Google Play will no longer pay to discover vulnerabilities in Android apps
androidauthority.com
androidauthority.com
Profit centres, lacking any understanding of costs, are scared to increase them and fixed on reducing them, even when short-term profit destroys long term market share. Mostly because profit centres reward on a short cycle and have high turnover as staff seek bigger profits.
----
[1] this takes time: after _years_ of saying I'm going to I've finally started experimenting with using Kagi for search instead. It also takes _good_ alternatives, a paid option won't be seen as good by many.
At least Google's M.O. has mostly been to make stuff and then just throw it out into the open (with no support). Apple has been the opposite, ingesting the ideas and features of whole other companies without buying them, because they control their own little ecosystem.
Yes, developers can use basic/locked down UWB functionality in their apps, but no they cannot run it in the background constantly like Apple does for their airtags, essentially making it useless.
I re-read How Google Works, Engineering at Google, etc. Kind of ironically, YT delivered these fantastic talks from 2011:
Google I/O 2011: HTML5 versus Android: Apps or Web for Mobile Development? https://youtu.be/4f2Zky_YyyQ?si=rbKgYi7Rck-6y3qE
Or HTML5, CSS3, and DOM Performance, Breaking News at 1000ms with Patrick Hamann
This was and still is fantastic stuff.
The next step would be to drop the unofficial requirement that every manager be able to code. MBAs at Google: regression to the mean.
Old Google was inspirational; new Google seems to evolve into yet another drawing board MBA construct.
Sure you could use a react based app with some of the compilers but it’s like opening another bag of worms.
We have much better features for building offline apps than we did before html5 anyway (local and session storage and web workers)
Offline apps aren’t as common because they don’t make money and if someone is using a web browser 9 out of 10 times, they have an internet connection.
Does Apple have a comparable program?
I don't see a reference in the Apple materials about any bounty reward program for Apps vulnerabilities [1]. If this is true, then Google was going above and beyond and is now simply reverting to the mean so they can reduce any potentially excess financial spend. Maybe they don't actually care so much about their users after all? If they were shifting the limited funds to a more effective vehicle, they missed the prime opportunity to mention it (tongue in cheek, because Elgoog doesn't have real resource constraints).
https://bughunters.google.com/about/rules/android-friends/61... https://bughunters.google.com/report/targets/290590452
This was a program finding vulns in non-Google apps on Play. A cool idea, but I suspect challenging to operate without teeth making the developers actually update their apps.
Less trust; less money on the line on which to base that trust equates, for me, to a reduced premium for a listing.
A real opportunity exists for trusted and vetted apps.
I guess Google will just sell anything now
If Google were to say "No more checking for vulnerabilities in FDroid... (or insert other)" I would agree with your take - that seems like common sense. Not their store, not their problem. Same for side-loaded apps.
But that's not what's happening. They're busy selling those malicious/vulnerable apps for a cut of the profit.
Now - Google can be a responsible party here without having this program (there are plenty of valid discussions around whether this was really an effective way to combat malware on their store) - but to recap...
The store doesn't get to absolve themselves of responsibility for the things it's selling.
"It's the store's responsibility not to sell me malicious/defective products". If they can't do that... maybe they shouldn't be allowed to operate that store anymore.
If you went back farther, you would find exploits that compromise your iOS device simply by receiving a compromised jpg image, not even by you opening the message. https://arstechnica.com/gadgets/2023/09/apple-patches-clickl...
I think the expectation in 2024 should simply be 0 day exploits are available for purchase that target both platforms, neither is secure.
iOS is a very buggy operating system; they polish the hell out of the top of it, but its internals are hairy and scary. That first paragraph doesn't represent a security bug, but its adjacent to many other, more serious problems iOS has had. Its about once every-other year we get some wild bug where a complete stranger can text you a specially crafted string of unicode characters and it crashes the entire OS.
It isn't fair or accurate to say that Android is less secure than iOS in 2024. They both have problems, and both will continue to have problems, but both are significantly more secure than they were 10 years ago, and its very rare for applications downloaded from their respective official app stores to do significant damage to the user. The correct lens through which to view this policy change is: It was a program which exclusively worked with "major applications", and this kind of program is a responsibility which these major applications should take on, not Google.
Essentially anything for x will crash it: “”:x
[1] https://bgr.com/tech/the-most-sophisticated-iphone-attack-ev...