Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

111–116 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#112
post #100
post #96

Earlier quoted context omitted.

Serious question: do we know as a matter of fact that iOS and family are safer than Android, including Pixel, especially when it comes to 0-day exploits?

No, but Google has significantly downgraded security from it used to be and Apple isn't sharing security patches very broadly outside their company 4 months ahead of fixing them. They don't have partners to share it with. That's not to say there aren't people in the company leaking them but they likely don't take that long to fix most patches. We considered the Pixel stock OS largely competitive with iOS on security…

> Both should result in substantial regulatory action against them, and perhaps it will, but it will probably come a very long time from now when the damage is done.

Instead of focusing on ChatControl, the EU should look into that...

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#113
post #8

> We want to make sure that if you download an app from a developer, regardless of where you get it, it's actually from them. That's it. In what scenario is this a serious threat because I can't think of any.

It sounds like EV certificates, and it turned out that in practice no one cared about id verification.

This feels like an airplane bullet hole example.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#114

Earlier quoted context omitted.

Not the OP, but Google spent years advertising Chrome front and center on the Internet's most visited pages. Money doesn't buy that kind of real estate, ownership does.

> Money doesn't buy that kind of real estate, ownership does. If this is the reason, the remedy doesn't attack the root of the matter. If Chrome were unbundled from Google, what's to stop Google from creating a new Chromium fork - and naming it Cobalt and marketing the hell out of it to achieve the same market share?

Antitrust orders are more complicated than just declaring a business unit spontaneously independent. They usually include provisions to ensure the the situation is actually fixed, like prohibitions on the parent competing in that entire market and financial/infrastructure support for the new companies on their transition to independence.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#115

Earlier quoted context omitted.

> Money doesn't buy that kind of real estate, ownership does. If this is the reason, the remedy doesn't attack the root of the matter. If Chrome were unbundled from Google, what's to stop Google from creating a new Chromium fork - and naming it Cobalt and marketing the hell out of it to achieve the same market share?

Antitrust orders are more complicated than just declaring a business unit spontaneously independent. They usually include provisions to ensure the the situation is actually fixed, like prohibitions on the parent competing in that entire market and financial/infrastructure support for the new companies on their transition to independence.

Are you able to share a case when an American court issued such a broad order on a F100 company? There was a stronger case for breaking up Microsoft, but the DoJ shied from that remedy, there was never a chance that Google could have been broken up in this case, IMO.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#116
post #62

Earlier quoted context omitted.

Why not spin them each off into an independent non-profit?

Because people don't just throw away money.

Of course they don't. But the courts/government should force them to do so in this case. If the company or its shareholders need to be compensated then so be it. Better to pay them off and get Android and Chrome out of their hands before they can cause further damage.
Post reply on HN