Fin24.com | Google, Samsung to issue monthly Android security fixes

1Las Vegas - Google and Samsung Electronics will release monthly security fixes for Android phones, a growing target for hackers, after the disclosure of a bug designed to attack the world's most popular mobile operating system.
2The change came after security researcher Joshua Drake unveiled what he called Stagefright, hacking software that allows attackers to send a special multimedia message to an Android phone and access sensitive content even if the message is unopened.
3"We've realised we need to move faster," Android security chief Adrian Ludwig said at this week's annual Black Hat security conference in Las Vegas.
4Previously, Google would develop a patch and distribute it to its own Nexus phones after the discovery of security flaws.
5But other manufacturers would wait until they wanted to update the software for different reasons before pushing out a fix, exposing most of the more than one billion Android users to potential hacks and scams until the fix.
6Ludwig also said Google has made other security changes.
7In an interview, he told Reuters that earlier this year the team broke out incidence rates of malicious software by language.
8The rate of Russian-language Androids with potentially harmful programs had spiked suddenly to about 9% in late 2014, he said.
9Google made its roughly weekly security scans of Russian phones more frequent and was able to reduce the problems to close to the global norm.
10Ludwig said improvements to recent versions of Android would limit an attack's effectiveness in more than nine out of 10 phones, but Drake said an attacker could keep trying until the gambit worked.
11Drake said he would release code for the attack by August 24, putting pressure on manufacturers to get their patches out before then.
12Nexus phones are being updated with protection this week and the vast majority of major Android handset makers are following suit, Ludwig said.
13Samsung Vice President Rick Segal acknowledged that his company could not force the telecommunications carriers that buy its devices in bulk to install the fixes and that some might do so only for higher-end users.
14"If it's your business customers, you'll push it," Segal said in an interview.
15Samsung is the largest maker of Android phones.
16Ludwig said many Android security scares were overblown.
17He added that only about one in 200 Android phones Google can peer into have any potentially harmful applications installed at any point.
18Drake noted that those figures exclude some products, including Fire products from Amazon, which use Android.
19As with Apple's iPhones, the biggest security risk comes with apps that are not downloaded from the official online stores of the two companies.
20Stolen files from Hacking Team, an Italian company selling eavesdropping tools to government agencies around the world, showed that a key avenue was to convince targets to download legitimate-seeming Android and iPhone apps from imposter websites.