Live data from Hacker News

There are over a billion outdated Android devices in use

danluu.com

181–190 of 474 posts

Re: There are over a billion outdated Android devices in use

#181

Earlier quoted context omitted.

On the other hand, if you care about privacy, then not updating your apps often helps too. Damned if you do, damned if you don't.

I think if you update often enough (at least when some vulnerabilities found), you're more safe than if you don't.

Except many times the update will ask to expand its access to information in your phone it shouldn't need. So you choose between explicitly granting permission for unnecessary data access or don't update and hope you don't get owned via a vulnerability in that app.

Re: There are over a billion outdated Android devices in use

#182

Earlier quoted context omitted.

Apple has allowed you to download the last compatible version for years - that ability goes as far back as at least iOS 5 that came out in 2012.

No it doesn't. It only allows you to do that for an app you already installed in the past. If you want to install an app for the first time, where the current version is incompatible with your OS, you can't. Believe me, I've tried.

There is an work around, download it via iTunes. You don't have to sync via iTunes to do it just use the same account. Apple still makes the previous version of iTunes that allowed you to download apps available to download.

Re: There are over a billion outdated Android devices in use

#183
post #73

Earlier quoted context omitted.

Even if this were true (it's not) that was a conscious choice by Google to capture market share. This issue was predicted (and observed) years ago, almost since the release of Android in fact, and is only getting worse. That is all due to Google's own choices.

The real problem with it is Linux. Here's a few facts: The Kernel has no stable ABI for drivers. Manufacturers only ever develop a driver for their chips once, and then send that to the OEM. They never update. The Linux Kernel LTS gets 2 years of updates, Google's fork about 4. From the day a Kernel is released, to the day it ships in a phone, usually 2 years are spent integrating the blobs and code drops from the ch…

Well that’s not actually a problem if Google controlled the hardware (or a hardware standard, at least).

But they don’t.

So while you’re absolutely correct from a technical perspective it’s still a consequence of Googles strategy, and a problem for us all.

Re: There are over a billion outdated Android devices in use

#184
post #79

I still have Nexus 7 running on KitKat 4.2 as I dislike material look and for newer Android versions I always go with phones that ship with customized UI that better correspond to my aesthetics sense. Disclaimer: I am a visual artist as well and hate it when somebody enforces certain style, in my case anything flat, low-contrast, confusing where my brain has to spend >20ms identifying controls.

Are you concerned at all with security of the device? Just asking because I know lots of people who stick with older droids and none seem to care.

Sure I am concerned and am pretty well-versed in advanced cryptology myself and protocol/stack weaknesses/exploits. Frankly, Android lost me when I once bought a new phone and after installing a few apps from play store it was spamming me like crazy and discussing stuff with servers in China. Since then I use all Android devices for harmless stuff like browsing while in bath/sauna, controlling my DJI drone, navigation device on my bike, watching edX/Udacity/Coursera/Udemy etc. but never for serious stuff. For serious stuff I use Sailfish on a recent Jolla phone instead with customized security stack compiled from sources (security by obscurity as well).

Re: There are over a billion outdated Android devices in use

#185
post #181

Earlier quoted context omitted.

I think if you update often enough (at least when some vulnerabilities found), you're more safe than if you don't.

Except many times the update will ask to expand its access to information in your phone it shouldn't need. So you choose between explicitly granting permission for unnecessary data access or don't update and hope you don't get owned via a vulnerability in that app.

So instead of finding someway to block or spoof a developer telling you they need different permissions, you'll wait around until some hacker breaks into your shit feeling like you beat the system?

Re: There are over a billion outdated Android devices in use

#186

Earlier quoted context omitted.

I have a rooted device, so I can basically make apps do what I want and stop them from doing what I don't want. IMHO that's far better than Google's vision of "security" where they want to be in control and even consider the user an attacker.

How much of a solution is rooting a device for 1 billion users?

I think every device should ship with root by default, it's the case for computers, I don't see why phones would be any different.

Re: There are over a billion outdated Android devices in use

#189

Earlier quoted context omitted.

The only impact? You are a walking vulnerability. KRACK, Blueborne, just to name a few recently highly publicized vulnerabilities. You are like the perfect exploit, just waiting to get pwned. You are, Bill Harper.

I, like the parent poster, am running the latest update for my phone. Yes, I know I'm a walking vulnerability, but short of purchasing a new phone, there is nothing I can do about it. IIRC, updates for my device were cut off before it was even out of warranty , and I'm sorry, I'm not dropping — I can't drop — $600 every year and a half on new hardware just to get new software. Vendors need to support devices for the…

You don't have to drop $600 every year and a half. Which would only be $34 a month over that period.

You can drop $600 every 3 years with google devices and have monthly security updates. You could save $17 every month for that 3 year time to buy the next phone.

If you want to stay secure you will, if it not a priority you wont.

Re: There are over a billion outdated Android devices in use

#190

Earlier quoted context omitted.

Dangerous? What's the worse that could happen?

1. Ability to passively decrypt network activity (KRACK). 2. Ability to throw a fully persistent implant onto the device (via Wi-Fi exploit + pivot to AP kernel exploit)

Most phones already come with two persistent implants - the user-antagonistic OS, and the baseband processor!

I'm all for trusting computing devices to act as one's agents, but attempting to do so with anything resembling a modern mobile phone is barking up the wrong tree.

Even though just having one means taking the location-tracking hit from negligently designed cellular protocols, further exposure can be mitigated by using these little snitches for as little personal activity as possible.

Post reply on HN