Slashdot Mirror


More Malicious Apps Found On Google Play

suraj.sun writes "We've seen quite a few Android malware discoveries in the recent past, mostly on unofficial Android markets. There was a premium-rate SMS Trojan that not only sent costly SMS messages automatically, but also prevented users' carriers from notifying them of the new charges, a massive Android malware campaign that may be responsible for duping as many as 5 million users, and an malware controlled via SMS. Ars Technica is now reporting another Android malware discovery made by McAfee researcher Carlos Castillo, this time on Google's official app market, Google Play, even after Google announced back in early February that it has started scanning Android apps for malware. Two weeks ago, a separate set of researchers found malicious extensions in the Google Chrome Web Store that could gain complete control of users' Facebook profiles. Quoting the article: 'The repeated discoveries of malware hosted on Google servers underscore the darker side of a market that allows anyone to submit apps with few questions asked. Whatever critics may say about Apple's App Store, which is significantly more selective about the titles it hosts, complaints about malware aren't one of them.'"

143 comments

  1. Except by Anonymous Coward · · Score: 4, Insightful

    >complaints about malware aren't one of them
    So the ones that raid your contacts and send the information to persons unknown are fine?

    1. Re:Except by devleopard · · Score: 3, Insightful

      I've never seen or installed such an app on my iOS devices. I'm sure if I spent some time searching the Slashdot archives, there'd be at least one article; I'm sure the apps do exist. (And are no longer on the app store today). However, these articles about Android malware are weekly, or more often. Google needs to shut it all down, and then relaunch Play where all apps are properly vetted.

      Would that destroy the "freedom" concept? Maybe, but such an idea just doesn't work. Would you run any random Windows app on a Windows machine without an antivirus? Android has a massive smartphone share, and it's thusly going to be targeted. Imagine a 1997 where 40% or more all computers sold came with Mac OS or Redhat. Do you think that today we'd know those platform as untargeted by malware? Of course not. Either Google needs to lock things down, or we'll start seeing Norton or McAfee on the phones within the year.

      --
      The best thing about a boolean is even if you are wrong, you are only off by a bit.
    2. Re:Except by Cute+Fuzzy+Bunny · · Score: 3, Informative

      Yep, that was the funny part of the article. "Whatever critics may say about Apple's App Store, which is significantly more selective about the titles it hosts, complaints about malware aren't one of them.'"

      But one of them would be that the assertion is ridiculously incorrect.

      Even weak google-fu turns up this, among many...
      http://nakedsecurity.sophos.com/2011/11/08/apple%E2%80%99s-app-store-security-compromised/

      Why do apple people think their products and services are malware proof, even though anyone with a self respecting brain capacity would know its not true in theory or in practice? Is that why they pay twice as much for stuff?

    3. Re:Except by PNutts · · Score: 5, Insightful

      >complaints about malware aren't one of them
      So the ones that raid your contacts and send the information to persons unknown are fine?

      No, but who could have imaged the apps below would harvest your contacts! It's almost like they were built specifically to share information.

      Foursquare
      Path
      Instagram
      Facebook
      Twitter for iOS
      Voxer

    4. Re:Except by Anonymous Coward · · Score: 0

      Speaking of ridiculously incorrect assertions...

    5. Re:Except by Anonymous Coward · · Score: 2, Insightful

      I think that anyone with self respecting brain capacity would realize that picking the small handful of issues Apple has had with their vetting model cannot be compared to the thousands of apps that compromise Google's model.

    6. Re:Except by BasilBrush · · Score: 4, Insightful

      You finding an example of malware doesn't disprove the assertion that people are complaining about malware on the iOS App Store. Just as finding one criminal in the country's safest town wouldn't mean people are complaining about crime there.

      iOS App Store has a minuscule amount of malware compared to it's size. There's orders of magnitude more malware on the Android stores.

    7. Re:Except by BasilBrush · · Score: 4, Informative

      So the ones that raid your contacts and send the information to persons unknown are fine?

      Clearly not. But they are many times less bad than the Android one described that is costing you serious money by sending premium-rate SMSs.

    8. Re:Except by Cute+Fuzzy+Bunny · · Score: 1, Insightful

      I too enjoy the random use of immediately made up statistics laid out in terms like 'miniscule' and 'orders of magnitude'. Most of the apps I've downloaded from the app store and from play/market reported all sorts of things they didnt need to know about or report back to some mothership who-knows-where. I've never loaded a malicious app that caused me harm or did something that required repair...from either.

      Yet there are plenty of stories about malware and the ability to enact it on both platforms, in all kinds. To say otherwise is simply laying on the blinders because otherwise you'll wonder why you paid so much.

    9. Re:Except by Anonymous Coward · · Score: 0

      Aww... guy seems to be having a hissy-fit that Apple's app store has literally no issues with Malware. Sure, there may be the (rare) occasional blip that comes up mainly from a security research firm but one cannot in even the remote sense compare whatever issues Apple's app store to the wild-west mentality and cess pool policies that Android's "open" model has.

      The problem is that the only people that can really keep their Android devices malware/virus free are not representative of the majority of smartphone users. Yet these tech-saavy individuals have the audacity to criticize Apple and their "walled garden" approach as draconian knowing full well that their own solution is essentially garbage. The majority of smartphone users DO NOT want to babysit their devices like their desktop counterparts. They just want them to work. Android enthusiasts are just being ignorant to the problem at hand.

      But hey, keep preaching that "open & free" mentality. Look how good it's working for ya.

    10. Re:Except by Anonymous Coward · · Score: 0

      instagram is now owned by facebook

    11. Re:Except by bhagwad · · Score: 1

      ...compare whatever issues Apple's app store to the wild-west mentality and cess pool policies that Android's "open" model has.

      It's not as if being the "wild west" is something new. Regular operating systems like Windows have been a "wild west" for decades and I hope they will continue to be that way. Android is even MORE controlled than Windows since there's no single windows marketplace. The wild west is a good thing. It democratizes the ecosystem and does immense good for the computing world in general.

    12. Re:Except by Electricity+Likes+Me · · Score: 2

      In fact I'd go with the idea that many iOS apps are just more intelligent parasites then the well-known examples of Android malware. If you sit around all day spamming premium SMS, you kill your hosts pretty quickly.

      iOS can give away all your private information happily, and no one's the wiser. The app store review process is basically encouraging this kind of intelligent evolution.

    13. Re:Except by Grishnakh · · Score: 1

      Android is even MORE controlled than Windows since there's no single windows marketplace.

      Not exactly: there's more than one Android marketplace. For one thing, I'm on T-mobile, and they have their own little app store (which I admit I've never even bothered looking at). Secondly, it's not hard to install other apps from other sources than the Google Play store. Of course, if you do such a thing, obviously you're taking an additional risk, but the option is always there. Unlike Apple, they don't make it extremely hard (or require someone to hack the phone, a la "jailbreaking") to do things the makers never intended or don't approve of.

      The wild west is a good thing. It democratizes the ecosystem and does immense good for the computing world in general.

      Agreed. It's more risky, but as they say, freedom isn't free. You want Big Brother watching over you all the time and telling you what you can and can't do with your phone, go spend 2-4x as much and buy an iPhone. You want freedom, get an Android phone, and exercise some basic caution (like not downloading some POS app that has no reviews).

      One of the things I like about my Android phone is that I can change just about anything. Don't like the dialer and contact manager? No problem, just download one of the many alternatives. Try that with an iPhone. iPhone lovers are like the people who buy a car and never customize anything on it, and worse even leave the airbag warning labels stuck to the dashboard (the ones you're supposed to peel off when you buy it) and leave the dealer's advertising stuck all over it.

