Friday, August 29, 2014

Micromax Canvas 2 Colours Receiving Android 4.4.2 KitKat Update in India

micromax_canvas_2_colours_android_kitkat_update_official_facebook.jpg

Micromax on Friday announced the Android 4.4.2 KitKat update for its Canvas 2 Colours (A120) smartphone. The smartphone was launched in April with Android 4.2 Jelly Bean out-of-the-box.
The smartphone manufacturer made the announcement on its Facebook page, asking Canvas 2 Colours users to reboot their smartphone to get the KitKat update notification over Wi-Fi as recommendation. Micromax also posted the announcement again on Sunday with an image providing the changelog for the Android 4.4.2 KitKat update.
The over-the-air (OTA) Android 4.4.2 KitKat update for the Canvas 2 Colours is about 283MB in size and will include Music Album art on the lock screen along with an improved user interface.
The Micromax Canvas 2 Colours (A120) is a dual-SIM (GSM+GSM) device that comes with a 5-inch IPS display with a resolution of 720x1280 (HD) pixels. It is powered by a 1.3GHz quad-core MediaTek (MT6582) processor coupled with 1GB of RAM.
The Canvas 2 Colours features 4GB of inbuilt storage, which is further expandable via microSD card (up to 32GB). It sports an 8-megapixel autofocus rear camera with LED flash, while there is a 2-megapixel front-facing camera also onboard. On the connectivity front, the Canvas 2 Colours includes 3G, GPS, Wi-Fi, Micro-USB, and Bluetooth options.
Last week, Micromax had also rolled out the Android 4.4.2 KitKat update for the Canvas Doodle 3. The Android 4.4.2 KitKat update is sized around 387MB. The smartphone was launched in April this year with Android 4.2.2 Jelly Bean out-of-the-box.
The Canvas Doodle 3 features a 6-inch display and is powered by a 1.3GHz dual-core MediaTek (MT6572) processor alongside 512MB of RAM. It also includes a 5-megapixel autofocus rear camera; 0.3-megapixel front-facing camera; 4GB of built-in storage (expandable up to 32GB), and a 2500mAh battery.

Thursday, August 28, 2014

Google must make Android safer – our data is at risk




Over the past few months, the Android platform developed by Google and based on the Linux operating system has been having a difficult time. Hackers, with malicious intent and those without, have been investing time in finding out how weak this operating system is.
Android runs on more than four out of five mobile devices. It is popular because it is free and its terms do not dictate to device manufacturers what hardware it must be used on.
The hacking seen so far is partly a result of this popularity. But there also seem to be inherent problems, which experts and hackers have discovered don’t exist on other mobile platforms.

What are the issues?

Android is getting the most attention from malware creators, because it has more than 40,000 different malware compromises. This is worrying especially as the same systems for Windows and Apple phones seem to have only handful such issues (on non-jailbroken devices).
In June concerns arose about an SMS worm that could propagate via Android devices. One of the primary issues is the version control system these devices uses. As new and better versions of Android have been released, manufacturers having committed their development efforts to one version cannot always allow for upgrades. This is commonplace among the lower-priced devices, which tend to be fixed to a specific version of Android. Currently new devices are using the KitKat version of Android, but previous versions, such as JellyBean and IceCreamSandwich, remain in use.
In July researchers published their analysis of Android devices purchased on eBay. Even though these devices had had the information on them deleted, they could recover and analyse it. Naked Selfies among other confidential data were found, exposing a serious flaw in the encryption used by Android. The factory reset option, which should be able to permanently wipe any historical data from the device, seemed not to work well either. (This is the same issue, which was reported earlier in August, regarding the Tesco Hudl tablet, which uses Android as the operating system.)
Now researchers have found a flaw in the Gmail application on Android devices. The flaw makes it easy to create malware to obtain personal information, effectively using the email application as a route to extract all kinds of data from your phones. The researchers have claimed that this is also possible on iPhones and Windows phones. What they neglect to share is that Microsoft and Apple have app stores that undergo a range of stringent security checks before any app is allowed on their devices. This is unlike the Google Play environment, which is not the only source for apps on Android device.
There are many non-Google Android app stores – some legitimate but many not. Worse still, the security community has also exposed issues with the official Google Play store. We can trust almost all applications downloaded on Apple and Microsoft phones, but for any on the Android platform the risk is considerably higher. Unless you have up-to-date anti-malware software and are extremely cautious, chances are that your Android phone may eventually be compromised.

Should I be concerned?

Sadly, I think all Android users should be concerned. It is an excellent mobile operating system and has enabled low-cost smartphones and tablet computers to exist in the market place. But Google needs to tighten controls on how applications can enter this device as well as some of its underlying features.
Whenever I meet someone with an Android device, the first question I ask them is if they have any anti-malware installed. They often give me a quizzical look. The reality is that, if they don’t have such security apps installed, the data on their Android is not safe.

Wednesday, August 27, 2014

Nexus X leak confirms monster specs and new Android L details

Nexus X Android 5.0 L


Various reports have recently claimed that Google’s upcoming new Nexus device will not be called the Nexus 6 as expected, but instead will get a unique Nexus X moniker.TKTechNews, one of the sources of previous leaks, has returned with more information about the Motorola Nexus X, listing several AnTuTu benchmark screenshots for the handset, which seem to reveal an important new detail about Android L.
The screenshots mention several hardware details for the Nexus X that were rumored before, including a 2K display, 2.7GHz quad-core Qualcomm Snapdragon 805 processor, 3GB of RAM, 32GB of storage and 13-megapixel camera.
The images also identify the model as a Nexus X for Google, provide a 35,430 AnTuTu score for it, and list Android version as “5.0,” a detail Google is yet to confirm about Android L.
Considering the major changes coming with Android L – especially the new Material Design lines – Google is expected to move from Android 4.4.x (KitKat) to Android 5.0 (L), rather than make a small jump to Android 4.5. Assuming the images are genuine, this Nexus X benchmark seems to confirm what Google did not say on stage at Google I/O – that Android L will mark it’s move from Android 4.x (used since Ice Cream Sandwich) to Android 5.x.
A different report, extracting information from various sources, revealed that the “L” could stand for Lemon Meringue Pie.

Tuesday, August 26, 2014

Android App Causes National Weather Service Website Blackout

A single Android application has caused some real performance problems for the US National Weather Service  website over the past 24 hours. If you visited the site yesterday you may have received nothing, partial pages or missing forecast data. The NWS posted a message on their status page stating that an “abusing android app” was impacting their forecasts. Christopher Vaccaro, a spokesman for NWS added “We are actively working with the app developer to resolve an issue with their program which is making data requests from us too frequently”. Yes, you read that correctly. An Android application making frequent weather update requests has killed an important service, quite possibly accidentally (abusive implies malicious intent, but the frequency could just be wrong in the code). I personally suspect it was an accident as NWS did not release the name of the application and I can imagine a developer accidentally putting the update timer in milliseconds instead of seconds , or something equally silly. NWS later updated their status page to say that they have called in Akamai to add DDoS filters to block the offending traffic and resume service. The service is back up and running now, but let us briefly examine what happened and what lessons can be learned.

During this period weather warnings were not accessible and a significant number of the offices switched to distributing their updates via social media instead of the traditional automated channels. Luckily (surprise, surprise) social media sites understand Internet architecture and do pretty well at handling large volumes of traffic. On the other hand this is unfortunately not the first time that this has happened to the NWS. One of the previous communication challenges led to a failure to alert of an incoming tornado. What I find interesting about this situation is that a service that is a key part of critical weather warnings was brought down by an Android app. At a presentation 2 years ago I talked about how smartphones represented an interesting opportunity for cyber criminals as they were high bandwidth , constantly connected and received far less security scrutiny. In this case I am sure it is an accident, but the fact remains mobile phones caused a significant issue to the service.

There are a large number of ways in which weather warnings can be distributed (in severe cases mass general media including TV, Radio, Social Media or even emergency broadcast) but this service does seem to have an important central role. It begs the question why DDoS filters were not already in place (particularly as DDoS has had such a prominent position in the media over the last few years) or why a better structure of API keys (individual tokens that allow individual applications or services access so that they can be selectively revoked) was not used. More fundamentally, if this level of traffic caused a black out imagine what a very large number of people trying to hit the services in a genuine emergency would do . It sounds like the architecture (particularly caching and content delivery channels) needs to be overhauled and services to offices (and other key sites) separated from those used by Android applications. All in all it seems like NWS have more work to do than just calling in Akamai . Though at least for now you can get back to their site to find out whether you need an umbrella or not tomorrow.


If you run a website or online service which provides important (let alone critical) data you should be considering how you would handle such a scenario now, before it happens. Do you have an emergency response plan in the event technical mitigations fail?  Do you have a communications strategy (even reverting to social media, that was not a bad move by NWS)? Do you have the right network security to filter accidental or malicious attacks and most importantly do you have an architecture that can handle large volumes of traffic in the event that they occur? These are questions most of us should be asking ourselves. High visibility sites like the US National Weather Service even more so.

