Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

21–30 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#21

I hope that this action, along with Google's refusal to correctly safeguard and segregate apps, costs Google all of Android in the long term. Neither deserves to exist. Any thoughts on Linux phones?

Unchecked Apple without real competition would be worse than the status quo.

That is a misrepresentation because Samsung, Huawei, and various Linux vendors each will have their own answer, their own alterative. In no universe will Apple be without competition. Apple is not even a consideration since it doesn't allow unapproved app installation anyway.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#22

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

The sad thing is I think Google keeping Chrome is actually likely the better of two possible bad outcomes... Anyone else interested and willing to pay the true value of owning the entire Internet ecosystem is almost certainly going to look to extract value from that, and that's almost certainly worse than what Google does today. E.g. using everyone's browser to extract training data for AI without getting IP blocked.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#23
post #7

Google sold Android to nerds as open source. We thought that mobile operating systems would be won by the "Linux of mobile OSs." But Google has made sure that didn't happen and we're left with devices more locked down than the proprietary Windows ecosystem we were hoping to leave in the past - and with a company in charge looking to exert even more power over us than Microsoft did.

The trick is adding a ton of features which expose extra attack surface that needs them to maintain and fix, under the pretense that it will make everyone's life easier. Make it complicated enough so that the community cannot maintain it, enabling the corporation to throw its weight around.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#24
The only reason that would make me fear from an antitrust judgement splitting Android from Google is that it may lose the Google contributions to AOSP.

Google is more and more showing that they really don't want to contribute to AOSP.

So for me, Android should be split out of Google. Maybe the other Android manufacturers will start contributing to AOSP, and maybe Android will die. But let me be honest: if Google keeps going this way, I will move to an iPhone (and I've been using and developing for Android forever). We may as well try the split, and if it fails I'll end up with an iPhone anyway.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#25
post #12
post #8

> We want to make sure that if you download an app from a developer, regardless of where you get it, it's actually from them. That's it. In what scenario is this a serious threat because I can't think of any.

People are installing banking apps that are actually from criminals. Basically app phishing.

> People are installing banking apps that are actually from criminals.

and this identification does nothing about that, this is not to protect users. such phishing are always found on play-store alone.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#26
Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier:

https://wiki.postmarketos.org/wiki/Devices#Main

Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging that?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#27

Earlier quoted context omitted.

Unchecked Apple without real competition would be worse than the status quo.

That is a misrepresentation because Samsung, Huawei, and various Linux vendors each will have their own answer, their own alterative. In no universe will Apple be without competition. Apple is not even a consideration since it doesn't allow unapproved app installation anyway.

Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#28
post #27

Earlier quoted context omitted.

That is a misrepresentation because Samsung, Huawei, and various Linux vendors each will have their own answer, their own alterative. In no universe will Apple be without competition. Apple is not even a consideration since it doesn't allow unapproved app installation anyway.

Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.

> Developers aren't going to develop for five slightly-different ecosystems

The point, perhaps, is for one to emerge as the prominent choice, the correct one. Diversity however has its own value.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#29
post #27

Earlier quoted context omitted.

That is a misrepresentation because Samsung, Huawei, and various Linux vendors each will have their own answer, their own alterative. In no universe will Apple be without competition. Apple is not even a consideration since it doesn't allow unapproved app installation anyway.

Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.

There already are multiple different android ecosystems today. For example Samsung has SDKs that have features when targeting their flavor of Android. There will still be a common base.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#30

Earlier quoted context omitted.

Unchecked Apple without real competition would be worse than the status quo.

That is a misrepresentation because Samsung, Huawei, and various Linux vendors each will have their own answer, their own alterative. In no universe will Apple be without competition. Apple is not even a consideration since it doesn't allow unapproved app installation anyway.

It is a shame that those companies don't contribute to AOSP (or fork it). Apparently Huawei decided that they would do better alone with their own HarmonyOS, but I don't get it. It could be so powerful if AOSP was actually shared between the Android manufacturers...

I would happily leave Android and go with such a fork. Instead, each (Samsung, Huawei, ...) try to make their own thing. And good luck to them to beat Android on their own.

Post reply on HN