you so far. You have several possible threats. 1. Apps that are malicious from the start. Best addressed by better automated testing. 2. Apps that become malicious particularly when the app changes hands. Best addressed by making this impossible. James/foo should never be transferred ownership should result in Jane/foo which users would have to download. 3. Apps that aren't malicious but include a component that is user hostile. Virtually always included for money. Best addressed by just forbidding apps with ads. We wont do this but not much of value would be lost. 4. Apps that include a component that isn't malicious but itself becomes malicious later. Requires due diligence by the developer. Arguably one could imagine better automated enumeration of the constituent components to discern what might have been compromised so that developers could have their apps automatically pulled and informed that they were compromised. One could also imagine a statutory fine for paid that earn developer revenue wherein their product harms users. This couldn't accrue to free apps without making foss impossible. Eliminating apps paid for with ads would eliminate a gray area. An interesting point for those who presently avoid ad laden apps is whether your paid for apps are infected with the same potential malware vectors as the ad supported version as whether or not to show ads may be solely a function of an in app purchase you have made. Your paid for app might therefore be just as vulnerable. What reasonable measures would one expect Google to actually take? Probably only reactive measures like removing this particular app while making no meaningful moves to correct any systemic problems. In the longer term one might expect them to do a better job of finding malware automatically. If you value not getting hacked in the longer term it looks like this is insufficient. If for example Fdroid is insufficient in scope of applications then perhaps we should work on improving this situation as Google is unlikely to fix this for us.
- deleted 6y ago[deleted]
- sloshnmosh 6y agoImagine if this app had opened the Chrome browser tabs to a specially crafted webpage that exploited a vulnerability in Chrome like the recent zero days in the V8 scripting engine.
- guy-om 6y agoQR code scanning should just be native in every OS.
- djrogers 6y agoWhat in the seven hells is this? Why on earth would any app not running in the foreground of my mobile device have the ability to launch a random web page? Guess this is why some walled gardens look a lot nicer from the inside...
- spacemanmatt 6y agoAnyone else just delete some unused apps?
- xtat 6y agoapp stores are false security, always have been