Apple unveils Mac OS X 10.8 Mountain Lion coming this summer

  • Inside OS X 10.8 Mountain Lion: Enhanced Printing & Scanning

  • Apple's 'iPad 3' rumored to have Siri, dual-core A5X chip, 1080p camera

  • Apple's North Carolina solar, fuel cell plants will be largest of their kind

  • AI readers get lowest prices ANYWHERE on MacBooks plus Free 2-Day shipping: Mac Price Guide updated Feb. 22nd. (Find the best prices on Macs)
    Monday, December 5, 2011

    Serious security flaws discovered in Android phones, Samsung and HTC ignore issue

    By Daniel Eran Dilger

    Published: 08:00 PM EST (05:00 PM PST)


    The ease and ability of Android licensees to modify the software they install on their smartphones has opened vast security holes that enable rogue apps to record calls, monitor users' locations and access sensitive data without permission, researchers say, noting that while Google and Motorola acknowledge the issues, HTC and Samsung have ignored their findings.

    Researchers from North Carolina State University have demonstrated that Android's permission-based security system can be easily circumvented due to flaws in the software that licensees add to their devices, according to security testing performed on popular HTC, Samsung, Motorola and Google-branded smartphones.

    "Android provides a permission-based security model that requires each application to explicitly request permissions before it can be installed to run," the researchers note in the paper (PDF) "Systematic Detection of Capability Leaks in Stock Android Smartphones," which will be presented at this year's Network and Distributed System Security Symposium.

    "In this paper, we analyze eight popular Android smartphones and discover that the stock phone images do not properly enforce the permission model. Several privileged permissions are unsafely exposed to other applications which do not need to request them for the actual use."

    Google's Android security model erased by its own openness

    The researcher's tests on 8 popular Android smartphones (HTC Legend/EVO 4G/Wildfire S, Motorola Droid/Droid X, Samsung Epic 4G, and Google Nexus One/Nexus S) resulted in security breaches in 11 out of 13 privileged permissions, with up to 8 security failures found on a specific model (the HTC EVO 4G).

    "By exploiting these leaked capabilities," the paper notes, "an untrusted app on these affected phones can manage to wipe out the user data on the phones, send out SMS messages (e.g., to premium numbers), record user conversation, or obtain user geolocations – all without asking for any permission."

    This summer, Symantec issued a report highlighting the problem that Google's Android permission system "relies upon the user to make the important security decisions," but the security firm did not publish any findings indicating that Google's permission system simply did not work as advertised on popular Android smartphones.

    Apple's App Store curation vs Google's permission model

    The new research paper contrasts app security models by Apple and Google, noting that "Apple uses a vetting process through which each third-party app must be scrutinized before it will be made available in the app store. After installing an app, Apple’s iOS platform will prompt the user to approve the use of some functions at run-time, upon their first access.

    "From another perspective, Google defines a permission-based security model in Android by requiring each app to explicitly request permissions up-front to access personal information and phone features. The requested permissions essentially define the capability the user may grant to an Android app.

    "In other words, they allow a user to gauge the app’s capability and determine whether or not to install the app in the first place. Due to the central role of the permission-based model in running Android apps, it is critical that this model is properly enforced in existing Android smartphones."

    Android's permission model has already resulted in a plague of malware, as there is no active curation in Google's Android Market that prevents rogue or malicious developers from posting apps that request inappropriate levels of permissions, in hopes that naive users will install their software without paying attention to complex permission details.

    But proponents of Android claim that astute users can safeguard themselves simply by being vigilant about what apps they install, confident that the Android platform won't allow apps to go beyond the permissions they request. That turns out to not be the case, as the researchers have demonstrated that licensee-bundled software can bypass Android and enable rogue apps to wipe the phone, place unauthorized calls or messages, and spy on their location or access supposedly secure data.

    The bigger the problem, the greater the denial

    After finding serious security lapses in shipping Android phones, the researchers noted that "since April, 2011, we have been reporting the discovered capability leaks to the corresponding vendors," noting that "we experienced major difficulties with HTC and Samsung."

    "After identifying these capability leaks, we spent a considerable amount of time on reporting them to the corresponding vendors. As of this writing, Motorola and Google have confirmed the reported vulnerabilities in the affected phones. HTC and Samsung have been really slow in responding to, if not ignoring, our reports/inquiries."

    The report notes that "smartphones with more pre-loaded apps tend to be more likely to have explicit capability leaks. The reference implementations from Google (i.e., the Nexus One and Nexus S) are rather clean and free from capability leaks, with only a single minor explicit leak."

    It also added that "those smartphones with system images (i.e., the Motorola Droid) close to the reference Android design (i.e., the Nexus One and Nexus S) seem to be largely free of capability leaks, while some of the other flagship devices have several."

