Download the
Tom's Guide App from the AppsStore
News and trends on internet
/ mobile / "sound & picture" / IT
Yes No

Researchers Find That Not All Androids Are Equally Secure

- By - Source : NCSU

Researchers at North Carolina State University (NCSU) have published a paper which details differences in Android security across eight models.

According to the findings, only three phones "properly" enforced Android's permission-based security model.

The conclusion is that Google's Nexus One and Nexus S phones with baseline Android configurations as well as the Motorola Droid "were basically clean." However, pre-installed applications added by manufacturers and carriers add a substantial risk of successful malicious attack to phones, Xuxian Jiang, an assistant professor of computer science at NCSUand co-author of a paper describing the research, said.

HTC’s Legend, EVO 4G and Wildfire S, Motorola’s Droid X and Samsung’s Epic 4G revealed "significant vulnerabilities." The EVO 4G was the most vulnerable phone with eight leaked permissions in the test. The Legend and the Wildfire had six leaks each, followed by the Wildfire and Droid X with four leaks each.

"Some of these pre-loaded applications, or features, are designed to make the smartphones more user-friendly, such as features that notify you of missed calls or text messages," said Jiang. “The problem is that these pre-loaded apps are built on top of the existing Android architecture in such a way as to create potential 'backdoors' that can be used to give third-parties direct access to personal information or other phone features."

The researchers said that they notified the software vendors of the discovered vulnerabilities prior to the release of the report and recommend that users should keep up with security updates from software vendors to protect themselves from attacks.

Share:
13
Comments
X

Comments

captaincharisma 11/30/2011 9:12 PM
Show
LuckyDucky7 11/30/2011 9:24 PM
Hide
-7+

Quote :“The problem is that these pre-loaded apps are built on top of the existing Android architecture in such a way as to create potential 'backdoors' that can be used to give third-parties direct access to personal information or other phone features."



So how about the rootkits that are pre-loaded, almost completely hidden, and sends third parties information about everything I do (i.e. CarrierIQ) on the phone?

Because while it's good to secure the apps on your device that's useless if your device has a program on it that is inherently extremely dangerous to your security at a lower level...

otacon72 11/30/2011 9:34 PM
Hide
-8+

captaincharisma :
just more negative propaganda coming from the folks from apple



Truth hurts. My company won't allow anything made by Apple or any Android device to connect to the network. Say what you want about RIM but they keep racking up security awards and certifications left and right.

Niva 11/30/2011 9:38 PM
Hide
-0+

Good article, I own a Samsung Galaxy S (original) and have been bitterly disappointed with the lack of updates to the OS and the preloaded applications. The extra skins and software loaded on top of the vanilla android are ok, but I prefer the defaults. If I ever buy another Android it will be Nexus line exclusively. My wife's Nexus One is awesome.

STravis 11/30/2011 9:46 PM
Hide
-2+

I'm shocked, I say, shocked that all the holes exist; no, not really. This is what happens when the code monkeys add features to differentiate the OS, yet, nobody takes the time to understand the impact of these 'features'

starryman 11/30/2011 10:48 PM
Hide
-1+

Duh! Android is full of security holes and that's intentional. Think about it... when you own a Android device you already have been hacked into. BUT I do love my Samsung Galaxy S2 with 2.3 Gingerbread.

NapoleonDK 12/01/2011 12:39 PM
Hide
-0+

In other words: Preloaded crapware is a security risk.

sinfulpotato 12/01/2011 3:02 AM
Hide
-1+

I always switch to a ROM anyways. No bloatware and most ROMs are as close to stock google android as you can get.

tanjo 12/01/2011 3:38 AM
Hide
-0+

Wow! Newsflash!
Remove all bloatware and download something more reliable.

eddieroolz 12/01/2011 7:49 AM
Hide
-0+

So this is just like with bloatware loaded onto Windows by OEMs; a lot of them really compromise your experience as well as security of the system.

everygamer 12/01/2011 3:58 PM
Hide
-0+

This is going to likely become moot with ICS, when ICS is released it does away with the vendor modifications and forces the Android phones to a more stock build for distribution.

tomsreview1 12/01/2011 4:49 PM
Hide
-0+

Quote :The Legend and the Wildfire had six leaks each, followed by the Wildfire and Droid X with four leaks each.


?? lol. But yeah, it's Android, so I can't say I'm surprised.

Hetneo 12/02/2011 3:01 AM
Hide
-0+

LuckyDucky7 :
So how about the rootkits that are pre-loaded, almost completely hidden, and sends third parties information about everything I do (i.e. CarrierIQ) on the phone?Because while it's good to secure the apps on your device that's useless if your device has a program on it that is inherently extremely dangerous to your security at a lower level...


Root it, wipe it out and install vanilla Android.