Live data from Hacker News

There are over a billion outdated Android devices in use

danluu.com

161–170 of 474 posts

Re: There are over a billion outdated Android devices in use

#161

Earlier quoted context omitted.

The only impact? You are a walking vulnerability. KRACK, Blueborne, just to name a few recently highly publicized vulnerabilities. You are like the perfect exploit, just waiting to get pwned. You are, Bill Harper.

I, like the parent poster, am running the latest update for my phone. Yes, I know I'm a walking vulnerability, but short of purchasing a new phone, there is nothing I can do about it. IIRC, updates for my device were cut off before it was even out of warranty , and I'm sorry, I'm not dropping — I can't drop — $600 every year and a half on new hardware just to get new software. Vendors need to support devices for the…

It's really not your fault. But collectively we should care more about this and hold vendors accountable for continued security of devices they sold us.

AFAIK Microsoft and Red Hat are the only ones who do a good job of patching security bugs on older OSes.

Re: There are over a billion outdated Android devices in use

#164
post #154

Earlier quoted context omitted.

They have no incentives to do so. I would like Samsung to make it into a business. Have folks pay 5 dollars per year if they want to get ongoing security updates for older devices. I would pay in an instant.

For reference Red Hat charges around $425/yr for extended support. Obviously the situation is different because Red Hat has a lot more software to support but they also have a fewer products and more customers that care enough to buy it. But I think the upshot is that a $5/yr extended support contract is a bit of a pipedream. Just as an order of magnitude estimate we're assuming that it's about 100 times more effort…

Exactly. Why did you think Oracle wanted to muscle in on that?

Re: There are over a billion outdated Android devices in use

#165
post #100

Earlier quoted context omitted.

It's remarkable how fishy the whole ecosystem around Android ROMs and flashing tools really is. 95% of the posts are in barely comprehensible English. Seemingly every guide tells you to run a random binary from a file sharing host or generic domain. As a rule, source code is non-existent. Downloads are attributable to a forum handle in the best case. Oh and you have to run it with elevated privileges to both your hos…

Yep. It's better than it was - most XDA developers understand what a GPL violation is. I imported my Galaxy S8+ to save over $400AUD on retail. This meant I needed to find a ROM on an obscure site to flash to the phone using a stolen (?) piece of factory software. I can only trust my phone because a Samsung in default configuration won't accept a "modified" update - only one from and signed (?) by Samsung themselves.…

>using a stolen (?) piece of factory software

You mean ODIN! That's probably leaked. Many good memories of that tool.

Re: There are over a billion outdated Android devices in use

#166

I didn't see it in the article, and so I wonder what the country breakdown for this might be. I get the impression that in the developing world, where android has really taken off, the ability to receive updates is diminished.

Importantly, in China, the biggest Android market, none of the phones access the Play store, so that entire country will be omitted from the data. I'll bet they're not getting updates either.

Re: There are over a billion outdated Android devices in use

#168
post #20

Earlier quoted context omitted.

Yes, I think user apathy has to be a big part of it. I have a 2012 iPhone5 with iOS 6.1.3 still on it. I never upgraded it. When iOS 7 came out, all the news reports said it killed the battery. Same with iOS 8, 9, and finally iOS X. Yes, I assume that eventually, iOS point release 7.x.x fixed the battery issue but I don't care to keep visiting news websites to figure out which exact version is finally "safe" to upgra…

> (As trivia, I also notice that iPhone5s on ebay that still have iOS 6 sell for a slightly higher premium.) This is probably because it has a better jailbreak scene around it than newer versions of iOS. Also, just as an FYI, the latest version of iOS is 11, and they're not numbered using roman numerals.

The latest version of iOS for the iPhone 5 is certainly 10. 11 dropped support for 32-bit phones, and the iPhone 5, along with the 5c, were the last 32-bit iPhones.

Re: There are over a billion outdated Android devices in use

#169

Earlier quoted context omitted.

As someone who goes as long as possible without performing updates, this is exactly the reason why. Example: Last time I updated my iPhone, the music app got an update and now they are trying to shove iCloud down my throat. Not to mention needless UI changes when I was more than satisfied with how it was before.

I understand this entirely, but there are some pretty bad iOS vulnerabilities out in the wild now (e.g. KRACK wpa2). It’s pretty dangerous to avoid updates nowadays. I think what needs to happen across the industry is a complete decoupling of “feature” from security patching. Too many people are exposed because of exactly the kind of unwanted UI upgrades you describe.

Dangerous?

What's the worse that could happen?

Re: There are over a billion outdated Android devices in use

#170

Earlier quoted context omitted.

I understand this entirely, but there are some pretty bad iOS vulnerabilities out in the wild now (e.g. KRACK wpa2). It’s pretty dangerous to avoid updates nowadays. I think what needs to happen across the industry is a complete decoupling of “feature” from security patching. Too many people are exposed because of exactly the kind of unwanted UI upgrades you describe.

Dangerous? What's the worse that could happen?

1. Ability to passively decrypt network activity (KRACK).

2. Ability to throw a fully persistent implant onto the device (via Wi-Fi exploit + pivot to AP kernel exploit)

Post reply on HN