The ability for users to load software ‘off market’ opens the door for malicious applications to be distributed without the need for a vulnerability:’ says Wisniewski, meaning anyone can write an app and anyone can install anything on their Android phone. granting it permission to go wild with their personal data. Symantec reports that a maximum of 49 devices were infected with the Android.Nickispy trojan .
Google’s main defence is the Android Permissions notifier, which tells you exactly which phone features an app will be able to access once installed. The problem is, no one reads these permissions. It’s a boring list of things most of us don’t understand. How is the everyday man expected to know whether it’s right or wrong for a particular app to require access to his contacts details?
There is also the problem of software updates, which has been the bane of Android over the last year or two, as Google relentlessly releases new OS versions and the networks struggle to keep up.
“The other factor that increases the risk for Android users is the lack of patches that fix the vulnerabilities that are discovered:’ explains Wisniewski. “Even if Google fixes the flaws in the core version of Android, most carriers and phone makers lag far behind integrating the fixes, if they bother at all.”
Which all sounds very worrying, but then again it’s common practice, and advice throughout the tech world is to always update to the latest version of any software. If you have been stranded with an unsupported Android model that’s sitting on version 1.6 of the operating system, you may well be more vulnerable because the hackers have had longer to work on exploits.
Source
Google’s main defence is the Android Permissions notifier, which tells you exactly which phone features an app will be able to access once installed. The problem is, no one reads these permissions. It’s a boring list of things most of us don’t understand. How is the everyday man expected to know whether it’s right or wrong for a particular app to require access to his contacts details?
There is also the problem of software updates, which has been the bane of Android over the last year or two, as Google relentlessly releases new OS versions and the networks struggle to keep up.
“The other factor that increases the risk for Android users is the lack of patches that fix the vulnerabilities that are discovered:’ explains Wisniewski. “Even if Google fixes the flaws in the core version of Android, most carriers and phone makers lag far behind integrating the fixes, if they bother at all.”
Which all sounds very worrying, but then again it’s common practice, and advice throughout the tech world is to always update to the latest version of any software. If you have been stranded with an unsupported Android model that’s sitting on version 1.6 of the operating system, you may well be more vulnerable because the hackers have had longer to work on exploits.
Source

