Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

11–20 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#12
post #8

> We want to make sure that if you download an app from a developer, regardless of where you get it, it's actually from them. That's it. In what scenario is this a serious threat because I can't think of any.

People are installing banking apps that are actually from criminals. Basically app phishing.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#13

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Yep. If we’re gonna be forking browsers, Firefox should be the base, not Chromium. Mozilla is in much less of a position to abuse their position, and more Firefox forks means more chances that one catches on with some slice of the larger public and helps chip away at Blink hegemony.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#14
Seems like there needs to be a split of both hardware and software. Mobile phones morphed into something else lately. Not all of us need all the features of a smart phone, but still need a comms device. We need a simpler OS with simpler hardware that focuses on comms and less features. Simpler OS, lower attack surface, simpler to maintain without the help of a gigantic corporation. I don't need a supercomputer in my pocket.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#15
Security of the Android ecosystem should not be compromised just to make the lives of Googlers easier in handling the public, internal, and pixel branches of AOSP.

Edit: The HN title is false and security patches were released. But this is more about Google trying to appease OEMs who aren't capable with keeping up with a monthly OS release schedule.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#16

Seems like there needs to be a split of both hardware and software. Mobile phones morphed into something else lately. Not all of us need all the features of a smart phone, but still need a comms device. We need a simpler OS with simpler hardware that focuses on comms and less features. Simpler OS, lower attack surface, simpler to maintain without the help of a gigantic corporation. I don't need a supercomputer in my…

>Not all of us need all the features of a smart phone, but still need a comms device. [...] I don't need a supercomputer in my pocket.

What's stopping you from using a feature phone?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#17

I hope that this action, along with Google's refusal to correctly safeguard and segregate apps, costs Google all of Android in the long term. Neither deserves to exist. Any thoughts on Linux phones?

Unchecked Apple without real competition would be worse than the status quo.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#18
post #16

Seems like there needs to be a split of both hardware and software. Mobile phones morphed into something else lately. Not all of us need all the features of a smart phone, but still need a comms device. We need a simpler OS with simpler hardware that focuses on comms and less features. Simpler OS, lower attack surface, simpler to maintain without the help of a gigantic corporation. I don't need a supercomputer in my…

>Not all of us need all the features of a smart phone, but still need a comms device. [...] I don't need a supercomputer in my pocket. What's stopping you from using a feature phone?

Security/privacy?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#19
post #12
post #8

> We want to make sure that if you download an app from a developer, regardless of where you get it, it's actually from them. That's it. In what scenario is this a serious threat because I can't think of any.

People are installing banking apps that are actually from criminals. Basically app phishing.

Let's not call them banking apps. They're not. They're scam apps.

The problem represented in the tweet is deeper. It is about not receiving patches which means the device is basically unsafe to use altogether.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#20

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

I wonder if Android and Chrome would support open source even less as independent companies though.
Post reply on HN