6 ms·
It's kind of ridiculous that my Google Nexus 5X, which was released just over 3 years ago, will not receive updates to patch vulnerabilities like this anymore.
by trulyrandom 8y ago
It's kind of ridiculous that my Google Nexus 5X, which was released just over 3 years ago, will not receive updates to patch vulnerabilities like this anymore.
- deleted 8y ago[deleted]
- outlog 8y agoAbsolutely agree - there should be regulation demanding a 5 year period of security updates (or similar).. Check out https://www.lineageos.org https://www.lineageos.org or one the other dists out there - and get that loaded up..
- OpenBSD-supreme 8y agoNo, that's not strong enough. It should be indefinitely (or owner has right to damages) UNLESS the entire spec and interface of a device is completely, comprehensively, and publically documented from the silicon up, and the device must either lack software integrity checking or it must be fully under the owner's control (eg purge OEM public key, replace with his own). This should apply to all products containing microprocessors and software to execute, and should apply to burned in ROMs too (since that software in ROM should be user writable/replaceable, this should discourage use of burn in ROMs). This should apply to the end product, so the whole car, TV, washing machine, vacuum cleaner, cellphone, game console, Intel CPUs and chipsets, etc, must have its microcontroller interfaces and specs fully and publically documented or damages could be awarded later once exploits appear. This should tamp down on IoT for fridges and can openers too as what OEM wants to either document IP xor expose themselves to potentially unlimited civil liabilities.
- qubex 8y agoDo you really want legislators defining what is and what is not a ‘security’ issue?
- koolba 8y agoThat’s literally one of the jobs of government, to step in when the private sector does not regulate itself well enough to protect consumer interests. It’s not about wanting the government to step in, its about having no other recourse.
- kingofhdds 8y agoI'm not sure any of us has a right to speak for every consumer. I live in a country were majority would likely prefer cheaper devices w/o any security guarantees. Forcing producers to provide 5(?)-years updates will make prices rise, and it could be against interests of a large segment of consumers. The only regulation which I believe would be beneficial for all is obligatory transparency. There should be clear warnings like "The producer expects you to replace this device in 2 years, and will not support it after that", or "This producer doesn't promise anything in regard of this device - use at your own risk"
- rlpb 8y ago"The producer expects this device to be unsafe after 2 years" would be more accurate :)
- EpicEng 8y ago>I'm not sure any of us has a right to speak for every consumer. Yet almost every civilization on Earth has already decided that we, the masses, _do_ have a right to speak for everyone when it constitutes a common good. In the US, you have to wear a seatbelt in most states. Your food is regulated by the FDA. Your cars must meet certain safety standards, as does your home. This list goes on and on.
- jayshua 8y agoJust because a lot of people do it doesn't mean it's the right choice though. Most Republicans seem to disagree from what I can tell.
- tohnjitor 8y agoGoogle has already addressed the issue with Android One. Android One certified devices are guaranteed at least two years of security updates. Most of the manufacturers already have such devices available.
- 131012 8y agoAny advices, caveats or other thoughts on this process?
- londons_explore 8y agoMost important isn't really the release date, but the date it was last sold to the public. A member of the public should expect to be able to buy a new phone and use it for 3 years without exposing their nude pics to blackmailers. So far, that isn't the case in the Android world.
- trulyrandom 8y ago> Most important isn't really the release date, but the date it was last sold to the public. Agreed. I picked mine up 2 years ago and am now forced to upgrade to a newer model or install a third-party version of Android like LineageOS.
- Casseres 8y agoIt's worse than that for other high-end phones. I bought the first Razer Phone from the Microsoft Store 1 year and 4 months ago (Nov 24, 2017). The last security patch was from July 5, 2018. From what I understand, the CAT Phones (with built-in FLIR, etc) get even less updates.
- Tepix 8y agoDictated obsolescence. Knowingly and willingly exposing your customers who are unable or unwilling to buy a new device to hacking.
- swebs 8y agoIt's crazy how this is even an issue in Android when it has been a solved problem in desktop Linux for decades. I can install Ubuntu on any ancient laptop and have daily security updates for life. The only explanation I can think of is that Google planned this on purpose so users would be forced to buy new devices every few years.
- IshKebab 8y agoIt's nothing to do with Linux. It's because desktops use standardised discoverable hardware with mostly documented peripheral interfaces. ARM phones do not.
- ReptileMan 8y agoIf you can force phone manifacturers to standrize chargers, same is possible for other issues.
- jsight 8y agoThat is really only an issue for low-level drivers and kernel level issues. There is nothing stopping OS vendors from fixing this without updating the drivers.
- PascLeRasc 8y agoAt the risk of sounding uninformed, does this mean the Year Of The ARM Desktop will have these same issues with updates and standardised hardware, or is it just a mobile SOC thing?
- hawski 8y agoI thought that it still _may_ receive security updates. But now it's on Google's mercy. Or is the fix impossible without whole OS update for some reasons. Either way it is ridiculous indeed. I have a 5X. It certainly pokes me to install LinageOS faster. A side question: does anyone use Plasma Mobile on their 5X? - https://www.plasma-mobile.org/neon-arch-reference-rootfs/ https://www.plasma-mobile.org/neon-arch-reference-rootfs/
- man007 8y agoThe unfortunate reality is that most users don't care for security. Google can continue to get away with only 3 years support of security updates. Another reason why I am considering going back to an iPhone.
- cosarara 8y agoThey don't care about security because they have never been affected by having an Android security patch level too old, and they don't know anybody who has. And they probably won't, honestly. I find it very concerning that I can't download an update to fix this particular vulnerability without a help from the manufacturer of my device. PNG has nothing to do with drivers, after all. And yet, I doubt I'm going to get pwned over this one. Mitigations to the rescue.
- trulyrandom 8y agoI disagree. Users may not care about security in the same way that technical people do, but they do expect the data on their phones to be private (nudes, in particular). I think the reason why the current situation is generally accepted, is because nobody has exploited one of these vulnerabilities to extract user data on a large scale, yet.