Live data from Hacker News

Void captures over a million Android TV boxes

news.drweb.com

81–90 of 113 posts

Re: Void captures over a million Android TV boxes

#81
post #77
post #75

Earlier quoted context omitted.

The manufacturers do not have the problem. They created a problem for many users as a side effect of forced obsolescence making consumers in richer countries buy new hardware every few years. So it is not really "self created" in my book.

Didn't Google create the problem. They could have made the Android core updatable without the need for a manufacturer update

Google certainly contributed to it. But whether the issue for consumers was caused by hardware makers or by OS makers it is not a self-imposed wound for the consumers -- they had nothing to do with it.

Re: Void captures over a million Android TV boxes

#82
post #80

Earlier quoted context omitted.

Its a self created problem of locked down user hostile devices. Operating system and software upgrades are not locked to the hardware manufacturer in the laptop world (not yet, for the most part). It is a pipe dream of mine that someday these attacks are used as an excuse by some government perhaps the EU to force opening up devices for install of other operating systems, maybe forced to open sourcing firmware etc.

Androids are less locked-down than iOS devices. The problem is that Google used to not have the ability to require long term support from device OEMs and now that it has the market power to demand long term support they seem reluctant to prioritize that in license agreements. Then there are devices, like in China, where Google Mobile Services is not on many phones so Google has no leverage at all re supporting update…

There is nothing in principle requiring Android phones be locked down, but its a de facto reality that manufacturers of almost all phones have made them locked down and you have to research to even know beforehand if you can even do something as little as a bootloader unlock or a rooting. Why is os and phone model so tightly integrated and locked together, when in the pc world you can generally install any os on any computer? That's what I was saying.

Which is to say I think you are speaking in terms of what you can do within the android's playground itself, its certainly much more open than ios in that regard. But when it comes to the fact of being able to change the playground itself ie install whatever os you want on the hardware or upgrade the os on the phone then suddenly most phones aren't any better than iphones either. Some are slightly better in that you can at least unlock the bootloader or root it, but I don't know if much progress has been made beyond that in being able to reverse engineer or otherwise them to able to install anything you want on them. That was the point with respect to I was speaking.

Re: Void captures over a million Android TV boxes

#83
post #80

Earlier quoted context omitted.

Its a self created problem of locked down user hostile devices. Operating system and software upgrades are not locked to the hardware manufacturer in the laptop world (not yet, for the most part). It is a pipe dream of mine that someday these attacks are used as an excuse by some government perhaps the EU to force opening up devices for install of other operating systems, maybe forced to open sourcing firmware etc.

Androids are less locked-down than iOS devices. The problem is that Google used to not have the ability to require long term support from device OEMs and now that it has the market power to demand long term support they seem reluctant to prioritize that in license agreements. Then there are devices, like in China, where Google Mobile Services is not on many phones so Google has no leverage at all re supporting update…

And thats my point, you should not need OEM support for a pure software issue of operating system upgrades. I do not ask Dell or Lenovo before writing 'apt update && apt upgrade' when on my pc. I do not need to ask Dell or Lenovo before plugging in a flash drive with the iso of my favorite os or to upgrade the next version of the same and so on. These are things that if the device wasn't locked down, shouldn't have required the OEM's direct involvement in the first place.

Re: Void captures over a million Android TV boxes

#84

> such devices often run on outdated Android versions, Ah the new economical divide. Most "real people" also have phones which aren't receiving updates for a few years by now. In south america the median android version is 8. And phones are not optional as most countries already jumped into both digital government and money transfer.

Its a self created problem of locked down user hostile devices. Operating system and software upgrades are not locked to the hardware manufacturer in the laptop world (not yet, for the most part). It is a pipe dream of mine that someday these attacks are used as an excuse by some government perhaps the EU to force opening up devices for install of other operating systems, maybe forced to open sourcing firmware etc.

Laptops work because the BIOS provides a universal abstraction layer and because support is upstreamed in the Linux kernel. Supporting phones for longer would require them to also upstream support.

Re: Void captures over a million Android TV boxes

#85
post #50

Earlier quoted context omitted.

Updates for Android continue to be a huge problem. Android OEMs have historically been terrible at releasing timely updates (it can take months), releasing updates at all (particularly cheap Android phones get EOLed long before an admittedly way more expensive iPhone would) and such updates aren't typically pushed in the same way. One big problem with Android is the way driver updates work. It's a nontrivial process…

Fuchsia was a backup plan. Google is now the only option for phone manufacturers. No backup needed. Plan A worked.

Fuchsia is a jobs program to prevent OS devs from making something that fan compete with android.

Re: Void captures over a million Android TV boxes

#86

Earlier quoted context omitted.

Its a self created problem of locked down user hostile devices. Operating system and software upgrades are not locked to the hardware manufacturer in the laptop world (not yet, for the most part). It is a pipe dream of mine that someday these attacks are used as an excuse by some government perhaps the EU to force opening up devices for install of other operating systems, maybe forced to open sourcing firmware etc.

