Live data from Hacker News

There are over a billion outdated Android devices in use

danluu.com

351–360 of 474 posts

Re: There are over a billion outdated Android devices in use

#351

Earlier quoted context omitted.

I have a rooted device, so I can basically make apps do what I want and stop them from doing what I don't want. IMHO that's far better than Google's vision of "security" where they want to be in control and even consider the user an attacker.

How much of a solution is rooting a device for 1 billion users?

I see phone repair shops at every street corner, I don't see why they could not offer this as a service.

Re: There are over a billion outdated Android devices in use

#352

Earlier quoted context omitted.

> Security is used to euthanize perfectly working systems and harass users for money That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. > Better have a bricked phone but secured phone? lets just say don't do any financial transactions on the device or apprecia…

That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. As a user, do I care whether my phone is unusable because the developers wanted specifically to render older hardware unusable or whether it was just through their negligence in failing to consider older devic…

> I keep hearing this, but what's the actual presence of malware on Android? If you're not installing shady apps from the Play Store, what's your actual level of risk?

I wish I could quantify that. It's a hard task. But the store is not the only possible vector. On an old Android you're running a very outdated version of Chrome when looking at any pages / ads. That would be the most exposed/insecure element in the system.

Re: There are over a billion outdated Android devices in use

#353
post #200

Love the HN crowd here explaining that staying still on old tech full of security holes is a-ok. :) Both Android and iOS have made awesome progress on all fronts, from security to stuff like AR and ML. You can now have a supercomputer in your pocket - just using it for phone/texts is such a waste.

Well I do not need supercomputer in my pocket (and I guess most people don’t). Phone and text plus decent browser that honors my privacy and security will do. Music app, Maps and perhaps Youtube as luxury but beside that? I would rather like a smartphone < 100$ that I can replace every year and do not worry when it breaks or if I loose it.

If you trust them, Huawei has some decent phones in the € 120-150 price range. Nothing super-exciting, but for the use case you describe, they are perfectly cromulent.

Re: There are over a billion outdated Android devices in use

#354

Earlier quoted context omitted.

I understand this entirely, but there are some pretty bad iOS vulnerabilities out in the wild now (e.g. KRACK wpa2). It’s pretty dangerous to avoid updates nowadays. I think what needs to happen across the industry is a complete decoupling of “feature” from security patching. Too many people are exposed because of exactly the kind of unwanted UI upgrades you describe.

Dangerous? What's the worse that could happen?

Similar questions were likely asked by owners of insecure routers/cameras before they got hit with Mirai

Re: There are over a billion outdated Android devices in use

#355
post #339

Earlier quoted context omitted.

That's quite the opposite. It's hw companies not used to having to support their stuff after it leaves the door. To keep supporting this, they should plan/calculate this in from the get-go. They don't plan anything, so now you have devices that don't get updates. Supporting/updating devices requires active planning, but then you get cries over companies that actually do perform updates and get the whole 'planned obso…

Android device manufactors are not solely hardware companies. Samsung surely is not, they do publish updates for some time, then they stop doing that. This is planned. As time progresses your device becomes less usable, not because of the hardware, but of the software and bugs/security issues within. So if your (example) Samsung device gets updates for 2 years, then the planned obsolescence for that device is 2 years…

My phone doesn't become obsolete because of that. It's because I'm not allowed to use many apps without updating them after a certain time. These newer versions are slower and use more resources. Even with regular updates my phone would be unusable after enough userland development.

Re: There are over a billion outdated Android devices in use

#356

Earlier quoted context omitted.

> Security is used to euthanize perfectly working systems and harass users for money That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. > Better have a bricked phone but secured phone? lets just say don't do any financial transactions on the device or apprecia…

That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. As a user, do I care whether my phone is unusable because the developers wanted specifically to render older hardware unusable or whether it was just through their negligence in failing to consider older devic…

> Stupidity or malice, the result is the same

Yes but whether we attribute the intent to stupidity or malice is important as per the general health of our thought process. Its likely laziness combined with malice when its noted. I imagine a dev getting up in arms about package size and then when the issue is raised its not given high priority because someone twigs the convenient side effect. That's the worst case. Either way the mindset of paranoia is warped and self centred. Its not because they're thinking of forcing you to upgrade its more because they're _not_ thinking of you and instead the wide-eyed new sales opportunities that ship with greater disc space.

> I keep hearing this, but what's the actual presence of malware on Android?

oh wow, you're gonna play this game? I could tell you that its perfectly safe to trace the outline of a cliff with your feet and in many, many cases its going to be absolutely fine until the one case where the earth gives way and its not.

Let me put it this way; when I see the tagline:

> there are over a billion outdated Android devices

my first thought is:

> what's the most effective exploit to tap into that market?

the existence of security flaws encourages action and the hubris of not updating is the clarion call to those that exercise the exploits.

> I'd say your exposure to malware on Android is far less than it is on PC

This. What is this? This is complete conjecture. Get out of here.

Re: There are over a billion outdated Android devices in use

#357

Earlier quoted context omitted.

That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. As a user, do I care whether my phone is unusable because the developers wanted specifically to render older hardware unusable or whether it was just through their negligence in failing to consider older devic…

> I keep hearing this, but what's the actual presence of malware on Android? If you're not installing shady apps from the Play Store, what's your actual level of risk? I wish I could quantify that. It's a hard task. But the store is not the only possible vector. On an old Android you're running a very outdated version of Chrome when looking at any pages / ads. That would be the most exposed/insecure element in the sy…

there are bluetooth exploits and network adapter exploits which are for more localised fun.

Re: There are over a billion outdated Android devices in use

#358
post #288
post #239

Earlier quoted context omitted.

I agree, but it is true that newer updates dramatically slow down older hardware.

I thought this had been tested recently and shown not true? A psychological illusion or something? I’ve never noticed any significant, let alone dramatic, speed change on any given device from iOS 3 on the original iPad onwards.

They tested the performance of the hardware (CPU, GPU, etc), not of the APIs or updated apps. So the CPU and GPU of my iPhone 6 are just as fast as when they were released. But I can guarantee you that the camera app as well as a lot of third party apps aren't as fast as they were when I bought the phone.

Re: There are over a billion outdated Android devices in use

#359

Earlier quoted context omitted.

That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. As a user, do I care whether my phone is unusable because the developers wanted specifically to render older hardware unusable or whether it was just through their negligence in failing to consider older devic…

> I keep hearing this, but what's the actual presence of malware on Android? If you're not installing shady apps from the Play Store, what's your actual level of risk? I wish I could quantify that. It's a hard task. But the store is not the only possible vector. On an old Android you're running a very outdated version of Chrome when looking at any pages / ads. That would be the most exposed/insecure element in the sy…

The Chrome part can be covered easily - just install mobile firefox which updates as any other app. Vastly superior browser with add-blocking possible, thus minimizing this vector of attack.

Re: There are over a billion outdated Android devices in use

#360

Earlier quoted context omitted.

As someone who goes as long as possible without performing updates, this is exactly the reason why. Example: Last time I updated my iPhone, the music app got an update and now they are trying to shove iCloud down my throat. Not to mention needless UI changes when I was more than satisfied with how it was before.

I understand this entirely, but there are some pretty bad iOS vulnerabilities out in the wild now (e.g. KRACK wpa2). It’s pretty dangerous to avoid updates nowadays. I think what needs to happen across the industry is a complete decoupling of “feature” from security patching. Too many people are exposed because of exactly the kind of unwanted UI upgrades you describe.

Google kind of does that but OEM does not seem to implement them into their phones.
Post reply on HN