[HN Gopher] Google Play will no longer pay to discover vulnerabi...
___________________________________________________________________
Google Play will no longer pay to discover vulnerabilities in
Android apps
Author : axiomdata316
Score : 120 points
Date : 2024-08-21 23:06 UTC (17 hours ago)
(HTM) web link (www.androidauthority.com)
(TXT) w3m dump (www.androidauthority.com)
| samename wrote:
| Android is already known to be less secure than iOS, how much
| worse will it get now?
| sva_ wrote:
| Probably not much. Main risk on Android is from shady apps. The
| reward program was only aimed at very popular apps.
| stronglikedan wrote:
| maybe once upon a time, but that's no longer the case. they
| each have vulnerabilities, just different ones.
| nonplus wrote:
| That question seems like it has to be framed in a
| misunderstanding of how secure you believe the iOS platform is.
| Here's a list of CVEs for iOS just this year:
| https://www.bitsight.com/blog/apple-vulnerabilities-cisa-kno...
|
| If you went back farther, you would find exploits that
| compromise your iOS device simply by receiving a compromised
| jpg image, not even by you opening the message.
| https://arstechnica.com/gadgets/2023/09/apple-patches-clickl...
|
| I think the expectation in 2024 should simply be 0 day exploits
| are available for purchase that target both platforms, neither
| is secure.
| 015a wrote:
| On your iPhone, recognizing and accepting the obvious risk that
| a stranger on the internet is telling you to enter some weird
| input in your computer: pull down Spotlight and type ""::
|
| iOS is a _very_ buggy operating system; they polish the hell
| out of the top of it, but its internals are hairy and scary.
| That first paragraph doesn 't represent a security bug, but its
| adjacent to many other, more serious problems iOS has had. Its
| about once every-other year we get some wild bug where a
| complete stranger can text you a specially crafted string of
| unicode characters and it crashes the entire OS.
|
| It isn't fair or accurate to say that Android is less secure
| than iOS in 2024. They both have problems, and both will
| continue to have problems, but both are significantly more
| secure than they were 10 years ago, and its very rare for
| applications downloaded from their respective official app
| stores to do significant damage to the user. The correct lens
| through which to view this policy change is: It was a program
| which exclusively worked with "major applications", and this
| kind of program is a responsibility which these major
| applications should take on, not Google.
| buildbot wrote:
| Huh, wild. ":": also crashes spotlight on iOS 18.1
| ikekkdcjkfke wrote:
| The fix for this is obviously to pre-filter that exact
| string /s
| buildbot wrote:
| Yeah, there's a few more I've found now too. It's
| interesting, any search box can trigger it, for example,
| the settings app search.
|
| Essentially anything for x will crash it: "":x
| rfl890 wrote:
| Between the both of them, I would take the more "open" one.
| wnevets wrote:
| iOS has a hardware backdoor built in. [1]
|
| [1] https://bgr.com/tech/the-most-sophisticated-iphone-attack-
| ev...
| overstay8930 wrote:
| Android isn't less secure but you can definitely screw up
| Android way more than you can iOS, there are some massive
| botnets that run purely on Android.
| ece wrote:
| Android TV boxes are really like the Windows ME of yore.
| rty32 wrote:
| Reference needed.
| metadat wrote:
| Is Android just so good there are no major vulns anymore?
|
| Does Apple have a comparable program?
|
| I don't see a reference in the Apple materials about any bounty
| reward program for Apps vulnerabilities [1]. If this is true,
| then Google was going above and beyond and is now simply
| reverting to the mean so they can reduce any potentially excess
| financial spend. Maybe they don't actually care so much about
| their users after all? If they were shifting the limited funds to
| a more effective vehicle, they missed the prime opportunity to
| mention it (tongue in cheek, because Elgoog doesn't have _real_
| resource constraints).
|
| [1] https://security.apple.com/bounty/categories/
| zorgmonkey wrote:
| They still have the bug bounty for the Pixel devices. I don't
| know they ever had one for the open source Android OS (AOSP),
| but a bug in AOSP would be likely to effect a Pixel device. The
| bug bounty that is getting removed is one that google offered
| for certain very popular apps in the play store. I also see
| that have bug bounty's for some of the main Google android
| apps.
|
| https://bughunters.google.com/about/rules/android-friends/61...
| https://bughunters.google.com/report/targets/290590452
| UncleMeat wrote:
| Apple never had a comparable program.
|
| This was a program finding vulns in non-Google apps on Play. A
| cool idea, but I suspect challenging to operate without teeth
| making the developers actually update their apps.
| mmaunder wrote:
| Hope we'll get there with WordPress plugins. For now we
| (Wordfence) are paying over $30,000 per vulnerability for the top
| vulns.
| pookybear223 wrote:
| wow, $30,000 relative to how much google was paying seems
| incredulous. curious where you all allocate this funding from
| internally. we consider such thing soon on our site.
| ayberk wrote:
| As a Google engineer, it's really saddening to see the Welchism
| completely taking over Google. There are more than enough
| examples showing focusing on bottomline to increase shareholder
| value doesn't work in the long run, but it's obvious the current
| leadership doesn't care.
| fngjdflmdflg wrote:
| Looking at your profile, on the bright side I have heard GCP is
| still more of a forward looking unit, and Google Cloud Run for
| example is a pleasure to use, especially for small side
| projects.
| ein0p wrote:
| This is an interesting corporate paradox that existed
| forever. It boils down to this: profit centers are always
| more frugal than cost centers. With cost centers you can say
| "you gotta spend money to make money" and PHBs will nod their
| heads. With established profit centers the most profitable
| (in the short run) course of action is to cut cost.
