
The open nature of Google’s Android operating system means manufacturers can add their own software layer to the phonehelping them stand out from the pack with a different look and features. Yet new research shows such tailoring may also be responsible for a host of security weaknesses that could make phones more vulnerable to hackers.
According to a study conducted by computer science researchers at North Carolina State University, changes manufacturers made to the stock Android software were responsible for more than 60 percent of the security flaws uncovered in phones from different handset companies. A paper (pdf) on the work is slated to be presented Wednesday at the ACM Conference on Computer and Communications Security in Berlin.
“We were surprised by the overall insecurity,” says one of the authors, Xuxian Jiang, an associate professor of computer science at the university, who researches mobile malware. Jiang sees it as an indication that some phone vendors aren’t taking security seriously enough, and that they feel constant pressure to bring new software features to market.
In their study, researchers looked at 10 Android smartphones; five ran variations of the fourth generation of Android software, and five used the second generation (in between those two, Google released a version 3.2, also known as Honeycomb, that was intended for tablets). The researchers tested one handset with each of the two Android versions from Samsung, HTC, LG, and Sonyincluding the popular Samsung Galaxy S3 and HTC One Xas well as two Google-branded handsets (the Nexus S and Nexus 4, made by Samsung and LG, respectively) that served mainly as frames of reference, since they don’t include the same customized software skins found on many other Android handsets.