blob: 637aa11929d04956b65057e3527e40dcbb391744 [file] [log] [blame]
Natalie Silvanovichf9118652014-06-19 10:24:16 -07001page.title=Android Security Acknowledgements
2@jd:body
3
4<!--
5 Copyright 2014 The Android Open Source Project
6
7 Licensed under the Apache License, Version 2.0 (the "License");
8 you may not use this file except in compliance with the License.
9 You may obtain a copy of the License at
10
11 http://www.apache.org/licenses/LICENSE-2.0
12
13 Unless required by applicable law or agreed to in writing, software
14 distributed under the License is distributed on an "AS IS" BASIS,
15 WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 See the License for the specific language governing permissions and
17 limitations under the License.
18-->
19<p>The Android Security Team would like to thank the following people and
20parties for helping to improve Android security. They have done this either by
21finding and responsibly reporting security vulnerabilities to <a
22href="mailto:security@android.com">security@android.com</a> or by committing code
23that has a positive impact on Android security, including code that qualifies
24for the <a href="https://www.google.com/about/appsecurity/patch-rewards/">Patch
25Rewards</a> program.</p>
26
27<h2>2014</h2>
28
Natalie Silvanovichb80378c2014-07-21 18:17:20 -070029<div style="LINE-HEIGHT:25px;">
Natalie Silvanovichf9118652014-06-19 10:24:16 -070030<p>Jeff Forristal of <a href="http://www.bluebox.com/blog/">Bluebox
31Security</a></p>
32
Natalie Silvanovichb80378c2014-07-21 18:17:20 -070033<p>Aaron Mangel of <a href="https://banno.com/">Banno</a> (<a
Natalie Silvanovichf9118652014-06-19 10:24:16 -070034href="mailto:amangel@gmail.com">amangel@gmail.com</a>)</p>
35
36<p><a href="http://www.linkedin.com/in/tonytrummer/">Tony Trummer</a> of <a
Natalie Silvanovichb80378c2014-07-21 18:17:20 -070037href="http://www.themeninthemiddle.com">The Men in the Middle</a> <br>(<a
Natalie Silvanovichf9118652014-06-19 10:24:16 -070038href="https://twitter.com/SecBro1">@SecBro1</a>)</p>
39
40<p><a href="http://www.samsung.com">Samsung Mobile</a></p>
41
42<p>Henry Hoggard of <a href="https://labs.mwrinfosecurity.com/">MWR Labs</a> (<a
43href="https://twitter.com/henryhoggard">@HenryHoggard</a>)</p>
Natalie Silvanovichf9118652014-06-19 10:24:16 -070044
45<p><a href="http://www.androbugs.com">Yu-Cheng Lin 林禹成</a> (<a
46href="https://twitter.com/AndroBugs">@AndroBugs</a>)</p>
47
48<p><a
49href="http://www.ec-spride.tu-darmstadt.de/en/research-groups/secure-software-engineering-group/staff/siegfried-rasthofer/">Siegfried
50Rasthofer</a> of <a href="http://sseblog.ec-spride.de/">Secure Software
51Engineering Group</a>, EC SPRIDE Technische Universität Darmstadt (<a
52href="mailto:siegfried.rasthofer@gmail.com">siegfried.rasthofer@gmail.com</a>)</p>
53
Natalie Silvanovichb80378c2014-07-21 18:17:20 -070054<p>Steven Arzt of <a href="http://sseblog.ec-spride.de/">Secure Software
Natalie Silvanovichf9118652014-06-19 10:24:16 -070055Engineering Group</a>, EC SPRIDE Technische Universität Darmstadt (<a
56href="mailto:Steven.Arzt@ec-spride.de">Steven.Arzt@ec-spride.de</a>)</p>
57
58<p><a href="http://blog.redfern.me/">Joseph Redfern</a> of <a
Natalie Silvanovichb80378c2014-07-21 18:17:20 -070059href="https://labs.mwrinfosecurity.com/">MWR Labs</a> <br>(<a
Natalie Silvanovichf9118652014-06-19 10:24:16 -070060href="https://twitter.com/JosephRedfern">@JosephRedfern</a>)</p>
61
62<p><a href="https://plus.google.com/u/0/109528607786970714118">Valera
63Neronov</a></p>
64
65<p><a href="https://github.com/michalbednarski">Michał Bednarski</a></p>
66
67<p><a href="http://www.linkedin.com/in/luander">Luander Michel Ribeiro</a> (<a
68href="https://twitter.com/luanderock">@luanderock</a>)</p>
69
70<p>Stephan Huber of Testlab Mobile Security, <a
71href="https://www.sit.fraunhofer.de/">Fraunhofer SIT</a> (<a
Natalie Silvanovichb80378c2014-07-21 18:17:20 -070072href="mailto:Stephan.Huber@sit.fraunhofer.de">Stephan.Huber@sit.fraunhofer.de</a>)
73</p>
Natalie Silvanovichf9118652014-06-19 10:24:16 -070074
75<p><a href="http://www.corkami.com">Ange Albertini</a> (<a
76href="https://twitter.com/angealbertini">@angealbertini</a>)</p>
77
78<p><a href="https://www.linkedin.com/in/tdalvi">Tushar Dalvi</a> (<a
79href="https://twitter.com/tushardalvi">@tushardalvi</a>)</p>
80
81<p>Axelle Apvrille of Fortinet, FortiGuards Labs</p>
82
83<p>Tongxin Li of Peking University (<a
84href="mailto:litongxin1991@gmail.com">litongxin1991@gmail.com</a>)</p>
85
86<p><a href="https://www.facebook.com/zhou.xiaoyong">Xiaoyong Zhou</a> of <a
Natalie Silvanovichb80378c2014-07-21 18:17:20 -070087href="http://www.cs.indiana.edu/~zhou/">Indiana University Bloomington</a> <br>(<a
Natalie Silvanovichf9118652014-06-19 10:24:16 -070088href="https://twitter.com/xzhou">@xzhou</a>, <a
89href="mailto:zhou.xiaoyong@gmail.com">zhou.xiaoyong@gmail.com</a>)</p>
90
91<p><a href="http://homes.soic.indiana.edu/luyixing">Luyi Xing</a> of Indiana
92University Bloomington (<a
93href="mailto:xingluyi@gmail.com">xingluyi@gmail.com</a>)</p>
94
95<p>Yeonjoon Lee of Indiana University Bloomington (<a
96href="mailto:luc2yj@gmail.com">luc2yj@gmail.com</a>)</p>
97
98<p><a href="http://www.informatics.indiana.edu/xw7/">Xiaofeng Wang</a> of
99Indiana University Bloomington (<a
100href="mailto:xw7@indiana.edu">xw7@indiana.edu</a>)</p>
101
102<p>Xinhui Han of Peking University (<a
103href="mailto:hanxinhui@pku.edu.cn">hanxinhui@pku.edu.cn</a>)</p>
104
Natalie Silvanovichb80378c2014-07-21 18:17:20 -0700105<p><a href="http://thejh.net/">Jann Horn</a> <a href="https://android-review.googlesource.com/#/c/98197/">
106<img style="vertical-align:middle;" src="images/tiny-robot.png"
107alt="Green Droid Patch Symbol"
108title="This person contributed code that improved Android security">
109</a></p>
110
111<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
112Trusted Systems Research Group</a>, US National Security Agency
113<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
114<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
115title="This person contributed code that improved Android security"></a></p>
116
117<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
118Trusted Systems Research Group</a>, US National Security Agency
119<a href=
120"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
121<img style="vertical-align:middle" src="images/tiny-robot.png"
122alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
123
124<p><a href="http://www.linkedin.com/in/billcroberts">
125William Roberts</a> (<a href="mailto:bill.c.roberts@gmail.com">bill.c.roberts@gmail.com</a>)
126<a href=
127"https://android-review.googlesource.com/#/q/owner:bill.c.roberts%2540gmail.com+status:merged">
128<img style="vertical-align:middle" src="images/tiny-robot.png"
129alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
130
131<p>Scotty Bauer of University of Utah (<a href="mailto:sbauer@eng.utah.edu">sbauer@eng.utah.edu</a>)</p>
132
133<p><a href="http://www.cs.utah.edu/~rsas/">Raimondas Sasnauskas</a> of University of Utah</p>
134
135</div>
136
137<h2>2013</h2>
138
139<div style="LINE-HEIGHT:25px;">
140
141<p>Jon Sawyer of <a href="http://appliedcybersecurity.com/">Applied Cybersecurity LLC
142</a> (<a href="mailto:jon@cunninglogic.com">jon@cunninglogic.com</a>)</p>
143
144<p>Joshua J. Drake of <a href="http://www.accuvant.com/">Accuvant LABS
145</a> (<a href="https://twitter.com/jduck">@jduck</a>)
146<a href="https://android-review.googlesource.com/#/q/change:72228+OR+change:72229">
147<img style="vertical-align:middle" src="images/patchreward.png"
148alt="Patch Rewards Symbol" title="This person qualified for the Patch Rewards program!"></a></p>
149
150<p>Ruben Santamarta of IOActive
151(<a href="https://twitter.com/reversemode">@reversemode</a>)</p>
152
153<p>Lucas Yangi (amadoh4ck) of
154<a href="http://raonsecurity.com/">RaonSecurity</a>
155(<a href="mailto:amadoh4ck@gmail.com">amadoh4ck@gmail.com</a>)</p>
156
157<p><a href="https://tsarstva.bg/sh/">Ivaylo Marinkov</a>
158of <a href="http://www.ecommera.com/">eCommera</a> <br>
159(<a href="mailto:ivo@tsarstva.bg">ivo@tsarstva.bg</a>)</p>
160
161<p><a href="http://roeehay.blogspot.com/">Roee Hay</a>
162<br>(<a href="https://twitter.com/roeehay">@roeehay</a>,
163<a href="mailto:roeehay@gmail.com">roeehay@gmail.com</a>)</p>
164
165<p>Qualcomm Product Security Initiative</p>
166
167<p><a href="https://lacklustre.net/">Mike Ryan</a> of
168<a href="https://isecpartners.com/">iSEC Partners</a>
169<br>(<a href="https://twitter.com/mpeg4codec">@mpeg4codec</a>,
170<a href="mailto:mikeryan@isecpartners.com">mikeryan@isecpartners.com
171</a>)</p>
172
173<p><a href="http://cryptoonline.com/">Muhammad Naveed</a>
174of <a href="http://illinois.edu/">University of Illinois
175at Urbana-Champaign</a>
176<br>(<a href="mailto:naveed2@illinois.edu">naveed2@illinois.edu</a>)</p>
177
178<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
179Trusted Systems Research Group</a>, US National Security Agency
180<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
181<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
182title="This person contributed code that improved Android security"></a></p>
183
184<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
185Trusted Systems Research Group</a>, US National Security Agency
186<a href=
187"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
188<img style="vertical-align:middle" src="images/tiny-robot.png"
189alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
190
191
192</div>
193<h2>2012</h2>
194
195<div style="LINE-HEIGHT:25px;">
196
197<p>Robert Craig of <a href="http://www.nsa.gov/research/ia_research/">
198Trusted Systems Research Group</a>, US National Security Agency
199<a href="https://android-review.googlesource.com/#/q/owner:%22Robert+Craig+%253Crpcraig%2540tycho.ncsc.mil%253E%22+status:merged">
200<img style="vertical-align:middle" src="images/tiny-robot.png" alt="Patch Symbol"
201title="This person contributed code that improved Android security"></a></p>
202
203<p>Stephen Smalley of <a href="http://www.nsa.gov/research/ia_research/">
204Trusted Systems Research Group</a>, US National Security Agency
205<a href=
206"https://android-review.googlesource.com/#/q/owner:%22Stephen+Smalley+%253Csds%2540tycho.nsa.gov%253E%22+status:merged">
207<img style="vertical-align:middle" src="images/tiny-robot.png"
208alt="Patch Symbol" title="This person contributed code that improved Android security"></a></p>
209
210<p><a href="http://thejh.net/">Jann Horn</a></p>
211
212</div>
213
Natalie Silvanovichf9118652014-06-19 10:24:16 -0700214<br>
Natalie Silvanovichb80378c2014-07-21 18:17:20 -0700215<p><small>If you have reported a vulnerability prior to 2014 and want to be
216included on this list, or to report a vulnerability in Android, contact <a href="mailto:security@android.com">security@android.com</a></small></p>