8 ms·
That’s all great - but don’t lure people too much into a false sense of security. While your Nexus 6 may run a shiny new version of Android, underneath it runs
by DCKing 5y ago
That’s all great - but don’t lure people too much into a false sense of security. While your Nexus 6 may run a shiny new version of Android, underneath it runs a crusty old 2017 kernel full of holes of different sizes. The community is great, but vendor support remains important. LineageOS and other projects can’t fix things in kernels they can’t compile - they can only provide security updates for open source components.
That makes Google’s promise here so key. 5 years of updates is 5 years of kernel level fixes. After that, it’s probably left up to the community.
I really don’t recommend people to go out and buy abandoned Android phones to flash software. LineageOS and other community projects are a blessing in many many ways, but they don’t make your phone completely up to date. And that’s something one should make an informed decision about (buying an iPhone, I decided against that).
- ablekh 5y ago> underneath it runs a crusty old 2017 kernel full of holes of different sizes > LineageOS and other projects can’t fix things in kernels they can’t compile I think that you're wrong on this, that is unless you decided to use term "kernel" above too liberally, referring to all software running on a device. AFAIK, alternative Android images, such as LineageOS, include relevant - and quite up-to-date! - AOSP common kernels (aka Android common kernels or ACKs; https://source.android.com/devices/architecture/kernel/android-common https://source.android.com/devices/architecture/kernel/andro...), which are open source, plus some manufacturer-specific proprietary binary drivers and firmware (though there exist a related, but slowly-moving, project Replicant focused on creating and maintaining a fully open, i.e., kernel + drivers + firmware, Android distribution: https://replicant.us https://replicant.us).
- arendtio 5y agoSo would you please help me to find an ROM with an up-to-date Android Common Kernel for my i9300 Samsung Galaxy S3? AFAIK, the only way to run it with working drivers for all hardware components, are ROMs which use the rusty 3.0.101 Linux kernel from back in the day and I think that is what DCKing is referring to. If you want to create a new ROM, you either have to use the old kernel and have an upper Limit of Android 7.x (in this case) or you have to accept, that not all components are supported (e.g. no GPS). I would be glad if the situation would be different. Maybe it is different for phones you buy today?
- ablekh 5y agoObviously, not all devices have up-to-date kernels. It depends on whether they are supported by relevant Android distributions. That's why I used the phrase "quite up-to-date" instead of just "up-to-date". Unfortunately for you, LineageOS has stopped supporting i9300 Samsung Galaxy S3 with the latest official release being 14.1, which is based on Nougat (Android 7.1.2). Having said that, I ran across the following post that describes successful installation of LineageOS 18.1 (Android 11) ROM on Samsung Galaxy S3 i9300: https://devsjournal.com/install-lineage-os-in-galaxy-s3-i9300.html https://devsjournal.com/install-lineage-os-in-galaxy-s3-i930.... This is just FYI. So, if you understand relevant risks and feel adventurous, you can try to install it on your device. Disclaimer: I'm neither affiliated with the author of the post, nor responsible for any damage that might be associated with following the advice contained in the above-linked post.
- arendtio 5y agoThank you for looking up that ROM, as I might want to try it out. However, you are also proving my point, even that ROM with Android 11 is still running the old 3.0.101 Linux kernel. You can see it in the video at the last row: https://youtu.be/K_i29pczfRA?t=10 https://youtu.be/K_i29pczfRA?t=10 So congratulations to the guy who made it possible to run Android 11 with that ancient Linux kernel, even when Android officially doesn't support it. And to illustrate what I mean by ancient: Linux 3.0 was released in 2011 and got support updates until 2013 [1]. So even when CyanogenMod/LineageOS supported the Samsung Galaxy S3 the included Linux kernels were old as crap. You can't blame them for it, as they had little choice given that a few crucial drivers are not open source and included in the upstream Linux kernel. I just wonder if anything has changed for modern devices? [1]: https://en.wikipedia.org/wiki/Linux_kernel_version_history https://en.wikipedia.org/wiki/Linux_kernel_version_history
- soylentnewsorg 5y agohttps://forum.xda-developers.com/t/kernel-7-x-i9300-hybrid.3718112/ https://forum.xda-developers.com/t/kernel-7-x-i9300-hybrid.3... backported 4.2, which includes some of the 4.3 changes as well. supports lineage. 4.1 is a version google supports till 2024, so I'm assuming 4.2/4.3 is going to be even later. So, you got a phone from 2011 that's going to run a modern kernel and latest android till after 2024. > And to illustrate what I mean by ancient yes. I would love to see an iphone from 2011 that's going to be running the latest ios and apple kernel after 2024.
