"Android malware attack spreads via e-mail"
http://www.usatoday.com/story/tech/2013/03/28/android-malwar...
http://securitywatch.pcmag.com/mobile-security/311417-window...
"Android malware attack spreads via e-mail"
http://www.usatoday.com/story/tech/2013/03/28/android-malwar...
http://securitywatch.pcmag.com/mobile-security/311417-window...
2) FTA:
>Q: What can or should individuals do?
> Stone-Gross: Do not allow installation of applications that are not distributed through the official Google Play marketplace on the device
So this malware isn't effective unless the user explicitly makes their device vulnerable, doing something normally only developers or hard core users - people who are likely to spot this attack - would do.
There's nothing anyone can do if a user installs software. UNIX design or not, if the user runs a program, it can access everything that the user can. Nothing that this malware did needed special access (e.g. root exploit).
The idea that all apps run under a single "user" and all share the permissions of that "user" is just how UNIX does it, not how things must work. I don't think we've figured out proper app sandboxing yet (Mac, iOS, and Android all have their problems with it, and differently) but it seems to be the way to go.
- a recent convert to Apple
However, this will break nearly everything – and I am rather positive that Windows offers similar security measures, if required.
Now the malware problems on both platforms rarely rely on privilege escalation. They use trojan horses instead, and wait for you to install them.