HaVe a NiCe dAy

Saturday 9 March 2013

Android the largest security risk: OS fragmentation


Until recently bought your phone or tablet is, odds are higher that your Android-device operating system is running an older version, expose you to serious security risks are.

The latest figures from Google indicate that the Android users 44% "gingerbread," or versions 2.3.3 through 2.3.7, which was released two
years ago is now. Gingerbread security vulnerabilities have been fixed in later versions have a number of. OS error data download Play Google Android 22 February to 4 March collect data from connected devices are based.

Download only 16 percent of Android devices running version 4.1 or 4.2, and Google's mobile operating system, according to. The "Jelly Bean" latest six months before the Android version was released, but the Android OS to the majority of users unable to upgrade because the process is tightly controlled by carriers That is known.

"Download problem with Android is that most people have older versions on their phone,", North Eastern University in Boston, a post-doctoral researcher with SECLAB, Collin Mulliner the RSA Conference last month Mobile security during a panel discussion.

Our SecurityWatch Summit last fall, Dean Guido, CEO and co-founder of Trail of bits is described in the majority of iOS devices within weeks, not days, Apple's new operating system updates are released 's.

Mobile carrier updates are on
"The most important things in software security today is the ability to update an era," Mulliner said panel. The consumer phones and iPads, the Android operating system update for the mobile carriers can start the Android devices to control the entire process. At this time, the push updates to users record the mass is quite disappointing.

The problem is that the Android operating system's open platform device manufacturers and carriers to bundle additional software or special configuration settings to tweak that allows fixed. When Google has released an operating system update, both retailers and carriers rolling out the latest version of his homebrew system changes that require testing. Carriers claim this is a slow process, but many security experts believe that carriers are preferred security benefits.

Some phones only update the Android update because they do not have or are being phased out older models, Chris Soghoian, a privacy researcher and activist in his early years in a different function.'s. example, an LG Android-smart phone for the first 16 months did not receive OS updates, and many phones that never get updated first, alone together.



A drive-by attack, where a malicious user only has to visit the site of the contract, the biggest Android-users face threat, Charlie Miller, iOS and the Android security of their work famous researcher, is in the same panel at the RSA Conference.

Miller said, "People that drive by a big risk, but not in real life". Download the latest version of Android security patches and exploit mitigations is better.

Cyber ​​criminals know users are running vulnerable operating system. All criminals malicious app the Android continues to exploit a vulnerability in older versions, and an important part of user hit the ground.

As before Soghoian said "You do not need a zero day most free software if users with Android devices running attack at the age of 13 months."

Unfortunately, the security situation seriously until carriers, or Google update process started wrests control away from carriers is unlikely to change. Safest site around 4 Android device from Google's smartphone Nexus is, as the company has complete control over updates.

No comments:

Post a Comment

Related Posts Plugin for WordPress, Blogger...