Google is changing its policy for publishing vulnerability patches in Android

The GrapheneOS project, which develops an alternative open source firmware Android, a company focused on enhancing security and privacy, announced that Google has made changes to its policy for publishing vulnerability patches for the platform. Android and vulnerability disclosures. October vulnerability report Android published empty.

Google now provides security patches natively for Android Exclusively to OEMs through closed channels with a non-disclosure agreement obliging them not to disclose the source code using the provided patches for a period of three months from receipt. During this time, only binary builds with the patch included may be distributed.

The code itself remains under the Apache open source license, but distribution rights are temporarily restricted by a non-disclosure agreement. The motivation for this change in company policy is a "drive for increased security," described as an attempt to implement the principle of "Security through Obscurity."

Despite the challenges this poses for open-source third-party firmware, the GrapheneOS project has found a way around this by partnering with an OEM that provides embargoed patches to the project before they are officially released.

It is noted that from now on, GrapheneOS will provide two different release channels: fully reproducible builds at the time of publication based on AOSP, but without closed security fixes, and builds with included patches, the reproducible source code of which will be published only after the embargo expires.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster