This brief considers the various stakeholders in today's mobile device
ecosystem, and analyzes why widely-deployed hardware security primitives
on mobile device platforms are inaccessible to application developers
and end-users. Existing proposals are also evaluated for leveraging such
primitives, and proves that they can indeed strengthen the security
properties available to applications and users, without reducing the
properties currently enjoyed by OEMs and network carriers. Finally, this
brief makes recommendations for future research that may yield practical
and deployable results.