Wireless Carriers Leave Millions of A... Chalanachithram.com | Topics | Search
Hide Clipart | Log Out | Register | Edit Profile

Last 30 mins | 1 | 2 | 4 hours     Last 1 | 7 Days

Chalanachithram.com DB » TF Industry related » Archive through February 11, 2013 » Wireless Carriers Leave Millions of And Phones Vulnerable « Previous Next »

Author Message
Top of pagePrevious messageNext messageBottom of page Link to this message

Gamingfan
Side Hero
Username: Gamingfan

Post Number: 8407
Registered: 08-2012
Posted From: 59.93.107.138

Rating: N/A
Votes: 0 (Vote!)

Posted on Monday, February 11, 2013 - 12:45 pm:   Insert Quote Edit PostDelete PostPrint Post   Move Post (Moderator/Admin Only)Ban Poster IP (Moderator/Admin only)

SAN JUAN, PUERTO RICO – There are millions of vulnerable Android phones in the hands of consumers today because wireless phone carriers and phone hardware makers refuse to transmit existing software security fixes to phones in a timely manner, according to a security researcher.

Unlike phones made by Apple, which has power over carriers and controls the distribution of software updates to its phones, Android users can’t get an update to their phones without the carrier’s intervention, notes Chris Soghoian principal technologist and senior policy analyst with the American Civil Liberties Union. “The phones have to contact a server run by the carrier in order to get an update.”

As a result, Android users are slave to the update schedule of wireless carriers or the hardware makers, who can take a year or longer to distribute new firmware updates containing fixes to phones.

“When Apple decides that it’s going to give a security update to consumers or a feature update, every consumer who plugs their phone into their computer gets the update whether or not their respective regional carrier likes it,” Soghoian said, speaking at the Kaspersky Security Analyst Summit.

But with Android, “you get updates when the carrier wants it and when the hardware manufacturer wants it, and usually that’s not very often.”

Research released by DuoSecurity last September found that half of sampled Android devices had unfixed vulnerabilities, even though there were patches from Google that were available for them. There are over 100 million Android devices deployed worldwide

Hardware makers are slow to provide fixes to vulnerabilities because it’s not cost-effective for them. When Google updates Android, engineers have to modify it for each phone or chip that relies on the operating system, which is time-intensive and takes away from the work engineers would rather spend developing new versions of the phone.

Although Google is quick to fix vulnerabilities in its software when it finds out about them, there is a dangerous lag in getting those fixes to Android users, he noted.

“This is not an instance where I’m criticizing Google for not fixing the bugs,” Soghoian said. “Google’s team will usually fix it very promptly and make it available to all of their hardware partners. The problem here is that fixes for critical security vulnerabilities are simply not getting downstream and reaching consumers.”

The carriers and hardware makers blame each other for the delays, but the bottom line is that consumers are left with outdated and vulnerable devices, Soghoian said.

“You don’t need [a zero-day exploit] to attack most Android devices if consumers are running 13-month old software,” Soghoian said.

Soghoian said that carriers either need to accept responsibility for the devices they’re selling or cede control of updates to Google.

But he said this is likely not to happen unless the government applies pressure.
Talent and intelligence are useless when not supplemented by mental strength!!

If you want a boy to love you for a lifetime, love his heart, not his money.If you want a girl to love you for a lifetime, love her soul, not her body.

Add Your Message Here
Post:
Bold text Italics Underline Create a hyperlink Insert a clipart image HASH(0x9f37224){Movie Clipart}
Show / hide regular icons selection options

Click on following links to open cliparts by Alphabetical Order

 A   B   C   D   E   F   G   H   I   J   K   L   M  

 N   O   P   Q   R   S   T   U   V   W   X   Y   Z  

Show / Hide Filmy icons selection options

Click on following links to open cliparts by Alphabetical Order

 A   B   C   D   E   F   G   H   I   J   K   L   M  

 N   O   P   Q   R   S   T   U   V   W   X   Y   Z  

Username: Posting Information:
This is a public posting area. Enter your username and password if you have an account. Otherwise, enter your full name as your username and leave the password blank. Your e-mail address is optional.
Password:
E-mail:
Options: Enable HTML code in message
Automatically activate URLs in message
Action: