Friday, 4 May 2012

Malicious apps hosted in Google store turn Android phones into zombies

quote [ Google has been caught hosting more than a dozen malicious titles in its official Android app market. Some had been downloaded tens of thousands of times and turn smartphones into zombies that await commands from their attacker overlords, security researchers said. ]

This is my 100 post. Never thought back when I started I would get to type that. Ive stuck in and eaten crow and shared some fun. This link isnt as important to you as it is to me.



I have my quirks. I always post image on the right for example.

'Its the smiles the keep me going... the little giggles and bits of good cheer.'

(kudos whomever knows what movie that quote is from)

OP here:
http://online.wsj.com/article/SB10001424052702304811304577366332400453796.html

Idiot Kucther in 'brownface' here:
http://www.hollywoodreporter.com/news/popchips-responds-criticism-ashton-kutcher-brownface-ad-319583

[by RedRiverRat@5:10amGMT] [+5 Informative]

Comments

MrZeroPing said @ 5:16am GMT on 4th May [Score:1 Funny]
Your 100th post is a repost. QUICK! CHANGE TO PORN!
tiemy said @ 5:17am GMT on 4th May
scumbag writer criticizes overly optimistic commencement addresses, writes essay doing basically the same thing
RedRiverRat said @ 5:20am GMT on 4th May
oh shit
RedRiverRat said @ 5:20am GMT on 4th May
scramble save mode on high
happiest_sadist said @ 8:50am GMT on 5th May
Good save, that man.
Navier-Strokes said @ 5:23am GMT on 4th May
lilmookieesquire said @ 3:55pm GMT on 4th May
That does not look like an easy way to make a living.
ckfahrenheit said @ 5:30am GMT on 4th May
brownface?
RedRiverRat said @ 5:34am GMT on 4th May
it was an emergency placeholder to avoid repost
RedRiverRat said @ 5:36am GMT on 4th May
what I ended up with isnt great either. It may get edited later.
ckfahrenheit said @ 7:02am GMT on 4th May
cool
I like flux
damnit said @ 5:46am GMT on 4th May
RedRiverRat said @ 5:53am GMT on 4th May
I liked the badgers better. Ooo its a snake
RedRiverRat said @ 5:56am GMT on 4th May
if you havent ever you should see what b3ta is up to. Silly English peoples but they have some primo photoshops and are all around amusing. I rec subscribing to their weekly newsletter. It launched people.

bathoz said @ 2:54pm GMT on 4th May
Imagine if they'd gotten people with talent to do that. Or, you know, the ability to sing.
lilmookieesquire said @ 3:53pm GMT on 4th May
You could weaponize this guys singing.
DarkShadowRavenDragonGrrl69 said @ 5:32pm GMT on 4th May
Eh, it didn't stop weebl from producing loads of this crap.
pleaides said @ 6:20am GMT on 4th May [Score:1 Underrated]
Bravo on 100th post RRR, if this is a repost and you need some more material I've got a few articles up my sleeve :)

(they're not porn)
IronMensan said @ 6:34am GMT on 4th May
Google and Apple have procedures that are basically the opposite of each other. Anyone can put anything into the Android Marketplace. If people complain about something, Google will remove it. Apple has a review process that all applications go through before they appear in the App Store but once something is approved, they almost never look at it again.

I had one app that worked on iOS 2.0 and would crash immediately on any other version. It was still in the App Store like that when iOS 5.0 was in beta and I finally got around to fixing it.

The review was inconsistent. I submit a full and a lite version of a different application. One was approved and the other was rejected for a bug that was in both of them.
foobar said @ 7:30am GMT on 4th May
Really all Apple's review process is for is to keep you from undercutting Apple's business model(s). They don't (and couldn't) check for naughty behaviour except the most obvious shenanigans.

It's also easier for third parties to automatically get and then check apps in the Market. That doesn't mean the same thing isn't happening in the App Store, you just don't find out about it.
eIfish said @ 11:40pm GMT on 4th May
That said, the iPhone's security model makes it a lot harder for an app to do malicious stuff: it can't even run unless it's in the foreground or less than three minutes have elapsed since it was backgrounded. A lot of the most exploitable permissions an Android app can request simply don't exist on iOS ("modify/delete SD card contents", "Modify global system settings", "automatically start at boot", for example).

