Researcher: Android may not need antivirus software
IDG News Service - Antivirus developer SMobile released software this week to protect users of the G1 Android phone, although one security analyst wondered if people really need it.
Even though Android, the software developed by Google Inc. and running on just one phone sold by T-Mobile USA Inc., is open source, it is unlikely to be more susceptible to malware than other, proprietary mobile operating systems, said Charlie Miller, principal analyst at Independent Security Evaluators LLC and the researcher who found the first Android vulnerability.
While a developer could write a harmful application and distribute it via the Android Market, Google has put up some roadblocks that would make it hard for malware to cause much harm, Miller said. "If you want to do anything dangerous like access personal contacts, you have to specifically say to the virtual machine 'these are things I'm going to have to do,' and the virtual machine will ask the user if that's OK," he said. Android applications run in a Java virtual machine on the phone.
For example, if a user downloads a Scrabble game containing malicious code that tries to gather information from his e-mail account, the phone will ask the user to approve the application's access to the e-mail account. In that case, the user should decline the download, realizing that a Scrabble game shouldn't need to read from an e-mail account, he said.
Just this week, however, hackers discovered a way to install applications natively on the phone instead of using the virtual machine. The capability could open doors to new security threats by letting applications access any phone function. Google said it has developed a fix for the bug and plans to push it out to users soon.
That is the second vulnerability to be discovered in as many weeks. The first, discovered by Miller, resulted from Google using outdated open-source code that didn't include an update already issued that closed the hole. But such vulnerabilities aren't unique to Android or open-source software. "The fact is, you could do that against the iPhone or against the BlackBerry or whatever. All these phones have issues," he said.
SMobile has argued that because Android is open source, it will attract more hackers who will be able to look for holes they can exploit to gather user data for malicious purposes.
While companies such as McAfee, Symantec and F-Secure make antivirus software for smart phones, although not yet for Android, only a few mobile viruses have appeared, and those haven't spread very far. That's partly because of the wide variety of operating systems that run mobile phones. A virus written for one operating system doesn't spread widely because it won't work on phones running different operating systems.
- Review: The T-Mobile G1 'Google phone' is a tweaker's delight
- Video: G1 buyers like 'open' Android software
- John Brandon: T-Mobile G1 -- a real Web 2.0 stunner
- Motorola prepares its Android phone
- The Android fine print: Kill switch and other tidbits
- G1 Android phone is only half 'open,' with T-Mobile lock-in
- Android about advertising, not the enterprise
- Android-Amazon music deal should worry Apple, analyst says
- FAQ: What T-Mobile's Android G1 phone will do for you
- John Brandon: T-Mobile G1 with Google Android is Smartphone 2.0
- Seth Weintraub: Ten areas where Android could make waves vs. iPhone
- Single-Vendor Security Ecosystems Offer Concrete Benefits Over Point Solutions IT security decision-makers from companies with 100 to 5,000 employees evaluates the current endpoint security solution market based on Forrester's own market data,...
- Case Study: Intuit Turns to Self-Service IT Intuit empowered its users to resolve their own IT issues with a consumer-like experience to free IT to focus on more strategic initiatives....
- Automation for a Better Tomorrow Check out the five most common annoyances facing enterprise IT service desks today, and how automation can resolve all of them. Download the...
- Beyond the Enterprise App Store Leverage proactive, secure and automated IT Service delivery to move beyond the traditional App Store and empower your users. Read the white paper...
- Business-driven data protection Setting up data protection infrastructures with your organizations' core mission or business in mind is key. In this webinar, the ARCserve team will...
- On-Demand Webinar: Mind the Gap! Watch the webinar featuring Bob Janssen, CTO and Co-Founder of RES Software, to start building a solid foundation for business and IT to... All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!