Hacker News new | past | comments | ask | show | jobs | submit login
Some Android Phone Manufacturers Lying to Users About Security Updates (theverge.com)
61 points by cfadvan on April 12, 2018 | hide | past | favorite | 30 comments



Be sure to read Google's response at the end of the article. Sounds like the researcher's patch detection method is not reliable.


It may not be for Google phones but I fully believe the researcher is correct with the basis of the article. I have the Galaxy S8 (locked to a US Carrier) and updates are a shitshow. Extremely high impact vulnerabilities (such as BlueBorne) were patched over a 3 month period to the world. Interestingly enough you can't even fully blame the carriers because a lot of the time Samsung's own unlocked version gets updates last...


Security is the reason why I switched to an iPhone.

Updates are guaranteed and encryption is second to none.

I had tons of fun “encrypting” android on my milestone and Samsung galaxy S2 but it was just a show, and things really haven’t improved since then even on google devices.

Heck after doing proper analysis of ARM trust zone and getting first hand access to some of the trustlets the industry uses to facilitate HVB, encryption and other security features on ARM devices there is no way I’m touching them again if I can avoid it.

As for security patches even a Google device isn’t guarantee of updates as if you buy one through a carrier they are responsible for the updates which is something I found out with the original LG Nexus (5?).

Even flashing a Google clean ROM didn’t help getting OTA updates since it seemed they were checking the IMEI.

After the let down which was the One Plus One it was iPhone all the way.


Well, the mentioned analysis app the researchers placed on the Play store is potentially quite useful. If Google will "bless" it -- can we at least have a link to a copy of their statement as posted securely on their own domain?

The Android ecosphere particularly with respect to security is a really good case for the appropriate use of the word "clusterfuck".

And even once a user is aware their phone may not be up-to-date, it's not easy for them to determine this nor what they are missing.

So, why not at least give users a good overview of this? Turn them into a more informed consumer?

Unless all you want to do is push ads at them...


>can we at least have a link to a copy of their statement as posted securely on their own domain?

https://opensource.srlabs.de/projects/snoopsnitch

with fdroid link if you want that


Thank you for that. I see it requires non-standard access to the OS.

What I meant was, to see Google endorsing it -- on their own site(s). Even if/where they do, obviously in its current state the app won't be functional for the average user.

Sorry, I didn't read further in before making my comment.

Regarding that, it would be useful if Google provided or enabled such a tool for the average, locked-down user to review the exact state of their Android OS (less carrier specific modifications) and updates to same.


the opensource git will soon contain this update as well, then it will make its way to F-Droid ;)


I switched away from Android phones in the "Stagefright" aftermath. My device was only three years old but the only response to my requests for an update was "Get a new device". So I did.


But what's the alternative?


Apple. Say what you want about them, their update policy is clear, consistent and fast.


Does Apple announce each model's end-of-life date (in terms of security maintenance) in advance?


As I understand it you generally have 5 years for hardware and software support with software requiring that you upgrade to major versions as they're released for continued updates. Perhaps someone can share a link or provide better details for software support/EOL info?

Here's their vintage/obsolete products info page: https://support.apple.com/en-us/HT201624


As an ordinary consumer using my phone, how would I know when it's going to become unmaintained and I'll need to buy a new phone (if I want to continue having security maintenance)?

This is one thing I think Linux distros could do better: not just advertising upgrades to the next release, but warning when the current release is (soon to be) no longer maintained.


They don’t announce it, but based on their current cycle, which has been going on for at least 5+ years, they drop support for an “A” chip every year. Currently the last chip to lose support was A6, so you should get about five years out of an A11.


They will force you to update your battery? Don't let their bad policies cloud your judgment....


For those that can afford it, iPhone.

I have a few WP devices that had more updates than all my Android systems together.

Until Google gets really starts forcing the OEMs to provide updates, nothing will change for the regular users.

Treble is not the solution, as the OEMs are the ones that should provide the updates and certification is only required if devices are actually shipped with 8.0.

Of course technically inclined users will just root their devices, assuming they are willing to trust random downloadable firmware blobs.


>For those that can afford it, iPhone?

Hmmm. Current new iPhone 6s - $449, SE - $349 and plenty of used and refurbished options from $300.


Last year I got a brand new 32GB SE from Walmart for $140, locked for a year of $25/month minimum usage, although I'm just using it as an iPod touch replacement, i.e. not using it as a phone or paying monthly.


Not everyone lives in US with US level salaries.

Also some people like to have the opportunity for once on their life to buy brand new things.



Despite other legitimate grievances, iOS devices have a much better track record of receiving updates.


Flashing a custom ROM I guess. Most are made by enthusiasts, so while amazing, there are no hard guarantees about performance and security.

Despite that, a custom ROM feels like having a modern device again. All the marketing-driven little walls are gone.


get a Xiaomi Redmi Note 4 with snapdragon 625(mido) and flash LineageOS on it (but don't do it on April 1st, and don't install Google's Play services)


Libram!


Even assuming you meant Librem, where can I buy a Librem device? After sending the money, I have a tolerance of 21 days until holding the device in working condition in my hand. Any offers?


maybe eelo.io


Did Lineage OS not ship a fix?


Entirely possible that he had a US phone which was not easily rootable/flashable.


Most common phones like Samsungs are though.


Are you kidding? Maybe the earlier Samsung phones, sure. But ever since the Galaxy S6, Samsung phones with Snapdragon CPUs (i.e. all the US models) have had locked bootloaders that are notoriously difficult to circumvent. Pretty much all custom ROM development on recent Galaxy's are aimed at the International Exynos-based processors for that reason. The GS8 even takes it one step further, where if the phone detects it has been rooted, it will cap the battery at 80% charge.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: