Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

51–60 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#51
post #27

Earlier quoted context omitted.

That is a misrepresentation because Samsung, Huawei, and various Linux vendors each will have their own answer, their own alterative. In no universe will Apple be without competition. Apple is not even a consideration since it doesn't allow unapproved app installation anyway.

Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.

This ship has sailed, in the past Amazon's store did not succeed a lot, but there are already a few important enough offsprings: * Huawei with separate store and no Gapps * Samsung with importantly different browser and ton of extra features, also another store * in China the app-in-wechat and similar are a major thing

If you develop for a diverse set of user you need a lot of effort.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#52
post #48
post #43

Earlier quoted context omitted.

> Yet people happily signed up, giving up their privacy in the process. When Facebook started, it was a different era. And since then, Facebook has clearly abused their position with anti-competitive behaviours. > How many people are willing to pay $5/month for a browser? If they can keep using Google Chrome for free, we already know the answer. If the only way for them to have a reasonable browser would to pay... wh…

>When Facebook started, it was a different era. And since then, Facebook has clearly abused their position with anti-competitive behaviours. Insurgents like tiktok show that even today, people will happily give up their privacy for some dopamine. >If they can keep using Google Chrome for free, we already know the answer. Why would google continue maintaining chrome if they can no longer derive any benefit from it? >I…

> Why would google continue maintaining chrome if they can no longer derive any benefit from it?

That is unrelated to the sentence you quote: if people can use Google Chrome for free, they don't pay for a browser. But if Chrome disappeared, they would still need a browser. Maybe they would pay if they didn't have a free choice?

> No, the contention is that people will go for free browsers that violate their privacy or monetize them somehow, not some future where all browsers cost money.

If there are more browsers instead of a monopoly, then websites will work on the paid, secure browser that I will use, so I'm happy. I don't want to prevent people from using bad software: I want to make it possible for companies to build good software.

By not using Chromium today, many times the websites don't work correctly because devs don't care, because Chromium is a monopoly. I say split it! Then websites will have to work on more than 1 browser.

> Remember when whatsapp was also $1/year, ostensibly for similar reasons? How did that go?

It was a huge success? WhatsApp is still a huge success.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#53
post #46

Earlier quoted context omitted.

>a simpler hardware/software phone needs less resources to maintain And a such a product is going to absolutely niche, which means no economies of scale producing or maintaining it. You try to justify that by saying it'll be maintained by "the community", but who's going to want to do unglamorous work fixing security issues, compared to developing features? Mainstream phones have dedicated security teams and freelanc…

Ignoring how strangely against this idea you are, for no justifiable reason, it wouldn't look like a 3310, it would still look like a smart phone, probably OLED so more battery life. It would just miss a lot of modern features which are absolutely irrelevant to anyone who wants a privacy/security focused mobile phone. Probably not the latest CPU, not the latest mobile chip, but still decent for what it has to do.

>Ignoring how strangely against this idea you are, for no justifiable reason

Ignoring how you assert this, when I outlined plenty of reasons which you've yet to rebut...

>it wouldn't look like a 3310, it would still look like a smart phone, probably OLED so more battery life. It would just miss a lot of modern features which are absolutely irrelevant to anyone who wants a privacy/security focused mobile phone. Probably not the latest CPU, not the latest mobile chip, but still decent for what it has to do.

Sounds like a $200 mid-range phone that's sold in much of Asia. Question is, who's going to make it? How are you going to amortize the development costs? You mentioned that it's going to use custom software/hardware to keep security maintenance burden low, but how would that be funded? Most of the SoC vendors are going to be providing kernels/drivers to you with the expectation that you're going to use it to build an Android phone. Good luck convincing them to provide engineering support for your custom software/hardware stack.

Not to mention the questions about maintenance you haven't addressed aside from some handwaving about it'll be simpler and therefore can be "community maintained".

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#54
post #46

Earlier quoted context omitted.

>a simpler hardware/software phone needs less resources to maintain And a such a product is going to absolutely niche, which means no economies of scale producing or maintaining it. You try to justify that by saying it'll be maintained by "the community", but who's going to want to do unglamorous work fixing security issues, compared to developing features? Mainstream phones have dedicated security teams and freelanc…

Ignoring how strangely against this idea you are, for no justifiable reason, it wouldn't look like a 3310, it would still look like a smart phone, probably OLED so more battery life. It would just miss a lot of modern features which are absolutely irrelevant to anyone who wants a privacy/security focused mobile phone. Probably not the latest CPU, not the latest mobile chip, but still decent for what it has to do.

I have crossed paths with them before. Yellow rock approach.

https://danieldashnawcouplestherapy.com/blog/yellow-rock-met...

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#55
post #32

Earlier quoted context omitted.

Security/privacy?

So you want a $100 feature phone that has serious security features like monthly security patches and dedicated security coprocessors? It's tough to make the economics of that work out. All the serious security features costs money to implement, either in the form of development costs or added costs to the BOM. Those costs can be absorbed if you're selling a $600 phone, but not a $100 phone. If you try to add those f…

>Whenever microsoft tries to push for better security they get shouted down by people claiming it's some sort of conspiracy to implement DRM.

Mainly because it is, and you can go Q.E.D. all you like, but there doesn't need to be a bunch of mustachioed villains explicitly making evil plans when everyone's ultimate aims align. They're going to get theirs, and the rest will just be a long for the ride while those people in a position of power continue to weave a collective path through the space of "conspicuously unimplemented features".

The computer was meant to be as a calculator. An unassuming tool to automate the mundane, not as a link in the chain of techno-fascism/feudalism/tyranny. The only thing that will ward off that eventuality is how we as people embrace and guide it's further usage & implementation.

The tech is currently here for every bad ending. I want to make that clear. It has already arrived. The knowledge of it's configuration to bring those ends are the part that isn't quite realized yet. I pray that it won't be unearthed, but with the way things are currently going, I have serious doubts.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#56
post #46

Earlier quoted context omitted.

>a simpler hardware/software phone needs less resources to maintain And a such a product is going to absolutely niche, which means no economies of scale producing or maintaining it. You try to justify that by saying it'll be maintained by "the community", but who's going to want to do unglamorous work fixing security issues, compared to developing features? Mainstream phones have dedicated security teams and freelanc…

The Flipper Zero and its success through direct crowdfunding proves that if you build it, and this next step is equally important to the first, if you build a community around it to directly market it effectively with reversible crowdfunding, you don’t have to wait for them to then come, as they’re already here, right there with you.

Flipper zero doesn't really have a competitor, aside from maybe a bunch of bulky equipment that fits on a table. Such a feature phone would be competing against iPhones/Pixels, both of which are pretty secure and have dedicated security teams. Any new product would have to compete on price/feature/reputation, which would be tough.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#57
post #55
post #32

Earlier quoted context omitted.

So you want a $100 feature phone that has serious security features like monthly security patches and dedicated security coprocessors? It's tough to make the economics of that work out. All the serious security features costs money to implement, either in the form of development costs or added costs to the BOM. Those costs can be absorbed if you're selling a $600 phone, but not a $100 phone. If you try to add those f…

>Whenever microsoft tries to push for better security they get shouted down by people claiming it's some sort of conspiracy to implement DRM. Mainly because it is, and you can go Q.E.D. all you like, but there doesn't need to be a bunch of mustachioed villains explicitly making evil plans when everyone's ultimate aims align. They're going to get theirs, and the rest will just be a long for the ride while those people…

>Mainly because it is, and you can go Q.E.D. all you like, but there doesn't need to be a bunch of mustachioed villains explicitly making evil plans when everyone's ultimate aims align. They're going to get theirs, and the rest will just be a long for the ride while those people in a position of power continue to weave a collective path through the space of "conspicuously unimplemented features".

Like it or not, TPM was meant to increase security by deterring evil maid attacks. If you can't stop this sort of attack, your device doesn't offer serious security, and a feature phone with wifi/bluetooth/cellular data turned off probably has similar security. Moreover TPMs were introduced over a decade ago and there's still no DRM that's based on it. People did forget about SGX though, which came and went but had actual DRM built for it. I've also never heard a peep about HDCP which is specifically for DRM purposes and is built into every GPU/monitor.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#58
post #20

Earlier quoted context omitted.

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

I wonder if Android and Chrome would support open source even less as independent companies though.

Why not spin them each off into an independent non-profit?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#59
post #38
post #34

Earlier quoted context omitted.

Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this. Maybe the development will slow down, but let's be honest: we would still be fine if Android and iOS had stopped "improving" years ago. Now it's mostly about adding shiny AI features and squeeze the users.

>Split it to a point where no one company can own the entire Internet ecosystem. Apply antitrust laws to keep it like this. Facebook was once small too. Yet people happily signed up, giving up their privacy in the process. What makes you think the remaining companies offering a free browser wouldn't try to monetize users in a similar way? How many people are willing to pay $5/month for a browser?

Browsers should be classified as critical infrastructure and be run by NPOs or PBCs. There’d be no need for end users to pay anything if the tens of thousands of companies all relying on the web chipped in to sustain the infrastructure that allows them to exist and be profitable.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#60
post #56

Earlier quoted context omitted.

The Flipper Zero and its success through direct crowdfunding proves that if you build it, and this next step is equally important to the first, if you build a community around it to directly market it effectively with reversible crowdfunding, you don’t have to wait for them to then come, as they’re already here, right there with you.

Flipper zero doesn't really have a competitor, aside from maybe a bunch of bulky equipment that fits on a table. Such a feature phone would be competing against iPhones/Pixels, both of which are pretty secure and have dedicated security teams. Any new product would have to compete on price/feature/reputation, which would be tough.

The success of the Raspberry Pi proves that existence of competitors is no impediment to success with the proper connections with vendors and with the community.

The OpenWRT One is another example of collaborating with community trusted vendors to build a niche community based hardware product.

https://openwrt.org/toh/openwrt/one

Post reply on HN