4 ms·
"Android phones are very different from iPhones, for example. Apple runs a closed system. It controls the hardware and software, and it's fairly easy to ship ou
by infinity0 11y ago
"Android phones are very different from iPhones, for example. Apple runs a closed system. It controls the hardware and software, and it's fairly easy to ship out a major revamp. The company says 85 percent of iPhone users have the latest operating system, iOS8."
The fact that Apple runs a closed system is not relevant to Android having poor security updates, as is evident by how GNU/Linux distros work - yet these things are mentioned next to each other, as if they are related.
(edit: lots of people missing the point here. media articles can equally point to free open source software GNU/Linux distros as having relatively successful security update mechanisms, yet Apple's closed ecosystem is always given more focus as the contrasting example to Android's; why? it is not the closed property that makes a security update mechanism succesful, yet that is the implication.)
(edit: this is how weasel wording works; statements of fact which may be individually correct, are placed together in suggestive positions, so that the non-cautious reader walks away with a false understanding of a more complex point, but allow the author to deny responsibility of this)
Other media articles have similar weasel wording. I'm not commenting on the author's intent - e.g. they may just be repeating the dominant narrative on this - however the wording has misleading connotations regardless of intent.
- jlgaddis 11y agoThat's not "spin", that's just fact.
- shkkmo 11y agoHow is that 'weasel wording'? That's an accurate statement of fact. The article never calls Android 'open' and doesn't blame the issue on the openness of the ecosystem. The issue is described fairly accurately. It would however be nice if the article brought up the point that the issue could be mitigated if users were allowed to actually control the software that runs on their phone (without hacking around restrictions). Instead most users are reliant on the device manufacturing seeing the financial incentive to provide updates.
- awj 11y ago> Instead most users are reliant on the device manufacturing seeing the financial incentive to provide updates. Most users are reliant on this regardless. Few people possess the technical ability, much less time, to perform these tasks. Making the platform "open" and pointing to that as a solution would also be a way of weaseling out of that responsibility to users.
- shkkmo 11y agoThe number of people who could use a fairly simple third party to to update their operating system on their phone is much, much larger than the number who can figure out how to obtain root access or unlock their bootloader using a technique that varies depending on exact model number and firmware version. Obviously there are users who will be left behind, but that is an issue for novice users of ANY free and open source software.
- Arnt 11y agoIt is relevant: Apple's system is closed against meddling by lazy middlevendors as well as against the likes of us. If Apple decides that you should upgrade (or not) there's little Deutsche Telekom or Verizon or any other middlevendor can do about it. That it's closed against us is not nice at all, but being closed against Deutsche Telekom and Verizon and such is a feature, not a bug.
- acdha 11y agoYou still haven't made a case for that being wrong. This isn't that hard: Bug in iOS: 1. Apple releases a patch 2. All users of supported devices can install it Left hanging: people with old devices (minimum age approaching half a decade) Bug in Android: 1. Google releases a patch 2. Many Nexus users can install it immediately 3. Everyone else has to beg dozens of manufacturers to ship an update for a device which brings no further revenue to the hardware manufacturer 4. At least in the U.S. everyone then has to beg carriers to ship an update to existing devices rather than using this as a chance to push you to upgrade to a $$$ new device and extended contract lock-in Left hanging: everyone who doesn't own a recent Nexus device. Minimum age: negative – devices without the current OS will be sold to users months after release. Note that absolutely none of this is Android's fault technically. It's only Google's fault to the extent that they naively believed everyone else would be responsible and neglected to have this license require updates, unlocking after dropping support, etc.
- ethbro 11y agoBoth of you are right. infinity0's point seems to be that a more fair reporting would be: (1) here's the problem with Android's ecosystem [was included] (2) here's the solution with Apple's ecosystem [was included] (3) here's the solution with OSS distros' ecosystems [was NOT included] I think it's fair to take umbrage that an intelligent but uninformed reader could very easily walk away from that article with the conclusion that "If Google ran Android more like Apple runs iOS, then Android would be more secure." Which itself is probably true, but far from the only solution. And indeed, probably the least free (speech) solution.
- acdha 11y agoI understand the argument but it's very weak because open source projects have the same fundamental problem and we have something approaching two decades of security problems caused by it. The underlying challenge is that anyone can ship a copy of something without making a binding commitment to ship updates. Point 3 is only true if you cherry-pick “OSS” to mean “People who installed Red Hat, Ubuntu, Debian, etc. themselves and religiously install updates”. OSS also includes things like the various forks and boutique distributions which started drifting behind, all of those insecure libraries where someone installed a copy of OpenSSL, libtiff/libpng/etc., or almost any PHP app, and never came back to update it. This problem is only going to get worse as the IoT gold rush continues and all of these “Two EEs and a web developer” companies ship a device shortly before folding, being bought out, etc. and there's no indication to the customer when it's no longer safe to have that device on a network. Note that this isn't saying that open-source is insecure – the same problems routinely happen with commercial software, too – but rather that it's not a magic wand for solving the problem. Apple ships updates promptly because their reputation depends on it, which is the exact same mechanism which keeps Debian, Red Hat, Ubuntu, etc. going, too, but that approach doesn't work in the case where the real customer isn't the person using the device. As long as Samsung keeps Verizon happy, they only care about the user experience to the extent that many people would choose to buy another not-Apple device instead of theirs. Ultimately, I think we really need legal changes to ban corporate attempts to shirk liability for flaws in their products and sharp restrictions on the ability to prevent users from securing their own devices – something like a vendor being required to publish the full source, build toolchain, hardware unlocks, etc. if they go more than a couple months without releasing a patch for a known problem in a particular device.
- rsynnott 11y agoIn practice, the situation is not directly comparable to Linux distros; Android vendors produce closed Android forks for each phone, and update these seldom and late. If someone was doing this with Linux distros, they'd be similarly nightmarish, security-wise.
- DannyBee 11y agoThey are in fact, related. The Linux Distro's are OEMs. the larger ones happen to be more responsive OEM's than the OEM's on the android side. But there are plenty of crappy, not-updated-that-often linux distros that strand users too! Just like in android, on GNU/Linux you are dependent on how good your OEM is, and what they provide you in terms of a security update mechanism/times.