- DCKing 5y agoNo, I’m talking about the Linux kernel. You can check this for yourself. Take a look at the roms distributed on LineageOS as the example project and see if they include kernels that are up to date in any way. For older phones outside of vendor support, those kernels will always be out of date. Some diligent LineageOS projects are known to incorporate some open source kernel fixes sometimes, or grab newer blobs from other phones from other devices. But there’s only so much to they can do. In general, it’s true to say that older devices with community Android support are not completely up to date - the kernels are old, and vendor drivers are not getting updated. Outside of making big usability concessions in projects like Replicant, the community can’t do much here.
- ablekh 5y agoGood points. Though I'm a bit confused by your reply. Are you saying that LineageOS folks do not always or, at least, mostly use the latest AOSP common kernels for their relevant ROMs (as opposed to "some open source kernel fixes")?
- DCKing 5y agoI don’t know. I’m saying that custom rom use kernels that make your phone work. In the best case that involves shipping 1) the driver and firmware blobs the vendor provided while supporting the phone and 2) a kernel that is binary compatible with those blobs. Because of how Linux works, in the best case (2) is an old kernel of the same major version as the vendor shipped with the phone, with maybe some security fixes that made it into the mainline kernel or in the Android kernel. But if your stock rom has security bugs in e.g. the wifi driver, graphics driver of baseband firmware, your custom rom has those exact same bugs. Even if the custom rom is years newer than the latest vendor update.
- ablekh 5y agoUnderstood, thank you for clarifying.
- ablekh 5y agoJust ran across this relevant nice little article, which I found quite interesting: https://arstechnica.com/gadgets/2021/09/android-to-take-an-upstream-first-development-model-for-the-linux-kernel https://arstechnica.com/gadgets/2021/09/android-to-take-an-u.... I hope that people who interacted with me in this sub-thread (and other folks here) will enjoy reading it as well.
- soylentnewsorg 5y agoAlright - I'll bite. This is a smartphone, not a windows PC with a bunch of services. There is Zero listening on any port. There is no attack surface for any kernel - the only thing there would be a bug in mms. Please share your source for kernel attacks, on any android version, that's not an attack on an app - but on the kernel. No, this is not a google play attack, or an attack on an outdated app - which are updated fine. In addition, I'm unsure why you think you can't update the kernel on a phone. In fact, updating the kernel is standard procedure for... pretty much all directions on flashing a custom ROM. I had my nexus6 on kernel 4.9.3. There are literally new phones, right now, selling with that kernel version and earlier, with android11. This is like saying windows server 2016 has a kernel that's outdated, or that windows 10 which came out in 2015 is outdated. I think you are extremely confused. >I really don’t recommend Which is a good thing, because you should not be recommending about things you do not understand on even a basic level. >After that, it’s probably left up to the community. right. the entire point of my post. you can load stuff from the community. which includes the community of things like lineage - a big official community that's an llc - a corporation like redhat. A phone is not a server. It is not a security risk to run an outdated kernel. there are no services running a hacker can connect to. You don't connect to a kernel over the internet. A kernel which is by no means out of date, and is currently running in many datacenters.
- TimeBearingDown 5y agoSmartphones aren’t servers, but they run tons of services that interact with the surrounding world. Bluetooth, WiFi, etc… The kernel also still plays a vital and security-meaningful role in processing calls from applications. Running an out of date kernel could mean strangers ransoming your data, or could mean an attack becomes persistent and starts logging and uploading through reboots. Running an out of date kernel often does not result in this, and that higher level security matters first. However, the kernel does have an attack surface through those higher levels, and pwning the kernel still means something. Those datacenters are running LTS kernels with minor versions updated, or have security patches backported, or have far more limited connections to the world than your phone — only one protocol, one port, one service, for example. One example, since you asked: https://thehackernews.com/2019/10/android-kernel-vulnerability.html https://thehackernews.com/2019/10/android-kernel-vulnerabili...
- saladuh 5y agoIt's not the kernel security updates that are important in regards to this 5 year promise, those are all open source and can be applied to any device a ROM (such as CalyxOS) supports. It's the proprietary firmware blobs that are the big deal, and what this 5 years promise from google means is that those blobs, required for certain hardware on the device, will receive 5 years of security updates. And that's good, because those are the security vulnerabilities that e.g. the CalyxOS team cannot patch themselves (no source code). This is why CalyxOS now makes it clear what devices they support are still getting full security updates (kernel + firmware blobs) or just kernel updates. I believe the most recent CalyxOS patch added the ability for the user to see in settings the month and year of the last firmware security update for their device vs their current kernel security update.