Live data from Hacker News

Delayed Security Patches for AOSP (Android Open Source Project)

twitter.com

91–100 of 116 posts

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#91
post #45

Earlier quoted context omitted.

Drone manufacturers like Samsung, Xiaomi etc need an OS. Right now it's more profitable for them to just pay licences to Google. But if Google lost Android... they would need to find a solution. I would like to see this, at least something would be happening.

I could see sort of an Android consortium taking over developing it and keeping it going outside of Google. Samsung, Oppo, Xiaomi, Huwawei, Motorola, etc. Honestly it'd probably be better off that way. Google has far too much influence and control.

None of those companies have a tiny little bit of interest of helping their competitors with joint development. I guess you're too young to remember the balkanization of Symbian among such companies?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#92

Earlier quoted context omitted.

A year or so ago, I would have agreed. Not anymore. Sure, a company can buy Chrome and proceed to sell user browsing habits data to the highest bidder, or use it as a backbone for decentralized scraping - backed by real user data and real residential IPs to fool most anti-scraping checks. But if they fuck with users enough, Chrome would just die off over time, and Firefox or various Chromium forks like Brave would ta…

Why do suppose Chrome would die off for user-hostile actions under a non-Google entity (2nd paragraph), but not while being controlled by Google (3rd paragraph)?

Not the OP, but Google spent years advertising Chrome front and center on the Internet's most visited pages. Money doesn't buy that kind of real estate, ownership does.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#93
post #76
post #27

Earlier quoted context omitted.

Android only ever had a chance because it is one ecosystem. Developers aren't going to develop for five slightly-different ecosystems in a trench coat.

Apps that run on the Kindle Fire can't use Google Mobile Services, and the Amazon appstore is missing many well-known titles. The Play Store is mostly absent from China, and I really don't know how that ecosystem works. Was there one ecosystem?

You're too young to remember Symbian and Java phone ecosystem mess, are you? Or even Android of around 2.x era, where getting an app doesn't mean it works on your phone?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#94

Earlier quoted context omitted.

Why do suppose Chrome would die off for user-hostile actions under a non-Google entity (2nd paragraph), but not while being controlled by Google (3rd paragraph)?

Not the OP, but Google spent years advertising Chrome front and center on the Internet's most visited pages. Money doesn't buy that kind of real estate, ownership does.

OP, agreed.

Prior to Chrome, Google actually used to promote Firefox on its own pages instead - which was a major driver of Firefox adoption. Google did it because they had a partnership with Mozilla, and were very much in favor of users switching to a browser that's not Internet Explorer.

Then Google decided they wanted more control over Firefox. Mozilla decided that Google isn't going to get it. This resulted in Chrome.

Firefox was evicted from Google's promotion, and it never quite recovered.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#95

Earlier quoted context omitted.

Either the new company takes over maintaining Android, or it fumbles the bag and the development becomes less centralized for a while - until some leader emerges and takes over. Either way, the new control center of Android wouldn't be Google. A decade ago, I would have seen that as a very bad thing. Now, I'm almost certain that this would be a change for the better. Google is not what it once was.

Or a more likely scenario is that Apple picks up even more market share, and we go from a duopoly to a monopoly.

Well, there is barely any new Android feature worth talking about for the past three years (no, new skins definitely don't count). I seriously doubt there is going to be any change in the market share if Android were controlled by a different company. We would have already seen that by now.

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#96
post #68
post #3

"No tags were pushed to AOSP for the July 2025 monthly release of Android. We asked about this on the android-building group but each of our posts was rejected. We emailed people at Google we've previously contacted about mistakes pushing tags but received no response this time." https://xcancel.com/GrapheneOS/status/1952413110947430786 "July monthly release was not pushed to AOSP and then neither was the August mont…

That's about the monthly and quarterly releases of Android, not the Android security patches. The post title is misinterpreting what's wrong. There is a lot wrong but that's not it. The baseline Android security patches are being delayed for Android as a whole, not AOSP specifically. Not having the very tiny monthly updates pushed to AOSP is an annoyance which will delay a subset of non-security bug fixes until the q…

Serious question: do we know as a matter of fact that iOS and family are safer than Android, including Pixel, especially when it comes to 0-day exploits?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#97

Earlier quoted context omitted.

Why do suppose Chrome would die off for user-hostile actions under a non-Google entity (2nd paragraph), but not while being controlled by Google (3rd paragraph)?

