Even though both Apple’s iOS and Google’s Android smartphone operating systems are pretty secure, they are still susceptible to multiple types of attacks, Symantec said.
Android and iOS were designed with mobile security in mind and were superior to traditional desktop operating systems, Symantec researchers wrote in a whitepaper released June 28. However, the security features are not sufficient to meet enterprise requirements, the paper concluded.
Apple had better access control, application provenance and encryption in iOS while Google was better at application isolation, Khoi Nguyen, group product manager in the enterprise mobility group at Symantec, told eWEEK.
“The project wasn’t about determining which platform was better,” Nguyen said. Symantec was more interested in examining the core security architecture to analyse strengths and potential vulnerabilities, Nguyen said.
All bets are off for users with jailbroken devices regardless of the company, said Nguyen. They are every bit as vulnerable as traditional computers and an attractive target.
Both platforms enforce access control policies via passwords, Symantec found, although the iOS offers more options for protecting data, such as an automatic data wipe after a specified number of failed password attempts.
Apple’s certification and rigid control over which applications can be posted to the App Store protects users, Nguyen said. The iTunes App Store acts as a certificate authority to sign the app and is the only source for non-jailbroken iOS devices.
Google’s “less rigorous” system helped trigger the increase in Android malware because it was easier to get malicious apps onto the Android Market, Symantec found. Luckily for Google, most Android malware to date has not had a significant impact on users yet.
On the other hand, Android 2.2 and 2.3 do not have any built-in encryption capabilities. The tablet version, Android 3.0, offers an encryption option, but it is turned off by default. Both platforms use some form of sandboxing to isolate applications and require apps to request permissions to access device capabilities.
While iOS apps are forbidden to read or write to other apps or the operating system and have limited access to the SIM card or the kernel, they can perform a wide range of actions such as accessing the Internet, getting the phone number, looking at the calendar and controlling the video camera without requesting permission from the user.This can raise potential privacy flags.
Android apps are blocked from accessing most system services unless the user explicitly grants permission. When the user tries to install an app, it is shown a list of permissions the app needs, so the user knows up front exactly what the app will do on the device, such as sending SMS messages or accessing the Internet.
While Android gives the user control over what to allow on a case-by-case basis, it also runs the risk of overwhelming non-technically savvy users by asking them to make security decisions, Nguyen said.
While mobile devices are designed to be more secure, the way they are used makes them more insecure than laptops and desktops within the enterprise. Regularly synchronising devices with cloud services and home desktop computers so that all the information is always accessible means sensitive corporate data on those devices are being exposed to systems the IT department has no control over, Symantec said.
The devices are more vulnerable because they travel more than laptops, are easier to steal and conceal, and easier to break into once stolen, according to Symantec.
Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector
Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…
Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…
Judge Kaplan praises former FTX CTO Gary Wang for his co-operation against Sam Bankman-Fried during…
Explore the future of work with the Silicon In Focus Podcast. Discover how AI is…
Executive hits out at the DoJ's “staggering proposal” to force Google to sell off its…