Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

81–90 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#81

Earlier quoted context omitted.

Yep. If we’re gonna be forking browsers, Firefox should be the base, not Chromium. Mozilla is in much less of a position to abuse their position, and more Firefox forks means more chances that one catches on with some slice of the larger public and helps chip away at Blink hegemony.

Fully agreed. I am however worried by the fact that Firefox is basically kept alive by Google. I assume it's just so that they can pretend Chrome isn't a monopoly, but the minute Firefox becomes an inconvenience they can stop financing it. I hope we can find a way for Firefox to sustain itself long term.

Google pays Firefox for traffic acquisition, not out of pity. If Google stopped paying, another search engine like Bing or Perplexity would be happy to take over.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#82
post #64

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Security patches aren't being delayed for AOSP specifically but rather Android as a whole including the stock Pixel OS. The title is misinterpreting our reply. We didn't say they're delaying patches to AOSP specifically. Stock Pixel OS has delayed patches too. A more detailed explanation is at https://x.com/GrapheneOS/status/1964754118653952027 . GrapheneOS has an OEM partner and early access to the security patches…

Thanks for the clarification. Delaying patches for all Android is even worse than delaying for AOSP. Excerpts below.

  .. Google recently made.. misguided changes to Android security updates.. almost entirely quarterly instead of monthly to make it easier for OEMs. They're giving OEMs 3-4 months of early access which we know for a fact is being widely leaked including to attackers.

 .. Google's existing system for distributing security patches to OEMs was already.. problematic. Extending 1 month of early access to 4 months is atrocious. This applies to all of the patches in the bulletins. This is harming Android security to make OEMs look better by lowering the bar.. The existing system should have been moving towards shorter broad disclosure of patches instead of 30 days. 

  .. Android's management has clearly overruled the concerns of their security team and chosen to significantly harm Android security for marketing reasons.. Android is very understaffed due to layoffs/buyouts and insufficient hiring.. Google does a massive portion of the security work on the Linux kernel, LLVM and other projects.. providing the resources and infrastructure for Linux kernel LTS releases. Others aren't stepping up to the plate.
This would be a good discussion topic for the Linux Plumbers conference in 3 months.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#83

FYI the poster this story links to says that this title is incorrect: https://x.com/grapheneos/status/1964757878910136346?s=46 They say this: Our reply here was linked on Hacker News with an inaccurate title ("Delayed Security Patches for AOSP"). Security patch backports were pushed to AOSP on September 2nd for Android 13, 14 and 15 as expected. More information is available at x.com/GrapheneOS/sta… explaining the si…

Thanks for the clarification. 90 day embargo of patches for all Android is worse than delaying for AOSP, https://news.ycombinator.com/item?id=45158523#45161240

  They're giving OEMs 3-4 months of early access which we know for a fact is being widely leaked including to attackers.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#84
post #41

Earlier quoted context omitted.

And by destroying the Android development team you'd achieve what exactly? Magical appearance of the security patches you're complaining about here? Would you start to actually pay for all those hundreds of engineers maintaining the OS?

Either the new company takes over maintaining Android, or it fumbles the bag and the development becomes less centralized for a while - until some leader emerges and takes over. Either way, the new control center of Android wouldn't be Google. A decade ago, I would have seen that as a very bad thing. Now, I'm almost certain that this would be a change for the better. Google is not what it once was.

Or a more likely scenario is that Apple picks up even more market share, and we go from a duopoly to a monopoly.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#85

This is entirely unsurprising. It's been clear that Google has been into their Android duopoly-abusive stage for a while now, with more and more of their Android changes moving into GMS or non-AOSP Google apps (like camera, messages, location services, etc) over the last decade. Graphene has been doomed to this fate for a long time, and anyone who thought otherwise was naively optimistic. The same is clearly coming f…

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

They should lose YouTube as well. Remember how they used their control over YouTube to kill Windows Phone back in the day also. They should have lost it right then.

Google is very clearly an abusive monopoly, and has been for a very long time. We all overlooked it because they were mostly benevolent. That is no longer the case.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#86
post #45
post #41

Earlier quoted context omitted.

And by destroying the Android development team you'd achieve what exactly? Magical appearance of the security patches you're complaining about here? Would you start to actually pay for all those hundreds of engineers maintaining the OS?

Drone manufacturers like Samsung, Xiaomi etc need an OS. Right now it's more profitable for them to just pay licences to Google. But if Google lost Android... they would need to find a solution. I would like to see this, at least something would be happening.

I could see sort of an Android consortium taking over developing it and keeping it going outside of Google. Samsung, Oppo, Xiaomi, Huwawei, Motorola, etc.

Honestly it'd probably be better off that way. Google has far too much influence and control.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#87
post #81

Earlier quoted context omitted.

Fully agreed. I am however worried by the fact that Firefox is basically kept alive by Google. I assume it's just so that they can pretend Chrome isn't a monopoly, but the minute Firefox becomes an inconvenience they can stop financing it. I hope we can find a way for Firefox to sustain itself long term.

Google pays Firefox for traffic acquisition, not out of pity. If Google stopped paying, another search engine like Bing or Perplexity would be happy to take over.

True, but what happens when Firefox's marketshare decreases to the point where the amount of traffic lost by not having the Google deal stops mattering to Google?

If Google does the math one day, and determines that they won't lose out anymore by not paying Firefox they'll stop paying.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#88
post #81

Earlier quoted context omitted.

Google pays Firefox for traffic acquisition, not out of pity. If Google stopped paying, another search engine like Bing or Perplexity would be happy to take over.

True, but what happens when Firefox's marketshare decreases to the point where the amount of traffic lost by not having the Google deal stops mattering to Google? If Google does the math one day, and determines that they won't lose out anymore by not paying Firefox they'll stop paying.

It's revenue share based, so the cost to google is the time it takes to renew the deal. This is a fixed cost that doesn't depend on the market share of Firefox.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#89

Earlier quoted context omitted.

Just a year prior, I would have been against a decision to force Google to part with either Android or Chrome. Now, I'm of the opinion that they should have been forced to sell off both, and maybe Chromebooks too, for the good measure. No company with a direction as vile and openly user-hostile as what Google currently demonstrates should have anywhere near this level of control over the ecosystem.

They should lose YouTube as well. Remember how they used their control over YouTube to kill Windows Phone back in the day also. They should have lost it right then. Google is very clearly an abusive monopoly, and has been for a very long time. We all overlooked it because they were mostly benevolent. That is no longer the case.

> YouTube to kill Windows Phone back in the day also.

I hope you're not referring to YouTube blocking the 3rd party YT Windows Phone client that didn't play or display ads? At the time, Microsoft was threatening Android OEMs with patent infringement (without disclosing the specific patents!), and making it go away if they agreed to make Windows phone models[1]. Google refusing to make a first-party YouTube client for Windows Phone was to be expected, it was an ugly, hand-to-hand fight and all parties used the weapons they had at hand.

1. The agreements were never made public, but HTC and Samsung disclosed they'd be making Windows phones in their respective agreements with Microsoft. Microsoft also initially filed an Amicus brief in Google v Oracle - supporting Oracle's position.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#90

Earlier quoted context omitted.

The sad thing is I think Google keeping Chrome is actually likely the better of two possible bad outcomes... Anyone else interested and willing to pay the true value of owning the entire Internet ecosystem is almost certainly going to look to extract value from that, and that's almost certainly worse than what Google does today. E.g. using everyone's browser to extract training data for AI without getting IP blocked.

A year or so ago, I would have agreed. Not anymore. Sure, a company can buy Chrome and proceed to sell user browsing habits data to the highest bidder, or use it as a backbone for decentralized scraping - backed by real user data and real residential IPs to fool most anti-scraping checks. But if they fuck with users enough, Chrome would just die off over time, and Firefox or various Chromium forks like Brave would ta…

Why do suppose Chrome would die off for user-hostile actions under a non-Google entity (2nd paragraph), but not while being controlled by Google (3rd paragraph)?
Post reply on HN