Live data from Hacker News

System Hardening in Android 11

security.googleblog.com

111–120 of 211 posts

Re: System Hardening in Android 11

#111
post #67
post #63

Earlier quoted context omitted.

It's really no secret after all these years that you need to buy a Google phone to get best support for their OS, just like you need to buy an Apple hardware to get support for their OS.

I bought a Nokia 6.1 around 2 years ago, which is part of the Android One program and it worked well! Had all security monthly updates, the system is clean and stable, updated to major versions of Android smoothly without any issue. If I can, I will buy another Android One phone. There is an horror story about an Android One Xiaomi phone, but Nokia delivered the promise with the 6.1, according to my experience

> There is an horror story about an Android One Xiaomi phone

Which one? I had a Xiaomi Mi A1 and nowadays I have a A2, both are fine Android One phones that still receives updates (in the case of A1, only security ones, but the A2 received a Android 10 update).

Yeah, Xiaomi may take a while to update their phones in Android One program, but otherwise it is fine.

Re: System Hardening in Android 11

#112
post #63

This is nice and all, but bigger issue is when will Android phones reach Android 11? Has fragmentation gotten better? Do most phone manufacturers support upgrading to major versions of Android (it does not seem to be in their interest)?

It's really no secret after all these years that you need to buy a Google phone to get best support for their OS, just like you need to buy an Apple hardware to get support for their OS.

Google still has shorter support periods than Lineage manages. The Nexus 6 was dropped by Google at Android 7 but you can install Lineage 17.1 (10.0) on it today. Same with some really old devices like the Galaxy Note 3 or S4. And even older devices got supported up to Android 9 like the S3 or Nexus 5.

The real secret is to buy one of the devices the real core Lineage developers maintain because they will keep those security patches and major release updates coming to you for free that these billion dollar corporations couldn't be bothered to do.

If the entire Android ecosystem wasn't a disgusting exploitation machine meant to produce more rare earth metal waste than naval warfare by forcibly obsoleting devices every 2 years everyone would be better off. Every company could be sponsoring free software devs to support their phones in something like Lineage in perpetuity while paying a fraction what they do for their large internal dev teams to do it. But the perverse incentives mean they don't want to update phones, which also means making it hard to support their device in a real operating system like Lineage is in their interest.

Re: System Hardening in Android 11

#113

Earlier quoted context omitted.

> apps can't simply access the "external" storage (enforces scoped storage) So how will perfectly valid use cases like file manager or backup manager work now?

Or the One Android App That Does Not Suck: Termux?

Sadly it seems that prior restrictions in Android have already taken their toll on Termux: https://news.ycombinator.com/item?id=23224669

Re: System Hardening in Android 11

#114
post #60

Earlier quoted context omitted.

It provides same services as Apple ships with iOS (iCloud, Push messaging services, Find my Friend, AppStore, Location, etc.), except that in Android that's branded "malware that calls home" and in Apple world it's called "integral part of the OS". The only difference here is that in Android you can actually separate the two.

The second difference is, you can replace it - https://microg.org/

MicroG still talks to Google services. It takes their code off your device but doesn't relieve you of the primary issue, that everything is dependent on Google's cloud services to work, and that they can still track everything you sent to them.

Re: System Hardening in Android 11

#115
post #69

Earlier quoted context omitted.

It's not clear that push notifications have to be centralised. The OS could coalesce requests for notifications while still querying multiple sources, thus minimizing the time that radios have to be powered on.

The most efficient decentralized way would be direct end-to-end connections. One could assign an IPv6 address to each application and have the notifications just sent there, no middleman necessary. If an application takes up too much battery, just kill it by changing the address. That would be a killer app for IPv6 if mobile networks were up to it...

Many LTE networks are IPv6 first, with IPv4 only services generally performing much worse or being unreachable. All 3 US Cell carriers have made this jump, though you see people complaining about IPv4 only sites and services not loading or working poorly through CGNAT.

Re: System Hardening in Android 11

#116

Earlier quoted context omitted.

You're upset about them requiring hardware attestation in SafetyNet (I am too) so you move to a platform that is way less flexible and way more closed? Not a troll, I'm really curious.

For me, Play Services is a non-starter: It's malware, plain and simple. For a couple years I tried to use Android without Google services, but I found it too restrictive. Most apps I'd want/need to use wouldn't even run without Google Play, even if you got the APK, since there's not really a good app store that has a lot of Android apps without Google Play. (F-Droid's hard-line open source requirement is too restrict…

microg is a FOSS implementation of google play services, without the malware part. Apps will still see "google play services" on your phone and mostly will run without problems, but their API calls are actually handled by microg.

Re: System Hardening in Android 11

#117

Dear Android Product Owner, I want to have control over which Android apps 'auto-run' on my device.

To be honest I don't understand how this works e.g. even with LineageOS' PrivacyGuard I still see some background processes in cache that had no permission to run on boot.

But it's absolutely necessary. I can't upgrade until I have that. I want full control of what runs on startup and what should be allowed to keep running on background (manually closed by me, I'm not asking for a skynet AI to guess).

Another one is blocking internet access but that will never happen because of their business model and ads. I guess I'll have to risk my personal data by using an open source firewall (not like I'm not going to review all the code) and unlocking bootloader/root.

Android is a disgrace because of these "small" things that they refuse to fix. But I'm glad it's slowly getting better.

Re: System Hardening in Android 11

#119
post #80

I don’t pretty much like Apple ecosystem but I have to say that the best decision I made technically was to switch to an iPhone 7 Plus 3 years ago after years of Android (since T-Mobile G1, first android phone ever). I said goodbye to a lot of customizations but at the same time regain my sanity from battery life, slowness and absurd support timelines

> at the same time regain my sanity from battery life, slowness and absurd support timelines If the phone had bad battery life or was slow to begin with, don't buy it. If it doesn't and it suddenly appears while you're using it... that's user error. Support: I'm really not sure what kind of support you're expecting, I assume not "how do I take a screenshot" kind of support. I once returned a phone for warranty but th…

For the support I meant the security and OS patches X years after the phone released. My wife iPhone 6s is still receiving iOS update at this time. Now try that with most expensive Android flagship. I don’t care if it comes from Samsung LG or Google I could always argue against you!

Re: System Hardening in Android 11

#120
post #74

Earlier quoted context omitted.

I can certainly echo this sentiment. It is maddening to see Play services as the "culprit" for the bad thing I'm investigating. Very frustrating.

If you're comfortable disclosing, what is this "bad thing"? From my understanding, Play Services provides roughly the same suite of things that are also supplied on iOS, only on iOS, it's built into the OS (location services, cloud messaging, etc.), while on Android it's a modular component that Google can push updates to without a full OS update. Is that not accurate?

Everything that Google announced in the submitted article requires an OS update. So being able to push just Play Services updates doesn’t help too much....
Post reply on HN