Google essentially got slapped in the face when Epic Games, the developer of the super popular Fortnite, decided not to make the game available through the Play Store, but via its own app.
Google warned Epic that doing so could potentially put Android users at greater security risk, but the game developer brushed it off, insisting on going it alone for several reasons -- including not having to give Google a cut in-app revenue and "embracing open platforms."
Well, now the worst has happened. Despite having no obligation to do so, Google recently discovered an exploit within the Fortniteinstaller app that allowed malicious apps installed on one's Android phone to hijack the download process so that instead of downloading the game from Epic's server, it could download and install something entirely different, which could potentially leave the device open to attacks.
SEE ALSO: What You Should Know About 'Fortnite' AddictionHere's a quick run-down of what happened:
Google first discovered the vulnerability inside of the Fortniteinstaller app on Aug. 15 and immediately notified Epic. Details for the exploit weren't public yet. Within 48 hours, Epic patched the Fortniteinstaller and deployed it to all Android users who installed the app.
Here's where things get a little ugly. Even though Epic quickly released a patch for the installer app, it asked Google not to disclose the details of the exploit until after 90 days. Not only would there be more time for users to update their installer apps, but hackers also wouldn't be able to take advantage of the bug.
However, Google's bug disclosure guidelines explicitly states the following:
"This bug is subject to a 90-day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report - including any comments and attachments - will become visible to the public."
Despite Epic's request for Google to wait the full 90 days before disclosing the exploit, Google abided by its own guidelines and shared the details.
Per a Google rep posting to an Issue Tracker thread on the bug report:
"...now the patched version of Fortnite Installer has been available for 7 days we will proceed to unrestrict this issue in line with Google's standard disclosure practices".
Naturally, the Fortnitedeveloper wasn't happy about Google's decision at all. Epic provided Mashable the following comment from CEO Tim Sweeney:
"Epic genuinely appreciated Google's effort to perform an in-depth security audit of Fortniteimmediately following our release on Android, and share the results with Epic so we could speedily issue an update to fix the flaw they discovered.
However, it was irresponsible of Google to publicly disclose the technical details of the flaw so quickly, while many installations had not yet been updated and were still vulnerable.
An Epic security engineer, at my urging, requested Google delay public disclosure for the typical 90 days to allow time for the update to be more widely installed. Google refused. You can read it all at https://issuetracker.google.com/issues/112630336
Google's security analysis efforts are appreciated and benefit the Android platform, however a company as powerful as Google should practice more responsible disclosure timing than this, and not endanger users in the course of its counter-PR efforts against Epic's distribution of Fortnite outside of Google Play."
Ultimately, who's in the right and who's in the wrong? Honestly, neither company is.
Google is right that Epic's decision to not release Fortnite through the Play Store leaves the app more vulnerable. As my colleague, Mashable tech reporter Matt Binder, previously made clear: Android users need to disable certain Android security permissions in order to install Fortnite and there's no guarantee they'll remember to turn them back on after doing so.
Maybe Google really is upset at the idea of not getting any revenue from the massively popular game (apps listed on Google Play pay a share of their sales to Google), as Sweeney implied. But the Android gatekeeper maintains that its speedy disclosure of the exploit was done in the name of user security.
Following Sweeney's statement, Google had only this to say in response to Mashable's request for comment: "User security is our top priority, and as part of our proactive monitoring for malware we identified a vulnerability in the Fortniteinstaller. We immediately notified Epic Games and they fixed the issue."
And it's true, Google does have a responsibility to ensure that users are safe. Otherwise, third-party developers could give the entire platform an even worse reputation.
That said, if Google truly cares about protecting its users first and foremost, it should have been more flexible on its bug disclosure deadline so as to nottip off hackers so quickly. That's why Epic asked for 90 days to begin with.
The disagreements between Google and Epic should not be overlooked. Google may wish to have nothing to do with Fortniteafter being shunned by Epic Games, but their paths will inevitably cross because of the Android platform.
It's possible Google will discover vulnerabilities in future versions of the Fortniteinstallerm or even other app installers from other companies that decide to follow in Epic's footsteps and not offer their apps in the Play Store. Will Google have to monitor and perform security audits on all of those as well in order to protect Android users? Hard to say, but it's sure gonna be interesting to watch from the sidelines.
If anyone's laughing at this turn of events, it's Apple. The company's closed platform means all apps mustbe released through the App Store. By not allowing apps to be officially released in any other way, Apple has guarded itself against the issue Google's now facing.
With additional reporting by Adam Rosenberg.
Copyright © 2023 Powered by
Epic Games slams Google for sharing Fortnite Android app exploit info-天兵天将网
sitemap
文章
1
浏览
75
获赞
14671
Reddit's former CEO slams Reddit for 'amplifying hate, racism and violence'
On Monday, Reddit CEO Steve Huffman posted an open letter to employees, saying that the company doesTikTok is all about the 'one thing about me' trend
One thing about me is I am going to write about my favorite TikTok trends of the week.That, of coursElon Musk sends Twitter employees his weirdest email so far
It must be fun working for Elon Musk. The self-proclaimed Chief Twit who recently fired roughly halfSome of Twitter's suspended journalists and still locked out
It's been a week and the journalists who were unceremoniously kicked off of Twitter, then unceremoniCoronavirus is not the man now dog: YTMND is back, and just in time
The pandemic profoundly alters our sense of time. Quarantine grinds lives to a halt, injecting themPsychics, hiking, podcasts, and cooking: What has Christy Carlson Romano been up to since Disney?
Christy Carlson Romano is not ready to write a memoir. But she has plenty of stories to tell —Elon Musk sends Twitter employees his weirdest email so far
It must be fun working for Elon Musk. The self-proclaimed Chief Twit who recently fired roughly halfThe 9 best tweets of the week
It was a...let's say...weird...week to try to laugh at tweets. A leaked draft of a Supreme Court decTrump's border wall gets a GoFundMe campaign that's trying to raise $1 billion
President Trump has so far failed to secure funding for his long-promised wall along the U.S.-MexicoThe U.S. Department of Justice wants Binance to share why it walked away from FTX acquisition
FTX and its founder Sam Bankman-Fried may be having a lot more than money problems in the future.TheTikTok finally rolls out a creator crediting tool
TikTok is introducing a creator crediting tool that allows users to directly tag and credit videos uApple's latest iOS 16.3 update now available for iPhone
The latest iOS update, iOS 16.3, began rolling out to iPhone users on Monday. With this update, ApplAmazon created a waitlist for grocery deliveries because demand is so high
Crushed by the massive increase in demand due to the coronavirus pandemic, Amazon is making some bigProject Management Institute courses to level up your career growth in 2022
You Got This is a series that spotlights the gear you need to improve one area of your life.If you fQR code Super Bowl ad for Coinbase was kind of brilliant
The early winner for the most effective ad during this year's Super Bowl might just go to Coinbase,