400 Percent Increase In Android Malware
mobilecrunch.com
mobilecrunch.com
> now would be as good a time as any to choose an antivirus app.
You don't say...
I never download anything that requires anything other than the Internet permission, maybe Location, and sometimes SD Card modifications (though I hate that one too).
Some of my competitors that are completely free ask for phone identity, contacts, etc, and yet they are soaring to the tops of the ranks.
People are downloading anything, and not worrying about anything.
Unfortunately, the average user still has the mentality of "So, I have nothing on here they can get". Which is obviously idiotic as the hacker will use YOUR phone to do something illegal possibly. I don't know why people don't get this???????
"This application requests permission to read phone state and identity." <-- That sounds so harmless to most people.
If it said "This application requests permission to retrieve your phone number and your full name and send it over the internet to a 3rd party company", then they might be inclined to pass up installing the app.
The malware Google removed a few weeks ago was apparently trying to get the phone's network ID numbers, wasn't it? So who cares what you have on there, they want to steal your phone's identity!
Given the history of Windows, it's not surprising that the average person has no idea about security and installs anything willy-nilly. One might think that Google would have taken heed of that... instead, it seems like we're going to end up with phones running anti-virus that are getting compromised constantly. They weren't kidding when they said Android is the Windows of mobile phones.
The permissions listed seem to pertain to the uses-permissions in the Manifest.
If the Manifest doesn't request these permissions, and they aren't allowed, they won't work. If I don't put the Internet uses-permission in my Manifest, then any Internet calls I make won't work.
Caution is a good policy, but it shouldn't cripple your usage of a device. Use reviews and word of mouth to gauge the legitimacy of an application. Steering clear of "free tv shows free" makes sense, but not installing Facebook or Twitter seems silly overreaction.
Like on Debian or Ubuntu, you have the packages reviewed/compiled by the company, and the ones that are not. It would be nice if Google put forth an effort to at least have a 'reviewed and likely to be safe' area. As it is, I have to find software through other methods, like reviews or such on the web, and determine whether the vendor is trustworthy.