    14. Re:Except by slack_justyb · · Score: 1

      Google needs to lock things down

      I think the problem is that people just don't want / cannot be smart about using technology and thus you feel that the makers need to step in an make this stuff safe for us. The unfortunate part about all of this is that we now live in a world were it is perfectly okay to hand someone a device that can ruin them financially, expose every single person they know, track their every movement, and/or watch what they are doing at the time or at least listen in. Somehow, we don't feel that there is any obligation to include a manual, require training, own a license to use such a device, or anything along those lines. No sir, we'll just keep handing these fuckers out to any idiot that wants something shiny. It's a shame that Apple didn't get into the gun business, a least we'd be a couple of idiots less on this planet.

    15. Re:Except by Anonymous Coward · · Score: 0

      "[...] thousands of apps that compromise Google's model." [citation needed]

    16. Re:Except by Kanasta · · Score: 1

      Does anyone send premium-rate SMSs on purpose anyway? They are never covered in any plan, and are always stupid things.
      WHy not just ban them all?

    17. Re:Except by Anonymous Coward · · Score: 0

      lol, twice as much.. I think everyone knows that Android users almost never pay for anything.

    18. Re:Except by scot4875 · · Score: 1

      Furthermore, any iOS app can access anything, and the user isn't notified. At all.

      Android informs the user about what permissions the app requires and lets them make an informed choice. This is apparently a bad thing, according to Apple fanboys.

      --Jeremy

      --
      Jesus was a liberal
    19. Re:Except by Tharsman · · Score: 1

      The carriers make a lot of money off those, obviously they won’t ban the premium rate sms themselves.

      Google will never do anything to anger or disturb the carrier's revenue stream, so they will never ban all premium-rate SMS on Android.

    20. Re:Except by Anonymous Coward · · Score: 0

      I too enjoy the random use of immediately made up statistics

      Not that this is scientific or reliable, but it's certainly interesting.

      I've never loaded a malicious app that caused me harm or did something that required repair...from either.

      That you know of. That's the problem. Nobody thinks they have an STD either, and yet they keep spreading. If people don't know what's going on in their own crotch, what makes you think they have a clue what's happening on their device?

  2. It drives me crazy by Reed+Solomon · · Score: 4, Insightful

    Why can't they offer a vetting process for apps? Not everything needs the "Google seal of approval", but having a google verified or trusted apps icon appear on an app might alleviate some of the problems, or at least the perception of the google market store (I can't call it google play store, it's just stupid) being a haven for malware and cheap ripoffs.

    In fact, this could be a policy that a third party app store could institute. It would be interesting to see it happen, as they could potentially become more popular than Google's own store.

    1. Re:It drives me crazy by Anonymous Coward · · Score: 2, Informative

      There is a "super developer" tag for some developers (adobe, rovio, others), plus there is the "suggested by the team" category, so what you suggest already exists in some form.

    2. Re:It drives me crazy by Anonymous Coward · · Score: 2, Insightful

      Oh bull. Google isn't letting malware into their store so a few more handsets will show ads.

      Shit just slips through.

    3. Re:It drives me crazy by alostpacket · · Score: 4, Interesting

      AFAIK, contrary to popular belief Google does not make much off of app sales. That money goes to the user's carrier. Rumor has it this was a back-room deal in the early days of Android to prevent carrier app stores (which were terrible back in the BREW days).

      --
      PocketPermissions Android Permission Guide
    4. Re:It drives me crazy by __aaltlg1547 · · Score: 1

      But does their suggestion imply anything other than they were paid for the endorsement? Are they liable under Google's ToS for any damages if the app turns out to be nothing but a fraud scheme?

    5. Re:It drives me crazy by Anonymous Coward · · Score: 1

      The idea is pretty simple. Because its an open platform, anyone can start their own app store and each one has different levels of vetting. Sounds like you prefer the Amazon model. It's fairly easy to install the Amazon Appstore if that's what you want.

    6. Re:It drives me crazy by Microlith · · Score: 3, Insightful

      That's meaningless for the problem at hand, which is that Google's own store is being used as a vector for malware. Google pressing a bit harder on app developers to prevent their store being a hazardous place would have no impact on the openness of the platform.

    7. Re:It drives me crazy by Anonymous Coward · · Score: 1

      Sir, what kind of sad fuck existence do you lead? "Fuckle Assdroid"? At least put some effort into it.

    8. Re:It drives me crazy by Anonymous Coward · · Score: 0

      That's a really clever renaming!

    9. Re:It drives me crazy by BasilBrush · · Score: 1

      No they're letting malware into their store because "it's open!"

    10. Re:It drives me crazy by Anonymous Coward · · Score: 0

      Please stop replying to posts that you don't even know are there. It's confusing.

    11. Re:It drives me crazy by Anonymous Coward · · Score: 0, Funny

      If a 6 figure income, a hot wife that knows how to cook, and enjoying the finer things in life to you means a "sad fuck existance" then you lead an even sadder fuck existance as you can only screw inflatable dolls because your mom told me you were so fugly when you were born she considered killing you. Fuck, your mom also told me that you are so fugly now a prostitute will not even fuck you no matter how much she is fucking paid. But she had to keep you since murdering stupid fucktarded dipshits like you is, unfortunately, illegal.

      BTW, I put more effort into "Fuckle Assdroid" than you have put into your entire miserable existance fucktard.

      Wow! Your complete overreaction tells me you're lying through the holes in your teeth.

    12. Re:It drives me crazy by cynyr · · Score: 2

      Is apple? do they refund the purchase price if they remove an app?

      I do generally agree with the GGP, and would like to see something implemented as an optional thing. $5 to have your app vetted and get a little sticker next to it for every update you make.

      --
      All of the above was encrypted with a Quad ROT-13 method. Unauthorized decryption is in violation of the DMCA.
    13. Re:It drives me crazy by Anonymous Coward · · Score: 0

      That's a real nice dream there kid. Keep sucking those dicks in the truck stop toilets and you might earn enough to open your own shoe shine stand one day!

    14. Re:It drives me crazy by Anonymous Coward · · Score: 0

      "Shit just slips through."

      Yeah, and that is called Fuckle Assdroid, or as you Fuckle loving fucktards call Google Android. Look at the track record of Apple compared to Fuckle, Apple always comes out ahead with iOS as it is far more secure than your fuckle piece of shit.

      How cute, the FuckSheep asswipe shitstain made a funny.

    15. Re:It drives me crazy by Anonymous Coward · · Score: 0

      If a 6 figure income, a hot wife that knows how to cook, and enjoying the finer things in life to you means a "sad fuck existance" then you lead an even sadder fuck existance as you can only screw inflatable dolls because your mom told me you were so fugly when you were born she considered killing you. Fuck, your mom also told me that you are so fugly now a prostitute will not even fuck you no matter how much she is fucking paid. But she had to keep you since murdering stupid fucktarded dipshits like you is, unfortunately, illegal.

      BTW, I put more effort into "Fuckle Assdroid" than you have put into your entire miserable existance fucktard.

      Let me decode this for the rest of you:

      a) Six figure income - You're not supposed to count cents, dipshit.
      b) A hot wife that knows how to cook - Is really a fat girl with a smelly twat who's meal idea's originate from a can.
      c) Goes off into a fucktard rant - a sick little shit with a low IQ and mental and physical problems.

    16. Re:It drives me crazy by Anonymous Coward · · Score: 0

      I believe they promote developers. I don't know if those products are vetted or not, but I suspect the lawyers would be on to that sort of thing over there...

  3. Happening on App Store too by chrb · · Score: 5, Insightful

    "some of App Store's shiniest celebrities are among those that beam away your contact list in order to make hooking up with other friends who use the app smoother. " http://m.gizmodo.com/5885321/how-iphone-apps-steal-your-contact-data-and-why-you-cant-stop-it

    1. Re:Happening on App Store too by Anonymous Coward · · Score: 0

      It is more than a bit of stretch to make this some sort of equivalency.

    2. Re:Happening on App Store too by chrb · · Score: 5, Informative
      It's the same problem. From ArsTechnica:

      "Google has removed at least 15 Android apps from its official Play market after receiving outside reports they were malicious trojans that siphoned names, telephone numbers of email addresses of every person in the phone's contact list.

      ..In the background and without warning, they also obtained the phone number and a unique identifier of the infected device and sent the information in clear text to a remote server under the control of the software developers. "

      Which is exactly what some iOS apps are also doing. This is not an Android specific problem.

    3. Re:Happening on App Store too by gstrickler · · Score: 3, Informative

      5 of those 6 apps listed give you a warning and/or choice before they touch your contacts. Path is the only one that does it without your consent.

      I only have one of those 6 installed (FB), and I did not give it permission to access and synchronize my contacts, and I never will.

      As others pointed out, comparing that to malware is more than a stretch. You could make a case for Path qualifying because it did so without notification or consent. At most, that's one app that qualifies. Even if you do count it as malware, comparing it to malware that sends SMS messages that cost you money is absurd.

      If you want to point out malware on iOS, you should point to the 2-3 actual cases of malware that have been found in the App Store over the years, not 5 applications that notify you they're going to access your contacts.

      --
      make imaginary.friends COUNT=100 VISIBLE=false
    4. Re:Happening on App Store too by BasilBrush · · Score: 1

      "We've seen quite a few Android malware discoveries in the recent past, mostly on unofficial Android markets. There was a premium-rate SMS Trojan that not only sent costly SMS messages automatically, but also prevented users' carriers from notifying them of the new charges, a massive Android malware campaign that may be responsible for duping as many as 5 million users, and an malware controlled via SMS."
      It's in the fucking summary.

      It doesn't happen to iPhones.

    5. Re:Happening on App Store too by chrb · · Score: 1

      It's in the fucking summary.

      The text you quote is in the summary, but it has absolutely nothing to do with the article, which is about apps uploading contacts to remote servers.

      It doesn't happen to iPhones.

      Yes it does - there are iPhone apps which upload the contacts to a remote server.

    6. Re:Happening on App Store too by chrb · · Score: 1

      5 of those 6 apps listed give you a warning and/or choice before they touch your contacts.

      They only tested 12 popular iPhone apps. Out of the 12 apps tested, 6 uploaded your contact details to a remote server, 1 without any warning. There are 585 thousand apps in the App Store. If you just extrapolate that data, then you can estimate that 48750 apps are grabbing users contacts without consent, and 292500 apps are grabbing contacts with a warning.

      That would just be a very rough estimate, but the problem is obviously not limited to the popular apps that one security researcher happened to analyse, and which happened to transmit the contacts in plaintext across the network. (As he points out, if the app encrypts the contacts data, he wouldn't see it)

    7. Re:Happening on App Store too by gstrickler · · Score: 1

      And 2/3 of the people in my office are orthodox Jews. If you just extrapolate that, there are 200M Orthodox Jews in the USA.

      In other words, the sample size is too small and too selective to be of any use and your comment is complete nonsense.

      --
      make imaginary.friends COUNT=100 VISIBLE=false
    8. Re:Happening on App Store too by BasilBrush · · Score: 1

      There has been no iPhone malware that sends maliciously premium-rate SMSs. There has been Android malware that does that.

    9. Re:Happening on App Store too by X.25 · · Score: 1

      5 of those 6 apps listed give you a warning and/or choice before they touch your contacts. Path is the only one that does it without your consent.

      Android asks you for permission when you're installing the application.

      Is it Android's fault that users are stupid and give permission, then yell "MALWARE!!!"?

    10. Re:Happening on App Store too by scot4875 · · Score: 1

      There has been no iPhone malware that sends maliciously premium-rate SMSs. There has been Android malware that does that.

      Correct. Unfortunately, you're still missing the point.

      --Jeremy

      --
      Jesus was a liberal
    11. Re:Happening on App Store too by scot4875 · · Score: 1

      In other words, the sample size is too small and too selective to be of any use and your comment is complete nonsense.

      It is complete nonsense; however it is also completely reasonable to assume that there are tons of apps out there that do this surreptitious data harvesting. And it's the height of naivete to assume that having less information to protect yourself with (in this case, not knowing what permissions an app requires) is somehow better than being able to make an informed choice.

      --Jeremy

      --
      Jesus was a liberal
    12. Re:Happening on App Store too by gstrickler · · Score: 1

      Agreed. However, as we're all well aware, most users completely ignore the permissions Android apps (and Facebook Apps, etc.) request when installing. That's only useful info to an awake, aware, knowledgeable user. All apps should first be vetted by someone qualified to determine if the requested permissions or behaviors represent an inappropriate level of risk (Apple does some of that, but not enough), before they are placed on a store such as Google Play. Apple's approach is better for 95+% of users, but it's not best for everyone.

      --
      make imaginary.friends COUNT=100 VISIBLE=false
    13. Re:Happening on App Store too by Anonymous Coward · · Score: 0

      Love this, you won't sync your contact list so facebook doesn't have your friends numbers? Sorry mate, they already do. I bet you 90% of your friends already gave them all the info, all they needed to do then is reference this to your friends list proper.

      The only thing you get out of this is a bitch of a time updating peoples numbers when they go out drunk and lose their phone, and lack of all the nice profile photos in your contact list (which actually makes it much easier to scan through the 300+ contacts.)

      You may not want to give facebook your private info but merely having an account with friends attached has already given them everything they need. Not that they couldn't already gleam this from other sources already.

  4. disenchanted by Anonymous Coward · · Score: 0

    so, I bought an android and its nice and whatever, then i go to download a random free game or app from the google whatever place..

    it tells me it will know my location to play a free non multiplayer game? my other stored contacts information? wth?

  5. Permissions by pd0x · · Score: 3

    I think it's worth noting that the new malicious applications found by McAfee researchers were video trailer applications that overtly requested the READ_PHONE_STATE and READ_CONTACTS permissions at install time.

    While it's clear that users have limited comprehension of the permissions requested at install time (for instance see: Android Permissions: User Attention, Comprehension, and Behavior) it is rather suspicious that a trailer application require access to your contact list. From the sounds of it the malware doesn't do much other than siphon off your contact list & some identifying information (Android ID & phone number).

    Should it be removed from the Android market? Yes. Is it the best example of subversive Android applications? Probably not.

    1. Re:Permissions by chrb · · Score: 1

      The question is, should apps be allowed to upload your contact data? Both Android and ios apps allow this, and some of the most popular apps do it.

    2. Re:Permissions by alostpacket · · Score: 4, Informative

      You don't need a permission to read the Android Device ID, however READ_PHONE_STATE gives them access to the ESN, MEID, IMEI, IMSI etc...

      The other worrisome problems with that permission are that:

      1) It is granted by default for any apps targeting 1.5 or below, and the user is not warned about it.

      2) It also allows some access to see incoming and outgoing numbers when a call is taking place.

      --
      PocketPermissions Android Permission Guide
    3. Re:Permissions by pd0x · · Score: 2

      You are 100% right about the Android Device ID but is less of a privacy concern than the ESN, IMEI, etc that is protected by READ_PHONE_STATE. It is randomly generated, and can change with factory reset or by means of root access. The use of the Android Device ID for the purpose of tracking app installations is clearly supported behavior with the caveats I mention outlined.

      Worry #1 is probably not that devastating a concern. The Google platform distribution shows only 0.3% of users are running 1.5 or below at this point. It is my experience that few apps support Cupcake and below.

    4. Re:Permissions by pd0x · · Score: 3, Interesting

      It seems that a good number of apps do this to "find friends" using the app. It would certainly be much better if upon app installation your associated account e-mail was hashed using SHA256 (or some alternative hashing algorithm) and stored by the service. Rather than upload a users entire contact list the apps could then submit hashes of contact e-mail addresses looking for matches without being able to identify users not using the service in question.

    5. Re:Permissions by nabsltd · · Score: 2

      it is rather suspicious that a trailer application require access to your contact list.

      When every app with a "social networking" component requires access to the contacts list, it's not really that suspicious.

      If you didn't install any app that required access to your contacts, you pretty much won't install any games, multimedia manipulation apps, etc. The only real thing this malware did to get easily caught was to not supply some sort of lame "recommend" feature. Once an app needs access to your contacts and the Internet, it's basically malware waiting to happen.

    6. Re:Permissions by pd0x · · Score: 1

      That's a fair perspective. I suspect my app installation habits differ from most users.

    7. Re:Permissions by Anonymous Coward · · Score: 0

      Well, if you are into the whole social network hype, you kind of deserve to get tracked and ripped off. You basically asked for it yourself.

      "Hey every bad guy out there, here, have all information you want about me!"

    8. Re:Permissions by cynyr · · Score: 1

      Yes it is, lots of my apps do not have access to the internet, and some only over wifi. I'm also using ad-away and droid wall along with CM7's permission blocking. There are still i'm sure a few things that get by, I see a handful of ads on "words for friends" for example.

      --
      All of the above was encrypted with a Quad ROT-13 method. Unauthorized decryption is in violation of the DMCA.
    9. Re:Permissions by Electricity+Likes+Me · · Score: 3, Insightful

      Actually the real problem is you can't hit "no" and continue with the installation.

      Knowing what an app wants to do is one thing, but it doesn't tell me whether it's actually malicious. Getting an intelligent list of what it tried to do would help. Being able to tell my tablet to disallow or just lie about certain things would help more though - i.e. prevent access to contacts data, or, better, pretend I don't have any contacts data.

    10. Re:Permissions by Anonymous Coward · · Score: 0

      Doesn't matter what version the phone is running, if the app targets the lower api it uses the lower api. So.. I make an app.. use the 1.5 sdk as target and bam!

    11. Re:Permissions by Anonymous Coward · · Score: 0

      This wont happen, everyone would say no to ads, and honestly, thats how goolge makes it money on android.

    12. Re:Permissions by nabsltd · · Score: 1

      I'm also using ad-away and droid wall along with CM7's permission blocking.

      Well, yeah, if you want to void the warranty on your phone and spend a lot of time keeping up with exactly which version of the third-party OS you run will work with your phone, I suppose that will work.

      Unfortunately, it's not really an option for 99% of people.

  6. Freedom by Anonymous Coward · · Score: 0

    Enjoy that freedom, y'all.

    1. Re:Freedom by Anonymous Coward · · Score: 0

      We will. Enjoy your locked down, one-trick pocket appliance.

      "They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
      --Benjamin Franklin

  7. When did the trolls start posting articles? by Anonymous Coward · · Score: 1

    Not only have there been numerous problems with malware on iOS, a recent study (too lazy to search for it) randomly selected a bunch of apple-vetted apps and apps from a jailbreak-only iPhone app store, and found that a larger percentage of apple app store apps are malware than ones from the third-party unvetted store...

    1. Re:When did the trolls start posting articles? by PNutts · · Score: 1

      Not only have there been numerous problems with malware on iOS, a recent study (too lazy to search for it) randomly selected a bunch of apple-vetted apps and apps from a jailbreak-only iPhone app store, and found that a larger percentage of apple app store apps are malware than ones from the third-party unvetted store...

      Seems legit.

    2. Re:When did the trolls start posting articles? by BasilBrush · · Score: 4, Funny

      I've seen a recent study (too lazy to search for it) that says that the Queen of England is a Lizard.

    3. Re:When did the trolls start posting articles? by thetoadwarrior · · Score: 1

      Yeah and I can't understand why people get all upset over Hitler. After all Stalin killed people too!

    4. Re:When did the trolls start posting articles? by Anonymous Coward · · Score: 0

      Every single president of the United States has murdered people as well.

    5. Re:When did the trolls start posting articles? by scot4875 · · Score: 1

      Heh, the funny thing is that GP is correct; this research did happen, the articles do exist, and there was a nice Slashdot discussion about it that you apparently missed. (oh noes! You failed to white knight for Apple! Are they going to make you revoke your membership card?)

      However, I'm too lazy to do his Googling either -- I honestly don't care if you remain ignorant.

      --Jeremy

      --
      Jesus was a liberal
    6. Re:When did the trolls start posting articles? by BasilBrush · · Score: 1

      Lazy and full of bullshit.

  8. Google and Market Choice? Perhaps. by __aazsst3756 · · Score: 1

    One argument is that this is simply a market choice, A) a free and open market that is easy to upload malware, or B) a closed market that is difficult to upload malware.

    Perhaps, but I believe you can have both. If a third party was able to find this malware in the market, why can't Google? Google simply needs to make this a priority, and do a better job. Scanning and making sense of the data really is their core strength.

  9. And Apple addressed it by daveschroeder · · Score: 3, Insightful

    Apple: App Access to Contact Data Will Require Explicit User Permission

    I guess you forgot that part.

    And the part about how these apps weren't "malware", irrespective of whether they were doing something previously allowable without explicit user permission.

    So it's not at all accurate to say that it's "happening on the App Store too".

    1. Re:And Apple addressed it by chrb · · Score: 4, Informative

      And how is that solution different from Android? Android already requires users to authorize apps to read contact details, the problem is that most people don't care. These Android apps are being called malware because they upload the contacts list without permission, which is exactly the same as many ios apps do.

    2. Re:And Apple addressed it by BasilBrush · · Score: 1

      And how is that solution different from Android?

      On the one hand you've got iPhone Apps sending contact details - previously without user permission - now with user permission. Although in either case not with malicious intent.

      On the other hand you've got Android apps sending premium rate phone numbers without the users permission.

      And you\re having trouble differentiating?

      Or were you just trying to ignore the type of malicious app mentioned in the summary, because it's bad news for Android?

    3. Re:And Apple addressed it by 93+Escort+Wagon · · Score: 5, Interesting

      And how is that solution different from Android? Android already requires users to authorize apps to read contact details, the problem is that most people don't care. These Android apps are being called malware because they upload the contacts list without permission, which is exactly the same as many ios apps do.

      Either you've never looked into this, or you're dissembling. I have an Android phone; and at the time an app is installed Android provides a somewhat generic list of all the things the app will have access to - there are usually a half dozen or so items on that list, and it would be very easy to overlook contact Info since it's somewhat buried among the generic stuff like phone state, network access, and so on.

      With iOS, when an app tries to access Contacts - you get a pop-up at that time telling you that and asking if it should be allowed. It's a dramatic improvement over what it used to be, and over what Android currently does.

      --
      #DeleteChrome
    4. Re:And Apple addressed it by chrb · · Score: 1

      On the one hand you've got iPhone Apps sending contact details - previously without user permission - now with user permission. Although in either case not with malicious intent.

      And how would you know that it is without malicious intent? There are many, possibly hundreds, of iPhone apps that grab the contacts, how do you know what happens to those contact details once they are uploaded?

      On the other hand you've got Android apps sending premium rate phone numbers without the users permission.

      That is not what the article is about.

      Or were you just trying to ignore the type of malicious app mentioned in the summary, because it's bad news for Android?

      I was responding to the article, not the summary. The summary has nothing to do with the article. The article is claiming that users contact details can be grabbed by Android apps. The same is true of iphone apps.

    5. Re:And Apple addressed it by AmberBlackCat · · Score: 1

      I would LOOOOOOVE to be able to install Android apps and then click no on that popup after the fact. Because adding unnecessary permissions is a favorite activity of Android developers. Phone owners should be able to change any permissions on an individual basis at any time without rooting the phone.

    6. Re:And Apple addressed it by chrb · · Score: 1

      So Android prompts for permissions at install time, and iOS prompts for permissions at runtime. That is not a major difference: it is exactly the same system of explicitly asking the user for permissions, it just happens at a different time. The majority of users are just going to click "ok" anyway. To claim that the iPhone is somehow protected while Android is vulnerable is really stretching.

    7. Re:And Apple addressed it by Anonymous Coward · · Score: 0

      Upon entering a public space, someone requires you to agree to assume the risk that violence may occur.

      Yes or no?

      Someone walks up to you and asks if they may punch you in the face.

      Yes or no?

    8. Re:And Apple addressed it by BasilBrush · · Score: 1

      That is not what the article is about.

      It's in the summary. More importantly it's in Android phones. But you want to ignore it because it's not convenient for your favoured platform.

    9. Re:And Apple addressed it by Electricity+Likes+Me · · Score: 3, Interesting

      This, so much this.

      Telling me something wants a bunch of vague permissions is about as useless as the iPhone "This app may read private data" message, since pretty much everything wants to do that.

      What I want is to be able to see exactly what it's planning to do. If an eBook reader app wants SD cart access, maybe I want to only give it access to the "Books" directory on the card, since it has no reason to look anywhere else. If something wants full web access...well I'd like to prevent that, and then see if the app has any actual problems. Or I'd like to be notified about the hostname's being contacted and whitelist/blacklist them selectively.

      Of course, these aren't Android or even smartphone specific problems IMO - it's a problem with providing user security on every single platform in existence. No one's made it suitably simple to tell what an app is doing, or wants to do, and allow or deny that with reasonable, but not owerpowering, fidelity.

    10. Re:And Apple addressed it by Anonymous Coward · · Score: 0

      I agree, and Google's aware of the fact that many users would love this option. I've seen a petition floating around somewhere. But think about it for a few seconds - all you have to do is block an application from creating network sockets and then it can't download any ads. Why would (profit-seeking) developers write an app if you could disable ads that easily.

      Although it doesn't make a difference in the end - for those apps that request network access when they have no business doing so, you can just turn on airplane mode.

    11. Re:And Apple addressed it by thegarbz · · Score: 1

      there are usually a half dozen or so items on that list, and it would be very easy to overlook contact Info since it's somewhat buried among the generic stuff

      And there's the crux of it right there. People are prepared to read only the first line of any warning they are getting. But OH MY GOD SIX LINES? My privacy and data aren't worth the 6 seconds it takes to read these!!!

      The reality is that most apps will actually require fairly few permissions, so if I'm downloading a game for instance my alarm bells instantly go off when I see more than 2-3 permissions being requested to begin with.

    12. Re:And Apple addressed it by damium · · Score: 2

      Some custom builds have this feature on android (CM7 for one) but revoking permissions often leads to the app crashing when it tries to do something it expects to work and doesn't check for failure. I've revoked contact, gps, and/or network permissions for apps that I don't use those features on with no ill effects unless the feature is used.

    13. Re:And Apple addressed it by TheRaven64 · · Score: 1

      So you're saying you want a phone with the security model that Symbian had for the last ten years? Everything old is new again...

      --
      I am TheRaven on Soylent News
    14. Re:And Apple addressed it by Anonymous Coward · · Score: 0

      Upon entering a public space, someone requires you to agree to assume the risk that violence may occur.

      Yes, that's a totally valid analogy, because an app reading the user's contact list is a random event outside the control of the app developer. A better one would be "upon entering a club, the bouncer tells you that if you come in he reserves the right to beat you up whenever he feels like it".

    15. Re:And Apple addressed it by AmberBlackCat · · Score: 2

      The operating system should be sending "dummy" data instead of no data for these requests.

    16. Re:And Apple addressed it by Electricity+Likes+Me · · Score: 2

      Pretty much this. If the feature can't be barred off (and by most accounts, it probably shouldn't be since I don't really wants apps checking to see what kind of security environment they're in - let developers figure that one out) then the OS should lie about what's out there. Disallow net access? Then mimic no connectivity. Disallow contacts access? Tell the app I have no contacts, or better - give me an option to send a random dummy list of contacts.

      It feels like that would be the right step away from full-sandboxing - enough interoperability to be useful, while letting me make sure things are well behaved before I let them near my actual data.

    17. Re:And Apple addressed it by gl4ss · · Score: 1

      I would LOOOOOOVE to be able to install Android apps and then click no on that popup after the fact. Because adding unnecessary permissions is a favorite activity of Android developers. Phone owners should be able to change any permissions on an individual basis at any time without rooting the phone.

      but but.. that would make the security system exactly like j2me was meant to be!

      (no shitting, I wouldn't put it past the patent bullshit that it would be one of the reasons why it's not like that on android..)

      "allow for 24 hours" etc things asked when the app needs a permission would be nice. sms could have just "only this time" too. oh and location etc should have just a "provide fake location" option, to prevent crashing of the app. sure, it would be shit for location based shit games but they're fucked with hackers anyways.

      --
      world was created 5 seconds before this post as it is.
    18. Re:And Apple addressed it by damium · · Score: 1

      Dummy data wouldn't be good for things like contact info unless you pulled it from known invalid data. What if you get someone's real phone number or email address with random data? Succeeding with no data or reliable fake data is usually better. Evented failures (like no net access available or gps failed to find location) where possible are better. All of these can be detected with enough effort on the developer's part in much the same way that some web developers are detecting ad blocking and script blocking.

      Most users will continue to grant all access to everything that asks for it without even reading or wondering why it is needed.

    19. Re:And Apple addressed it by Anonymous Coward · · Score: 0

      You neglected to mention that for the past 4 years, apps have been raping your contact list without any mention of it. This popup permission is a VERY recent development.

      See "Dragon naturally speaking" as a legit example. People were surprised to find there contacts on remote servers.

    20. Re:And Apple addressed it by Anonymous Coward · · Score: 0

      Uhm, it WAS for the past four years. This contact permission popup is an extremely recent development. To claim that i users have been protected for all these years would be negligent at best, outright lies as worst.

  10. Re:Google and Market Choice? Perhaps. by __aaltlg1547 · · Score: 2

    Where is their incentive?

  11. NO MORE WITH THE HAND HOLDING by Anonymous Coward · · Score: 0

    You are responsible for what you install, and the consequences thereof. Enough with pushing responsibility to another party. If you install something you better vet the code.

