Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

31–40 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#31
post #26

Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier: https://wiki.postmarketos.org/wiki/Devices#Main Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging th…

Main is described as "The most supported devices, with all the features and stability you'd expect from a regular OS."

Unfortunately there was/is no device supported by postmarketOS that fits that description. You'll need at least good telephony support including 4G features like VoLTE, proper camera support (not potato polaroid from the 80s quality), Wifi, Bluetooth, geolocation, working GPU acceleration, media hardware decoders, decent battery life. And I'm probably forgetting a few things.

Let's hope that initiatives like https://liberux.net/ will help make a fully working, long lasting device available!

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#32
post #16

Earlier quoted context omitted.

>Not all of us need all the features of a smart phone, but still need a comms device. [...] I don't need a supercomputer in my pocket. What's stopping you from using a feature phone?

Security/privacy?

So you want a $100 feature phone that has serious security features like monthly security patches and dedicated security coprocessors? It's tough to make the economics of that work out. All the serious security features costs money to implement, either in the form of development costs or added costs to the BOM. Those costs can be absorbed if you're selling a $600 phone, but not a $100 phone. If you try to add those features to a $100 phone, it'll end up making the phone more expensive, which means nobody but security freaks would buy your phone, and you lose economies of scale that's needed to make a phone at all.

Back to your point, there's already a "split of hardware and software" in the PC market, and we know how it works out. Security there is a joke. Windows might be getting monthly security patches, but the same can't be said of the panoply of third party drivers/firmware. Whenever microsoft tries to push for better security they get shouted down by people claiming it's some sort of conspiracy to implement DRM.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#33
post #27

Earlier quoted context omitted.

Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.

> Developers aren't going to develop for five slightly-different ecosystems The point, perhaps, is for one to emerge as the prominent choice, the correct one. Diversity however has its own value.

I wish Android manufacturers contributed to AOSP, so that it would still be one ecosystem, but with shared ownership. But I guess it's more profitable for all of them to let Google do it on their own. And it sucks for the user, because we have to live with Google's decisions.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#34

Earlier quoted context omitted.

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

The sad thing is I think Google keeping Chrome is actually likely the better of two possible bad outcomes... Anyone else interested and willing to pay the true value of owning the entire Internet ecosystem is almost certainly going to look to extract value from that, and that's almost certainly worse than what Google does today. E.g. using everyone's browser to extract training data for AI without getting IP blocked.

Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this.

Maybe the development will slow down, but let's be honest: we would still be fine if Android and iOS had stopped "improving" years ago. Now it's mostly about adding shiny AI features and squeeze the users.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#35
post #16

Seems like there needs to be a split of both hardware and software. Mobile phones morphed into something else lately. Not all of us need all the features of a smart phone, but still need a comms device. We need a simpler OS with simpler hardware that focuses on comms and less features. Simpler OS, lower attack surface, simpler to maintain without the help of a gigantic corporation. I don't need a supercomputer in my…

>Not all of us need all the features of a smart phone, but still need a comms device. [...] I don't need a supercomputer in my pocket. What's stopping you from using a feature phone?

I don’t even want a smart phone if the banks/trading firms don’t force me to use a phone for auth. I keep a used smart phone for company stuffs (again auth) and bank stuffs.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#36
post #26

Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier: https://wiki.postmarketos.org/wiki/Devices#Main Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging th…

Unfortunately, and as much as I like Linux for phones, I think it's very, very far from AOSP. It completely misses the AOSP security model and the apps (no, I don't believe that running waydroid on Linux is entirely viable, otherwise instead of Linux for phone we would have Waydroid as an alternative to Android).

I think the only realistic alternative would be to build upon AOSP properly, with Google being just a contributor instead of the owner. But it cannot come from a community fork by someone in their garage, it has to come from Android manufacturers. I was hoping that Huawei would start something like that, instead they went with their own HarmonyOS.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#37

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

> This is all the more likely now that Google has been emboldened by not having to sell off Chrome for anticompetitive reasons.

Exactly. The only thing that can prevent this behaviour is regulations. But apparently nobody wants to regulate, so we're screwed.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#38
post #34

Earlier quoted context omitted.

The sad thing is I think Google keeping Chrome is actually likely the better of two possible bad outcomes... Anyone else interested and willing to pay the true value of owning the entire Internet ecosystem is almost certainly going to look to extract value from that, and that's almost certainly worse than what Google does today. E.g. using everyone's browser to extract training data for AI without getting IP blocked.

Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this. Maybe the development will slow down, but let's be honest: we would still be fine if Android and iOS had stopped "improving" years ago. Now it's mostly about adding shiny AI features and squeeze the users.

>Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this.

Facebook was once small too. Yet people happily signed up, giving up their privacy in the process. What makes you think the remaining companies offering a free browser wouldn't try to monetize users in a similar way? How many people are willing to pay $5/month for a browser?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#39

Earlier quoted context omitted.

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

The sad thing is I think Google keeping Chrome is actually likely the better of two possible bad outcomes... Anyone else interested and willing to pay the true value of owning the entire Internet ecosystem is almost certainly going to look to extract value from that, and that's almost certainly worse than what Google does today. E.g. using everyone's browser to extract training data for AI without getting IP blocked.

A year or so ago, I would have agreed. Not anymore.

Sure, a company can buy Chrome and proceed to sell user browsing habits data to the highest bidder, or use it as a backbone for decentralized scraping - backed by real user data and real residential IPs to fool most anti-scraping checks. But if they fuck with users enough, Chrome would just die off over time, and Firefox or various Chromium forks like Brave would take its place. This already happened to the browsing titan that was IE, and without the entire power of Google to push Chrome? It can happen again.

The alternative is Google owning Chrome for eternity - and proceeding with the most damaging initiatives possible. Right now, Google is seeking to destroy adblocking, tighten the control over the ad data ecosystem to undermine their competitors, and who knows what else they'll come up with next week.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#40
post #32

Earlier quoted context omitted.

Security/privacy?

So you want a $100 feature phone that has serious security features like monthly security patches and dedicated security coprocessors? It's tough to make the economics of that work out. All the serious security features costs money to implement, either in the form of development costs or added costs to the BOM. Those costs can be absorbed if you're selling a $600 phone, but not a $100 phone. If you try to add those f…

You missed my point, a simpler hardware/software phone needs less resources to maintain. No eyecandy/cushy features to maintain, security becomes easier to maintain by the community. No constantly added features and gimmicks which break and introduce weak points.

Let's not forget that all these "features" which enable corporations like Google take complete control over the project also end up driving price up, constantly. Cheap phones are a sh*t iteration of more expensive phones, instead of being simpler more basic implementations of must have features without the "quality of life" bloat on the top tier models. They should have a different tier OS rather than the same one.

I would also not make the parallel between comms devices and PCs, they're different beasts.

Post reply on HN