Live data from Hacker News

Android overtakes Windows as the internet’s most used operating system

techcrunch.com

301–310 of 417 posts

Re: Android overtakes Windows as the internet’s most used operating system

#301

Earlier quoted context omitted.

It kind of is Google's fault. Most people associate any version of Android with Google. Manufactures that don't update their phones causes harm to both the manufacture's image and Google image. Personally, I place all the blame on Google for not making the upgrades possible from their side. It should be easy to upgrade the core operating system as easy as updating Windows, OSX, and Linux.

I dunno. Enthusiasts may track the versions coming out of Google HQ. But for most updating is a hassle rather than something they look forward to. This because it means downtime for their device, and if the update fails it may leave them with a bricked device (chance is small, but it is still in the back of their mind). For most people a computer, a phone, or a tablet is an appliance.

iOS updates are something that seems like many people look forward too. If Android updates were as unobtrusive as updates to iOS (even Windows 10 is getting closer to unobtrusive updating), then there wouldn't be much of an issue there.

We are getting closer to the point where being secure and up to date is almost painless. That should be our goal in the tech industry.

Re: Android overtakes Windows as the internet’s most used operating system

#302
post #279

Earlier quoted context omitted.

> you should have started on it years ago As somebody who has been following Android for a while, this statement is incredibly unfair. The Android ecosystem is huge and remarkably safe. For those actually interested in the details, the Android security team releases annual security reviews, and the report for 2016 was just released: https://security.googleblog.com/2017/03/diverse-protections-... The tldr: the number…

Citing Google's blog post for Android security is not very convincing. If Android is so secure, why are we seeing (often more frequently than) weekly headlines on Android security woes, often containing something like "millions of devices affected" (and often enough, no fix in sight)? Also, quote from linked blog post: > only 0.05 percent of devices that downloaded apps exclusively from Play contained a PHA. 1. What…

>weekly headlines on Android security woes

stagefright is the last major Android vulnerability I'm aware of. Do you have sources for these? In my experience it's far less than weekly. Maybe yearly at most.

Re: Android overtakes Windows as the internet’s most used operating system

#303
post #48

Earlier quoted context omitted.

Is that our problem or Google's? You can point fingers at 50 different companies in the ecosystem, or you can collectively point the finger at the root cause. By the topic of this article, they're no longer the underdog when it comes to dictating terms to device vendors, they're the biggest shop in town and there's no reason the vulns-frozen-for-life-of-device model should continue to be adhered to.

This represents such a fundamental misunderstanding of the power structures i almost don't know where to begin. Suffice to say, if it was as easy as waving the magic wand you think it is, it would have happened already. Instead, if you tried to wave it, handset makers would have walked and just done something else. Heck, some did! Besides, why stop at Google? Why not blame the carriers for devices like this be on the…

I mostly agree with you (Mencken's famous Quote about complex problems comes to mind), but I don't think we shouldn't assume no responsibility on Google's end either. This whole economy of "throw-away devices" without much more than a couple of very late patches seems to have been facilitated in ordes to boost Android's adoption - which arguably worked out for them.

Sadly this also leaves us with the current sorry state of affairs. I don't think much "could've" and "would've" would be helping there, but I would very much like to see a major economic force guaranteeing some common grounds for devices. Imagine what an "IBM clone era" of phones could mean - all it would take would be a common ground w.r.t booting and a couple of drivers.

Sometimes I'm really left wondering why we can't have such nice things...

Re: Android overtakes Windows as the internet’s most used operating system

#304
post #279

Earlier quoted context omitted.

> you should have started on it years ago As somebody who has been following Android for a while, this statement is incredibly unfair. The Android ecosystem is huge and remarkably safe. For those actually interested in the details, the Android security team releases annual security reviews, and the report for 2016 was just released: https://security.googleblog.com/2017/03/diverse-protections-... The tldr: the number…

Citing Google's blog post for Android security is not very convincing. If Android is so secure, why are we seeing (often more frequently than) weekly headlines on Android security woes, often containing something like "millions of devices affected" (and often enough, no fix in sight)? Also, quote from linked blog post: > only 0.05 percent of devices that downloaded apps exclusively from Play contained a PHA. 1. What…

In today's media environment is it strange scary-sounding headlines are published without deep analysis or actual evidence to back them up? But headlines saying devices are vulnerable is not evidence that the Android users are adversely impacted by PHA.

On the other hand, I referenced a report with actual numbers of devices impacted. Obviously you should be skeptical, but as you point out, if millions of devices affected is true, shouldn't we be seeing millions of instances of Android spam, remote roots, SMS fraud, botnets, etc.?

Yes, it is true that some users sideload, and threats to Android users vary a lot by country. There is only so much Google can reasonably do, and this is appropriate given Android is open source and has so many participants (device vendors, carriers, app stores, etc.). But it turns out with good integration with the developers, the distribution platform, and regular check ups, you can do a decent job at protecting your users.

You can also compare to other platforms and recall how devastating actual malware on Windows was, and how long Microsoft struggled (and still struggles) to protect their users. In Android, yes there are many vulnerabilities like Stagefright found, but in the end Android users are surprisingly safe.

Re: Android overtakes Windows as the internet’s most used operating system

#305
post #185

Earlier quoted context omitted.

Just to play devil's advocate: Windows became the dominant platform when it had terrible security. Android became the dominant platform when it had terrible security. Maybe people don't care that much about security vs other features. At it's low point, Windows security was a lot worse than Android security. At one point, a fresh Windows XP machine plugged into the Internet would be compromised within a couple of min…

I don't really understand this metric at all. I've heard it colloquially, but I highly doubt anyone was scanning IP address ranges so often that you could be passively attacked on the internet without any interaction by two minutes in. Even more so, people are often behind NAT, which acts as a good firewall on its own. Maybe it's related to browsing habits? IE? I mean, you aren't going to get hit by a drive-by attack…

Ah you cute youngling.

https://en.wikipedia.org/wiki/Blaster_(computer_worm)

At the peek couple of months your computer would BSOD _during_ installation process, right after initializing network interface and RPC service.

