Tuesday, March 22, 2011

How not to respond to an accusation of distributing spyware

Take a look at this interesting android-security discussion thread.

Here's what I see happening:

1. Avast researcher finds someone who has a hacked version of the Walk and Text app, which caused their phone to send out a text message to their friends.

2. Avast posts a blog article about this, complete with screenshot and disassembly

3. App developer posts broken-english response and demands the blog post be taken down, while claiming that the app wasn't posted by them, and they didn't have a harvesting page up on their site

4. Avast responds that they confirmed that the harvesting page was up previously

Now the denial in step 3 makes no sense. The app in question was analyzed and determined to contain that URL, and the message was sent with that phone's sender information. So this developer, who should have just stayed shut about this now has basically ended up tossing what little reputation his company had into the toilet. Brilliant

0 comments: