Live data from Hacker News

Android overtakes Windows as the internet’s most used operating system

techcrunch.com

311–320 of 417 posts

Re: Android overtakes Windows as the internet’s most used operating system

#311
post #296

Earlier quoted context omitted.

Those things you listen actually make less work for the manufacturers, and speedy updates make more work - that solves the mystery for me at least.

Oh, its not a mystery at all. Its just odd to come across people (in general, not you) who still think an advertising company would care all that much about their users (who are not their customers anyway). But yes, they're quite far from being the worst in this aspect.

Well I'm guilty of that same conception too. Why are the two at odds? Google wants to own the best platform for users out there. Engineers want to work on the best, app developers want to work on the best, and users want to use the best they can afford.

Re: Android overtakes Windows as the internet’s most used operating system

#312
post #279

Earlier quoted context omitted.

> you should have started on it years ago As somebody who has been following Android for a while, this statement is incredibly unfair. The Android ecosystem is huge and remarkably safe. For those actually interested in the details, the Android security team releases annual security reviews, and the report for 2016 was just released: https://security.googleblog.com/2017/03/diverse-protections-... The tldr: the number…

Citing Google's blog post for Android security is not very convincing. If Android is so secure, why are we seeing (often more frequently than) weekly headlines on Android security woes, often containing something like "millions of devices affected" (and often enough, no fix in sight)? Also, quote from linked blog post: > only 0.05 percent of devices that downloaded apps exclusively from Play contained a PHA. 1. What…

Most Android issues arise due to either vendors which don't update the devices, or malicious vendors that actually pre-install malware (beware of phones ordered from aliexpress etc ...).

Android is open source, after all. Not much Google can do there.

Re: Android overtakes Windows as the internet’s most used operating system

#313
post #25

I guess this means we can officially stop hating on Microsoft for having such a lax attitude towards security, considering their last OS to suffer from that attitude was released 16 years ago, and it accounts for less than 3% of present day traffic according to statcounter.com Meanwhile according to the same stats, Android sits around 37.9%, and I have to wonder just how many of those devices are still impacted by fo…

"Google Security Team, here's your call to stop pontificating on the Project Zero blog and throwing cheap muck at Microsoft. You've got an even bigger and more complicated mess to clean up, you dug the hole yourself, it's going to take you longer, and you should have started on it years ago"

Is Linus Torvalds criticized as strongly as this, when many of the hundreds of Linux distro maintainers fail to ship kernel security patches speedily? No? Google puts a lot of effort into securing Android and patching vulns quickly, but ultimately it is the fault of the MANUFACTURERS and OPERATORS for failing to update their commercial works derived from Android OS.

Re: Android overtakes Windows as the internet’s most used operating system

#314
post #279

Earlier quoted context omitted.

Citing Google's blog post for Android security is not very convincing. If Android is so secure, why are we seeing (often more frequently than) weekly headlines on Android security woes, often containing something like "millions of devices affected" (and often enough, no fix in sight)? Also, quote from linked blog post: > only 0.05 percent of devices that downloaded apps exclusively from Play contained a PHA. 1. What…

In today's media environment is it strange scary-sounding headlines are published without deep analysis or actual evidence to back them up? But headlines saying devices are vulnerable is not evidence that the Android users are adversely impacted by PHA. On the other hand, I referenced a report with actual numbers of devices impacted. Obviously you should be skeptical, but as you point out, if millions of devices affe…

> ... scary-sounding headlines are published without deep analysis or actual evidence to back them up...

Scary-sounding headlines, sure. But there usually is actual evidence.

> I referenced a report with actual numbers of devices impacted.

No, there is no "actual numbers of devices impacted". A number 1.4 billion is thrown out to impress; the pool of devices to which their analysis applies is much smaller, and of which only a percentage is given.

> if millions of devices affected is true, shouldn't we be seeing millions of instances of Android spam, remote roots, SMS fraud, botnets, etc.?

First, what you mentioned do exist. Maybe not in large numbers (not sure), but there's no guarantee they're not rising. Secondly, there are plenty of easier and more profitable channels for hackers these days. Please don't equate vulnerabilities not being exploited with being invulnerable.

> There is only so much Google can reasonably do.

Changing the subject? I was responding to "The Android ecosystem is huge and remarkably safe", and specifically how you quoted the blog post to back that up.

> ... in the end Android users are surprisingly safe.

Webcam users are surprisingly safe too. Not realizing their webcams are DDoS'ing some poor website right now, or their video feed is being streamed online.

Re: Android overtakes Windows as the internet’s most used operating system

#315
post #185

Earlier quoted context omitted.