    With only Google and Motorola having acknowledged any of the problems, that leaves the most successful Android licensees, HTC and Samsung, not only ignoring the reported issues but also continuing to deliver products that are the least safe for users, in many cases without any provisions for updating phones that have already been sold.

    Filed under : iPhone 61 Comments ] 
    Story topics: Samsung, Google, HTC, Android, Security   Print ] [ Story Link ] 


    RSS
    RSS
    Mac Connection End of Summer Sale
    MacBook Pro Model
    Apple
    Price
    Discount
    2.4GHz dual 13" MacBook Pro $1,199.00 $1,095.12* $103.88
    2.8GHz dual 13" MacBook Pro $1,499.00 $1,382.19* $116.81
    2.2GHz quad 15" MacBook Pro $1,799.00 $1,658.63* $140.37
    2.4GHz quad 15" MacBook Pro $2,199.00 $1,983.61* $215.39
    2.4GHz quad 17" MacBook Pro $2,499.00 $2,274.61* $224.39
    Early 2011 MacBook Pro Model
    Apple
    Price
    Discount
    2.7GHz dual 13" MacBook Pro $1,499.00 $1,159.19* $339.81
    2.0GHz quad 15" MacBook Pro $1,799.00 $1,503.49* $295.51
    2.2GHz quad 15" MacBook Pro $2,199.00 $1,645.03* $553.97
    2.2GHz quad 17" MacBook Pro $2,499.00 $1,814.38* $684.62
    *Instant 3% AppleInsider Reader Discount Applied When Adding Items To Your Cart

    AppleInsider Features
    Hot Forum Topics

    Recent Articles
    Apple's first Amsterdam retail store set to open March 3
    Killer Deals: Save up to $680 off MacBook Pros and $79 off Mac minis
    New Beatles ringtones are exclusive to Apple's iTunes Store
    Microsoft joins Apple in FRAND patent fight against Motorola
    Apple tells court banning iPad sales would 'hurt China's national interest'
    Reports suggest Office for iPad is still coming, despite Microsoft's denial
    Factory workers claim Foxconn hid underage employees before FLA inspection
    'Nightline' report on Apple production line shows iPhone is basically handmade
    Google reportedly prepping heads-up display Android eyeglasses for 2012 launch
    Apple confirms plans for 'green' data center in Oregon
    Inside OS X 10.8 Mountain Lion: Enhanced Printing & Scanning
    Safari user sues Google over claimed privacy violation
    Qualcomm releases new Gobi universal mobile chips with LTE support
    Apple's Mac sales solid ahead of "possible MacBook Air refresh" as early as March
    With China Telecom iPhone deal final, Apple turns attention to China Mobile
    Apple extends Mac App Store sandboxing restriction deadline to June 1
    Apple launches iTunes in the Cloud service in Japan
    Microsoft Office for iPad said to arrive soon, Microsoft calls claims 'inaccurate'
    'iPad 3' rumored to launch in Germany on March 23
    Apple's 'iPad 3' rumored to have Siri, dual-core A5X chip, 1080p camera
    Apple to allow independent environmental audits of its supply chain
    Suppliers gearing up for Apple's launch of new MacBook Air models
    Proview ready to negotiate on eve of Shanghai court hearing
    Apple opening up supplier factories to third-party environmental inspections
    Apple's iPhone 4S climbs to 29% smartphone market share in UK
    China Telecom to offer fully-subsidized iPhone 4S starting March 9
    Microsoft to challenge iCloud with SkyDrive OS X client
    Apple threatens Proview with defamation countersuit
    Amazon gearing up to launch 10-inch Kindle Fire in Q2 2012 - report
    Apple's North Carolina solar, fuel cell plants will be largest of their kind
    Apple's sixth-gen iPhone expected to debut in September or October of 2012
    Chinese iPad trademark suit seen as chance for Samsung, Lenovo to gain on Apple
    ABC offers glimpse at 'Nightline' special 'iFactory: Inside Apple'
    Samsung officially spinning off struggling LCD business in April
    Lower Chinese court rules to halt iPad sales
    Samsung reportedly tapping Chinese supplier to produce 'iPad 3' displays
    'A5X' CPU featured on purported Apple 'iPad 3' logic board
    Alleged 'iPad 3' photos showcase larger camera, tapered case
    Apple issues statement on iPhone 4 'antenna-gate' lawsuit settlement
    Mountain Lion focuses on Cocoa, drops X11 and deprecates Carbon Core








    AppleInsider RSS Feed
    AppleInsider © 1997-2011
    Please review our Privacy Policy.
    Written/Edited/Compiled by the AppleInsider Staff.