
A complaint filed with the Federal Trade Commission accuses wireless phone carriers of leaving millions of Android phone users vulnerable to attack from hackers by failing to distribute fixes for known security flaws in a timely manner.
The American Civil Liberties Union asked the FTC on Wednesday to investigate AT&T, Verizon Wireless, Sprint Nextel and T-Mobile for unfair and deceptive business practices stemming from their failure to provide available security patches for the Android operating system running on phones and for failing to inform consumers that their systems are unpatched and vulnerable to attack.
“A significant number of consumers are using smartphones running a version of the Android operating system with known, exploitable security vulnerabilities for which fixes have been published by Google, but have not been distributed to consumers’ smartphones by the wireless carriers and their handset manufacturer partners,” the ACLU writes in its 16-page complaint (.pdf). “There are millions of vulnerable Android phones in the hands of consumers today because wireless phone carriers and phone hardware makers refuse to transmit existing software security fixes to phones in a timely manner, according to a security researcher.”
Unlike phones made by Apple, which controls the distribution of software updates to its phones, Android users can’t get an update to their phones without a carrier’s intervention. Instead, they have to obtain updates from servers operated by the carriers. But the wireless carriers and hardware makers can take a year or longer to distribute new firmware updates containing security fixes for phones.
Read also:
ACLU asks FTC to enforce Android updates (NBCNews.com)
ACLU: Carriers leave consumers exposed by withholding Android updates (GigaOM)
ACLU Asks FTC to Probe 'Dangerous' Android Bugs (PC Magazine)
Explore: 33 additional articles.