• On GameSpot: So-called 'Halo killer' gets 23 to life
August 19, 2008 10:57 AM PDT

Android security team appeals to bug hunters

by Tom Espiner
  • Font size
  • Print
  • 2 comments

The security team behind Google's mobile platform, Android, has tried to raise its profile among security researchers by appealing for their vigilance in monitoring the platform.

In an e-mail to the popular Full Disclosure mailing list, the Android security team said that because flaws in the system are inevitable, Google would require help from the security research community both in finding and disclosing those vulnerabilities.

"As you may expect, building and maintaining a secure mobile platform is a difficult task," wrote an Android security team member. "While we have found and fixed many of our own bugs as well as flaws in other open-source projects, we realize that the discovery of additional security issues in a system this large and complex is inevitable."

The team requested that security researchers disclose Android vulnerabilities to Google, rather than making them generally available.

"We do appreciate and encourage responsible disclosure, especially since Android will be deployed on many different devices that will require a large amount of coordination to patch," wrote the security team member. "Help from security researchers in the form of usable bug reports and responsible timelines will greatly assist us in securing the ecosystem of Android devices as quickly as possible."

Google had not responded to a request for comment at the time of writing.

Multiple vulnerabilities in the Android platform were reported in March. Although Android is not yet deployed on any devices, exploits for the vulnerabilities were tested on an Android emulator included in its software development kit.

A long-awaited beta version of the SDK was made available to developers Monday.

Tom Espiner of ZDNet UK reported from London.

advertisement
Click here!
Recent posts from Security
Apple updates Safari for security
Microsoft probing Windows 7 zero-day hole
Eastern Europeans charged in payment processor hack
A child porn-planting virus: Threat or bad defense?
Microsoft patches critical hole in Windows kernel
Panda's Cloud Antivirus leaves beta behind
Apple plugs holes for domain spoofing, other attacks
Microsoft launches Forefront Protection 2010
Add a Comment (Log in or register)
by totalmonkey August 19, 2008 11:57 AM PDT
Does this headline sound like it came from a scifi movie or video game to anyone else?
Reply to this comment
by wurtis65 October 26, 2008 11:59 AM PDT
My company, Mocana, just announced a security SDK for Google's Android platform that readers of this article might be interested in investigating. With it Android developers can build robust encryption, authentication, VPN, antivirus and antimalware feature into Android Handsets. It's called NanoPhone, and you can learn more at http://mocana.com/NanoPhone-Android.html
-Kurt
Reply to this comment
advertisement

As alternative energy grows, NIMBY greens

With more renewable energy projects trying to come online, the country grapples with the balance between local land use and a national push for clean energy.

Google to remake programming with Go

A Unix co-creator is among those behind a language Google hopes will speed computers and programming. Today, Go becomes open-source software.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right