Barcode scanner app on Google Play infects 10M users with one update
blog.malwarebytes.com
blog.malwarebytes.com
This is a legit open source app that's been recently flooded by 1-star reviews claiming that the app contains malware, probably in order to get users to switch to the other apps. The funny thing is this app has not been updated since 2019 on the Play Store, so those reviews are clearly bogus.
It takes a special kind of scum to slander an open source project in order to push malware.
[1]: https://play.google.com/store/apps/details?id=com.google.zxi...
https://f-droid.org/en/packages/com.google.zxing.client.andr...
I mean, I could very well make an open source app and then load some malware in the apk in addition to the well behaved thing... Are they immune from this attack?
Every significant review system is being gamed to the point of being unusable, and yet stories about not being able to trust them keep being reported as if this were somehow noteworthy. For every one of these stories that rises to a thread on HN, how many other small time vendors are getting screwed by someone who is willing to pay a room full of people in some 3rd-world country to debase their competitor's online presence?
But it's still not stabilized, society has not yet found out how to deal with all this.
It's like when there were no speed limits for cars or standard signage. There was more freedom but it was way more dangerous and unpredictable and also as a result, not yet as useful as it could be.
It's not necessarily anybody's fault. A company like Google maybe sees itself as a company but it's way past that. It really provides quite essential platforms for people, families, cities, you name it. And also the platform for content creators and developers and businesses. Many of these don't have a proper contract with the platform. It doesn't scale to have lawyers to be involved in every point to point dealing either.
My assumption is that there is going to be maturation of these platforms, common rules and terms. Governments and WTO could be involved.
https://play.google.com/store/apps/details?id=com.srowen.bs....
One solution might be to only publish reviews/ratings from accounts with a minimum spend threshold and unique active payment details. This would effectively price out the scammers.
The sheer scale of situations where the top review is negative describes something that ... is not a bug, is actually supposed to be that way, is how the dang app works by design for good reason ... is bonkers.
It seems like reviews are driven by people who don't know, and respond reviews by to people who don't know who describe what sounds like fundamentally broken things... so they give it a thumbs up and they're both completely ignorant.
The volume of people who do know the app and would see / write a review seems like it is MUCH smaller.
I had a game app update recently. I went to update it (one of the few times I go directly to the play store app). There at the top is a review that described how they saw opposing players "just disappear" during the game and raged about that 'bug'. But it's not a bug the game has some fog of war and view distance type mechanic. It's entirely expected / appropriate.... but there it is the top review.
When people don't know why Google banned their 15 year accounts I wonder if it's not from innocent stuff like this.
Anybody complaining about app stores has forgotten how bad the alternatives are. And community-maintained repositories aren't a solution, that's just the app store model but on a smaller scale so it's less of a Target for bad actors. If ubuntu's universe repo had to suffer the same amount of abuse as the play store does, it would crumble in a day.
It is just 'protection'.
https://play.google.com/store/apps/details?id=com.robinhood....
TL;DR someone apparently cloned ZXing Barcode Scanner, added annoying ads, uploaded it to the Play Store with the same name. Soon enough the malicious clone got taken down. Legitimately pissed off people who installed the malicious clone are leaving angry reviews for the non-malicious original (presumably because the malicious clone is gone from the Play Store).
Don’t be naive, the majority will accept the money and gladly.
I believe that particularly makeshift applications such as e.g. barcode scanners are susceptible to this kind of overtake. Apps that offer what should have been offered by the OS vendor in the first place. Why should the app developer refuse the money if what their app offers will be incorporated in a next OS update by anyways? Why defend your mini-adapter-app in an ocean of mini-adapter-apps, with yours becoming so large just because of a random seed and path dependency?
This can have a big impact for end users. Imagine an authenticator app ending service to all their users in such a scheme and how you will be cut out from all your accounts by this. How many authenticator apps do you have to use in parallel to mitigate this risk of a single point of failure?
This is really it. The Google/Android team have already made the "Zebra" library that actually reads barcodes; why on earth do they not include this as a standard app. Instead we get this myriad of different barcode scanner apps with all sorts of harmful features. All the heavy lifting is done by the Android team anyway (the actual barcode scanning).
To make matters worse, scanning a barcode when you enter a store/cafe (to register your location), is now begin done everywhere in order to track potential covid19 spreaders. This forces anyone without an iPhone to install at least one of these potentially harmful apps.
I heard from a friend that iOS has TOTP and indeed a barcode scanner build in, same goes for cal/carddav. To be fair, my wife's Pocophone also comes up with a QR-code icon when the cam detects a QR code. And, FireFox for mobile has a QC code scanner build in (although since I now have to open a new tab for each new page and I end up with many many tabs of the same 4 websites I find myself using FF less and less).