| ggm wrote:
| I would say this slightly differently. Cost Centres are
| increadibly focussed on the bottom line costs, but they
| fight fiercely to defend necessary spend and are not scared
| of spending astronomically higher amounts to get to a
| better place longterm. Mostly I believe because cost
| centres retain staff and have to have a long term outlook.
|
| Profit centres, lacking any understanding of costs, are
| scared to increase them and fixed on reducing them, even
| when short-term profit destroys long term market share.
| Mostly because profit centres reward on a short cycle and
| have high turnover as staff seek bigger profits.
| burtonator wrote:
| Time to break up Google.
| dspillett wrote:
| Or just make sure that we don't put too much into place that
| will get in the way of future disruptors, so that as they
| slowly fall out of favour due to chasing the bottom line and
| it eventually affecting their offerings to the point where a
| critical mass of users seriously look for alternatives1,
| there are viable alternatives there waiting to be found.
| Google and the other entrenched big companies spend a lot of
| lobbying money on trying to make sure the status quo can be
| maintained, by raising the barrier for entry into their
| markets.
|
| ----
|
| [1] this takes time: after _years_ of saying I'm going to
| I've finally started experimenting with using Kagi for search
| instead. It also takes _good_ alternatives, a paid option
| won't be seen as good by many.
| ddalex wrote:
| it's not Welchism, Welch at least gave the players a chance to
| stay in the game based on their own efforts.
| paxys wrote:
| Considering this program paid out a total of $265k over a
| decade, I'm gonna say cost wasn't really the concern.
| hnburnsy wrote:
| Doesn't it say they stopped reporting payouts in 2019?
| _the_inflator wrote:
| It hurts in so many ways.
|
| I re-read How Google Works, Engineering at Google, etc. Kind of
| ironically, YT delivered these fantastic talks from 2011:
|
| Google I/O 2011: HTML5 versus Android: Apps or Web for Mobile
| Development? https://youtu.be/4f2Zky_YyyQ?si=rbKgYi7Rck-6y3qE
|
| Or HTML5, CSS3, and DOM Performance, Breaking News at 1000ms
| with Patrick Hamann
|
| This was and still is fantastic stuff.
|
| The next step would be to drop the unofficial requirement that
| every manager be able to code. MBAs at Google: regression to
| the mean.
|
| Old Google was inspirational; new Google seems to evolve into
| yet another drawing board MBA construct.
| BLKNSLVR wrote:
| Does this mean they're, in parallel, reducing their cut for apps
| sold via the Play Store?
| paxys wrote:
| How are the two related?
| BLKNSLVR wrote:
| Good question, I don't know, but it feels as if their bug
| bounty service is something that contributes to the level of
| trust in the apps listed in the play store for which they
| charge a premium.
|
| Less trust; less money on the line on which to base that
| trust equates, for me, to a reduced premium for a listing.
| DutchRanger wrote:
| Because you used to give a certain % to Google for their
| service that includes the Security Reward Program. But now
| that they are shutting it down you get less for the amount
| you pay for the service.
| cultureswitch wrote:
| Any big company is incapable and ultimately unwilling to bring
| meaningful security curation to an app store, exhibit 3843579401
| will5421 wrote:
| Seems reasonable. App authors would've been "discovering"
| vulnerabilities in their own apps and asking Google to pay for
| them.
| ainiriand wrote:
| Unfortunately it does not work that way. They are meant to be
| vulnerabilities exploiting Android through the app, not
| backdoors in the app. It is meant to secure the Android OS, not
| to secure the app.
| a_dabbler wrote:
| There's a separate program for bugs in the Android OS, this
| program did pay for finding bugs in the app to secure the
| app. Also the mitigation for people abusing the program is
| that they only pay for bugs in popular apps, it's unlikely
| for a major app dev to be backdooring their code just to try
| and scam this bounty program
| ainiriand wrote:
| Ah thanks for clarification. It got it wrong it seems!
| paxys wrote:
| Bug bounty programs for Android still exist. This one was
| specifically about finding vulnerabilities in apps
| themselves.
| UncleMeat wrote:
| The program was operated through HackerOne (at least the last
| time I looked at this thing back in like 2018), which does the
| basic due diligence to address things like this.
| 39896880 wrote:
| Why should they? It's your device. You own it. It's your
| responsibility to make sure you don't install malicious code.
| immibis wrote:
| Google promises that apps in the app store are safe.
| horsawlarway wrote:
| In the most basic sense - they should be concerned about
| malicious code because they're busy advertising and
| distributing those apps for a cut of the profit.
|
| If Google were to say "No more checking for vulnerabilities in
| FDroid... (or insert other)" I would agree with your take -
| that seems like common sense. Not their store, not their
| problem. Same for side-loaded apps.
|
| But that's not what's happening. They're busy selling those
| malicious/vulnerable apps for a cut of the profit.
|
| Now - Google can be a responsible party here without having
| this program (there are plenty of valid discussions around
| whether this was really an effective way to combat malware on
| their store) - but to recap...
|
| The store doesn't get to absolve themselves of responsibility
| for the things it's selling.
|
| "It's the store's responsibility not to sell me
| malicious/defective products". If they can't do that... maybe
| they shouldn't be allowed to operate that store anymore.
| goldfishgold wrote:
| What a ridiculous idea. You think your mother should or is
| capable of auditing the Facebook app before installing it?
| Woshiwuja wrote:
| Good idea!
___________________________________________________________________
(page generated 2024-08-22 17:02 UTC)