illogical-robot / apkmirror-public

APKMirror.com bugs
http://www.apkmirror.com
100 stars 32 forks source link

Contains dangerous apps? #183

Closed andyg21 closed 3 years ago

andyg21 commented 3 years ago

Expected behavior

APKMirror must not contain dangerous apps

Actual behavior

APKMirror contains dangerous apps (as reported by Chrome browser on Android device) Screenshot_20210630-201859_Chrome

Steps to reproduce the problem

Visit https://www.apkmirror.com/apk/hola/hola-free-vpn-proxy/hola-free-vpn-proxy-1-184-486-release/hola-free-vpn-proxy-unblocker-arm7a_1-184-486-android-apk-download/

archon810 commented 3 years ago

Google has flagged Hola VPN for some reason, but it's not clear why. Their app is missing from the Play Store now too.

There's http://adios-hola.org/ but it's from 2015.

If you're aware of something that definitively shows Hola isn't safe, we'll consider further action.

archon810 commented 3 years ago

Google's own page for this https://transparencyreport.google.com/safe-browsing/search?url=https:%2F%2Fwww.apkmirror.com%2Fapk%2Fhola%2Fhola-free-vpn-proxy%2Fhola-free-vpn-proxy-1-184-486-release%2F&hl=en-US simply states "Distribute uncommon downloads" without further explanation, which is nonsense.

TPS commented 3 years ago

There're more pertinent details w/ links @ Wikipedia, starting from the 2015 paragraph onwards.

archon810 commented 3 years ago

There are some explanations of how their network works, but it doesn't mean it's currently considered malware.

andyg21 commented 3 years ago

https://www.haaretz.com/israel-news/tech-news/.premium-a-brothers-feud-and-a-trojan-horse-dispute-reveals-web-s-dark-side-1.9959383

archon810 commented 3 years ago

@andyg21 I'm not a subscriber. Can you share the full text somewhere please?

Edit: Found the text on their AMP site. https://www.google.com/amp/s/www.haaretz.com/amp/israel-news/tech-news/.premium-a-brothers-feud-and-a-trojan-horse-dispute-reveals-web-s-dark-side-1.9959383

TPS commented 3 years ago

All that's pretty extraordinary. @archon810 Does it influence this issue 1 way or the other?

archon810 commented 3 years ago

At this point I don't see a reason to remove Hola from the site unless a more damning and conclusive report comes out, preferably by a security vendor or Google itself. Users will continue to see the notice but only on Hola pages from what I can tell.

archon810 commented 2 years ago

I can no longer reproduce seeing this warning on https://www.apkmirror.com/apk/hola/hola-free-vpn-proxy/hola-free-vpn-proxy-1-184-486-release/hola-free-vpn-proxy-unblocker-arm7a_1-184-486-android-apk-download/ or any other Hola page on apkmirror. Closing.