Apple iOS vs. Google Android: It Comes Down to SecurityAdded 4th Dec 2012
Which is more secure, mobile devices based on Google Android or Apple iOS? It's not just a theoretical question to IT professionals making decisions about the future use of smartphones and tablets in the enterprise.
Apple's locked-down approach in iOS has given it something of an edge in the debate, especially since Android's more open platform is being targeted by malware writers. Hardly a week goes by that security vendors hunting Android malware don't remind us of the growing tally, as Trend Micro recently did it claiming that Android malware surged this year from 30,000 specimens in June to almost 175,000 in September.
But on Android's side, security experts point out that the closed, proprietary iOS architecture has some drawbacks, such as when an iOS device is "jailbroken," its security shield is basically broken. Android's inherent openness and flexibility, something missing from iOS, is making it attractive as a platform for organizations considering customization of security the way they want it.
"You can build more security for Android," notes Tom Kellermann, vice president of cybersecurity at Trend Micro, who points out Android's open API model is conducive for that. But he notes that for now, at least, Google Android is also viewed as more vulnerable. In a study that Trend Micro did of security of the three mobile platforms iOS, Android and RIM BlackBerry, BlackBerry actually came out on top in that, he points out.
Worries about possibly having to cope with Android malware on either corporate-owned devices or Bring Your Own Device (BYOD) situations seems to be swaying a number of information-technology managers to vote 'yes' on iOS, 'no' on Android.
At Los Angeles-based real-estate investment firm Hearthstone, for example, the CTO there, Robert Meltz, says this is one of the main reasons why his company is going with managed BYOD iOS devices.
New York-based Blackstone Group feels much the same, according to CTO Bill Murphy. And in the healthcare environment, such as hospitals where use of tablets and other mobile devices under BYOD arrangements with healthcare professionals is surging, the same reservations about Android are voiced.
"We tested Android and we think it's more vulnerable than iOS," says Barak Shrefler, the IT and security manager at Hadassah University Hospital in Jerusalem, who said IT staff are concerned that malware or vulnerability issues around Android will simply result in future headaches, at least more than Apple iOS. At the same time, Shrefler acknowledges he's worried about jailbroken iOS devices, too.
Tamir Hardof, director of product marketing at Juniper, admitting he's reluctant to take sides, nevertheless said "data shows there are more security threats on the Android side." But he added that Apple's closed system may not be what's preferred for some enterprise customers with specific security requirements, and he's optimistic in general that "security will improve for Android devices."
Tyler Shields, senior security researcher at Veracode, had this to add to the debate: "One of the primary differences between iOS and Android is the application distribution and vetting models. IOS has a single application store, iTunes, that customers can download applications from. While Apple is not perfect, they have executed better than Google in the application vetting process while attempting to limit malware distribution."
Shields continues, "On the other hand, Android applications can be acquired from both the Google Play store as well as a number of third-party stores. This distribution model lends itself well to repackaged applications that contain malware. It's difficult, if not impossible, for Google to police the security of their application ecosystem because they don't have a single application funnel where all applications must pass."
Chris Astacio, Websense manager of security research, also weighed in. "In the ongoing discussion of whether iOS or Android devices are more secure, the overwhelming majority of evidence helps to support Apple's case for supremacy," says Astacio. Why? "The iOS closed operating system and application vetting process help prevent a vast majority of the successful malicious examples we have seen in Android devices."
But Astacio also includes something of a caveat.
"Apple's vaunted application-screening process will only maintain its current success until the top-notch hackers feel it is profitable to create malware sophisticated enough to hide from their application-screening process. For now, there is significant danger in what we call 'legitimate applications behaving badly.' This is where the information gathered by applications is targeted by hackers through some mode of interception, perhaps most likely by hacking into the application developer's networks. For now, though, if I'm placing a wager on which is more secure, I'm putting my money on Apple."
Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: MessmerE. E-mail: firstname.lastname@example.org.
Read more about wide area network in Network World's Wide Area Network section.
India's Essar Group has finally sold its operation in east Africa to Kenya's Safaricom and Airtel Kenya for $100 million after years of running the operation at a loss.
With smartphones and tablets increasingly at risk from malware, researchers from North Carolina State University have devised a new and potentially better way to detect it on Android devices.
Automation, virtualization, cloud computing -- these technology trends are transforming the data center and enabling companies to lower costs, increase flexibility and improve reliability. However, these shifts require IT, and their outsourcing providers, to rethink traditional strategies.
The first Cebit trade show in the post-Snowden era will focus on security, showing off locally developed bug-proof phones and messaging systems, as well as the ability to protect mobile devices using smartcards.
CIOs who haven't moved their companies from Windows XP by now ought to be fired, some people think, but those who haven't and are still on the job have options for saving their bacon.
The U.S. National Security Agency (NSA) has turned the European Union into a tapping "bazaar" in order to spy on as many EU citizens as possible, NSA leaker Edward Snowden said.
A phenomenal idea that reveals the damage traditional toys have had on our children and facilities how we can encourage our girls to take up careers in science, technology, engineering and mathematics.
A new commercial tool designed to allow cybercriminals to easily transform legitimate Android applications into malicious software has hit the underground market, paving the way for cheap and easy development of sophisticated Android malware.
Malware often does strange things, but this one -- which looked like Skype installed on a corporate domain controller -- was most "peculiar," says Jim Butterworth, a security expert at ManTech International, whose security subsidiary HBGary recently found the custom-designed remote-access Trojan on a customer's network.
Microsoft will deliver five security updates to customers next week, two tagged as "critical," including one that will quash the open vulnerability in Internet Explorer that hackers have been exploiting since January.
Having lots of Wi-Fi networks packed into a condominium or apartment building can hurt everyone's wireless performance, but Stanford University researchers say they've found a way to turn crowding into an advantage.
Organizations can now add machine-generated data to their palate of information sources that can be aggregated and analyzed, thanks to a new connector jointly developed by Tableau Software, a provider of business intelligence software, and Splunk, which sells a log-file search engine.
The Tor network is in danger of being swamped by criminals abusing its anonymity to hide an underworld of parasitic botnets, malicious command and control and ‘darknet' markets, according to research from Kaspersky Lab.
Rogue adverts that use social engineering to persuade users to install malware have displaced porn as the leading method of attack on mobile devices, according to a report from security firm Blue Coat.
A convoluted web of applications is stunting the digital transformation of the world's biggest international organisations.