Live data from Hacker News

There are over a billion outdated Android devices in use

danluu.com

191–200 of 474 posts

Re: There are over a billion outdated Android devices in use

#191

Earlier quoted context omitted.

1. Ability to passively decrypt network activity (KRACK). 2. Ability to throw a fully persistent implant onto the device (via Wi-Fi exploit + pivot to AP kernel exploit)

Most phones already come with two persistent implants - the user-antagonistic OS, and the baseband processor! I'm all for trusting computing devices to act as one's agents, but attempting to do so with anything resembling a modern mobile phone is barking up the wrong tree. Even though just having one means taking the location-tracking hit from negligently designed cellular protocols, further exposure can be mitigated…

Your phone will probably turn up in a botnet soon enough, but atleast you had the moral high ground.

Re: There are over a billion outdated Android devices in use

#192
post #191

Earlier quoted context omitted.

Most phones already come with two persistent implants - the user-antagonistic OS, and the baseband processor! I'm all for trusting computing devices to act as one's agents, but attempting to do so with anything resembling a modern mobile phone is barking up the wrong tree. Even though just having one means taking the location-tracking hit from negligently designed cellular protocols, further exposure can be mitigated…

Your phone will probably turn up in a botnet soon enough, but atleast you had the moral high ground.

Oh no, not a month's allocation of mobile data down the drain!

An impersonal passive botnet would likely do less damage than status quo "apps" that are built to siphon as much personal data as possible.

Never mind these few Mifi devices that I have - default configs that listen on wan telnet with static passwords! Well known domestic manufacturer, not worth attempting to report - the manufacturer obviously did not care, has long moved on, and there's countless other models with the same problem.

The panacea of every node being secure with an identifiable owner fell apart long ago. You can either cling to that belief in a fundamentalist manner (and prop up the totalitarians who wish to track communication ever more). Or you can work on understanding how non-technical people actually attempt to moderate their own exposure to these insecure-by-design surveillance devices.

Re: There are over a billion outdated Android devices in use

#193
post #71

Earlier quoted context omitted.

That's bad for developers, but good for consumers. Is it? I'm a developer --- and a consumer, as are most --- and have always kept to the principle of as much compatibility as possible, mostly by not gorging on new features for the sake of new features, and a "do what you can with what you have" approach. To me, spending a little extra effort to get much more compatibility is well worth it, since I've been on "the ot…

The QA effort to support 3-4 of the most recent OS’s isn’t “a little extra effort.” It can get pretty expensive, too, since you may have to have devices for all supported OS versions and possibly idioms (e.g. iPhone, iPad).

If only Android devs only had to think about 3-4 of the most recent OSes...

There are outliers in either direction, but these days the minimum supported version tends to be either API Level 19 if you're conservative, with a stead shift towards ... API Level 21. For reference, Oreo is API Level 26.

Re: There are over a billion outdated Android devices in use

#194

Earlier quoted context omitted.

Windows driver API has been far from stable from Windows Vista. One of my computers came with Windows Vista (a 2009 Dell Pentium Dual Core - not the Core 2 Duo I referenced) and it still runs Windows 10. Microsoft provided drivers for the standard PC hardware that was in my 2006 Core Duo Mac Mini and Windows 7 recognized all of my hardware - usb, sound, graphics, Bluetooth, Ethernet etc. Microsoft goes out of its way…

> But why are printer drivers still a thing? Apple introduced AirPrint for iOS 4 back in 2010 and for MacOS a few years later. Have you looked at the unimaginable amount of crap a typical Windows printer driver forces upon you? It's not just the driver, it's usually also a stripped down license of some image editor, an "update agent" (because Windows 7 does not have an "app store" or a centralized driver distribution…

Your problem may be more your choice of vendors than anything else. HP's big printers (e.g. M600 family) are still pretty nice, but I've started to avoid them for anything smaller, and god help you if you look at the truly low print volume stuff from them.

Re: There are over a billion outdated Android devices in use

#195

Earlier quoted context omitted.

Windows driver API has been far from stable from Windows Vista. One of my computers came with Windows Vista (a 2009 Dell Pentium Dual Core - not the Core 2 Duo I referenced) and it still runs Windows 10. Microsoft provided drivers for the standard PC hardware that was in my 2006 Core Duo Mac Mini and Windows 7 recognized all of my hardware - usb, sound, graphics, Bluetooth, Ethernet etc. Microsoft goes out of its way…

Have you looked at the unimaginable amount of crap a typical Windows printer driver forces upon you? Yes. I go out of my way to run a clean crap free Windows PC. Even going as far as either buying from the business line of laptops or buying from the Microsoft store. But the minute I install a printer driver.... It's even worse for people like my parents, they search online for printer driver and usually end up downlo…

Check printer specs first and select something with built in PCL or (better) Postscript support. With native Postscript you may even be able to just get a PPD file as the "driver."

Won't help as much if you want color though, particularly inkjet color.

And for your parents, see if they're putting the current year on searches - on Bing and DDG that ends (or did end recently) in much worse results because the original sites often don't include dates but malicious ones have all the same keywords plus the year. In my recent experience adding the year meant > 90% malware results on the first page.

Google was much better about this a month or two back.

Re: There are over a billion outdated Android devices in use

#196
post #191

Earlier quoted context omitted.

Your phone will probably turn up in a botnet soon enough, but atleast you had the moral high ground.

Oh no, not a month's allocation of mobile data down the drain! An impersonal passive botnet would likely do less damage than status quo "apps" that are built to siphon as much personal data as possible. Never mind these few Mifi devices that I have - default configs that listen on wan telnet with static passwords! Well known domestic manufacturer, not worth attempting to report - the manufacturer obviously did not ca…

You should install security updates. Period.

You don't help anyone by feeling better because instead of having the vendor maybe sniff on you, a hacker can do it instead.

I also haven't found any apps yet that intentionally waste my monthly datacap.

Re: There are over a billion outdated Android devices in use

#197

Earlier quoted context omitted.

Basically yes, but that's often not good enough either. Lots of third party code OEMs end up with in their kernels, unmaintainable, and often incompatible with anything.

Now waitasec... I own Crappy unupdated Android one of. And the drivers use the Linux kernel. Last I checked, they need to release source for their drivers. So where is it? And why can't we upstream those patches and "fix" android?

It doesn’t help that not every manufacturer (especially ones from China) don’t release the source code. And when they do, they sometimes contain opaque binary blobs that don’t tell you what is happening.

Re: There are over a billion outdated Android devices in use

#198

Earlier quoted context omitted.

1. Ability to passively decrypt network activity (KRACK). 2. Ability to throw a fully persistent implant onto the device (via Wi-Fi exploit + pivot to AP kernel exploit)

Most phones already come with two persistent implants - the user-antagonistic OS, and the baseband processor! I'm all for trusting computing devices to act as one's agents, but attempting to do so with anything resembling a modern mobile phone is barking up the wrong tree. Even though just having one means taking the location-tracking hit from negligently designed cellular protocols, further exposure can be mitigated…

This all might be true, but as a reason to not install patches, it still makes no sense. If you don’t trust the baseband or the OS, why did you buy the phone to begin with? You trust iOS n, but not iOS n+1?

Re: There are over a billion outdated Android devices in use

#199

I've got a 7 or 8 year old Google Nexus phone. Google stopped updating the OS 5 years ago. The only impact I've noticed is that newer apps won't run on and older OS. For me, however, that really isn't a problem since I use it for making and receiving calls and texts, and checking my email. Right now, I'm in no hurry to lay out hundreds for a new phone, Apple or Android, that will be obsoleted in just a couple years w…

The problem that you don't notice is the lack of security updates.

If you genuinely only use the phone features of the phone, that doesn't matter anywhere near as much. You only need to update if someone finds something like a text messaging buffer overflow. That sort of thing generally makes the news these days.

Re: There are over a billion outdated Android devices in use

#200

Love the HN crowd here explaining that staying still on old tech full of security holes is a-ok. :) Both Android and iOS have made awesome progress on all fronts, from security to stuff like AR and ML. You can now have a supercomputer in your pocket - just using it for phone/texts is such a waste.

Well I do not need supercomputer in my pocket (and I guess most people don’t). Phone and text plus decent browser that honors my privacy and security will do.

Music app, Maps and perhaps Youtube as luxury but beside that?

I would rather like a smartphone < 100$ that I can replace every year and do not worry when it breaks or if I loose it.

Post reply on HN