The latest update to Google's Android mobile operating system enhances its security and functionality, making the platform more attractive to enterprises.
The update, known as Ice Cream Sandwich, improves Android security by simplifying the process by which applications manage authentication and run secure sessions.
According to a post made by Android's development team aimed at users and third-party developers, Google has introduced new cryptographic processes.
"A new keychain API [application programming interface] and underlying encrypted storage let applications store and retrieve private keys and their corresponding certificate chains. Any application can use the keychain API to install and store user certificates securely."
This makes it harder for hackers to access users' data, or to trick users into visiting malicious sites disguised as the web properties of legitimate companies or services.
The update also introduces the ability to randomise where Android devices store components of software installed on them. Known as Address Space Layout Randomization (ASLR), this makes it harder for hackers to find where their code has been stored once they have convinced a user to install it on their device. This limits what hackers are able to do with malware.
"Android 4.0 now provides address space layout randomization (ASLR) to help protect system and third-party applications from exploitation due to memory-management issues," wrote Google on the update.
Further security is provided by a new feature that enables administrators to remotely disable the camera.
"The platform adds a new policy control for administrators who manage devices using an installed Device Policy Manager. Administrators can now remotely disable the camera on a managed device for users working in sensitive environments."
There are also separate enhancements for third-party virtual private networks (VPN) developers, which is aimed specifically at enterprise users.
"Developers can now build or extend their own VPN solutions on the platform using a new VPN API and underlying secure credential storage. With user permission, applications can configure addresses and routing rules, process outgoing and incoming packets, and establish secure tunnels to a remote server."
Meanwhile, security firm McAfee has found that hackers are using QR (quick response) codes to distribute malware on Android devices.
"The latest Android malware uses QR code to distribute malicious links," wrote Arun Sabapathy, research scientist at McAfee Labs in a blog.
Once the code is scanned by a mobile device's camera, it prompts the device to open up the URL of an infected site, which immediately attempts to download malware.
Typically, this sort of malware is designed to attempt to send a high volume of SMS messages to premium rate numbers, which can quickly amount to large bills if enterprise users or device administrators are slow to check costs with their providers.
Sabapathy recommends that users preview URLs before allowing their devices to browse to unknown sites.
"Use a mobile QR code-/barcode-scanning app that previews URLs, and avoid scanning suspicious codes," he said.
Have your say on this article
Newsletters
Latest stories from Hacking
You may also like
Hacking jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?