NoGoolag
4.54K subscribers
13.1K photos
6.88K videos
584 files
14.1K links
Download Telegram
🗞 Google tightens restrictions on apps with sexual content, loot boxes, hate speech, and marijuana sales

Google is making a number of policy changes to the Google Play store and the applications that are allowed to be inside it. This seems to be both a big push towards making the Play Store more family friendly while also clearing up some gray areas that developers have been curious about. The latest changes
...


https://www.xda-developers.com/google-play-restrictions-sexual-content-loot-boxes-hate-speech-marijuana


#google #playstore #cannabis #censorship
The Eye on the Nile

Phishing attack on government opponents in Egypt - with apps from the Play Store

Specialists reveal a sophisticated phishing attack in Egypt. Android apps that made it into the Play Store without catching the eye were involved.

Back in March 2019, Amnesty International published a report that uncovered a targeted attack against journalists and human rights activists in Egypt. The victims even received an e-mail from Google warning them that government-backed attackers attempted to steal their passwords. https://www.amnesty.org/en/latest/research/2019/03/phishing-attacks-using-third-party-applications-against-egyptian-civil-society-organizations/

According to the report, the attackers did not rely on traditional phishing methods or credential-stealing payloads, but rather utilized a stealthier and more efficient way of accessing the victims’ inboxes: a technique known as “OAuth Phishing”. By abusing third-party applications for popular mailing services such as Gmail or Outlook, the attackers manipulated victims into granting them full access to their e-mails.

Recently, we were able to find previously unknown or undisclosed malicious artifacts belonging to this operation. A new website we attributed to this malicious activity revealed that the attackers are going after their prey in more than one way, and might even be hiding in plain sight: developing mobile applications to monitor their targets, and hosting them on Google’s official Play Store.

After we notified Google about the involved applications, they quickly took them off of the Play Store and banned the associated developer.

👉🏼 Read more:
https://research.checkpoint.com/the-eye-on-the-nile/

#Egypt #pishing #attacks #research #android #apps #playstore
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
Fix Signature Spoofing Support

Solution when "Play Store (Phonesky) has correct signature" is not checked,

run these 2 commands in termux app or other terminal app:

su

pm grant com.android.vending android.permission.FAKE_PACKAGE_SIGNATURE


For android 9 and lower you can do it this way:
Go to settings
apps
app permission
signature spoofing
3 dot menu
show system apps
give permission to fakestore.


How to give Fake Store permissions on the second user. Not possible the usual way with terminal. So in /data/system/users/10/runtime-permissions.xml
Add the line:
<pkg name="com.android.vending">
<item name="android.permission.FAKE_PACKAGE_SIGNATURE" granted="true" flags="0" />
</pkg>

Then reboot


📡 @NoGoolag
#fsss #fix #signature #spoofing #problems #issues #playstore #phonesky
Over 4000 Android Apps Expose Users' Data via Misconfigured Firebase Databases

More than 4,000 Android apps that use Google's cloud-hosted Firebase databases are 'unknowingly' leaking sensitive information on their users, including their email addresses, usernames, passwords, phone numbers, full names, chat messages and location data.

The investigation, led by Bob Diachenko from Security Discovery in partnership with Comparitech, is the result of an analysis of 15,735 Android apps, which comprise about 18 percent of all apps on Google Play store.

"4.8 percent of mobile apps using Google Firebase to store user data are not properly secured, allowing anyone to access databases containing users' personal information, access tokens, and other data without a password or any other authentication," Comparitech said.

👀 The full contents of the database, spanning across 4,282 apps, included:

‼️
Email addresses: 7,000,000+
‼️ Usernames: 4,400,000+
‼️ Passwords: 1,000,000+
‼️ Phone numbers: 5,300,000+
‼️ Full names: 18,300,000+
‼️ Chat messages: 6,800,000+
‼️ GPS data: 6,200,000+
‼️ IP addresses: 156,000+
‼️ Street addresses: 560,000+

👉🏼 Read more:
https://thehackernews.com/2020/05/android-firebase-database-security.html

#android #app #google #playstore #firebase #database #security #breach #leak
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
Fortnite for Android has also been kicked off the Google Play Store

You can still install it directly from Epic, however

Following its removal from the Apple App Store, Fortnite has also been kicked off of the Google Play Store for Android. Earlier today, Epic Games snuck in an update for both the iPhone and Android versions of the game that allowed users to pay Epic directly for in-app purchases instead of using the officially sanctioned system for both platforms.

What followed was a wild ride: Apple kicked Fortnite off the App Store, then Epic sued Apple, and finally there was an in-game video parodying Apple’s own 1984 commercial, positioning Apple itself as the monopolist.

https://www.theverge.com/2020/8/13/21368079/fortnite-epic-android-banned-google-play-app-store-rule-violation

https://www.engadget.com/fortnite-android-225437892.html

https://youtu.be/euiSHuaw6Q4


#Google #apple #fortnite #appstore #playstore #payments #EpicGames
A tip from a kid helps detect iOS and Android scam apps’ 2.4 million downloads

Smartphone apps raked in ~$500,000, in part thanks to shilling on TikTok and Instagram

Researchers said that a tip from a child led them to discover aggressive adware and exorbitant prices lurking in iOS and Android smartphone apps with a combined 2.4 million downloads from the App Store and Google Play.

Posing as apps for entertainment, wallpaper images, or music downloads, some of the titles served intrusive ads even when an app wasn’t active. To prevent users from uninstalling them, the apps hid their icon, making it hard to identify where the ads were coming from. Other apps charged from $2 to $10 and generated revenue of more than $500,000, according to estimates from SensorTower, a smartphone-app intelligence service

The apps came to light after a girl found a profile on TikTok that was promoting what appeared to be an abusive app and reported it to Be Safe Online, a project in the Czech Republic that educates children about online safety. Acting on the tip, researchers from security firm Avast found 11 apps, for devices running both iOS and Android, that were engaged in similar scams.

https://arstechnica.com/information-technology/2020/09/scam-apps-with-2-4-million-downloads-found-on-apple-and-google-shelves/

#scam #kids #adware #Playstore #android #AppStore #iOS #tiktok #instagram
Google to update Play Store guidelines to make it harder to bypass the 30% fee

https://www.xda-developers.com/google-double-down-30-in-app-fee

Google will reportedly get stricter with developers over in-app purchases, according to Bloomberg. The move is set to be announced next week and will surely upset some developers who have previously circumvented Google’s rules.

Bloomberg’s report claims Google will issue updated guidelines that will clarify a requirement for apps to use Google Play In-app Billing service for in-app purchases. That means if you purchase a Spotify subscription through the Android app, Google wants its 30% cut of the revenue.

Google’s policies aren’t necessarily changing. Rather, the company is reportedly cracking down and will no longer allow developers to prompt users to pay with their credit card, rather than offering a subscription through Google’s billing service for in-app purchases.

Here’s what Google’s existing Play Store guidelines say, in part:
Developers offering products within a game download on Google Play or providing access to game content must use Google Play In-app Billing as the method of payment.
Developers offering products within another category of app downloaded on Google Play must use Google Play In-app Billing as the method of payment, except for the following cases:
Payment is solely for physical products.
Payment is for digital content that may be consumed outside of the app itself (e.g. songs that can be played on other music players).

Even with these policies in place, Google has more or less allowed some high-profile companies to circumvent the guideline by turning a blind eye when they offer an alternative method of payment. With Google ready to double down on the requirement, developers will allegedly get a short grace period to comply before facing enforcement. Apple has recently come under fire for a similar practice — though the Cupertino-based company has strictly enforced its own requirements from the very beginning.

Google’s updated policies will surely escalate what is growing into an ugly battle between developers and Apple and Google. Both companies are already embroiled in an ugly legal battle with Epic Games, which recently tried to circumvent App Store and Play Store policies by encouraging Fortnite players to purchase in-game content from Epic directly. Apple and Google responded by taking Fortnite down from their respective app stores.

Meanwhile, it was announced this week that some of the industry’s most popular developers, including Epic Games, Spotify, and Tile, were banding together to create the Coalition for App Fairness. The group’s aim is to “create a level playing field for app businesses.”