    The attitude of the USA has become the prime example of a irresponsible nation, denouncing personal responsibility and pointing fingers.... No small wonder we're a failing country

    1. Re:NO MORE WITH THE HAND HOLDING by Anonymous Coward · · Score: 0

      You are responsible for what you install, and the consequences thereof. Enough with pushing responsibility to another party. If you install something you better vet the code.

      The attitude of the USA has become the prime example of a irresponsible nation, denouncing personal responsibility and pointing fingers.... No small wonder we're a failing country

      Which country vets the code on their smartphone apps? And I assume you "vet the code" of the OS(s) and apps you use? And remember "vet" means a thorough examination and critical appraisal. It is enviable that you know all the exploits and which apps take advantage of them. Please share.

  12. Re:Google and Market Choice? Perhaps. by nurb432 · · Score: 1

    I tend to agree, not at least doing automated scanning is irresponsible. At least make an attempt..

    I would also hope there is some prosecuting involved when these apps are found and removed.Otherwise, they will just try again.

    --
    ---- Booth was a patriot ----
  13. Security researcher lol by Anonymous Coward · · Score: 0

    I made a "proof of concept" key that lets intruders into Carlos castillos house I suggest all members of his household buy my "security services"

  14. my favorite is when they steal ALL my info and... by Anonymous Coward · · Score: 0

    My favorite android scam is when they create fake reviews and when you open the app you automatically run scripts to like ans subscribe to things on facebook and other social networks, and of course they love to use your email app to send things out. It's amazing how all of it works but also a pain in the rear-end to find out which app is doing all of this. Unlike a PC, tablets or smart phones are ridiculously hard to administer any solution. Antivirus apps never seem to work for me on those things. I agree with the whole authentication thing but what would work even better is if google's lawyers would go out and charge every developer that maliciously fked up people's devices on purpose.

  15. And yet... by Anonymous Coward · · Score: 0

    And yet slashdotters like to make fun of WP7 even though by most all accounts it is a very good OS. Looks like the shoes is on the other foot nowadays.

    Surely people on this site will now make fun of Android like they make fun of Windows, right? I mean, they wouldn't be openly hypocritical, right?

  16. Google gathering ripoff-artists by Jens+Egon · · Score: 3, Insightful

    Yes, there's a significant problem here.

    The problem is that Google does NOT like free apps. Google make their money from advertizing, and on Google Play they're actively hiding whether are apps paid for by advertizing. This means that FOSS is having a hard time there. And cheap rip-offs of various kinds are having a field day. Once a thriving community of rip-off artists have been gathered bad things(tm) happen (even more).

    By the way. Congratulations, the professional anti-Google scaremongers found a semi-reasonable point to criticize. Well done.

    And just enough off-center from the real problems not to bother your Corporate Overlords, nice.

  17. Thanks, George W. and US' morons! by Anonymous Coward · · Score: 0

    The obvious thing to do when you cannot protect people is help them defend themselves (martial arts, gun wielding, etc.)

    The safe choice would be recommend to users not to use real names, to protect themselves from evildoers. But no, they had to enforce he requirement for people to use real names (because there could be a terrorist among us).

    Now, maybe I'm dumb -- but even I know a terrorist would lie about his name -- while normal non-aggressive dudes think they can be honest and say the truth, because they haven't anything to hide.

    So, the policy is give criminals a huge database of names (and locations!) to fetch potential victims or aliases. Mission accomplished!

    With people that wise in government, I guess the US really doesn't need enemies.

    1. Re:Thanks, George W. and US' morons! by Anonymous Coward · · Score: 0

      Now, maybe I'm dumb -- but even I know a terrorist would lie about his name -- while normal non-aggressive dudes think they can be honest and say the truth, because they haven't anything to hide.

      So, the policy is give criminals a huge database of names (and locations!) to fetch potential victims or aliases. Mission accomplished!

      With people that wise in government, I guess the US really doesn't need enemies.

      Good guess there- definitely dumb.

      Phonebooks provide exactly that information and nobody's calling YellowPages a supporter of terrorism.

  18. A little help here? by PopeRatzo · · Score: 2

    Would it have killed all the "security researchers" who wrote or compiled all the articles behind all the links in this story to maybe list the apps that have been found to have trojans?

    I mean, Android users might find that information useful and it might actually help minimize the damage from these apps.

    Right now, it's like a news story that tells us "Three common home products have been proven to cause deadly forms of cancer" without mentioning which products they are.

    --
    You are welcome on my lawn.
  19. Blah blah blah... by Petersko · · Score: 1

    "Well, if you are into the whole social network hype, you kind of deserve to get tracked and ripped off. You basically asked for it yourself."

    And if you got a telephone, you deserve to be called by telemarketers and scam artists. And if you got a car you deserve to be carjacked. And if you have electricy you deserve to be electrocuted.

    You basically asked for it yourself. Those are all possible consequences of choosing those products.

    Stay in your luddite cave and disconnect. Toodles.

  20. It's what I've been saying here all along... apk by Anonymous Coward · · Score: 0

    Getting "downmodded" for it rampantly by offended "penguins" no doubt: ANDROID's @ the "top-of-the-food-chain" on smartphones, & what happens then? YOU GET ATTACKED!

    * It's no different than what has happened to Windows for decades now really - once you're the "top dog" (most used/biggest market-share)? You're going to be "targetted for termination!"

    I use this analogy here a lot in regards to it:

    Malware maker of today, are criminals (not just kids in their basement doing it for shits & giggles) - they're after your monies &/or personal information (like Credit Card #'s, which is of course again, your "$"):

    They're just like pickpockets (my fav. to compare them to) - They don't go after OS's that aren't widely used, and avoid ones that "techno geeks" use on PC's (like Linux, which also gets the benefits of "least used" in 1 respect - 'security-by-obscurity' thru lower marketshare/usage on PC's)...

    They go where the LARGEST #'s of folks are, & especially "non-techie" types: Smartphones = ANDROID (like for PC's its Windows).

    That yields a BIGGER/BETTER "ROI" in terms of time put in for creating their malwares (which, on an 'educated guess' from building freeware/shareware on the side myself for many years ontop of work-related duties in the past, is about 1 month tops) - So, they attack ANDROID like mad!

    Linux derivant or not, it's also PROOF that even Linux != invulnerable (despite YEARS of hearing that on /. along the lines of "Linux = Secure & Windows ! = Secure)).

    APK

    P.S.=> It was BOUND TO HAPPEN, & here 'tis folks... too bad, because ANDROID's pretty nifty stuff on smartphones, but in a way (making lemonade outta lemons)? It's NOT BAD: Simply because these malware makers are THE BEST "R&D" THERE IS FOR ANDROID AS AN OPERATING SYSTEM - they point out where the "holes" are so that GOOGLE can "shore them up". Always a 'bright-side' in everything...

    ... apk

  21. Yes, tyranny is better. by Anonymous Coward · · Score: 0

    "Whatever critics may say about China, which is significantly more selective about the freedoms it allowss, complaints about crime aren't one of them"

  22. Re:Google and Market Choice? Perhaps. by thetoadwarrior · · Score: 1

    Same reason their customer support is shit and your only point of contact really is a dumb messaging board service. Google, imo, isn't that bothered about looking after people.

  23. GOOD POINT & I agree (slightly diff. reasons) by Anonymous Coward · · Score: 0

    Whenever I see an article dealing in malware, I have found that the BETTER ONES list actual IP addresses OR host-domain name lists for botnet C&C servers (which I add the ip addresses to my software firewall rules table in Windows via powershell & the host-domain lists to that AND my hosts file (for layered-security/defense-in-depth purposes).

