Android update for Samsung strengthens security against scams and hackers

Android, telefone

Android, telefone - Primakov/shutterstock.com

Samsung is rolling out a robust Android system update to its flagship Galaxy smartphones that introduces an innovative fake call detection feature. This advancement, powered by Rich Communication Services (RCS) technology, aims to combat sophisticated scams that use artificial intelligence voice cloning, offering an extra layer of security for millions of users.

A new security barrier against voice fraud with artificial intelligence

The fake call detection feature, described by Google as an industry first, represents a crucial step in defending users. Although the system was initially made available to Pixel device owners, its implementation on Samsung Galaxy models marks the expansion of an essential security improvement, covering a much larger user base.

The functionality comes at an important time, as the threat of scams that use impersonation and voice manipulation has grown significantly. The expansion to third-party devices confirms that this most significant security update is moving beyond Google’s proprietary hardware.

The mechanism behind checking fake calls via RCS

Unlike methods that analyze audio during a call, the new function operates silently and encrypted. It performs end-to-end cryptographic verification using RCS, the protocol that has replaced SMS messages on most modern Android devices.

When a saved contact initiates a call, the Google Phone app sends a silent, real-time confirmation token to the recipient’s device via the RCS network. If this token is missing, indicating that the call may come from VoIP software that spoofs the number, the receiver’s phone directly checks the contact’s real device.

If the original device confirms that no call is in progress, a visual alert appears on the screen, advising the user to end the call immediately. This method is not vulnerable to convincing voice cloning, as the device’s identity is checked even before the voice is evaluated, and not the content of the conversation.

For the feature to work fully, some conditions are necessary:

  • Both the caller and the receiver must use the Google Phone app as their default dialer.
  • You must have Google Contacts and Google Messages installed.
  • Both devices must have an active RCS connection.
  • The feature does not protect against spoofed calls from contacts using different dialing apps, with RCS disabled, or calling from an iPhone.

Google built this tool on top of the open RCS standard, seeking to encourage other phone app developers and device manufacturers to adopt the same verification mechanism, which would expand its protective reach over time. Detection is enabled by default on any Android 12 or later device that uses Google Phone as its primary dialer.

Understand the differences between the new protection in relation to other existing systems

Google’s device-level approach differs significantly from other call authentication frameworks. One example is STIR/SHAKEN, an FCC-required network-level call authentication framework that verifies carrier routing.

However, experts point out that STIR/SHAKEN does not completely solve the problem of accurate caller identification. Voice service providers can rent thousands of phone numbers to telemarketers and scammers, who technically comply with STIR/SHAKEN while still forwarding fraudulent calls.

In contrast, Google’s method asks whether the specific hardware registered to the contact is actually making the call. A spoofed number, even if it passes all operator authentication steps, fails this check, as the spoofed number does not have access to the cryptographic token that only the real device can send.

Other new features coming to Samsung devices with the improvement package

In addition to the crucial fake call detection, the new Android update package brings other important improvements for Samsung device users.

Among them, the expansion of Quick Share interoperability with Apple’s AirDrop stands out. Now, users of several Samsung Galaxy models, as well as other manufacturers such as OnePlus, Xiaomi, Vivo and Honor, can send and receive files directly from iPhones, iPads and macOS devices through the Quick Share interface. This functionality eliminates the need for third-party applications to exchange data between platforms.

Another addition is a wardrobe tool powered by Gemini, Google’s artificial intelligence, which is rolling out to Google Photos. This feature promises to offer new possibilities for organizing and interacting with images.

The global impact of identity scams and the importance of innovation

The arrival of these new security protections comes in a scenario where identity fraud represents a global threat of major proportions. INTERPOL, in a recently conducted global financial fraud threat assessment, linked impersonation fraud — the specific target of fake call detection — to global losses estimated at $442 billion in the previous year.

This alarming number highlights the urgency of innovative technological solutions to protect consumers. The integration of an RCS-based call verification system into millions of Samsung Galaxy devices is a significant step towards mitigating risks and safeguarding users’ information and finances.