Not the OP, but Google spent years advertising Chrome front and center on the Internet's most visited pages. Money doesn't buy that kind of real estate, ownership does.

> Money doesn't buy that kind of real estate, ownership does.

If this is the reason, the remedy doesn't attack the root of the matter. If Chrome were unbundled from Google, what's to stop Google from creating a new Chromium fork - and naming it Cobalt and marketing the hell out of it to achieve the same market share?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#98
post #33

Earlier quoted context omitted.

> Developers aren't going to develop for five slightly-different ecosystems The point, perhaps, is for one to emerge as the prominent choice, the correct one. Diversity however has its own value.

I wish Android manufacturers contributed to AOSP, so that it would still be one ecosystem, but with shared ownership. But I guess it's more profitable for all of them to let Google do it on their own. And it sucks for the user, because we have to live with Google's decisions.

But does Google accept third-party contributions for AOSP?

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#99
post #33

Earlier quoted context omitted.

I wish Android manufacturers contributed to AOSP, so that it would still be one ecosystem, but with shared ownership. But I guess it's more profitable for all of them to let Google do it on their own. And it sucks for the user, because we have to live with Google's decisions.

But does Google accept third-party contributions for AOSP?

Yes, anyone is free to contribute to AOSP and many manufacturers already do.

https://source.android.com/docs/setup/contribute/submit-patc...

Re: Delayed Security Patches for AOSP (Android Open Source Project)

#100
post #96
post #68

Earlier quoted context omitted.

That's about the monthly and quarterly releases of Android, not the Android security patches. The post title is misinterpreting what's wrong. There is a lot wrong but that's not it. The baseline Android security patches are being delayed for Android as a whole, not AOSP specifically. Not having the very tiny monthly updates pushed to AOSP is an annoyance which will delay a subset of non-security bug fixes until the q…

Serious question: do we know as a matter of fact that iOS and family are safer than Android, including Pixel, especially when it comes to 0-day exploits?

No, but Google has significantly downgraded security from it used to be and Apple isn't sharing security patches very broadly outside their company 4 months ahead of fixing them. They don't have partners to share it with. That's not to say there aren't people in the company leaking them but they likely don't take that long to fix most patches. We considered the Pixel stock OS largely competitive with iOS on security but recent changes including but not limited to this are changing our mind. Both the Linux kernel and Google with Android are doing a horrific job with security. Apple has their own issues but it's not this embarrassingly bad and getting consistently better. Google could easily provide strong security for Pixels and AOSP but is downgrading them to appease OEMs failing to keep up with the previous already bare minimum patch system they were expected to follow.

An issue reported to Google 3 months ago and fixed today would likely get disclosed to partners around November 2025 or December 2025 and then officially fixed in March 2025. It's not just 1 month of early access for OEM partners now but rather around 4 months. Patches are artificially delayed beyond the time to fix them by 4 months. This is completely ridiculous. Google also doesn't control the patch releases for many projects such as the Linux kernel and many other external projects they use. This means they're always going to be at least around 4 months behind on including a small number of patches for those projects as mandatory to fix for Android OEMs. The bar for Android OEMs was already ridiculously low and they've made it far lower. It's dragging down the Pixel stock OS with it to a significant extent.

Google realizes this system is horrible and has therefore added a binary-only exception to the embargo which is a complete joke since they know it's easy to reverse the patches. However, it's not really being used in practice. It's just an option to ship binary-only patches without the long delay now. We have this option for GrapheneOS since we do have access to the partner bulletins via an OEM partner. We could also ask our OEM partner not to share them with us and instead obtain them another way with no NDA to publish them right away. We haven't asked for the December patches yet since we haven't decided how to handle it. The current embargo would allow us to publish a special delayed source release variant of GrapheneOS this month with December 2025 patches, but we want to provide source code for all our releases and do not want to have a special variant of the OS needed for the latest Android patches. With how broadly they've distributed the December 2025 patches, they can't seriously be considered private and it should be permitted to simply ship them now.

Android's partner licensing people are destroying the security work. Play Integrity API is similar pretend security actually just enforcing Google's partner licensing model while actually disallowing using much more secure devices. That's highly anti-competitive and so is what they're doing with security patches. Both should result in substantial regulatory action against them, and perhaps it will, but it will probably come a very long time from now when the damage is done.

Post reply on HN