The Most Secure Android Phone, Ever
fastcompany.com
fastcompany.com
http://itknowledgeexchange.techtarget.com/IT-watch-blog/like...
It creates a virtual machine that's hardware encrypted on the device, and actually runs them as two separate phones. Similar full-on or pseudo-virtualized environments have been used on the iPhone, iPad, and other devices to various degrees of success over the years, but I think it is a slight hyperbole to say "this could change the way people use smartphones, entirely".
The linked article seems to be about 2 separate disk partitions, but the same user space. And that doesn't sound good then.
There was a consumer grade phone a few years ago that pulled very similar partitioning tricks but my Google-Fu has failed me in retrieving it. Thanks for clarifying.
There are quite a few companies using iPads as well (SAP for example bought 3,000+ for their sales workforce)
Then you haven't been reading asymco :).
This recent article includes such sentences as "During the last month alone RIM lost 1.2 million users." http://www.asymco.com/2011/10/07/3411/
In the context of the article, by "anybody" I meant companies and organisations, who are working with highly sensitive and confidential information. That's the segment the phone in the article is trying to compete in. In order to move these people away from RIM, they have to build up trust though, which is a long process.
They call it the Divide platform. The professional side of the device has includes enhanced security, access control, remote wipe capabilities..
What exactly does that mean? Do they keep a blacklist of apps? Perhaps they only mean the "work apps"?
A compromised phone scanning itself does not make a lot of sense. If the server scans the phone, it still can't be trusted since you're asking an insecure device: "are you compromised?".
Guess the point is just to know if there are any unwanted apps, that did not gain "root", on the phone. Is this useful?
>> Control over apps in the "work" partition is handled by the end user's corporate IT team
So maybe each time the phone checks in to the network, some sort of hash is computed to see if anything is different than the expected system?
I am referring to the fact that applications can be installed from Market (or otherwise), receive no explicit user-granted (or visible) permission, and yet have unfettered access to the largest chunk of native code in the system, which more often than not is a year behind the latest security updates.
No amount of userspace virtualisation can work around that.
The kernel vulns are still there in most phones and exploitable from user space.
Have a look at the very new Android security review, by "experts" and official:
http://source.android.com/tech/security/index.html
While its a good start (user separation among others), it doesnt address any core security issue, like timely kernel updates (and many phones don't even support OTA properly/don't get updates pushed, so no timely Android core updates either), sdcard security, drivers fully communicating in user space (this one won't be fixed as its a work-around to avoid GPL).