Popular Google Play store apps are abusing permissions and committing ad fraud
buzzfeednews.com
buzzfeednews.com
https://www.reddit.com/r/miband/comments/8eqtve/why_did_mifi...
Would it be possible for me to reproduce what you have found? and if so, how can I do so?
Sure, we talk about the problem a lot. But we need to take action. It seems every big corporation are abusing the trust we give them in some form or another.
Please, for the love of God, can anybody prove me wrong. Are there any companies than don't abuse our trust?
It makes a lot of sense to keep your customers happy in the long run (bottom line and stock value).
I guess you need to look in the direction of GNU/Linux. For example, company https://puri.sm. They have nice laptops and nice Debian-based OS and they are working on the phone (soon to be released).
If a murderer knocks on your door, informs you that if you let them in they're going to brutally murder you, but you choose to ignore that because they brought you free stuff, you don't get to complain about being murdered later.
Actually, you do; murder is illegal even if you were informed in advance. The same should be with the ad industry. See GDPR.
A terms of service is not a free pass to do whatever the fuck you want. Just because I agreed to Apple's terms of service doesn't mean they can turn me into a human centiPad, even if it says so in the small print.
They never say that. They just do it.
Anyway, you're right, and so are the other people pointing out quite correctly that murder is still illegal and an agreement doesn't magically give them a right to kill me. But you know what isn't illegal? A company selling your data that you gave to them and agreed to allow them to sell in exchange for providing a service. Yes, I know there are some weak protection rules out there, and things like the GDPR exist in some countries. IANAL, but an app using permissions that you gave it, to do things it says it's going to do in its description and/or TOS is not illegal in most countries. If it was, we'd not be in the privacy clusterfuck that we're in today.
The point is that trust has nothing to do with it. If anything, these companies tell you exactly what they're going to do (and if they don't, that's another problem altogether which I'm not getting into here) and you can trust that they will do what they said they're going to do to make as much money from you as they can. Treating companies like living, empathetic human beings worthy of your trust to "be nice and give you a product for free without selling your data you agreed to allow them to sell" is silly.
a) The device's App-Data settings. I keep most boxes unchecked. I don't understand why CamScanner (legit super useful app) needs internet connection when I just email myself all the scans, and not using the cloud-options. Only Email needs internet connection on that scenario.
b) NoRoot Firewall, I either recognize the IP or the domain name, or I check on ipaddress.com the IP, and then I end up global-blocking the whole block of that IP and be done with it.
In this world you have to go with Security in mind. Default state is block-everything, and only allow the truly needed/useful (to me, not the app developer) connections to go through.
Also you are assuming people have due diligence to actually care or understand which permissions an app is requesting and to actually stop long enough to consider the implications. Consider that most of the world is technologically illiterate, and pop-ups will probably at most be a very mild annoyance for end-users who blindly press ALLOW in order to open the app because it has kittens and rainbows.
I own and operate a fairly popular audio streaming platform, and I've had to deal with numerous instances of unscrupulous app developers who steal API keys from our licensed developers, release apps wrapped in tons of ads, and are able to remain totally anonymous by:
1) Setting up what is presumably a fictitious company
2) Privacy policy link that directs to pastebin
3) Email address for support where nobody responds
These apps steal tens of thousands of dollars of ad revenue from my business monthly, and I have absolutely zero recourse. Filing DCMA and other complaints with Google typically goes into a black hole, and when they do respond or address the issue its typically "we don't see the need to take any action here" - presumably because these apps are generating enough revenue for AdMob and the Play Store that Google has zero incentive to take action.
How often does this happen in the Apple App Store, almost never.
It's absolutely infuriating.
The problem is Google has no incentive to address these issues, because they prioritize their own platform growth revenue over user and partner experience.
With all the frustration one can have with the Apple App Store, including huge wait times for new releases, arbitrary reasonings for declining apps etc, it's almost worth it vs the wild-west of the Google Play Store.
Avoiding ads is not stealing. Neither is wrapping someone else's content in ads.
What the hell are you talking about? If I take Office 2016, create custom launcher which will just pop ads here and there, offer it to companies, I can't possibly claim this as legal business anywhere where copyright law can be upheld
i want no part of it. when a phone maker comes to the market without this locked down model i will buy it, and if windows goes this route i will drop it for linux.
and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter.
Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware.
The locked in store model is better than than what we had before for the general consumer (at least iOS's, unequivocally is, IMO). The App Store might be bad for developers, but it's way better for consumers.
By isolating applications and introducing permissions, malware that can steal or encrypt user data isn't possible even for people installing those pirated APKs.
The wasted bandwidth would be made clear by the OS to the user too, so it'd be trivial to identify if it was a significant consumer.
I doubt user data being protected by these mechanisms helped people to guard their data.
Check out history of Java sandbox with its numerous vulnerabilities. I have no reasons to expect anything different from built-in sandboxes. It's like relying on unix user permissions and allow to run anything under untrusted user. Works in theory, but you'll be owned pretty soon, because local root escalation vulnerabilities are not that rare.
In those days the only sandbox I would trust is JavaScript one. It's battle tested.
You cannot ask for permission to bypass sandbox restrictions on Android. You need root access, which means physical access to do things like unlock the bootloader or an exploit.
iOS sandbox seems slightly weaker here due to the use of hidden/private functions to protect certain things, sideloaded apps would likely be a bigger risk on iOS than Android at the moment, but that's not something unresolvable.
In any case, the things you're discussing aren't really so problematic - isolation systems are only getting better, OS level ones are improving every day. We could easily have sandboxes at this level just as secure as the javascript ones.
Currently iOS users lack this option so for them the only way out is to change platform.
Yes, this is free software. Being less susceptible to these problems has been one of the stated advantages of using such for a long time. Alternative 'stores' carrying 'pirated' non-free software do not have this advantage and can easily turn into dark places so the solution does not lie there.
Will people choose a 'boring' free software 'store' over a 'cool pirate store' (Arrrrr!)? Some will, some won't. Those who will will end up being mostly silent as the thing just works. Those who won't will be susceptible to the whims of those who put up those 'stores' and are likely to come home with a bit more than they asked for.
Some 'stores' will get a good reputation along the lines of that of F-Droid, some will get the reputation of being the place to go to get the latest craze but also the latest infection. Users will start making conscious decisions based on those reputations, just like they already do elsewhere.
Will opening up closed platforms like iOS for third-party software repositories get rid of these problems? No, it won't, it will even raise the average level of problematic software on that platform. The difference between closed systems and more open ones is not that the closed ones are inferior, it is that they limit the user's choice to get something which is better as well as worse than what the walled garden offers. In this context better can mean software which does not come with tracking, analytics, profiling and other such privacy-invading nonsense. I can get the source code and build it myself, I can host my own repository, only time limits where I can go. This is not true for the Google Play Store or the Apple Appstore, nor is it true for the Amazon equivalent or any of those Chinese alternatives. That is why I chose to use something like F-Droid.
By the way, there is nothing keeping e.g. Facebook or Twitter from releasing a free software version of their apps. Their value - and most of their profiling proficiency - lies in their platforms, not in the apps used to access them. They might lose any additional venues for leaching the user of data but they would gain some believability when they state that they're not up to no good. Of course there are plenty of alternative apps for these services so they don't really need to but they could if they wanted to.
Really? Is there a huge market of mainstream consumer Linux software which I've missed in the past 3 decades of using it?
The answer is, of course, no. Linux distributions have mostly been used by developers and other IT people and there's never been the equivalent of the mainstream mobile app ecosystem used by people who are asked to make critical security decisions which they don't know how to answer. If there was an equivalent, there would be the same sleazy sites pushing free porn, games, taking successful apps and repackaging them, etc. that we see in the mobile/Windows desktop world, and normal people would routinely be socially-engineered to get access to free stuff, just as Linux users have for years been fooled into running binaries or installing packages. This isn't more widespread because there's not much money in it but if that were to change it would immediately require the same kind of hardening which every other consumer OS has had to make.
Also, where are those Linux users [who] have for years been fooled into running binaries or installing packages? The majority of Linux users get their software from repositories maintained by whichever distribution they use. This fact is one of the reasons why Linux users are far less likely to install 'random' software. It is that aspect of Linux distributions which 'stores' like F-Droid bring to Android.
Last, what kind of 'hardening' do you deem every other consumer OS has had to make which Linux distributions have yet to accomplish? I'd go so far as saying that the likes of Windows and MacOS are playing catch-up here in finally getting around to implementing a sane repository infrastructure from which users can install and update software instead of having them hunting around the web for some SETUP.EXE to download and click on - which then proceeds to install not only the requested program but also a host of toolbars and 'shopping assistants'.
That both Apple as well as Microsoft took one step further in making these software repositories single-source to the detriment of their user's freedom of choice is what started this discussion in the first place.
Part of one of the antitrust suits against Google was that it required Play Services to be preinstalled by manufacturers on Android phones before the Play Store could be preinstalled - but the latter needs the former to work.
There are many other stores where the chance of being exposed to these shenanigans is close to 1. Think of the article recently about super-shady app stores for iOS that misused enterprise certificates to sideload apps [0].
If alternate app stores were to be allowed on iOS, all that would happen is a great proliferation of these scumware stores, full of knockoffs, fakes and outright malware.
It's going to be almost impossible for a lot of people to distinguish between legit good quality, legit crap quality and non-legit harmful app stores, resulting in waves of malware and privacy theft that will make the old Windows XP days look like a panacea.
While it has its problems, the curated nature of iOS' App Store is a distinct positive for users.
[0] https://www.theverge.com/2019/2/20/18232583/apple-ios-develo...
Android apps run the risk of becoming facebook apps. A rising platform that had a lot going for it. Little by little more restrictions pushed many away and turned into what it is today.
This way almost everyone is happy because most apps don't really require anything other than internet, camera and GPS which can be denied by the user.
https://developer.mozilla.org/en-US/docs/Web/API/Geolocation
> use GPS like an app can
that means high resolution location, background updates, geofencing, etc ...
For example, for a smart home app asking 'precise location constantly even when not using the app' is sufficient to perform geofencing - but asking for a more limited 'know when you arrive home' is much more likely to get user approval.
And for Linux or Windows this is still true.
macOS = useful; iOS = nope
They seem to be able to find epic's fortnite just fine. What more do you want?
Because even good apps ask for all things, It cannot be used as a filter to determin bad apps.
Company makes a product and provides samples to the distributors buyers who then run it through the wringer. If it's crap then they don't order any. If it's 'good' then they'll market it to the retail buyers who place orders if they think they can sell it (and it's not crap).
None of that exists in the 'app market'. If it did then you'd submit an app to a distributor who would notice you're sending private user data to a Chinese website and they'll not only not market it, they'll never touch any of your stuff again.
The downside of that system is 99.99% of apps out there would never get installed on a phone in the wild.
What's really needed is the abolishment of ad driven revenue model. If the user derives value from the app, they ought to pay for it. This way, the app developer is incentivized to make the app better for the consumer, rather than attempt to generate revenue thru illicit/anti-user means.
> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter.
I don't totally understand what you want. You say you want a phone (presumably OS?) that does not require an app store then totally dismiss a very popular operating system that has exactly that feature. Who cares if a large segment of Android users don't side load apps, that does nothing to prevent you from doing it.
I've been using Android without Google Play services for a few months and everything works fine. My bank apps work, the few social media apps I use work, WhatsApp/Signal work, Bing/Cortana work, I could go on but I think you get the idea. Most of my apps have been side loaded (or downloaded via F-Droid).
There are other apps stores that have become relatively popular when pre-installed such as Amazon's and the various Chinese app stores.
What about maps? or Waze? Gmail?
The usability of OsmAnd~ will depend greatly on the area where it is to be used. It can use a host of map tile providers and/or vector maps, the detail level of these varies from very good to hardly any. I use it in Sweden where it generally works fine.
Waze -> ...
OsmAnd~ can be used for navigation but it does not offer live traffic updates.
Gmail -> my own mail server + K9 on Android
Gmail is more or less equivalent to a mail user agent, right? Mail is an internet standard which has been around for a while, long before Google was launched from a scruffy server under a desk. With a bit of luck mail - or some other open protocol like it - will be around when Google has gone the way of so many of its predecessors.
The list goes on:
Google Search -> a private Searx instance
Google Drive/Documents/etc -> Nextcloud on a private server
Google News (remember that?) -> News application on the above mentioned Nextcloud server, using either the web front or one of the Android apps available on F-Droid.
Youtube -> private Peertube instance on the already mentioned server
Facebook, Twitter, Snapchat, Instagram -> No need for such
Whatsapp -> private XMPP (ejabberd) server using Conversations Android client, using OMEMO encryption. Also using Telegram app from F-Droid.
Spotify et al -> Airsonic on that server I mentioned, feeding off my private collection and also serving internet radio stations (which it also sometimes uses to update the private collection). Using Dsub (from F-Droid) on Android, the web interface on PC's. The same collection can be reached through a host of MPD instances scattered about the place, these are controlled through MPDroid or M.A.L.P (both from F-Droid). There are also a few Kodi instances, controlled through Kore (from F-Droid).
The list goes on.
There is no Google-proprietary code on any of my Android devices yet they provide me with all these services.
How is Steam or Windows Store any different? How do you install apps/games on PC?
Not through Windows Store, that's for sure :)))
So I think it is the opposite: mobile OS provide better security than desktop OS.
Nope, it hasn't. It's very successful. It succeeded in lining the pockets of Apple and Google.
Doesn't that mean the multiple-stores and side-loading model has failed also? I'm not quite sure what your point is.
Some numbers from the presentation
- the "GPS icon" is visible for only 0.04% of actual accesses to location data
- of 42000 apps transmitting personal information, 21000 (50%) don't use TLS and send data unencrypted
- 1,325 apps that don't have location permission, actually obtain street-level location data and transmit it home
https://www.usenix.org/conference/enigma2019/presentation/eg...https://twitter.com/CraigSilverman/status/111862075124903936...
I bet Eastern Europe is also represented.
I don't think it's fair to say it's just a cheap labor thing.
Also, I suspect that those who concentrate on adding spyware and ad fraud, repackaging, etc are not the top talent.
> Kaltheuner, of Privacy International, told BuzzFeed News the policies are vague about how third parties, including potentially the Chinese government or other authorities, can gain access to the data being collected.
Google's privacy policy [1] is also very vague. Instead of clearly writing technical details, what data they collect and when, they just give a general description. Take this phrase, for example:
> We may also collect information about you from trusted partners, including marketing partners who provide us with information about potential customers of our business services, and security partners who provide us with information to protect against abuse.
Or this:
> We provide personal information to our affiliates and other trusted businesses or persons to process it for us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures.
Absolutely no details. I don't see how Google hiding its "partners" identity is different from Chinese companies hiding their identity.
The article says that Chinese company can share the data with their government (without any proofs), but doesn't Google share the data too when required by the law?
Also, there is an interesting note hidden in Chrome's policy [2]:
> Chrome won't allow a site to access your location without your permission; however, on mobile devices, Chrome automatically shares your location with your default search engine if the Chrome app has permission to access your location and you haven’t blocked geolocation for the associated web site.
So instead of singling out a Chinese company, we should pay attention to all of the mobile apps and their practices.
Regarding excessive permissions, I think Google could improve the situation by promoting apps with few required permissions in the search results and making permission list more noticeable. For example, currently, if you browse Google Play, permission list is hidden behind a tiny link.
Of course these garbage apps make it through somehow. My favorite is an SNES emulator that's full of ROMs. Clearly a copyright violation, but somehow made it through state-of-the-art AI...
I'd actually be fine with it letting stuff like that through, but filter out actual malicious to the user apps.
Of course, there's nothing in this approach financially for the maintaining company, so this was not going to happen.
Yes.
IMHO that place is sideload as system app when you first install the OS. Which was my solution to the YALP issue.
(YALP store is not on my actual phone - that only has F-Droid)
- battery booster - phone cleaner - anti virus - note taking app - file manager - ···
For risk management from getting banned, those adware companies, will usually register multiple accounts, with offshore address in Hong Kong or Singapore.
This is a good starting move by Google, but not enough still. We still see companies like Cheetah mobile, Du group being active in Google Play Store.
Those companies (and their associated accounts which distributes malware) who caught red-handed, should be banned permanently.
https://news.ycombinator.com/item?id=19278936
It might actually be beneficial for privacy, since trying to "poison the well" of tracking data gets detected by the adtech companies and they'll likely start ignoring you. In that sense, affecting their bottom line is the only way to make advertisers leave you alone...
Creepy and deceitful.
My guess is that this kind of add-on will make your traffic stand out like a sore thumb too so while some companies will happily log that you're into every ad they throw at you, most won't bill for your fake clicks and simply have a very easy time tracking the pages you visit across the web. Where you go says a lot more about you than any ad you click on while you are there.
If enough people use something like this it would force shitty low effort ad platforms to implement some basic fraud detection, but forcing minor players into investing in their services isn't exactly screwing anyone over.
I do object to collecting and sending my personal information, but I feel they just mixed it, as that probably relates to more then just these Chinese apps.
And I really don't like the fact that it seems that Google only cares about abusing the users, and breaches of trust and privacy when it hurts the advertisers (and themselves), and not when the normal user gets hurt.
Not surprising though, but still annoying.
In addition, I don't see the companies paying for ads getting hurt the most, in the end, if they would recognize that these types of ads are inefficient, they just wouldn't use it as much (they would use other outlets) or lower how much the value (and pay) for it. Which would help me (by getting rid of something I dislike), and at the same time hurt those that maintain and support that part of the business in the adtech world (another plus for me).
It's absurd.
Or make it so that no one has anything against you ever. Because people have been sued already for uploading their contacts' information to WhatsApp without permission.
