Security in the Android ecosystem is awful. There’s just no other word to describe it.
In large part, the blame for that can be placed at the feet of Google. Although they have succeeded in creating a wildly successful platform, their management of OEM devices (in particular, security updates for them) have been virtually nonexistent.
This has led to a situation where many device manufacturers don’t bother to push critical updates at all. It costs money to do so, and until now, there hasn’t been a downside for failing to. That, however, is about to change.
Recently, Google announced some big changes coming to their OEM agreements that would require Android device manufacturers to roll out security updates on a regular basis.
The company offered few details when the announcement was made, but since that time, an unverified copy of the new contract was leaked and obtained by The Verge. It sheds some additional light on what’s coming.
Specifically, the new agreement requires OEMs to regularly schedule updates for any device launched after January 31, 2018 if that device has been activated by more than 100,000 users. OEMs will be required to provide security updates for a minimum of two years.
In addition to that, they must make updates that address security vulnerabilities available to their customers no more than 90 days after the patch is released. Taken together these two pieces of information point to the fact that OEMs will be required to issue quarterly updates to their customers, at a minimum.
It’s a good move and one that’s long overdue. When this new agreement becomes official corporate policy, it will have an almost immediate, profound impact on security in the Android ecosystem. While it’s far from a perfect solution, it represents a very good beginning.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
By now, almost everyone has heard of the Spectre and Meltdown security flaws that have been making headlines for more than a year. They’re serious flaws with dire implications for tens of millions of users around the world who have an intel-based PC.
Windows 10 is far and away the fastest growing version of the OS in the company’s history. It recently hit an installation base of a staggering 700 million devices after about three years on the market.
Google is making a small but pivotal change as it relates to calls placed to 911 operators. Having recently finalized a complex partnership with RapidSOS and West (two emergency technology companies) and T-Mobile, Google will now send location data from its “Emergency Location Service” when an Android user places a 911 call.
Google has recently made some changes and improvements to its G-Suite. It introduces new tools designed to allow managers and admins greater visibility into how the people in their organizations use the G-Suite.
Microsoft has been making two major Windows 10 releases every year, giving businesses 18 months before they need to move to the next update. This plan and schedule is part of the company’s “Windows as a service” paradigm, designed to ensure that Windows 10 gets new features, as opposed to the company’s former practice of a new Windows release every three years.
In 2016, an unnamed US energy company left some 30,000 records (containing information about its security assets) exposed for more than two months (a total of 70 days), in violation of energy sector cyber security regulations. When the incident was initially reported, the name of the company was withheld.
It’s official, Apple now has company in the Trillion Dollar Club as Amazon’s stock surged past $2,000, briefly pushing the company’s total value to just over the trillion-dollar mark.
Earlier this year, Microsoft announced that it had entered into a partnership with Open Whisper Systems, the makers of the Signal app. The purpose of the partnership was to bring Signal’s open source, end-to-end encryption protocol to Skype.
File this one away under “unintended consequences.” There’s a newly emerging trend in the medical community called “Snapchat Dysmorphia” that’s leaving plastic surgeons around the country to sound the alarm, and in some cases, scratch their heads in disbelief.