Published On: November 7, 2016

With the widespread adoption of bring your own device (BYOD) policies sweeping through the state, and the security threats those devices pose, it’s crucial that you focus on the security of your hardware, your network, and your employees understanding of your company’s security policies.
When Will Android's Security Flaws Inflict Pain on Your Business?
With 80% of the world’s smartphone users now on the Android platform, this makes adopting and understanding a security policy more important than it has ever been.

Android still uses a software update chain-of-command designed back when the Android ecosystem had zero devices to update, and it just doesn’t work. There are just too many cooks in the kitchen: Google releases Android to OEMs (Samsung, LG, HTC, etc), OEMs can change things and release code to carriers (ATT, Verizon, etc), carriers can change things and release code to consumers. It’s been broken for years.

What this means is if you have an Android device made by Samsung running on Verizon’s network, you will need to wait for Google to fix a vulnerability, and then Samsung to implement the fix on your specific device, and then Verizon to implement and send out the fix to you. This can take up to several months, and in many cases will never get fixed at all.

Compare this to when a security vulnerability is detected on Apple’s iOS, which can be fixed and sent to your device within hours.

Let’s look at one of the dozens of security vulnerabilities that has hit Android just this year. Three of the biggest ones have been found just in the last 30 days. One of these is called Stagefright.
When Will Android's Security Flaws Inflict Pain on Your Business?
The reaction the Stagefright, a vulnerability that affects 95% of Android devices and can allow a remote arbitrary code execution just by receiving a malicious MMS, is an example of how terrible things are with Android and security. Google, Samsung, and LG have all pledged to “Take Security Seriously” and issue a fix as soon as possible.

The problem is that their fix will be to patch 2.6% of all active Android devices. That doesn’t guarantee that those 2.6% of users lucky enough to get updates will take the time to install that update, or for that matter even be lucky enough to have their carrier make it available to them. That 2.6% is a best case scenario. That’s the percentage of Android devices that are running Android 5.1 today, nearly five months after the OS was released.

This is an obvious problem for offices that allow employees to bring their own devices to use on the company’s network. So what can you do to ensure your office environment is safe?

Ensure you have a security policy, and make sure your employees understand it. Make sure you understand the attack vectors in the hardware you and your employees are using. If you are using Xerox equipment you are already protected by McAfee on a hardware level, full disk encryption and image overwrite, IPsec, 802.1x encryption, and much more making Xerox the only brand to be trusted by the United States Department of Defense.

At Smart Document Solutions we specialize in, and are the #1 Authorized Xerox Agent in Phoenix, Flagstaff, Scottsdale, Tempe and Paradise Valley. If you have any questions about how Xerox can help make your Arizona office a secure and smart office, don’t hesitate to give us a call at 602-788-0250 or contact us online.

Share This Article, Choose Your Platform!