Maybe the experience on Pixel Phones is better? GCam makes a lot of difference in many aspects.
Both a QR-capable camera and a flashlight in the notification bar are in all my Android phones, and they've been for a very long time. I know the Nexus One didn't include it, but those will have problems with modern TLS anyway.
The problem is likely elsewhere. It wouldn't surprise me if many of these users are tricked into installing these apps. It is quite popular for malware to disguise itself as a legitimate app as to not raise suspicion.
I don't like that example of utilitarian because it fights the youtube platform which does not want you downloading videos. Anything that sidesteps some sort of security fence or functionality is shady to begin with; even if you think it's fair use. Plus there's the whole copyright minefield.
Why are Google afraid to release a free non-harmful version of those popular apps. Is it to keep the illusion the app-store is a vibrant market place where tons of developers get rich? It just seems nuts to allow all those harmful apps (that does virtually nothing) to float among the top downloads.
QR scanning seems a little more complicated. FF for Android integrates a QR scanner, but chrome does not. Google's default camera also opens links, if you allow Google Lens.
They already did; these have both been built-in for years. The flashlight was added in Android 5.0 (https://www.androidauthority.com/android-5-0-lollipop-offici... I'm having a harder time figuring out when the barcode scanner was added, but my phone does it automatically in the camera app now.
(Disclosure: I work for Google, speaking only for myself)
Fear of anti-competition lawsuits and complaints. They're seeing what happens when Apple integrates stuff into iOS / OS X core that previously were third party provided, or the flak that Amazon gets for pushing AmazonBasics products.
Platform providers are also criticized when natively offering features that apps offer. You sort of can't win.
They have done more drastic things in the past. They have even removed apps entirely from Android phones due to very harmful features, and nobody cared when they heard about the horrid things these apps did in the background.
People doing low effort apps can only just whinge when the floor shifts under them. i have no sympathy - they just need to adapt and improve, and create new value to sell.
Our (New Zealand) Covid tracing app scans QR codes itself. What jurisdictions are requiring to scan an arbitrary QR code using random apps?
https://www.health.govt.nz/our-work/diseases-and-conditions/...
Imagine you are an app developer of a really simple app that takes a number and tells you if that number is in a valid phone format or not. You have a textbox, the user enters it, you do the checking and display the result. Easy. Now imagine you want to allow scanning a qr which contains a number, to do the checking afterwards. You need to either ask your users to use an external app to scan and then open yours, include all the qr related library inside yours, or use a special intent from a third party app (that the users need to have already installed).
First solution is slow and inconvenience for users, the second is what almost all apps do, but then the code logic is duplicated on all of them (with the increment in app size). The third option is the best, both for the developer and for the user, however there is no official qr service so in the end this is basically option 1.
I mean, you already have a service to get a picture, a file and a contact, among others (you don't need to include all the code, simply do a call to the respective intent and wait for the result) so why don't extend this with the qr too?
When we sit down they just say, "use your camera app to scan the barcode". It seemed to work for everyone at the table. Samsung, Pixel, and iPhone.
Also FM Radio, screen recorder and IR remote control.
what do you recon would be included?
- barcode scanner, - auth app, - calculator of some kind, - wifi management, dns/network/firewall management.
Android is like Forrest Gump's box of chocolates: you never quite know what you're going to get. And sometimes it's stale.
I think Apple have the right idea with app review on browser extensions for Safari.
/s
Chrome used to. You used to be able to just download the source code of an extension, point Chrome at it, and done you are.
Well, you still can. But Chrome will CONSTANTLY nag you about it and try to forget you added that extension using source, like it's some vile crime.
They removed it because of "security", which is a hilarious reason because it just made everything so much worse.
Would be a real shame if some software would block your ads because you didn't want to pay, wouldn't it?
You'd think if they were serious about privacy their privacy policy would just say "we spy on nothing and collect nothing and share with no one". 1password effectively has that privacy policy, lastpass does not.
That's to say:
(a) The time for a given barcode to be accurately detected varies considerably from app to app.
(b) And various apps have different detection capabilities with respect to one another (i.e.: the detection performance varies from app to app depending on the contrast across the barcode image, camera focus or lack thereof, etc.).
(c) For a given app, the detection capability for different types of barcode scans can vary considerably.
For that reason, I have five different QR scanners installed including SecScanQR that you've mentioned and the one with the same namesake as mentioned in this Malwarebytes article.
It seems there's a great deal of variability in the detection algorithms between apps. Unfortunately, from my experience I've found that some of the commercial apps have better detection performance than those on F-Droid—but granted that's only from my limited testing. Which app I use sometimes depends on other features, for instance, the fact that it has a better database or export ability, etc. is more important than the fact that it's insensitive in the detection department.
