commitment to updates is the major point of difference between the vendors... it's a bloody farce, i'm going to get a better android upgrade path on the n900 from the good hackers at the nitdroid project then any customer* of multi-billion dollar trans nationals such as sony ericsson.
And a way to fix it would be for google to release an updater client so you could update an android phone without being pushed an update from your carrier.
Android is open. Completely open to install unwanted apps, decompile developer apps, and send user data to China. There's no bit of information that isn't open for abuse.
An Android app that would list currently open security holes would be a great way to publicise this.