Google Play attempts to make Android apps safer through rewards program

Google will pay $1,000 to those who find vulnerability in Android apps

Google Play has teamed up with HackerOne, an independent bug bounty platform, to create the Google Play Security Rewards System, with $1,000 up for grabs for flaws found in popular Android apps.

The program hopes to improve security research as well as app security which will benefit Android users, developers, and Google Play as a whole.

Apps such as Duolingo, Snapchat, Tinder, Dropbox, and Headspace are currently in the Google Play Security Reward program, with the hopes of more apps joining later on.

The system works by encouraging hackers to identify problems and vulnerabilities within different apps. However, the bugs have to follow certain criteria to qualify for the reward.

As of right now, the program is limited to remote-code-execution vulnerabilities and corresponding proof of concepts which run on devices with Android 4.4 or higher. This would include vulnerabilities that allow the downloading and execution of malicious code, the manipulation of a user interface to commit a transaction, and the opening of a webview leading to phishing attacks.

After a bug has been identified, the hacker works directly with the developer to fix the problem by reporting the issue to the firm through provided links. Once it is fixed, the hacker reports it to the Google Play Security Reward System, which will then consider it for the $1,000 reward, provided it followed the criteria.

"As the Android ecosystem evolves, we continue to invest in leading-edge ideas to strengthen security," said Vineet Buch, the director of product management at Google Play.

"Our goal is continue to make Android a safe computing platform by encouraging our app developers and hackers to work together to resolve unknown vulnerabilities, we are one step closer to that goal."

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

How to unroot Android
Google Android

How to unroot Android

9 Sep 2020
Gmail vs Outlook.com: Which one is better?
email providers

Gmail vs Outlook.com: Which one is better?

22 Jan 2021
Nokia and Google to co-develop cloud-native 5G solutions
Network & Internet

Nokia and Google to co-develop cloud-native 5G solutions

15 Jan 2021
Google Meet will help troubleshoot a low-quality video conference
video conferencing

Google Meet will help troubleshoot a low-quality video conference

13 Jan 2021

Most Popular

School laptops sent by government arrive loaded with malware
malware

School laptops sent by government arrive loaded with malware

21 Jan 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
What is the Raspberry Pi Pico?
Hardware

What is the Raspberry Pi Pico?

21 Jan 2021