| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 1 | page.title=Android Security FAQ |
| 2 | parent.title=FAQs, Tips, and How-to |
| 3 | parent.link=index.html |
| 4 | @jd:body |
| 5 | |
| 6 | <ul> |
| 7 | <li><a href="#secure">Is Android Secure?</a></li> |
| 8 | <li><a href="#issue">I think I found a security flaw. How do I report |
| 9 | it?</a></li> |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 10 | <li><a href="#informed">How can I stay informed about Android security?</a></li> |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 11 | <li><a href="#use">How do I securely use my Android phone?</a></li> |
| 12 | <li><a href="#malware">I think I found malicious software being distributed |
| 13 | for Android. How can I help?</a></li> |
| 14 | <li><a href="#fixes">How will Android-powered devices receive security fixes?</a> |
| 15 | </li> |
| 16 | <li><a href="#directfix">Can I get a fix directly from the Android Platform |
| 17 | Project?</a></li> |
| 18 | </ul> |
| 19 | |
| 20 | |
| 21 | <a name="secure" id="secure"></a><h2>Is Android secure?</h2> |
| 22 | |
| 23 | <p>The security and privacy of our users' data is of primary importance to the |
| 24 | Android Open Source Project. We are dedicated to building and maintaining one |
| 25 | of the most secure mobile platforms available while still fulfilling our goal |
| 26 | of opening the mobile device space to innovation and competition.</p> |
| 27 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 28 | <p> A comprehensive overview of the <a |
| 29 | href="http://source.android.com/tech/security/index.html">Android |
| 30 | security model and Android security processes</a> is provided in the Android |
| 31 | Open Source Project Website.</p> |
| 32 | |
| 33 | <p>Application developers play an important part in the security of Android. |
| 34 | The Android Platform provides developers with a rich <a |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 35 | href="http://code.google.com/android/devel/security.html">security model</a> |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 36 | that to request the capabilities, or access, needed by their |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 37 | application and to define new capabilities that other applications can request. |
| 38 | The Android user can choose to grant or deny an application's request for |
| 39 | certain capabilities on the handset.</p> |
| 40 | |
| 41 | <p>We have made great efforts to secure the Android platform, but it is |
| 42 | inevitable that security bugs will be found in any system of this complexity. |
| 43 | Therefore, the Android team works hard to find new bugs internally and responds |
| 44 | quickly and professionally to vulnerability reports from external researchers. |
| 45 | </p> |
| 46 | |
| 47 | |
| 48 | <a name="issue" id="issue"></a><h2>I think I found a security flaw. How do I |
| 49 | report it?</h2> |
| 50 | |
| 51 | <p>You can reach the Android security team at <a |
| 52 | href="mailto:security@android.com">security@android.com</a>. If you like, you |
| 53 | can protect your message using our <a |
| 54 | href="http://code.google.com/android/security_at_android_dot_com.txt">PGP |
| 55 | key</a>.</p> |
| 56 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 57 | <p>We appreciate researchers practicing responsible disclosure by emailing us |
| 58 | with a detailed summary of the issue and keeping the issue confidential while |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 59 | users are at risk. In return, we will make sure to keep the researcher informed |
| 60 | of our progress in issuing a fix and will properly credit the reporter(s) when |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 61 | we provide the patch. We will always move swiftly to mitigate or fix an |
| 62 | externally-reported flaw and provide updates to users. </p> |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 63 | |
| 64 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 65 | <a name="informed" id="informed"></a><h2>How can I stay informed about Android security?</h2> |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 66 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 67 | <p>For general discussion of Android platform security, or how to use |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 68 | security features in your Android application, please subscribe to <a |
| 69 | href="http://groups.google.com/group/android-security-discuss">android-security-discuss</a>. |
| 70 | </p> |
| 71 | |
| 72 | |
| 73 | <a name="use" id="use"></a><h2>How do I securely use my Android phone?</h2> |
| 74 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 75 | <p>Android was designed so that you can safely use your phone without making |
| 76 | any changes to the device or installing any special software. Android applications |
| 77 | run in an Application Sandbox that limits access to sensitive information or data |
| 78 | with the users permission.</p> |
| 79 | |
| 80 | <p>To fully benefit from the security protections in Android, it is important that |
| 81 | users only download and install software from known sources.</p> |
| 82 | |
| 83 | <p>As an open platform, Android allows users to visit any website and load |
| 84 | software from any developer onto a device. As with a home PC, the user must be |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 85 | aware of who is providing the software they are downloading and must decide |
| 86 | whether they want to grant the application the capabilities it requests. |
| 87 | This decision can be informed by the user's judgment of the software |
| 88 | developer's trustworthiness, and where the software came from.</p> |
| 89 | |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 90 | |
| 91 | <a name="malware" id="malware"></a><h2>I think I found malicious software being |
| 92 | distributed for Android. How can I help?</h2> |
| 93 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 94 | <p>Like any other platform, it will be possible for unethical developers |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 95 | to create malicious software, known as <a |
| 96 | href="http://en.wikipedia.org/wiki/Malware">malware</a>, for Android. If you |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 97 | think somebody is trying to spread malware, please let us know at <a |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 98 | href="mailto:security@android.com">security@android.com</a>. Please include as |
| 99 | much detail about the application as possible, with the location it is |
| 100 | being distributed from and why you suspect it of being malicious software.</p> |
| 101 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 102 | <p>The term <i>malicious software</i> is subjective, and we cannot make an |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 103 | exhaustive definition. Some examples of what the Android Security Team believes |
| 104 | to be malicious software is any application that: |
| 105 | <ul> |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 106 | <li>uses a bug or security vulnerability to gain permissions that have not |
| 107 | been granted by the user</li> |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 108 | <li>shows the user unsolicited messages (especially messages urging the |
| 109 | user to buy something);</li> |
| 110 | <li>resists (or attempts to resist) the user's effort to uninstall it;</li> |
| 111 | <li>attempts to automatically spread itself to other devices;</li> |
| 112 | <li>hides its files and/or processes;</li> |
| 113 | <li>discloses the user's private information to a third party, without the |
| 114 | user's knowledge and consent;</li> |
| 115 | <li>destroys the user's data (or the device itself) without the user's |
| 116 | knowledge and consent;</li> |
| 117 | <li>impersonates the user (such as by sending email or buying things from a |
| 118 | web store) without the user's knowledge and consent; or</li> |
| 119 | <li>otherwise degrades the user's experience with the device.</li> |
| 120 | </ul> |
| 121 | </p> |
| 122 | |
| 123 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 124 | <a name="fixes" id="fixes"></a><h2>How do Android-powered devices receive security |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 125 | fixes?</h2> |
| 126 | |
| 127 | <p>The manufacturer of each device is responsible for distributing software |
| 128 | upgrades for it, including security fixes. Many devices will update themselves |
| 129 | automatically with software downloaded "over the air", while some devices |
| 130 | require the user to upgrade them manually.</p> |
| 131 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 132 | <p>Google provides software updates for a number of Android devices, including |
| 133 | the <a href="http://www.google.com/nexus">Nexus</a> |
| 134 | series of devices, using an "over the air" (OTA) update. These updates may include |
| 135 | security fixes as well as new features.</p> |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 136 | |
| 137 | <a name="directfix" id="directfix"></a><h2>Can I get a fix directly from the |
| 138 | Android Platform Project?</h2> |
| 139 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 140 | <p>Android is a mobile platform that is released as open source and |
| 141 | available for free use by anybody. This means that there are many |
| 142 | Android-based products available to consumers, and most of them are created |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 143 | without the knowledge or participation of the Android Open Source Project. Like |
| 144 | the maintainers of other open source projects, we cannot build and release |
| 145 | patches for the entire ecosystem of products using Android. Instead, we will |
| 146 | work diligently to find and fix flaws as quickly as possible and to distribute |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 147 | those fixes to the manufacturers of the products through the open source project.</p> |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 148 | |
| Adrian Ludwig | 4caa0d7 | 2011-09-21 15:38:55 -0700 | [diff] [blame] | 149 | <p>If you are making an Android-powered device and would like to know how you can |
| Dirk Dougherty | 22558d0 | 2009-12-10 16:25:06 -0800 | [diff] [blame] | 150 | properly support your customers by keeping abreast of software updates, please |
| 151 | contact us at <a |
| 152 | href="mailto:info@openhandsetalliance.com">info@openhandsetalliance.com</a>.</p> |