Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Android Security: Google or Carriers issue?

Posted on January 16, 2015 By Michael Kavka No Comments on Android Security: Google or Carriers issue?

In the world of Android a couple of disturbing articles have come out recently. Google is no long patching 4.3 (Jellybean) and earlier versions. Also the amount of malware for Android increased by 75% last year. This begs, who is to receive blame on the vendor side?

We all know people do not patch apps. Maybe they don’t like “new” terms that come with the update (most terms are the same as the prior versions). A lot get not the best information. Patching is important, and we all know that. In the world of PC’s we all know about Patch Tuesday (Microsoft, Adobe), and know how long it can take Apple to patch flaws in OSX and iOS (which they completely control and is out of the carriers hands). So what about Android, the worlds most popular phone OS?

The announcement this week that Google is no long patching WebView for versions 4.3 and earlier started me thinking more about this. Yes, Google is “abandoning” 930 Million users. Yes, They come out with new versions of Android so fast that the OS is fractured all over the place. The question is though, is Google doing the right thing? I personally think so. The reasoning why places a bunch of blame on the carriers.

Outside of iOS (iPhone), the carriers control when consumers get updates to their Android (and Windows) phones. In the world of Android, Google announces a patch, update, new version, then it gets sent to the device manufacturers. They have to test against their hardware and customization that they have done to Android for their devices (the look and feel of the OS you see). Then it gets sent to the carriers (Verizon, AT&T, Sprint, etc.) where even more testing has to be done against the carriers modifications to the OS (special built in apps, their radios, any network lock downs or features such as tracking cookies). Basically once Google releases the new version/patch/update getting it onto most peoples phones is out of their hands, the exception being the Nexus devices which Google controls. The longer an update take to get out there, the more chance there is for a breach. The easier it also may be for malware to get on the phones, and could be a reason the amount of malware for Android increased by 75% last year.

So the question arises, why does it take so long to hit our phones. the obvious and simple answer to me is money. Why bother pushing patches and updates, let alone new versions of the OS to phones especially ones that are only a year or two old, when you can try to force people to get new hardware, and either extend or get new contracts to get the latest? Security as a Service you can almost think of it as, but not quite. Seriously, the carriers have a cash cow on their hands with Android and doing things this way. The lastest verion of iOS is out and works on phones that are years old. Apple has it available for those older phones through their updater, although some features may not work on the older phones, it is still available. I am by no means an Apple fan, but the control they have over their updates is what Google needs to have over Android. The carriers don’t care, and won’t unless they lose some major lawsuit because someone’s phone got hacked due to a security update not having been available for that model. When I tweeted to my carrier (Verizon) about this, they sent me a link to their “news” page which has no information on updates. I also tweeted them back as they asked about what I was looking for (latest Windows Phone update, Android Lollipop) for specific devices. Never heard back from them.

The bottom line on this, from my perspective, is that both Google and the carriers are to blame. Google is to blame, not for not patching, but for not controlling the push out of patches and updates to the OS, and the carriers for not pushing out updates and patches in a timely fashion. Until this gets resolved, Android is going to stay heavily fragmented, and security for everyday peoples phones is going to be shaky at best.

General Tags:Android, AT&T, Google, Security, Sprint, T-Mobile, Verizon

Post navigation

Previous Post: Can Infosec get ahead of the Blackhats?
Next Post: Thotcon 0x6 has come and gone

Related Posts

  • New Year, New Post, from the start General
  • Ransomware, Are You Ready? General
  • The One About Chained Exploits and Pentest Results General
  • Passing the Cert – SANS Notes and thoughts General
  • Random Stream of Thoughts General
  • Year End Musings General

More Related Articles

New Year, New Post, from the start General
Ransomware, Are You Ready? General
The One About Chained Exploits and Pentest Results General
Passing the Cert – SANS Notes and thoughts General
Random Stream of Thoughts General
Year End Musings General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Japanese media group Nikkei discloses cyberattack targeting journalistic sources October 5, 2026
  • Alleged dev of Ploutus ATM malware appears in US court after arrest October 5, 2026 Sergiu Gatlan
  • Cybersecurity incident affects local server at Indiana Area School District in Pennsylvania October 5, 2026 DysruptionHub Staff
  • ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure October 5, 2026
  • SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors October 5, 2026
  • Filling the Well: Nightmare-Eclipse's BigDiskBuster and the Defender Update That Never Lands October 5, 2026 Serhii Melnyk and Timmy Lister
  • Data breach at Denmark’s national population register exposes 8.8 million people October 5, 2026
  • Malicious Crypto Shell Packages Target RubyGems October 5, 2026 c0a15726-c5b1-4b0d-85e6-fe15553df9e2
  • OpenAI will show visual ads in ChatGPT while you generate images October 5, 2026 Mayank Parmar
  • The US needs a real plan to defend its water systems October 5, 2026 Greg Otto
  • Microsoft: Windows KB5124010 update crashes some games and apps October 5, 2026 Sergiu Gatlan
  • Google halts open-source bug bounty program amid AI spam surge October 5, 2026 Sergiu Gatlan

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Japanese media group Nikkei discloses cyberattack targeting journalistic sources October 5, 2026
  • Alleged dev of Ploutus ATM malware appears in US court after arrest October 5, 2026 Sergiu Gatlan
  • Cybersecurity incident affects local server at Indiana Area School District in Pennsylvania October 5, 2026 DysruptionHub Staff
  • ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure October 5, 2026
  • SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors October 5, 2026
  • Filling the Well: Nightmare-Eclipse's BigDiskBuster and the Defender Update That Never Lands October 5, 2026 Serhii Melnyk and Timmy Lister
  • Data breach at Denmark’s national population register exposes 8.8 million people October 5, 2026
  • Malicious Crypto Shell Packages Target RubyGems October 5, 2026 c0a15726-c5b1-4b0d-85e6-fe15553df9e2
  • OpenAI will show visual ads in ChatGPT while you generate images October 5, 2026 Mayank Parmar
  • The US needs a real plan to defend its water systems October 5, 2026 Greg Otto
  • Microsoft: Windows KB5124010 update crashes some games and apps October 5, 2026 Sergiu Gatlan
  • Google halts open-source bug bounty program amid AI spam surge October 5, 2026 Sergiu Gatlan
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.