Google and Android have your back by protecting your backups

Posted by Troy Kensinger, Technical Program Manager, Android Security and Privacy Android is all about choice. As such, Android strives to provide users many options to protect their data. By combining Android’s Backup Service and Google Cloud’s Titan Technology, Android has taken additional steps to securing users’ data while maintaining their privacy. Starting in Android … Devamını oku

Control Flow Integrity in the Android kernel

Posted by Sami Tolvanen, Staff Software Engineer, Android Security & Privacy [Cross-posted from the Android Developers Blog] Android’s security model is enforced by the Linux kernel, which makes it a tempting target for attackers. We have put a lot of effort into hardening the kernel in previous Android releases and in Android 9, we continued … Devamını oku

Trustworthy Chrome Extensions, by Default

Posted by James Wagner, Chrome Extensions Product Manager [Cross-posted from the Chromium blog] Incredibly, it’s been nearly a decade since we launched the Chrome extensions system. Thanks to the hard work and innovation of our developer community, there are now more than 180,000 extensions in the Chrome Web Store, and nearly half of Chrome desktop … Devamını oku

Android and Google Play Security Rewards Programs surpass $3M in payouts

Posted by Jason Woloz and Mayank Jain, Android Security & Privacy Team [Cross-posted from the Android Developers Blog] Our Android and Play security reward programs help us work with top researchers from around the world to improve Android ecosystem security every day. Thank you to all the amazing researchers who submitted vulnerability reports. Android Security … Devamını oku

Introducing the Tink cryptographic software library

Posted by Thai Duong, Information Security Engineer, on behalf of Tink team At Google, many product teams use cryptographic techniques to protect user data. In cryptography, subtle mistakes can have serious consequences, and understanding how to implement cryptography correctly requires digesting decades’ worth of academic literature. Needless to say, many developers don’t have time for … Devamını oku

Evolution of Android Security Updates

Posted by Dave Kleidermacher, VP, Head of Security – Android, Chrome OS, Play [Cross-posted from the Android Developers Blog] At Google I/O 2018, in our What’s New in Android Security session, we shared a brief update on the Android security updates program. With the official release of Android 9 Pie, we wanted to share a … Devamını oku

A reminder about government-backed phishing

Posted by Shane Huntley, Threat Analysis Group TLDR: Government-backed phishing has been in the news lately. If you receive a warning in Gmail, be sure to take prompt action. Get two-factor authentication on your account. And consider enrolling in the Advanced Protection Program. One of the main threats to all email users (whatever service you … Devamını oku

Expanding our Vulnerability Reward Program to combat platform abuse

Posted by Eric Brown and Marc Henson, Trust & Safety Since 2010, Google’s Vulnerability Reward Programs have awarded more than $12 million dollars to researchers and created a thriving Google-focused security community. For the past two years, some of these rewards were for bug reports that were not strictly security vulnerabilities, but techniques that allow … Devamını oku

Google Public DNS turns 8.8.8.8 years old

Posted by Alexander Dupuy, Software Engineer Once upon a time, we launched Google Public DNS, which you might know by its iconic IP address, 8.8.8.8. (Sunday, August 12th, 2018, at 00:30 UTC marks eight years, eight months, eight days and eight hours since the announcement.) Though not as well-known as Google Search or Gmail, the … Devamını oku

Mitigating Spectre with Site Isolation in Chrome

Posted by Charlie Reis, Site Isolator Speculative execution side-channel attacks like Spectre are a newly discovered security risk for web browsers. A website could use such attacks to steal data or login information from other websites that are open in the browser. To better mitigate these attacks, we’re excited to announce that Chrome 67 has … Devamını oku