3 ms·
That just refers to the security updates that require a full firmware update. I think people get focussed on that because they’re used to the iPhone where that’
by tomComb 4y ago
That just refers to the security updates that require a full firmware update. I think people get focussed on that because they’re used to the iPhone where that’s only way to fix security issues. On android, the majority of security issues are patched immediately and silently through the play store, so that continues pretty much for the life of the phone.
In other words, updates are much less important on android than they are on the iPhone.
- morsch 4y agoHere's the security bulletin for January: https://source.android.com/docs/security/bulletin/2023-01-01 https://source.android.com/docs/security/bulletin/2023-01-01 How do I determine which, if any, of these is fixed via the Play store update mechanism?
- nevi-me 4y agoThe bulletin specifies only CVE-2023-20912 as being fixed by Play Store. https://source.android.com/docs/security/bulletin/2023-01-01#google-play-updates https://source.android.com/docs/security/bulletin/2023-01-01...
- abliefern 4y agoWow. So "the majority of security issues are patched immediately and silently through the play store" seems catastrophically incorrect.
- tomComb 4y agoWell, yes, I have to agree. See the other comment I just posted. My understanding is that they are at the point (at least now with Android 13, which is what the Nokia will presumably ship with) that they can update most of userland (and even graphics drivers though that requires vendor participation), so they should be able to address Framework vulnerabilities, which is the critical discrepancy here.
- tomComb 4y agoI'm puzzled ... I can understand why the BLE drivers would still require a firmware update (and that is fine since drivers for older hardware shouldn't be much of a problem), but why wouldn't all of the Framework vulnerabilities be handled via Play Store updates. I believe that all of the Framework is updatable in this way. Perhaps it's because that is not true of Android 10 so they need to address it in a firmware update anyway?
- uallo 4y ago> so that continues pretty much for the life of the phone. I'm on a Pixel 1 with Android 10. Last security update it got was from October 2019 which is about three years after the phone was introduced. Is this supposed to be different on newer Android versions?
- Gigachad 4y agoIt isn’t. The situation is so dire on Android right now
- tomComb 4y agoThat refers to the formal (full firmware) updates, I'm talking about security updates that get pushed to the phone without you having to do anything. It started with the browser component many years ago, and has grown its coverage with each version. The limitations are mainly in the kernel, but they now even do graphics drivers this way (though that requires vendor cooperation, unlike everything else), but you wouldn't have that with Android 10. This capability has steadily grown to cover more of the OS over time, particularly recently, so unfortunately, Yes, Android 10 does have much less of this ability then later versions.
- uallo 4y ago> That refers to the formal (full firmware) updates, I'm talking about security updates that get pushed to the phone without you having to do anything. It is called "Android security patch level", that is not a full firmware update. It may still be something else than you have in mind, though. (How) can I check the patch level of the security updates you are relating to?
- tomComb 4y agoMy understanding of this capability is that it started with the browser component and grew from there, suggesting that it happens automatically and there is nothing you need to check. But someone has pointed out that all the Framework vulnerabilities are still listed as being addressed by full, old-fashioned security updates, so I must admit that there is something I'm missing here.
- openplatypus 4y agoNever had an iPhone. I don’t know what comes through Play Store, only thing it tells me is that specific app was updated. All I know is that my cell phone vendors tells I am not getting more security updates. Consumers should not understand CVEs to feel safe.