Hacker News new | ask | show | jobs
by Daneel_ 2154 days ago
Android also has global issues with malware infections and crapware, primarily due to people downloading software from third-party app stores.

I’m not saying the apple model is how I want things (far from it), but it certainly has been effective at controlling malware on the platform.

2 comments

The problems with Android are typically caused by apps that actually make it to the official Play Store. The cause of that is poor reviewing by Google, nothing to do with OS issues.

A mac-like system for iOS would work just fine.

Can you please tell me what app stores you're referring to, and which apps on F-Droid currently contain malware?
Here's an article from from April this year 2020

https://www.techradar.com/news/phantomlance-malware-breaches...

Dozens of malicious apps infected with the malware are being distributed via the Play Store and alternate app stores such as APKpure and APKCombo, often targeting users to spy on their habits and steal data.

According to security firm Kaspersky, this malware campaign has been live for over 4 years, and is likely the work of the OceanLotus advanced persistent threat (APT) group, thought to be based out of Vietnam.

So its on playstores and has no relevance to alternatibe playstores or sideloadimg
> and alternate app stores such as APKpure and APKCombo

From GP’s quote directly above.

So? If it already on the pfficial appstore, its not the fault of alternative apstores.
I can tell you about an app that you might have heard of that bypassed the Google Play Store and was a security nightmare.

https://www.cnet.com/news/just-as-critics-feared-fortnite-fo...

> Fortnite became available for Android on Aug. 9, starting with Samsung Galaxy devices, and then became available for all of Android on Aug. 12. Google brought the vulnerability to Epic Games' attention on Aug. 15. Epic Games immediately acknowledged its mistake and fixed the bug with version 2.1.0 of the launcher on Aug. 16.

Iirc the issue was that they first downloaded a file and then ran it. Thus there was a short window of time where someone can tamper with the file before it's running. Far from being a security nightmare it was a subtle flaw, and fixed quickly.