6 ms·
Google Play will no longer pay to discover vulnerabilities in Android apps
- samename 2y agoAndroid is already known to be less secure than iOS, how much worse will it get now?
- sva_ 2y agoProbably not much. Main risk on Android is from shady apps. The reward program was only aimed at very popular apps.
- stronglikedan 2y agomaybe once upon a time, but that's no longer the case. they each have vulnerabilities, just different ones.
- nonplus 2y agoThat question seems like it has to be framed in a misunderstanding of how secure you believe the iOS platform is. Here's a list of CVEs for iOS just this year: https://www.bitsight.com/blog/apple-vulnerabilities-cisa-known-exploited-vulnerabilities https://www.bitsight.com/blog/apple-vulnerabilities-cisa-kno... If you went back farther, you would find exploits that compromise your iOS device simply by receiving a compromised jpg image, not even by you opening the message. https://arstechnica.com/gadgets/2023/09/apple-patches-clickless-0-day-image-processing-vulnerability-in-ios-macos/ https://arstechnica.com/gadgets/2023/09/apple-patches-clickl... I think the expectation in 2024 should simply be 0 day exploits are available for purchase that target both platforms, neither is secure.
- 015a 2y agoOn your iPhone, recognizing and accepting the obvious risk that a stranger on the internet is telling you to enter some weird input in your computer: pull down Spotlight and type "":: iOS is a very buggy operating system; they polish the hell out of the top of it, but its internals are hairy and scary. That first paragraph doesn't represent a security bug, but its adjacent to many other, more serious problems iOS has had. Its about once every-other year we get some wild bug where a complete stranger can text you a specially crafted string of unicode characters and it crashes the entire OS. It isn't fair or accurate to say that Android is less secure than iOS in 2024. They both have problems, and both will continue to have problems, but both are significantly more secure than they were 10 years ago, and its very rare for applications downloaded from their respective official app stores to do significant damage to the user. The correct lens through which to view this policy change is: It was a program which exclusively worked with "major applications", and this kind of program is a responsibility which these major applications should take on, not Google.
- buildbot 2y agoHuh, wild. “:”: also crashes spotlight on iOS 18.1
- ikekkdcjkfke 2y agoThe fix for this is obviously to pre-filter that exact string /s
- buildbot 2y agoYeah, there’s a few more I’ve found now too. It’s interesting, any search box can trigger it, for example, the settings app search. Essentially anything for x will crash it: “”:x
- rfl890 2y agoBetween the both of them, I would take the more "open" one.
- wnevets 2y agoiOS has a hardware backdoor built in. [1] [1] https://bgr.com/tech/the-most-sophisticated-iphone-attack-ever-used-a-hidden-hardware-feature-to-backdoor-the-phone-but-youre-safe/ https://bgr.com/tech/the-most-sophisticated-iphone-attack-ev...
- overstay8930 2y agoAndroid isn’t less secure but you can definitely screw up Android way more than you can iOS, there are some massive botnets that run purely on Android.
- ece 2y agoAndroid TV boxes are really like the Windows ME of yore.
- LegitShady 2y agoPretty sure many of them come pre-pwned
- rty32 2y agoReference needed.
- joemazerino 2y agoConsidering zerodium and other 0day vendors are spending more on Android than iPhone, I don't agree. https://zerodium.com/program.html https://zerodium.com/program.html
- metadat 2y agoIs Android just so good there are no major vulns anymore? Does Apple have a comparable program? I don't see a reference in the Apple materials about any bounty reward program for Apps vulnerabilities [1]. If this is true, then Google was going above and beyond and is now simply reverting to the mean so they can reduce any potentially excess financial spend. Maybe they don't actually care so much about their users after all? If they were shifting the limited funds to a more effective vehicle, they missed the prime opportunity to mention it (tongue in cheek, because Elgoog doesn't have real resource constraints). [1] https://security.apple.com/bounty/categories/ https://security.apple.com/bounty/categories/
- zorgmonkey 2y agoThey still have the bug bounty for the Pixel devices. I don't know they ever had one for the open source Android OS (AOSP), but a bug in AOSP would be likely to effect a Pixel device. The bug bounty that is getting removed is one that google offered for certain very popular apps in the play store. I also see that have bug bounty's for some of the main Google android apps. https://bughunters.google.com/about/rules/android-friends/6171833274204160/android-and-google-devices-security-reward-program-rules https://bughunters.google.com/about/rules/android-friends/61... https://bughunters.google.com/report/targets/290590452 https://bughunters.google.com/report/targets/290590452
- UncleMeat 2y agoApple never had a comparable program. This was a program finding vulns in non-Google apps on Play. A cool idea, but I suspect challenging to operate without teeth making the developers actually update their apps.
- mmaunder 2y agoHope we’ll get there with WordPress plugins. For now we (Wordfence) are paying over $30,000 per vulnerability for the top vulns.
