Google has launched Google Play Security Reward Program just a few days back in coordination with bug bounty platform HackerOne. However, Google itself runs its own bug bounties for Android, Chrome, and websites and now expanding this concept to popular Android Apps. For this, researchers will be paid $1,000 reward for qualifying vulnerabilities.
As per HackerOne, hackers will identify the app vulnerabilities and report it to the developers as soon as they find them. After this, the hacker will request for a reward from the program. Once it is evaluated to check whether it meets the Google’s criteria or not, he will be awarded $1000 for this.
Note: Google brings the bug bounty vulnerability research model to Android apps in the Play Store.
Google Play Security Reward Program includes following apps till now:
– Dropbox, Alibaba, Duolingo, Line, Mail.Ru, Headspace, Tinder, Snapchat
To know its working, one should be aware of “qualifying bugs” for which researchers are awarded. These bugs are limited to RCE(remote code execution) flaws that work on Android devices with version 4.4 or above. This includes attacks which allow malicious code to be downloaded and executed, opening a webview in an app for phishing and manipulating the user interface to cause a fraudulent transaction. Here is its working:
– Researchers find bugs and report it directly to the app’s developer via their current vulnerability disclosure process.
– The bounty page consists of links to the page where they report issues to the participating firms.
– App developer fixes the bug while working with them.
– Once the bug gets resolved, the researchers request a reward from the Google Play Security Reward Program.
– Android Security team issues an additional reward to thank them for improving security within the Google Play ecosystem.
Many companies in the bounty program are already offering bug bounties separately via HackerOne or through their own programs. Some of these companies are listed below:
– Tinder has bug bounty which is a private program.
– Dropbox is running its bounty since 2014 and currently offers $15,625 for “trivial” RCE’s affecting its Android app, iOS and higher rewards for attacks on its servers.
– Snapchat has already paid out approx. $140,000 via HackerOne bounty program.
– It aims to incentivize research in a bug bounty model.
– It can improve Android app security which will benefit app developers.
– It will also benefit the entire Google Play ecosystem and Android users.
– It will resolve unknown vulnerabilities and make Android a safe computing platform.
Apart from these, there are plenty of other features. For details, please have a look at this following video.
As far we have seen, Google Play Security Reward Program offers a lot of benefits/rewards to increase android security. You might not be confused now for not opting this program even after watching the above video.
In fact, you can easily install the app from the Google play store. However, if you still have any query regarding this Android security reward program, then you are free to get expert advice from our Android development team at ValueCoders. ValueCoders, an Indian IT outsourcing company, provides expert software development teams for Android application development, for all your android app development needs. Contact Us Today!!
We Brew Our Blogs Especially For Startups, Agencies & CTOs. Subscribe & Get Latest Updates Straight To Your Inbox
Save Upto 50% Of Development Cost and Get 2x Faster DeliveryCONTACT US
While Pokémon GO is ruling the app stores , Prisma is also catching everybody's eyes. This photo app originated from Germany has gone viral in only five weeks […] - Read More
Google has released the first beta SDK of Flutter, a mobile UI framework, which helps developers in creating interfaces for the apps on Android as well as the iOS […] - Read More
Every-time Android appears in a new appeal with its brand new updates. From Donut(1.6) to Nougat(7.0) (newly released), it has been a glorious journey. In recent times, […] - Read More
Next.js has reached version 8. Next.js is a React framework for static and server applications. The latest version includes features such as Server.js without the […] - Read More
From our last blog, you already know that Angular 4 was going to release in March 2017. On 23rd, Google's Angular team finally announced the release of version 4 […] - Read More
On May 3, 2018, the Angular team announced the new version of Angular called as Angular 6. This released is focused on improving Angular toolchain. Angular is one of […] - Read More