10 ms·
Chinese apps, even those from big established players, are often indistinguishable from malware. Off the top of my head, I can think of: - Hiding their app ico
by HeavenFox 4y ago
Chinese apps, even those from big established players, are often indistinguishable from malware. Off the top of my head, I can think of:
- Hiding their app icon from launcher, but add a widget that looks the same. So if the user tries to uninstall the app, they just deleted the widget and the app remains.
- One app would install other apps from the same company in the background without user consent.
- Multiple apps will wake each other so they always stay in the background and become impossible to kill
- Requesting every permission under the sun and transmit as much info to the mothership as possible
- Secretly turning on the camera and film their users
However, these only happen on Android version. iOS version never have these issues.
So even though I am not a fan of the Apple monopoly, I am really really afraid that by allowing third party app stores and sideloading, the western apps will race to the bottom and become just like this.
("But you can always download from the official App Store!" you may say. But what if, say, Tik Tok announces they will from now on leave the App Store and available only via direct download?)
- otterley 4y ago> iOS version never have these issues The security argument for the App Store has never been stronger. > "But you can always download from the official App Store!" you may say. But what if, say, Tik Tok announces they will from now on leave the App Store and available only via direct download? ... and nothing of value was lost.
- kelnos 4y ago> The security argument for the App Store has never been stronger. Perhaps, for many users this is true. But I don't need or want a nanny-company telling me what I can and can't install on my devices. (And yes, I do sideload apps -- including one I've written myself -- on my Android phone. So this isn't a theoretical "don't take my freedom" type concern.) >> But what if, say, Tik Tok announces they will from now on leave the App Store and available only via direct download? > ... and nothing of value was lost. Couldn't agree more with that sentiment. The problem is, though, that many people will still download it from TikTok's own website or app store. Security is a collective problem: even if I manage to avoid malware, a friend or colleague -- who may have email or chat or whatever history with me -- could get hacked, and that would still leak some of my data.
- gretch 4y ago> Perhaps, for many users this is true. But I don't need or want a nanny-company telling me what I can and can't install on my devices. 100% agree. Simply don’t buy an Apple phone.
- faeranne 4y ago> Simply don't buy an Apple phone. We said that about the headphone jack. Look where we are now. Companies follow what works, and Apple continues to pioneer anti-consumer practices. You shouldn't buy Apple, but that's not gonna solve the problem. We gotta continue to show why this is bad so others don't chase the same goals.
- jxramos 4y agothis has been a recent consideration of mine I haven't fully explored or thought how to deal with yet. I now look at new friends with suspicion, especially those who are not tech savvy. I just gave out an email to a friend recently and he forwarded me an email list without BCC revealing all the recipients. I thought to myself, "oh boy somewhere down the road I'm going to be getting hacked email messages from one of these individuals."
- m3kw9 4y agoWhy not just use android if you want to side load why force apple to allow side loading?
- CharlesW 4y agoBecause his freedom is more important than our security.
- wiseowise 4y agoWhat kind of question is that?
- faeranne 4y agoBecause it isn't just Apple. Back when Apple removed the headphone jack, people constantly said "Well just use Samsung" or some other brand. Look at where we're at now. If Apple can beat the current pressure, other brands will follow. We're no longer in a theoretical space with this. Companies actively follow the trend, and by excusing it because "it's just Apple", will end badly.
- manuelabeledo 4y ago> The security argument for the App Store has never been stronger. Is this really what we want? Because if so, what is the difference between a clamped down App Store with arbitrary rules, and what China does with their Great Firewall?
- simmerup 4y agoEvery industry is regulated, it’s coming for software and it will help the common user from being exploited. Do you see the legislation for broadcasting and say, ‘What makes that different from how you have no free speech in China?!’ We’ve already had voluntary step backs in the idea of online liberalism with Twitter having to be heavily pressured to take down ISIS propaganda. Codifying those rules for everyone is inevitable.
- dec0dedab0de 4y agowhat is the difference between a clamped down App Store with arbitrary rules, and what China does with their Great Firewall? With a locked down App store in America you have an option of using another device, or just using a computer, without any repercussion. With the Chinese great firewall working around it can lead to legal troubles, to put it lightly.
- raincole 4y ago... you know you can buy an Android phone, if that's what you want, right? You can't get an ISP without Great Firewall in China. If you try to found such an ISP you'll be in jail.
- matheusmoreira 4y ago> you can buy an Android phone, if that's what you want That's not what I want. I want Apple hardware. With software of my choosing on it.
- otterley 4y agoI want a pony!
- andersa 4y agoThis makes no sense. It's an argument for proper security controls and permissions setup on the OS level, not an app store.
- alex7734 4y ago> ("But you can always download from the official App Store!" you may say. But what if, say, Tik Tok announces they will from now on leave the App Store and available only via direct download?) Personal freedom always has personal responsibility attached. If you direct download it and it's malicious, well, that's your own problem. Probably should've thought about it better. If you don't want to think about security, all you have to do is only install apps that are in the app store. Why should everyone else be restricted from doing whatever they want with their phones?
- Eddy_Viscosity2 4y ago> If you direct download it and it's malicious, well, that's your own problem. How about if we had laws that also made it a problem for the person/company who developed it too? Seems like they have some responsibility too.
- saagarjha 4y ago> iOS version never have these issues. This is not true. It’s much rarer but there’s nothing special about iOS in this regard when it comes to abusing 0-days.
- secondcoming 4y agoIt’s absurd that Android even allows apps access to the APIs that enable this sort of thing. It was pretty much impossible on Symbian OS.
- ignoramous 4y agoex-AOSP dev here > Hiding their app icon from launcher... Well, apps that don't have a declared launchable (homescreen) UI don't get these icons. Granted it has been abused by spyware apps to "hide" from unsuspecting users, but you'll find these in Android's Settings app. > One app would install other apps from the same company in the background without user consent. I doubt installation without user consent is possible at all in Android 9+. Afaik, only Google PlayStore (or other OEM embedded stores) have permissions to silent install, as it were. And I haven't seen anyone allege PlayStore silently installing apps. See also: https://www.xda-developers.com/android-14-background-install-control/ https://www.xda-developers.com/android-14-background-install... > Multiple apps will wake each other so they always stay in the background and become impossible to kill One can Force Stop an app to make sure no component (service, activity, recievers, or resolvers) can run in the background, until the user explicitly starts the app process again via the Launcher. Android also limits background processes, tracks per-app CPU and memory use to limit it, and "caches" processes aggresively if need be (puts their threads to sleep so they aren't executing anything but could be resumed quickly). > Requesting every permission under the sun and transmit as much info to the mothership as possible The Trust on First Use model has been taken to the cleaners by Android apps hell bent on tracking their users. Starting Android 12 though, Android auto removes permissions granted from installed apps user hasn't interacted with. > Secretly turning on the camera and film their users Android 13+ has camera and mic indicators. And for earlier versions, even if inconvenient for end users to setup, there exist open source apps that continuously log cam or mic access from other apps. None of this is perfect, mind you; but I wanted to point out that Android has been responding to growing privacy concerns: https://security.googleblog.com/2022/12/app-defense-alliance-expansion.html?m=1 https://security.googleblog.com/2022/12/app-defense-alliance...
- nopinsight 4y ago>> Secretly turning on the camera and film their users > Android 13+ has camera and mic indicators. Indicators are a good step, but wouldn't it be better to disallow apps from turning on the camera without the user's explicit consent altogether?
- 4y ago
- 2h 4y ago> I am really really afraid that by allowing third party app stores and sideloading please stop it. I do not want my devices to become a toaster. I am a computer programmer. I would like the ability to write programs for my own personal use, and run those on my own devices THAT I PAID FOR. please stop pushing some narrative that will take this ability away from me.
- killjoywashere 4y ago[flagged]
- 2h 4y agoI like how me wanting to run software that I wrote, on a device that I bought, suddenly makes me pro China. stop projecting.
- cubefox 4y ago> So even though I am not a fan of the Apple monopoly, I am really really afraid that by allowing third party app stores and sideloading, the western apps will race to the bottom and become just like this. This did not happen with Windows, so why would it happen with Android, that is much more restrictive in terms of permissions?
- outworlder 4y agoHave we already forgotten all those machines with so many Internet Explorer toolbars that would take up half the screen? All the malware ?
- cubefox 4y agoYes. This all went away without app stores.