Skip to main content

Google made a program to test security patch compliance on Android devices

The post Google made a program to test security patch compliance on Android devices appeared first on BardTech.

Android Security Patch Bulletin

Security, mostly due to heavy software fragmentation, is one of the biggest issues with the Android ecosystem. Google’s own Pixel smartphones are the gold standard of secure Android smartphones, but Google doesn’t only want to secure their own devices. Google has introduced measures like Project Treble , worked to extend Linux kernel LTS from 2 to 6 years, introduced the Android Enterprise Recommended Program, and have even reworked their OEM agreements to start mandating regular security patches. But in an announcement posted today, the company has announced that they’ve been working on a new tool to make sure that smartphone device makers are complying with monthly security patch bulletins.

At Google I/O, Google’s head of Android platform security, David Kleidermacher, announced that Google’s Android partners are required to push regular security updates. In the announcement posted today, Google re-iterated that OEMs should roll out a security patch update at least once every 90 days in case of high severity vulnerabilities, while Android Enterprise Recommended devices must receive them at least once every 90-days. Monthly security updates are recommended and strongly recommended for commercially sold and Enterprise devices, respectively. Android One devices are required to receive monthly security patch updates, however.

But, just rolling out an update and calling it a day doesn’t seem to be enough to keep users secure. This was proven when we heard allegations about manufacturers misrepresenting (perhaps intentionally) the state of the security patches  that were rolled out to their devices. So, the question is, how do we make sure that OEMs patch all vulnerabilities outlined in a monthly security bulletin? The answer is to make it easier for OEMs to do so.

In the past, all Android device makers, after merging the latest framework and vendors patches outlined in each monthly security patch bulletin, had to manually test whether their patches actually fixed the vulnerabilities the patches were intended to fix. This can be a long and not really straightforward process. Now, Google decided to make their work easier as they are releasing a program which will automate the testing process of the security patches. This will most likely be in the form of an automated CTS (Compatibility Test Suite) test that OEMs are required to pass for their updated build to be Google Play Certified. This will push smartphone makers to release security updates that comply with the security bulletin.

We have been developing security update testing systems that are now making compliance failures less likely to occur. In particular, we recently delivered a new testing infrastructure that enables manufacturers to develop and deploy automated tests across lower levels of the firmware stack that were previously relegated to manual testing. In addition, the Android build approval process now includes scanning of device images for specific patterns, reducing the risk of omission.

Google’s Existing Security Measures in Android

This is the latest effort from Google to fix the security patch issues in the Android ecosystem. Previously, the company announced that with the partnership with the Linux Foundation, Linux kernel’s Long-Term-Support (LTS) will be increased from 2 years to 6 years. The reasoning behind this decision was that most of the devices being released came with already outdated and discontinued versions of the Linux kernels because it was so hard to build, design, and ship the device within the 2-year window that Linux’s LTS kernels offered. OEMs also don’t have to backport security patches from the newer versions of the Linux kernel thanks to longer LTS.

In addition, Project Treble also made releasing security patches (and software updates in general) easier for OEMs. As you may already know, Project Treble modularizes the Android operating system framework so that implementing the newest security patch in the vendor and kernel can be done independently of patching the framework.

So, what are the goals of Project Treble, extended Linux kernel LTS, and automated security patch testing? One might think that it’s more security updates, but it’s actually the opposite. Google wants to improve the security of the Android to a level that security updates will be a rare necessity. But, the company also wants the manufacturers to be able to push the updates as soon as possible, should the occasion arise. Sure, as a short-term solution, it’s nice if manufacturers don’t miss a month without releasing the security update. But, in the long-term, it’d be nicer if there was not as much necessity of them as it is today.


Source: Android Developers Blog

Original Content By XDA Developers

The post Google made a program to test security patch compliance on Android devices appeared first on BardTech.



Tags: Android Security, android security update, Google, Mini XDA, Monthly Security Updates, News, project treble, android, compliance, devices, google, patch, program, security

Original link: here
via BardTech

Comments

Popular posts from this blog

How to change the PIM of a VeraCrypt volume

The developers of VeraCrypt introduced Personal Iterations Multiplier (PIM) functionality in the encryption program in version 1.12 . PIM stands for "Personal Iterations Multiplier". It is a parameter that was introduced in VeraCrypt 1.12 and whose value controls the number of iterations used by the header key derivation function. PIM is used by volumes even if the creator of the volume did not specify a value. It is an optional component that improves security: it adds another step to the authentication process similarly to two-factor authentication. The main difference is that the PIM value is fixed and not generated on the fly when requested. An attacker needs to know the master password and the PIM, if not set to default, to breach the encryption successfully and access the content of the drive or partition. A couple of good reasons exist to change the PIM value: It was leaked or stolen. The default value is used and that is not as secure as using a custom PIM. Yo...

Huawei Mate 20 Pro launched in India with Kirin 980 for ₹69,990 ($988)

For years, the highest-end Android flagship used to be defined by Samsung’s Galaxy Note series as the “best-of-the-best” Android phones. Google entered the premium smartphone segment in 2016 with the Google Pixel . In addition, one company that has been steadily improving its flagship phones is Huawei. Huawei has also been steadily increasing the prices of its flagship phones at the same rate. Indian consumers, however, were left out as Huawei had not opted to launch any Mate series phone in India before. This year, as the company’s strategy has changed, high-end flagship smartphone buyers now have another option to choose from. The Huawei P20 Pro was launched in India in April . Now, Huawei has launched the Huawei Mate 20 Pro in India—the first ever launch of a Mate series phone in the country. The Huawei Mate 20 Pro is the successor of the Huawei Mate 10 Pro . It’s positioned as a higher-end variant of the standard Huawei Mate 20. It should be noted that Huawei didn’t launch the s...

The 5 Best Free IPTV Apps to Watch Live TV on Android

It’s easier than ever to watch on-demand TV shows and movies on your Android device. But what about live TV? Yes, there are services like Sling and PlayStation Vue. However, if you know where to look, you don’t need to subscribe to their expensive plans. You can use free IPTV instead; you just need an IPTV app and an IPTV source. What Is an IPTV App? IPTV apps are a bit like Kodi; they are empty shells that can’t stream any content without some user input. You have the responsibility for adding channels, playlists, and other sources. Typically, you cannot use the apps to watch Netflix, Hulu, or direct content from other third-party providers. Here, we’re not interested in the best on-demand streaming apps or places to watch TV online. We are only looking at the IPTV apps themselves. Specifically, we want to know what the best IPTV apps on Android are. 1. Lazy IPTV Our first pick is Lazy IPTV. It supports M3U playlists in open-view, ZIP, and GZ formats. The app can also read pl...