Android security is still important, no matter what Google tells you
This article may contain personal views and opinion from the author.
Adrian Ludwig speaking at Black Hat USA 2015
Google is basing its claims on wildly incomplete data
But let’s start with the facts: as Ludwig claims, Stagefright has resulted in zero confirmed infections in the wild – data based on Google Play Services’ built-in malware detection. All that is good and well, except he conveniently forgets to mention the fact that Google Play is unavailable in a number of countries, most notably China, which also happens to be one of the biggest smartphone markets in the world.So his claim that no Stagefright exploits exist is based on wildly incomplete data, which also just so happens to fit a “pattern” he noticed – this is military-grade disinformation at its best, and it coming from the head of security for the most widely used mobile OS in the world is downright scary.
But never mind the Chinese – what’s important is no Americans were infected, right? Except that’s not concrete information, either: Ludwig claims no confirmed cases exist, raising the possibility that there were, or maybe even still are, probable candidates. And let’s not even begin discussing the fallibility of Google’s malware detection, which has failed a numberof timesin the past.
Ludwig may be technically correct, but he's still missing the point
Ludwig did have a point, however: regular users needn’t worry about being hacked by elaborate means such as exploiting Stagefright or its brethren – phishing and adware are a much more common occurence, especially in the mobile world. So the everyday consumer is much more likely to infect themselves, due to their own stupidity and/or ignorance, rather than become an unwitting target of malware.The Qatari government's phishing tactics involved creating fake social media profiles
As for the obvious question this poses: “Why should I care about Qatar?”, consider this: as of March 2015, it's officially the richest country in the whole world, and is also one of the biggest players in the oil industry. It’s also run by a laughably corrupt government with no regard for human rights, a trend which seems to be getting ever so popular these days. Autocracies like these have both the desire and the resources to exploit vulnerabilities like Stagefright, and use them against their opposition. And who’s to say there isn’t a treasure trove of undiscovered bugs stashed somewhere right now, waiting to get abused?
Things that are NOT allowed: