blob: 02d0e27db45774c771852f405c073ffb8fbe38f8 [file] [log] [blame]
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -07001page.title=Android Security Acknowledgements
2@jd:body
3
4<!--
5 Copyright 2014 The Android Open Source Project
6
7 Licensed under the Apache License, Version 2.0 (the "License");
8 you may not use this file except in compliance with the License.
9 You may obtain a copy of the License at
10
11 http://www.apache.org/licenses/LICENSE-2.0
12
13 Unless required by applicable law or agreed to in writing, software
14 distributed under the License is distributed on an "AS IS" BASIS,
15 WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 See the License for the specific language governing permissions and
17 limitations under the License.
18-->
Clay Murphyef6e3bd2014-07-11 01:44:17 +000019
20<p>The Android Security Team would like to thank the following people and
21parties for helping to improve Android security. They have done this either by
22finding and responsibly reporting security vulnerabilities to <a
23href="mailto:security@android.com">security@android.com</a> or by committing code
24that has a positive impact on Android security, including code that qualifies
25for the <a href="https://www.google.com/about/appsecurity/patch-rewards/">Patch
26Rewards</a> program.</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070027
28<h2>2014</h2>
29
Clay Murphyef6e3bd2014-07-11 01:44:17 +000030<p>Jeff Forristal of <a href="http://www.bluebox.com/blog/">Bluebox
31Security</a></p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070032
Clay Murphyef6e3bd2014-07-11 01:44:17 +000033<p>Aaron Mangeli of <a href="https://banno.com/">Banno</a> (<a
34href="mailto:amangel@gmail.com">amangel@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070035
Clay Murphyef6e3bd2014-07-11 01:44:17 +000036<p><a href="http://www.linkedin.com/in/tonytrummer/">Tony Trummer</a> of <a
37href="http://www.themeninthemiddle.com">The Men in the Middle</a> (<a
38href="https://twitter.com/SecBro1">@SecBro1</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070039
40<p><a href="http://www.samsung.com">Samsung Mobile</a></p>
41
Clay Murphyef6e3bd2014-07-11 01:44:17 +000042<p>Henry Hoggard of <a href="https://labs.mwrinfosecurity.com/">MWR Labs</a> (<a
43href="https://twitter.com/henryhoggard">@HenryHoggard</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070044<p></p>
45
Clay Murphyef6e3bd2014-07-11 01:44:17 +000046<p><a href="http://www.androbugs.com">Yu-Cheng Lin 林禹成</a> (<a
47href="https://twitter.com/AndroBugs">@AndroBugs</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070048
Clay Murphyef6e3bd2014-07-11 01:44:17 +000049<p><a
50href="http://www.ec-spride.tu-darmstadt.de/en/research-groups/secure-software-engineering-group/staff/siegfried-rasthofer/">Siegfried
51Rasthofer</a> of <a href="http://sseblog.ec-spride.de/">Secure Software
52Engineering Group</a>, EC SPRIDE Technische Universität Darmstadt (<a
53href="mailto:siegfried.rasthofer@gmail.com">siegfried.rasthofer@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070054
Clay Murphyef6e3bd2014-07-11 01:44:17 +000055<p>Steven Artz of <a href="http://sseblog.ec-spride.de/">Secure Software
56Engineering Group</a>, EC SPRIDE Technische Universität Darmstadt (<a
57href="mailto:Steven.Arzt@ec-spride.de">Steven.Arzt@ec-spride.de</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070058
Clay Murphyef6e3bd2014-07-11 01:44:17 +000059<p><a href="http://blog.redfern.me/">Joseph Redfern</a> of <a
60href="https://labs.mwrinfosecurity.com/">MWR Labs</a> (<a
61href="https://twitter.com/JosephRedfern">@JosephRedfern</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070062
Clay Murphyef6e3bd2014-07-11 01:44:17 +000063<p><a href="https://plus.google.com/u/0/109528607786970714118">Valera
64Neronov</a></p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070065
66<p><a href="https://github.com/michalbednarski">Michał Bednarski</a></p>
67
Clay Murphyef6e3bd2014-07-11 01:44:17 +000068<p><a href="http://www.linkedin.com/in/luander">Luander Michel Ribeiro</a> (<a
69href="https://twitter.com/luanderock">@luanderock</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070070
Clay Murphyef6e3bd2014-07-11 01:44:17 +000071<p>Stephan Huber of Testlab Mobile Security, <a
72href="https://www.sit.fraunhofer.de/">Fraunhofer SIT</a> (<a
73href="mailto:Stephan.Huber@sit.fraunhofer.de">Stephan.Huber@sit.fraunhofer.de</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070074
Clay Murphyef6e3bd2014-07-11 01:44:17 +000075<p><a href="http://www.corkami.com">Ange Albertini</a> (<a
76href="https://twitter.com/angealbertini">@angealbertini</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070077
Clay Murphyef6e3bd2014-07-11 01:44:17 +000078<p><a href="https://www.linkedin.com/in/tdalvi">Tushar Dalvi</a> (<a
79href="https://twitter.com/tushardalvi">@tushardalvi</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070080
81<p>Axelle Apvrille of Fortinet, FortiGuards Labs</p>
82
Clay Murphyef6e3bd2014-07-11 01:44:17 +000083<p>Tongxin Li of Peking University (<a
84href="mailto:litongxin1991@gmail.com">litongxin1991@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070085
Clay Murphyef6e3bd2014-07-11 01:44:17 +000086<p><a href="https://www.facebook.com/zhou.xiaoyong">Xiaoyong Zhou</a> of <a
87href="http://www.cs.indiana.edu/~zhou/">Indiana University Bloomington</a> (<a
88href="https://twitter.com/xzhou">@xzhou</a>, <a
89href="mailto:zhou.xiaoyong@gmail.com">zhou.xiaoyong@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070090
Clay Murphyef6e3bd2014-07-11 01:44:17 +000091<p><a href="http://homes.soic.indiana.edu/luyixing">Luyi Xing</a> of Indiana
92University Bloomington (<a
93href="mailto:xingluyi@gmail.com">xingluyi@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070094
Clay Murphyef6e3bd2014-07-11 01:44:17 +000095<p>Yeonjoon Lee of Indiana University Bloomington (<a
96href="mailto:luc2yj@gmail.com">luc2yj@gmail.com</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -070097
Clay Murphyef6e3bd2014-07-11 01:44:17 +000098<p><a href="http://www.informatics.indiana.edu/xw7/">Xiaofeng Wang</a> of
99Indiana University Bloomington (<a
100href="mailto:xw7@indiana.edu">xw7@indiana.edu</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -0700101
Clay Murphyef6e3bd2014-07-11 01:44:17 +0000102<p>Xinhui Han of Peking University (<a
103href="mailto:hanxinhui@pku.edu.cn">hanxinhui@pku.edu.cn</a>)</p>
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -0700104
Natalie Silvanovich88d07272014-08-04 17:02:05 -0700105<p><a href="http://thejh.net/">Jann Horn</a> <a href="https://android-review.googlesource.com/#/c/98197/">
106<img style="vertical-align:middle;" src="images/tiny-robot.png"
107alt="Green Droid Patch Symbol"
108title="This person contributed code that improved Android security">
109</a></p>
110
111<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
112Trusted Systems Research Group</a>, US National Security Agency
113<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
114<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
115title="This person contributed code that improved Android security"></a></p>
116
117<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
118Trusted Systems Research Group</a>, US National Security Agency
119<a href=
120"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
121<img style="vertical-align:middle" src="images/tiny-robot.png"
122alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
123
124<p><a href="http://www.linkedin.com/in/billcroberts">
125William Roberts</a> (<a href="mailto:bill.c.roberts@gmail.com">bill.c.roberts@gmail.com</a>)
126<a href=
127"https://android-review.googlesource.com/#/q/owner:bill.c.roberts%2540gmail.com+status:merged">
128<img style="vertical-align:middle" src="images/tiny-robot.png"
129alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
130
131<p>Scotty Bauer of University of Utah (<a href="mailto:sbauer@eng.utah.edu">sbauer@eng.utah.edu</a>)</p>
132
133<p><a href="http://www.cs.utah.edu/~rsas/">Raimondas Sasnauskas</a> of University of Utah</p>
134
135<p><a href="http://www.subodh.io">Subodh Iyengar</a> of <a href="https://www.facebook.com">Facebook</a></p>
136
137<p><a href="http://www.shackleton.io/">Will Shackleton</a> of <a href="https://www.facebook.com">Facebook</a></p>
138
139</div>
140
141<h2>2013</h2>
142
143<div style="LINE-HEIGHT:25px;">
144
145<p>Jon Sawyer of <a href="http://appliedcybersecurity.com/">Applied Cybersecurity LLC
146</a> (<a href="mailto:jon@cunninglogic.com">jon@cunninglogic.com</a>)</p>
147
148<p>Joshua J. Drake of <a href="http://www.accuvant.com/">Accuvant LABS
149</a> (<a href="https://twitter.com/jduck">@jduck</a>)
150<a href="https://android-review.googlesource.com/#/q/change:72228+OR+change:72229">
151<img style="vertical-align:middle" src="images/patchreward.png"
152alt="Patch Rewards Symbol" title="This person qualified for the Patch Rewards program!"></a></p>
153
154<p>Ruben Santamarta of IOActive
155(<a href="https://twitter.com/reversemode">@reversemode</a>)</p>
156
157<p>Lucas Yang (amadoh4ck) of
158<a href="http://raonsecurity.com/">RaonSecurity</a>
