Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2026 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Androids Biggest Weakness

June 15, 2011 By Michael Kavka Leave a Comment

I have an Android phone, and I enjoy it. I don’t care for the iPhone. That being said, Apple has one huge advantage over Android.

The Android Smartphones are popular. The work well (for the most part), and are reliable (again for the most part). The open development community for apps has produced some great free applications, that you would have to pay for on iOS. There is a drawback to Android though, and it is something that by all rights should be more of a strength.

When you look into the world and history of Operating Systems, you see a bloody trail over security. Which OS is more secure, which one addresses security problems the fastest, etc. The Open Source community has always claimed that because more people can look at the code, patches can come out faster, and in the Desktop arena this definitely seems to be true. In the world of Smart Phones though, this “advantage” is lost.

The problem is not directly Android or Google, or the Open Source community. The problem is in Manufacturers, and even more so on the carriers. There is a process for patches and updates. Google writes an update, tests, sends to the manufacturer who tests, approves and then sends to the carrier. Android is so customizable, and on so many different manufacturer’s phones that this process has to happen for each model, each customized OS, and each carrier.

Now we are getting into a situation with this long protracted system of updates. Holes being found in the systems are there for months, possibly years before a patch gets pushed out. In this age of phone upgrades every 18 months, of more mobile applications for smart phones, more people banking and shopping off smart phones, and the upcoming Near Field Communications, updates for security need to happen a lot faster. The risk of more and more identity theft is growing, and the slowness of the pipeline is maddening.

Now add on that every manufacturer has been customizing the Android OS to try and differentiate itself from the others. How many more security issues can this raise. How many of the mods are creating security holes (we won’t go into other issues these mods cause)?

Yes, Apple has to go through the same sort of pipeline, but Apple has only piece of hardware (with different chips for GSM or CDMA) and just the carriers to deal with. Its a much shorter pipeline, and Apple can cut a carrier off from future iPhone releases if it wants to. Android needs to come up with something similar soon, especially with all the malware that has been coming out for the platform already.

Filed Under: Linux, Mobile Computing, Security Tagged With: Android, iOS, Mobile Comupting, OS, Patches, Security, Smart Phones, Smartphones

RSS Taggart Institute Intel Feed

  • Chinese cyberspies breach Singapore's four largest telcos February 9, 2026 Bill Toulas
  • Fallout from latest Ivanti zero-days spreads to nearly 100 victims February 9, 2026 Matt Kapko
  • Someone's attacking SolarWinds WHD to steal high‑privilege credentials - but we don't know who or how February 9, 2026 Jessica Lyons
  • Discord to require video selfies or government IDs to verify all users’ ages February 9, 2026
  • Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks February 9, 2026 Bill Toulas
  • The Screen Time Panic Sets Parents Up to Fail February 9, 2026 Emanuel Maiberg
  • Hackers breach SmarterTools network using flaw in its own software February 9, 2026 Bill Toulas
  • Senegal confirms breach of national ID card department after ransomware claims February 9, 2026
  • GCP-2026-007 February 9, 2026 Google Cloud Documentation
  • Singapore Says China-Linked Threat Actors Targeted Telecom Sector February 9, 2026 Decipher

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP