Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

41–50 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#41

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

And by destroying the Android development team you'd achieve what exactly? Magical appearance of the security patches you're complaining about here?

Would you start to actually pay for all those hundreds of engineers maintaining the OS?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#42
post #7

Google sold Android to nerds as open source. We thought that mobile operating systems would be won by the "Linux of mobile OSs." But Google has made sure that didn't happen and we're left with devices more locked down than the proprietary Windows ecosystem we were hoping to leave in the past - and with a company in charge looking to exert even more power over us than Microsoft did.

The trick is adding a ton of features which expose extra attack surface that needs them to maintain and fix, under the pretense that it will make everyone's life easier. Make it complicated enough so that the community cannot maintain it, enabling the corporation to throw its weight around.

It’s the perfected form of what MS was trying to achieve with IE back in the 90s. All the power of a closed source monopoly, further enhanced by friends and foes alike incorporating your tech as a load-bearing pillar of their strategies, with a cloak of plausible deniability in the form of an open source repo protecting you from antitrust enforcement. A true have your cake and eat it situation.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#43
post #38
post #34

Earlier quoted context omitted.

Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this. Maybe the development will slow down, but let's be honest: we would still be fine if Android and iOS had stopped "improving" years ago. Now it's mostly about adding shiny AI features and squeeze the users.

>Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this. Facebook was once small too. Yet people happily signed up, giving up their privacy in the process. What makes you think the remaining companies offering a free browser wouldn't try to monetize users in a similar way? How many people are willing to pay $5/month for a browser?

> Yet people happily signed up, giving up their privacy in the process.

When Facebook started, it was a different era. And since then, Facebook has clearly abused their position with anti-competitive behaviours.

> How many people are willing to pay $5/month for a browser?

If they can keep using Google Chrome for free, we already know the answer. If the only way for them to have a reasonable browser would to pay... who knows? People pay more than that to access movies that they could download as torrents.

Also does it have to be 5$ per month? Do browsers need to keep adding so many features, and hence so many bugs and security issues, that only huge companies can keep up and nobody wants to pay for that work?

Maybe it's enough to pay 1$/year for a company to maintain a reasonably secure browser with the features that people actually need. Do people actually need QUIC? Not sure.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#44
post #41

Earlier quoted context omitted.

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

And by destroying the Android development team you'd achieve what exactly? Magical appearance of the security patches you're complaining about here? Would you start to actually pay for all those hundreds of engineers maintaining the OS?

Either the new company takes over maintaining Android, or it fumbles the bag and the development becomes less centralized for a while - until some leader emerges and takes over.

Either way, the new control center of Android wouldn't be Google. A decade ago, I would have seen that as a very bad thing. Now, I'm almost certain that this would be a change for the better. Google is not what it once was.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#45
post #41

Earlier quoted context omitted.

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

And by destroying the Android development team you'd achieve what exactly? Magical appearance of the security patches you're complaining about here? Would you start to actually pay for all those hundreds of engineers maintaining the OS?

Drone manufacturers like Samsung, Xiaomi etc need an OS. Right now it's more profitable for them to just pay licences to Google. But if Google lost Android... they would need to find a solution.

I would like to see this, at least something would be happening.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#46
post #32

Earlier quoted context omitted.

So you want a $100 feature phone that has serious security features like monthly security patches and dedicated security coprocessors? It's tough to make the economics of that work out. All the serious security features costs money to implement, either in the form of development costs or added costs to the BOM. Those costs can be absorbed if you're selling a $600 phone, but not a $100 phone. If you try to add those f…

You missed my point, a simpler hardware/software phone needs less resources to maintain. No eyecandy/cushy features to maintain, security becomes easier to maintain by the community. No constantly added features and gimmicks which break and introduce weak points. Let's not forget that all these "features" which enable corporations like Google take complete control over the project also end up driving price up, consta…

>a simpler hardware/software phone needs less resources to maintain

And a such a product is going to absolutely niche, which means no economies of scale producing or maintaining it. You try to justify that by saying it'll be maintained by "the community", but who's going to want to do unglamorous work fixing security issues, compared to developing features? Mainstream phones have dedicated security teams and freelance vulnerability researchers going after them for fame/clout. Who would want to do security research for what's essentially a glorified nokia 3310 that maybe 1000 people use?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#48
post #43
post #38

Earlier quoted context omitted.

>Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this. Facebook was once small too. Yet people happily signed up, giving up their privacy in the process. What makes you think the remaining companies offering a free browser wouldn't try to monetize users in a similar way? How many people are willing to pay $5/month for a browser?

> Yet people happily signed up, giving up their privacy in the process. When Facebook started, it was a different era. And since then, Facebook has clearly abused their position with anti-competitive behaviours. > How many people are willing to pay $5/month for a browser? If they can keep using Google Chrome for free, we already know the answer. If the only way for them to have a reasonable browser would to pay... wh…

>When Facebook started, it was a different era. And since then, Facebook has clearly abused their position with anti-competitive behaviours.

Insurgents like tiktok show that even today, people will happily give up their privacy for some dopamine.

>If they can keep using Google Chrome for free, we already know the answer.

Why would google continue maintaining chrome if they can no longer derive any benefit from it?

>If the only way for them to have a reasonable browser would to pay... who knows? People pay more than that to access movies that they could download as torrents.

No, the contention is that people will go for free browsers that violate their privacy or monetize them somehow, not some future where all browsers cost money.

>Maybe it's enough to pay 1$/year for a company to maintain a reasonably secure browser with the features that people actually need. Do people actually need QUIC? Not sure.

Remember when whatsapp was also $1/year, ostensibly for similar reasons? How did that go?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#49
post #46

Earlier quoted context omitted.

You missed my point, a simpler hardware/software phone needs less resources to maintain. No eyecandy/cushy features to maintain, security becomes easier to maintain by the community. No constantly added features and gimmicks which break and introduce weak points. Let's not forget that all these "features" which enable corporations like Google take complete control over the project also end up driving price up, consta…

>a simpler hardware/software phone needs less resources to maintain And a such a product is going to absolutely niche, which means no economies of scale producing or maintaining it. You try to justify that by saying it'll be maintained by "the community", but who's going to want to do unglamorous work fixing security issues, compared to developing features? Mainstream phones have dedicated security teams and freelanc…

Ignoring how strangely against this idea you are, for no justifiable reason, it wouldn't look like a 3310, it would still look like a smart phone, probably OLED so more battery life. It would just miss a lot of modern features which are absolutely irrelevant to anyone who wants a privacy/security focused mobile phone. Probably not the latest CPU, not the latest mobile chip, but still decent for what it has to do.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#50
post #46

Earlier quoted context omitted.

You missed my point, a simpler hardware/software phone needs less resources to maintain. No eyecandy/cushy features to maintain, security becomes easier to maintain by the community. No constantly added features and gimmicks which break and introduce weak points. Let's not forget that all these "features" which enable corporations like Google take complete control over the project also end up driving price up, consta…

>a simpler hardware/software phone needs less resources to maintain And a such a product is going to absolutely niche, which means no economies of scale producing or maintaining it. You try to justify that by saying it'll be maintained by "the community", but who's going to want to do unglamorous work fixing security issues, compared to developing features? Mainstream phones have dedicated security teams and freelanc…

The Flipper Zero and its success through direct crowdfunding proves that if you build it, and this next step is equally important to the first, if you build a community around it to directly market it effectively with reversible crowdfunding, you don’t have to wait for them to then come, as they’re already here, right there with you.
Post reply on HN