Delayed Security Patches for AOSP (Android Open Source Project)
101–110 of 116 posts
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#102Re: Delayed Security Patches for AOSP (Android Open Source Project)
#103Earlier quoted context omitted.
Serious question: do we know as a matter of fact that iOS and family are safer than Android, including Pixel, especially when it comes to 0-day exploits?
No, but Google has significantly downgraded security from it used to be and Apple isn't sharing security patches very broadly outside their company 4 months ahead of fixing them. They don't have partners to share it with. That's not to say there aren't people in the company leaking them but they likely don't take that long to fix most patches. We considered the Pixel stock OS largely competitive with iOS on security…
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#104Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier: https://wiki.postmarketos.org/wiki/Devices#Main Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging th…
I am the pmOS maintainer for the PinePhone. It was demoted from main to community because I was the only maintainer and one of the criteria for main is to have two or more maintainers. ( https://gitlab.postmarketos.org/postmarketOS/pmaports/-/merg... ) Originally many pmOS core devs were maintainers, which is why it was in main, but they all lost interest and it was about to be demoted to testing / unmaintained, so I…
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#105Earlier quoted context omitted.
Apps that run on the Kindle Fire can't use Google Mobile Services, and the Amazon appstore is missing many well-known titles. The Play Store is mostly absent from China, and I really don't know how that ecosystem works. Was there one ecosystem?
You're too young to remember Symbian and Java phone ecosystem mess, are you? Or even Android of around 2.x era, where getting an app doesn't mean it works on your phone?
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#106Earlier quoted context omitted.
Why not spin them each off into an independent non-profit?
Because people don't just throw away money.
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#107> We want to make sure that if you download an app from a developer, regardless of where you get it, it's actually from them. That's it. In what scenario is this a serious threat because I can't think of any.
People are installing banking apps that are actually from criminals. Basically app phishing.
There's 0 reason you should need an app to fucking pay for parking. Why do you then?
Because running mostly unsandboxed native code on customers devices is a fantastic way to steal data and build profiles. Browsers just don't cut it - they're too safe, too secure, too abstracted.
Let's be honest here - what is a banking app? Web forms, some more web forms, and then to top it off, some web forms. I mean, hell, half these apps are just web views with spywa - I mean analytics - slapped on top.
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#108This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…
Yep. If we’re gonna be forking browsers, Firefox should be the base, not Chromium. Mozilla is in much less of a position to abuse their position, and more Firefox forks means more chances that one catches on with some slice of the larger public and helps chip away at Blink hegemony.
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#109Earlier quoted context omitted.
You're too young to remember Symbian and Java phone ecosystem mess, are you? Or even Android of around 2.x era, where getting an app doesn't mean it works on your phone?
Oh, my sweet summer child, my first classroom exposure was CP/M.
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#110Earlier quoted context omitted.
I could see sort of an Android consortium taking over developing it and keeping it going outside of Google. Samsung, Oppo, Xiaomi, Huwawei, Motorola, etc. Honestly it'd probably be better off that way. Google has far too much influence and control.
None of those companies have a tiny little bit of interest of helping their competitors with joint development. I guess you're too young to remember the balkanization of Symbian among such companies?
Huawei found themselves on their own because of the ban, and decided to go for HarmonyOS NEXT. Probably they wouldn't come back to a "joint development AOSP" now.
Now if Google lost Android, what would happen for the others? Would they each try their luck with their own OS or would they try to go for a joint development?