6 ms·
Seems reasonable. App authors would’ve been “discovering” vulnerabilities in their own apps and asking Google to pay for them.
by will5421 2y ago
Seems reasonable. App authors would’ve been “discovering” vulnerabilities in their own apps and asking Google to pay for them.
- ainiriand 2y agoUnfortunately it does not work that way. They are meant to be vulnerabilities exploiting Android through the app, not backdoors in the app. It is meant to secure the Android OS, not to secure the app.
- a_dabbler 2y agoThere's a separate program for bugs in the Android OS, this program did pay for finding bugs in the app to secure the app. Also the mitigation for people abusing the program is that they only pay for bugs in popular apps, it's unlikely for a major app dev to be backdooring their code just to try and scam this bounty program
- ainiriand 2y agoAh thanks for clarification. It got it wrong it seems!
- paxys 2y agoBug bounty programs for Android still exist. This one was specifically about finding vulnerabilities in apps themselves.
- UncleMeat 2y agoThe program was operated through HackerOne (at least the last time I looked at this thing back in like 2018), which does the basic due diligence to address things like this.
- joemazerino 2y agoThere's an app download requirement to prevent this.