Chinese app included malware to gain competitive advantage
krebsonsecurity.com
krebsonsecurity.com
Add to the funniness, there is a report posted by CNCERT just last month on their website showing their tests on Chinese online shopping apps[1] which includes Pinduoduo. If you see their investigations and numbers, you probably think Pinduoduo is fine (really, take look the report), LOL. (Note: in case you're wondering, corruption on a small routine report like this is very unlikely, but CNCERT probably did not look very deep into the rabbit hole at all)
[1] (It's obviously in Chinese): https://www.cert.org.cn/publish/main/8/2023/2023020210325795..., https://www.cert.org.cn/publish/main/upload/File/shoppingapp...
In the end, you still need independent experts such as like Liu Huafang to alert the country through public exposures, just like, you know, what has happened few years ago.
That's... not the impression I got? Pinduoduo is called out as the app that uses the most Android permissions (all four tested); while many apps are found to access the clipboard, only Pinduoduo and Taobao upload the content, and unlike Taobao, Pinduoduo doesn't just do this during a product search but also when not using the app. It's not as bad as other apps on some aspects (Suning Yigou requesting location 1199 times in the background, really?) but doesn't exactly look fine either.
My guess is that CNCERT collected this information with a test harness that logged access to standard Android APIs and wasn't designed to detect exploits; they'll need to up their game next time.
For those residing in urban China, it is nearly impossible to avoid owning a smartphone equipped with Chinese apps. This is particularly true during the COVID era, when a green QR pass from these apps is necessary for going anywhere. Mobile technology has become deeply ingrained in Chinese society.
For posterity: “Chinese app included malware to gain competitive advantage”
It does not matter what's the problem with this title, even if you make up a perfectly fine (and better in any aspect) title, it's still more appropriate to use the original title.
I believe the rule is specifically made for this case: you have different view on what's clickbait-y, or I didn't drink enough China-bad. That's the best way to prevent exaggerating.
[1] https://www.theguardian.com/technology/2021/sep/13/nso-group...
iPhone might also work but it's too hard to do forensics.
Picked up a newer Pixel and it worked then, but found it was hard to live without the goog services. It was either that or trust some rando packages in F-Droid, so went back to the Play store
That's pretty recent for being "now-defunct". What happened?
My take may be historically inaccurate, but I think Apple's app eco system is rooted in the limited capabilities of the iPhone browser, at the time. Apple only reluctantly allowed other companies to target the phone's guts and then much later discovered the app store revenue model they are now addicted to.
With modern browsers and Web apps, "native" apps have since become mostly obsolete. The perspective has shifted in that contemporary Android/iOS apps are no longer a kludge to work around browser capabilities, but instead a market place for selling user privacy to third parties.
Security comes in only when it's absolutely obvious that app developers are way-overstepping the boundaries of what the app is supposed to do. Like back grounding and monitoring the clipboard for no good reason whatsoever.
When you used google/firebase deeplink[1] functionality it was copying a hash shortly before the deeplink, that was then pasted inside the app and could be used to link both web+app sessions together, which was really helpful.
[1] https://firebase.google.com/docs/dynamic-links/operating-sys...
ref: (in Chinese, of course) https://view.inews.qq.com/k/20220119A06Z9L00?web_channel=wap...
Was the signing certificate the same?
Google strips and resigns all apps uploaded to them.
It is, yet it is also heart warming, for whether from China or the US, the concern by average end users is the same.
Humans ... no matter their political differences, are all just dumbasses.