Earlier quoted context omitted.
Drone manufacturers like Samsung, Xiaomi etc need an OS. Right now it's more profitable for them to just pay licences to Google. But if Google lost Android... they would need to find a solution. I would like to see this, at least something would be happening.
I could see sort of an Android consortium taking over developing it and keeping it going outside of Google. Samsung, Oppo, Xiaomi, Huwawei, Motorola, etc. Honestly it'd probably be better off that way. Google has far too much influence and control.
Delayed Security Patches for AOSP (Android Open Source Project)
91–100 of 116 posts
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#92Earlier quoted context omitted.
A year or so ago, I would have agreed. Not anymore. Sure, a company can buy Chrome and proceed to sell user browsing habits data to the highest bidder, or use it as a backbone for decentralized scraping - backed by real user data and real residential IPs to fool most anti-scraping checks. But if they fuck with users enough, Chrome would just die off over time, and Firefox or various Chromium forks like Brave would ta…
Why do suppose Chrome would die off for user-hostile actions under a non-Google entity (2nd paragraph), but not while being controlled by Google (3rd paragraph)?
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#93Earlier quoted context omitted.
Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.
Apps that run on the Kindle Fire can't use Google Mobile Services, and the Amazon appstore is missing many well-known titles. The Play Store is mostly absent from China, and I really don't know how that ecosystem works. Was there one ecosystem?
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#94Earlier quoted context omitted.
Why do suppose Chrome would die off for user-hostile actions under a non-Google entity (2nd paragraph), but not while being controlled by Google (3rd paragraph)?
Not the OP, but Google spent years advertising Chrome front and center on the Internet's most visited pages. Money doesn't buy that kind of real estate, ownership does.
Prior to Chrome, Google actually used to promote Firefox on its own pages instead - which was a major driver of Firefox adoption. Google did it because they had a partnership with Mozilla, and were very much in favor of users switching to a browser that's not Internet Explorer.
Then Google decided they wanted more control over Firefox. Mozilla decided that Google isn't going to get it. This resulted in Chrome.
Firefox was evicted from Google's promotion, and it never quite recovered.
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#95Earlier quoted context omitted.
Either the new company takes over maintaining Android, or it fumbles the bag and the development becomes less centralized for a while - until some leader emerges and takes over. Either way, the new control center of Android wouldn't be Google. A decade ago, I would have seen that as a very bad thing. Now, I'm almost certain that this would be a change for the better. Google is not what it once was.
Or a more likely scenario is that Apple picks up even more market share, and we go from a duopoly to a monopoly.
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#96"No tags were pushed to AOSP for the July 2025 monthly release of Android. We asked about this on the android-building group but each of our posts was rejected. We emailed people at Google we've previously contacted about mistakes pushing tags but received no response this time." https://xcancel.com/GrapheneOS/status/1952413110947430786 "July monthly release was not pushed to AOSP and then neither was the August mont…
That's about the monthly and quarterly releases of Android, not the Android security patches. The post title is misinterpreting what's wrong. There is a lot wrong but that's not it. The baseline Android security patches are being delayed for Android as a whole, not AOSP specifically. Not having the very tiny monthly updates pushed to AOSP is an annoyance which will delay a subset of non-security bug fixes until the q…
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#97Earlier quoted context omitted.
Why do suppose Chrome would die off for user-hostile actions under a non-Google entity (2nd paragraph), but not while being controlled by Google (3rd paragraph)?
Not the OP, but Google spent years advertising Chrome front and center on the Internet's most visited pages. Money doesn't buy that kind of real estate, ownership does.
If this is the reason, the remedy doesn't attack the root of the matter. If Chrome were unbundled from Google, what's to stop Google from creating a new Chromium fork - and naming it Cobalt and marketing the hell out of it to achieve the same market share?
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#98Earlier quoted context omitted.
> Developers aren't going to develop for five slightly-different ecosystems The point, perhaps, is for one to emerge as the prominent choice, the correct one. Diversity however has its own value.
I wish Android manufacturers contributed to AOSP, so that it would still be one ecosystem, but with shared ownership. But I guess it's more profitable for all of them to let Google do it on their own. And it sucks for the user, because we have to live with Google's decisions.
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#99Earlier quoted context omitted.
I wish Android manufacturers contributed to AOSP, so that it would still be one ecosystem, but with shared ownership. But I guess it's more profitable for all of them to let Google do it on their own. And it sucks for the user, because we have to live with Google's decisions.
But does Google accept third-party contributions for AOSP?
https://source.android.com/docs/setup/contribute/submit-patc...
Re: Delayed Security Patches for AOSP (Android Open Source Project)
#100Earlier quoted context omitted.
That's about the monthly and quarterly releases of Android, not the Android security patches. The post title is misinterpreting what's wrong. There is a lot wrong but that's not it. The baseline Android security patches are being delayed for Android as a whole, not AOSP specifically. Not having the very tiny monthly updates pushed to AOSP is an annoyance which will delay a subset of non-security bug fixes until the q…
Serious question: do we know as a matter of fact that iOS and family are safer than Android, including Pixel, especially when it comes to 0-day exploits?
An issue reported to Google 3 months ago and fixed today would likely get disclosed to partners around November 2025 or December 2025 and then officially fixed in March 2025. It's not just 1 month of early access for OEM partners now but rather around 4 months. Patches are artificially delayed beyond the time to fix them by 4 months. This is completely ridiculous. Google also doesn't control the patch releases for many projects such as the Linux kernel and many other external projects they use. This means they're always going to be at least around 4 months behind on including a small number of patches for those projects as mandatory to fix for Android OEMs. The bar for Android OEMs was already ridiculously low and they've made it far lower. It's dragging down the Pixel stock OS with it to a significant extent.
Google realizes this system is horrible and has therefore added a binary-only exception to the embargo which is a complete joke since they know it's easy to reverse the patches. However, it's not really being used in practice. It's just an option to ship binary-only patches without the long delay now. We have this option for GrapheneOS since we do have access to the partner bulletins via an OEM partner. We could also ask our OEM partner not to share them with us and instead obtain them another way with no NDA to publish them right away. We haven't asked for the December patches yet since we haven't decided how to handle it. The current embargo would allow us to publish a special delayed source release variant of GrapheneOS this month with December 2025 patches, but we want to provide source code for all our releases and do not want to have a special variant of the OS needed for the latest Android patches. With how broadly they've distributed the December 2025 patches, they can't seriously be considered private and it should be permitted to simply ship them now.
Android's partner licensing people are destroying the security work. Play Integrity API is similar pretend security actually just enforcing Google's partner licensing model while actually disallowing using much more secure devices. That's highly anti-competitive and so is what they're doing with security patches. Both should result in substantial regulatory action against them, and perhaps it will, but it will probably come a very long time from now when the damage is done.