I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic
I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic
Posted Jan 20, 2016 20:14 UTC (Wed) by david.a.wheeler (subscriber, #72896)Parent article: Dutch consumer group sues Samsung over Android updates (OSNews)
For example, statistics by Scanit’s Browser Security Test group found that 98% of time in 2004 Internet Explorer was vulnerable to dangerous known remote attacks, for which no patch to fix it was available, compared to 17% for Opera and 15% for Mozilla/Firefox. There were only 7 days in 2004 that Internet Explorer was safe from known yet unstoppable remote attacks. This is from "A Year Of Bugs" by scanIT’s Browser Security Test. Since not all vulnerabilities are equal, they only considered the especially dangerous “remote code execution” vulnerabilities, i.e., defects that allow a “malicious web page or e-mail message to execute arbitrary code or OS commands on the viewer’s computer.” They then compared the time from the “public announcement of the vulnerability to the time when the fix is available to the general user population.” For Internet Explorer, “there was only one period in 2004 when there were no publicly known remote code execution bugs - between the 12th and the 19th of October - 7 days in total.” Mozilla and the family (including Firefox, Netscape Navigator and the Camino browsers) has the shortest attack window of opportunity. There were 56 days (15%) in 2004 when there was a publicly known remote code execution vulnerability with no publicly-available patch, and about half of that 15% only applied to MacOS users.
Brian Krebs “Security Fix” column later compiled statistics on vulnerability response times, including those for Microsoft Internet Explorer (IE) and Mozilla Firefox. Security Fix that 78% (284/365) of the time in 2006 Internet Explorer was vulnerable to dangerous known attacks, for which no patch to fix it was available, compared to 2% (9/365) for Mozilla Firefox.
If people did that kind of calculation for Samsung Smartphones, as deployed on typical US carriers, I think they'd find that many phones are at or nearly 100% vulnerable. The problem isn't open source, it's the lack of real openness. For most people there's no practical way to upgrade the Android operating system to a current version.
Then people can buy smartphones based on a METRIC. E.G., if Samsung can't get its phones upgraded, sounds like a great reason to never buy one. Perhaps it's also time for a two-year minimum warranty for the US for consumers. It seems to be working in Europe.
