173
submitted 1 year ago by L4s@lemmy.world to c/technology@lemmy.world

Two file management apps on the Google Play Store have been discovered to be spyware that quietly sends user data to servers in China.

you are viewing a single comment's thread
view the rest of the comments
[-] Tankaus@lemmy.world 122 points 1 year ago

The fishy apps are File Recovery & Data Recovery and File Manager, according to an alert this week from Pradeo, a leading mobile cybersecurity company. The apps, both from the same developer, are programmed to launch without any input from the user and quietly send sensitive user data to servers based in China.

[-] eroc1990@lemmy.parastor.net 38 points 1 year ago

Thank you for posting this, since OP wasn't kind enough to include it in the post description.

[-] BettyWhiteInHD@lemmy.world 36 points 1 year ago* (last edited 1 year ago)

Update: L3s made the decision to mark it as a bot and has taken the time to reach out and sort of explain their thought process and feelings and I really appreciate it. No bad blood or hurt feelings or anything, and I genuinely think that there's value and good intention in what they're doing, I just had an issue with this one specific thing and it looks like we got past it. No big deal, we're all adults, now let's eat some cheese.


@L4s is a bot account and not marked as such in the account preferences. I've messaged the owner of the account about it and asked them to toggle that on, but so far I've heard nothing, so I'm reaching out to support. They are also a moderator here.

[-] eroc1990@lemmy.parastor.net 18 points 1 year ago

I didn't even notice it was missing the bot marker. Good catch.

@L3s@lemmy.world you plan on fixing that any time soon?

[-] L3s@lemmy.world 8 points 1 year ago* (last edited 1 year ago)

Edit: I've realized I'm wrong below. A bot is a bot, and mine is no exception. Sorry to anyone who felt deceived, that was not my intention.

@BettyWhiteInHD@lemmy.world my apologies for not replying, I read your message while updating a bunch of code for the bot and forgot to reply.

When I made L4s I had gone through Lemmy’s Code of Conduct, and didn’t see where that was required for bots? If I misunderstood the Code of Conduct I will gladly mark it as a bot, or if the admins of lemmy.world clarify to me they want it to be done. Please let me know if you are aware of where it is required, as I want to abide by the the rules here, and don't want to annoy anyone. Maybe @ruud@lemmy.world could clear this up for me, I know he is extremely busy though.

The goal of L4s is to help jump-start communities and content, and I felt 99% of people uncheck “show bot accounts” since they don’t want what would be the equivalent of “automod”, spellchecker bots, etc to show up - not something that's bringing them content they subscribed to or previously enjoyed on reddit.

So far it’s helped multiple communities that way (see !technology@lemmy.world prior to its posts, and a few days after, it’s now the largest "active users" community on all instances), and has sparked a lot of conversations in the posts. The reason I bring that up is most have not complained about the fact it’s not checked, even though I do not hide that it’s a bot in any way, and most enjoy seeing the content it posts. Checking that would mean that those who don't quite understand there are content bots, would no longer see these posts.

Also, yes, I'm a mod here. My role irl is very deeply technology related, that is what I enjoy. In my free-time I have been trying to make Lemmy.World one of the best instances as far as content, and helping keep !technology@lemmy.world on-topic and toxic free.

[-] Rentlar@lemmy.ca 19 points 1 year ago

I second the suggestion to mark @L4s@lemmy.world as a bot. Regardless of what the CoC says, it would be unethical not to.

In this thread people were complaining about how the body contained insufficient information, and the copied title of the article is click bait. A human poster would be able to respond to these concerns whereas a bot cannot.

I think it would be overall healthier for the Fediverse as a whole if the bot-marking feature was widely respected and exceptions like this not being taken.

[-] eroc1990@lemmy.parastor.net 12 points 1 year ago

This was my main concern. It felt very low effort and felt like a Reddit karma farmer, not a bot meant to spark discussion within the community. I wouldn't have had an issue with the content if it was clear that the post was made by a bot.

[-] L3s@lemmy.world 10 points 1 year ago* (last edited 1 year ago)

Edit: I've realized my mistake and will just leave it on, my bot is not above any other, and my goal doesn't justify not checking the box.

That's a fair point, and seeing that a lot of people would prefer it be on, I will probably reconsider my stance regardless of what the admins say.

[-] Rentlar@lemmy.ca 6 points 1 year ago

I still appreciate your work in modding and creating tools that help make Lemmy.world thrive. Thanks for your consideration as well.

[-] BettyWhiteInHD@lemmy.world 9 points 1 year ago* (last edited 1 year ago)

Update: L3s made the decision to mark it as a bot and has taken the time to reach out and sort of explain their thought process and feelings and I really appreciate it. No bad blood or hurt feelings or anything, and I genuinely think that there's value and good intention in what they're doing, I just had an issue with this one specific thing and it looks like we got past it. No big deal, we're all adults, now let's eat some cheese.


I understand your reasoning and the purpose of this bot and I'm sure a lot of people are happy with it and appreciate it and I'm not against your work on this bot in any way. But the reason why I think it's important to mark it as a bot, because to not do so is genuinely misleading and forces people like me to bypass the built in "Please don't show bots" check in favor of blocking a bot account.

