Apple iOS vs. Google Android: It Comes Down to SecurityAdded 4th Dec 2012
Which is more secure, mobile devices based on Google Android or Apple iOS? It's not just a theoretical question to IT professionals making decisions about the future use of smartphones and tablets in the enterprise.
Apple's locked-down approach in iOS has given it something of an edge in the debate, especially since Android's more open platform is being targeted by malware writers. Hardly a week goes by that security vendors hunting Android malware don't remind us of the growing tally, as Trend Micro recently did it claiming that Android malware surged this year from 30,000 specimens in June to almost 175,000 in September.
But on Android's side, security experts point out that the closed, proprietary iOS architecture has some drawbacks, such as when an iOS device is "jailbroken," its security shield is basically broken. Android's inherent openness and flexibility, something missing from iOS, is making it attractive as a platform for organizations considering customization of security the way they want it.
"You can build more security for Android," notes Tom Kellermann, vice president of cybersecurity at Trend Micro, who points out Android's open API model is conducive for that. But he notes that for now, at least, Google Android is also viewed as more vulnerable. In a study that Trend Micro did of security of the three mobile platforms iOS, Android and RIM BlackBerry, BlackBerry actually came out on top in that, he points out.
Worries about possibly having to cope with Android malware on either corporate-owned devices or Bring Your Own Device (BYOD) situations seems to be swaying a number of information-technology managers to vote 'yes' on iOS, 'no' on Android.
At Los Angeles-based real-estate investment firm Hearthstone, for example, the CTO there, Robert Meltz, says this is one of the main reasons why his company is going with managed BYOD iOS devices.
New York-based Blackstone Group feels much the same, according to CTO Bill Murphy. And in the healthcare environment, such as hospitals where use of tablets and other mobile devices under BYOD arrangements with healthcare professionals is surging, the same reservations about Android are voiced.
"We tested Android and we think it's more vulnerable than iOS," says Barak Shrefler, the IT and security manager at Hadassah University Hospital in Jerusalem, who said IT staff are concerned that malware or vulnerability issues around Android will simply result in future headaches, at least more than Apple iOS. At the same time, Shrefler acknowledges he's worried about jailbroken iOS devices, too.
Tamir Hardof, director of product marketing at Juniper, admitting he's reluctant to take sides, nevertheless said "data shows there are more security threats on the Android side." But he added that Apple's closed system may not be what's preferred for some enterprise customers with specific security requirements, and he's optimistic in general that "security will improve for Android devices."
Tyler Shields, senior security researcher at Veracode, had this to add to the debate: "One of the primary differences between iOS and Android is the application distribution and vetting models. IOS has a single application store, iTunes, that customers can download applications from. While Apple is not perfect, they have executed better than Google in the application vetting process while attempting to limit malware distribution."
Shields continues, "On the other hand, Android applications can be acquired from both the Google Play store as well as a number of third-party stores. This distribution model lends itself well to repackaged applications that contain malware. It's difficult, if not impossible, for Google to police the security of their application ecosystem because they don't have a single application funnel where all applications must pass."
Chris Astacio, Websense manager of security research, also weighed in. "In the ongoing discussion of whether iOS or Android devices are more secure, the overwhelming majority of evidence helps to support Apple's case for supremacy," says Astacio. Why? "The iOS closed operating system and application vetting process help prevent a vast majority of the successful malicious examples we have seen in Android devices."
But Astacio also includes something of a caveat.
"Apple's vaunted application-screening process will only maintain its current success until the top-notch hackers feel it is profitable to create malware sophisticated enough to hide from their application-screening process. For now, there is significant danger in what we call 'legitimate applications behaving badly.' This is where the information gathered by applications is targeted by hackers through some mode of interception, perhaps most likely by hacking into the application developer's networks. For now, though, if I'm placing a wager on which is more secure, I'm putting my money on Apple."
Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: MessmerE. E-mail: firstname.lastname@example.org.
Read more about wide area network in Network World's Wide Area Network section.
Despite going through a rough patch, the market has grown from 755 million mobile connections to 815 mobile connections in 2014.
IT bellwether TCS scripted history by becoming the first Indian company to stage a grand entry into the Rs 5 lakh crore market cap club.
Amod Malviya, CTO, Flipkart, says the outage was not due to an infrastructure failure. He says changes in the nature of traffic affect Flipkart’s complex algorithms, and throw up hidden choke points that don’t show up in routine stress tests.
IBM's SoftLayer cloud will offer supercomputer-friendly InfiniBand as an interconnect option.
Indian IT services company Tech Mahindra has announced that it plans to expand significantly in Korea and hire 300 in next 3 years and create an ecosystem involving universities, trade bodies and alliances to create jobs.
Twitter has been under pressure from U.S. civil rights leader Rev. Jesse Jackson to release the data.
A shortage may stall SSD prices, but the cost-per-gigabyte will continue to decline.
Sprint business customers will soon be able to purchase and bundle Google Apps for Business on their wireless bill.
Revenue was $2.91 billion for the second quarter, with more than half derived from mobile ads.
According to CIO Research, more CXOs and LoBs are directly sourcing IT from vendors, despite the fact that IT leaders are trying to work more closely with them.
Padmaja Alaganandan, Executive Director-Consulting, PwC Consulting, says the way Indian companies look at their workforce will change: The middle and lower rungs will be hired on a project- or part-time basis.
The annual cost of cybercrime is either staggering, or a mere blip on the world's economic bottom line, depending on how you look at it.
The idea of devops is to better streamline the work of developers and operation professionals.
Wireless broadband subscriptions now outnumber people in seven countries as consumers continue to snap up smartphones and tablets, according to a new report.
Former Microsoft CEO Steve Ballmer's 'devices and services' strategy may be in tatters, discarded by his successor, Satya Nadella, but Ballmer must be smiling all the way to the bank.