Android antivirus apps a complete waste of time
extremetech.com
extremetech.com
Something like "Instead of a subscription, I'm going to SMS these 3 numbers once a month and it's going to cost you five bucks"
This actually might bypass all the headaches folks are having with merchant accounts and payment plans and work out as something both the user and developer might like a lot better. If crooks can make millions charging for bogus SMS messages, why can't legitimate programmers use the same payment mechanism for stuff the users like?
Don't know. Just throwing it out there. What caught my eye was the assumption that any program using SMS to rack up charges was malware. Is that always a true statement?
This exists; you see it occasionally for web games.
It's quite expensive, though, and I suspect it's not allowed on Android if you're in the marketplace; does Google allow you to use third-party payment stuff for marketplace apps?
I'm seriously considering using something like BMT Micro to sell upgrades to a free app. The classic shareware model, more or less. I'd really like to sidestep all the annoyances and time overhead that come with selling stuff directly. I believe the iOS App Store is set up that way already (where you're effectively licensing them to sell your software and they're paying you royalties), but unfortunately not the Android Market.
Yep, the iOS app store is effectively a publisher; the only tax complexities involved are countries which practice withholding (the US and Japan, in particular; unless you register with their tax authorities they withhold a percentage, even for countries with which they have tax treaties), and special treatment of royalties in some countries.
Here's the problem: "Anti-virus" in general is limited because it relies on static signatures. Therefore it can only detect known malware and is vulnerable to evasion (polymorphism / metamorphism). On mobile devices AV is even more limited because of resource constraints (namely, limited battery and cpu).
By doing malware detection in the cloud, we have plentiful resources to do heavyweight analyses. We also get a better overall detection capability by using behavioral analyses instead of just static signatures (we actually run the apps).
If you're curious about the technical details, we presented at Black Hat in August. https://media.blackhat.com/bh-us-11/Daswani/BH_US_11_Daswani...
P.S. We’re hiring :-)
Also, people should stop wearing seatbelts, and just start driving better.
It's difficult to get infected with Android malware without directly installing questionable applications on your phone, but it is pretty easy to get into an accident through no fault of your own.
This is anecdotal, but after about the 10th time reinstalling my parents OS, I finally discovered that the root of all their malware-related problems stemmed from the fact that they were downloading music using Limewire. It hadn't crossed their minds that perhaps this was not a very good idea.
I'm sure they genuinely believed that their computer was repeatedly being infected "through no fault of their own".
I'm looking at you, GrooveShark.
If you're developing for android, you're going to install your own APKs from sd card. Even if you "don't install other apps" that way, you're still "leaving the vector open" by leaving the system setting on, apparently?
Also, if you want to upgrade the OS or kernel on some of the cheaper phones, you'll need to use cyanogenmod, and usually a custom version hacked together by randomers on forums. My (cheap, spare) droid runs a bootloader and OS which is the result of collaboration between a Chinese guy, a British guy and other developers from "the internet". You do have to join the forums, talk to people a bit, and read up on the feedback these users get when they post new ROMs though, I'll admit...
Maybe I'll install one of these free AV apps and see if they can find anything! :)
Yet, lots of people (both techs and non-techs) will think you are crazy if you dont use AV on your Windows PC. Its some sort of mass psycosis.
However, an AV is pretty good at detecting stuff that you may get exposed to otherwise - exploits can pwn your Windows computer without you even knowing, and sometimes even run off legit ad networks. NoScript / AdBlock, running Google Chrome, and practicing safe browsing can help, but an AV is a good additional layer.
I guess my point is - an AV is NOT a panacea, but it should be used as an additional layer of defence.
Anti-virus software is like having airport security that only screens those that fit a certain profile. Someone not meeting that profile is going to walk onto a plane with the intent to do harm, at which point you are no further ahead than you were when you had no security checks at all.
Unless you warn about everything going on in the system, you are not really aware of everything. If you do warn about everything, the user will start to ignore the warnings.
This thing just sniffs for malware whose transmission vector may by coincidence pass thru an iOS device, like PDFs and Dropbox.
How does that make them useless?
This is one of the key advantages of the iOS App Store - the process of analyzing app capabilities and security is offloaded to Apple - users don't have to care about it.