Sunday, 18 June 2017

Google Will Pay You $200,000 For Finding a Bug in Android OS




 Google to pay $200,000 for finding bug in android so if you are a hacker or a security researcher, that is probably going to be a good news for you. Google Will now Pay you Up to $200,000 if you Find any Bug in it’s Android OS. A few days ago, a malware called "Judy" hit over 36.5 million Android-based phones and caused a lot of damage. So, Google has decided to increase the bounty for finding a bug in Android OS to as much as $2,00,000.

According to cyber security firm Check Point, dozens of malicious apps were downloaded between 4.5 million to 18.5 million times from the Play Store. It was noted that the malicious code was present hidden in some apps since April 2016, undetected by Google. Google has now removed the infected apps from the PlayStore. “Judy” is one such case of how an open and free mobile operating system (OS) can be exploited by malicious app developers.

According to cyber security firm Check Point, dozens of malicious apps were downloaded between 4.5 million to 18.5 million times from the Play Store. Some of the malware-affected apps have been discovered residing on the online store for several years. “Judy” is one such case of how an open and free mobile operating system (OS) can be exploited by malicious app developers.

Most security flaws we hear about now affect old builds of the OS or require clever social engineering to get the user to weaken device security, technology website extremetech.com reported on Friday. The versions of Android being released now are more secure than what Google was putting out years ago and as a result no one has managed to claim Google’s largest bug bounties for Android.

Hoping to attract more researchers and engineers to the bug bounty programme, the company has increased the rewards to up to $2,00,000.Google started the bug bounty programme for Android about two years ago in which the security researchers, who demonstrate an exploit, get a cash prize — the amount of which varies based on the severity of the hack.

Tech companies such as Apple, Facebook, Microsoft, and Google have paid out millions of dollars in bug bounty programs over the past few years. Google started the bug bounty program for Android about two years ago in which the security researchers, who demonstrate an exploit, get a cash prize — the amount of which varies based on the severity of the hack. Since then the reward value has been increased from $50,000 to up to $200,000.

 The increased reward applies to two bounties: one for vulnerabilities in TrustZone or Verified Boots, and the other for a remote Linux kernel exploit. Among them, TrustZone or Verified Boot is a matter of serious concern than the Linux exploit, as reported by Extreme Tech. TruztZone is chipset related technology, which ensures biometric data, DRM and boot settings are kept in a trusted secure environment. On the other Verified Boot is software related, to ensure the OS has not tampered with each time a device starts up. Google has increased the bounty for both TrustZone and Verified Boot from $50,000 to $200,000.

It is speculated that Google will further increase the reward price if it again fails to get to a working exploit for Android’s core components.

 

 

0 comments:

Post a Comment