• chevron_right

      Google removes fake Signal and Telegram apps hosted on Play

      news.movim.eu / ArsTechnica · Wednesday, 30 August, 2023 - 22:09 · 1 minute

    Google removes fake Signal and Telegram apps hosted on Play

    Enlarge (credit: Mateusz Slodkowski/SOPA Images/LightRocket via Getty Images)

    Researchers on Wednesday said they found fake apps in Google Play that masqueraded as legitimate ones for the Signal and Telegram messaging platforms. The malicious apps could pull messages or other sensitive information from legitimate accounts when users took certain actions.

    An app with the name Signal Plus Messenger was available on Play for nine months and had been downloaded from Play roughly 100 times before Google took it down last April after being tipped off by security firm ESET. It was also available in the Samsung app store and on signalplus[.]org, a dedicated website mimicking the official Signal.org. An app calling itself FlyGram, meanwhile, was created by the same threat actor and was available through the same three channels. Google removed it from Play in 2021. Both apps remain available in the Samsung store.

    Both apps were built on open source code available from Signal and Telegram. Interwoven into that code was an espionage tool tracked as BadBazaar. The Trojan has been linked to a China-aligned hacking group tracked as GREF. BadBazaar has been used previously to target Uyghurs and other Turkic ethnic minorities. The FlyGram malware was also shared in a Uyghur Telegram group, further aligning it to previous targeting by the BadBazaar malware family.

    Read 6 remaining paragraphs | Comments

    • chevron_right

      Google escapes Play Store class action after finding more persuasive expert

      news.movim.eu / ArsTechnica · Tuesday, 29 August, 2023 - 19:46

    Google escapes Play Store class action after finding more persuasive expert

    Enlarge (credit: SOPA Images / Contributor | LightRocket )

    A US district judge has reversed course, revoking a 2022 class action status order for 21 million Google Play Store customers who alleged that Google “artificially inflated” prices for Android apps that could have been downloaded cheaper outside the Play Store.

    Yesterday, Judge James Donato ordered the class action cancelled after he said that new evidence showed that key expert testimony that plaintiffs relied on to claim that prices were inflated was "based on assumptions about the Play Store apps that are not supported by the evidence.”

    Because the expert testimony—which came from antitrust expert Hal J. Singer—failed a reliability test, it must be excluded, Donato said. Now it seems likely that plaintiffs may have to "dramatically reduce potential damages" in the case, which Singer had previously estimated could amount to billions, Bloomberg reported .

    Read 16 remaining paragraphs | Comments

    • chevron_right

      Manga Piracy Apps Stay Up on Google & Apple, Publisher Moves to Unmask Devs

      news.movim.eu / TorrentFreak · Thursday, 17 August, 2023 - 10:38 · 2 minutes

    manga Japanese manga comics remain massively popular online but with that comes high levels of piracy that publishers are struggling to contain.

    On top of dedicated websites pulling in tens of millions of visits each every month, there’s a thriving market of Android and iOS apps offering premium manga content for free but without appropriate licenses.

    Many of these apps, especially those Android-based, are made available outside official app ecosystems, but some still make their way onto Google Play and Apple’s App Store, with all the convenience that entails. To have the apps removed, publishers file takedown notices with Google and Apple but as recent court documents suggest, takedown notices aren’t always successful.

    Kadokawa Sent Takedown Notices, Apps Stay Up

    On June 16, 2023, manga publisher Kadokawa sent two takedown notices, one to Google and another to Apple. In broad terms the notices are identical, the only differences being the recipient and links to the content to be taken down.

    Kadokawa takedown notice (Apple) kadokawa-apple takedown

    The notice sent to Google lists works by manga artist Kugane Maruyama and requests the removal of two apps; one titled ‘SuA Manga Đọc truyện tranh’ and another titled ‘Mangalek’.

    The takedown notice sent to Apple lists three works by two manga artists – Shachi Sogano and Patora Fuyuhara – and requests the removal of three apps: ‘Manga Reader: Comic & Webtoons’, ‘Manga Reader: Top Manga Here’, and ‘Manga Reader – Comics and Novels’.

    Whether these takedown requests are more complex than they first appear is unknown, but it seems that neither Google nor Apple removed the apps in question. At the time of writing they remain available both on Google Play ( 1 , 2 ) and Apple’s App Store ( 1 , 2 , 3 ).

    Kadokawa Files DMCA Application at California Court

    It’s possible that Kadokawa always intended to take further action, whether its takedown notices were effective or not. In any event, the manga publisher has now filed requests with a California court to compel both Apple and Google to hand over the identities of the apps’ developers.