It's a bot; I specifically have a "Show bot accounts" unchecked; I'm still seeing a bot.

It may or may not be against ToS, at the end of the day I don't really care that much to be honest, but if I put myself on a "Do not call" list and still get calls from spammers, it's annoying even if it were entirely legal. I'm not saying it's as bad as that or that you're spamming for nefarious purposes, but there is a built in feature into the platform that allows people to be transparent and mark accounts as bots and users to choose to opt out of seeing those and that's a great, fairly unique feature to this platform.

Checking that would mean that those who don’t quite understand there are content bots, would no longer see these posts.

And respectfully, I don't think it's up to you to make that distinction for users that choose to opt out of seeing bot accounts. A bot is a bot. If people are OK with seeing your bot or the inevitable remindme or cat facts or whatever, they can enable that in their preferences, it's up to the user.

I hope you understand, this isn't an attack against you or your work in any way.

[-] L3s@lemmy.world -4 points 1 year ago* (last edited 1 year ago)

~~And respectfully, I don’t think it’s up to you to make that distinction for users that choose to opt out of seeing bot accounts.~~

~~Not to sound rude here, but I feel the same about you asking me to check that box.~~

~~Again, if the admins request me to check it, I will do it - or if the Code of Conduct changes. Lets see what they say in the post you made on !support@lemmy.world and go from there.~~

I was rude and wrong here.

[-] cyanarchy@sh.itjust.works 4 points 1 year ago

Not to sound rude here, but I feel the same about you asking me to check that box.

Task failed. These provisions were made with the expectation that individuals such as yourself would act in good faith. It's alarming to hear that a moderator of any community feels they are above that standard.

[-] L3s@lemmy.world 7 points 1 year ago* (last edited 1 year ago)

I agree, and have realized it's there for this reason. The bot button is checked on L4s.

In the comment above I was getting frustrated, as I'm doing something to try and help in my spare time and felt the work I've put in was being diminished. I let that get the best of me, and I shouldn't have.

[-] cyanarchy@sh.itjust.works 3 points 1 year ago

Thank you for understanding, I'm sorry if I came off combative myself. I would like to point out that the service you are providing is certainly useful. Personally, I'm only interested in seeing content that is parsed by a human and posted because of the natural interest around it. Otherwise, things get posted so fast and across enough communities that it drowns out all real and natural discussion in my subscription feed. That doesn't mean other people won't see and interact with these posts, and it doesn't mean they don't help grow a community. The nature of the fediverse itself seems to be a little messy, and sometimes people see different things even within the same community.

It might be nice for there to be a more fine-toothed control over what type of bot an account is flagged as, and what types of bots an individual user might see. I've disallowed viewing bot accounts since day one, mostly to avoid inane joke response bots as they were so prevalent on reddit. That's going to be a problem long term, because automoderators were a critical aspect of moderating larger communities.

[-] L3s@lemmy.world 4 points 1 year ago* (last edited 1 year ago)

I've disallowed viewing bot accounts since day one, mostly to avoid inane joke response bots as they were so prevalent on reddit.

I did the same thing for the same reason, and was my initial reasoning for not marking L4s. When I read "bots" my initial thought was the useless pun bots, or autocorrect bots, etc.

My plan to make mine different was if someone didn't receive a comment back on a less visible post, to comment back on L3s to keep conversations going, as the communities I've focused on are ones I enjoyed on [website we don't name] and genuinely enjoyed engaging there. I did that semi-successfully, but didn't consider that the majority of people wouldn't want to even see a content bot, and that was my mistake.

Pride put to the side, lesson learned and hopefully L4s can continue to help.

[-] techt@lemmy.world 6 points 1 year ago

I agree with the sentiment from the others here, but I also wanted to add that as a general rule, you shouldn't behave in a way that would be detrimental for the community if everyone did it. Bots should be marked as bots, or the user preference switch to show content from bots is meaningless regardless of how positive or influential you think yours is -- as I'm sure most bot creators feel about their own work.

It's understandable that you want to have a positive impact, and that is commendable, but your bot shouldn't be an exception just by your own judgment, especially considering the problems with what the bot is doing that have been pointed out to you.

Just my take. I would prefer your bot, and all bots, be marked as such irrespective of function.

[-] MedicPigBabySaver@lemm.ee 1 points 1 year ago

So, you're a weasel level jackass. Duly noted.

[-] L3s@lemmy.world 0 points 1 year ago

Yes. If you keep reading, I acknowledge that. A bot is a bot, mine is no exception.

[-] TheGoldenGod@lemmy.world 11 points 1 year ago

OP is a bot account apparently.

[-] eroc1990@lemmy.parastor.net 5 points 1 year ago

I noticed that after my comment. Still a low quality post from a bot seemingly farming for clicks through to articles, where a description summary from a human or better parsing from the bot could have improved the quality of the post.

[-] TheGoldenGod@lemmy.world 5 points 1 year ago

Agreed, the amount of clicks for the article would increase exponentially if they actually added context for those of us who never click these links.

this post was submitted on 09 Jul 2023
173 points (92.2% liked)

Technology

58311 readers
6674 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS