11 ms·
This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry
by gridder 3y ago
This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry
- refulgentis 3y agoCorrect. The issue is it is not commonly known that Apple isn't actually backporting fixes for exploits while it has been claiming to update the phones: this is earth-shaking[^1] news [^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Android itself for 7 years. I am sure significant decisions were made assuming this was the case.
- gridder 3y agoTouche. P.S. Keep in mind though, what is the state of security of the Android phone you bought new in November 2015?
- TheDong 3y agoThe Nexus 6 (2014) can still run a version of android with security patches: https://wiki.lineageos.org/devices/shamu/ https://wiki.lineageos.org/devices/shamu/ Google no longer offers security patches directly, but since you control the phone sufficiently to install your own OS, the community can come together and keep security updates flowing. You could do it yourself if you wanted. Apple devices make this sort of community maintainership effectively impossible. I know this means practically nothing since only nerds can actually install a third-party ROM, so for the general populace only the "default" security patch window matters, but for the hacker news crowd it seems like it might be a meaningful difference.
- fh9302 3y agoDoes that include updated drivers? If no, then there are still many unfixed security vulnerabilities.
- dangus 3y agoIs my grandma going to install a custom rom? If it’s not over the air it might as well not exist.
- mattigames 3y agoMaybe you could be a good grandson and do it for her?
- mattl 3y agoI don’t consider it a good thing to install a custom OS for someone and not give them the same level of support.
- mrcarruthers 3y agoIt's all well and good to say "oh you can just install a custom ROM". But you (and many here) can do that. Because you're technically inclined. But the vast majority have users have no idea what the hell you're talking about. They barely know what a security update is or what version of Android they're using, let alone being able to find, choose, and install a ROM. Can we just choose to stop suggesting it as a legitimate solution cause outside of this bubble, it absolutely is not.
- realusername 3y agopeople don't know how to install Windows either. In theory they could go to a shop to update their phone like their are doing with Windows but the reality is that nobody cares about updating their phone.
- tsimionescu 3y agoBut it is effectively impossible on Android as well. Let's ignore for a minute the fact that practically no one can install a custom ROM. The bigger problem is that a huge bunch of software running on the phone is fully proprietary and closed source, and there are many many different versions for different phones around - making it virtually impossible to do any meaningful reverse engineering. So sure, your main OS may be up to date, but the baseband OS and virtually all of the device drivers will be left vulnerable, and they have just as much if not more access to the data on your device.
- deleted 3y ago[deleted]
- lupusreal 3y agoIs the only standard to which we hold one company whatever the other does? Is there no room for higher principles here, in your view? The competition between consumer brands is all that matters? Come on.
- geodel 3y agoHuh, it can be totally earth shaking or completely normal depending on time and place. In current market place of smartphones it is more towards earth shaking than normal. You don't have to agree but resell value of older iPhone being much-much higher than Android tells customer values the support and quality of iPhone.
- mattigames 3y agoAs much as the sales of healing crystals tells me how much people value the health and anti-aging benefits of those.
- kaba0 3y agoHealing crystals seems to be a much smaller market (to the point of barely existing) than “Big Pharma”, so your analogy doesn’t really make sense.
- mattigames 3y agoThe irony of Steve Jobs himself dying because he wasted time trying non-big-pharma "remedies" before following actual oncologists advice is too much.
- ionyun 3y agoApple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.
- albntomat0 3y agoI looked it up, and the extended security updates for Google Pixel is only a recent change: Pixel 8: released in 2023, updates through 2030 Pixel 5: released in 2020, stopped getting updates in October 2023. https://support.google.com/pixelphone/answer/4457705?hl=en https://support.google.com/pixelphone/answer/4457705?hl=en
- jvdvegt 3y agoLooks like I hit a 'sweet spot' with my Pixel 4a (released in August 2020, guaranteed updates until November 2023)
- youngtaff 3y agoI use a Pixel 4a as a second phone and consider Google’s approach to be rubbish… 3 years worth of updates is pretty shit… my son’s iPhone 5c got updates for over 5 years (and I think there were some security issues they patched after that even) At the moment I’ve got a perfectly usable Pixel 4a that I’m going to have to replace as it’s not secure enough for work related stuff anymore
- dangus 3y agoPersonally I don’t think Apple’s level of support is incredibly bad when you take a look at the used device market. Even with Apple’s famously high resale values, depreciation on smartphones is huge. Don’t buy brand new old phones new from Apple, they’re a ripoff. If you buy either an iPhone 12 or 13 used for $250-350 you can basically plan on a $50 a year budget to have a smartphone that always has the latest OS judging by their expected remaining lifespans. I think the big flaw with the status quo is e-waste more than cost to the consumer. I think an iPhone 6S or 7 are incredibly slow and outdated devices for today’s usage but in 5 years I don’t think we will be able to say the same thing about an iPhone 12 or 13. Smartphone hardware is far more mature now than it was even 6 generations deep into the iPhone product line. We should be able to replace batteries for $20 and replace things like broken screens for not much more, and Apple should be enthusiastic about it considering how services are their bread and butter moving forward. Apple should be happy to produce fewer phones and keep more consumer dollars allocated toward the purchase of high margin digital goods.
- madars 3y agoIt's fine for a vendor to completely abandon 10 year old hardware but if you can still pay 30% App Store tax/pay for iCloud/etc, the security fixes should be backported as well. The current situation is charging full price for inferior (or maybe even dangerous) product: Apple wants to have its cake and eat it too.
- wtallis 3y agoAre you really saying Apple should actively break interoperability with old software?
- madars 3y agoThey should stop charging 30% App Store tax for an inferior product at the very least.
- rrdharan 3y agoWhat does this mean? The App Store fees are paid by the developers / vendors. Are you saying they should pay less proportionate to the number of times their apps are downloaded to older devices?
- JumpCrisscross 3y ago> What does this mean? It means they’re shoehorning another issue into this discussion.
- slaymaker1907 3y agoI think it’s a completely valid point. Apple is still making (potentially a lot) of money off these old devices yet isn’t willing to fully support them. It seems very unethical.
- schiffern 3y ago
- handsclean 3y agoIt’s an issue of expectations. If Apple advertises security support then it’s fraudulent to not deliver it; on the other hand, if they advertise an EOL date, then I’d agree there’s no reasonable expectation of security updates. But what they actually do is neither, they communicate very little, supporting some past iOS versions fully and others to degrees that only they know, resulting in them profiting off a reputation for backporting security updates while not actually binding themselves to deliver it, or, often, doing so. Like the battery issue, I feel the whole issue is communication. Apple needs to communicate when they EOL OS versions. You don’t otherwise know it, partly because EOL OS’s, including this phone’s, still get security updates, just not all of them.
- voidwtf 3y agoThey do communicate it in every major release, including which devices are supported. Many major vendors release security updates for EOL devices when doing so would greatly increase the security posture of those devices and comes at little to no cost to the vendor. Notably Cisco, Microsoft, Apple, and Samsung come to mind. Is the implication that once a device is EOL that a vendor should never release an update for that device again?
- wtallis 3y ago> Is the implication that once a device is EOL that a vendor should never release an update for that device again? It seems typical for vendors use "EOL" to refer to end of support life, not merely discontinuing sales of the produce. Most notably, that's how Microsoft generally frames EOL for major Windows releases, hence expectation of jumps in PC sales corresponding to EOL of XP, 7, and 10.
- dangus 3y agoThey only communicate it after the fact, when the new OS is impending release. There’s no way to know at time of purchase how many years your device will be supported. I feel like Apple changed the dynamics of smartphone market from company-issued devices like BlackBerry to BYO with the iPhone essentially on purpose so they don’t get stuck providing decades of enterprise support promises like companies like Microsoft. Companies purchasing bulk orders of hardware probably wouldn’t tolerate a vendor unwilling to make any sort of concrete support promise for the contract. But a company who employs iPhone users can basically put the responsibility on the user and simply block access to non-compliant devices.
- uxp8u61q 3y agoDoes apple release jailbreak tools for ten year old phones?
- no_time 3y agoThis bug touches nothing hardware specific. In alternative timeline where mobile OSes arent fisher price parodies of proper operating systems, they could push the same image to all iphones and have a proper hardware abstraction layer take care of the specific details. There is nothing fundamentally incompatible about the last couple of generation of iphones. ARMv8 CPU, PowerVR derived GPU. If the mobile computing space weren't driven by greed, this would be a non issue. A Sandy Bridge era intel machine deployed in 2011 is easily capable of running the latest Linux, BSD or win10. And in the case of the first two, I'd wager it will continue to be viable for the foreseeable future.
- nindalf 3y agoIt’s not economical to support devices used by less than 1% of the user base. Linux only manages it because community members step up to support older architectures. And sometimes when no one steps up the architectures are removed. - Linux dropping support for old graphics drivers (Nov 2023) - https://www.phoronix.com/news/Linux-Drop-Old-UMS-DRM-Infra https://www.phoronix.com/news/Linux-Drop-Old-UMS-DRM-Infra - Linux Kernel Developers Discuss Dropping A Bunch Of Old CPUs (Jan 2021) - https://www.phoronix.com/news/2021-Linux-Drop-Old-CPUs https://www.phoronix.com/news/2021-Linux-Drop-Old-CPUs Supporting all of these is work. It makes development of new features harder, because it has to account for quirks of older hardware. Older hardware is also harder to get in the hands of developers and harder to test on. That’s why Linux has dropped support for 386, 486, IA-64 and other architectures. There’s no point saying trillion dollar corporation etc. It comes down to some basic fact - phones must be built with SoCs, that’s the easiest way. The PC way doesn’t work at scale. Now that we are on SoCs you have to draw the line on support somewhere. Just because the costs imposed on future development aren’t obvious to us doesn’t mean they don’t exist. I think 5 years minimum (and sometimes more) of OS updates is pretty good, FWIW.
- beeboobaa 3y agoShrug. That's their problem. Or it should be, at least. Don't sell crap you can't support for a decent amount of time. Stop ruining this planet we live on by creating immense amounts of e-waste every few years. We both know your argument is dishonest or at least naive, though. They could easily support updates if they want to. But it's about money. This way they are forcing people to buy a new phone every few years. It's clever, shame about the planet.
- beeboobaa 3y agoMy 10 year old laptop is still getting OS updates
- hulitu 3y ago> My 10 year old laptop is still getting OS updates Microsoft is trying to fix this. Win 11 wants a TPM. /s