13 ms·
This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain. This is a side effect
by dan-0 7y ago
This seems to be getting a lot of attention, so as an Android Engineer with some security and framework experience let me try to explain.
This is a side effect of Android's initial approach to it's open nature. Android allows a manufacturer to modify its framework for their own use case. Then the manufacturer can allow a specific carrier to input their own system applications and firmware on to the devices well (your bloatware etc).
This can lead to multiple firmware variants for a specific device. It's not uncommon to see over 20 variants of a firmware for a specific Samsung device for example. This can be broken down by carrier, by region, by OS, etc.. for a number of different reasons.
This becomes a problem when Android needs to post an update. That update has to be pushed first to the Android framework, then to the manufacturer who decides if they are going to make modifications for the update, and if the manufacturer decides to make an update, they push it to the carrier who then has to make an update themselves.
This leads to a web with many broken ends, where a specific phone on one carrier may never see an OS upgrade after purchase, but on another carrier, the same phone might get them regularly.
Additionally some manufacturers take a greater degree of liberty in modifying the Android framework, making updates significantly more expensive to implement, so they don't.
The good news is Google over the past couple of years has been making a great effort under Project Trebel to simplify some of the APIs in the Android framework. What this is leading to is less friction when it comes to implementing core updates. Unfortunately not all manufacturers have opted in to adhering to the standards and Project Trebel yet.
This is all in stark contrast to iOS, which doesn't have the restriction of dealing with multiple manufacturers, and makes it harder for carriers to customize the device for their own business cases. This makes security and updates easier to push, but on the cost to the user of being an expensive single stream walled garden. Nothing against iOS in the statement, as a flagship device they're very nice. However, they don't have the adaptability that Android allows, making them prohibitive in some markets.
Sorry for any grammar issues, I'm on my phone (a regularly updated Pixel 3).
- cstejerean 7y agoThis is what I love about Apple. They gave the carriers a big middle finger when it comes to the usual bullshit of bloatware, sticking their logos on things or getting in the middle of updates. That’s because they cared about the end user experience. Google was happy to just grab market share at the expense of the users by allowing carriers to continue with their usual shenanigans. For this reason Apple will have my eternal gratitude, because I remember what a shitshow smartphones (and deploying apps for them) was before Apple flexed their muscles on this.
- michaelcampbell 7y ago> That’s because they cared about the end user experience. I'm sure 100% of any revenue going to Apple and not shared with anyone had nothing to do with that.
- enraged_camel 7y agoIt may have, but I doubt it was the primary motivation. Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash.
- z3t4 7y agoApple also planned to sandbox all apps. But developers wanted bare metal performance.
- scarface74 7y agoSandboxes apps has to do with the permissions not having “metal performance”. iOS apps compile down to ARM native code. Unlike most Android apps that run on top of a VM.
- avtar 7y ago> Steve Jobs famously cared a lot about user experience, security and reliability. Remember that Apple under his leadership took a firm stance and loudly and publicly refused to allow Flash on its devices, despite the fact that many websites back then relied on Flash. A less generous take on that would be that he/Apple also wanted to push their app store. At the time Flash was popular for publishing apps and games on the web. Yes their decision helped move everyone away from Flash but it also meant they would be getting their 30% cut from iOS apps. Edit: I stand corrected. "While originally developing iPhone prior to its unveiling in 2007, Apple's then-CEO Steve Jobs did not intend to let third-party developers build native apps for iOS, instead directing them to make web applications for the Safari web browser." -- https://en.wikipedia.org/wiki/App_Store_(iOS)#iOS_SDK https://en.wikipedia.org/wiki/App_Store_(iOS)#iOS_SDK
- scarface74 7y agoSounds like an excuse for poor engineering on the part of Android. Microsoft also sells Windows to multiple OEMs and has done so for decades. OEMs also are free to add bloatware as well as the retailers (ie Best Buy adds its own bloat), but Microsoft doesn’t have this problem.
- jamespo 7y agoprobably cost you more money than you'd make writing malware for windows phones
- ry4nolson 7y agono one is talking about windows phones. they're talking about windows.
- rightbyte 7y agoYe. Patching system libs should be just pulling those as long as they are backwards compatible. Maybe some key parts that the OEMs fiddle with are not behind abstractions properly.
- diroussel 7y agoIt’s quite different as windows is closed source. The OEMs don’t build their own flavour of windows from source.
- scarface74 7y agoAnd almost everything that makes Android what it is outside of China is also closed source - Google Play Services and the drivers.
- MiddleEndian 7y agoSeems like the open source-ness of Android is of little use. It helps manufacturers rather than users.
- blablabla123 7y ago
- snarf21 7y agoThis is also solvable by Android taking a slightly different approach. Isolating the OS and security framework so that it can always just be updated. The carriers and and manufacturers are still free to install whatever bloatware they want and do what ever logo nonsense they want. We ran into nonsense issues creating a cross platform development toolchain when HTC phones just didn't implement certain functions of the WebView. We were then stuck trying to create workarounds for no reason. Android could have been the best of both worlds but they just punted it and left their users holding the bag.
- ansible 7y ago> This is also solvable by Android taking a slightly different approach. Isolating the OS and security framework so that it can always just be updated. I think that is the plan with Fuchsia. The core of the OS is small. The drivers can be separated out more easily, and with a (hopefully) stable driver API, they may not need to get updated ever (baring security bugs in the driver code itself).
- panpanna 7y agoNot to sound like a Google apologist, but all you ask is already in there. And Google's extensive compatibility requirements aside, webview is now directly updated from the store. Android Q will extend this to most system components via apex.
- PeterStuer 7y agoThanks for the info. Is there a place where one might find the data on brand/carrier responsiveness to security updates? I'm thinking e.g. Google publishing a dashboard on this might make it to the radar of the marketing departments of the involved partners.
- zaroth 7y agoArguably, it should not be legal to sell a device and not provide security updates for some guaranteed period of time, as a violation of the implied warranty for fitness for a particular use, or as an unfair or deceptive trade practice. I wonder if the FTC has ever pushed this particular angle?
- nradov 7y agoThat's just making excuses for poor software architecture without clearly defined layers and stable, documented APIs between them. MS Windows has a hardware abstraction layer. There's no reason Android couldn't have the same, except that it wasn't a priority. Some of this is (or was) a fundamental design limitation of the Linux kernel. But there are other kernels.
- dredmorbius 7y agoAs I've commented elsewhere on this thread: my 2015 purchased-new Android tablet has never to my knowledge seen a vendor OS update -- it's running 5.0.2, not even the most recent version at the time, as 5.1.1 was released over six months before the unit was sold. None of this information was available to me at the time, and the 5.1.1 history I've only just learnt whilst composing this comment. I'd purchased the device under sharp time, budget, and information constraints whilst travelling. Budget and other limitations, as well as a market void of credible alternatives (Purism have my eye) have prevented replacement, though I loathe this device. Google have considerable monopoly leverage, and yet have not used this to require obligations for (and permit forward use of) Android and related ecosystem services in the form of upgrade timeliness SLAs and minimum EoL requirements: this device was obsolete at time of sale, though I was completely unaware of this at the time. Instead Google have sought to perpetuate their own monopoly and interests: https://www.theverge.com/2018/7/18/17580694/google-android-eu-fine-antitrust https://www.theverge.com/2018/7/18/17580694/google-android-e... It is also not capable of being re-ROMed, another fact of which I was unaware. I'm beyond disgusted and will not and do not recommend Android to anyone.
- alexis_fr 7y agoAnd up to version 6, Android was not disk-encrypted. If you lose a phone, they don’t need your pw, they can just take the SD card out and read it. All your stored passwords, all your stored cookies, they can read them all... Never again will I ever trust Android anymore if they can’t even get the basics right.
- Marsymars 7y agoThat explains why we ended up in a bad place, but it's still an absurd situation. From my perspective, Essential pushes a monthly security update for the PH-1 like clockwork. However, my carrier (Telus) delays it for some random (between ~0-90 days since the PH-1 launch, currently on ~70 days) amount of time. In that entire time, there's never once been an update that's been delayed for any actual changes from the stock update. In fact, if I don't want to wait for the update, I can just swap in any random non-Telus SIM, and the update is no longer blocked. The user experience is better with any carrier in the world other than the one I bought the phone from in the first place!
- kilolima 7y agoAnd yet someone can discover a security vulnerability in a software package and it gets put out to every Linux distro as an update in less than a week, usually by volunteers...
- mr_toad 7y agoIf Google put their foot down the manufacturers and carriers would tow the line. Trying to sell a (non-Apple) smartphone without Android in 2019 would be like trying to sell a PC without Windows. Your market share could be counted on one hand.
- dredmorbius 7y agoNB: "toe" https://grammarist.com/usage/toe-the-line/ https://grammarist.com/usage/toe-the-line/
- vinayan3 7y agoSounds like getting phones with stock Android is the best option. I rarely see in the stores Android One being a major feature / selling point: https://www.android.com/one/ https://www.android.com/one/
- sammorrowdrums 7y agoWhile not a perfect solution, I've been buying phones from manufacturer since my HTC desire was ruined by bloatware (you could put many apps on SD card but not Facebook as it was included bloatware, which got huge over time and literally meant I couldn't install updates or would have to delete other apps etc.) It has helped the frequency and speed of updates a bit. Not a fan of carrier customisation.
- panpanna 7y ago> This can lead to multiple firmware variants for a specific device. It's not uncommon to see over 20 variants of a firmware for a specific Samsung device for example. This can be broken down by carrier, by region, by OS, etc.. for a number of different reasons. You forgot to mention this was fixed about 2 years ago when Google pushed mandatory changes in the way customisation are added to the firmware image.