|
|
Log in / Subscribe / Register

The Android Security 2015 Annual Report

Google has announced the availability of the Android security 2015 year in review [PDF]. "Android’s open source model has also allowed device manufacturers to introduce new security capabilities. Samsung KNOX, for example, has taken advantage of unique hardware capabilities to strengthen the root of trust on Samsung devices. Samsung has also introduced new kernel monitoring capabilities on their Android devices. Samsung is not unique in their contributions to the Android ecosystem. Blackberry has worked to enhance the security of their devices by enabling kernel hardening and other features in the Blackberry PRIV. CopperheadOS has both introduced security improvements to their own version of Android and made significant contributions to the Android Open Source Project. These are just some of the various contributions made possible through open sourcing that improved the Android ecosystem in 2015."

to post comments

The Android Security 2015 Annual Report

Posted Apr 19, 2016 19:48 UTC (Tue) by dany (guest, #18902) [Link] (24 responses)

Anybody see a problem?

Samsung has also introduced new kernel monitoring capabilities on THEIR Android devices..
Blackberry has worked to enhance the security of THEIR devices...
CopperheadOS has both introduced security improvements to THEIR own version...

Unless google takes these patches and include them in baseline android, its just another thing to increase android fragmentation.. And you wonder, why are you still on some obscure version of android. I would argue, that if devices are sold and are under warranty, they all should have lastest version of android, or at least latest security patches.

The Android Security 2015 Annual Report

Posted Apr 19, 2016 19:58 UTC (Tue) by gioele (subscriber, #61675) [Link] (4 responses)

> Anybody see a problem?
>
> Samsung has also introduced new kernel monitoring capabilities on THEIR Android devices..
> Blackberry has worked to enhance the security of THEIR devices...
> CopperheadOS has both introduced security improvements to THEIR own version...

I see another problem:

Samsung has also introduced new **CLOSED and UNREVIEWED** kernel monitoring capabilities on THEIR Android devices..

I suppose that, just like antiviruses, these additions carry their own set of vulnerabilities.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 5:24 UTC (Wed) by aryonoco (guest, #55563) [Link] (3 responses)

KNOX is not closed. It was open sourced and contributed to AOSP by Samsung. It was a big tarball of a patch, but Google has been nibbling at it and has been rolling in some features into AOSP proper.

Android might not be as open and transparent as we would like, but the whole situation is also not as depressing as some LWN readers think.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 7:06 UTC (Wed) by liam (guest, #84133) [Link] (1 responses)

I'm not sure that he's referring to knox.
Samsung KNOX, for example, has taken advantage of unique hardware capabilities to strengthen the root of trust on Samsung devices. Samsung has also introduced new kernel monitoring capabilities on their Android devices.
Page 6 of the Annual Report.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 11:40 UTC (Wed) by spender (guest, #23067) [Link]

Don't worry, Samsung's changes are merely to prevent cookie cutter post-kernel exploitation payloads. It's pretty obvious to me how it can be avoided/defeated, and I'm sure others will figure it out soon as well. Give it a few months and it'll have a net 0 effect; that's how all these weak mitigations work.

-Brad

The Android Security 2015 Annual Report

Posted Apr 20, 2016 17:15 UTC (Wed) by Del- (guest, #72641) [Link]

>the whole situation is also not as depressing as some LWN readers think.

What do you mean by that? Strawman?

The Android Security 2015 Annual Report

Posted Apr 20, 2016 6:18 UTC (Wed) by douglascodes (guest, #105468) [Link] (15 responses)

Agreed. These new security solutions do not help devices which lag behind updates 6 months or more. They represent security as marketing and do not improve the condition of millions of devices currently in the hands of users.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 6:48 UTC (Wed) by roblucid (guest, #48964) [Link] (14 responses)

Exactly.. I just have decided to pass on all smart-phones, because I don't trust embedded device vendors to maintain their OS with updates.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 8:27 UTC (Wed) by patrick_g (subscriber, #44470) [Link] (9 responses)

Even Nexus models? They are directly maintained by Google.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 10:55 UTC (Wed) by nye (guest, #51576) [Link] (8 responses)

I would say *especially* Nexus models, because they are directly maintained by Google.

Any Google products should always be used under the assumption that it will cease to exist tomorrow. This is a company whose name is synonymous with abandoning things at a moment's notice in favour of some other shiny thing the second somebody gets bored.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 11:50 UTC (Wed) by pizza (subscriber, #46) [Link] (5 responses)

> I would say *especially* Nexus models, because they are directly maintained by Google.

Wow, talk about confirmation bias.

You're taking many years of evidence showing that the Nexus models have been the best supported Android devices, bar none, and just ignoring that.