    The information requested from both companies is broadly the same and comprehensive. (Apple request shown below)

    – Any and all information showing all names, addresses (including postal codes and addresses used for address (PIN) verification, e-mail addresses (including email addresses used for recovery or other purposes), and telephone numbers (including, but not limited to, those required for Apple account registration);

    – Any and all information showing access log (including dates, times, IP addresses, and access type) of each of the Infringer’s Accounts, including access log along with timestamp for each login (namely, login history);

    – Any and all information showing (a) all names, telephone numbers, and addresses (including postal codes), any payment method, including but not limited to credit card holders, bank accounts, registered with; and (b) the type of the payment method and the name of the company or financial institution associated with such payment method registered with any and all of the Infringer’s Accounts.

    Publicly available information suggests that some of these apps and/or their developers may have links to full-blown pirate sites, so any information obtained here may prove useful in progressing investigations elsewhere.

    Kadokawa’s DMCA subpoena application can be found here (Google 1 , 2 / Apple 1 , 2 , 3 , pdf)

    From: TF , for the latest news on copyright battles, piracy and more.

    • chevron_right

      Android 4.4 KitKat is truly dead, loses Play Services support

      news.movim.eu / ArsTechnica · Tuesday, 25 July, 2023 - 16:46 · 1 minute

    Android 4.4 KitKat is truly dead, loses Play Services support

    (credit: Google)

    The Android ecosystem rightfully gets a lot of slack for being unable to deliver operating system updates to everyone in a timely manner, but there's more to Android updates than just OS support. App updates can keep a phone chugging along even after the updates have stopped, and Google's do-it-all super app, Google Play Services, contains a ton of app APIs and features and enables the really important stuff like Play Store transactions and advertisements.

    Google just announced Play Services is dropping support for an old version of Android, and while OS development might stop at just three or four years, Play Services goes back way longer than that. Google announced Play Services is dropping support for Android 4.4 KitKat, which is now 10 years old. Support isn't really being artificially cut off, either. Google says KitKat's active device count is "below 1 percent," so there's not much reason to support it anymore.

    These devices will stop getting Play Services updates after July, and then it's anyone's guess as to how much longer they will work. At some point, Google will change something, and your device will become a brick. Old, unsupported Android devices can't log in to a Google account, which is a prerequisite for opening half of the apps that come with your phone. You'll be locked out of the Play Store, Gmail, Google Maps, and other Google products, with no way to see these old versions again. Luckily, someone saw all this coming and took screenshots of every old version.

    Read 1 remaining paragraphs | Comments

    • chevron_right

      Google’s Android and Chrome extensions are a very sad place. Here’s why

      news.movim.eu / ArsTechnica · Friday, 2 June, 2023 - 21:07

    Google’s Android and Chrome extensions are a very sad place. Here’s why

    Enlarge (credit: Photo Illustration by Miguel Candela/SOPA Images/LightRocket via Getty Images)

    No wonder Google is having trouble keeping up with policing its app store. Since Monday, researchers have reported that hundreds of Android apps and Chrome extensions with millions of installs from the company’s official marketplaces have included functions for snooping on user files, manipulating the contents of clipboards, and injecting deliberately unknown code into webpages.

    Google has removed many but not all of the malicious entries, the researchers said, but only after they were reported, and by then, they were on millions of devices—and possibly hundreds of millions. The researchers aren’t pleased.

    A very sad place

    “I’m not a fan of Google’s approach,” extension developer and researcher Wladimir Palant wrote in an email. In the days before Chrome, when Firefox had a bigger piece of the browser share, real people reviewed extensions before making them available in the Mozilla marketplace. Google took a different approach by using an automated review process, which Firefox then copied.

    Read 18 remaining paragraphs | Comments

    • chevron_right

      101 applications sur Google Play ont été infectées par un logiciel espion

      news.movim.eu / Numerama · Wednesday, 31 May, 2023 - 13:21

    Plus d'une centaine d'applications sur Google Play contiennent un logiciel espion, récupérant données et fichiers sur le smartphone de la victime. Ces applis ont été retirées, mais il convient toujours de les désinstaller. [Lire la suite]

    Abonnez-vous aux newsletters Numerama pour recevoir l’essentiel de l’actualité https://www.numerama.com/newsletter/

    • chevron_right

      App with 50,000 Google Play installs sent attackers mic recordings every 15 minutes

      news.movim.eu / ArsTechnica · Wednesday, 24 May, 2023 - 17:49 · 1 minute

    App with 50,000 Google Play installs sent attackers mic recordings every 15 minutes

    Enlarge (credit: Getty Images)

    An app that had more than 50,000 downloads from Google Play surreptitiously recorded nearby audio every 15 minutes and sent it to the app developer, a researcher from security firm ESET said.

    The app, titled iRecorder Screen Recorder, started life on Google Play in September 2021 as a benign app that allowed users to record the screens of their Android devices, ESET researcher Lukas Stefanko said in a post published on Tuesday. Eleven months later, the legitimate app was updated to add entirely new functionality. It included the ability to remotely turn on the device mic and record sound, connect to an attacker-controlled server, and upload the audio and other sensitive files that were stored on the device.

    Surreptitious recording every 15 minutes

    The secret espionage functions were implemented using code from AhMyth , an open source RAT—short for remote access trojan—that has been incorporated into several other Android apps in recent years. Once the RAT was added to iRecorder, all users of the previously benign app received updates that allowed their phones to record nearby audio and send it to a developer-designated server through an encrypted channel. As time went on, code taken from AhMyth was heavily modified, an indication that the developer became more adept with the open source RAT. ESET named the newly modified RAT in iRecorder AhRat.

    Read 15 remaining paragraphs | Comments

    • chevron_right

      Google Bans ‘Downloader’ App: TV Outfits Claim Browser Violates Injunction

      news.movim.eu / TorrentFreak · Tuesday, 23 May, 2023 - 11:34 · 7 minutes

    downloader-logo If the best ideas are always the simplest, in 2016 software developer Elias Saba hit the jackpot.

    Two years after Amazon launched its first generation Fire TV, there was still no easy way to transfer files to the device. Released on the Amazon Appstore in November 2016, Saba’s ‘Downloader’ app offered users just two things; an empty URL field and a download button. It was basic yet functional, and in time, extraordinarily successful.

    The Amazon Appstore and Google Play currently account for more than 50 million installs of Downloader, underpinned by Saba’s decision not to charge a single penny for the software. downloader-amazon reviews At the time of writing, Downloader has 664,605 customer ratings on Amazon, averaging 4.3 stars out of a possible five. For several TV companies from Israel, Saba’s work, success and generosity are of no consequence; Downloader is in their way and has to go.

    Google Kicks Downloader Out of the Play Store

    In a notification sent to Sabas yesterday, Google informs the developer that “after a recent review,” Downloader was found to contain content that “doesn’t comply with the Unauthorized Use of Copyrighted Content policy” operated on the Play Store.

    The review was prompted by a copyright complaint from Israel-based TV companies HOT Communications Systems Ltd, DBS Satellite Services (1998) Ltd, United King Distribution Videos (1990) Ltd, and Charlton Ltd.

    “We have received an infringement notice that your app contains copyrighted content,” Google’s notice explains. “Your app has been suspended and removed due to alleged copyright infringement (according to the terms of the Digital Millennium Copyright Act).”

    Notices like this can be terminal app-suspended

    Google’s notification reveals that the TV companies supplied no details of specific original content or details of content allegedly infringed. As a DMCA takedown notice, it arguably fails at the very first hurdle. Instead, the notice draws Google’s attention to a feature added to Downloader more than six years ago.

    The companies claim that this feature violates an injunction the TV companies obtained from a New York court in 2022. Neither the injunction, nor the process that led to its issuance, have anything to do with Saba or his software.

    Since the TV companies claim otherwise, a little background may help.

    Users Demand More, Get More

    Within weeks of its launch, Downloader’s users were already requesting new features. For Saba, a former Fire TV Product Manager at Amazon, that didn’t come as a surprise. As a developer, it wasn’t a problem either.

    “I added basic file management and a web browser to Downloader in February 2017 because users complained that it was too tedious to enter long URLs using a remote control and the on-screen keyboard,” Saba informs TorrentFreak.

    The addition of a web browser didn’t just consign long URLs to history; for Downloader and its users, a little history was being made. While Downloader users happily searched Google and navigated to files displayed on a TV , bigger players in the software market were still playing catch up.

    TV Surfing Pioneer Taken Offline on a Whim

    When Downloader fueled free, accessible web browsing via TV sets, Saba says that filling another gap in the market was an accident, an “unintended side-effect” of the new feature.

    “My app predated nearly all stand-alone web browsers on streaming devices, including Amazon’s own Silk browser and Firefox, which arrived on TV streaming devices six months after my app gained a web browser,” Saba recalls.

    While popular in its own right, Downloader was about to get a huge boost. Popular open source media player Kodi was previously available from Amazon’s Appstore but after the company removed it , only unofficial installation methods remained.

    In an April 2017 tweet , the people behind Kodi described Downloader as ‘The only correct way of installing Kodi on Amazon devices.” Over the years, millions of people followed that advice.

    Saba estimates that over 45 million Fire TV users installed Downloader at some point. At the time of writing, Downloader has at least five million active installs on Android TV devices through Google Play. Downloader is free and the nearest thing it has to an advert is Saba’s blog, AFTVNews.com , loading as the browser’s default homepage.

    Downloader’s browser feature is the start, middle and end of the TV companies’ complaint to Google.

    Browser Can Access a Pirate Streaming Site

    The bones of the complaint fit neatly into a single paragraph. Sent to Google by Eran Presenti, a partner at M. Firon & Co., one of Israel’s largest law firms, it reads as follows:

    “[T]his app which can be downloaded to any Android based device including smart TV – allows users to view the infamous copyright infringing website known as SDAROT (www.sdarot.tw) against which the are 2 Isareli court and a NY Federal court judgments issuing permanent injunction against the saus website [sic].”

    Google Chrome, an app that arrives pre-installed on millions of Android devices, also allows users to view the infamous Sdarot. The same is true for Safari, Edge and Firefox. All of them show an image similar to the one below in response to input featuring Sdarot’s URL.

    Evidence that Downloader’s browser displays websites in response to user input is reportedly contained in eight screenshots listed by Google. Saba actually received eight filenames ending in .jpg, but no actual images.

    A link to a website in the notice claims to provide a copy of an ‘Amended Default Judgment & Injunction’ dated July 6, 2022. The link was supposed to lead to sdarot.tv, a domain previously owned by Sdarot but later seized by the TV companies. A copy of the injunction isn’t available because the domain itself is completely broken.

    Despite acting as the evidence behind Downloader’s removal from Google Play, Saba informs us that the screenshots and injunction remain a mystery to him. Fortunately, we know all about the underlying case and injunction; more interestingly, Google knows all about it too.

    TV Companies Fight a War They Can’t Win

    HOT Communications, DBS Satellite, United King and Charlton Ltd are on a mission to destroy Sdarot, Israel’s largest pirate site. The subscription streaming platform has been targeted in at least three lawsuits, all of them decided in favor of the plaintiffs, yet still refuses to die.

    In May 2022, we broke the news that the companies had obtained an injunction from a New York court that required every ISP in the United States to block Sdarot and two other pirate sites.

    What happened next remains shrouded in mystery but the record shows that after winning the injunction, the TV companies decided they didn’t want U.S. ISPs to block the sites after all.

    The scope of the injunction remained a concern. It began with consumer ISPs but also prohibited any webhost, CDN provider, DNS provider, domain company, advertising service, financial institution, or payment processor from doing business with the sites’ operators moving forward. Cloudflare, Google, EFF, and industry group CCIA felt strongly enough to intervene in the lawsuit.

    With no means to protect itself from an injunction that failed to narrowly target specific, identified defendants and their agents, and/or third parties in active concert or participation with them, Cloudflare refused to comply with its terms and the TV companies’ “blatant attempt at a power grab.”

    The TV companies unwisely moved to hold Cloudflare in contempt but in the weeks that followed, the injunction was amended and the TV companies went after Sdarot instead.

    Sdarot Remains Online, Downloader Targeted

    For reasons that currently make little sense, the TV companies seem to have cited an injunction that appears to have nothing to do with Saba or Downloader, to convince Google that displaying the Sdarot website, after someone keys Sdarot.tw into Downloader’s browser, is a breach of its terms.

    Since Saba’s initial appeal to Google was rejected, he’s since filed a DMCA counternotice to have Downloader reinstated. That’s currently listed as pending but at least in theory, Google should reinstate the software unless the TV companies file a lawsuit against Saba.

    Thus far, however, legal action against intermediaries has failed to achieve its primary goal. A review of the position on the ground today suggests a situation that’s arguably worse than before.

    Sdarot now operates from a Taiwan .tw domain which present its own legal challenges. As for the site’s hosting, Sdarot now spreads its infrastructure across several countries including Moldova and Russia, utilizing a number of hosts that are well-known for filing DMCA complaints in the cabinet marked ‘TRASH’.

    From: TF , for the latest news on copyright battles, piracy and more.

    • chevron_right

      On espère que vous aimez les jeux vidéo sur Netflix, puisque 40 titres arrivent

      news.movim.eu / Numerama · Tuesday, 21 March, 2023 - 09:29

    Pour diversifier ses sources de revenus, Netflix mise sur les jeux vidéo. Deux ans après le lancement de ses premiers titres sur mobile, le géant du streaming s’approche doucement de la centaine. [Lire la suite]

    Abonnez-vous aux newsletters Numerama pour recevoir l’essentiel de l’actualité https://www.numerama.com/newsletter/