Laptops work because the BIOS provides a universal abstraction layer and because support is upstreamed in the Linux kernel. Supporting phones for longer would require them to also upstream support.

Its true that a lack of standardization on phones makes things a bit harder but its as you said, still the key point is that they need to make the firmwares opened up. If manufacturers want to keep it all locked down then they deserve and should expect these type of attacks all the time. If they don't want these to happen, they should make their firmwares available and upstreamed or at least not cause roadblocks toward reverse engineering of the device by means of cryptographic locks or otherwise.

Re: Void captures over a million Android TV boxes

#87

> such devices often run on outdated Android versions, Ah the new economical divide. Most "real people" also have phones which aren't receiving updates for a few years by now. In south america the median android version is 8. And phones are not optional as most countries already jumped into both digital government and money transfer.

Out of curiosity, where did you find this data (genuine question)

After reading your comment, I was trying to find that for India, and landed on this page: https://gs.statcounter.com/android-version-market-share/all/..., and thought that India it is Android 13

But then for South America, the same page (https://gs.statcounter.com/android-version-market-share/all/...) tells should be Android 13 as well

India also has the same setup - digital money transfer happens via phones (in some ways, your phone number is your identity)

Re: Void captures over a million Android TV boxes

#88
post #58

Earlier quoted context omitted.

Fragmentation used to be touted as a feature of Android, not a … well, you know. “Freedom”, I believe they called it. Also, hardware standardization in the PC world is pretty much a thing. Not so much in the mobile (and mobile offshoot) world.

Fragmentation is not the problem. The problem is inability to change os or firmware. If control of upgrading or changing os wasn't solely with the maker there wouldn't have been an issue in the first place. I bet for example many of these bugs might be due to the much older linux kernels in use in phones. Again something easily solved by making the os easily changeable and not presenting cryptographic etc roadblocks…

You're making a bold assumption that an alternate, extremely uneconomical, OS would be more secure. This is far from obvious.

Now, if the phone's original OS were open source, it would be easier to make bugfix patches when old vulns are discovered.

Re: Void captures over a million Android TV boxes

#89
post #88

Earlier quoted context omitted.

Fragmentation is not the problem. The problem is inability to change os or firmware. If control of upgrading or changing os wasn't solely with the maker there wouldn't have been an issue in the first place. I bet for example many of these bugs might be due to the much older linux kernels in use in phones. Again something easily solved by making the os easily changeable and not presenting cryptographic etc roadblocks…

You're making a bold assumption that an alternate, extremely uneconomical, OS would be more secure. This is far from obvious. Now, if the phone's original OS were open source, it would be easier to make bugfix patches when old vulns are discovered.

By "alternate" I don't necessarily mean some obscure os, but any os in general , in fact I rather specifically had in mind Android or Linux. By alternate here I meant the fact of being able to install any you want instead of being stuck with whatever ancient Android version and Linux kernel the original came with. Ie if your phone came with an ancient Android, you should be able to without OEM support install a newer Android or a recent Linux or anything else you'd like.

Re: Void captures over a million Android TV boxes

#90
Some of my hard requirements for a media device are that it must not share any of my personal information with any third party and it must fully cache the full-resolution and complete media content prior to beginning playback. If it's going to be connected to the Internet it must receive regular security updates for anything that's not written in a memory- and type-safe language like Go or Rust.

While Go and Rust aren't necessarily magic pixie-dust that can account for all types of security vulnerabilities, if I'm going to be faced with the possibility of some project being abandoned at some point for the next new shiny thing that everyone would rather work on, I'd at least like to give it a fighting chance of remaining secure for some time after abandonment without any updates. Ideally it would be a Rust userspace media management package running on Debian Stable getting unattended upgrades every night.

Since nothing like that exists I've recently decided to give CoreELEC/Kodi a try on an ODROID-N2+, albeit disconnected from any network. I was surprised at how seamless and integrated everything was.

The remote control for my television "just worked" with it out of the box thanks to HDMI CEC support. Arrow buttons, play/pause, back, etc. all did just what I expected them to do. It's a marked improvement from the last time I built a custom media box, which I had running MythTV on Gentoo, when I needed to jump through hoops to set up an IR blaster. And you can't argue with a 12v/2a power supply.

For now I'm keeping it off my home network and am "sneaker-netting" content on a USB drive between my trusted devices and the ODROID. When I get tired of doing that I might add some firewall rules to my router to only allow it to talk to a locked-down VM doing nothing but hosting a read-only file share. But some day I hope to look forward to building a similar form-factor box that has all the media gadgets and gizmos with a Rust userspace that respects my privacy and auto-updated Debian Stable so I can actually connect it to the Internet.

Post reply on HN