I wish someone with more knowledge and experience could give others and me the good oil on this. Reckon it'd save us considerable time experimenting.
I'm very happy with it
This right here is a big reason, apart from actual restorable backups, why I root my Android device. Sure it is not required nowadays but it does give a sense of control if thats the right word.
So many times I had to restore older copies of apps like Chess or even Yoga app. The older apps allowed a functionality (downloadable content for offline view) which was straightup removed in newer versions.
Same for Authenticator or any other app which does things locally.
Recently Google Authenticator app added the ability to move all codes to next phone by displaying multiple sequence of QR codes, but I coded a simple no internet just local storage & javascript app to to utilize otpauth:// protocol to eadily readd the codes on new phone https://spa.bydav.in/otp.html
Wouldn't that be anti-competitive? Similar situation when Microsoft was including IE on their system that made them a quasi monopolist with subpar product. I'd rather have Google having stricter rules when it comes to malware.
And why stop here? We should open the market for TCP implementations. The status quo is anti-competitive and stifles innovation!
_Re-open_. There were, indeed, commercial TCP/IP stacks available for various operating systems until the operating systems started including them.
If we do a comparison with the browser situation, then it would be quite sufficient to allow people to install 3rd party TCP/IP stacks. Does Microsoft prevent that? I honestly don't know myself since I don't really use Windows. :D
The key to understanding the browser case is that, as MS wanted it, it would have tied client and server and rich application development together, all of which would have necessitated Windows. IE was a threat because of ActiveX.
In the early days Wordpress sold use of their domain to black hat seo / spammers.
I wouldn't accept it to sneak the change in, but I'd probably be perfectly willing to take their hand off and sell rights to the product. Assuming of course I didn't just delete the message assuming it was some sort of phishing scam or other rather than a genuine offer.
I'd feel obligated to make it known that I'd done this, perhaps via a notification in the app prior to hand-over and in its README. Something along the lines of a normal change of ownership message (copyright has been transferred to X, contact them for further information, future official releases will come from their fork, of course existing open source releases remain open source even if they change licencing arrangements for future releases, yadda yadda). Though we all know how often people just click through notifications, so I'm not sure how much difference that would really make - so if I were a robot I might be considered culpable under the second half of the first law...
If the buyer would walk away if I didn't agree to a more silent sale then I wouldn't touch it. It is a thin line that I won't cross, but still a line I like to think wouldn't cross. Then again I have the luxury of being relatively comfortable at this point in my life (decent day job at a company which is weathering the current collection of world crises pretty well, the little flat's mortgage near paid), for many others out there the financial incentive would be much harder to ignore. I'm not sure that I like that I wouldn't draw my line in a different place, but I'd be dishonest if I tried to claim that I would.
Bundling can be seen as bad in terms of competition [0], but it can also be good for the user experience. I wonder if these apps go unimplemented for fear of regulation. It might be silly to think of a barcode scanner (or other small utility) in that way, but, if the app is so silly, then is it really worth the risk (not just from regulation, but from having to deal with bugs)?
0 - https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor....
The questions are: how do you decide is necessary and how do you present it to the user? Different people have different needs and making every should have been feature visible ends up making every other feature less visible. That may be fine if you're developing software for a specialist who will take the time to learn a particular application which is relevant to them, but it's a drawback when you're creating software for a general audience since only a handful of enthusiasts will take the time to learn the software.
I wouldn't be surprised if there are app developers that actually do accept these kinds of offers though.
Just one, together with alternative forms of 2 factor auth, such as a Yubikey (U2F token) or printed backup codes.
Or it suddenly gone from app / play store
Breaking OS changes are a problem, it's true. Thankfully they basically never happen on phones (certainly if you have a phone that stopped updates ~4-5 years ago it will still work).
"Thankfully they basically never happen on phones"
There has probably never been a phone OS update that didn't break things. And not in a "technically something broke so haha gotcha! way"
Broken in a "half the apps out there need to be rebuilt with a new SDK version and/or deprecated or there'll be obvious bugs" way
I wouldn't accept it to sneak the change in, but I'd probably be
imagine android version of Google Authenticator having no way to export data to the iphone version..
oh wait..
I will imagine that anyone who creates an authenticator is half-decent enough to NOT take that bribe and serve the greater good.
I will also imagine that when people install authenticators, they would NOT trust one from HenryBemis but only from sources that they recognize (Google, Microsoft, Yubikey, etc.)
It always amazes me how come all smartphone OS creators switch every connectivity option to ON by default on every new app installation. It would take a use another 3-4 seconds per app installation to prompt the user whether they want this app to access Wifi/Data/Background/Roaming. In the same sense than the OS asks you whether you allow access to Calendar, Contacts, Camera, etc. At least half my apps on my Android do NOT need access to the internet to function. They may 'want', but definitely not need.
Dear HenryBemis,
As a CEO of TRC, I would like to extend you an offer to purchase source and distribution rights to your app, SummerChildAuthenticator, to the form of $500,000 (five hundred thousand US dollars). We are a fast growing SV startup that wants to make it easier for people to secure their papers and money on-line. We have developed a streamlined, easy-to-use, user interface for authenticator applications and are looking for a way to quickly put it in front of a wide audience. We believe that your SummerChildAuthenticator, with its established base of over 50 000 users, is the gateway we are looking for.
If you are interested in this offer, please reply to this e-mail.
Sincerely yours,
TeMPOraL, CEO, TRC
<smallfont>Temporal's Rackets and Cons is a startup registered in Southern Vescillo, Arstotzka.</smallfont>
--
You think to yourself: "this is a good deal! The app is unlikely to grow more, it isn't making you any money anyway. Here is this hot new startup with great ideas, what's the worst that could happen? They'll just inject an ad here and there. Meanwhile, I have medical expenses, and..."
So you agree, and I take your app, and run a "growth hacking" campaign on Reddit to blow its userbase up to 500 000 people, and then proceed with my main business plan, which is selling access to OTP codes to the mob running phishing scams.
(Oh, dear reader, you've noticed Arstotzka and thought I'll be selling data to evil government? Nope, we registered there only because it'll make it mighty hard for anyone to sue us.)
Any developer knows/understands if the offer comes from a legit source or scumbag. I cannot make other people's choices for them. My answer would be 'no' even for 100k, BUT I am in HN and I suggest people get off facebook and google because they are privacy nightmares (also certified in a couple of audit/security areas - so there's that). Btw I did have an app on Apple store, target audience was children (3-6 years old), it did OK, I just didn't have the time to keep it around (for the little revenue it was bringing). It worked 100% offline, no tracking, no ads, no nothing. I have a free version as a sample and the full version at $0.99. I chose to sell than help the ad beast grow bigger and track children more.
But that is just me. $50k is a serious amount but it won't make me or break me. For some other parts of the world, where a monthly salary may be $200.....
And while I don't think you personally will sell out like this, I wanted to highlight that a) it's easy to make such an offer sounding legit enough (particularly to developers with little experience with the world at large), and b) an Authenticator app is a perfectly valid target for such offer. I'd even say it's more lucrative target than most.
And a lot of reputable software companies have sold out to peddling adware. Adobe is one, and there are a lot of others. Abandoned shareware or open source often resurface with adware installers.
> When inserted into a computer, the CDs installed one of two pieces of software which provided a form of digital rights management (DRM) by modifying the operating system to interfere with CD copying. Neither program could easily be uninstalled, and they created vulnerabilities that were exploited by unrelated malware. One of the programs would install and "phone home" with reports on the user's private listening habits - even if the user refused its end-user license agreement (EULA), while the other was not mentioned in the EULA at all. Both programs contained code from several pieces of copylefted free software in an apparent infringement of copyright, and configured the operating system to hide the software's existence, leading to both programs being classified as rootkits.
> on about 22 million CDs
https://en.wikipedia.org/wiki/Superfish
> The installation included a universal self-signed certificate authority; the certificate authority allows a man-in-the-middle attack to introduce ads even on encrypted pages. The certificate authority had the same private key across laptops; this allows third-party eavesdroppers to intercept or modify HTTPS secure communications without triggering browser warnings by either extracting the private key or using a self-signed certificate.
I yes, I too rememeber the FirefoxOS. Good times.
I suppose I should be grateful that I can turn off a lot of permissions for apps at all these days, unlike the malware built into recent versions of the major desktop operating systems. :-(
I had two apps that radically changed their business model (owner?) through updates with no recourse.
I had an app called gas cubby, which let me locally - on the phone - keep track of all my vehicles. I could enter detailed information about each car such as year, make, model, vin, insurance policy, gas purchases, oil changes and the like. It would tell you gas mileage and remind you of upcoming maintenance. One day, I updated the app and all my local data was uploaded to the cloud.
Another app I updated was camscanner from tencent that basically did the same thing. Think of all the PDFs you scan going to their cloud.
A while back, I was approached by a [NATION OBFUSCATED] developer, asking to buy up one of my older apps (they are all open-source).
I ignored the request, and reported the approach to Apple, as I'm sure that this actor has been doing the same for many other apps.