Just to play devil's advocate: Windows became the dominant platform when it had terrible security. Android became the dominant platform when it had terrible security. Maybe people don't care that much about security vs other features. At it's low point, Windows security was a lot worse than Android security. At one point, a fresh Windows XP machine plugged into the Internet would be compromised within a couple of min…

I don't really understand this metric at all. I've heard it colloquially, but I highly doubt anyone was scanning IP address ranges so often that you could be passively attacked on the internet without any interaction by two minutes in. Even more so, people are often behind NAT, which acts as a good firewall on its own. Maybe it's related to browsing habits? IE? I mean, you aren't going to get hit by a drive-by attack…

People in this thread don't remember the NET SEND spam from Windows Messenger. (Which was a system service and had absolutely nothing to do with MSN Messenger)

You could basically do "NET SEND 12.34.56.78 my spam message" and it would appear on the screen of your victim.

http://blogopod.com/image/2008/net-send-spam-big.gif

Re: Android overtakes Windows as the internet’s most used operating system

#316
post #296

Earlier quoted context omitted.

Those things you listen actually make less work for the manufacturers, and speedy updates make more work - that solves the mystery for me at least.

Oh, its not a mystery at all. Its just odd to come across people (in general, not you) who still think an advertising company would care all that much about their users (who are not their customers anyway). But yes, they're quite far from being the worst in this aspect.

They can care for selfish reasons. If android is completely riddled with bugs and is constantly compromised users will use a different phone system. Even outside security issues being able to roll out new features to people keep them from switching to iOS or Windows Phones.

Re: Android overtakes Windows as the internet’s most used operating system

#317
post #314

Earlier quoted context omitted.

In today's media environment is it strange scary-sounding headlines are published without deep analysis or actual evidence to back them up? But headlines saying devices are vulnerable is not evidence that the Android users are adversely impacted by PHA. On the other hand, I referenced a report with actual numbers of devices impacted. Obviously you should be skeptical, but as you point out, if millions of devices affe…

> ... scary-sounding headlines are published without deep analysis or actual evidence to back them up... Scary-sounding headlines, sure. But there usually is actual evidence. > I referenced a report with actual numbers of devices impacted. No, there is no "actual numbers of devices impacted". A number 1.4 billion is thrown out to impress; the pool of devices to which their analysis applies is much smaller, and of whi…

> On the other hand, I referenced a report with actual numbers of devices impacted.

Really. "We can't trust Google (because!) so ignore the detailed report with actual data and instead remember all those scary headlines!"

This sort of conspiratorial thinking is so strange every time I see it I do a double take.

That report is indeed remarkable given the number of devices. If they're seeing penetration rates of .05 percent that means most Android users will never see a virus or a trojan. It is a bit disturbing the way this was achieved though: by centralizing application distribution in a store. It would be great if there was a decentralized way to accomplish the same.

Re: Android overtakes Windows as the internet’s most used operating system

#318
post #205

Earlier quoted context omitted.

> They take the AOSP source code that Google drops and then they add all of their source code and then build and distribute their own version of Android that only they can update. Yep that's a insanely huge design flaw, coherent with: "Google needs to be updating their own software independently of manufacturer-specific components."

So an OEM being allowed to build their own OS is a huge design flaw? Is Debian also responsible for Ubuntu's security flaws?

It isn't "their own OS". It's Google's OS, which is explicitly and directly controlled by Google's contracts, which you continue to pretend do not exist. It is a single platform, and it is by no means an open source one. If it was, it wouldn't require the explicit approval of a single corporate entry to distribute it or any updates to it.

Re: Android overtakes Windows as the internet’s most used operating system

#319
post #13

Earlier quoted context omitted.

Don't forget that the proprietary Google Play Services are required by more and more apps and that Google is doing everything it can to push these services to the largest number of devices by weaving some sort of web of interdependency.

I agree it isn't perfect, but services that phone home to google servers can't realistically be open source. Google is pushing them insofar as it is trying to make them better. I think it's still a far cry from the state of affairs on iOS or MacOS, and the fact that you can fork it if you are willing to replicate those apis is still reassuring.

> I agree it isn't perfect, but services that phone home to google servers can't realistically be open source.

Yes, they can. Google makes a conscious choice not to make them open source. There's no fundamental law or anything saying that they can't.

I think the better question is: Why do those services need to phone home? There are plenty of apps that should work just fine without doing that, but don't.

Re: Android overtakes Windows as the internet’s most used operating system

#320
post #25

I guess this means we can officially stop hating on Microsoft for having such a lax attitude towards security, considering their last OS to suffer from that attitude was released 16 years ago, and it accounts for less than 3% of present day traffic according to statcounter.com Meanwhile according to the same stats, Android sits around 37.9%, and I have to wonder just how many of those devices are still impacted by fo…

>Google Security Team, here's your call to stop pontificating on the Project Zero blog and throwing cheap muck at Microsoft.

Yes, because it's better to let hackers continue to exploit Windows than inform users and MS that their OS is at risk.

>You've got an even bigger and more complicated mess to clean up, you dug the hole yourself, it's going to take you longer, and you should have started on it years ago.

Security patches are given to OEM's 1 month before they are publicly released. Google patches their devices promptly. Unless I'm mistaken, I'm not aware of technology that allows Google to take an OEM's source code, apply patches, build it, sign it and then release it to all of the OEM's customers.

Post reply on HN