Google’s Android platform allows users to access multiple app stores, while apps can also be side-loaded. But if developers want to be in the Play Store, they have to abide by Google’s rules. We’ll see what the response is like when Google clarifies its stance on in-app purchases next week.


#google #playstore #fee #30%
The #Epic @fedilab @k9mail cases have reinforced our strong stance that we must control the distribution channels of #FLOSS and no longer depend on the #PlayStore

A major threat to the adoption of an alternative is that users expect updates to be automatic but #Google made that possible only for the #PlayStore

Code Lutin will invest on @fdroidorg to make software update possible on non-rooted #Android devices thus, allowing people to adopt #FreeSoftware

#MécénatCodeLutin #DeleteGoogle #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Here’s a sneak peek at Aurora Store v4, a big update to the open source Play Store client

The Aurora Store is a popular open-source client of the Google Play Store, allowing users to search, download, and update Android apps and games on any device running Android 5.0 and above. The app’s main highlight is that it doesn’t require GApps, MicroG, or Google service of any kind. Originally a fork of the Yalp Store, the app was later rewritten from scratch to offer a modern UI with Material Design.

The team behind Aurora Store is working on a major update that improves the app discovery and brings the user interface a step closer to the Google Play Store. XDA Senior Member Hb20032003 has shared some images — originally posted over at Aurora Store’s official Telegram group — giving us a sneak peek at what the fresh UI will look like. As you can see in the screenshots below, the new UI is clearly inspired by the Google Play Store, focusing on making it easier to discover new apps. The old Home, Updates, Categories tabs have been replaced by the Apps, Games, and Updates, and there’s now a floating search button instead of the top search bar. We also see new columns such as “For You,” “Top Charts,” and “Editor’s Choice,” along with proper app categories.

https://www.xda-developers.com/aurora-store-v4-update-sneak-peek-open-source-play-store-client/

#aurora #appstore #playstore #client
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Why is Telegram no longer updated in the Play store?

All third party clients will be removed from play.

As you know, Telegram Android's code is full of coupling, complexity, and shit. They compress a month's worth of shit into one commit at a time and release it, then close the issue section. But is there more?

Last year, the Play store required all apps to update their target API to 29 (Android Pie).

One year later, what has Telegram changed? Just a requestLegacyExternalStorage cheat symbol.

Back to the question, why is Telegram no longer updated in the play store? Because they don't want to modify their shit mountain for their users; to avoid being unexplainable, they stop updating a month in advance, and once they are taken down by Google, it can be attributed to censorship.

Oppose censorship, but don't support being fed shit.

If this happens, please don't support Telegram, for the sake of true freedom.

https://telegra.ph/Why-is-Telegram-no-longer-updated-in-the-Play-store-04-26

#telegram #google #playstore #updates #censorship #comment
📡 @nogoolag 📡 @blackbox_archiv
JavaScript developers left in the dark after DroidScript software shut down by Google over ad fraud allegations

Developers frustrated after being only able to discuss with Google bots

https://www.theregister.com/2021/04/27/droidscript_google_ban/

Google have declared Droidscript is malware
https://groups.google.com/g/androidscript/c/Mbh5TZ6YYnA/m/GflwflqaDAAJ


#droidscript #playstore #Google
Google Play makes bizarre decision to ban call-recording apps

Google abandoned plans for a call-recording API in 2020, now it bans workarounds?

Google has announced a bizarre policy that effectively bans call-recording apps from the Play Store. As part of Google's crackdown on apps that use Android's accessibility APIs for non-accessibility reasons, Google says call recording is no longer allowed via the accessibility APIs. Since the accessibility APIs are the only way for third-party apps to record calls on Android, call-recording apps are dead on Google Play.
#google #callrecording #playstore #android #accessibility
🔴 App download / install / manage

Google PlayStore can be installed with #minmicrog and other microg installers. Some apps you bought with a Google account may require it to check for licenses.
If it doesn't work check possible solutions here: https://t.me/NoGoolag/19314 ( #issues )