This is apparently a common method for malware-slingers. They buy established, older apps, that they assume the developer has abandoned (I hadn't abandoned it, but it's a simple app that hardly ever needs tweaking. If I stop supporting an app, I remove it from the store).
They then "update" the app, with a little "extra flavoring."
This happened to me with Chrome. It auto-updated, then automatically synced browser history, passwords, and who knows what else, to Google. They soon changed it to opt-in sync, but it was too late for me at that point; they had already hoovered up my personal data. That was when I stopped using Chrome and switched fully to Firefox.
and secondly, they or an analytics package can just read everything client side and upload it to a server anyway
doesn't matter if its whatsapp, or signal, or some protonmail client if such a thing exists
I just don't use them with that assurance in mind, I use them for other things.
Neither of the 2 scenarios you describe are even remotely what's happened here. Not sure how you got from 'malicious ad popups' to 'app added cloud feature'.
Google does allow no-root firewalls on the PlayStore which rely on VPN APIs. Here are some open source ones: https://www.reddit.com/r/androidapps/comments/jhtvn4/a_list_...
few QR code apps from F-Droid.
https://f-droid.org/en/packages/com.example.barcodescanner/
https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...
What I do instead is monitor Android's traffic with a LittleSnitch-esque firewall and block all apps I don't use. Also, I've disabled auto-updates on non-essential apps. Only Photos, Maps, Chrome, and Firefox are allowed to auto update on my Android.
Nobody said blanket trust anything. F-Droid is a community project with a framework that allows for disclosing user hostile behavior in apps. By using it and paying attention, we can all make it even better - the exact opposite of Google, whose incentives do not align at all with these goals.
https://play.google.com/store/apps/details?id=org.barcodesca...
It also uses the ZXing library. It does not contain any tracking or ad SDK's per the exodus report :
https://reports.exodus-privacy.eu.org/en/reports/org.barcode...
https://play.google.com/store/apps/details?id=com.secuso.pri...
Was ZXing also hit by some issue, or is that just confused people that mistook the ZXing barcode scanner for the Lavabird barcode scanner?
In the comments of the article, someone wrote:
> The Zxing project is the flagship open source barcode scanner project for many years, and the December 2020 build was infected with malware. That bad build has been removed, of course, but the damage to the project continues.
Is there any further information on this?
It could also be both of course.
The dev says the app hasn't been updated since 2019.
Another point is the often complete change in UI or app behavior and you only find out about when you want it the least. I once had the case where I came out of a bar in the middle of a cold night, tired, had some beers and just wanted to use my Bikesharing app to unlock a freefloating bike to get home - whilst the app decided that it had to introduce a completely new UI and forced me to take an unskippable "guided tour" through the new features right at the spot.
This separation should be the price of admission for software developers who want to use online updates, and by now there is probably a need for real laws to regulate the industry since firstly it is very clear that it will not regulate itself effectively and secondly it is no longer just random applications but essentials like operating systems, web browsers and even the software controlling your car that are being treated in this cavalier way.
The Play Store doesn't give enough information to really judge if the upgrade is necessary.
We are not talking about patching. We are talking about updating.
> They'd just keep it around unpatched, while connecting it to the network. Is millions of vulnerable devices better than giving vendors of some software the ability to remotely patch their software?
Yes. Vendors do not patch their SW. For the average SW developer fixing bugs is like castor oil. Remember the forced transition from Win 7 to Win 10 when a good OS was replaced by an abomination ? And no, 10 is not better securitywise than 7. There are lot of RCEs in 10. Did you ever play an EA game ? With Origin doing a 4GB update before playing ? On a 25 Mbps internet connection ?
So for me if you have a security patch for your sw i will apply it. Maybe after some buffer period in the case of known offenders (MS) depending on severity. If it's "performance and usability improvements" just forgetit. If you did't bother to write a changelog for your SW i will not waste my time and money (an internet connection is not free ) updating it.
Yes auto updates allow delivery of malware but its not like manual updating was any better. No user was auditing changes before hitting the update.
Microsoft went in hard / aggressively and are forcing update installs and restarts, which IMO is going the wrong direction.
Wasn't there a Linux project where they could update the OS / kernel without a restart? I feel like this is what all OSes should aim for. I like to think Android is going in one direction, moving shared libraries (Play Services) outside of the core OS so it can be updated independently.
You can turn it off, but you have to dig in settings. During initial iOS 14 setup it has a screen telling you it's turning autoupdates on, but you're not allowed to opt out there.
Unattended upgrades are a remote code execution vulnerability.
Around the end of December started seeing web page notifications after my phone had been locked for a while. I clear those and it goes away for a day or so. I originally attributed it to an open tab, or some site that I had inadvertently enabled notifications for. It took me a few days of seeing these and checking browsers to realize it was more, so I started checking apps recently installed. I even installed malwarebytes to do a scan, found nothing. There were three recently updated, including barcode scanner. I opened that and malwarebytes immediately flagged it. So the scanner seemed to know about it at that time, but couldn't detect it until you actually opened the application.
I used to have Theft Aware before it got bought by Avast, and I tried Lookout some years ago. But it was this incident that finally convinced me to install and keep anti-malware app on my phone. I've also disabled app updates from the play store.
EDIT: Mine was by "The Space Team", not the one listed in the article. Seems like a number of barcode scanner apps were targeted recently.
Buy iPhone.
I know some people hate Apple but these type of things never happen or so rare. I hear android malware very often though.
Buy Nokia 3310.
These types of things literally never happen.
Or maybe people have a lot of reasons for why they chose what they chose and this isn't productive.
For a counter point, I am also using this app since 2016, & have all apps on auto update, & have never received any web add popup or notification because of this or any app.
It took me a bit of digging to make the distinction. I have both of them listed in my App Library, and both with the same name. At some point, I believe I went to install ZXing on a new phone and Android warned me that the app may be incompatible, so I went to the space team one. It makes sense that if people aren't looking directly in their app library that they can get these mixed up and leave the bad reviews.
However, since the space team version got infected, I did try the ZXing app - no pop-ups, and it works just fine (despite the age warning).
https://play.google.com/store/apps/details?id=com.qrcodescan...
What does this mean for other apps with overreaching permissions?
The key here is that the author had a properly working, trusted, non-invasive application for years and then they pushed an updated version that was less so. Fortunately, it was an app with minimal permissions - it could only open web pages. In my case, running ublock, those pages came up blank. But for others not running an ad filter, they got pop-ups prompting them to install even more malware.
As for Google Play release process, I can't speak on that too much. They do scan for malicious code, but this code may not be malicious enough. If part of an application's purpose is to open web links, more code that opens links would not be as noticeable. Apple has a more intensive process to review new apps, and they spot-check app updates, but it's going to be somewhat similar. We hear about Apple pulling existing applications all the time for random reasons, but it's often after an update or report. Google pulled some of these apps after they were reported, but it was also after.
I'm not defending Google Play - they have a more relaxed review process than Apple, relying more on automation. But both have "legitimate" apps pulled for obscure reasons (and the only recourse seems to be getting attention on HN/Twitter/other), and both have let scam apps through. Apple seems to catch more of the "bad" apps, but also drops more legitimate apps that compete with Apple's business interest.
Open source software and more open and transparent platforms!
Today users of common brands of Android and Apple devices are really restricted in control of their devices, so there is very few ways to check what the system or apps are doing, inspect, firewall/limit things, go tinker inside the apps.
And as said by other people, most of the time you have auto updates forced on users and so app developer does not even have to really justify what changed and why.
The phone market is a duopoly, Google and Apple have the market shared between them. There is no need to really improve this situation for end-users. For me it feels like Windows XP all over again.
I am a happy user of a Linux phone. I very much enjoy and support Jolla and Sailfish OS, while also hoping for the Pinephone and the Librem 5 to take off and be available as an option for daily use.
Apple also contacted users directly to alert them of whatever apps they had purchased on the App Store were compromised so they could monitor for updates, or remove the app entirely.
Has Google done the same? Neither Apple or Google have the ability to directly remove apps on a users device, but simply removing it from the store and then having users rely on a solution like MalwareBytes seems like Google is abnegating their responsibility of a safe marketplace.
https://developers.google.com/android/play-protect/client-pr...
Play protect is a complete joke, it can't even detect malicious chinese apps that request every single permission that exists.
I'm pretty sure both can. But it's a legal problem, not a technical one.
Last time I went on an "update spree" and updated everything I tend to use frequently, I got the new Firefox mobile update, which is frankly utter garbage, and now I regret it.
(Why it's utter garbage? It's much more laggy across the board, and there are issues getting uBlock Origin to work on it. And this tends to be the story with updates - I haven't seen the app that got leaner, or faster, or more ergonomic with an update. Not a single one.)
The "update culture" has unfortunately trained users to obediently "bend over and take it", which is horrible from both the security and change-management point of view; but is the dream of those who want to exert control over "the sheeple".
I seriously ask the question what damage could a potential malicious app on iOS cause? There is no running in the background, so no exploiting while I don't use the app, no being part of a botnet when the app is closed. There is a FS sandbox that will not let you access another Apps data without being able to jailbreak etc. I think an auto-update is more risky on iOS than to live with an older version of the app that does its job (you never know what an update changes/breaks for you, and downgrading is not an option in the appstore).
