Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Android Security: Google or Carriers issue?

Posted on January 16, 2015 By Michael Kavka No Comments on Android Security: Google or Carriers issue?

In the world of Android a couple of disturbing articles have come out recently. Google is no long patching 4.3 (Jellybean) and earlier versions. Also the amount of malware for Android increased by 75% last year. This begs, who is to receive blame on the vendor side?

We all know people do not patch apps. Maybe they don’t like “new” terms that come with the update (most terms are the same as the prior versions). A lot get not the best information. Patching is important, and we all know that. In the world of PC’s we all know about Patch Tuesday (Microsoft, Adobe), and know how long it can take Apple to patch flaws in OSX and iOS (which they completely control and is out of the carriers hands). So what about Android, the worlds most popular phone OS?

The announcement this week that Google is no long patching WebView for versions 4.3 and earlier started me thinking more about this. Yes, Google is “abandoning” 930 Million users. Yes, They come out with new versions of Android so fast that the OS is fractured all over the place. The question is though, is Google doing the right thing? I personally think so. The reasoning why places a bunch of blame on the carriers.

Outside of iOS (iPhone), the carriers control when consumers get updates to their Android (and Windows) phones. In the world of Android, Google announces a patch, update, new version, then it gets sent to the device manufacturers. They have to test against their hardware and customization that they have done to Android for their devices (the look and feel of the OS you see). Then it gets sent to the carriers (Verizon, AT&T, Sprint, etc.) where even more testing has to be done against the carriers modifications to the OS (special built in apps, their radios, any network lock downs or features such as tracking cookies). Basically once Google releases the new version/patch/update getting it onto most peoples phones is out of their hands, the exception being the Nexus devices which Google controls. The longer an update take to get out there, the more chance there is for a breach. The easier it also may be for malware to get on the phones, and could be a reason the amount of malware for Android increased by 75% last year.

So the question arises, why does it take so long to hit our phones. the obvious and simple answer to me is money. Why bother pushing patches and updates, let alone new versions of the OS to phones especially ones that are only a year or two old, when you can try to force people to get new hardware, and either extend or get new contracts to get the latest? Security as a Service you can almost think of it as, but not quite. Seriously, the carriers have a cash cow on their hands with Android and doing things this way. The lastest verion of iOS is out and works on phones that are years old. Apple has it available for those older phones through their updater, although some features may not work on the older phones, it is still available. I am by no means an Apple fan, but the control they have over their updates is what Google needs to have over Android. The carriers don’t care, and won’t unless they lose some major lawsuit because someone’s phone got hacked due to a security update not having been available for that model. When I tweeted to my carrier (Verizon) about this, they sent me a link to their “news” page which has no information on updates. I also tweeted them back as they asked about what I was looking for (latest Windows Phone update, Android Lollipop) for specific devices. Never heard back from them.

The bottom line on this, from my perspective, is that both Google and the carriers are to blame. Google is to blame, not for not patching, but for not controlling the push out of patches and updates to the OS, and the carriers for not pushing out updates and patches in a timely fashion. Until this gets resolved, Android is going to stay heavily fragmented, and security for everyday peoples phones is going to be shaky at best.

General Tags:Android, AT&T, Google, Security, Sprint, T-Mobile, Verizon

Post navigation

Previous Post: Can Infosec get ahead of the Blackhats?
Next Post: Thotcon 0x6 has come and gone

Related Posts

  • New Year, New Post, from the start General
  • Ransomware, Are You Ready? General
  • The One About Chained Exploits and Pentest Results General
  • Passing the Cert – SANS Notes and thoughts General
  • Random Stream of Thoughts General
  • Year End Musings General

More Related Articles

New Year, New Post, from the start General
Ransomware, Are You Ready? General
The One About Chained Exploits and Pentest Results General
Passing the Cert – SANS Notes and thoughts General
Random Stream of Thoughts General
Year End Musings General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk August 27, 2026
  • Linux Foundation Backs New TRACE AI Security Standard  August 26, 2026 Lindsey O'Donnell-Welch
  • LACMA data breach last year exposed social security and medical data August 25, 2026 Bill Toulas
  • Hackers abuse npm mirrors to host phishing redirect pages August 25, 2026 Lawrence Abrams
  • The GTA VI leaks are breaking the internet. Security researchers have seen this before. August 25, 2026 Matt Kapko
  • 58 arrested in international cybercrime crackdown August 25, 2026
  • AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes August 25, 2026 Bill Toulas
  • CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool August 25, 2026 aws@amazon.com
  • Employee benefits platform Paylogix says hackers stole financial and health data August 25, 2026
  • Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice August 25, 2026 Tim Starks
  • Socket for Asana Is Now Available August 25, 2026 Jeppe Hasseriis
  • Water sector passes, government sector fails attempts to spot and halt simulated CISA attack August 25, 2026 Tim Starks

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk August 27, 2026
  • Linux Foundation Backs New TRACE AI Security Standard  August 26, 2026 Lindsey O'Donnell-Welch
  • LACMA data breach last year exposed social security and medical data August 25, 2026 Bill Toulas
  • Hackers abuse npm mirrors to host phishing redirect pages August 25, 2026 Lawrence Abrams
  • The GTA VI leaks are breaking the internet. Security researchers have seen this before. August 25, 2026 Matt Kapko
  • 58 arrested in international cybercrime crackdown August 25, 2026
  • AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes August 25, 2026 Bill Toulas
  • CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool August 25, 2026 aws@amazon.com
  • Employee benefits platform Paylogix says hackers stole financial and health data August 25, 2026
  • Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice August 25, 2026 Tim Starks
  • Socket for Asana Is Now Available August 25, 2026 Jeppe Hasseriis
  • Water sector passes, government sector fails attempts to spot and halt simulated CISA attack August 25, 2026 Tim Starks
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.