Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

71–80 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#71
post #24

The only reason that would make me fear from an antitrust judgement splitting Android from Google is that it may lose the Google contributions to AOSP. Google is more and more showing that they really don't want to contribute to AOSP . So for me, Android should be split out of Google. Maybe the other Android manufacturers will start contributing to AOSP, and maybe Android will die. But let me be honest: if Google kee…

Note the post title is incorrect. See https://news.ycombinator.com/item?id=45160975. Android patches are being delayed in general, not only for AOSP.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#72

And so, Google's war on open Android continues. Fucking hell. Can Google stop being evil for like 5 minutes? It's like they can't go a week without coming up with some new fucked up thing to do to their already tormented mobile ecosystem.

"Why should people believe what you say about /^.*$/?"

That regex derived from the tweet seems apt.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#73

FYI the poster this story links to says that this title is incorrect: https://x.com/grapheneos/status/1964757878910136346?s=46 They say this: Our reply here was linked on Hacker News with an inaccurate title ("Delayed Security Patches for AOSP"). Security patch backports were pushed to AOSP on September 2nd for Android 13, 14 and 15 as expected. More information is available at x.com/GrapheneOS/sta… explaining the si…

X cut off the link you copied within our reply. Here's that link along with 2 alternatives other than X:

https://x.com/GrapheneOS/status/1964754118653952027

https://bsky.app/profile/grapheneos.org/post/3lyb6rx46tc2r

https://grapheneos.social/@GrapheneOS/115164133992525834

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#74
post #26

Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier: https://wiki.postmarketos.org/wiki/Devices#Main Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging th…

[deleted]

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#75

And so, Google's war on open Android continues. Fucking hell. Can Google stop being evil for like 5 minutes? It's like they can't go a week without coming up with some new fucked up thing to do to their already tormented mobile ecosystem.

Note the post title is incorrect. See https://news.ycombinator.com/item?id=45160975. Android patches are being delayed in general, not only for AOSP.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#76
post #27

Earlier quoted context omitted.

That is a misrepresentation because Samsung, Huawei, and various Linux vendors each will have their own answer, their own alterative. In no universe will Apple be without competition. Apple is not even a consideration since it doesn't allow unapproved app installation anyway.

Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.

Apps that run on the Kindle Fire can't use Google Mobile Services, and the Amazon appstore is missing many well-known titles.

The Play Store is mostly absent from China, and I really don't know how that ecosystem works.

Was there one ecosystem?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#77
post #57
post #55

Earlier quoted context omitted.

>Whenever microsoft tries to push for better security they get shouted down by people claiming it's some sort of conspiracy to implement DRM. Mainly because it is, and you can go Q.E.D. all you like, but there doesn't need to be a bunch of mustachioed villains explicitly making evil plans when everyone's ultimate aims align. They're going to get theirs, and the rest will just be a long for the ride while those people…

>Mainly because it is, and you can go Q.E.D. all you like, but there doesn't need to be a bunch of mustachioed villains explicitly making evil plans when everyone's ultimate aims align. They're going to get theirs, and the rest will just be a long for the ride while those people in a position of power continue to weave a collective path through the space of "conspicuously unimplemented features". Like it or not, TPM…

Okay, so there's so much wrong here i don't know where to start.

> Like it or not, TPM was meant to increase security by deterring evil maid attacks. If you can't stop this sort of attack, your device doesn't offer serious security, and a feature phone with wifi/bluetooth/cellular data turned off probably has similar security

TPMs in their commercial implementation do not deter any evil maid attack. Only some special cases like HEADS Firmware actually protects you from an evil maid attack. TPMs, Secureboot, etc. merely prevent non-signed code from booting when the hard has not been tampered with. Tamper with the hardware and make it show a green "everything is fine" screen while booting a tainted kernel and device drivers and a tpm won't save you.

> Moreover TPMs were introduced over a decade ago and there's still no DRM that's based on it.

Google Play Integrity API is essentially this. Can't run certain apps on devices that don't pass TPM based attestation. Not exactly DRM but something akin to it.

> People did forget about SGX though, which came and went but had actual DRM built for it.

People didn't forget, it got broken so badly intel gave up on it.

> I've also never heard a peep about HDCP which is specifically for DRM purposes and is built into every GPU/monitor.

You've just not been listening. It's just that HDCP also has been bypassed a lot.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#78
post #26

Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier: https://wiki.postmarketos.org/wiki/Devices#Main Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging th…

[deleted]

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#79
post #26

Looks like PostmarketOS (mainline Linux for phones, with choice of frontend, such as Plasma Mobile or Phosh) has demoted all their previous "Main"-tier devices to "Community" or lower tier: https://wiki.postmarketos.org/wiki/Devices#Main Anyone know whether this is a sign of a push for being daily driver quality? Or a sign that volunteers previously doing promising work have drifted away, and they're acknowledging th…

I am the pmOS maintainer for the PinePhone. It was demoted from main to community because I was the only maintainer and one of the criteria for main is to have two or more maintainers. ( https://gitlab.postmarketos.org/postmarketOS/pmaports/-/merg... ) Originally many pmOS core devs were maintainers, which is why it was in main, but they all lost interest and it was about to be demoted to testing / unmaintained, so I volunteered to become the maintainer to stop that from happening.

A blanket statement of a phone being "of daily driver quality or not" is impossible to make because everyone has different expectations of a "daily driver". I have been daily-driving the PinePhone since 2021 (it is my first and only smartphone) but that doesn't mean everyone else will be happy with it.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#80
post #64

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Security patches aren't being delayed for AOSP specifically but rather Android as a whole including the stock Pixel OS. The title is misinterpreting our reply. We didn't say they're delaying patches to AOSP specifically. Stock Pixel OS has delayed patches too. A more detailed explanation is at https://x.com/GrapheneOS/status/1964754118653952027 . GrapheneOS has an OEM partner and early access to the security patches…

[deleted]
Post reply on HN