Nexus devices are the ones receiving major OS updates at launch time. They're the overwhelming majority of the models fully supported out of the box by the AOSP, and consequently the ones best supported by 3rd-party ROMs (eg cyanogen). They also have none of the crap/shovelware that carriers (and other manufacturers) are still foisting on us.

But no, feel free to chose a (usually) more expensive and (often) technically inferior alternative that has worse manufacturer support -- at launch time, at mid-life, and at EOL, because you don't like that some people knowingly purchased a device that was entirely reliant on ongoing benevolence of a third-party service that had no way of making money.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 13:38 UTC (Wed) by nye (guest, #51576) [Link] (3 responses)

>You're taking many years of evidence showing that the Nexus models have been the best supported Android devices, bar none, and just ignoring that.

I'm taking many years of evidence showing that Google will drop anything they don't consider fun or fashionable, and paying great attention to it. You surely can't dispute that this is their MO as a company?

>But no, feel free to chose a (usually) more expensive and (often) technically inferior alternative

Technically inferior to the Nexus devices? They are usually fairly cost-effective, being upper-mid tier devices at lower-mid tier prices, but they're made with minuscule margins using any opportunities to cut costs. As a result, they typically have numerous, often well-publicised flaws as a result[0] - and this is if you exclude deliberate anti-features such as the exclusion of removable storage.

[0] For example, the Nexus 7, which is the only Nexus device I ever actually bought myself, and therefore the only one I have personal experience of. It used bottom-tier flash that caused the devices to start having major I/O problems by the time the new device smell had faded. This was partially mitigated by the addition of discard support some time later, so long as you don't use more than about half of the available space. It's unsupported now, of course.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 14:20 UTC (Wed) by pizza (subscriber, #46) [Link] (1 responses)

> I'm taking many years of evidence showing that Google will drop anything they don't consider fun or fashionable, and paying great attention to it. You surely can't dispute that this is their MO as a company?

That's *every* company's MO, in case you haven't noticed. (Especially when acquisitions are concerned..)

But more specifically, are you seriously stating that Android is something that Google may drop due to it no longer being fun or fashionable?

I own a three-year-old Nexus 10. It was released with Android 4.2, but saw official 4.3, 4.4, 5.0, and 5.1 updates over the two years it was being sold by Google. It won't get an official 6.0 update, but Google is still releasing monthly security updates for its 5.1 load.

Meanwhile, because Google had the audacity to follow the terms of the GPL and released their complete kernel sources, (along with their userspace stuff, even though they weren't required to), it was one of the first platforms that Cyanogen supported with their 6.0 loads.

Even if Google were to completely cease any future Android development, or halt the Nexus program, or finally abandon the N10, device owners can still support ourselves without having to resort to reverse-engineering.

And yes, this is a huge technical advantage in my book.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 15:56 UTC (Wed) by nye (guest, #51576) [Link]

>That's *every* company's MO, in case you haven't noticed. (Especially when acquisitions are concerned..)

I think Google are *particularly* bad in the attention span department though, and not just regarding acquisitions.

>But more specifically, are you seriously stating that Android is something that Google may drop due to it no longer being fun or fashionable?

I doubt Android will be going away any time soon, but any given device, sure. There are some cases where specific promises have been made for security support for a given amount of time, which is a good start, but on its own that doesn't get you very far. My experience with the N7 has been pretty miserable. After about 6 months they were working entirely on the new model and clearly didn't do much testing, with the result that every OTA update since then has failed and required flashing with the stock ROM manually - if you're lucky it will simply refuse to work; if you're less lucky the device will end up stuck in a boot loop and require Special Tactics to fix. I mean, I'm a fairly hardcore nerd, and maintaining a working Nexus 7 has been a bit too much for me to deal with, so it's been non-functional for months at a time more than once.

>Even if Google were to completely cease any future Android development, or halt the Nexus program, or finally abandon the N10, >device owners can still support ourselves without having to resort to reverse-engineering.
>And yes, this is a huge technical advantage in my book.

In an abstract sense, sure. In a practical sense, a distinction that's only relevant for, at best, a tenth of a percent of the audience is pretty much moot.

The Android Security 2015 Annual Report

Posted Apr 22, 2016 7:47 UTC (Fri) by marcH (subscriber, #57642) [Link]

> > You're taking many years of evidence showing that the Nexus models have been the best supported Android devices, bar none, and just ignoring that.

> I'm taking many years of evidence showing that Google will drop anything they don't consider fun or fashionable, and paying great attention to it. You surely can't dispute that this is their MO as a company?

How do you know that all the projects still kept alive are considered fun or fashionable? I bet even most Googlers don't know that.

