Hacker News new | ask | show | jobs
by georgyo 1986 days ago
I've been using this one since the Android 1.0: https://play.google.com/store/apps/details?id=com.google.zxi...

What's interesting, is that despite the app not being updated since 2018, open source, and containing no ads or tracking the reviews are saying it recently became adware.

Searching for barcode scanner in the app store brings you to a horrible sea of ad supported crap ware, and it seems like that crap ware wants to ensure you don't download something that might be decent.

3 comments

Yeah, something's fishy.

I scraped the latest 1000 reviews (coincidentally almost exactly 12 months worth).

The "adware" reviews are all very recent with large amounts of votes.

They seem to start on December 18, with 162 1-star reviews in the following 25 days -- more than all the 1-star reviews in the 6 months prior.

I wouldn't be surprised if these reviews are not only automated spam, but are constantly being deleted and reposted to keep them "fresh", and at the top of the "relevant reviews".

Charts: https://imgur.com/a/QUyHcHu

CSV of review data: https://pastebin.com/ZanYgd5Y

The malware app was also called "barcode scanner", published by "the space team", so it wouldn't surprise me if a lot of people just found the more popular zxing app on the store and left reviews in the wrong place. I had the malware version installed and went through the same process Cedric did to find out that an update they pushed around that time turned on the bad behavior.
Curious: How did you do that? (scrape + chart)
Scrolled down until 1000 reviews had loaded.

Used the simplescraper.io Chrome extension (with a little bit of DevTools fiddling) to export a CSV.

Created a pivot table in Excel and charted the results.

Either it's a campaign to try and lower the ratings or a bunch of people have managed to get separately installed malware and thought this was the cause.

The last update I see available is what I have installed - 4.7.8 from September 2018. Definitely no strange behavior from it.

Hm, it says updated February 2019?

But I also use this app for QR-codes, since I was never able to find an alternative. The vast permissions required make me nervous every time I install it... Good to know it is on F-Droid as well, built from a source tarball, so should be OK [1]?

[1] https://f-droid.org/en/packages/com.google.zxing.client.andr...

Interesting, in the Android play store it says Sept 2018. But I opened it on a browser and I see Feb 2019.

However all the negative comments about ads are from after November 2020. Clearly a smear campaign.