Live data from Hacker News

Forced to upgrade

herman.bearblog.dev

271–280 of 303 posts

Re: Forced to upgrade

#271

Earlier quoted context omitted.

Nothing inherent makes security on 7 year old hardware any more difficult than on 2 year old hardware. Also, we're getting into the differences between upgrades (what OP said) and updates (the thing necessary to keep up with security) here. I'm having a really hard time coming up with an OS feature introduced in a full OS upgrade within the last 10 years that I actually want. I would have been perfectly content with…

> I'm having a really hard time coming up with an OS feature introduced in a full OS upgrade within the last 10 years that I actually want. - Live Photos. I won't consider any device that doesn't have something analogous, now. They're magical. Non-kid-havers may feel otherwise, but making every photo I snap of my kids a "Live Photo" is one of the most important improvements any technology thingy has provided in my en…

Copying on any device and immediately pasting on any other device I own.

Headphones automatically connecting to any of my devices that play audio, even switching between them.

Re: Forced to upgrade

#272

Earlier quoted context omitted.

I think we should expect basic software security updates and third party app compatibility to continue until the last device’s hardware fails. This idea that a device that millions of people still use is “old and icky and we just don’t wanna support it anymore” is user-hostile and should not be tolerated.

I've still got a working Android Dev Phone 1 here. Updated fully to Android 1.6. Got a massive 256MB of internal storage (basically none usable, mind you, all taken up by the OS) and a zippy 500MHz processor with a single core to share between the OS and apps. What you're proposing is a massive waste of effort and talent--attempting to accomplish something bordering on impossible with a benefit of practically nil. In…

I wouldn’t take it too seriously. It’s just a HN opinion that always gets upvoted because it’s the right intersection of anti-Big Tech, pro-environment and not wanting to change your own workflow (https://xkcd.com/1172/).

People who’ve actually had to maintain software that supports old hardware understand that it is a business decision. Is the cost of supporting older hardware (harder to maintain software, unable to use newer APIs, need to maintain multiple, rarely used code paths) greater than the benefit (revenue, network effect of keeping users)?

At Meta with billions of users the network effect and revenue means that they’ll never stop supporting Android 5 and up. But for a small app with a couple million users and a few thousand users on the oldest OS, it won’t make sense.

People actively throwing their toys out their pram choose not to understand this trade off. They think this can be solved with regulation like it’s a magic wand that makes economic trade offs disappear.

Re: Forced to upgrade

#273

Earlier quoted context omitted.

If I upgrade Windows, and it breaks my line-of-business program, whose fault is it? Hint: It's the one that changed.

If your application uses raw NT syscall (which Microsoft explicitly says is an unstable interface) and an upgrade breaks it, then the application certainly is at fault. Like, this isn't some incidental case where you accidentally depended on unspecified behavior or an official interface broke; if there's a big warning on an interface that says this thing is unstable and will break your code, and it breaks your code,…

If there was no stable interface to Windows, that would also be Microsoft's fault.

Re: Forced to upgrade

#274
post #164

Earlier quoted context omitted.

I love SE3, had SE2 before it. I love the phone and the size, but I do NOT love the battery life.. It's manageable though.

I have https://iwalkmall.com/products/cute-portable-charger-4500mah to extend the battery life when I'm on the go

I'd be scared to break the thing: it is so big and directly connected. It wouldn't fit into a pocket anyway...

Also I wouldn't choose one with a lightning connector, better with a USB-C (or A) female port, so I could also use it for some other devices too if necessary.

Re: Forced to upgrade

#275

Earlier quoted context omitted.