Have you never worked in any big company and seen behind the One Voice/One MO Grand Illusion?

The Android Security 2015 Annual Report

Posted Apr 20, 2016 15:13 UTC (Wed) by mathstuf (subscriber, #69389) [Link]

Google has made their home screen and voice app such that you can't disable them in 6.0, so there is some crapware I'd like to disable but can't.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 12:48 UTC (Wed) by ledow (guest, #11753) [Link] (1 responses)

You think Samsung don't abandon models at the drop of a hat and then never update them, nor help people get off the default Samsung firmware?

I have a Galaxy Ace that last received updates... YEARS ago. And neither Google nor anyone else are going to step in and maintain that for me.

The Android Security 2015 Annual Report

Posted Apr 22, 2016 7:53 UTC (Fri) by marcH (subscriber, #57642) [Link]

I had an Ace 2. It worked perfectly fine until the... first and last major Samsung update which featured a memory leak. Widely reported and never fixed.
It will never be supported by Cyanogen or any first tier mod (at least) because of the licensing gaps, confusion and mess; especially around firmware blobs.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 10:06 UTC (Wed) by nhippi (subscriber, #34640) [Link] (3 responses)

Featurephones have no better security. The platforms are just too obscure to be bothered by hackers. And unless you are specifically targeted, security via obscurity is not that bad strategy (it's awfully quiet at my http server listening in a non-standard port).

The Android Security 2015 Annual Report

Posted Apr 23, 2016 4:03 UTC (Sat) by marcH (subscriber, #57642) [Link] (2 responses)

I had a similar experience with a small and private ssh server which I moved to a non-standard port after getting tired of log spam. The spam went instantly down to zero.

It should get even better with IPv6 which has an address space too large to brute-scan. As long as a server isn't advertised in DNS or anywhere else it will likely stay very quiet even on standard ports. Anyone experienced that yet?

The Android Security 2015 Annual Report

Posted Apr 23, 2016 5:36 UTC (Sat) by magila (guest, #49627) [Link]

I haven't noticed any spam on my ssh server over IPv6 even though it is at an address which has a public domain pointing at it. I'm pretty sure it's just a matter of time until the script kiddies get updated scripts to attack over IPv6. Even then, using a sub-domain that you don't make public will probably keep you safe.

The Android Security 2015 Annual Report

Posted Apr 25, 2016 20:45 UTC (Mon) by flussence (guest, #85566) [Link]

I've had the same effect by dropping HTTP from my public-facing servers, leaving HTTPS only. Webapp worms and those brain-damaged web spiders that ignore robots.txt ratelimits, all vanished.

The downside to that is — last time I tested the waters, anyway — Let's Encrypt doesn't support anything other than plain HTTP verification.

The Android Security 2015 Annual Report

Posted Apr 20, 2016 14:49 UTC (Wed) by thestinger (guest, #91827) [Link] (2 responses)

> CopperheadOS has both introduced security improvements to THEIR own version...

It states right there that the Android Open Source Project is benefiting from CopperheadOS:

> CopperheadOS has both introduced security improvements to their own version of Android and made significant contributions to the Android Open Source Project.

CopperheadOS targets a different niche than Android. It can make performance, memory usage and compatibility sacrifices that are not going to be made in AOSP. That niche isn't going to go away. It's no different than the existence of distributions like Hardened Gentoo. Do you think Google is willing to make 5-30% performance sacrifices and 1-5% battery life sacrifices for security? No. And they're not going to be as willing to break misbehaving third party apps or in some cases even correct code that's depending on attack surface that removed. There are already developers complaining about the hidepid=2 feature that we helped to land upstream, and that's a much more clear cut case (i.e. a sane app sandbox should *clearly* not have this functionality) than most:

https://code.google.com/p/android/issues/detail?id=205565

It's only feasible to upstream a subset of the changes, and it takes a lot of work to do that. It takes effort that could otherwise go towards developing new features. If the goal was solely to make CopperheadOS better, then it probably wouldn't make sense to upstream anything despite the long-term reduction in the maintenance burden. The features suitable for upstreaming are usually the easiest to maintain...

The Android Security 2015 Annual Report

Posted Apr 24, 2016 7:37 UTC (Sun) by jospoortvliet (guest, #33164) [Link] (1 responses)

Don't underestimate that maintenance burden, Google might have thought the same when they made their first kernel patches many years ago - and then they learned they were wrong.

The Android Security 2015 Annual Report

Posted May 1, 2016 14:13 UTC (Sun) by thestinger (guest, #91827) [Link]

Google's kernel changes are straightforward and easy to maintain. It's not why Android devices stay on one kernel version.


Copyright © 2016, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds