Apple iOS vs. Google Android: It Comes Down to SecurityAdded 4th Dec 2012
Which is more secure, mobile devices based on Google Android or Apple iOS? It's not just a theoretical question to IT professionals making decisions about the future use of smartphones and tablets in the enterprise.
Apple's locked-down approach in iOS has given it something of an edge in the debate, especially since Android's more open platform is being targeted by malware writers. Hardly a week goes by that security vendors hunting Android malware don't remind us of the growing tally, as Trend Micro recently did it claiming that Android malware surged this year from 30,000 specimens in June to almost 175,000 in September.
But on Android's side, security experts point out that the closed, proprietary iOS architecture has some drawbacks, such as when an iOS device is "jailbroken," its security shield is basically broken. Android's inherent openness and flexibility, something missing from iOS, is making it attractive as a platform for organizations considering customization of security the way they want it.
"You can build more security for Android," notes Tom Kellermann, vice president of cybersecurity at Trend Micro, who points out Android's open API model is conducive for that. But he notes that for now, at least, Google Android is also viewed as more vulnerable. In a study that Trend Micro did of security of the three mobile platforms iOS, Android and RIM BlackBerry, BlackBerry actually came out on top in that, he points out.
Worries about possibly having to cope with Android malware on either corporate-owned devices or Bring Your Own Device (BYOD) situations seems to be swaying a number of information-technology managers to vote 'yes' on iOS, 'no' on Android.
At Los Angeles-based real-estate investment firm Hearthstone, for example, the CTO there, Robert Meltz, says this is one of the main reasons why his company is going with managed BYOD iOS devices.
New York-based Blackstone Group feels much the same, according to CTO Bill Murphy. And in the healthcare environment, such as hospitals where use of tablets and other mobile devices under BYOD arrangements with healthcare professionals is surging, the same reservations about Android are voiced.
"We tested Android and we think it's more vulnerable than iOS," says Barak Shrefler, the IT and security manager at Hadassah University Hospital in Jerusalem, who said IT staff are concerned that malware or vulnerability issues around Android will simply result in future headaches, at least more than Apple iOS. At the same time, Shrefler acknowledges he's worried about jailbroken iOS devices, too.
Tamir Hardof, director of product marketing at Juniper, admitting he's reluctant to take sides, nevertheless said "data shows there are more security threats on the Android side." But he added that Apple's closed system may not be what's preferred for some enterprise customers with specific security requirements, and he's optimistic in general that "security will improve for Android devices."
Tyler Shields, senior security researcher at Veracode, had this to add to the debate: "One of the primary differences between iOS and Android is the application distribution and vetting models. IOS has a single application store, iTunes, that customers can download applications from. While Apple is not perfect, they have executed better than Google in the application vetting process while attempting to limit malware distribution."
Shields continues, "On the other hand, Android applications can be acquired from both the Google Play store as well as a number of third-party stores. This distribution model lends itself well to repackaged applications that contain malware. It's difficult, if not impossible, for Google to police the security of their application ecosystem because they don't have a single application funnel where all applications must pass."
Chris Astacio, Websense manager of security research, also weighed in. "In the ongoing discussion of whether iOS or Android devices are more secure, the overwhelming majority of evidence helps to support Apple's case for supremacy," says Astacio. Why? "The iOS closed operating system and application vetting process help prevent a vast majority of the successful malicious examples we have seen in Android devices."
But Astacio also includes something of a caveat.
"Apple's vaunted application-screening process will only maintain its current success until the top-notch hackers feel it is profitable to create malware sophisticated enough to hide from their application-screening process. For now, there is significant danger in what we call 'legitimate applications behaving badly.' This is where the information gathered by applications is targeted by hackers through some mode of interception, perhaps most likely by hacking into the application developer's networks. For now, though, if I'm placing a wager on which is more secure, I'm putting my money on Apple."
Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: MessmerE. E-mail: firstname.lastname@example.org.
Read more about wide area network in Network World's Wide Area Network section.
Next year will see demonstrable evidence of the Internet of Things, real-time communications on the Web, and SDN-enabled platforms with killer applications for them.
A Stratecast survey has found that more than 80 per cent of employees admit to using unauthorised Software-as-a-Service (SaaS) applications during work.
Microsoft moved to reassure business and government customers worldwide that it is committed to informing them of legal orders related to their data, and will fight in court any 'gag order' that prevents it from sharing such information with customers.
Distributed denial-of-service attacks against financial firms and other industries have been mounting, so today the Cloud Security Alliance (CSA) announced it is establishing the Anti-Bot Working Group to help fight this threat.
The majority of today's CIOs see value in mobilizing enterprise applications and in deploying mobile-related innovations such as GPS features, location-based services (LBS), mobile payments and QR codes. Many also say their organizations are already somehow increasing revenue and developing new revenue streams directly related to mobile. But nearly as many CIOs also see the cost of deploying new innovations as prohibitive and complexity as a major concern, according to a new survey commissioned by Mobile Helix, a mobile security vendor.
The price of bitcoins may be soaring, but China isn't too thrilled with the virtual currency. On Thursday, the nation moved to regulate use of bitcoins, stating that its financial institutions could not deal in the virtual currency.
New attack campaigns have infected point-of-sale (PoS) systems around the world with sophisticated malware designed to steal payment card and transaction data.
Ruby on Rails users are advised to upgrade to newly released versions of the Web development framework that contain important security fixes, according to the Rails development team.
Mobile technology is increasing the complexity, usage and costs of mainframe applications, according to Compuware research.
Asian markets are ready for advanced mobile technology and fast connectivity, according to new insights released by Telenor Group in Asia.
Large smartphones with 5-in. or larger displays -- often called phablets -- are eating into sales of smaller tablets with screens in the 7-in. range.
Analysts have predicted that the Internet of Things will continue to grow in 2014, and more enterprises will start to realise the potential benefits.
When end users circumvent the IT department and start using software-as-a-service (SaaS) applications without permission, the IT pros complain about the plague they call "shadow IT." But it would seem the professionals are also operating in the shadows, according to a survey out today.
Once upon a time, not so long ago, the IT admin chose exactly what hardware and software would be used by employees. Recent trends like the consumerization of IT and BYOD (bring your own device) have shifted the balance of power, but IT still has to maintain some degree of control over the applications used and where sensitive data is stored. Many users just download apps or start using unsanctioned services, though, and introduce unnceccesary security risks through "shadow IT."
Once heavily reliant on the Chinese market, Lenovo is now looking to make acquisitions as it tries to expand its growing enterprise business to other countries.