Whether Apple deciding the permissions an app gets vs the developer deciding and then giving the user a Hobson's choice is better for security, who knows. If Apple did their job, their model would be superior: 'punt it to the user and hope he's a computer security expert' has never been a very good idea.
foobar said @ 6:15am GMT on 5th May
WebOS did it far better. An app could request access to something sensitive, but only when it first wanted it and the user could say "no" without having to not install the app.
eIfish said @ 1:57pm GMT on 5th May
I think, though, there is something to be said for not bothering the user with questions he doesn't know the answer to, risking popup fatigue when there's an actually important question. A lot of times apps will ask to do stuff when it's not actually in the user's interest (wanting access to location or contacts or to run in the background or to autostart, when the app has no clear need to), and rather than ask the user, it would serve him better for the app store to simply deny them.

Reducing combinatorial explosion on permissions would also limit the amount of corner cases to be tested, but I'm not sure how much real benefit that is.

* After contactsgate, the new iOS will ask like this with the address book like it already does with Location, rather than leaving it to the App Store Janitors to decide. A lot of the stuff that iOS just lets apps do (net access, for example), I reckon it can get away with because background apps get suspended so quickly (five seconds, unless Apple grants an extension or exemption - apps with these privileges are supposed to be scrutinised more intensively).
Cakkafracle said @ 8:25am GMT on 4th May
did anyone else know that the dancing kid in the Pepsi Generation commercial was 'Carlton' from Fresh Prince?
I did not.

https://www.youtube.com/watch?v=po0jY4WvCIc

(found this of the brownface link)
Cakkafracle said @ 8:25am GMT on 4th May
so you can stay in bed with us:
Rojo^ said @ 12:15pm GMT on 4th May [Score:5 Insightful]
Step 1: Root your Droid.
Step 2: Install DroidWall.
Step 3: Explicitly allow apps access to the Internet as appropriate, one-by-one.
Step 4: When you install new apps, if network access is not necessary for them, simply don't grant it. Internet access for apps is opt-in only, denied by default.

Your phone will be much faster and use less battery. Win. It used to bother me that apps I installed would want to have hardware access to incoming and outbound calls, network control, and other permissions that I would think to be completely unrelated to the core function of the app. Now I just install anyway and laugh at their feeble attempts to farm data from me or push ads to me. Bwahaha.
dangerm00se said @ 9:57pm GMT on 4th May
how easy it to brick your phone rooting it?
cb361 said @ 10:52pm GMT on 4th May
I don't know, but you can really fuck it up if you ejaculate inside it.
taeyn said @ 11:52pm GMT on 4th May
its pretty easy to root a phone these days. lots of gudes over at xda-developers depending on your phone.
azazel said @ 4:04pm GMT on 4th May
EDDIE IZZARD IS COMING TO SWEDEN NEXT YEAR AND I CAN'T AFFORD TICKETS! FUCK MY LIFE. ANYONE WANT TO BUY A BABY OR TWO?
KingPellinore said @ 4:15pm GMT on 4th May
Can I put them on spikes?
azazel said @ 4:24pm GMT on 4th May
No.
KingPellinore said @ 4:42pm GMT on 4th May
azazel said @ 5:38pm GMT on 4th May
Ah.

I never get references. It's some sort of defense mechanism, I think.
KingPellinore said @ 6:06pm GMT on 4th May
He has a more extended bit about putting babies on spike earlier in the show, but I can't find that one on YouTube.

Love me some Izzard.
tickaz said @ 4:44pm GMT on 4th May
Well if we can't cook them on a spit then whats the point
cb361 said @ 8:13pm GMT on 4th May
You have to buy tickets a year in advance? That's tough.

I saw Eddie Izzard on stage about seventeen years ago. I'd love to say it was before he was big, but he was pretty big back then too.
kichijoii said @ 9:43pm GMT on 4th May
"I'd love to say I'm a big hipster, but I guess I can't."
cb361 said @ 10:10pm GMT on 4th May
I'm such a hipster that I refuse to wear anything with a brand name on it, just to be on the safe side.
Eru said @ 3:00am GMT on 5th May
I got to see him in Sydney last november. It was an awesome show.
b said @ 7:07pm GMT on 4th May
125 entries for me (wow, more than I though) and I always stick the image on the right too.
maryyugo said @ 7:36pm GMT on 4th May

Avira Free Android Security.
maryyugo said @ 7:36pm GMT on 4th May
Actually, I looked more carefully and that is loss and theft prevention, not anti-malware. Sorry about that.

Post a comment
[note: if you are replying to a specific comment, then click the reply link on that comment instead]

You must be logged in to comment on posts.




Members

Registered: 24545

Classifieds

Heaven666
What has been seen cannot be un-seen


BOOBLE
Search sites, pics, movies, personals.


Best Porn
Reviews of the best porn sites with pics, vids, scene desription and member area preview


LONELY GUYS
Meet Women Near You