Monday, March 3, 2014

RSAC: Google's Android Security Guru Says They're Winning the War

Image via Flickr user JD Hancock


At the RSA Conference, Google's Lead Engineer for Android Security Adrian Ludwig presented the company's philosophy for securing their mobile platform. It's a typically Google approach that relies on collecting data and building services. But at the same time it seems to fly in the face of conventional mobile security. 
Invisible Security
Several times during the talk, Ludwig returned to the idea of subtle security. "Effective and invisible security evokes calm," he said. The goal was to let the user interact with their phone, tablet, or whatever was running Android without security issues getting in their way. "Not trumpeting security doesn't mean it's not there," said Ludwig. "It means it's working."
This approach is markedly different from that of the security industry as a whole, he said, which relies heavily on "security theater." To him, this means apps that loudly proclaim how much they're protecting you. "Most security is ultimately about selling you more security," said Ludwig in a surprisingly frank statement at a conference that caters to security companies.
Permissions were the notable exception. "It's the one place that we're explicit about security to the user," he said. These define what an app can and cannot access, and we have encouraged readers to look at them carefully to make good decisions about what they download. Ludwig said that wasn't really the intention. "Did we think people were going to make smart decisions every time? Remember, we see what people search for everyday," he added wryly. He went on to say that permissions are there not so much for users, but to help developers make good decisions "most of the time."
This fit with another of Ludwig's surprising statements: that he doesn't see Android as an operating system, but rather a development platform. "[Android] was a set of APIs intended to create powerful applications," he said. "We deliver services in the form of applications."
What Google ProvidesWhile Ludwig spent some time discussing how the underpinnings of Android made the platform secure—including thanking the NSA for SC Linux—he also touched on more visible Google services. For example, he claimed that Google's malware detection efforts on Google Play surpass that of the entire AV industry. Though he acknowledged that it wasn't infallible.
In addition to another obvious tool like the Android Device Manager, Ludwig pointed to Google's Verified Apps service, which provides some protection for users who install apps from outside the Play store. "You probably have it on your phone and don't know it, because that's how we roll," said Ludwig.
There's also the Android Safety Net, which Ludwig said extended real-time protection to devices themselves. This looks for potential abuses, like frequently requesting to send premium SMS messages—a common tactic used to monetize malicious apps.
"I'd have to guess that this is the largest deployment of security services in the world," said Ludwig. 
Diversity and Openness is GoodAndroid is known as an open platform, and Ludwig said that this approach has provided invaluable data about good actors, bad actors, and normal behavior on mobile devices. "As the world becomes more interactive and there's more data flowing back and forth, security actually gets better." Ludwig believes that this greatly differs from established security strategies, which he said depend upon isolation.
Openness has meant a fragmented Android, but Ludwig seemed to suggest that this diversity was a good thing. The enormous diversity of Android hardware and software means that it is much more difficult to affect all devices. "A single gold master with a bug affects hundreds of million of users," he said. "There is no single gold master [for Android], every device is built from source that differs."
Being open has also given security companies a place on Android. "We didn't prevent them from running on our platform," he said, no doubt making a jab at Apple. Instead, Ludwig said Google welcomed security companies in and Android benefited from their work.
Openness also facilitates academic research in the growing field of mobile security. "Mobile security is a euphemism for Android security," said Ludwig. "All of the papers are about Android security because it's the only place [researchers] have access in mobile."
Is It Working?
To demonstrate the effectiveness of Google's approach to security, Ludwig ran through a timeline of the Masterkey exploit, which careful SecurityWatch readers will recall from last summer. He said Google was able to quickly determine that there were no such exploits in the Play store when they were informed it existed. What's more, after the Bluebox researchers who discovered the exploit publicly released their data, Google apparently tracked only eight attempts per million installs.
Ludwig had a similar view on Android malware as a whole, which has been widely reported to be on the rise. He attributed this more to the rapid proliferation of Android devices, and the data he presented showed a relatively small instance of malware on the enormous universe of Androids. "You get incredible headlines with basically no one being affected."
It has to be said that, so far, Google has done a terrific job of managing Android security—especially considering how smartphones burst onto the scene and came to dominate modern computing. However, there are still serious issues to be addressed going forward, like leaky apps and securing personal data.
From Google's perspective, Android has balanced security with grace. Keeping that balance will probably be how Android is judged as it matures. 

Friday, February 28, 2014

Amazon gifting Android, Kindle app credit to its Appstore users this week

Amazon gifting Android, Kindle app credit to its Appstore users this week

Amazon made a whole lot of money this Christmas, but it's not being a Scrooge by hoarding all of its riches. Instead, it's giving back to users of the Amazon Appstore this week.
The retailers announced that from now until December 28, users who download anything from its app store will be rewarded with $5 credit (about £3.06, AU$5.60) toward a future app purchase.

Download BlueStacks 0.8.4.3036 Beta for Windows
We confirmed that this deal for Android and Kindle device users applies to customers worldwide by logging into Amazon.com and making any app purchase there.

"For our international customers, they can get the $5 credit if they download an app from the Amazon Appstore via Amazon.com," a company spokesperson told TechRadar today.
Free apps for the holidays

In addition to running this four-day promotion, the online retailer is highlighting its "free app of the day" section that benefits both Android and Kindle owners.
Angry Birds Star Wars II and Doodle Farm are among the popular apps that don't cost any money for 24 hours one day this week. And, yes these are the full, paid version of the games.
It's good timing since these free apps fulfill the requirement to earn that promotion credit, as long as it's done before December 29.
Not a bad deal. You get a free app and credit toward another paid app in the future. Amazon gets to remind you that its Google Play store alternative still exists.

Thursday, February 27, 2014

[New App] ViaProtect Gives A Basic Look At Where Android Apps Are Sending Your Data

No one app is going to make an Android device immediately safe from any and all threats, but some can make it easier to remain ever vigilant. viaProtect may one day be such a app. This piece of software gives you a basic idea where the apps installed on your phone or tablet are sending your information. It doesn't go into specifics, but it will at least show you how much of your traffic is encrypted and some other security-related information.

viaProtect1

viaProtect2 viaProtect5

viaProtect3 viaProtect4

Wednesday, February 26, 2014

CHROME READER APP FOR ANDROID

chrome reader


If you’re a Chrome user and an Android lover at the same time (these two things are going together almost by default), today I have some great news for you,  because the Chrome Reader App for Android is here!
While the voice controlled  ”virtual assistant” thing is hardly breaking news since Google Now/Siri &comp, this new app from Technology Discovery will be adored by those of you who are spending lots of time online, reading blogs and articles, like yours truly.
Because, what this Android app does is making our online lives easier : basically, the Chrome reader will allow you to put your eyes to rest while it will read for you, in a relaxing feminine voice, the online content you require.
All you have to do is visit Google Play Store, download and install the app on your droid and get things going. Using the application is fairly easy for both “newbies” and advanced users. Even if you’re not a techie, installing and enjoying the Chrome reader will present no significant problem.
After installation,the app will require you to open the Chrome browser, press Enable, select and copy the text you need to be read out loud and the app will do the rest, it’s that easy folks!
chrome reader
After you press enable, you go back to your Chrome browser, you select the text you want to be read for you and that’s it. Easy as pie. If you want the app to stop reading, all you have to do is shake the device, the voice will stop on your command!
The interface is nicely designed in a minimalist manner; there are only four buttons for controlling the app (Enable, Disable,Troubleshooting and Exit) and using it is intuitive enough for my grandmother.
 This app is very useful if you have to learn something and you’re too lazy to keep your eyes peeled on your screen (or you’re too tired, either way); using the Chrome reader feels like attending a class in which you have full control over your teacher. Also, this app is great if you’re into eBook reading, it works like a charm at night, when you’re going to bed and trying to fall asleep while listening to the first chapter of, let’s say, Lord of the Rings. I know, I am old school, I love reading books in the age of Android games. I am no fun.
For the Chrome reader to work correctly, it requires your droid  to run on Android 4.0 and up. Enjoy!
chrome reader

Tuesday, February 25, 2014

How to Keep Your Android Apps From Lagging

If Instagram on Android is being slow, try clearing out its cached data.


