Facebook has open-sourced a static analysis tool that its software and security engineers use internally to identify potentially dangerous security and privacy flaws in Android and Java.

See also: Android malware has stolen money from 10 million users!
This security-focused tool is called Mariana Trench (MT). It can analyze large databases of tens of millions of lines of code to identify vulnerabilities before they are introduced into the codebase.
Facebook revealed that its engineers found over 50% of all security flaws in the apps , using automated tools similar to Mariana Trench.
Mariana Trench works by analyzing the flow of information from “sources” (sensitive user data, such as passwords or locations) to “sinks” (operations or methods that use data coming from sources).
Mariana Trench is specifically designed to automatically discover such issues, which, in most cases, could lead to serious privacy and security errors.
Developers and engineers can use the tool to focus on specific security and privacy issues by customizing and training it, adding new rules and creation models, so that it accommodates areas with sensitive data.
See also: Facebook: Puts brakes on plans to develop Instagram for children

The company previously released two other static code analysis tools designed to detect and prevent security issues for Python code (Pysa) and Hack code (Zoncolan).
You can find the Mariana Trench code analysis tool on GitHub and its own dedicated website, a binary distribution on PyPI, and a short tutorial to get you started.
"We built MT to focus specifically on Android apps. There are differences in patching and ensuring patch adoption between mobile and web apps, so they require different approaches," said Dominik Gabi, Software Engineer at Facebook.
«While server-side code can be updated almost instantly for web apps, mitigating a security flaw in an Android app depends on each user updating the app on their device in a timely manner.»
See also: Android users without access to Google Maps, YouTube and Gmail from today
«This makes it that much more important for any app developer to install systems that prevent vulnerabilities before they become available for mobile, whenever possible.»
