Live data from Hacker News

There are over a billion outdated Android devices in use

danluu.com

371–380 of 474 posts

Re: There are over a billion outdated Android devices in use

#371

Earlier quoted context omitted.

No, it's the carrier's fault. The carrier locks down your OS.

The carrier doesn't lock down iOS. Every iOS user worldwide can update to iOS the day it is released if the phone is compatible.

Also true for Windows 10 Mobile. (My phone gets an update today, why doesn't yours?) Android is the only smart phone platform that carriers still have a say in.

Re: There are over a billion outdated Android devices in use

#372

With current and older devices working perfectly well, and new devices being even less serviceable and more user-hostile with greater efforts towards planned obolescence, is it any wonder that people just aren't "upgrading" any more? I don't consider this a problem, but a sign of an ecosystem that is gaining stability. In fact I'd say it's even better, from an e-waste perspective, that the amount of churn has decreas…

As someone who goes as long as possible without performing updates, this is exactly the reason why. Example: Last time I updated my iPhone, the music app got an update and now they are trying to shove iCloud down my throat. Not to mention needless UI changes when I was more than satisfied with how it was before.

It's more than UI changes: the update from iOS10 to 11 removed support for 32bit applications, rendering dozens of applications that I use daily (and have paid for a lot of money) unusable. So now I have to decide between two bad options - not being secure or losing all that invested money.

Re: There are over a billion outdated Android devices in use

#373
post #336
post #327

Earlier quoted context omitted.

Apps that represent light websites like Google and Facebook are now 300mb+. With such memory hogging updates, few people with older phones are going to update.

Size is not speed.

True, but...

Older hardware has older chips (and possibly slower memory) so... a larger size alone would still likely have an actual processing speed impact, no? The newer OS and app versions are developed with chip/memory speed "XYZ" in mind, and that's the target they aim for. That the OS does run on older hardware is great, but if your memory size goes up 2-3 times for apps, I can not imagine that there's 0 speed impact.

Re: There are over a billion outdated Android devices in use

#374
post #208

Earlier quoted context omitted.

Many Android devices of that age and even newer had flaws resulting in the failure to properly validate HTTPS connections as they would accept invalid certificates. As a result, every time I fire up an off the shelf WiFi Pineapple in public and run SSLSplit (not to be confused with Moxies SSLStrip), I get credential after credential, typically starting with e-mail accounts. This is obviously bad because if someone is…

Most of these "oh no, security!" issues can be mitigated by avoiding public WiFi or using a VPN on them.

VPN can be a problem, especially on these older devices as those services themselves are vulnerable due to underlying OS issues. In terms of WiFi, keep in mind LTE is effectively broken because of the emergency tower redirection implementation. It's possible for attackers to direct devices to their own OpenLTE tower.

https://sourceforge.net/projects/openlte/files/

Re: There are over a billion outdated Android devices in use

#375

Earlier quoted context omitted.

That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. As a user, do I care whether my phone is unusable because the developers wanted specifically to render older hardware unusable or whether it was just through their negligence in failing to consider older devic…

> I keep hearing this, but what's the actual presence of malware on Android? If you're not installing shady apps from the Play Store, what's your actual level of risk? I wish I could quantify that. It's a hard task. But the store is not the only possible vector. On an old Android you're running a very outdated version of Chrome when looking at any pages / ads. That would be the most exposed/insecure element in the sy…

Chrome on Android is updated separately from the OS release. Even old Androids have new Chrome. This is not the Safari-on-iOS situation.

The same is valid for the system WebView, but "only" since Android 4.4. It is updated via Play Store, independently from the base system.

Re: There are over a billion outdated Android devices in use

#376
post #321

Earlier quoted context omitted.

> The presence of GNU software pieces (or any software licensed under GNU [LA]GPL v3+) ensures the device is free of locks (or with user breakable locks). That's not true, as the Linux kernel is still GPLv2. So while you could swap out the userspace GNU utils, the device manufacturer can still lock the bootloader which is perfectly fine with the GPLv2. Even if the bootloader is unlockable (e.g. LG allows this btw), y…

> That's not true, as the Linux kernel is still GPLv2. So while you could swap out the userspace GNU utils, the device manufacturer can still lock the bootloader which is perfectly fine with the GPLv2. Yeah, probably. But the presence of packages like GNU libc can make it harder for the manufacturer to lock the device. > ... kernel version due to proprietary binary blobs which nearly every phone uses. Sadly, binary b…

> this happened because many Linux developers don't care about binary blobs.

It is mostly users, not developers, who don't care about binary blobs. The users then take the "pragmatic" approach of using binary blobs, but hey, stuff works for them.

See also the Nvidia binary driver. Who is the advocate for that? Users (hey, never had a problem and it runs my apps very well) or developers (whoa, we cannot develop Wayland/etc with this)?

Re: There are over a billion outdated Android devices in use

#377
post #131

Earlier quoted context omitted.

Security, basically. If you care about your privacy, you should care about security (can't have one with the other). You need updated phone for that.

Security isn't as big of an issue with many of these devices as you might think. Unless it is years out of date, Play Services still gets updates, the system web view still gets updated, Chrome still gets updates, and in many cases the vendor will still roll out an emergency patch if there is something serious.

That's a huge guessing game, though - remember StageFright? You could have a phone with an up to date Chrome, up to date Play Services, and still be trivially exploited simply by viewing a standard video file. (Not to mention wondering which of your apps uses an out of date embedded web view)

I would submit that the number of people qualified to safely make (and update) that risk assessment is extremely small, and all of them would recommend updating to a version which patches problems rather than hoping you can dance around them.

Re: There are over a billion outdated Android devices in use

#379

Earlier quoted context omitted.

Making it easier for users to run software with unpatched vulnerabilities, even accounting for some extra slowness, isn’t a good thing..

Then manufacturers should fix that problem. The reason people don't like security updates, is that they are tied to feature updates. Most people don't like the new feature updates, and would happily take just the security updates. If users were given that option, I'm betting that a lot of the push-back to updates would drop fast.

Manufacturers have no incentive now to do so.

Re: There are over a billion outdated Android devices in use

#380

Earlier quoted context omitted.

That's a cynical and paranoid mindset. Bloat is a lazy tendency not a malicious evil and developers tend to optimise for the latest and greatest if left unchecked and forced to consider backwards compatibility. As a user, do I care whether my phone is unusable because the developers wanted specifically to render older hardware unusable or whether it was just through their negligence in failing to consider older devic…

> Stupidity or malice, the result is the same Yes but whether we attribute the intent to stupidity or malice is important as per the general health of our thought process. Its likely laziness combined with malice when its noted. I imagine a dev getting up in arms about package size and then when the issue is raised its not given high priority because someone twigs the convenient side effect. That's the worst case. Ei…

> my first thought is:

> > what's the most effective exploit to tap into that market?

So??? What is it? Do let us know.

I'd venture to say that the fragmentation of that market makes it reasonably secure. Just like how the average router is incredibly insecure, and yet you don't advise people to avoid e-banking and just deal with their money in paper form and through face-to-face contacts.

Yes, you are technically right. But @quanticle is right, in practice: unless those users do some very stupid shit, they're pretty safe doing ebanking on their phones. (and those who do the "very stupid shit" are likely to do it on their computers, too)

Post reply on HN