    * After all, you're "reading up" on the stuff, to GET pertinent information, & to me? I hear exactly what you're saying... it's NOT ENOUGH to say "there is malware here" but where it's coming from (or in your case, its name).

    APK

    P.S.=> To me? It's like getting ready to eat a good meal, only to find it has NO flavor (or I suppose for a better analogy for us both? No nutritional value..)

    ... apk

  24. Re:It's what I've been saying here all along... ap by cynyr · · Score: 1

    I don't think that anyone said that linux with a dumb user is secure. What was the point was back then you could install malware on a windows computer simply by connecting to it, loading a malformed picture, or any other number of things that even a smart user couldn't prevent.

    Now how many of these apps can self install on an android phone without the owners knowledge? how is that any different that say, around the year 2000 when your mom/grandma/uncle/younger brother would just click and download and install any link/program they found on the internet? People really need to realize that these smartphones really are just tiny portable computers that happen to have phone programs installed by default, all the same things you have to do on your computer to keep it safe apply on them as well.

    --
    All of the above was encrypted with a Quad ROT-13 method. Unauthorized decryption is in violation of the DMCA.
  25. Typical Google. by DaneM · · Score: 2

    Google's always been awful about not checking its ads for malware, so I see this as no big surprise. In my experience, the text links at the top of my Gmail page have been about 95% scam and malware sites, akin to the stuff I find in my spam box. (I've since installed a browser extension to disable such ads.) Google has thus shown a previous utter disregard for ensuring the sanitation of their profit centers, so I fully expect this new "app store" (no, I don't care that it's called "Google Play;" I'll call a spade a spade, thank you very much) will be much the same until Google gets sued or some such. (In other news, I seem to recall them being sued in Australia or the EU for their fraudulent ads.)

  26. freeeeeedom by Garybaldy · · Score: 1

    H'm the freedom to do whatever I want within the law. With the risk of something possibly going wrong.
    Or
    Being ruled with an iron fist. With little chance of anything going wrong. But no guarantee.

  27. That doesn't sound feasible. by phorm · · Score: 1

    a) They'd have to have such a deal with all carriers for it to be feasbile
    b) Not everybody *HAS* a carrier (think: tablets/wifi)
    c) Who cares if the carriers have app stores?

    I think that perhaps instead of carrier, you meant manufacturer? Even in that case you've already got the "amazon app store" etc though...

  28. Halting Problem by tepples · · Score: 1

    not at least doing automated scanning is irresponsible

    How would you solve the Halting Problem to make automated scanning feasible?

  29. Right - that was part of my point (see quote) by Anonymous Coward · · Score: 0

    "They're just like pickpockets (my fav. to compare them to) - They don't go after OS's that aren't widely used, and avoid ones that "techno geeks" use on PC's (like Linux, which also gets the benefits of "least used" in 1 respect - 'security-by-obscurity' thru lower marketshare/usage on PC's)... They go where the LARGEST #'s of folks are, & especially "non-techie" types: Smartphones = ANDROID (like for PC's its Windows)." - MYSELF -> by Anonymous Coward on Saturday April 14, @06:16PM (#39688889

    I don't call them "dumb" though - just ignorant of things online... innocents really, when you come right down to it.

    * Hence, the boldes portions of the quotation above... Again though, on malware makers (even though they're misguided thieves & scum basically): They DO show GOOGLE (& perhaps even the Penguins crew that maintains & codes Linux itself) where the holes are, or potentials for them, & gives them impetus + perhaps even ideas how to "shore them up"...

    AND?

    I *think* you're going to like THIS:

    "you could install malware on a windows computer simply by connecting to it, loading a malformed picture, or any other number of things that even a smart user couldn't prevent." - by cynyr (703126) on Saturday April 14, @07:53PM (#39689545) Homepage

    This 'smart user' can, even on Windows (modern Windows, that is, even running as admin & it's only about 5 minutes time to setup really).

    I run as a member of the "administrator class" users, but in a special "limited administrator class" (what I call it @ least) type user!

    Just like you see on how MacOS X makes you LITERALLY "login" to install apps, like it or not.

    So, how to stop ME, from screwing myself on taking chances on messing up as you state?

    Even when the crap might be trying to install without me realizing it, say, invisibly??

    This is how, & it works - So, yes, just like MacOS X does it?

    It can be done on Windows, and I am honestly surprised it's not (especially when running as admin, vs. what you noted above, because this? This stops that kind of crap, even when running as admin):

    The settings to examine & change are as follows in gpedit.msc &/or regedit.exe:

    ---

    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Admin Approval Mode for the Built-in Administrator account

    OR

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v FilterAdministratorToken

    (Set as ENABLED)

    ---

    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode

    OR

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin

    (Set as PROMPT FOR CREDENTIALS)

    ---

    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Behavior of the elevation prompt for standard users

    OR

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorUser

    (Set as Automatically deny elevation requests)

    ---

    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Detect application installations and prompt for elevation

    OR

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v EnableInstallerDetection

    (Set as ENABLED)

    ---

    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Only elevate UIAccess applications that are installed in secure locations

    OR

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v EnableSecureUIAPaths

    (Set as ENABLED)

    ---

  30. Bad robot by Anonymous Coward · · Score: 0

    "It's almost like they were built specifically to share information"

    I see, so you think that because they're built to share SOME information with SOME people when under MY permission, that this is some sort of blanket right to grab all my contact details and upload them to their servers to use as they will?

    There are two parties involved in a conversation, and they don't even really have 1 of those peoples permission to grab that contact detail. Just because I consented to Bob having my private telephone number, doesn't mean I granted Mark Zuckerberg the right to that data and Bob cannot give permission on my behalf and didn't anyway.

    1. Re:Bad robot by Grishnakh · · Score: 1

      If you use Facebook on your phone, you should be happy for Mark Zuckerberg to have access to all your private phone numbers and other data. You'd have to be blind to not know by now that Facebook doesn't care one whit about your privacy, so by using their app on your phone you should expect they would grab all the data they can.

    2. Re:Bad robot by Anonymous Coward · · Score: 0

      If you use Facebook on your phone

      From the GP:

      Just because I consented to Bob having my private telephone number, doesn't mean I granted Mark Zuckerberg the right to that data

      This also affects people who don't use Facebook, on their phones or otherwise.

  31. (Mostly) Pointless Finger Pointing by c1t1z3nk41n3 · · Score: 1

    I'm not sure why this has quickly devolved into a discussion over whether Android or Apple is less safe in regards to the apps available for it. A far more useful discussion would be how can we as end users protect ourselves from these practices. I like to think I'm a cut above the average person (not necessarily the average slashdotter) by being somewhat selective about the apps I install, paying attention to the permissions they request, and running an iptables based firewall to whitelist the apps that I allow network access to. Even with that though I can't claim to be immune to downloading an app that has some malware on the backend. I've resisted the idea of antivirus/antimalware programs so far as I find that my phone's resources are quite limited enough as is. I'm not all that concerned about premium SMS either as I run a prepay sim with no extra funds on it. Can anyone point out any other obvious practices I may be missing?

  32. Time for more android distributors by dutchwhizzman · · Score: 1

    It's about time Google is getting serious competition from competitive android distributions. I for one would like very much to be able to store my data on non-google servers (preferably my own) and use a competitors apps store that is trustworth and not laden with (google) ads. It works for Linux, it should work for Android. It's about time we separated the software from the hardware and the service providers. Anti competitive pacts like the US phone companies almost certainly seem to be having should be looked into. It's virtually impossible to get a decent phone separate from an affordable plan there, even tho there will be plenty of people wanting to just purchase a phone and get a cheap plan with it, that suits their needs. This is all a tinfoil hat size of a conspiracy that seems to be going on between the phone vendors and the operators, making free choice for buyers impossible.

    --
    I was promised a flying car. Where is my flying car?
    1. Re:Time for more android distributors by Fri13 · · Score: 1

      Erh.... You clearly don't know that Android has nothing to do with Google services or applications.

      Google services are used trough Google applications, they are called as "gapps".

      Gapps do not belong to Android, as they are third party applications what only Google offers trough Play and operators and Phone OEM preinstall them because people wants Google services (search, maps, navigation, cloud sync to contacts, email etc) and because Google pays to them from every search what is made trough Google Search widget (that search bar on launcher desktop).

      I have used many Android phones what does not have gapps installed. But the phone feels just half smart then.

      There are as well official Android phones what has gapps replaced with Microsoft versions (hotmail, bing etc).

  33. There is a lot Google could do about this by DrXym · · Score: 1
    If a dev writes a game that needs permissions to look at my address book or send / receive SMS messages then alarm bells should ring in Google land. If a new developer dumps 5 or 6 apps on the market then alarm bells should ring. If a developer pushes out anything with "sexy" in the title then alarm bells should ring. If a dev releases a substantially sized free app which contains no advertising APIs of any kind then alarm bells should ring. And all apps should be subject to a randomized security scan either during submission or post submission.

    What would outright suck however is Google becoming more like other stores and putting a delay between upload and release. I LIKE the fact that I can rapidly upload updates to my apps. There have been occasions where I've turned around an update in under 30 minutes. If I tried to turn around a fix on any other store, e.g. Amazon's or the Blackberry store I'd be looking at the better part of a week for an update to appear. I have no idea what the hell they do in that time but somehow I doubt they're looking for malware or would be capable of spotting it even if it were there.

  34. Yeah well, duh by SmallFurryCreature · · Score: 1

    The old "those who trade freedom for security, soon have neither" springs to mind.

    Because believe it or not, iOS and OSX are not immune to malware, virusses and trojans. They just are more hidden, so that when it happens, their users are less prepared for it.

    Android is open, anyone can make an app. It is a free market. Apple is closed, your app has to be be vetted. It is a closed market. Closed markets are ALWAYS easier and safer then free markets. But the vetting takes place outside your control and you never can tell in advance when it will turn out to be harmful. Take Sony refusing to allows multiplayer for ME3. The windows platform for that game could never have such a blockage. But then, there is zero quality control for Windows games.

    You just got to search the Android market to see a LOT of crap, not just malware but apps that are valid enough as code but the idea they try to push is a scam itself. Pyramid schemes, credit rating boosters, signal, battery, memory boosters. But these same applications exist for Windows. They do NOT appear on the game consoles. But what do you rather have? The save walled garden or the free wilderness?

    To be honest, most of the time the save walled garden. It is just easier and live is already to complicated. The sad thing however if you are in that walled garden to long, the wilderness might have disappeared and you no longer have an option.

    Think Amazon destroying the physical bookstore so that when they next delete a book, there is nowhere else to get it. If Apple owned 99% of the market, there would be no more malware. But what then would be defined as malware would be Apples definition and not yours. And I don't like that idea one bit.

    --

    MMO Quests are like orgasms:

    You may solo them, I prefer them in a group.

  35. Android team needs to focus on the user, for real. by Anonymous Coward · · Score: 0

    First of all, why do people feel the need to point out issues in Apple products _every_ time there is an article about Android? So, this is the thing. The Andy Rubin hypocrite loves to put carriers (not users) first, and that is his top priority. That's what the asshole is talking about every time he says the word "ecosystem", which is about 1000 times every hour.

    These idiots insist on having a minuscule team and will make it as difficult as possible for anyone from the outside to contribute and help them. They exist inside of Google but have very little contact with the rest of the company and almost nobody in engineering likes them, particularly the Rubin asshole.

    The obvious solution to this is for the Android team to really focus on the user, the user, not the carrier. Stop wasting time on shit nobody cares about like new fancy filters for the camera and focus on the real problems. Also, the SDK is a fucking joke.

    --
    Disclaimer: I work for TAGA (The Arrogant Google Assholes)

  36. i have a problem with this by corvax · · Score: 1

    The problem is "security" companies who make "proof of concept" code and release it into the wild . Instead of helping the companies with which they've found the flaw. This reminds me of the mob asking for protection money they release the code then they say look look android isn't secure UNLESS you buy our product.

  37. Fancy phones? Pah by elbbit · · Score: 1

    I'm still chatting with my Nokia 8250. No, seriously, I do.

  38. Your preinstalled HTC Facebook app harvests it.. by Anonymous Coward · · Score: 0

    Your preinstalled HTC Facebook app harvests it.. whether you use it or not. Or even agreed to this.

  39. Re:Your preinstalled HTC Facebook app harvests it. by Grishnakh · · Score: 1

    Um, I don't know about your phone, but my HTC Sensation doesn't have any pre-installed Facebook apps that I could find. It has some crappy "Friend Stream" widget that you can install on one of your main screens if you choose, but that's not set up by default, and it only runs if you install it (it's a widget, not an app). I never installed mine, so it never runs. Besides, to allow it access to your Facebook account, you have to actually configure the widget with your FB account info. It can't magically figure out your FB username and password.

  40. Re:It's what I've been saying here all along... ap by Anonymous Coward · · Score: 0

    That's the thing. Practically none of the malwares that have been reported have been widespread (50,000-100,000 cumulative infected installs, none of which are currently available on the Android Market. All of these malwares can be uninstalled by going through the standard uninstall procedure. All of these malwares also require the user to consent to such permissions as "SERVICES THAT COST YOU MONEY / Send SMS".

  41. time for... by CimmerianX · · Score: 1

    Avast for Android.

    A/V, malware scanning, limited firewall, and theft protections.....

    I use it on every device.

  42. How many can install w/ out users knowing? by Anonymous Coward · · Score: 0

    "Now how many of these apps can self install on an android phone without the owners knowledge?" -

    On ANDROID? Here's an example of it:

    http://www.theregister.co.uk/2010/11/10/android_malware_attacks/

    * So please: DON'T EVEN TRY TO MAKE IT SOUND LIKE "IT CAN'T HAPPEN ON ANDROID", because it clearly can, and ANDROID (thus Linux) IS NO MORE SECURE THAN ANY OTHER OS!

    Linux just has less users (Linux on the desktop) WHICH IS WHY IT'S NOT TARGETTED AS MUCH (not as much "ROI" for the malware makers attacking 1% of the total market when roughly 94% of it is on Windows & 5% is on MacOS X).

    APK

    P.S.=> PERTINENT QUOTE/EXCERPT FROM THE ARTICLE LINK ABOVE:

    No permissions necessary

    By Dan Goodin in San Francisco â Get more from this author

    Posted in Malware, 10th November 2010 22:09 GMT

    "Researchers have disclosed bugs in Google's Android mobile operating system that allow attackers to surreptitiously install malware on users' handsets."

    "The most serious of the two flaws was poignantly demonstrated on Wednesday in a proof-of-concept app that was available in the Google-sanctioned Market. Disguised as an expansion for the popular game Angry Birds, it silently installs three additional apps that without warning have access to a phone's contacts, location information and SMS functionality and can transmit their data to a remote server."