8 ms·
The newest threat on the official Android market
- cgtyoder 13y agoLooks like it's gone from Google Play.
- Apocryphon 13y agoI thought KitKat was supposed to block apps from automatically sending SMS messages to premium numbers? This is a nasty piece of malware, but premium SMS scam apps are nothing new to Android. So the article playing up the danger of this random, seemingly single-market focused malware (Hispanophone vs. global) isn't particularly scary.
- ben1040 13y ago>I thought KitKat was supposed to block apps from automatically sending SMS messages to premium numbers? From the analysis posted, it's trying to bypass that by not sending an SMS to a premium number. It's sending the phone number to a website, and whatever it is that is running on that website is subscribing the user to a premium service.
- hansjorg 13y agoIt probably sends a non-premium message too then. There must be some kind of check in the network so that it's not possible to charge someone just by knowing their number.
- jdangu 13y agoNo check, Premium SMS technically doesn't require any opt-in. Charging on SMS receipt is called "MT billing" [1] and this is how PSMS works in most countries including the US. PSMS is heavily regulated but the nature of the business today makes it unattractive for anything but fraud. [1] https://en.wikipedia.org/wiki/Reverse_SMS_billing https://en.wikipedia.org/wiki/Reverse_SMS_billing
- hansjorg 13y agoThat's an eye opener. Should be trivial to enforce this on a network level (requiring user initiation), but I guess that is not something network providers would just implement on their own. I wonder why the app requires SMS write permissions though. App stores like Google Play should reward apps which require the least amount of permissions by pushing them higher in the search results (and publicize that fact).
- objclxt 13y agoYeah, it reverse bills the SMS. Android can only block your device from sending premium rate SMS, not receiving them (how could it? It's up to your network operator to handle that side of things). The original idea with reverse-billing was that users could subscribe to services such as weather updates, which would automatically send a message once a day/week, and the user be charged upon receipt. The problem with reverse billing is that it's clearly open to substantial abuse.
- fasteo 13y agoIt is a Spanish premium subscription number. To subscribe you need to opt-in, either by web (getting a PIN code you need to enter to confirm the subscription) or by SMS (You need to confirm by replying to a free message from the short code). I guess this app is going through SMS opt-in, sending the reply behind the scenes.
- magic_haze 13y agoXPrivacy should really come installed by default with Android: the new versions are really quite good (especially with the cloudsourcing and on-demand bits) and really highlight how atrocious most apps are with your personal data. And it is a hell of a lot more effective than relying on companies like Avast to detect and remove bad actors from the market. I've lost track of the number of times random apps (most of whom are just shells around a website) ask permissions for my full phone number, Google and Facebook accounts, contact info etc. for no reason at all. At this point, I'm scared of using Android without the module. (not that ios or windows are any better)
- jyrkesh 13y agoYeah, I've been holding back on rooting my Nexus 5 for a while just because I don't want to deal with the full wipe, but this convinced me. Obviously this article is somewhat AV FUD (just don't download the sketchy Spanish night vision app with WRITE_SMS permissions), but it's time I got my permissions in check.
- magic_haze 13y agoThe entire store experience is the opposite of what Eric Lippert calls the Pit of Success: literally no one involved in the process is incentivized to protect your data. Developers ask for all the permissions they can get away with because users get confused by multiple warnings, users blindly click accept on everything because they've learnt they can't use the app without that, Google is blindly complicit in all this because for some reason, they think everyone is as interested in/capable of protecting user data as they are... (Or they just don't care.)
- malandrew 13y agoTo be honest, the default approach should be making app developers only be allowed to ask for one permission at a time. This would provide a constraint where the developer would ask for permissions they need only when a user tries out a feature in the app that relies on that one permission. Accessing the address book is another area where permissions could be made much better. No app really needs access to my entire address book. They just need to launch the built in address book and only get the information they need for the one or more contacts you choose from your address book.
- amimetic 13y agoBear in mind it is Avast writing this post (not exactly my favourite company at the moment, incorrectly reporting a trojan to a few users in one of my Apps), so the alarmist perspective is motivated by their business. If the worst they can report on is an obscure and rather obviously dodgy looking App no longer on Google Play then there isn't much for us to worry about.
- rjzzleep 13y agoat this point i'd like to recommend cyanogenmod with privacy guard again [1] or openpdroid [2], or both. the cool thing about openpdroid is that you can spoof location requests too. also, i don't think any other privacy app allows you to block requests to sim and imei info [1] http://www.androidcentral.com/cyanogenmod-updating-privacy-guard-20-new-features-coming-cm102 http://www.androidcentral.com/cyanogenmod-updating-privacy-g... [2] http://www.xda-developers.com/android/openpdroid-brings-an-open-source-privacy-solution/ http://www.xda-developers.com/android/openpdroid-brings-an-o...
- drdaeman 13y agoI believe XPrivacy[1] looks more promising than OpenPDroid. First of all Xposed Framework feels easier to integrate - no need to mess with full-fledged ROM embedding, just light patch to the Dalvik and reboot. And the things I really fancy about XPrivacy is that current versions have learning mode (like `su` GUI prompts, configurable to automatically deny or allow after a timeout) and yet-underdeveloped but very promising argument-level permission controls (i.e. allows WebView's loadUrl for one URI, but not another). [1]: http://forum.xda-developers.com/showthread.php?t=2320783 http://forum.xda-developers.com/showthread.php?t=2320783
- deleted 13y ago[deleted]
- devx 13y agoI hope CyanogenMod (but other ROMs are welcome to do it, too) keeps focusing on the privacy and security aspect.
- georgemcbay 13y agoGiven how shady the whole premium SMS/premium number business is to begin with, it should be made legally simple to refuse all payment on charges to them. eg. Say you notice you suddenly owe $100 on your phone bill due to a phone app causing charges to your bill (or even just because you gullibly fell for a social engineering attack), you should be able to just refuse to pay with no repercussions other than that the premium provider will be sent a notification that you refused to pay and then may block you via caller id from future use of the service. I doubt this will ever happen since politicians generally don't give a rat's ass about consumers anymore, but it would be nice.
- fungi 13y agoin aus > Require mobile carriers to provide the option of barring premium SMS and MMS services on all plans from 1 July 2010. This gives consumers a choice to block such services; http://www.acma.gov.au/theACMA/premium-phone-services-australia-bill-shock-i-acma http://www.acma.gov.au/theACMA/premium-phone-services-austra... My SIM came pre-blocked which was nice.
- biafra 13y agoWhen I asked O2 Germany to do this, they told me they would have to block mobile internet as well.
- cmelbye 13y agoI'm surprised they went to those measures to get the user's phone number, it seems like there would be much simpler and more inconspicuous ways to do so on Android.
- jmnicolas 13y agoIt's a long time since I didn't touch Java, I don't get the instruction "break label217;". Is it equivalent to a "goto label217" ? (shock and horror !!!)