I installed just about every Android anti-malware app that I could find in late January, and none detected the bad app.
Finally by googling some of the ad domains that kept popping up, I found the forum discussion that they mention. In other words it took them about two months to react!
Edit: either it took forever or there are multiple barcode scanner apps that are affected and they didn't find all of them.
That was not one that was mentioned by the article
It's url: https://play.google.com/store/apps/details?id=com.qrcodescan...
(See the reviews)
The zxing one seems to not have been updated in years (plus it's still on the store).
I immediatly uninstalled the app and left a review. Like many other negative reviews I received some copy-pasted response stating they only have some in app ads.
It is beyond me that the developers just lie about including malware in their app while it is so obvious they are.
But wait, there is more, that permission (and some others) are considered so harmless that if you install an app without it, and then the developer publish an update with it, play store will automatically update it without even asking! Remember this doesn't happen with 'dangerous' permissions, so apparently Google thinks accessing the internet is not dangerous at all.
Google knows who their devs are. Law enforcement can demand they give up that info.
https://play.google.com/store/apps/details?id=com.prof18.sec...
But then a lot of people like your app, and ask for a small extra feature. You support it, and then get a bit annoyed by all the features people are asking for. Then you have to update it for the latest release... then suddenly fix it when some obscure version of Android breaks on it.
Then someone offers you £60k for a small ad no-one will even see and you think.. don't you deserve a bit of credit?
Maybe you'll be the good one who doesn't take it, but the free model is generally unsustainable.
The usual "400$/month per 1k users" stuff, just integrate an ad network is common, but sometimes as dev you even get offers like "we hire you, with a contract, you can’t be fired, legally you’re a consultant to us for 2 years, at a few hours per week officially, for a silicon valley wage, unofficially you just don’t do anything and collect but we get full control over your apps".
Personally I’ve had quite a few such offers, and I’ve rejected them in the past and will also reject them in the future
Trust devs who’ve proven themselves :)
I think that if the app is open source, it's harder to hide such behavior.
You wrote a wrapper around ZXing, which already has an official app as well as simple variations of that app from the ZXing team. That app is open source and ad-free.
There are already many similar wrappers around ZXing on the Play Store.
So what does your app do (or not) that makes it special?
But in this case, there is only one standard, and lots of imitators: https://play.google.com/store/apps/details?id=com.google.zxi...
But fallout from the bad app, or possibly deliberate actions by the malware maker have caused hundreds of bad reviews. It might be that removing the malware app from the store means people search for Barcode Scanner, find ZXing instead of the bad one, then post their bad review there. Or maybe the bad app is deliberately telling people "Click here to review the app", and pointing to the wrong app.
There's also reports of some sort of malware doing fishy things with intents to make it look like the ZXing software is bad https://github.com/zxing/zxing/issues/1345#issuecomment-7590....
I'd like to see a proper investigation by someone at Google Play. The original Barcode scanner is not needed for QR codes any more - almost any camera app will recognise those, as will Google's lens application, but it is still useful for scanning other barcode formats and for generating barcodes by sharing data with it from other apps, without needing to upload to a server or anything.
I appreciate the app but...don't you think that's too much?
* Stricter review process to catch this preemptively
* Stricter app isolation to limit impact without a vulnerability explicit
* Longer maintained and more forceful operating system updates to minimize the number of phones running with known exploits
* Likely removing/disabling app from phones and not just the app store
The same goes for Chrome Extensions which have been removed from the Chrome Web Store. In that case, they get removed automatically from the browser, which is somewhat ok. I would prefer that they would get disabled without me being able to enable it again, and get labeled as malicious. Because how else can I verify that I once installed an extension or an app which then turned malicious?
Currently I know that either one of my or my dad's devices has something malicious on it, because I got an HTTP GET request to a URL whose full path is only known to our devices (and only via HTTPS).
1. https://www.softwaretalks.io/v/4047/black-hat-usa-2013-how-t...
https://fossbytes.com/peel-remote-use-remove-smart-remote/ "Truth be told, Peel Remote has been scrutinized for more than a year because of the company desperate measure to gain revenue. In 2017, the app introduced a malign ad practice of unethical lock screen ads and overlays."
My girlfriends tablet just started turning the screen on at random times. It took some time to find out which app causes this.
The fact that Google allows applications on Google Play to have identical/duplicate names is a significant ongoing problem as it causes considerable confusion.
I'm not against apps that have similar functions having identical (duplicate) filenames as this stops developers having to dream up ridiculous names that have little or no bearing to an app's function but it would make sense to separate the apps in some simple way that users could easily identify. For instance, apps with identical names could be flagged in many ways such as, say, Google providing a sequence number to the end of the filename. And I'm sure there are many other suitable ways I've not thought of.
