• Ghostalmedia@lemmy.world
      link
      fedilink
      English
      arrow-up
      48
      arrow-down
      7
      ·
      9 months ago

      To be fair, things like this are pretty rare.

      The more common experience is that those reviewers are anal as hell reject people for petty stuff. This malware guy lucked out and got the burned out app reviewer who didn’t look twice.

        • Ghostalmedia@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          9 months ago

          Yeah, but as the poor sap who has been deemed “computer guy” for every elderly parent, aunt and uncle in the family, I think the Play and App Stores do a decent job of keeping malware in check.

          It’s not perfect, but about once every year or two I have to put out a malware fire with a Windows laptop in the family. Dealing with the phones is less of a headache. Especially the iOS devices.

          I wish iOS made it easier for people like me to remove those guardrails for my own needs, but for my 80 year old parents, I’m all for keeping them living in Apple and Google’s stores.

    • Vub@lemmy.world
      link
      fedilink
      English
      arrow-up
      25
      arrow-down
      11
      ·
      9 months ago

      I am surprised this happened, it’s the first case of anything like this that I have heard of. Do you know of any other cases?

    • stoy@lemmy.zip
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      14
      ·
      9 months ago

      Pretty well, it was bound to happen sooner or later and thisnis the first time Inhave heard about it

      • VelociCatTurd@lemmy.world
        link
        fedilink
        English
        arrow-up
        27
        arrow-down
        3
        ·
        9 months ago

        There’s been plenty of malicious apps found in the past. Though, I’m sure the play store isn’t much better. Disappointing that Apple will bend devs over a Barrel sometimes but they don’t find shit like this.

        • stoy@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          3
          ·
          9 months ago

          I never said that there wasn’t any malicious apps on the App Store, just that this was the first one that I have heard about that actively tries to fake being the official one and managed to get vetted.

        • stoy@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          4
          ·
          9 months ago

          I never said that this is the first dodgy app in the app store?

          I said that this is the first app I have heard about that pretends to be the official app that have gone through the vetting step on the App Store.

  • JustARegularNerd@aussie.zone
    link
    fedilink
    English
    arrow-up
    42
    ·
    edit-2
    9 months ago

    I work at an MSP and while it wasn’t LastPass, when you search “Microsoft Authenticator” in the app store there’s a similar looking Authenticator app that’s also blue, and because it’s an ad it shows up first. Had a user install that and was confused why they weren’t able to get MFA working.

    • Blue Lou@lemmy.world
      link
      fedilink
      English
      arrow-up
      23
      ·
      edit-2
      9 months ago

      I recently ran through an MFA enforcement campaign and had to build that app into my instructions. “Make sure it’s the Microsoft authenticator, not the first result in the paid ad slot” because so many people were installing that app. I do deal with pretty low levels of tech savvy, but still.

  • AutoTL;DR@lemmings.worldB
    link
    fedilink
    English
    arrow-up
    8
    ·
    9 months ago

    This is the best summary I could come up with:


    Bad actors could potentially utilize the new regulation to trick consumers into buying subscriptions that are difficult to cancel.

    When introducing its plan for DMA compliance, Apple wrote, “The new options for processing payments and downloading apps on iOS open new avenues for malware, fraud and scams, illicit and harmful content, and other privacy and security threats.”

    What’s more, it’s upsetting to learn that LastPass had to warn customers publicly about a fake app that never should have been published in the first place.

    “Our threat intelligence team posted a blog yesterday to raise awareness and help inform the public and our customers of the situation.

    We are in direct contact with representatives from Apple, and they have confirmed receipt of our complaints, and we are working through the process to have the fraudulent app removed.”

    Hoff added that the company is working with Apple to “understand more broadly how an application like this passed their normally rigorous security and brand protection mechanisms.


    The original article contains 684 words, the summary contains 162 words. Saved 76%. I’m a bot and I’m open source!

  • cheese_greater@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    9
    ·
    9 months ago

    Its beyond irresponsible it wasn’t pulled the moment the most recent revelations came about. It also made me wonder if Apple “sees” certain fields of your keychain items, in-line with their conflation of convergent encryption as e2ee and other assorted privacy antics