Article Details
Scrape Timestamp (UTC): 2023-11-04 05:39:35.481
Source: https://thehackernews.com/2023/11/google-play-store-introduces.html
Original Article Text
Click to Toggle View
Google Play Store Introduces 'Independent Security Review' Badge for Apps. Google is rolling out an "Independent security review" badge in the Play Store's Data safety section for Android apps that have undergone a Mobile Application Security Assessment (MASA) audit. "We've launched this banner beginning with VPN apps due to the sensitive and significant amount of user data these apps handle," Nataliya Stanetsky of the Android Security and Privacy Team said. MASA allows developers to have their apps independently validated against a global security standard such as the Mobile Application Security Verification Standard (MASVS), thereby providing more transparency and enabling users to make informed choices prior to downloading them. The efforts are part of Google's broader push to make the Data safety section a one-stop shop that presents a "unified view of app safety," offering details about the kind of data that's being collected, for what purpose, and if it's being shared with third-parties. Third-party app developers who are interested in participating can reach out directly to one of the six Authorized Labs partners, who will then test the public version of the app available in the Play Store and flag potential security issues for remediation. "Once the app meets all requirements, the lab sends a Validation Report directly to Google as confirmation, and developers will be eligible to declare the security badge on their data safety form," Google notes. "On average, the process takes around 2-3 weeks from initial assessment to badge availability." That said, Google emphasized that the independent security testing process helps users check if a "developer has prioritized security and privacy practices and committed to user safety." It, however, noted that certification to baseline security standards does not imply that a validated app is free of vulnerabilities.
Daily Brief Summary
Google is introducing an "Independent security review" badge on the Play Store's Data safety section for Android apps that have successfully undergone a Mobile Application Security Assessment (MASA) audit.
Initially launched with VPN apps due to their sensitive data handling nature, the security audit will provide more transparency to users about an app's security standards before they download it.
MASA allows developers to independently validate their apps against global security standards such as Mobile Application Security Verification Standard (MASVS).
By participating in the security evaluation process, developers will get a chance to flag potential security issues in their apps and remediate them. On fulfilling all requirements, a security badge will appear on their data safety form.
Google's move forms part of its broader goal to create a unified view of app safety, providing details about what data is being collected by the app, its intended use and whether it is shared with third parties.
However, Google cautions that attaining a validation to baseline security standards does not necessarily mean an app is free from vulnerabilities.