Tag Archives: Android

Can Android Without Dalvik Avoid Oracle’s Wrath?

jfruhlinger writes “Despite the fact that Oracle is suing Google over claims that Android violates Java IP, Android is roaring ahead in the marketplace. Still, some groups are wondering if they can implement Android without incurring Oracle’s current or future wrath by avoiding the Dalvik VM. A project called IcedRobot aims to create a GNU-compatible version of Android, and rumors abound that RIM is planning on putting an OpenJDK-version of Android on its upcoming PlayBook tablets.”

Read more of this story at Slashdot.

Link to the original site

Gentlemen Prefer Androids, Ladies iOS

Ponca City writes “PC World reports that women are more likely to buy an iPhone for their next smartphone purchase, while men prefer Android devices. According to data collected in October 2010, 31 percent of women wanted to buy an Apple iOS device next, followed by 22.8 percent interested in a Google Android device while among men preferences were reversed with 32.6 percent of men interested in an Android purchase and 28.6 desired an iOS phone. ‘So where is the extra appeal of Android to men coming from?’ asks Tracey E. Schelmetic. ‘More male-targeted commercials that emphasize cool gadgetry versus usability? More techno-macho phone brand names like “Droid”? Extra advertising on the Spike channel by phone makers using the Android platform?’”

Read more of this story at Slashdot.

Link to the original site

Android Phones Get Virtualization

bednarz writes “VMware is teaming with LG to sell Android smartphones that are virtualized, allowing a single phone to run two operating systems, one for business use and one for personal use. A user’s personal email and applications would run natively on the Android phone, while a guest operating system contains the employee’s work environment. The devices would also have two phone numbers.”

Read more of this story at Slashdot.

Link to the original site

Security Expert Warns of Android Browser Flaw

justice4all writes “Google is working on a fix to a zero-day flaw discovered by British security expert Thomas Cannon that could lead to user data on a mobile phone or tablet device being exposed to attack. Cannon informed Google before posting information about the flaw on his blog. ‘While doing an application security assessment one evening I found a general vulnerability in Android which allows a malicious website to get the contents of any file stored on the SD card,’ Cannon wrote. ‘It would also be possible to retrieve a limited range of other data and files stored on the phone using this vulnerability.’” Sophos’s Chester Wisniewski adds commentary on how this situation is one of the downsides to Android’s increasing fragmentation in the mobile marketplace.

Read more of this story at Slashdot.

Link to the original site

Researcher To Release Web-Based Android Attack

CWmike writes “A computer security researcher says he plans to release code Thursday that could be used to attack some versions of Google’s Android phones over the Internet. The attack targets the browser in older, Android 2.1-and-earlier versions of the phones. It is being disclosed Thursday at the HouSecCon conference by M.J. Keith, a security researcher with Alert Logic. Keith says he has written code that allows him to run a simple command line shell in Android (video) when the victim visits a website that contains his attack code. The bug used in Keith’s attack lies in the WebKit browser engine used by Android. Google said it knows about the vulnerability. ‘We’re aware of an issue in WebKit that could potentially impact only old versions of the Android browser,’ Google spokesman Jay Nancarrow confirmed in an e-mail. ‘The issue does not affect Android 2.2 or later versions.’ Version 2.2 runs on 36.2 percent of Android phones, Google says”

Read more of this story at Slashdot.

Link to the original site

Serious Security Bugs Found In Android Kernel

geek4 writes with this excerpt from eWeek Europe: “An analysis of Google Android Froyo’s open source kernel has uncovered 88 critical flaws that could expose users’ personal information. An analysis of the kernel used in Google’s Android smartphone software has turned up 88 high-risk security flaws that could be used to expose users’ personal information, security firm Coverity said in a report published on Tuesday. The results, published in the 2010 edition of the Coverity Scan Open Source Integrity Report, are based on an analysis of the Froyo kernel used in HTC’s Droid Incredible handset. … While Android implementations vary from device to device, Coverity said the same flaws were likely to exist in other handsets as well. Coverity uncovered a total of 359 bugs, about one-quarter of which were classified as high-risk.”

Read more of this story at Slashdot.

Link to the original site

.Net On Android Is Safe, Says Microsoft

An anonymous reader writes “With Oracle suing Google over ‘unofficial’ support for Java in Android, Microsoft has come out and said it has no intention of taking action against the Mono implementation of C# on the Linux-based mobile OS. That’s good news for Novell, which is in the final stages of preparing MonoDroid for release. Miguel de Icaza is not concerned about legal challenges by Microsoft over .Net implementations, and even recommends that Google switch from using Java. However, Microsoft’s Community Promise has been criticized by the Free Software Foundation for not going far enough to protect open source implementations from patent litigation, which is at the heart of the Oracle-Google case.”

Read more of this story at Slashdot.

Link to the original site

Android Data Stealing App Downloaded By Millions

wisebabo writes “A wallpaper utility (that presents purloined copyrighted material) ‘quietly collects personal information such as SIM card numbers, text messages, subscriber identification, and voicemail passwords. The data is then sent to www.imnet.us, a site that hails from Shenzen, China.’”

Read more of this story at Slashdot.


Link to the original site

Android Rootkit Is Just a Phone Call Away

alphadogg writes “Hoping to understand what a new generation of mobile malware could resemble, security researchers will demonstrate a malicious ‘rootkit’ program they’ve written for Google’s Android phone next month at the Defcon hacking conference in Las Vegas. Once it’s installed on the Android phone, the rootkit can be activated via a phone call or SMS message, giving attackers a stealthy and hard-to-detect tool for siphoning data from the phone or misdirecting the user. ‘You call the phone, the phone doesn’t ring, and when the phone realizes that it’s being called by an attacker’s phone number, it sends him back a shell [program],’ said Christian Papathanasiou, a security consultant with Chicago’s Trustwave, the company that did the research.”

Read more of this story at Slashdot.

Link to the original site

Android growth spurs new mobile malware, SMS Trojan discovered

By Tim Conneally, Betanews

Security researchers at Kaspersky Lab announced the first malware for the Android operating system to be classified as a Trojan-SMS, the most widespread type of malware on mobile phones.

The malware is disguised as a media player application with the standard Android .APK file extension. When the 13KB file is installed, the mobile device will start to send SMS messages to premium numbers which incur charges on the user’s account.

Because Android is growing at such an explosive rate, and users are storing an increasing amount of important data on their mobile phones, the platform is an attractive one for renegade application makers.

“We can expect to see a corresponding rise in the amount of malware targeting [Android],” Denis Maslennikov, Mobile Research Group Manager at Kaspersky Lab said in a blog posting Monday. “Kaspersky Lab is actively developing technologies and solutions to protect this operating system and plans to release Kaspersky Mobile Security for Android in early 2011.”

The company has profiled the malware as “Trojan-SMS.AndroidOS.FakePlayer.a”

Copyright Betanews, Inc. 2010

Link to the original site