Google Launches App Security Team
Google is creating a dedicated security team to hunt for bugs in "sensitive" Android apps. It will concentrate on the nature of the app rather than how widely its used.
The new team will working in a different way to Google's existing program that offer bounties to independent security researchers who spot bugs in apps from the Google Play Store. To get the most "bang for its buck," that program only covers apps which have more than 100 million downloads.
While it's logical enough to prioritize those apps as the number of people affected by a security breach will be highest, it doesn't take account of how sensitive the data handled by an app is, not how important the app's task.
Elections And COVID Apps Affected
Rather than change the rules for independent researchers, Google is advertising for somebody to head a dedicated in-house team. Among its tasks is to: "perform application security assessments against highly sensitive, third party Android apps on Google Play, working to identify vulnerabilities and provide remediation guidance to impacted application developers."
According to Google, some of the subjects of apps which will come under the new team include elections and COVID-19 contact tracing. (Source: zdnet.com)
In both cases, the consequences of a security breach would be serious, not only for the individuals concerned but because of a potential loss of functionality in the app. Both topics are mainly organized at a national or state level and so any one app is unlikely to reach the 100 million user mark.
Hardware Issues Also Traced
Google is also tackling security problems on Android devices themselves. It's launched a program called the Android Partner Vulnerability Initiative. Under the program, Google will look for problems with specific devices manufactured by third parties.
Until now Google has mainly only gone public with problems that affect Android itself. Now it's going to disclose bugs that affect particular manufacturers. As well as keeping users in the loop, the program could also put pressure on manufacturers to fix problems more quickly. (Source: bleepingcomputer.com)
What's Your Opinion?
Is it a good move for Google to launch this dedicated team for sensitive apps? Should it lower the threshold on the bounty program for independent researchers? If you use an Android device, do you feel confident about its protection against new threats?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.