Google Play issues security warning to app developers

Powered by SC Magazine
 

Devs given 30 days to fix bad apps.

Google Play has issued a letter to developers to address changes in policy to crack down on insecure and dangerous apps.

The letter said that Google had made changes to its policies in regard to ‘dangerous products' that disclose personal information without authorisation and the behaviour of adverts in applications.

Google said that it is providing more detail on the kinds of dangerous products that are not allowed on Google Play, and has added a new section that addresses advert behaviour in apps.

“First, we make it clear that adverts in your app must follow the same rules as the app itself. Also, it is important to us that adverts don't negatively affect the experience by deceiving consumers or using disruptive behaviour such as obstructing access to apps and interfering with other adverts.”

This policy states that adverts are considered part of the app for the purposes of content review and compliance with the developer terms, so all policies, including those concerning illegal activities, violence, sexually explicit content and privacy violations, apply.

Google said it must be clear to the user which app each ad is associated with or implemented in. Adverts must not make changes to the functioning of the user's device outside the ad by doing things such as installing shortcuts, bookmarks or icons or changing default settings without the user's knowledge and consent.

“If an ad makes such changes it must be clear to the user which app has made the change and the user must be able to reverse the change easily, by either adjusting the settings on the device, advertising preferences in the app, or uninstalling the app altogether.”

Also, adverts must not simulate or impersonate system notifications or warnings and adverts associated with an app must not interfere with any adverts on a third-party application, it said.

Research by MWR Infosecurity and Channel 4 News found that some leading applications were sending personal data back from devices to advertising companies without user knowledge and that permissions were granted to the apps when they were downloaded.

Updating its Google Play developer program policy, Google said that it is required to update its policies when it launches new features and when it sees unhealthy behaviour such as deceptive app names and spam notifications.

It has also restricted the use of names or icons that are "confusingly similar to existing system apps in order to reduce user confusion".

It said that any existing apps will be given 30 days to fix and republish the application and after this period, existing applications discovered to be in violation may be subject to warning or removal from Google Play.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, UK edition


Google Play issues security warning to app developers
 
 
 
Top Stories
Matching databases to Linux distros
Reviewed: OS-repository DBMSs, MariaDB vs MySQL.
 
Coalition's NBN cost-benefit study finds in favour of MTM
FTTP costs too much, would take too long.
 
Who'd have picked a BlackBerry for the Internet of Things?
[Blog] BlackBerry has a more secure future in the physical world.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Looking for storage? Seagate has five new small business NAS devices
Aug 22, 2014
Seagate has announced a new portfolio of Networked Attached Storage (NAS) solutions specifically ...
Run a small business in western Sydney?
Aug 15, 2014
This event might be of interest if you're looking to meet other people with a similar interest ...
Buying a tablet? Microsoft's Surface Pro 3 goes on sale this month
Aug 8, 2014
Microsoft has announced its Surface Pro 3 will go on sale in Australia on 28 August from ...
Apple's top MacBook Pro with Retina is now cheaper
Aug 1, 2014
Apple has updated its MacBook Pro range with faster processors and new pricing, including ...
Pass on carbon tax savings, warns ACCC
Jul 24, 2014
The ACCC is warning businesses that supply "regulated goods" to pass on any cost savings ...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  71%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  11%
 
Denial of service attacks
  6%
 
Insider threats
  10%
TOTAL VOTES: 765

Vote