Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

101–110 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#103
post #100
post #96

Earlier quoted context omitted.

Serious question: do we know as a matter of fact that iOS and family are safer than Android, including Pixel, especially when it comes to 0-day exploits?

No, but Google has significantly downgraded security from it used to be and Apple isn't sharing security patches very broadly outside their company 4 months ahead of fixing them. They don't have partners to share it with. That's not to say there aren't people in the company leaking them but they likely don't take that long to fix most patches. We considered the Pixel stock OS largely competitive with iOS on security…

Thanks, very informative

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#104
post #26

Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier: https://wiki.postmarketos.org/wiki/Devices#Main Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging th…

I am the pmOS maintainer for the PinePhone. It was demoted from main to community because I was the only maintainer and one of the criteria for main is to have two or more maintainers. ( https://gitlab.postmarketos.org/postmarketOS/pmaports/-/merg... ) Originally many pmOS core devs were maintainers, which is why it was in main, but they all lost interest and it was about to be demoted to testing / unmaintained, so I…

Thank you for your work on PostmarketOS.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#105
post #93
post #76

Earlier quoted context omitted.

Apps that run on the Kindle Fire can't use Google Mobile Services, and the Amazon appstore is missing many well-known titles. The Play Store is mostly absent from China, and I really don't know how that ecosystem works. Was there one ecosystem?

You're too young to remember Symbian and Java phone ecosystem mess, are you? Or even Android of around 2.x era, where getting an app doesn't mean it works on your phone?

Oh, my sweet summer child, my first classroom exposure was CP/M.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#106
post #62

Earlier quoted context omitted.

Why not spin them each off into an independent non-profit?

Because people don't just throw away money.

Non-profits can make a lot of money, they just have to reinvest said money back into capital, labor, or R&D. Non-profits can absolutely charge a license as well, if they want. You can do that with OSS, too. Just make it GPL and then charge for a more generous license like Qt does.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#107
post #12
post #8

> We want to make sure that if you download an app from a developer, regardless of where you get it, it's actually from them. That's it. In what scenario is this a serious threat because I can't think of any.

People are installing banking apps that are actually from criminals. Basically app phishing.

The reason this happens is that greedy companies like Google have made apps the de facto way to get anything done.

There's 0 reason you should need an app to fucking pay for parking. Why do you then?

Because running mostly unsandboxed native code on customers devices is a fantastic way to steal data and build profiles. Browsers just don't cut it - they're too safe, too secure, too abstracted.

Let's be honest here - what is a banking app? Web forms, some more web forms, and then to top it off, some web forms. I mean, hell, half these apps are just web views with spywa - I mean analytics - slapped on top.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#108

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Yep. If we’re gonna be forking browsers, Firefox should be the base, not Chromium. Mozilla is in much less of a position to abuse their position, and more Firefox forks means more chances that one catches on with some slice of the larger public and helps chip away at Blink hegemony.

Last time I suggested brave on hn to base off on Firefox and they said its pita but we have unpaid.volunteer run waterfox and others, then we have floorp, tor and others so I know for a fact brave not basing on Firefox is pure politics because of brendan

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#109
post #105
post #93

Earlier quoted context omitted.

You're too young to remember Symbian and Java phone ecosystem mess, are you? Or even Android of around 2.x era, where getting an app doesn't mean it works on your phone?

Oh, my sweet summer child, my first classroom exposure was CP/M.

Then you should know better :))

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#110
post #91

Earlier quoted context omitted.

I could see sort of an Android consortium taking over developing it and keeping it going outside of Google. Samsung, Oppo, Xiaomi, Huwawei, Motorola, etc. Honestly it'd probably be better off that way. Google has far too much influence and control.

None of those companies have a tiny little bit of interest of helping their competitors with joint development. I guess you're too young to remember the balkanization of Symbian among such companies?

Those are companies, their only interest is to maximise profit. Apparently right now the most profitable is to pay Google for the Android licence.

Huawei found themselves on their own because of the ban, and decided to go for HarmonyOS NEXT. Probably they wouldn't come back to a "joint development AOSP" now.

Now if Google lost Android, what would happen for the others? Would they each try their luck with their own OS or would they try to go for a joint development?

Post reply on HN