So this just happened - those of you who have a Xiaomi phone know when you install apps it has it’s own “Virus Checker” screen which comes up before the app is approved for install. This is provided by Avast I just found out…

Anyway while installing an app from F-droid today I got an error message on this screen - which said “app from unknown source” and two buttons below - “Ignore” and “Install”. So I clicked on “Install” since I wanted to install the app and then noticed that the install process seemed a bit different (I can’t remember what happened exactly) but I checked the app on F-Droid and the version history wasn’t available - which a notice says means the app was installed from Play Store or somewhere else. But I just installed it from F-Droid!

So I tried another few apps and it happened again for one of them. I clicked around and there it was, some sort of Xiaomi app store installing versions of the app instead of the one I told my phone to install.

I guess there is an innocent explanation for this - stopping people from installing malware and giving them a “correct” version of the app they wanted - but I have disabled it on my phone, I know what I am doing and if I want the cracked version it’s because that’s the version I meant to install ;)

  • Paragone@lemmy.world
    link
    fedilink
    English
    arrow-up
    49
    arrow-down
    3
    ·
    8 months ago

    XOR…

    Xaiomi is installing versions with Microsoft-style spyware/malware in 'em…

    Same as ISP’s altering the web-pages that people view, for their own commercial-reasons…

    Molesting-the-user seems to be THE SurveillanceCapitalism paradigm, in the Enshittocene…

    I’m not competent to do the decompilation/analysis required to discover if your new “helpful” versions are spyware/malware, but I’d bet they are not as clean as the original versions are.

    Avast has been caught being treason-against-privacy, recently, too, with their “privacy” app that was actually a trojan to enable Avast to sell privacy-information for profit…

    ( last few weeks in the Tech news, here on Lemmy.world, iirc )


    You might want to ask the MalwareBytes people to look into it?

    • VeganCheesecake@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      2
      ·
      8 months ago

      Without further evidence, I’d assume they just want to boost usage of their App Store. Since they’re the O.E.M. of the phone and developer of the installed Android Rom, they could build in a back door in a much less conspicuous way.

      • tomjuggler@lemmy.worldOP
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 months ago

        Yeah I’m going with they’re innocent. Just the UI with the install button and no explanation is not cool.

    • tomjuggler@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 months ago

      I heard about the avast thing, but how are isp’s modifying web pages, that shouldn’t be possible with with https, right?

    • Lunch@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 months ago

      Do you have a source in terms of the ISPs altering websites? Would love to mention that in my thesis.