I really don't want to encourage you to use WhatsApp, but one possible solution would be to use this app: https://f-droid.org/app/opencontacts.open.com.opencontacts
It's a separate store for your contacts, so that you don't have to use the Android contacts implementation where every app and their mum wants access to.
However, mind that WhatsApp is not going to be particularly user-friendly whether you do this or block access to the contacts in newer Android versions. It won't display people's names until they've chatted to you (and then only in a shitty secondary GUI), so you will often have to guess from their picture who they might be.
And worse still, there's no way to initiate a chat from within WhatsApp to someone who's not in your contacts.
Thankfully, there's an app for that nowadays, too: https://f-droid.org/app/io.github.subhamtyagi.openinwhatsapp
The lawsuit is not just for this matter, it's rather because users were forced to consent to the privacy policy in order to continue using the services, which is very hard to justify under the GDPR, but I presume/hope, they will also look into what WhatsApp wanted users to consent to and how they presented it (89 screens full of legalese).
In theory, there is some clause in WhatsApp's terms of service which requires every user to get that written permission from all their contacts that I joked about.
One actual thing that WhatsApp will be able to cling to, is that they do have a 'legitimate interest'. Without uploading these contacts, their service would not anymore grow at even just half the pace.
Bullshit, Google. Bullshit. Only a very small proportion of the apps on Play ask only for the permissions that are needed to perform their task, and Internet access is not a deniable permission, leaving a nice little back door for them to siphon off your data. The example of the flashlight app is not an edge case, it's the norm. Google does not care because they'd rather earn more ad revenue than have quality apps, and the number of apps with the ability to seriously spy on you is staggering.
A useful automated tool for this is 'Exodus' it will scan APKs for trackers and permissions and provide a web report.
Here is a report for one of the apps mentioned. https://reports.exodus-privacy.eu.org/en/reports/15627/
Why is that? I can't even imagine what's going on at the meetings leading up to implementing ad fraud in what I presume is a normal company otherwise and not a bunch of gangsters. Is it morally OK to do this in China for some reason?
> When Deng Xiaoping implemented the Reform and Opening Up policy in 1978, capitalism was added to the mix of the survivalist culture; in order to get rich, you had to compete fiercely, fend for yourself and take care of your own with no regard for rules. This would also explain the rampant corruption among government officials, who use their position to amass wealth for themselves and their family. And nowadays, a third phenomenon has also added itself to the dangerous cocktail of selfishness and competition: the digital age. Many Chinese young people spend the majority of their days glued to WeChat, or taking selfies everywhere, or shopping at the ubiquitous malls around the country. This “me” culture is certainly not unique to China; indeed, we see the same thing happening to the youth in New York to Buenos Aires to London to Brussels to Moscow. But in China it exacerbates the already self-centeredness brought on by the cruelty of the cultural revolution and the competitiveness of capitalism with Chinese characteristics.
> In other words, China doesn’t just lack common etiquette and basic manners; it lacks a moral compass altogether.
https://thediplomat.com/2016/09/chinas-quest-for-a-moral-com...
What's wrong with this guy? Does he not understand what investigating means? God forbid Google actually investigates claims of malfeasance.
That's no longer a reliable way of trusting the credibility. There's been many Pulitzer Prize news reporting which have come out to be completely false.
Google confirmed that these apps were committing ad fraud, and told me that ad fraud is against Play store policy. Yet the company was going to keep the apps in the store. That didn't make sense to me. Fortunately, they reversed their position.
(Also, in case it matters, I didn't submit my story here. But I always appreciate the interesting threads on my ad fraud stories.)
And when I busted a large ad fraud scheme of dozens of apps: https://www.buzzfeednews.com/article/craigsilverman/how-a-ma...
In all cases Google basically said it takes action against specific apps found violating policy. It seems unwilling to take action against a developer as a whole and ban them. I would also add that I suspect the Play store is not equipped to enforce a ban. People can easily create a newco and get back into the store. This is definitely a much larger issue. So I think that among other things these stories show that you can be a clear bad actor and still do business in the Play store.
Yet, those apps are being ranked higher than other honest apps, which are doing business in honest way.
These day, Google is not willing to do the right thing, unless being pressured by press media, or EU.
Really? Guess it can be easily done with new virtual firm and new contact data.
DU Group is an affiliate of Baidu, which has been using ads like "Click a button to boost your signal 5X stronger" to harvest users. It's common and unfettered in China, since they are all watchdogs of the party.
https://www.macrumors.com/2018/09/07/adware-doctor-stealing-...
https://www.forbes.com/sites/bernardmarr/2015/10/20/data-thi...