159(<a href="mailto:amadoh4ck@gmail.com">amadoh4ck@gmail.com</a>)</p>
160
161<p><a href="https://tsarstva.bg/sh/">Ivaylo Marinkov</a>
162of <a href="http://www.ecommera.com/">eCommera</a> <br>
163(<a href="mailto:ivo@tsarstva.bg">ivo@tsarstva.bg</a>)</p>
164
165<p><a href="http://roeehay.blogspot.com/">Roee Hay</a>
166<br>(<a href="https://twitter.com/roeehay">@roeehay</a>,
167<a href="mailto:roeehay@gmail.com">roeehay@gmail.com</a>)</p>
168
169<p>Qualcomm Product Security Initiative</p>
170
171<p><a href="https://lacklustre.net/">Mike Ryan</a> of
172<a href="https://isecpartners.com/">iSEC Partners</a>
173<br>(<a href="https://twitter.com/mpeg4codec">@mpeg4codec</a>,
174<a href="mailto:mikeryan@isecpartners.com">mikeryan@isecpartners.com
175</a>)</p>
176
177<p><a href="http://cryptoonline.com/">Muhammad Naveed</a>
178of <a href="http://illinois.edu/">University of Illinois
179at Urbana-Champaign</a>
180<br>(<a href="mailto:naveed2@illinois.edu">naveed2@illinois.edu</a>)</p>
181
182<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
183Trusted Systems Research Group</a>, US National Security Agency
184<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
185<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
186title="This person contributed code that improved Android security"></a></p>
187
188<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
189Trusted Systems Research Group</a>, US National Security Agency
190<a href=
191"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
192<img style="vertical-align:middle" src="images/tiny-robot.png"
193alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
194
195<p><a href="http://www.linkedin.com/in/billcroberts">
196William Roberts</a> (<a href="mailto:bill.c.roberts@gmail.com">bill.c.roberts@gmail.com</a>)
197<a href=
198"https://android-review.googlesource.com/#/q/owner:bill.c.roberts%2540gmail.com+status:merged">
199<img style="vertical-align:middle" src="images/tiny-robot.png"
200alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
201
202<p><a href="http://roeehay.blogspot.com/">Roee Hay</a>
203<br>(<a href="https://twitter.com/roeehay">@roeehay</a>,
204<a href="mailto:roeehay@gmail.com">roeehay@gmail.com</a>)</p>
205
206</div>
207<h2>2012</h2>
208
209<div style="LINE-HEIGHT:25px;">
210
211<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
212Trusted Systems Research Group</a>, US National Security Agency
213<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
214<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
215title="This person contributed code that improved Android security"></a></p>
216
217<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
218Trusted Systems Research Group</a>, US National Security Agency
219<a href=
220"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
221<img style="vertical-align:middle" src="images/tiny-robot.png"
222alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
223
224<p><a href="http://www.linkedin.com/in/billcroberts">
225William Roberts</a> (<a href="mailto:bill.c.roberts@gmail.com">bill.c.roberts@gmail.com</a>)
226<a href=
227"https://android-review.googlesource.com/#/q/owner:bill.c.roberts%2540gmail.com+status:merged">
228<img style="vertical-align:middle" src="images/tiny-robot.png"
229alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
230
231
232<p><a href="http://thejh.net/">Jann Horn</a></p>
233
234<p><a href="http://web.ict.kth.se/~rbbo/ussdvul.html">Ravishankar
235Borgaonkar</a> of TU Berlin
236(<a href="https://twitter.com/raviborgaonkar">@raviborgaonkar</a>)</p>
237
238<p><a href="http://roeehay.blogspot.com/">Roee Hay</a>
239<br>(<a href="https://twitter.com/roeehay">@roeehay</a>,
240<a href="mailto:roeehay@gmail.com">roeehay@gmail.com</a>)</p>
241
242</div>
243
244<h2>2011</h2>
245
246<div style="LINE-HEIGHT:25px;">
247
248<p>Collin Mulliner of <a href="http://www.mulliner.org/collin/academic">MUlliNER.ORG</a> (<a href="https://twitter.com/collinrm">@collinrm</a>)</p>
249
250</div>
251
252<h2>2009</h2>
253
254<div style="LINE-HEIGHT:25px;">
255
256<p>Collin Mulliner of <a href="http://www.mulliner.org/collin/academic">MUlliNER.ORG</a> (<a href="https://twitter.com/collinrm">@collinrm</a>)</p>
257
258<p>Charlie Miller (<a href="https://twitter.com/0xcharlie">@0xcharlie</a>)</p>
259
260</div>
261
Natalie Silvanovichf04ee8b2014-06-19 10:24:16 -0700262<br>
263<p><small>If you have reported a vulnerability prior to 2014 and want to be included on this list, or to report a vulnerability in Android, contact <a href="mailto:security@android.com">security@android.com</a></small></p>