Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

U.S. regulators want to know why your phone isn’t getting security updates faster

Google, Apple, Samsung and others have been asked to provide details about their mobile updates.

iPhone SE/iPad Pro 9.7 inch Launch In Tokyo
iPhone SE/iPad Pro 9.7 inch Launch In Tokyo
Photo by Tomohiro Ohsumi/Getty Images

Federal regulators have begun exploring a question of importance to millions of American consumers: How secure are your smartphones and tablets?

The Federal Communications Commission and the Federal Trade Commission today asked device makers, the creators of mobile operating systems and the major wireless carriers to provide information about how they address vulnerabilities in smartphones, tablets and other mobile devices.

The inquiry follows one high-profile vulnerability in the Android operating system nicknamed “Stagefright,” which left a billion devices potentially vulnerable to attack. Google has since patched the holes and Google, Samsung and LG all pledged to start pushing out updates once a month to fix security vulnerabilities.

But the federal agencies are examining the question of how long consumers may be left unprotected and whether there are delays in patching such vulnerabilities.

“To date, operating system providers, original equipment manufacturers and mobile service providers have responded to address vulnerabilities as they arise,” the FCC said in a statement announcing the inquiry. “There are, however, significant delays in delivering patches to actual devices — and that older devices may never be patched.”

The FTC, which has the authority to study issues of public interest, asked eight companies to provide information: Apple, Blackberry, Google, HTC, LG Electronics, Microsoft, Motorola Mobility and Samsung Electronics America.

The agency is asking each to provide details about devices sold over the last three years, whether they’ve been hit by bugs and whether — and when — the company patched the security hole.

It’s not just about the operating system vendors and hardware makers, though. Carriers in the U.S. play a huge role and often have the final say on what updates make it onto consumers’ phones.

The FCC made a similar inquiry of the major wireless carriers: AT&T, Verizon Wireless, T-Mobile, Sprint, US Cellular and TracFone wireless.

The CTIA wireless industry’s trade group issued a statement saying that customer security is a top priority for carriers, and that mobile operators make updates available as soon as they’re “thoroughly tested.”

The speed and frequency of security updates has long been an issue for the industry. While Apple has been able to get broad leeway in pushing out updates, the Android industry has tended toward a slow pace in which Google develops overall operating system patches, as well as feature upgrades, which are then tested and customized by hardware makers, a process which can take months. Finally, mobile carriers have to decide whether, or if, to make such updates available based on the age of the phone and the importance of the update.

Security-focused updates have a somewhat better track record, but vulnerabilities found for older versions of Android often still are left unpatched.

This article originally appeared on Recode.net.

See More:

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh