Share

Google will pay you to help solve Android bugs

Cape Town - Google has expanded its bug reward programme to Android smartphones, with the search giant promising to pay for vulnerabilities discovered.

"Today, we're expanding our program to include researchers that will find, fix, and prevent vulnerabilities on Android, specifically," Jon Larimer, Android Security Engineer wrote on the official Google blog on Tuesday.

Google will pay for each step required to fix a security bug on its Nexus 6 and 9 smartphones for sale on the Play Store.

The company already makes reward payments for bugs discovered in the Chrome browser and Larimer said that in 2014, Google paid out $1.5m in rewards.

In the Android programme, the rewards will be limited to AOSP or Android Open Source Project code as well vulnerabilities discovered in libraries and drivers.

Third party code vulnerabilities such as chip-set firmware will generally not be covered unless it impacts on the security of Android, Google said.

Rewards

"In addition to rewards for vulnerabilities, our program offers even larger rewards to security researchers that invest in tests and patches that will make the entire ecosystem stronger," said Larimer.

Rewards are divided into critical, high, and moderate severity and Google will typically pay $2 000, $1 000 and $500 respectively.

However, researchers who demonstrate serious security failures can expect to earn higher rewards, said Larimer.

"The largest rewards are available to researchers that demonstrate how to work around Android's platform security features, like ASLR, NX, and the sandboxing that is designed to prevent exploitation and protect users."

Android faces a similar threat landscape that Windows faces as the dominant operating system. (Duncan Alfreds, Fin24)

For serious application exploits that can be demonstrated to compromise the kernel, Google will pay out an additional $10 000, with successful remote attacks netting up to $30 000.

The company warned that while the reward amounts were not set in stone, it would pay more for "unusually clever or severe vulnerabilities".

Android is the most popular mobile operating system and criminals have turned their attention to steal personal and financial data from users.

Security scans

"IBM found that 73% of the 41 popular dating applications analysed have access to current and historical GPS location information. Hackers may capture your current and former GPS location details to find out where you live, work or spend most of your day," IBM said of its study to investigate vulnerable applications.

But Google said that it performs 200 million security scans of devices per day to ferret out malicious applications.

"Fewer than 1% of Android devices had a Potentially Harmful App (PHA) installed in 2014. Fewer than 0.15% of devices that only install from Google Play had a PHA installed," said Adrian Ludwig, lead engineer for Android Security.

Google indicated that rewards that go unclaimed for 12 months will be donated to charity.


- Follow Duncan on Twitter

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.16
-0.2%
Rand - Pound
23.82
-0.1%
Rand - Euro
20.47
-0.1%
Rand - Aus dollar
12.46
-0.5%
Rand - Yen
0.12
-0.2%
Platinum
926.50
+0.7%
Palladium
1,029.50
+0.3%
Gold
2,321.39
-0.0%
Silver
27.28
-0.1%
Brent Crude
88.42
+1.6%
Top 40
68,461
+0.6%
All Share
74,433
+0.6%
Resource 10
60,005
+0.7%
Industrial 25
103,854
+1.0%
Financial 15
15,879
-0.1%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders