Viking Horde: A New Type of Android Malware on Google Play
blog.checkpoint.com
blog.checkpoint.com
Similar with updates, I've been hurt couple of times by keeping apps updated, so now it happens only when it stops working completely.
I also do the same regarding updates. More than once I've found that functionality is crippled in a newer version or it's simply is less usable so now I also avoid updating unless there's a feature I really want or as you say, it stops working altogether.
Example is shazam. Used to be really simple. Big button, listen and get the name and thats about it. Now its loaded with buy now links, the big listen button is gone, wants you to register, takes too long to set up and so on.
Now most of what I see are free-to-play apps with like 100 million downloads and 4-5 stars, but none of the stuff I've downloaded in that criteria has managed to hold my interest for longer than 10-20 minutes.
I've gotten a lot more enjoyment out of a few humble mobile bundles than just about anything in the store.
Also: http://www.theverge.com/2015/3/17/8103593/golden-krishna-bes...
I don't know, how often do we hear about this kind of malware on Google Play?
Not nearly as often as I would have thought a few years back, especially given that Google does zero reviews of what gets uploaded.
I think their current system is working reasonably well, but obviously, it's not perfect.
[1] http://static.googleusercontent.com/media/source.android.com...
"Here's a list of thirty privileges this app needs to run. Do you approve?"
Given you just downloaded it, why wouldn't you?
After all, every other app requires a huge set of privileges to run, too.
Do you see the problem? :)
I find it perfectly effective: If you deny an app a permission, it doesn't get any information for that permission.
> some apps (like the Hue app) just crash if you deny them anything
That sounds like the app is badly implemented, really.
> Why didn't Android add the option to provide blank data to apps?
Because it's a completely new API and it shouldn't have to, apps should check the return code to see if the permission was denied or not.
Are you talking about denying permissions to apps that don't support the new-style permissions natively, perhaps?
Yeah, it really is badly implemented, but the blame for that lies in part with Android for making it so easy to write apps that break. It would have been perfectly easy to write the code so that it returned "GPS signal lost" for location, "no contacts" for contacts, "SD card is empty" for storage, "no phone call in progress" for phone, etc. In fact, modders of Android have been doing that kind of thing for years. It's truly astonishing that Google got this so wrong when there are so many better examples.
Because it's a completely new API and it shouldn't have to, apps should check the return code to see if the permission was denied or not.
Sometimes an app should believe the permission was granted when it actually wasn't, because of the aforementioned bad (or even malicious) apps. Maybe you have to use a particular app in order to control the lights in your house, or your car, or to chat with someone who refuses to use anything that doesn't have a permission list a mile long. Privacy controls are useless if the true control is still in the hands of the app.
Are you talking about denying permissions to apps that don't support the new-style permissions natively, perhaps?
No, I'm not, but clearly old-style permissions could have been reimplemented as forwarding calls to a new-style API that returned blank data if the user chose blank data for that app's permission, just as privacy mods for rooted phones have already done.
Ghe second solution is aimed at apps designed for older Android versions, if the user denies access, the app gets empty data back (e.g. Empty contact lists, no GPS satellite etc).
An app designed for Android 6 should handle negative feedback (disable functions, show a warning/explanation or something else), it shouldn't break. If you don't want to handle this, design for Android <6 and let the system take care of it. But it should be a difference between permission not granted and no data available, apps should handle these issues differently. If I were to deny my navigation app access to my location, it should ask me to revoke this decision and not warn me about not finding GPS satellites (which would make me run around with my phone hold up in the air hoping to get a GPS fix).
That kind of notification should be done by the permission system itself, perhaps as an icon in the status bar.
> No, I'm not, but clearly old-style permissions could have been reimplemented as forwarding calls to a new-style API that returned blank data if the user chose blank data for that app's permission, just as privacy mods for rooted phones have already done.
Not only is this clearly possible, and a good idea, but it is also pretty much exactly how Android implements it. If you don't use the new API, you'll just get blank data.
I've never used the app you're talking about, but it sounds buggy to me.
There's some extra functionality for users who have rooted their phone.
The best advice I can offer is to stay the hell away from Google Play. That trash, and the rest of their services, are the first things I strip from my phones. Instead, use properly licensed open source software, from the F-Droid repository (or similar). If it's not a proprietary app (Twitter/Facebook/Snapchat/etc.), there's likely a FOSS version that's better than anything on the Play store. Flashlight apps don't need to access your contact list, or read your call logs, or have an open port in your firewall. The damned bastards.
On F-Droid you'll find (for your rooted phone):
AFWall+, an IPTables firewall GUI. Very nice looking and intuitive. Don't think I've ever used a firewall so easy to configure.
Autostart, an app that prevents garbage from auto-starting. A bunch of junkware usually loads up when you activate things like WiFi and GPS, or reboot the phone. Autostart can be configured to block the bloat, and in turn, make your phone run much more efficiently.
Disable Manager, to disable unsavory services (Play, Facebook, etc.). If you're worried that deleting things will break the phone, this app will put your mind at ease, because you can use it to turn things off and on, like a switch, instead of outright deleting.
AdAway, generic name, but it does what it's supposed to; system-wide ad blocking. It's FOSS, under GPL. If you avoid the Play store, configure your firewall, and use an ad blocker addon on Firefox, you might not even need an app like this one.
There's a bunch of other cool, trustworthy, stuff on F-Droid that's not going to abuse your phone. When it comes down to it, if you stick with FOSS, you won't need to root the phone; a non-root firewall will suffice.
Apologies for the rant, this was supposed to be a short reply, I don't know what happened.
Here are the apps mentioned: - Viking Jump - Parrot Copter - Wifi Plus - Memory Booster - Simple 2048
It's possible you are still compromised from another app. Looks like next steps are getting a tool out to check that.
(With all of Google's talent and machine learning and AI, it can't detect this junk? please...)
All the more reason to avoid hardware from this company.
I'm pretty sure that this is not what Google wants although they might -as you correctly point out- profit from it in the first place. But the negative publicity in combination with possibly loosing companies buying ad space on Google because of fake clicks can not be worth it. Google is too big to profit from a scam like this in the long-term.
Still, one has to wonder how one arm of the company can be so successful at creating artificial intelligence (smart cars, tensor flow, deep dream, just OTOH), while the other - its primary revenue driver, at that - manages to overlook things that are so simple.
Or am I really expecting it to be much more difficult than simple heuristics like "game + SMS privileges = fishy"?