On February 28, 2018, the Federal Trade Commission (“FTC”) issued a report discussing security updates for mobile devices. The report stems from information the FTC collected from eight mobile device manufacturers — Apple, Blackberry, Google, HTC, LG, Microsoft, Motorola, and Samsung — and from information the Federal Communications Commission (“FCC”) collected from mobile carriers in May 2016.
The FTC found, among other things, that:
- The security update process is complex and time consuming, largely due to the customization of third-party operating system software at the device level. This increases the time and cost to develop, test, and deploy updates.
- Efforts have been made to streamline the security update process, but adoption of these efforts is uneven.
- Ongoing support and update schedules are variable. Most manufacturers do not provide formal support policies, relying instead on informal assessments of the device’s age, cost to support, vulnerability severity, and other factors. These manufacturers point to unpredictable variables, such as device popularity, as the reason they are unable to commit to update support schedules. However, the FTC noted that manufacturers who develop their own operating systems tend to commit to longer support periods because there is less customization of the system for their devices.
- Several manufacturers do not provide specific information about their support periods and updates to consumers.
- Manufacturers tend to prioritize new products for update support, specifically more expensive and more popular products.
- Many manufacturers do not maintain regular records about update support and other security-related decisions.
- Carrier involvement in the security update process can provide stability, but may also lead to delays.
In response to these findings, the FTC recommends that:
- Government, industry, and advocacy work together to educate consumers about the update process.
- Industry “start with security” by embedding security into design and support culture, including: ensuring that mobile devices receive security updates for a period of time consistent with consumers’ reasonable expectations; considering security updates during the product design process; considering whether to document security update support practices in a formal security policy and provide training to personnel involved in the process.
- Industry consider keeping more consistent records about security support topics, analyzing the data from those records to improve device security, and sharing data with industry partners.
- Industry continue to streamline the security update process, specifically with respect to bundling, testing, and deployment.
- Device manufacturers consider providing consumers with more information about their security update support practices, including adopting minimum guaranteed support periods for devices. The FTC reminds manufacturers that any information provided to consumers about security update support should be truthful, non-misleading, and supported by a reasonable basis so as not to violate Section 5 of the FTC Act.