Google extends open source bug bounty programme to Android and Apache

Android robot

Google has extended the scope of its recently launched open source bug bounty programme to include the Android mobile operating system.

The internet giant announced the launch of its Vulnerability Rewards Programme last month, which offers rewards of between $500 and $3,133.7 for anyone who roots out security holes in one of a dozen open source projects.

As reported by IT Pro at the time, the company said the scheme would eventually cover a wider range of open source projects, and the company made good on its promise in a blog post this week.

"The goal is very simple: to recognise and reward proactive security investments to third-party open source projects that are vital to the health of the entire internet," said Michal Zalewski from the Google Security Team.

"We started with a fairly conservative scope, but said we would expand the programme soon."

As such, it now covers the open source components of Android, Zalewski revealed, as well as web servers Apache httpd, lighttpd and nginx, and mail delivery services including Sendmail, Postfix, Exim and Dovecot.

A full list of all the new inclusions can be found here.

Google's decision to widen the range of projects covered by its reward programme comes at a time when several other tech giants have made moves to improve their response to vulnerability reports.

Internet giant Yahoo came under fire last month for rewarding security researchers for finding flaws in its products with money-off vouchers for its online corporate store. Several days later, the firm ushered in a reworked programme offering researchers up to $15,000 for uncovering issues.

Meanwhile, Facebook found itself on the receiving end of a barrage of abuse in August after declining to reward a researcher who uncovered a bug that could have allowed site users to post messages on the timeline of people they weren't even friends with.

Caroline Donnelly is the news and analysis editor of IT Pro and its sister site Cloud Pro, and covers general news, as well as the storage, security, public sector, cloud and Microsoft beats. Caroline has been a member of the IT Pro/Cloud Pro team since March 2012, and has previously worked as a reporter at several B2B publications, including UK channel magazine CRN, and as features writer for local weekly newspaper, The Slough and Windsor Observer. She studied Medical Biochemistry at the University of Leicester and completed a Postgraduate Diploma in Magazine Journalism at PMA Training in 2006.