Google strengthens the review of external contributors to AOSP to prevent malicious submission of bug code

Google strengthens the review of external contributors to AOSP to prevent malicious submission of bug code

September 19 news, Android Open Source Project (AOSP) refers to the people, processes and source code that create Android. People are responsible for overseeing the project and developing source code; processes refer to the tools and programs used to manage software development, and the final result is source code that can be used for mobile phones and other devices.

Currently, AOSP uses the Apache 2.0 open source license, which means that anyone can modify its code. However, one disadvantage of this strategy is that it provides an easy way for malicious people to damage it. In response to security issues, Google is strengthening the review of external contributors.

Android expert Mishaal Rahman explained that all external changes to AOSP now require review and approval by two Google reviewers. The goal is to prevent hidden security vulnerabilities and bugs in the code from entering AOSP - not to restrict who can submit code to AOSP.

In fact, Rahman made it clear that non-Googlers are not blacklisted from contributing. Instead, external code is only reviewed to give those directly affected a chance to determine whether it should be integrated into AOSP. This is a more thorough review process that helps screen the final code, identify the most beneficial parts, and reduce security issues.

Foreign media believe that this strategy may significantly reduce some of the vulnerability-related problems Google has faced in the past.

Just last year, David Schütz discovered a vulnerability in AOSP, a flaw that could allow hackers to bypass the Android lock screen. He later received a $70,000 reward from Google for reporting the vulnerability.

It is worth noting that Google has launched a project called Vulnerability Rewards Program in 2010. Since its launch, the project has contributed more than 11,000 vulnerabilities, and Google will reward them with cash. At present, Google has paid millions of dollars to these white hats.

<<:  Xiaomi and Huawei, turning hostility into friendship!

>>:  iOS17 is now available for update! Netizens tested it and found it to be very cool, but the battery life is...

Recommend

Want to start a business? Answer these 6 questions first

[[155511]] I often meet entrepreneurs who have gr...

Why do some advertisements make you want to move after watching them?

Have you seen ads like this: " U2 resin lens...

Can eye protection lamps prevent myopia?

"Doctor, is the eye protection lamp useful? ...

Do you have promotional abilities?

There are many tasks that operations are responsi...

Representatives suggest: Substantially reduce WeChat payment fees

[[384746]] Regardless of the field, handling fees...

SEM bidding promotion account building

Paid bidding promotion has always been an importa...

Start a course - Web Full Stack Architecture 30th Edition Liao Xuefeng

Open a course - Web Full Stack Architecture 30th ...

From 2019 to 2020, these 4 marketing trends will not change

2019 has finally come to an end. This year the ma...

New Media Operations丨Operator Cases, Essential Collection Tools

A good idea or activity. It does not necessarily ...

How do iPhone 13 users choose 4G or 5G packages? Learn in one article

[[426010]] In the past few days, users who have p...