Possibly most of you have iPhones, but you have friends that are unaware of how 
dangerous their Androids are, this should be forwarded to them.

John








Android folks you REALLY need to read this...it's vital.  This one is one of 
the most prolific ever released AND YOU DON'T HAVE A CLUE...and the fix is 
doubtful....Android is a dangerous system, read below that 99% of Malware is 
directed toward Android.  

Major Flaw In Android Phones Would Let Hackers In With Just A Text

JULY 27, 2015 6:01 AM ET


Android is the most popular mobile operating system on Earth: About 80 percent 
<https://www.idc.com/prodserv/smartphone-os-market-share.jsp> of smartphones 
run on it.

And, according to mobile security experts at the firm Zimperium 
<https://www.zimperium.com/company>, there's a gaping hole in the software — 
one that would let hackers break into someone's phone and take over, just by 
knowing the phone's number.

Just A Text

In this attack, the target would not need to goof up — open an attachment or 
download a file that's corrupt. The malicious code would take over instantly, 
the moment you receive a text message.

"This happens even before the sound that you've received a message has even 
occurred," says Joshua Drake, security researcher with Zimperium and co-author 
of Android Hacker's Handbook 
<http://www.amazon.com/Android-Hackers-Handbook-Joshua-Drake/dp/111860864X>. 
"That's what makes it so dangerous. [It] could be absolutely silent. You may 
not even see anything."

Here's how the attack would work: The bad guy creates a short video, hides the 
malware inside it and texts it to your number. As soon as it's received by the 
phone, Drake says, "it does its initial processing, which triggers the 
vulnerability."


Once the attackers get in, Drake says, they'd be able do anything — copy data, 
delete it, take over your microphone and camera to monitor your every word and 
move. "It's really up to their imagination what they do once they get in," he 
says.

There's A Solution, In Theory

According to Zimperium, this set of vulnerabilities affects just about every 
active Android phone in use. 

In correspondence in April and May, he shared his findings with Google, which 
makes the Android operating system. He even sent along patches to fix the bugs.

When you look at how long it'll take his Nexus, my Samsung Galaxy and your LG 
or ZTE to get those patches. Drake says that as few as 20 percent will get 
fixed, though the figure may be higher than that, "potentially up to the 
optimistic number of 50 percent."

Android Partnerships Are Complicated

Just half of affected smartphones is not a very optimistic estimate. And Google 
agrees with it.

Whether it gets put into people's phones is not in Google's hands.

Android phones are very different from iPhones, for example. Apple runs a 
closed system: It controls the hardware and software, and it's fairly easy to 
ship out a major revamp. The company says 85 percent of iPhone users have the 
latest operating system, iOS 8.

According to security firm F-Secure, 99 percent 
<http://www.digitaltrends.com/mobile/android-malware-threat-rears-head-time-means-business/>
 of mobile malware threats in the first quarter of 2014 were designed to run on 
Android devices.

Google gives its latest version of Android to manufacturers, and they then 
tweak it as they please. Carriers like Verizon and T-Mobile do more tweaking. 
The blog Android Central has described the challenge of updating the operating 
system as an "impossible problem 
<http://www.androidcentral.com/solving-impossible-problem-android-updates>." 
Earlier this year, a hole discovered in the Android Web-browsing app 
<http://www.androidcentral.com/android-webview-security> was left largely 
unpatched too.

Often, Mulliner says, manufacturers don't have a financial incentive to fix 
phones already sold.

"If you can save money by not producing updates, you're not going to do that," 
he says. "Since the market is moving that fast, it sometimes doesn't make sense 
for the manufacturer to provide an update."



_______________________________________________
MacGroup mailing list
[email protected]
http://www.math.louisville.edu/mailman/listinfo/macgroup

Reply via email to