top | item 39440875

(no title)

thimp | 2 years ago

This is actually a big problem on Android. My ex father-in-law literally had his bank account ripped off (£18000) from rogue app installed from outside the app store. And Google's stewardship of the play store is terrible.

Note I'm mostly an Android user.

discuss

order

itsoktocry|2 years ago

>This is actually a big problem on Android.

The fact that you have an anecdote does not make it a "big problem".

If you're side loading apps and entering banking credentials into them, that's a human problem, not a tech problem.

thimp|2 years ago

ALL problems are human problems. Don't try and write this off with that one.

I can go all day on these. Second one ... corp Android phone. App update ships own browser engine to display about box. Flaw in about box implementation allows user to hit Google. End user uses about box to exfiltrate data from device.

Not possible on iOS. Same browser engine and controls.

As mentioned I'm an Android user, just a better human than most when it comes to using the devices.

amadeuspagel|2 years ago

Ignoring this kind of absurd distinction is what made Apple the most valuable company on earth. (That doesn't justify their behaviour in this case, as PWAs are a secure alternative to sideloading.)

Fischgericht|2 years ago

That story sounds rather fishy. So your father has found the hidden option to enable developer mode which allows APKs to be sideloaded, and then went to some website to download and install an APK?

By the way: According to Kasparsky [1] last year there have been 600 Million downloads of malware that was installed from Google play store, without any sideloading or alternative App stores involved.

And of course the Apple App store also is full of malware and shady stuff, think of all the chinese IoT apps that are phoning home etc.

[1] https://www.kaspersky.com/blog/malware-in-google-play-2023/4...

thimp|2 years ago

Yeah he was persuaded to do it, ironically considering YT is Google, using a video on YT which was trying to sell him VPN software. I blame the paranoia from the constant VPN industry adds being forced down your throat really but the point is that it still does happen.

I will add that I have a lot of unsigned APKs on my device as well, but not from those sources!