Live data from Hacker News

There are over a billion outdated Android devices in use

danluu.com

231–240 of 474 posts

Re: There are over a billion outdated Android devices in use

#231

Earlier quoted context omitted.

> Love the HN crowd here explaining that staying still on old tech full of security holes is a-ok. :) It’s disheartening when a forum full of supposed tech enthusiasts starts to morph into a bunch of paranoid tech Luddites. That is what, imho, killed slashdot. Every post was full of comments slamming anything new. Eventually it just got toxic and boring. Who wants to hear a bunch of paranoid outliers brag about their…

Harsh tone but 100% warranted imo. It’s fascinating to see so many otherwise smart people completely fail to understand the changes around them.

Its harsh because there is no way to sugar coat it. This post is full of people bragging about running 9 year old phones with ancient highly vulnerable operating systems. On the same forum that has people bragging about being child geniuses and making posts like “I’m assuming that just by reading HN you have an above average intelligence”.

No. You don’t get to claim you are “above average intelligence” when you brag about downloading OS updates off sketchy “community” forums and then make posts like “better than some faceless corporation”. That isn’t intelligent. That is just being stupid.

Ever hear of the dunning kruger effect? Some folks need to go read about it and then smack themselves upside the head.

Seriously. Paranoid tech ludditism is an eye rolling, tedious, boring circlejerk. Go back to your green screen gramps— I’m sure it is good enough for anything but I like my 4K color monitor, thanks.

...Keep that stuff out of tech forums because it is cancer. Sla

Re: There are over a billion outdated Android devices in use

#232

Earlier quoted context omitted.

I have a rooted device, so I can basically make apps do what I want and stop them from doing what I don't want. IMHO that's far better than Google's vision of "security" where they want to be in control and even consider the user an attacker.

How much of a solution is rooting a device for 1 billion users?

Probably more feasible for some of them than buying a new phone, at least.

Re: There are over a billion outdated Android devices in use

#233
post #207

Those billion outdated devices are the low hanging fruit screening me and my fully updated iOS device. I can be confident that casual attackers aren't coming after me, only the higher tier ripoff artists gunning for iOS users and the APTs who are attacking my company specifically.

No, with certainty your private information has already been stolen or sold once or even multiple times. Equifax is just the hack you know about. Insider threats are common and your identity is surely sitting in some giant tarball that is bought and sold. Until society reboots you with a new SSN, new credit score, new drivers license...you are already compromised.

In ten years will there even be a single US citizen whose private data is wholly uncompromised? Doubtful

This is the ultimate data slavery...unable to protect our identifying strings...and unable to repudiate them when they are compromised. My SSN is compromised and I am stuck with it for another fifty years...same as you. Enjoy your phone.

Re: There are over a billion outdated Android devices in use

#234

I've got a 7 or 8 year old Google Nexus phone. Google stopped updating the OS 5 years ago. The only impact I've noticed is that newer apps won't run on and older OS. For me, however, that really isn't a problem since I use it for making and receiving calls and texts, and checking my email. Right now, I'm in no hurry to lay out hundreds for a new phone, Apple or Android, that will be obsoleted in just a couple years w…

I've got a Samsung S4 laying around that I hadn't used for years (it's 4 1/2 years old). Recently I fired it up just to check some things. As expected, it still runs beautifully for normal Web use across all sites. Other than the small form factor (which some people may prefer), it's easy to see how consumers might stick to older phones.

I used my S3 until it died on me, a couple of months ago.

Re: There are over a billion outdated Android devices in use

#236

Earlier quoted context omitted.

Most phones already come with two persistent implants - the user-antagonistic OS, and the baseband processor! I'm all for trusting computing devices to act as one's agents, but attempting to do so with anything resembling a modern mobile phone is barking up the wrong tree. Even though just having one means taking the location-tracking hit from negligently designed cellular protocols, further exposure can be mitigated…

At some point, reckless behavior affects people beyond the individual. I am irritated that people allow their systems, networks, devices etc to become compromised, thus becoming the assets of malicious actors. Most of the people in this category have are not particularly savvy, which doesn’t give them an out so much as it explains the predicament. However, you are demonstrating that you choose to be in this category,…

It's very fucking weird that by pointing out the larger non-corporate context of digital security, it's being inferred that I deliberately do not secure my devices. I guess by not toeing the AppGoogAzon "Security (TM)" marketing lines, I just end up in that "other - outsider" category, and must be wrong.

I already explained a mechanic of causality whereby assorted end nodes being owned up actually increases our security, as it helps keep at bay the simplistic/totalitarian philosophy of tracking/controlling communication. But don't let that get in the way of the malunderstanding that is ultimately driving this nebulous desire for promised "security".

Re: There are over a billion outdated Android devices in use

#237

Earlier quoted context omitted.

I understand this entirely, but there are some pretty bad iOS vulnerabilities out in the wild now (e.g. KRACK wpa2). It’s pretty dangerous to avoid updates nowadays. I think what needs to happen across the industry is a complete decoupling of “feature” from security patching. Too many people are exposed because of exactly the kind of unwanted UI upgrades you describe.

Dangerous? What's the worse that could happen?

Do you mean the worst that could happen to you personally or the worst for everyone?

When your device is compromised by hostile actors I guess it depends on what your nightmares are, but getting framed for child pornography and/or blackmailed for it is a popular one. Or getting your cloud accounts hijacked and all your stuff compromised. Or getting the bad guys access to your employer's network. Etc.

Collectively a widespread Android device botnet could take down a lot of infrastructure, or start a war, or ruin everyone's days with ransomware. I'm sure more imaginative people have thought about it.

Re: There are over a billion outdated Android devices in use

#238

Earlier quoted context omitted.

Most phones already come with two persistent implants - the user-antagonistic OS, and the baseband processor! I'm all for trusting computing devices to act as one's agents, but attempting to do so with anything resembling a modern mobile phone is barking up the wrong tree. Even though just having one means taking the location-tracking hit from negligently designed cellular protocols, further exposure can be mitigated…

Most people are willing to accept the risk that the NSA is listening in on them. Most people are not willing to accept the risk of an arbitrary person being able to steal their identity.

If one's "identity" is so bland that it can be trivially "stolen", then perhaps it's not much of an identity after all.

Re: There are over a billion outdated Android devices in use

#239
post #220

The flipside of this is that developers are forced to support versions of their apps that are compatible with previous operating systems. That's bad for developers, but good for consumers. iPhones shove updates down your throat as a user. They're so persistent that inevitably most people will accept the new update - and even if you're stubborn like me, eventually your apps will no longer be supported under the newer…

> iPhones shove updates down your throat as a user. And we have the monster that was Windows XP because of users thinking "updates" are "forced" down throats. iOS is correctly celebrated for having such a high adoption of the "latest and greatest", and certainly hasn't become the demon that is the unpatched Android landscape. So thankfully, from NetSec to the end user, it's a fantastic thing that iOS keeps devices mo…

I agree, but it is true that newer updates dramatically slow down older hardware.

Re: There are over a billion outdated Android devices in use

#240
post #206

Earlier quoted context omitted.

Sure, and I didn't advocate doing otherwise. My point is the larger context - there is no "secure" on mobile. Likewise, my point about losing a datacap was that it was preferable to having more personal info backhauled into commercial surveillance databases. It's not an either-or and I'm not desiring either one - just calling attention to the larger context of user-security versus the myopia of marketing/corporate se…

There is secure on mobile. Secure is not a binary property, it's a spectrum of options and possibilities which heavily depend on your environment and your threat model. You either get security updates at the possible downside of sending more data to some database of a known vendor or you get the very possible risk of being part of a slide on DEFCON Fail Panel by some unknown blackhat. I choose a known advesary over a…

At its core, digital security is a binary property equivalent to mathematical proof. Since universal security is neigh impossible (two people can keep a secret if both are dead), we then predicate it on various trust relationships / threat models - what one is secure against.

The modern non-technical but security-conscious person concedes that their devices are pwnt by (ie they are forced to trust) AppGoogAzon anyway, and simply shies away from trusting technology. The phenomenon is what it is - I'm not advocating for it, but advocating for understanding it.

Furthermore, are you saying that you actually know all the players in the commercial surveillance industry?!

I'd appeal to your same argument of known versus unknown, but point out that at least the motives of the rando blackhat are known. Whereas the surveillance industry will be innovating new ways of monetizing their malicious databases for the next century!

Post reply on HN