Update: Nik (@hvcco on Twitter) advised me of another example where a product manufacturer accidentally shipped with code that caused a significant denial of service. This example is rather old (and again shows we really should have learned our lessons by now) but is a nice description of the flaw. Most importantly this shows how bad code and accidents happen and malicious intent cannot always be assumed.

Monday, August 25, 2014

Gionee CTRL V4S with Android 4.4 KitKat Listed on Company Site

gionee_ctrl_v4s_screenshot_official_listing.jpg

Gionee seems all set to launch a new CTRL V-series smartphone in India, as the CTRL V4S has been listed on company's India website. Notably, no pricing or availability information was listed alongside.
According to the listing, the dual-SIM CTRL V4S runs Android 4.4 KitKat out-of-the-box and features a 4.5-inch FWVGA (480x854 pixels) IPS display.
The CTRL V4S is powered by a 1.3GHz quad-core Cortex-A7 processor coupled with an ARM Mali 400 GPU and 1GB of RAM. It comes with 8GB of inbuilt storage, which is further expandable via microSD (up to 32GB).
It sports an 8-megapixel rear camera with LED flash, while there is a secondary 2-megapixel front-facing camera also onboard. On the connectivity front, the Gionee CTRL V4S includes 3G, Wi-Fi, Micro-USB, GPRS/ EDGE, GPS/A-GPS, FM radio and Bluetooth 4.0 with A2DP.
The smartphone packs a 1800mAh battery, which according to the official listing, delivers up to 10 hours of talk time and up to 230 hours of standby time on 3G networks. The CTRL V4S measures 134.5x67.7x8.07mm and weighs 85 grams. It is listed to be available in Black and White colour options.
Notably, the Chinese smartphone-maker had launched the CTRL V4 last year in June. It came with a 4.5-inch FWVGA (480x854 pixels) display and was powered by a 1.2GHz Cortex A7 quad-core processor alongside 512MB RAM. It came with a 5-megapixel rear camera and 0.3-megapixel (VGA) front facing camera. The CTRL V4 had included 4GB of internal storage expanded by another 32GB via microSD card. It was powered by a similar 1,800mAh battery as now listed for CTRL V4S.
On Thursday, the company launched its Gpad G5 phablet in India, priced at Rs. 14,999. The phablet is powered by a 1.5GHz hexa-core Cortex-A7 processor and ARM Mali-450 MP GPU coupled with 1GB of RAM. The Gionee Gpad G5 comes with an 8-megapixel rear camera with LED flash, and a 2-megapixel front facing camera. It has 8GB of inbuilt storage with that can be expanded via microSD card (up to 32GB).

Friday, August 22, 2014

Spice Fire One, India’s first Firefox OS phone, challenges Android’s entry-level dominance

Spice Fire One, India’s first Firefox OS phone, challenges Android’s entry-level dominance

            Firefox OS in its earliest avatar 

Mozilla’s Firefox OS as a smartphone operating system has had a negligible impact on the market, but all that could change very soon as the first Firefox smartphone has been announced for India. The Spice Fire One has predictable low-end specifications and a greatly attractive price tag.

At Mobile World Congress, Mozilla unveiled plans to expand to additional markets in Latin America and eastern Europe, and also announced a blueprint for any phone maker to make $25 Firefox OS smartphones, which it has now delivered on seemingly with the Spice Fire One, priced at Rs 2,299.

Many vendors are touting their low-cost Android devices as built for the first-time smartphone buyer. But we think that Android, iOS, BB 10 and Windows Phone are so far advanced for most first-time buyers that they don’t even know how to tap the full capability of the OS. Firefox is meant for just this crowd, making it easier to get apps and simple to use for non-practiced users. Firefox OS is built specifically for low-powered phones, and is optimised to run on hardware as low as a single-core processor, which is what Spice’s Fire One sports.

The phone is expected gives users the basic experience, without the performance overhead. It’s meant to decentralise the app publishing process of the leading operating systems, by giving developers full freedom to publish Web apps. The idea behind Firefox OS is it’s a Web-first platform, and not apps-first. It uses the full suite of Web standards such as HTML 5, WebRTC or RTSP for live video streaming, to bring apps and or to convert web pages into apps. In fact, if you use an Android phone, you can check out how this works as the Firefox broswer app lets you install apps from the Marketplace, like you would a regular Android app.

There’s a handy advantage with this system. Unlike on iOS or Android, where you may have to download apps, with Firefox OS, you have instant access to all apps, since they are basically modified versions of the website or webpage. Firefox says its search-and-launch mechanism will at least partially rid the problem of searching for and installing apps, which is part of the learning curve on any smartphone. This also means that developers don’t have to be bound by app-store rules that most OSes have. A developer could publish any app for Firefox OS on the Firefox Marketplace, just as easily as they would make a webpage.