If you’ve noticed that Instagram on your Android handset has been unusually sluggish lately, you’re not alone. Many of us have noted an unfortunate combination of slower feed load times and an uptick in overall bugginess. Quitting and restarting occasionally fixes the problem, but there’s a far easier way to deal with a misbehaving app.
Just go into Settings > Apps, and then clear the cache. Voila, the app should be back to 100 percent.
Of course this doesn’t just apply to Instagram. Clearing cached data for any Android app should be your first course of action when problems arise. This will wipe out the temporary files that may be responsible for the trouble, and it can also have the added benefit of saving space on your handset.
If overall performance on your phone is slowing, there’s even a way to clear all cached app data at once on Android 4.2 and up. Go to Settings > Storage > Cached Data. This will give you the option to erase all your app’s saved data. It’s not something you’ll want to do regularly — in many cases, you’ll have to login to your apps again, and some may even load slower for a time — but as a once-a-year routine, it certainly can’t hurt. Think of it as clearing out the cobwebs in the back corners of your handset’s storage spaces.

Monday, February 24, 2014

Opera’s new Android app helps you get more out of your mobile Internet plan

opera logo


The Norwegian company, which is strongest in emerging markets due to its focus on compressing browser data with Opera Mini, has branched out into compressing data across apps,  as it officially launched a free data-savings app for Android smartphone users today. This shift is key because people typically consume data by accessing apps nowadays, not by surfing within browsers.
The app, Opera Max, extends the life of your data plan by up to 50 percent, the company says. This means that if you pay $40 a month for a 1GB data plan, using Opera Max lets you consume up to 1.5GB per month for the same cost. Opera notes that “if you have a pre-paid data plan, pay per megabyte of use, or are roaming internationally, this app adds even more value.”
In particular, Opera Max compresses videos across your Android device, which the company claims has never been done before. As videos tend to use a lot of data, compressing them means you get more out of apps including YouTubeInstagram and Vine.
In the Opera Max app, you get to see a timeline of your apps usage and how much you saved on data by month or by day — listed individually, as well as in total.

Opera Max Operas new Android app helps you get more out of your mobile Internet plan
How Opera Max works: Once the app has been downloaded, it immediately starts compressing and rerouting data via a VPN to the data-savings cloud. All non-encrypted data requests are then sent through Opera’s compression servers, which optimize video, images and websites to use less data.
“As ‘kings of compression,’ we think Opera Max is the next step in the evolution of this technology, which will intelligently compress data across apps, not just your browser,” Sergey Lossev, the head of product at Opera Max, says.
From today, the Opera Max beta will be available to Android users in the US and Europe who already pre-registered for it. The app will be launched gradually in other regions worldwide.

Friday, February 21, 2014

Report finds iOS apps riskier than Android apps

shutterstock 128343053
How many apps do you have on your smartphone or tablet right now? Well, take that number, and multiply it by 0.9. That’s about how many of your apps are a potential security concern according to a new study from Appthority.
The Appthority Reputation Report for Winter 2014 was compiled using data from the cloud-based Appthority App Risk Management Service. Appthority performed static, dynamic, and behavioral app analysis of 400 paid and free apps spanning iOS and Android to assess the relative security and risky behavior of the most popular apps.
Appthority found that 95 percent of the top 200 free apps on iOS and Android exhibit at least one risky behavior. That number drops to 80 percent for paid apps—an improvement, but four out of five paid apps exhibiting risky behavior is hardly something to cheer about. Appthority also discovered that iOS apps are riskier overall than Android apps—91 percent contain risky behavior as opposed to 83 percent on Android.
They risky behaviors vary, but include things like location tracking—found in 70 percent of the free iOS and Android apps—weak authentication, sharing data with ad networks, accessing the contact list, or identifying the user or UDID.
There are a couple significant caveats to the idea of iOS being a greater risk. First, Android apps have a much higher presence of accessing the UDID or identifying the user. Apple took steps to prevent developers from accessing UDID information on iOS mobile devices—but some developers have found ways to circumvent those rules.
The other thing that separates Android from iOS is that, although there are more iOS apps that exhibit risky behavior, the Android apps tend to collect more information about the user and the user’s mobile activities than their iOS counterparts.
To sum up, a higher percentage of iOS apps include risky behaviors than Android apps, and paid apps are generally less risky than free apps.
The differences in many cases are small and semantic, though. The fact that iOS has a higher percentage than Android may offer some small consolation to Android users, but the fact that nearly all of the apps on both major mobile platforms exhibit at least one risky behavior should be a red flag for both app developers and mobile device users—as well as for Apple and Google themselves.
The real lesson to be found in this report is that app developers recognize the financial value of gathering user data, and that mobile apps in general have a long way to go in terms of security and respecting a user’s privacy.