TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Malicious app on Google Play drops banking malware on users’ devices

104 pointsby caaqilover 3 years ago

5 comments

eMGm4D0zgUAVXc7over 3 years ago
I am *very* surprised that the list of requested permissions on Google Play does *not* have to match the actual permissions which the app gets when installed.<p>I would have thought that the list on Google Play is computed from the binary so it cannot be fake.<p>Is it really true that you can just leave out permissions in this list and then just get them once people install your app?
评论 #30126733 未加载
评论 #30126942 未加载
评论 #30126515 未加载
chetangotiover 3 years ago
It was discussed yesterday at <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30115132" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30115132</a> which has 57 comments.
评论 #30126532 未加载
superasnover 3 years ago
So many such issues could be easily mitigated if we just moved away from apps to PWAs&#x2F;Web apps with better support from mobile vendors for the push api, camera, etc - but the powers that be (Apple, Google, Microsoft) and also the sites (Reddit, Amazon, etc) want to move in the opposite direction because who cares about security and users when apps bring in the moolah.<p>As a matter of fact sometimes the websites are so much better too, like Amazon, which doesn&#x27;t even have a &quot;Find..&quot; function in the app. I really wish we could done be with these apps and everything just ran in the browser, except maybe apps that need some low level api or something.
评论 #30129250 未加载
评论 #30130360 未加载
评论 #30130356 未加载
评论 #30128102 未加载
bigyellowover 3 years ago
You&#x27;re telling me a for-profit, closed source, proprietary application store where anyone can submit software and call it anything they want has perverse incentives? I&#x27;m shocked. Shocked, I tell you.
JadeNBover 3 years ago
I thought we edited clickbait-y headlines like this. The name of the malicious app is &quot;2FA Authenticator&quot;.