Google essentially got slapped in the face when Epic Games012 Archives the developer of the super popular Fortnite, decided not to make the game available through the Play Store, but via its own app.
Google warned Epic that doing so could potentially put Android users at greater security risk, but the game developer brushed it off, insisting on going it alone for several reasons -- including not having to give Google a cut in-app revenue and "embracing open platforms."
Well, now the worst has happened. Despite having no obligation to do so, Google recently discovered an exploit within the Fortniteinstaller app that allowed malicious apps installed on one's Android phone to hijack the download process so that instead of downloading the game from Epic's server, it could download and install something entirely different, which could potentially leave the device open to attacks.
SEE ALSO: What You Should Know About 'Fortnite' AddictionHere's a quick run-down of what happened:
Google first discovered the vulnerability inside of the Fortniteinstaller app on Aug. 15 and immediately notified Epic. Details for the exploit weren't public yet. Within 48 hours, Epic patched the Fortniteinstaller and deployed it to all Android users who installed the app.
Here's where things get a little ugly. Even though Epic quickly released a patch for the installer app, it asked Google not to disclose the details of the exploit until after 90 days. Not only would there be more time for users to update their installer apps, but hackers also wouldn't be able to take advantage of the bug.
However, Google's bug disclosure guidelines explicitly states the following:
"This bug is subject to a 90-day disclosure deadline. After 90 days elapse or a patch has been made broadly available, the bug report - including any comments and attachments - will become visible to the public."
Despite Epic's request for Google to wait the full 90 days before disclosing the exploit, Google abided by its own guidelines and shared the details.
Per a Google rep posting to an Issue Tracker thread on the bug report:
"...now the patched version of Fortnite Installer has been available for 7 days we will proceed to unrestrict this issue in line with Google's standard disclosure practices".
Naturally, the Fortnitedeveloper wasn't happy about Google's decision at all. Epic provided Mashable the following comment from CEO Tim Sweeney:
"Epic genuinely appreciated Google's effort to perform an in-depth security audit of Fortniteimmediately following our release on Android, and share the results with Epic so we could speedily issue an update to fix the flaw they discovered.
However, it was irresponsible of Google to publicly disclose the technical details of the flaw so quickly, while many installations had not yet been updated and were still vulnerable.
An Epic security engineer, at my urging, requested Google delay public disclosure for the typical 90 days to allow time for the update to be more widely installed. Google refused. You can read it all at https://issuetracker.google.com/issues/112630336
Google's security analysis efforts are appreciated and benefit the Android platform, however a company as powerful as Google should practice more responsible disclosure timing than this, and not endanger users in the course of its counter-PR efforts against Epic's distribution of Fortnite outside of Google Play."
Ultimately, who's in the right and who's in the wrong? Honestly, neither company is.
Google is right that Epic's decision to not release Fortnite through the Play Store leaves the app more vulnerable. As my colleague, Mashable tech reporter Matt Binder, previously made clear: Android users need to disable certain Android security permissions in order to install Fortnite and there's no guarantee they'll remember to turn them back on after doing so.
Maybe Google really is upset at the idea of not getting any revenue from the massively popular game (apps listed on Google Play pay a share of their sales to Google), as Sweeney implied. But the Android gatekeeper maintains that its speedy disclosure of the exploit was done in the name of user security.
Following Sweeney's statement, Google had only this to say in response to Mashable's request for comment: "User security is our top priority, and as part of our proactive monitoring for malware we identified a vulnerability in the Fortniteinstaller. We immediately notified Epic Games and they fixed the issue."
And it's true, Google does have a responsibility to ensure that users are safe. Otherwise, third-party developers could give the entire platform an even worse reputation.
That said, if Google truly cares about protecting its users first and foremost, it should have been more flexible on its bug disclosure deadline so as to nottip off hackers so quickly. That's why Epic asked for 90 days to begin with.
The disagreements between Google and Epic should not be overlooked. Google may wish to have nothing to do with Fortniteafter being shunned by Epic Games, but their paths will inevitably cross because of the Android platform.
It's possible Google will discover vulnerabilities in future versions of the Fortniteinstallerm or even other app installers from other companies that decide to follow in Epic's footsteps and not offer their apps in the Play Store. Will Google have to monitor and perform security audits on all of those as well in order to protect Android users? Hard to say, but it's sure gonna be interesting to watch from the sidelines.
If anyone's laughing at this turn of events, it's Apple. The company's closed platform means all apps mustbe released through the App Store. By not allowing apps to be officially released in any other way, Apple has guarded itself against the issue Google's now facing.
With additional reporting by Adam Rosenberg.
Topics Android Cybersecurity Fortnite Gaming Google
Playboy, basically: 'jk nudity is back lol'A university was attacked by its lightbulbs, vending machines and lamp postsJustin Trudeau awkwardly staring at Trump's hand instantly becomes a memePeople are busy frying eggs on cars 'cause it's hot as hell down hereGift your Valentine their true heart's desire with a fried chicken bouquetThere's finally a way to prove HoloLens is as cool as you say it isInsane drone footage shows massive damage and flooding at California's Oroville DamHere are the stores that have dumped TrumpFrom Ian to Helene to Milton: Extreme weather is anything but 'natural'Now you can ask 'Be Mine?' with a custom Snapchat filterFlawless dog gets BeyoncéObama's photographer just threw shade at Trump's chaotic security meetingThis is a legitimately funny space prankApple teases a new show that's basically 'Shark Tank' for apps plus celebritiesIt sure looks like the iPhone 8 won't get long distance wireless charging'Rumps Against Trump' sees protesters bare their butts outside Trump TowerChina is censoring social media less now—but it's not freedomPlayboy, basically: 'jk nudity is back lol'Sam Altman open to ads on ChatGPT, calls Instagram ads ‘kinda cool’11 people and things to celebrate on Valentine's Day besides a significant other Adele posts heartwarming message to fans after finishing tour Map of the world's rudest place names is a thing of beauty Tsunami warning issued for Fukushima, Japan after powerful earthquake Hotel's magical Christmas decor comes from Apple designers Boys' childhoods are ruined by discovery of Thanksgiving turkey's fate Timely browser extension replaces ‘alt Welp, there's now a $130 'hipster nativity set' Bumbling Trump adviser Kris Kobach's secret plan for America, revealed People are dreading Thanksgiving now more than ever Donald Trump cancels, then uncancels, meeting with the 'not nice' New York Times This robot can teach you how to code by climbing on walls People are completely horrified by this 'Hail Trump' video Tesla is powering an entire island with solar energy, NBD Let a Butterball Turkey Talk Notre Dame football team placed on probation following academic misconduct Voting, cyber and political experts write letter demanding Russia hacking investigation Google is removing its 'In the news' label due to the fake news nightmare 'Bleak' — Most students have trouble identifying fake news, Stanford study finds Donald Trump disavowed the alt Killfies: India tops the list of most selfie deaths again
1.6411s , 10132.515625 kb
Copyright © 2025 Powered by 【2012 Archives】,Exquisite Information Network