10.06.2013 Views

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Study</strong> <strong>into</strong> <strong>the</strong> implications <strong>of</strong> <strong>Smartphone</strong> operating system security<br />

levels <strong>of</strong> assurance in <strong>the</strong> majority <strong>of</strong> <strong>the</strong> un<strong>of</strong>ficial app stores and file sharing websites that<br />

Android users can go to acquire mobile apps.<br />

There is no doubt that this weakens <strong>the</strong> Android security model and it is currently <strong>the</strong> single<br />

biggest reason why malware is able to infect Android <strong>Smartphone</strong>s.<br />

Should Sideloading be stopped?<br />

If sideloading apps pose a serious security risk to Android <strong>Smartphone</strong> users than why is it<br />

still allowed.<br />

There have been calls from <strong>the</strong> security industry to block sideloading and by default UK<br />

MNOs will turn-<strong>of</strong>f <strong>the</strong> sideloading option in Android <strong>Smartphone</strong>s that <strong>the</strong>y ship.<br />

The European Network and Information <strong>Security</strong> Agency (ENISA) in a report 111 published in<br />

2011 recommends that “<strong>the</strong> <strong>Smartphone</strong> should ei<strong>the</strong>r be blocked from using untrusted app<br />

stores or, for expert users, present clear warnings about installing from untrusted sources”.<br />

However, <strong>the</strong>re may consequences to <strong>the</strong> Android ecosystem that may affect its openness if<br />

Google was to decide to remove <strong>the</strong> sideloading option from <strong>the</strong> operating system in future<br />

releases. Electronic commerce retailers such as Amazon are reliant on sideloading support<br />

to allow its Android-powered Kindle smart devices to download apps from Amazon’s own<br />

curated app store.<br />

111 Appstore security – 5 lines <strong>of</strong> defence against malware, ENISA, 12 September 2011:<br />

http://www.enisa.europa.eu/activities/Resilience-and-CIIP/critical-applications/smartphone-security-<br />

1/appstore-security-5-lines-<strong>of</strong>-defence-against-malware<br />

Goode Intelligence © 2013 P a g e | 125 www.goodeintelligence.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!