I recently blogged about Google and Samsung starting to offer regular security patches for their Android devices.
Over on ars technica, Ron Amadeo has an interesting article describing why the current Android ecosystem is not conducive to the quick and widespread distribution of security fixes and why this needs to change, urgently.
At this point in time it seems that in order to be halfway secure, one has to basically root the phone and run well-tested and well supported distribution like CyanogenMod. While I - and presumably most, if not all, readers of this blog - certainly have the technical know how and abilities to root a phone, that’s a poor approach to security because most people either will not or cannot root their phones.