You can buy apps with your Google account from a web browser and then download it with Google playstore / Aurora Store / Yalp Store

Don't buy apps to Google, you're financing that evil corporation with the 30% cut they take from every app sold

Here are some better alternatives to get and manage Android apps:

🎁 F-Droid
apks from f-droid.org repository or extra repositories
https://t.me/NoGoolag/1034

🎁 Aurora Droid (F-Droid foss client)
apks from f-droid.org repository or extra repositories
https://t.me/NoGoolag/1242

🎁 Aurora Store (Google Playstore foss client)
apks from Google Playstore
https://t.me/NoGoolag/1123
⚠️ Google broke the search function in Aurora Store at the moment. Try the nightly version. You may find more info at @AuroraSupport
or https://gitlab.com/AuroraOSS/AuroraStore

🎁 Neo Store (F-Droid foss client)
https://t.me/NoGoolag/14666

🎁 Droidify (F-Droid foss client)
https://github.com/Iamlooker/Droid-ify/releases

🎁 App Lounge by eOS (Foss/commercial/pwa)
https://doc.e.foundation/support-topics/app_lounge

🎁 Obtainium (Foss apps from multiple sources)
https://github.com/ImranR98/Obtainium

🎁 Accrescent
https://accrescent.app

🎁 Skydroid
https://github.com/redsolver/skydroid
https://get.skydroid.app

🎁 Foxy Droid (F-Droid foss client)
apks from f-droid.org repository or extra repositories
https://f-droid.org/app/nya.kitsunyan.foxydroid/
https://github.com/kitsunyan/foxy-droid

🎁 apkeep
https://www.eff.org/deeplinks/2021/09/introducing-apkeep-eff-threat-labs-new-apk-downloader
https://github.com/EFForg/apkeep

🎁 APKGrabber
apks from Google Play, APKPure, APKMirror or Uptodown (enable Izzy repo)
https://f-droid.org/app/de.apkgrabber

🎁 APKMirror
apks from APKMirror
https://f-droid.org/app/taco.apkmirror

🎁 ApkTrack
Updates on PlayStore and other sources
https://f-droid.org/app/fr.kwiatkowski.ApkTrack

🎁 Kali Nethunter Store
Pentesting apps
https://store.nethunter.com

🎁 Evozi apk downloader (website)
https://apps.evozi.com/apk-downloader

🎁 Raccoon
APK Downloader for Linux, Windows and MacOS
https://raccoon.onyxbits.de


🔴 App management

🛠 AppManager
@AppManagerChannel
https://github.com/MuntashirAkon/AppManager
https://f-droid.org/repo/io.github.muntashirakon.AppManager

🛠 AppWarden
https://t.me/AuroraOfficial/59
Izzy repo https://apt.izzysoft.de/fdroid/repo/com.aurora.warden

🛠 /d/gapps
Delete/disable GApps and other bloatwares
https://t.me/NoGoolag/1247

🛠 Batch Uninstaller
Uninstall multiple applications at once
https://f-droid.org/app/com.saha.batchuninstaller

🛠 Apk Extractor
Extract APKs from your device, even if installed from the Playstore. Root access
https://f-droid.org/app/axp.tool.apkextractor

🛠 OpenAPK
App manager uninstall, hide, disable, extract, share
https://f-droid.org/app/com.dkanada.openapk

🛠 NeoBackup
https://github.com/NeoApplications/Neo-Backup


🔴 App info

🔬 ClassyShark3xodus
Scan apps for trackers
https://f-droid.org/app/com.oF2pks.classyshark3xodus

🔬 Exodus Privacy
Analyzes privacy concerns in apps from Google Play store
https://f-droid.org/app/org.eu.exodus_privacy.exodusprivacy

🔬 App Watcher
Follow updates and changelogs of apps in Play Store not currently installed on your device (enable Izzy repo)
https://f-droid.org/app/com.anod.appwatcher

🔬 Stanley
Explore app info for developers
https://f-droid.org/app/fr.xgouchet.packageexplorer


📡 @NoGoolag 📡 @Libreware
#apk #install #app #playstore #store #alternatives #fdroid #aurora #yalp #huawei