Google Play attempts to make Android apps safer through rewards program

Google will pay $1,000 to those who find vulnerability in Android apps

Google Play has teamed up with HackerOne, an independent bug bounty platform, to create the Google Play Security Rewards System, with $1,000 up for grabs for flaws found in popular Android apps.

The program hopes to improve security research as well as app security which will benefit Android users, developers, and Google Play as a whole.

Apps such as Duolingo, Snapchat, Tinder, Dropbox, and Headspace are currently in the Google Play Security Reward program, with the hopes of more apps joining later on.

The system works by encouraging hackers to identify problems and vulnerabilities within different apps. However, the bugs have to follow certain criteria to qualify for the reward.

As of right now, the program is limited to remote-code-execution vulnerabilities and corresponding proof of concepts which run on devices with Android 4.4 or higher. This would include vulnerabilities that allow the downloading and execution of malicious code, the manipulation of a user interface to commit a transaction, and the opening of a webview leading to phishing attacks.

After a bug has been identified, the hacker works directly with the developer to fix the problem by reporting the issue to the firm through provided links. Once it is fixed, the hacker reports it to the Google Play Security Reward System, which will then consider it for the $1,000 reward, provided it followed the criteria.

"As the Android ecosystem evolves, we continue to invest in leading-edge ideas to strengthen security," said Vineet Buch, the director of product management at Google Play.

"Our goal is continue to make Android a safe computing platform by encouraging our app developers and hackers to work together to resolve unknown vulnerabilities, we are one step closer to that goal."

Featured Resources

Defeating ransomware with unified security from WatchGuard

How SMBs can defend against the onslaught of ransomware attacks

Free download

The IT expert’s guide to AI and content management

How artificial intelligence and machine learning could be critical to your business

Free download

The path to CX excellence

Four stages to thrive in the experience economy

Free download

Becoming an experience-based business

Your blueprint for a strong digital foundation

Free download

Recommended

Google’s Grace Hopper subsea cable lands in Cornwall
Infrastructure

Google’s Grace Hopper subsea cable lands in Cornwall

15 Sep 2021
South Korea fines Google for abusing Android dominance
Policy & legislation

South Korea fines Google for abusing Android dominance

14 Sep 2021
Google handed user data to Hong Kong authorities despite pledge
privacy

Google handed user data to Hong Kong authorities despite pledge

13 Sep 2021
Google and Microsoft's hybrid work battle shows the narrative is just as important as the technology
collaboration

Google and Microsoft's hybrid work battle shows the narrative is just as important as the technology

9 Sep 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
BT conducts 'world's first' trial of quantum-secure communications
Network & Internet

BT conducts 'world's first' trial of quantum-secure communications

13 Sep 2021
Google takes down map showing homes of 111,000 Guntrader customers
data breaches

Google takes down map showing homes of 111,000 Guntrader customers

2 Sep 2021