5 ms·
I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installe
by ytjohn 6y ago
I was 100% impacted by this. I've used that barcode scanner app for pretty much forever. I can't be 100% certain, but it's one of the first apps I ever installed on my first android phone (around '08/'09). It was what I directed other people to since all the other barcode scanners had ads.
Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it goes away for a day or so. I originally attributed it to an open tab, or some site that I had inadvertently enabled notifications for. It took me a few days of seeing these and checking browsers to realize it was more, so I started checking apps recently installed. I even installed malwarebytes to do a scan, found nothing. There were three recently updated, including barcode scanner. I opened that and malwarebytes immediately flagged it. So the scanner seemed to know about it at that time, but couldn't detect it until you actually opened the application.
I used to have Theft Aware before it got bought by Avast, and I tried Lookout some years ago. But it was this incident that finally convinced me to install and keep anti-malware app on my phone. I've also disabled app updates from the play store.
EDIT: Mine was by "The Space Team", not the one listed in the article. Seems like a number of barcode scanner apps were targeted recently.
- f430 6y agoSo just to be aware, what was the root cause of this incident? Was it permission settings? How did it slip through the release process on Google Play, or is there none at all? What does this mean for other apps with overreaching permissions?
- ytjohn 6y agoThis app only had the basic permissions of camera and to open web links - pretty much exactly what you need to scan a QR code and open a web page. The software author (or more likely someone they sold it to) pushed a new version of the app that would just keep opening links to various ads. The key here is that the author had a properly working, trusted, non-invasive application for years and then they pushed an updated version that was less so. Fortunately, it was an app with minimal permissions - it could only open web pages. In my case, running ublock, those pages came up blank. But for others not running an ad filter, they got pop-ups prompting them to install even more malware. As for Google Play release process, I can't speak on that too much. They do scan for malicious code, but this code may not be malicious enough. If part of an application's purpose is to open web links, more code that opens links would not be as noticeable. Apple has a more intensive process to review new apps, and they spot-check app updates, but it's going to be somewhat similar. We hear about Apple pulling existing applications all the time for random reasons, but it's often after an update or report. Google pulled some of these apps after they were reported, but it was also after. I'm not defending Google Play - they have a more relaxed review process than Apple, relying more on automation. But both have "legitimate" apps pulled for obscure reasons (and the only recourse seems to be getting attention on HN/Twitter/other), and both have let scam apps through. Apple seems to catch more of the "bad" apps, but also drops more legitimate apps that compete with Apple's business interest.
- system2 6y agoTwo words for you: Buy iPhone. I know some people hate Apple but these type of things never happen or so rare. I hear android malware very often though.
- enragedcacti 6y agoThree words: Buy Nokia 3310. These types of things literally never happen. Or maybe people have a lot of reasons for why they chose what they chose and this isn't productive.
- jcun4128 6y agoWell... maybe Linux phones can catch up/have a market... at least code goes through the specific distro checks eg. Mobian if by apt
- davchana 6y agoWere you using the app from ZXing team https://play.google.com/store/apps/details?id=com.google.zxing.client.android https://play.google.com/store/apps/details?id=com.google.zxi... app? Because this app was last updated in 2018, has a generic name Barcode Scanner, & has attracted hundreds of reviews like yours saying App was updated recently, & now causes Web Ads. For a counter point, I am also using this app since 2016, & have all apps on auto update, & have never received any web add popup or notification because of this or any app.
- ytjohn 6y agoThe ZXing app is in fact the one I've had since "the dawn of android". But when I switched phones a couple years ago, I had apparently installed the one by the Space Team[1]. It took me a bit of digging to make the distinction. I have both of them listed in my App Library, and both with the same name. At some point, I believe I went to install ZXing on a new phone and Android warned me that the app may be incompatible, so I went to the space team one. It makes sense that if people aren't looking directly in their app library that they can get these mixed up and leave the bad reviews. However, since the space team version got infected, I did try the ZXing app - no pop-ups, and it works just fine (despite the age warning). https://play.google.com/store/apps/details?id=com.qrcodescanner.barcodescanner https://play.google.com/store/apps/details?id=com.qrcodescan...