News: 1699120567

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Android VPNs to get audit badges in Google Play Store if they aren't comically crap

(2023/11/04)


Google wants to help Android users find more trustworthy VPN apps through better badging alerting to independent audits.

The ad impresario and cloud concession has afforded independently audited applications in its Play store a more prominent display of their security bonafides, specifically a banner atop their Google Play page.

VPN apps are the first to receive this special treatment, explained Nataliya Stanetsky, from Google's Android Security and Privacy Team, in an [1]announcement , because they handle significant amounts of sensitive data. And they're thus a popular [2]target for subversion by miscreants.

[3]

"When a user searches for VPN apps, they will now see a banner at the top of Google Play that educates them about the 'Independent security review' badge in the Data Safety Section," said Stanetsky.

[4]Google bins integrity API that looked more than a bit like horrible DRM for websites

[5]Meta's ad-free scheme dares you to buy your privacy back, one euro at a time

[6]Help, Android 14 ate my Pixel! Bug causes endless reboots, loss of storage access

[7]Alphabet CEO testifies in Google Search trial: We pay billions to keep Apple at bay

Last year, Google's partnership with the App Defense Alliance (ADA), launched in 2019, was expanded to include the [8]Mobile App Security Assessment (MASA), a way to check Android apps to ensure they comply with [9]a security standard defined by OWASP.

It's not a particularly thorough audit. As the ADA's website states, "MASA is intended to provide more transparency into the app's security architecture, however the limited nature of testing does not guarantee complete safety of the application."

[10]

[11]

The ADA also advises that MASA does not necessarily check app developers' safety declarations. Obviously the alliance doesn't want to be blamed if it misses something and an info-stealing app slips by, but the group's MASA endorsement counts for something.

MASA looks for [12]obvious bad practices , like whether sensitive data gets written to application log files and whether the app reuses cryptographic keys for multiple purposes, among its many checks. It's safe to say you're better off with apps that avoid such missteps, even if it's not safe to say they're guaranteed to be secure.

[13]

At least if MASA misses, the Android ecosystem has other security measures in place. As Google proudly [14]proclaims , it tries to protect against PHAs and MUwS – potentially harmful applications and mobile unwanted software, in case your gibberish translator is down. It does so through static and dynamic risk analysis, by gathering data about malicious apps, with machine learning, and other mechanisms.

Previously, those Android developers who submitted their apps for MASA interrogation, successful certification received a small badge buried in the app's "Data safety" section.

Throwing modesty aside, Google Play will now proclaim MASA merit for VPN apps in a way that's more easily visible, using a banner near the top of the store listing that links to the [15]App Validation Directory . That's a central repository where all validated VPN apps – eight at the moment – can be seen as separate from more dubious peers of uncertain provenance.

[16]

" [17]Research shows that transparent security labeling plays a crucial role in consumer risk perception, building trust, and influencing product purchasing decisions," said Stanetsky. "We believe the same principles apply for labeling and badging in the Google Play store." ®

Get our [18]Tech Resources



[1] https://security.googleblog.com/2023/11/more-ways-for-users-to-identify.html

[2] https://www.theregister.com/2023/08/10/tunnelcrack_vpn/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZUbNGsMVaIKB7IlKWqqr@AAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2023/11/02/google_abandons_web_environment_integrity/

[5] https://www.theregister.com/2023/10/31/meta_ad_free_europe/

[6] https://www.theregister.com/2023/10/30/google_android_14_pixel_bug/

[7] https://www.theregister.com/2023/10/30/alphabet_sundai_pichai_google_antitrust/

[8] https://appdefensealliance.dev/masa

[9] https://owasp.org/www-project-mobile-app-security/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUbNGsMVaIKB7IlKWqqr@AAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUbNGsMVaIKB7IlKWqqr@AAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://github.com/appdefensealliance/ASA/blob/main/MobileAppSecurityAssessment/MobileSecurityGuide.md

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUbNGsMVaIKB7IlKWqqr@AAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://developers.google.com/android/play-protect/cloud-based-protections

[15] https://appdefensealliance.dev/directory?category=vpn

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUbNGsMVaIKB7IlKWqqr@AAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://iotsecurityprivacy.org/research

[18] https://whitepapers.theregister.com/



Warning!

Flip

Why not take the additional step to mark VPN apps that don't meet MASA criteria with a big red warning banner that warns users that the app is potentially unsafe?

Re: Warning!

IGotOut

Or, crazy I know, just not let them in the store at all?

Re: Warning!

Anonymous Coward

No, no, that was Apple's idea..

:)

Re: Warning!

BartyFartsLast

Because that sort of testing costs money.

A Google security rating -- REALLY?

herberts ghost

I note that as of this writing, they don't seem to certify NORTON or DuckDuckGo VPNs.

It may also certify that it does not interfere with googles tracking.

This may be like the NSA certifying an encryption scheme. (Yes we can break in, but it us too hard for amatures.)

Google "do evil!"?

Hokey Cokey

elsergiovolador

There is no "safe" VPN, unless you run it yourself and then that's subject to a lot of ifs.

I'm not tense, just terribly, terribly alert!