10 ms·
1. Security updates. No feature updates are required (Which is sensible in my opinion.) 2. The federal election happens later this month. Take this plan with a
by Vespasian 5y ago
1. Security updates. No feature updates are required (Which is sensible in my opinion.)
2. The federal election happens later this month. Take this plan with a grain of salt.
3. The original article by heise.de mentions that the federal government will push these plans during negotiation of the EU wide laws. The government thinks that the plans of the commission do not go far enough. However it's unlikely that Germany will implement stricter rules on a national level.
- tgv 5y agoSure, but Germany has a lot of clout in the EU, and this might be a good point for –just a random pick– a new chancellor to show his/her concern for the people. I'm almost sure the new German chancellor could get that done in EU record time.
- photon-torpedo 5y ago> to show his/her concern for the people While I'd be happy for this plan to go through, I don't think most of the people will be happy with the side effects. Especially because of the spare parts requirements, I guess manufacturers will 1) Withdraw from EU market. 2) Reduce number of models on offer. 3) Raise prices.
- _ZeD_ 5y agoit's still better than the actual state of million of phones filled with "abandonware"
- photon-torpedo 5y agoI agree it's better, just I doubt it'll be popular.
- worldofmatthew 5y agoIt would also mean poor people being unable to afford these devices.
- turbinerneiter 5y agoDo poor people not have a right to secure devices? Should it be legal to make cars for poor people without airbags and seatbelts? And are we really gonna argue that this idea would be for the benefit of the poor people?
- spoonjim 5y agoWho can afford to just withdraw from 25% of world GDP? That’s the leverage of unionization.
- robertlagrant 5y agoI'm not sure how unionisation is relevant, but lots of models of products target different regulatory regimes.
- iso1631 5y agoBy forming an economic union, the EU punches at a higher weight than it's constituent parts.
- robertlagrant 5y agoOh, I see!
- onli 5y ago1. No enterprise will withdraw from the EU market because of this. There are too many customers with too much money in the EU. It's a bigger market than the US. 2. That would actually be good, the amount of models aims at confusing customers. But also: Why would that happen? Many models can (and do) share the same spare parts. 3. Prices are already as high as they can be. They do not get lowered because production gets less expensive, they get lowered because of competition. This might have an effect on prices if the competition was very high and profit span very thin - which might be the case for the cheapest budget phones. For something like an iPhone? To my knowledge they are already utterly overpriced, as is tradition (https://www.forbes.com/sites/ewanspence/2017/11/08/apple-iphonex-profit-margin-price-cost/ https://www.forbes.com/sites/ewanspence/2017/11/08/apple-iph...), then it will have no effect there.
- worldofmatthew 5y agoSo, the price rises hit the poorest. Fantastic.....
- Hackbraten 5y agoBuying a phone that lasts you seven years may still be cheaper than buying two.
- worldofmatthew 5y agoYour average person breaks devices before than and you expect people to have access to a load of money at once?
- danhor 5y agoA very capable smartphone currently costs ~200€, so if prices rise by 50% (an unbelievable amount), that would be 300€. Certainly not nothing, but car repairs or a new dishwasher are much more expensive. I expect the poorest to benefit the most from extended longevity, since more affluent people "need" the better camera or a more fashionable design the most. I know quite a few people with >3 year old smartphones, but mostly with custom roms, since stock firmware isn't usable anymore.
- odiroot 5y ago> 2) Reduce number of models on offer. I see this as a big plus. Not a fan of Apple but they did get this one right (at least in the past).
- Hackbraten 5y ago4) Use components for which open-source drivers are available. Phone vendors would then be able to build the drivers from source, possibly reducing the cost of shipping updates.
- ksec 5y agoIn the modern day Smartphone market you are practically dealing with three groups. Apple, Samsung and Chinese Brands. These three represent over 80% of market and closing it to 90%. 1) Withdraw from EU market - I guess most people dont realise EU as a market itself is 2nd just behind US. 2) Reduce number of models on offer - Parts aren't that different across models. 3) Most likely answer - Although it doesn't cost that much at all. You can still get a 7 years old iPhone 6 repaired, it is just costly, as it did 7 years ago. The incentive pushes you to buy a new Phone.
- krageon 5y ago> withdraw Come on. Every time the EU tries to implement a consumer protection a whole contingent of people comes here to say that this will cause companies to leave the EU. China is so much worse in terms of constrictive laws and regulations and you can plainly see that companies don't care. They adapt and sell, that's how they work.
- CodesInChaos 5y agoI don't think security updates are quite enough. Sometimes you need updates to keep functioning. For example support for TLS 1.0/1.1 or older signature algorithms was widely removed, which can prevent old clients from connecting to most servers.
- everdrive 5y agoWould deprecated TLS not fall into the "security" category? It's hardly a feature.
- 0xcde4c3db 5y agoAs a practical matter, it's a far cry from something like backporting a vulnerability patch. How likely is it that you can actually get TLS 1.(N+1) without a breaking change to an API?
- CodesInChaos 5y agoI view this as a breaking change in the behaviour of many internet servers, which happened to be motivated by security. Which is different from fixing the security of the software on the device. Some other examples of non security issues that might require modifications: * Widespread adoption hosting multiple services on the same IP, relying on SNI for TLS to function. While this is in TLS as well, it's not a security issue. In practice it was adopted slowly enough that it didn't cause many problems * A quick switch from IPv4 to IPv6 (lol) * Y2K (happened before smartphones) * timezone database changes (e.g. if the EU abolishes DST) * Regulatory changes (e.g. which frequencies the phone may send on) * A third party service the phone relies on for essential functionality gets shut down
- krageon 5y agoIt does, plainly. Just like not using MD5 is a security concern and patching that out would be a security patch.
- rex_lupi 5y agoyes, security updates are really not enough. just consider the case of app permission hardenings on latest android versions (12/11/10)
- SilasX 5y agoRe 1, yes it’s sensible as law, but I imagine Big Tech freaking out at the possibility of having to maintain some security-only update branch for every version a user might have started with.
- detaro 5y agoI don't think this even registers on the list of topics relevant for the federal elections.
- hutzlibu 5y ago"Security updates. No feature updates are required (Which is sensible in my opinion.)" The lines get blurry. Is a modern browser a feature upgrade or security? Well, both. But if the vendors really would just sort of fix their old mobile browser, you would still be stuck with a old browser unable to interact with the modern web. Is it a feature update, that you want to install newer apps? (like another browser) For this to make sense, it should enable you to update your whole OS of the devicey that it can at least install and update common apps. Otherwise its benefit is very limited.
- Slartie 5y ago> But if the vendors really would just sort of fix their old mobile browser, you would still be stuck with a old browser unable to interact with the modern web. This is a non-problem nowadays. We have long left the times in which browsers received essential features every few weeks. Using a browser with a feature set from five years ago you can still use all the most-visited websites perfectly fine. At the worst you're unable to use small, non-essential features of some sites. Maybe some ads look less fancy ;-) Your problem today as a browser user is security against zero-interaction exploits, not missing out on some obscure brand-new CSS features. Security updates are thus what you need first and foremost.
- hutzlibu 5y agoWasm is becoming a thing. With updates needed.
- m0dest 5y agoBrowser APIs are less stable than you might think. If you've ever had to develop web apps for smart TVs (Samsung, LG, Vizio, etc.), then you'll find that each model year is frozen on an old version of Chromium – some from 2016, some from 2017, some from 2018, etc. There are enough differences between them to make this painful. For example: multiple versions of the Media Source Extensions API, web components, CSS variables, ES6 modules, and web font loading patterns.
- gpm 5y ago> The lines get blurry. Is a modern browser a feature upgrade or security? A modern browser should be a feature upgrade. A browser as modern as the one that came with the device, except without known security issues, should be a required security update. Coincidentally no one develops the latter without the former, so you get the former, but I don't see that you are entitled to it. If anything I think the law should be designed such that there's an argument that you are entitled to the version of the browser that came with your device with security updates and without any feature regressions, which is never available today since browsers do choose to remove features on a regular basis.
- rivo 5y agoNote that WKRL and DIDRL (two new European directives) will be in effect in Germany starting Jan 1, 2022. They include a consumer's right to updates that allow the device to keep working (including security updates). But they don't specify an actual period for updates (this will have to be decided by the courts). And, what I find worse, they force the seller to provide the update, not the manufacturer. If the seller is not able to do that (which will be the case most of the time), they can be relieved of their duty. We're only halfway there.
- jorams 5y agoI don't know anything about these directives, but > they force the seller to provide the update, not the manufacturer. This (like warranties) is normally because there's no actual relationship between the consumer and the manufacturer. You do enter a contract with the seller, so they can be held liable when the law is broken. For smartphones this can be different, since they tend to come with EULAs, but not necessarily.
- FieryTransition 5y agoI'm eternally grateful every time I can complain to the seller, and hold them liable for the product for at least 2 years here in Europe. I once tried getting in contact with a major manufacturer about a broken device, and they did absolutely everything to make my life hard and draw the dispute out, even when I had video evidence of the failure. I just gave up at the end. So yes, the seller has to be held liable, and if the product is bad for business, the seller will not want to carry the products. If sellers stop buying unreliable, hard to update devices/vulnerable devices, maybe it will make enough of a dent on the bottom line.
- deleted 5y ago[deleted]