In addition to Weibo, there is also WeChat
Please pay attention
WeChat public account
Shulou
2025-02-26 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > IT Information >
Share
Shulou(Shulou.com)11/24 Report--
CTOnews.com Android Open Source Project (AOSP) refers to the people, processes and source code that build Android. People oversee the project and develop the source code; process refers to the tools and programs used to manage the development of the software, resulting in source code that can be used for mobile phones and other devices.
AOSP is currently licensed under the Apache 2.0 Open Source License, which means anyone can modify its code. However, one disadvantage of this strategy is that it provides an easy route for malicious actors to destroy it. In response to security concerns, Google is stepping up scrutiny of external contributors.
Android expert Mishaal Rahman explained that all external changes to AOSP now require review and approval by two Google reviewers. The goal is to prevent hidden security holes and bugs in code from entering AOSP--not to restrict who can submit code to AOSP.
In fact, Rahman explicitly states that non-Google employees are not blacklisted for contributions. Instead, external code is only subject to review, giving those directly affected a chance to determine whether it should be integrated into AOSP. This is a more thorough review process that helps sift through the final code, identifying the most beneficial parts, and reducing security issues.
Foreign media believe that this strategy may significantly reduce some of the problems related to vulnerabilities that Google has faced in the past.
Just last year, David Schütz discovered a vulnerability in AOSP, a flaw that could allow hackers to bypass Android lock screens. He later received a $70,000 reward from Google for reporting the vulnerability.
It is worth noting that Google launched a program called Vulnerability Rewards Program in 2010, which has contributed more than 11000 vulnerabilities since its inception, and Google will reward them with cash. Google has already paid millions of dollars for these white hats.
Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.
Views: 0
*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.
Continue with the installation of the previous hadoop.First, install zookooper1. Decompress zookoope
"Every 5-10 years, there's a rare product, a really special, very unusual product that's the most un
© 2024 shulou.com SLNews company. All rights reserved.