Google: how do we improve Android security?

Google has stated that it is working to improve the security of Android and the measures it is taking to address common threats.

The company revealed that 59% of the critical vulnerabilities that affect the Android operating system are memory issues, such as memory corruption and overflows.

Τα ζητήματα ασφάλειας της μνήμης ήταν μακράν η κορυφαία κατηγορία ζητημάτων , ακολουθούμενη από ελαττώματα παράκαμψης δικαιωμάτων, τα οποία αντιστοιχούσαν στο 21% αυτών που επιδιορθώθηκαν από τους τεχνικούς ασφαλείας της Google το 2019.

Memory issues are generally the top category of security vulnerabilities on large platforms such as Java, Windows 10 and Chrome. Google technicians last year said that 70% of Chrome security vulnerabilities were memory issues. Earlier, Microsoft technicians reported that 70% of all bugs fixed in its products were memory problems or software issues that allowed access to operating system memory.

Google today says it encourages developers to use memory-safe programming languages ​​such as Java, Kotlin and Rust, but also seeks to improve the security of C and C ++. All of this is part of the company's efforts to harden Android and protect the operating system from malware and exploits.

"C and C ++ do not provide memory security like Java, Kotlin and Rust do. since majority of the security vulnerabilities mentioned in Android are memory security issues, a dual approach is applied: improving the security of C / C ++ while at the same time encouraging the use of languages ​​that are safe in memory " a post on her blog by the Android Security and Privacy Team.

Amazon Web Services (AWS) and Microsoft are also pushing for Rust to be adopted for the same security reasons. Mozilla created Rust to address security issues related to C ++ memory in Firefox's Gecko engine. Rust version 1.0 was released in 2015, but the language adoption is still relatively low.

For Android, the majority of bugs that Google fixed in 2020 were on media, Bluetooth, and NFC. The media library was the key element affected by critical and remote Stagefright bugs in Android that Google revealed in 2015.

According to Google, its efforts to harden the media server framework on Android resulted in 2020 not receiving any reports of critical vulnerability exploits in Android media frameworks.

iGuRu.gr The Best Technology Site in Greecefgns

Subscribe to Blog by Email

Subscribe to this blog and receive notifications of new posts by email.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).