SMS for 2FA is being phased out due to security concerns, but I don't get why they aren't using plain TOTP, so you can use any authenticator app you'd like. My bank did solve the issue in a pretty clever way though. Their phone app is so terrible that I refuse to use it. Sadly there new web version is also terrible, e.g. you can't copy paste when doing a transfer, so rather than being 100% sure the amount is correct,…

> but I don't get why they aren't using plain TOTP, so you can use any authenticator app you'd like Compared to the non-app solutions I'm familiar with in Germany, TOTP lacks at least two things: 1. There are no guarantees as to what happens to the shared secret (whereas at least some of these alternative solutions use your debit card as a smartcard to securely store the secret). From an individual point of view I gu…

> Perhaps more importantly, you can't really authenticate the individual transaction,

> also include the destination account and sum of money to be transferred in the TAN calculation

Which banks have it implemented? You are giving them too much credit. In most cases their 2FA is simply code consisting of digits or tapping multiple "confirm" without any context inside of their losy apps. In my personal anecdotal experience only SMS 2FA contain some additional information what exactly are you confirming.

Re: Forced to upgrade

#276

Earlier quoted context omitted.

> but I don't get why they aren't using plain TOTP, so you can use any authenticator app you'd like Compared to the non-app solutions I'm familiar with in Germany, TOTP lacks at least two things: 1. There are no guarantees as to what happens to the shared secret (whereas at least some of these alternative solutions use your debit card as a smartcard to securely store the secret). From an individual point of view I gu…

> Perhaps more importantly, you can't really authenticate the individual transaction, > also include the destination account and sum of money to be transferred in the TAN calculation Which banks have it implemented? You are giving them too much credit. In most cases their 2FA is simply code consisting of digits or tapping multiple "confirm" without any context inside of their losy apps. In my personal anecdotal exper…

> Which banks have it implemented?

In Germany all banks here (https://www.kontofinder.de/ratgeber/tan-verfahren-ueberblick...) that are listed as supporting chipTAN [1], plus probably most of those that are listed as supporting photoTAN [2] allow using a hardware photoTAN generator instead of an app, too (though sadly some banks like Ing-Diba require their own proprietary photoTAN generator instead of a standard photoTAN-device as supported by some other banks).

[1] That one is using your debit card as a smartcard for the shared secret.

[2] That one requires the shared secret to be transmitted to you in some form (probably a QR-code or something similar in a letter) and set up in the photoTAN generator app/hardware device on first use.

Re: Forced to upgrade

#277

Earlier quoted context omitted.

Google now promises seven years of OS and security updates. The latest Pixels should be supported until August or September 2031. That said, I don't trust Google, and would recommend filling out the arbitration optout form when you receive the device.

> and would recommend filling out the arbitration optout form when you receive the device. Do you assume you'll have some issue with them that will be worth individually suing them for?

What would such an assumption have to do with anything? I put my seatbelt on even when I don't intend to get into car crashes.

Arbitration clauses and class-action waivers universally favor the corporation -- in this case Google -- and should not be legal. I'm proud to retain my basic legal rights.

Re: Forced to upgrade

#278

Earlier quoted context omitted.

Google now promises seven years of OS and security updates. The latest Pixels should be supported until August or September 2031. That said, I don't trust Google, and would recommend filling out the arbitration optout form when you receive the device.

It's crazy that they don't put a scare screen for arbitration before checkout.

They never have to-- if people knew about them, they would opt out, and Google would lose their advantage.

Re: Forced to upgrade

#279

The main message I take from this story is that a decent quorum of consumers want Apple to offer a smaller phone in each generation. The OP seems not to have minded having to upgrade eventually, just not to a “virtual tablet.” I’ve heard others express the same desire.

The impression I get is that these consumers who want a smaller phone are a very loud minority. They also often seem to overlap with the set of consumers who are extremely cheap. To Apple they are just bad customers who they will always have a hard time making money from -- not super worth catering to.

Why is being a minority consumer worthy of a dismissal and lack of service?

Re: Forced to upgrade

#280

Earlier quoted context omitted.

> I'm having a really hard time coming up with an OS feature introduced in a full OS upgrade within the last 10 years that I actually want. - Live Photos. I won't consider any device that doesn't have something analogous, now. They're magical. Non-kid-havers may feel otherwise, but making every photo I snap of my kids a "Live Photo" is one of the most important improvements any technology thingy has provided in my en…

Neither of those should require an OS upgrade though, those should be apps.

You could already OCR. What made me actually use it was exactly its becoming an OS feature. Now it seems weird if there's an image with text and I can't select the text I can plainly see on my screen.
Post reply on HN