As for the fact that Google lets malware onto Google Play and that it has happened many times demonstrates the fact that Google doesn't consider the matter of highest importance. That's to say, keeping malware off users' Android phones is not as important as making money from its advertisers.
If keeping malware off apps were equally important to Google then this is malware would have unlikely escaped Google's monitoring, as Google has just about every technical measure at its disposal to monitor apps for malware—and I'd venture to say that even its AI technology could be brought bear.
Clearly, if both issues aren't of equal importance in Google's eyes then it raises questions as to why Google keeps changing or adding certain features to its Android operating system in the name of security but which annoy users (and in effect violate their privacy—in that users' data, etc are even more transparent to Google whether the user likes it or not).
Day by day, Google is proving itself to everyone to be more of a worry.
—
Note: I'm one of those who have an app on my phone named 'Barcode scanner' and it took me a while to determine (fortunately) that the one I have installed is not the app in question.
You're right, displaying the fact would solve most things. The question is why such an obvious matter—which also would have been even more obvious to Google—wasn't enacted as such.
Large scale is not a new quantity, it's a new quality.
they also offer an sdk of their own for including a barcode scanner into your app. https://github.com/WeTransfer/WeScan
I'm not really sure they are connected (package names don't verify domain names AFAIK). Just curious.
I'll never undertand why Google didn't include one from the start. They finally added it to the camera app but very few people know about it.
I require them to create 2 profiles in Chrome (and a 3rd for personal purposes), one for dev and one for official purposes, but I know that, in remote work, they get less serious.
It’s a major security problem. I’m wondering whether I should purchase the Chrome extension’s source code and deploy it myself on the store.
If you guys have any features you'd like to see in a stand alone QR code Reader, let us know.
Arguably manual curation doesn't scale to google play store or apple app store size and automated scanning only gets you so far.
You have several possible threats.
1. Apps that are malicious from the start.
Best addressed by better automated testing.
2. Apps that become malicious particularly when the app changes hands.
Best addressed by making this impossible. James/foo should never be transferred ownership should result in Jane/foo which users would have to download.
3. Apps that aren't malicious but include a component that is user hostile. Virtually always included for money.
Best addressed by just forbidding apps with ads. We wont do this but not much of value would be lost.
4. Apps that include a component that isn't malicious but itself becomes malicious later.
Requires due diligence by the developer. Arguably one could imagine better automated enumeration of the constituent components to discern what might have been compromised so that developers could have their apps automatically pulled and informed that they were compromised. One could also imagine a statutory fine for paid that earn developer revenue wherein their product harms users. This couldn't accrue to free apps without making foss impossible. Eliminating apps paid for with ads would eliminate a gray area.
An interesting point for those who presently avoid ad laden apps is whether your paid for apps are infected with the same potential malware vectors as the ad supported version as whether or not to show ads may be solely a function of an in app purchase you have made. Your paid for app might therefore be just as vulnerable.
What reasonable measures would one expect Google to actually take? Probably only reactive measures like removing this particular app while making no meaningful moves to correct any systemic problems. In the longer term one might expect them to do a better job of finding malware automatically.
If you value not getting hacked in the longer term it looks like this is insufficient. If for example Fdroid is insufficient in scope of applications then perhaps we should work on improving this situation as Google is unlikely to fix this for us.
Or does Google have the full address? Seems unlikely
Google has it, since publishing requires a $15 one-time fee. Of course, you can put bogus into the billing info for that as well.
How do you think small app developers earn money by displaying ads? But we want ads to be blocked and don’t want to pay money
THIS app, however, displayed ads outside of the application when the phone was unlocked. It's not the same thing, and it's not ok.
Guess this is why some walled gardens look a lot nicer from the inside...
https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...
you can directly download the APK from that site, don't need an F-Droid client.
If you want an F-Droid client, i recommend Foxy Droid. Unfortunately lacks some features of the official one but way faster and nicer to use.
Edit: Seems they're using MoPub and AdMob
https://en.wikipedia.org/wiki/Barcode_Scanner_(application)
https://play.google.com/store/apps/details?id=com.google.zxi...
I now use Google Lens through the default phone app.
I bet there's a _huge_ increase in use of QR code scanning apps compared to this the last year...
So will google fix these reviews like they did with RH? These are clearly wrong unlike RH...
People really need to start respecting m=milli and M=mega.
Edit: /s
Apple does not block apps from using the network or give you any way to find out what they are doing and who they are talking to.
In fact, apple does the opposite - it blocks apps that let you firewall your phone.