Josef Ressel Center for User-friendly Secure Mobile Environments
Android Security Symposium 2017
AT&T efforts to improve the distribution of Android security updates
About the speaker
Patrick McCanna
Abstract
PC's get patches every month. Apple has been very efficient in creating and distributing security patches. The AOSP source is updated regularly. Why was there such a delay in distributing security patches in Android? Shouldn't it be easy to distribute the AOSP source changes as updates to launched devices?
Starting in 2015, AT&T changed it's procedures to enable a rapid distribution of security updates. These changes allowed OEMs to rapidly distribute security updates after the Stagefright discovery. In this talk, we'll discuss what was delaying security updates in the past & the changes that allowed for rapid distribution of security updates during that urgent event. We'll also discuss AT&T's recent 2G sunset and features necessary for the future of secure mobile communication.
Android has provided us with security lessons that are applicable beyond the mobile industry. Industrial IoT, Connected home, Car & city solutions all can benefit in this discussion on the challenge of distributing open source software security updates to proprietary hardware.