blob: 7312382e150bc76b6afd5fd12fe2c321e7e4c629 [file] [log] [blame]
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -07001page.title=Android Security Acknowledgements
2@jd:body
3
4<!--
5 Copyright 2014 The Android Open Source Project
6
7 Licensed under the Apache License, Version 2.0 (the "License");
8 you may not use this file except in compliance with the License.
9 You may obtain a copy of the License at
10
11 http://www.apache.org/licenses/LICENSE-2.0
12
13 Unless required by applicable law or agreed to in writing, software
14 distributed under the License is distributed on an "AS IS" BASIS,
15 WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 See the License for the specific language governing permissions and
17 limitations under the License.
18-->
Clay Murphyef6e3bd2014-07-11 01:44:17 +000019
20<p>The Android Security Team would like to thank the following people and
21parties for helping to improve Android security. They have done this either by
22finding and responsibly reporting security vulnerabilities to <a
23href="mailto:security@android.com">security@android.com</a> or by committing code
24that has a positive impact on Android security, including code that qualifies
25for the <a href="https://www.google.com/about/appsecurity/patch-rewards/">Patch
26Rewards</a> program.</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070027
28<h2>2014</h2>
29
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -070030<div style="LINE-HEIGHT:25px;">
Clay Murphyef6e3bd2014-07-11 01:44:17 +000031<p>Jeff Forristal of <a href="http://www.bluebox.com/blog/">Bluebox
32Security</a></p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070033
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -070034<p>Aaron Mangel of <a href="https://banno.com/">Banno</a> (<a
Clay Murphyef6e3bd2014-07-11 01:44:17 +000035href="mailto:amangel@gmail.com">amangel@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070036
Clay Murphyef6e3bd2014-07-11 01:44:17 +000037<p><a href="http://www.linkedin.com/in/tonytrummer/">Tony Trummer</a> of <a
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -070038href="http://www.themeninthemiddle.com">The Men in the Middle</a> <br>(<a
Clay Murphyef6e3bd2014-07-11 01:44:17 +000039href="https://twitter.com/SecBro1">@SecBro1</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070040
41<p><a href="http://www.samsung.com">Samsung Mobile</a></p>
42
Clay Murphyef6e3bd2014-07-11 01:44:17 +000043<p>Henry Hoggard of <a href="https://labs.mwrinfosecurity.com/">MWR Labs</a> (<a
44href="https://twitter.com/henryhoggard">@HenryHoggard</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070045
Clay Murphyef6e3bd2014-07-11 01:44:17 +000046<p><a href="http://www.androbugs.com">Yu-Cheng Lin 林禹成</a> (<a
47href="https://twitter.com/AndroBugs">@AndroBugs</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070048
Clay Murphyef6e3bd2014-07-11 01:44:17 +000049<p><a
50href="http://www.ec-spride.tu-darmstadt.de/en/research-groups/secure-software-engineering-group/staff/siegfried-rasthofer/">Siegfried
51Rasthofer</a> of <a href="http://sseblog.ec-spride.de/">Secure Software
52Engineering Group</a>, EC SPRIDE Technische Universität Darmstadt (<a
53href="mailto:siegfried.rasthofer@gmail.com">siegfried.rasthofer@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070054
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -070055<p>Steven Arzt of <a href="http://sseblog.ec-spride.de/">Secure Software
Clay Murphyef6e3bd2014-07-11 01:44:17 +000056Engineering Group</a>, EC SPRIDE Technische Universität Darmstadt (<a
57href="mailto:Steven.Arzt@ec-spride.de">Steven.Arzt@ec-spride.de</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070058
Clay Murphyef6e3bd2014-07-11 01:44:17 +000059<p><a href="http://blog.redfern.me/">Joseph Redfern</a> of <a
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -070060href="https://labs.mwrinfosecurity.com/">MWR Labs</a> <br>(<a
Clay Murphyef6e3bd2014-07-11 01:44:17 +000061href="https://twitter.com/JosephRedfern">@JosephRedfern</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070062
Clay Murphyef6e3bd2014-07-11 01:44:17 +000063<p><a href="https://plus.google.com/u/0/109528607786970714118">Valera
64Neronov</a></p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070065
66<p><a href="https://github.com/michalbednarski">Michał Bednarski</a></p>
67
Clay Murphyef6e3bd2014-07-11 01:44:17 +000068<p><a href="http://www.linkedin.com/in/luander">Luander Michel Ribeiro</a> (<a
69href="https://twitter.com/luanderock">@luanderock</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070070
Clay Murphyef6e3bd2014-07-11 01:44:17 +000071<p>Stephan Huber of Testlab Mobile Security, <a
72href="https://www.sit.fraunhofer.de/">Fraunhofer SIT</a> (<a
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -070073href="mailto:Stephan.Huber@sit.fraunhofer.de">Stephan.Huber@sit.fraunhofer.de</a>)
74</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070075
Clay Murphyef6e3bd2014-07-11 01:44:17 +000076<p><a href="http://www.corkami.com">Ange Albertini</a> (<a
77href="https://twitter.com/angealbertini">@angealbertini</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070078
Clay Murphyef6e3bd2014-07-11 01:44:17 +000079<p><a href="https://www.linkedin.com/in/tdalvi">Tushar Dalvi</a> (<a
80href="https://twitter.com/tushardalvi">@tushardalvi</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070081
82<p>Axelle Apvrille of Fortinet, FortiGuards Labs</p>
83
Clay Murphyef6e3bd2014-07-11 01:44:17 +000084<p>Tongxin Li of Peking University (<a
85href="mailto:litongxin1991@gmail.com">litongxin1991@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070086
Clay Murphyef6e3bd2014-07-11 01:44:17 +000087<p><a href="https://www.facebook.com/zhou.xiaoyong">Xiaoyong Zhou</a> of <a
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -070088href="http://www.cs.indiana.edu/~zhou/">Indiana University Bloomington</a> <br>(<a
Clay Murphyef6e3bd2014-07-11 01:44:17 +000089href="https://twitter.com/xzhou">@xzhou</a>, <a
90href="mailto:zhou.xiaoyong@gmail.com">zhou.xiaoyong@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070091
Clay Murphyef6e3bd2014-07-11 01:44:17 +000092<p><a href="http://homes.soic.indiana.edu/luyixing">Luyi Xing</a> of Indiana
93University Bloomington (<a
94href="mailto:xingluyi@gmail.com">xingluyi@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070095
Clay Murphyef6e3bd2014-07-11 01:44:17 +000096<p>Yeonjoon Lee of Indiana University Bloomington (<a
97href="mailto:luc2yj@gmail.com">luc2yj@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070098
Clay Murphyef6e3bd2014-07-11 01:44:17 +000099<p><a href="http://www.informatics.indiana.edu/xw7/">Xiaofeng Wang</a> of
100Indiana University Bloomington (<a
101href="mailto:xw7@indiana.edu">xw7@indiana.edu</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -0700102
Clay Murphyef6e3bd2014-07-11 01:44:17 +0000103<p>Xinhui Han of Peking University (<a
104href="mailto:hanxinhui@pku.edu.cn">hanxinhui@pku.edu.cn</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -0700105
Natalie Silvanovich88d07272014-08-04 17:02:05 -0700106<p><a href="http://thejh.net/">Jann Horn</a> <a href="https://android-review.googlesource.com/#/c/98197/">
107<img style="vertical-align:middle;" src="images/tiny-robot.png"
108alt="Green Droid Patch Symbol"
109title="This person contributed code that improved Android security">
110</a></p>
111
112<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
113Trusted Systems Research Group</a>, US National Security Agency
114<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
115<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
116title="This person contributed code that improved Android security"></a></p>
117
118<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
119Trusted Systems Research Group</a>, US National Security Agency
120<a href=
121"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
122<img style="vertical-align:middle" src="images/tiny-robot.png"
123alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
124
125<p><a href="http://www.linkedin.com/in/billcroberts">
126William Roberts</a> (<a href="mailto:bill.c.roberts@gmail.com">bill.c.roberts@gmail.com</a>)
127<a href=
128"https://android-review.googlesource.com/#/q/owner:bill.c.roberts%2540gmail.com+status:merged">
129<img style="vertical-align:middle" src="images/tiny-robot.png"
130alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
131
132<p>Scotty Bauer of University of Utah (<a href="mailto:sbauer@eng.utah.edu">sbauer@eng.utah.edu</a>)</p>
133
134<p><a href="http://www.cs.utah.edu/~rsas/">Raimondas Sasnauskas</a> of University of Utah</p>
135
136<p><a href="http://www.subodh.io">Subodh Iyengar</a> of <a href="https://www.facebook.com">Facebook</a></p>
137
138<p><a href="http://www.shackleton.io/">Will Shackleton</a> of <a href="https://www.facebook.com">Facebook</a></p>
139
140</div>
141
142<h2>2013</h2>
143
144<div style="LINE-HEIGHT:25px;">
145
146<p>Jon Sawyer of <a href="http://appliedcybersecurity.com/">Applied Cybersecurity LLC
147</a> (<a href="mailto:jon@cunninglogic.com">jon@cunninglogic.com</a>)</p>
148
149<p>Joshua J. Drake of <a href="http://www.accuvant.com/">Accuvant LABS
150</a> (<a href="https://twitter.com/jduck">@jduck</a>)
151<a href="https://android-review.googlesource.com/#/q/change:72228+OR+change:72229">
152<img style="vertical-align:middle" src="images/patchreward.png"
153alt="Patch Rewards Symbol" title="This person qualified for the Patch Rewards program!"></a></p>
154
155<p>Ruben Santamarta of IOActive
156(<a href="https://twitter.com/reversemode">@reversemode</a>)</p>
157
158<p>Lucas Yang (amadoh4ck) of
159<a href="http://raonsecurity.com/">RaonSecurity</a>
160(<a href="mailto:amadoh4ck@gmail.com">amadoh4ck@gmail.com</a>)</p>
161
162<p><a href="https://tsarstva.bg/sh/">Ivaylo Marinkov</a>
163of <a href="http://www.ecommera.com/">eCommera</a> <br>
164(<a href="mailto:ivo@tsarstva.bg">ivo@tsarstva.bg</a>)</p>
165
166<p><a href="http://roeehay.blogspot.com/">Roee Hay</a>
167<br>(<a href="https://twitter.com/roeehay">@roeehay</a>,
168<a href="mailto:roeehay@gmail.com">roeehay@gmail.com</a>)</p>
169
170<p>Qualcomm Product Security Initiative</p>
171
172<p><a href="https://lacklustre.net/">Mike Ryan</a> of
173<a href="https://isecpartners.com/">iSEC Partners</a>
174<br>(<a href="https://twitter.com/mpeg4codec">@mpeg4codec</a>,
175<a href="mailto:mikeryan@isecpartners.com">mikeryan@isecpartners.com
176</a>)</p>
177
178<p><a href="http://cryptoonline.com/">Muhammad Naveed</a>
179of <a href="http://illinois.edu/">University of Illinois
180at Urbana-Champaign</a>
181<br>(<a href="mailto:naveed2@illinois.edu">naveed2@illinois.edu</a>)</p>
182
183<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
184Trusted Systems Research Group</a>, US National Security Agency
185<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
186<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
187title="This person contributed code that improved Android security"></a></p>
188
189<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
190Trusted Systems Research Group</a>, US National Security Agency
191<a href=
192"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
193<img style="vertical-align:middle" src="images/tiny-robot.png"
194alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
195
196<p><a href="http://www.linkedin.com/in/billcroberts">
197William Roberts</a> (<a href="mailto:bill.c.roberts@gmail.com">bill.c.roberts@gmail.com</a>)
198<a href=
199"https://android-review.googlesource.com/#/q/owner:bill.c.roberts%2540gmail.com+status:merged">
200<img style="vertical-align:middle" src="images/tiny-robot.png"
201alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
202
203<p><a href="http://roeehay.blogspot.com/">Roee Hay</a>
204<br>(<a href="https://twitter.com/roeehay">@roeehay</a>,
205<a href="mailto:roeehay@gmail.com">roeehay@gmail.com</a>)</p>
206
207</div>
208<h2>2012</h2>
209
210<div style="LINE-HEIGHT:25px;">
211
212<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
213Trusted Systems Research Group</a>, US National Security Agency
214<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
215<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
216title="This person contributed code that improved Android security"></a></p>
217
218<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
219Trusted Systems Research Group</a>, US National Security Agency
220<a href=
221"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
222<img style="vertical-align:middle" src="images/tiny-robot.png"
223alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
224
225<p><a href="http://www.linkedin.com/in/billcroberts">
226William Roberts</a> (<a href="mailto:bill.c.roberts@gmail.com">bill.c.roberts@gmail.com</a>)
227<a href=
228"https://android-review.googlesource.com/#/q/owner:bill.c.roberts%2540gmail.com+status:merged">
229<img style="vertical-align:middle" src="images/tiny-robot.png"
230alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
231
Natalie Silvanovich88d07272014-08-04 17:02:05 -0700232<p><a href="http://thejh.net/">Jann Horn</a></p>
233
234<p><a href="http://web.ict.kth.se/~rbbo/ussdvul.html">Ravishankar
235Borgaonkar</a> of TU Berlin
236(<a href="https://twitter.com/raviborgaonkar">@raviborgaonkar</a>)</p>
237
238<p><a href="http://roeehay.blogspot.com/">Roee Hay</a>
239<br>(<a href="https://twitter.com/roeehay">@roeehay</a>,
240<a href="mailto:roeehay@gmail.com">roeehay@gmail.com</a>)</p>
241
242</div>
243
244<h2>2011</h2>
245
246<div style="LINE-HEIGHT:25px;">
247
248<p>Collin Mulliner of <a href="http://www.mulliner.org/collin/academic">MUlliNER.ORG</a> (<a href="https://twitter.com/collinrm">@collinrm</a>)</p>
249
250</div>
251
252<h2>2009</h2>
253
254<div style="LINE-HEIGHT:25px;">
255
256<p>Collin Mulliner of <a href="http://www.mulliner.org/collin/academic">MUlliNER.ORG</a> (<a href="https://twitter.com/collinrm">@collinrm</a>)</p>
257
258<p>Charlie Miller (<a href="https://twitter.com/0xcharlie">@0xcharlie</a>)</p>
259
260</div>
261
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -0700262<br>
Natalie Silvanovich57f0bbd2014-07-21 18:17:20 -0700263<p><small>If you have reported a vulnerability prior to 2014 and want to be
264included on this list, or to report a vulnerability in Android, contact <a href="mailto:security@android.com">security@android.com</a></small></p>