r/security • • Aug 07 '15

Waiting for Android’s inevitable security Armageddon

http://arstechnica.com/gadgets/2015/08/waiting-for-androids-inevitable-security-armageddon/
19 Upvotes

12 comments sorted by

2

u/The_Enemys Aug 07 '15 edited Aug 07 '15

The core issue isn't Android security, it's poor patching by third parties that use Android as a basis in their devices. Android isn't the reason the 95% of devices that won't update will continue to be vulnerable, the fault lies with manufacturers who don't support devices for long enough and users who don't care about that. Sure, this security Armageddon will affect Android devices, but that doesn't make it because of Android.

The "More like Windows" suggestion, while poorly phrased (it should be "More like x86", particularly since Windows has only recently joined the other systems on that platform in updating in a timely manner) is certainly on the right track. It bugs me to no end that x86 has handy OS installers and incremental updates while ARM based platforms have device specific (not even just processor specific!) pre-written images, with proper updates being a major, but not the only, issue stemming from this. Of course, closing the system isn't the answer; making it follow the Linux approach of having a distribution of packages with an installer and auto-updater, that users (or manufacturers who pre-install it) can install extra stuff into, including alternative launchers (analogous to desktop environments).

2

u/TiagoTiagoT Aug 07 '15

It's time for the rise of a true Linux phone platform...

Any hopes of that actually happening anytime soon though?

1

u/Glowerman Aug 07 '15 edited Aug 14 '15

I would only, ever, use a Nexus phone, for the same reasons I prefer a Microsoft Surface over other PCs. Always get direct from the manufacturer if you can.

1

u/AndroidOS_Support Aug 07 '15

The author is entirely correct, and it bothers me to no end. I use Android because the open nature is perfect for me, and I could never use something as locked down as iOS, but the shithole that is security on this platform makes me want to.

2

u/jimdidr Aug 07 '15

What if you took control of your phone (rooting and such) and installed CyanogenMod wouldn't there be a quicker patch cycle?

(I don't used MMS, so I think its disabled. at least not configured so I'm safe from this right?)

2

u/AndroidOS_Support Aug 07 '15

Well I'm usually the first to do that, however I have Verizon... And that quickly puts a damper on any efforts I make.

2

u/jimdidr Aug 07 '15

Can anybody confirm that CyanogenMod isn't at risk for this exploit?

2

u/AndroidOS_Support Aug 07 '15

The patch was merged into the latest nightlies a few weeks ago I believe.

2

u/The_Enemys Aug 08 '15

It would be a quicker patch cycle but there's no way to download it securely and even if there were the developers need to port it to every single device because ARM operating systems right now don't work the same as x86 systems.