Mozilla says its currently making big changes to the OS, which will come to handsets over this year. Among the changes is one for the way users access recently used apps or the notification centre. In a bid to set itself apart from the likes of Android, Firefox is working on a cross-platform sync service with Firefox Accounts, which was introduced with the radical Australis makeover. With Firefox Accounts, Mozilla can better integrate services including Firefox Marketplace, Firefox Sync, backup, storage, or even a service to help locate, message or wipe a phone if it were lost or stolen, according to the company. It would ensure your open tabs are synced across the phone and your PC.

The latest version of the OS, v 1.3, addresses some concerns such as POP3 email support, and NFC connectivity for interfacing and triggers. Firefox has also made improvements to the camera app, with support for continuous autofocus provided the hardware is present for such a feature. It’s surely adding a lot of things that are considered crucial in modern day smartphones, but in its own way.

Of course, the big questions are always about what one can do with the phone, the apps, games and utilities available. Here’s where Firefox OS could come undone. Sure, the Marketplace boasts popular apps such as Line, Twitter, Facebook and even Candy Crush, but it’s still a very underwhelming collection. WhatsApp, for example, would be the first app most smartphone newbies look for, but it’s not yet available on Firefox. That could of course change as more devices and vendors come into the picture. But the hard fact is that Firefox OS is still quite nascent and that’s its biggest drawback. Firefox is hoping it can impress first-time smartphone users with how much can be done in so little, which is something Android has yet to convince anyone about, save for a few exceptions.

Android is clearly dominating the budget segment, and such a monopoly is never a good thing for consumers. Choice is great, and Mozilla and Spice are making options available. Make no mistake, Spice is fully invested in Android; the company’s website does not yet have a page for the new Firefox OS phone, so it’s clearly just the first step to gauging reaction. And at Rs 2,299 for the Fire One, it’s making things way easy for the undecided buyer.

Firefox OS phones might not be so revolutionary that they will change the Indian smartphone market or to dethrone Android; no one thinks Firefox OS is mature enough to do that. But Firefox has the right idea of targetting first-time smartphone buyers, and now we can wait for more manufacturers to follow Spice’s lead, if the first Firefox OS phone is a hit. 

Thursday, August 21, 2014

US, German researchers create framework for core Android security modules

glowing-keyboard-hacker-security-620x465

International security researchers have offered up a framework for Google's Android operating system that allows users and developers to plug in extra security enhancements.
The researchers, from North Carolina State University and Technische Universitat Darmstadt/CASED in Germany, have developed a modification to the core Android operating system called the Android Security Modules (ASM) framework. The framework aims to eliminate the bottleneck which can prevent developers and users from taking advantage of new security tools, and make it easier for third parties to integrate the latest cybersecurity programs on offer.
The project is described in a paper (.PDF) due for release at the Usenix Security Symposium in San Diego this week.
Dr. William Enck, an assistant professor of computer science at NC State and senior author of the paper commented:
"In the ongoing arms race between white hats and black hats, researchers and developers are constantly coming up with new security extensions. But these new tools aren't getting into the hands of users because every new extension requires users to change their device's firmware, or operating system (OS).
The ASM framework allows users to implement these new extensions without overhauling their firmware."
While the Android operating system's open and free nature makes it attractive for developers and users alike, there are many variations on both smartphone and tablet platforms. This, in conjunction with Android's popularity, means that firmware and patching can be haphazard -- and a potential risk to businesses relying on the OS, or for companies which implement BYOD (bring your own device) schemes. However, with a sufficient security underpinning, Android devices could be more adequately protected -- as well as the data they contain.
The ASM framework is one way to better protect Android-based devices, argues the researchers. Custom security control modules within the framework could receive "callbacks" for security-sensitive operations in the Android OS, which means that the OS contacts the security module directly to determine if an operation should go ahead. Enck said:
"Our ASM framework can be used in various personal and enterprise scenarios. For instance, security modules can implement dual persona: i.e., enable users to securely use their smartphones and tablets at home and at work while strictly separating private and enterprise data.
Security modules can also enhance consumer privacy. The framework provides callbacks that can filter, modify, or anonymize data before it is shared with third-party apps, in order to protect personal information."
Enck says the framework is available now for security specialists, but insists that for widespread adoption, either Google or Android handset manufacturers need to adopt the framework and integrate it within the operating system. However, the framework is unlikely to be a quick fix, as Google would need to alter the core architecture of the OS -- which is no small task.