3 ms·
> The only realistic way to get long term software support on Android is from Open Source. This means installing a replacement, 3rd party Open Source ROM. What
by Blip-A 3y ago
> The only realistic way to get long term software support on Android is from Open Source. This means installing a replacement, 3rd party Open Source ROM.
What ROM do you use and what level of support does it provide? I was interested in third-party ROMs until I read this part of the GrapheneOS FAQ[1]:
> GrapheneOS can only fully provide security updates to a device provided that the OEM is releasing them. When an OEM is no longer providing security updates, GrapheneOS aims to provide harm reduction releases for devices which only have a minimum of 3 years support. [...] Harm reduction releases do not have complete security patches because it's not possible to provide full security updates for the device without OEM support and they are intended to buy users some limited time to migrate to a supported device.
So, what exactly do people mean when they claim that third-party ROMs provide "long-term" support? Do they just allow older phones to run newer versions of Android, albeit without full security updates?
[1] https://grapheneos.org/faq#device-lifetime https://grapheneos.org/faq#device-lifetime
- jqpabc123 3y agoWhat ROM do you use and what level of support does it provide? See here: https://e.foundation/ https://e.foundation/ Do they just allow older phones to run newer versions of Android, albeit without full security updates? The "full security updates" GrapheneOS references has to do with proprietary device drivers. This is an unrealistic over-reaction in my opinion. Why abandon perfectly functional hardware based on some unknown possibility that exists with both old and new hardware? Newer, supported devices could easily have these same sort of issues. They really don't know and the OEM does not offer any guarantee or certification otherwise. If the mere possibility of a bug is enough to abandon support, they really shouldn't support anything because this possibility always exists. Most security issues occur in the OS or can be mitigated in the OS. Without physical possession of the device, access to drivers passes through the OS.
- predictabl3 3y agoExcept that popular chipsets (ie: get community support due to device saturation) do see vulnerabilities published past the point of support. I trust Qualcomm's ability to develop their modem driver (which is an entire Linux install) very little, and I trust it's ability to stand the test of time to be even less. I'm not sure I'm saying it's a total loss, but I feel a bit lost on what to do as well. Do I think Google will support their Tensor chips longer? Not really. I feel like I still lean towards buying a portable hotspot, a small Android tablet, and calling it good. I already get calls over VOIP and SMS/MMS over jmp.chat so I don't really need a "cellular phone". But also, ugh, those portable hotspots are probably even more of a vendor-ware security nightmare. At least I could upgrade them independently and somewhat treat it as isolated, if I only connect over Wifi? Maybe?
- jqpabc123 3y agoIf the mere possibility of a bug is a show stopper, you really shouldn't use anything because this possibility always exists --- with all hardware and software.
- predictabl3 3y agoI think there's a difference in saying "software tends to be buggy, security can't be perfect" vs "I'm using a baseband modem running out-of-date Linux, that has DMA to my entire phone, that the manufacturer has stopped supporting, and there's active CVEs". > Without physical possession of the device, access to drivers passes through the OS. With all due respect, that is not a wise take on modern device security. At all, all, all.