Re: Android overtakes Windows as the internet’s most used operating system

#306
post #279

Earlier quoted context omitted.

> you should have started on it years ago As somebody who has been following Android for a while, this statement is incredibly unfair. The Android ecosystem is huge and remarkably safe. For those actually interested in the details, the Android security team releases annual security reviews, and the report for 2016 was just released: https://security.googleblog.com/2017/03/diverse-protections-... The tldr: the number…

Citing Google's blog post for Android security is not very convincing. If Android is so secure, why are we seeing (often more frequently than) weekly headlines on Android security woes, often containing something like "millions of devices affected" (and often enough, no fix in sight)? Also, quote from linked blog post: > only 0.05 percent of devices that downloaded apps exclusively from Play contained a PHA. 1. What…

> 1. What percentage of Android devices download apps exclusively from Play?

The entirety of China doesn't even have Google Play Store.

Re: Android overtakes Windows as the internet’s most used operating system

#307
post #185

Earlier quoted context omitted.

Just to play devil's advocate: Windows became the dominant platform when it had terrible security. Android became the dominant platform when it had terrible security. Maybe people don't care that much about security vs other features. At it's low point, Windows security was a lot worse than Android security. At one point, a fresh Windows XP machine plugged into the Internet would be compromised within a couple of min…

I don't really understand this metric at all. I've heard it colloquially, but I highly doubt anyone was scanning IP address ranges so often that you could be passively attacked on the internet without any interaction by two minutes in. Even more so, people are often behind NAT, which acts as a good firewall on its own. Maybe it's related to browsing habits? IE? I mean, you aren't going to get hit by a drive-by attack…

Same thing applies today. Just fire up a DO instance and tail -f access.log

You will see random scanning attempts within minutes. Same principle , minus the effectiveness.

Re: Android overtakes Windows as the internet’s most used operating system

#308
post #279

Earlier quoted context omitted.

Citing Google's blog post for Android security is not very convincing. If Android is so secure, why are we seeing (often more frequently than) weekly headlines on Android security woes, often containing something like "millions of devices affected" (and often enough, no fix in sight)? Also, quote from linked blog post: > only 0.05 percent of devices that downloaded apps exclusively from Play contained a PHA. 1. What…

>weekly headlines on Android security woes stagefright is the last major Android vulnerability I'm aware of. Do you have sources for these? In my experience it's far less than weekly. Maybe yearly at most.

I could be exaggerating a little bit, but do check https://arstechnica.com/security/.

Re: Android overtakes Windows as the internet’s most used operating system

#309

Earlier quoted context omitted.

Writing code, outside of spaghetti BASIC and similar, is a full time job. It requires hours and hours of thinking and planning. People already have full time jobs, sometimes two or more. The last thing they want is another, likely unpaid one, when they come home and sit down before the computer.

This is the biggest mistaken belief of the programming industry. Where we're headed is multi-level architectures. At the bottom is what you think of as "all programming". It's low level code, with manual deployment, using a wide range of fairly arcane tools. You need to be a professional to do it. What is slowly emerging, which you suggest is impossible, is a layer on top of that. It is written in highly constrained…

> This is the biggest mistaken belief of the programming industry.

Actually I think what you're saying is the biggest mistaken belief in the programming industry. The industry has been chasing the dream of making programming accessible for everyone for as long as computers have existed. This was the reasoning behind COBOL, BASIC, and Scratch.

> You can't import random libraries, and you can't write spaghetti code, because you are writing in a highly constrained DSL. It's still real code. It's still a Turing machine.

If it's Turing complete then someone can and certain would write spaghetti code. Every constrained environment that ever existed for lay people to use ends up in the hands of frustrated programmers.

> There's no reason the marketing team can't write this file.

There's no reason why they couldn't just drag and drop such logic and prefer to do it as well. Most people have trouble understanding how to work with Turing complete languages to accomplish advanced tasks. Programmers aren't purposely trying to make their environments difficult -- in fact making everything as easy as possible has been the goal since the beginning.

> You could do the "hours of thinking and planning" so that your colleagues could write the high level business code.

Honestly that High level business code that you sort of dismiss is the hard part. Knowing to gather requirements and codify them is the job a programmer. It's a job in itself different from other jobs. It will never be a job for non-programmers and maybe not even junior programmers.

Re: Android overtakes Windows as the internet’s most used operating system

#310
post #291

Earlier quoted context omitted.

> you should have started on it years ago As somebody who has been following Android for a while, this statement is incredibly unfair. The Android ecosystem is huge and remarkably safe. For those actually interested in the details, the Android security team releases annual security reviews, and the report for 2016 was just released: https://security.googleblog.com/2017/03/diverse-protections-... The tldr: the number…

You mean the same report where they cleverly omit the actual situation about updates across Android devices, by only mentioning flagship devices sold in 2016?

The purpose of the report is not say what the update situation is across Android devices, Google has a monthly dashboard for that: https://developer.android.com/about/dashboards/index.html

If you're interested in the Android update situation, Adrian Ludwig just gave a talk at Next, the Google cloud conference about it (he even references the Wikileaks CIA breach): https://www.youtube.com/watch?v=Zm6ziX5pqt8

He talks about the task starting with only 5 OEMs to keep their flagships updated. And you start to see the insane complexity of running the update train: this meant 29 devices. Multiply by the 351 carrier partners, which goes to 5000+ builds and variants. That all need to be tested by all the parties. =/

Post reply on HN