- pookybear223 2y agowow, $30,000 relative to how much google was paying seems incredulous. curious where you all allocate this funding from internally. we consider such thing soon on our site.
- popcalc 2y agoHalf the internet runs on WordPress. I'd imagine they have the capital to invest in it.
- ayberk 2y agoAs a Google engineer, it's really saddening to see the Welchism completely taking over Google. There are more than enough examples showing focusing on bottomline to increase shareholder value doesn't work in the long run, but it's obvious the current leadership doesn't care.
- fngjdflmdflg 2y agoLooking at your profile, on the bright side I have heard GCP is still more of a forward looking unit, and Google Cloud Run for example is a pleasure to use, especially for small side projects.
- ein0p 2y agoThis is an interesting corporate paradox that existed forever. It boils down to this: profit centers are always more frugal than cost centers. With cost centers you can say “you gotta spend money to make money” and PHBs will nod their heads. With established profit centers the most profitable (in the short run) course of action is to cut cost.
- ggm 2y agoI would say this slightly differently. Cost Centres are increadibly focussed on the bottom line costs, but they fight fiercely to defend necessary spend and are not scared of spending astronomically higher amounts to get to a better place longterm. Mostly I believe because cost centres retain staff and have to have a long term outlook. Profit centres, lacking any understanding of costs, are scared to increase them and fixed on reducing them, even when short-term profit destroys long term market share. Mostly because profit centres reward on a short cycle and have high turnover as staff seek bigger profits.
- woodseigh 2y ago[dead]
- ElevenLathe 2y ago
- BLKNSLVR 2y agoDoes this mean they're, in parallel, reducing their cut for apps sold via the Play Store?
- paxys 2y agoHow are the two related?
- DutchRanger 2y agoBecause you used to give a certain % to Google for their service that includes the Security Reward Program. But now that they are shutting it down you get less for the amount you pay for the service.
- BLKNSLVR 2y agoGood question, I don't know, but it feels as if their bug bounty service is something that contributes to the level of trust in the apps listed in the play store for which they charge a premium. Less trust; less money on the line on which to base that trust equates, for me, to a reduced premium for a listing.
- cultureswitch 2y agoAny big company is incapable and ultimately unwilling to bring meaningful security curation to an app store, exhibit 3843579401
- deleted 2y ago[deleted]
- will5421 2y agoSeems reasonable. App authors would’ve been “discovering” vulnerabilities in their own apps and asking Google to pay for them.
- ainiriand 2y agoUnfortunately it does not work that way. They are meant to be vulnerabilities exploiting Android through the app, not backdoors in the app. It is meant to secure the Android OS, not to secure the app.
- a_dabbler 2y agoThere's a separate program for bugs in the Android OS, this program did pay for finding bugs in the app to secure the app. Also the mitigation for people abusing the program is that they only pay for bugs in popular apps, it's unlikely for a major app dev to be backdooring their code just to try and scam this bounty program
- ainiriand 2y agoAh thanks for clarification. It got it wrong it seems!
- paxys 2y agoBug bounty programs for Android still exist. This one was specifically about finding vulnerabilities in apps themselves.
- UncleMeat 2y agoThe program was operated through HackerOne (at least the last time I looked at this thing back in like 2018), which does the basic due diligence to address things like this.
- joemazerino 2y agoThere's an app download requirement to prevent this.
- 39896880 2y agoWhy should they? It’s your device. You own it. It’s your responsibility to make sure you don’t install malicious code.
- immibis 2y agoGoogle promises that apps in the app store are safe.
- horsawlarway 2y agoIn the most basic sense - they should be concerned about malicious code because they're busy advertising and distributing those apps for a cut of the profit. If Google were to say "No more checking for vulnerabilities in FDroid... (or insert other)" I would agree with your take - that seems like common sense. Not their store, not their problem. Same for side-loaded apps. But that's not what's happening. They're busy selling those malicious/vulnerable apps for a cut of the profit. Now - Google can be a responsible party here without having this program (there are plenty of valid discussions around whether this was really an effective way to combat malware on their store) - but to recap... The store doesn't get to absolve themselves of responsibility for the things it's selling. "It's the store's responsibility not to sell me malicious/defective products". If they can't do that... maybe they shouldn't be allowed to operate that store anymore.
- 39896880 2y agoAs of March 2024, ~97 percent of apps in the Google Play app store were freely available. So they’re not selling much.
- dartos 2y agoThe money isn’t in the apps themselves. App devs pay Google to promote their apps and Google likely takes a cut of any micro transactions that go through their pay platform
- goldfishgold 2y agoWhat a ridiculous idea. You think your mother should or is capable of auditing the Facebook app before installing it?
- Woshiwuja 2y agoGood idea!
- 486sx33 2y agoThis is really disappointing. Google play store was struggling enough with evil apps but it was the one “trusted” source. A real opportunity exists for trusted and vetted apps. I guess Google will just sell anything now