Security in the Android ecosystem is awful. There’s just no other word to describe it.
In large part, the blame for that can be placed at the feet of Google. Although they have succeeded in creating a wildly successful platform, their management of OEM devices (in particular, security updates for them) have been virtually nonexistent.
This has led to a situation where many device manufacturers don’t bother to push critical updates at all. It costs money to do so, and until now, there hasn’t been a downside for failing to. That, however, is about to change.
Recently, Google announced some big changes coming to their OEM agreements that would require Android device manufacturers to roll out security updates on a regular basis.
The company offered few details when the announcement was made, but since that time, an unverified copy of the new contract was leaked and obtained by The Verge. It sheds some additional light on what’s coming.
Specifically, the new agreement requires OEMs to regularly schedule updates for any device launched after January 31, 2018 if that device has been activated by more than 100,000 users. OEMs will be required to provide security updates for a minimum of two years.
In addition to that, they must make updates that address security vulnerabilities available to their customers no more than 90 days after the patch is released. Taken together these two pieces of information point to the fact that OEMs will be required to issue quarterly updates to their customers, at a minimum.
It’s a good move and one that’s long overdue. When this new agreement becomes official corporate policy, it will have an almost immediate, profound impact on security in the Android ecosystem. While it’s far from a perfect solution, it represents a very good beginning.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
If you take a lot of photos with your Android device, you’re probably constantly on the lookout for a better way to organize them and access them. That’s exactly what the authors of the malicious app called “The Album, by Google Photos” are hoping for.
Google is taking additional steps to bolster user privacy and better secure the data of the company’s legions of Android device owners. The company recently announced a change to the Android Backup Service that will encrypt all user backup data stored on its cloud servers, such that even Google itself can’t read it.
This hasn’t been a great month for two of the titans of tech. Both Apple and Microsoft have been plagued with bug-riddled updates to their operating systems. In Apple’s case, their new iOS 12 had to be patched just three weeks after its release because of all the bugs the company’s burgeoning user base discovered almost immediately after updating.
Facebook got hit hard by a currently unknown group of hackers. If you recently found yourself inexplicably logged out of the social media site, Facebook did it in response to the breach.
Jose Rodriguez, a Spanish Apple enthusiast, has discovered a new security flaw to be aware of. He posted a Proof of Concept video showing the exploit in action.
Symantec’s most recent statistics have revealed a disturbing trend. Malware designed to compromise checkout pages is seeing a big spike in use, with the company reporting a staggering 248,000 attempts since August 13th of this year, with more than a third of them (36 percent) between September 13th through September 20th. As disturbing as those numbers are, that’s just the tip of the iceberg.
Windows 10 is far and away the fastest growing version of the OS in the company’s history. It recently hit an installation base of a staggering 700 million devices after about three years on the market.
Google is making a small but pivotal change as it relates to calls placed to 911 operators. Having recently finalized a complex partnership with RapidSOS and West (two emergency technology companies) and T-Mobile, Google will now send location data from its “Emergency Location Service” when an Android user places a 911 call.
A new piece of legislation is making its way through the halls of Congress that could standardize and streamline the data security and breach notification process for financial institutions. This is something that most people in the industry tout as an improvement over the current situation.