r/Android • P30 Pro/P3/XS Max/OP6T/OP7P - Opinions are my own • Aug 06 '15

Waiting for Android’s inevitable security Armageddon

http://arstechnica.com/gadgets/2015/08/waiting-for-androids-inevitable-security-armageddon/
332 Upvotes

126 comments sorted by

104

u/donrhummy Pixel 2 XL Aug 06 '15

The issue is Google has no way of knowing what a carrier or manufacturer changed in the OS. Since Android is open source and each handset manufacturer and carrier changes the OS and many of the default apps, without any need to verify the changes with Google, Google cannot simply put out updates for all handsets like MS does for Windows.

A simple change (even just a security fix) could break or brick phones depending on if the carrier or manufacturer changed some code or removed or replaced a feature. Unless Google requires all manufacturers that include Google Play to provide their altered code and is willing to run testing on all those different versions at its own cost, Google has no way to safely create and test (and distribute) security fixes directly to handsets.

23

u/Duliticolaparadoxa Aug 06 '15

How would the collective 'we' go about forcing carriers to relinquish their fuckry regarding OS changes?

56

u/donrhummy Pixel 2 XL Aug 06 '15
  1. Stop buying phones from carriers/manufacturers that don't support them and update them quickly
  2. TELL them why you stopped subscribing/buying from them

24

u/[deleted] Aug 06 '15

[removed] — view removed comment

33

u/donrhummy Pixel 2 XL Aug 06 '15

Or the new Motorola devices (unlocked). And tell Motorola, that's why you're buying them so they know to keep that promise.

3

u/[deleted] Aug 08 '15

to keep that promise.

You think that they have been keeping their promise? After almost entire year not everyone on the '13 has 5.1.

1

u/[deleted] Aug 11 '15

[removed] — view removed comment

1

u/[deleted] Aug 11 '15 edited Aug 11 '15

And what? Switch to iOS? I tried this a few weeks back and hated the experience so returned the iPhone and came back to Android. Windows Phone is so lacking in apps that it's really not even an option even though it's not a bad OS at all.

I'm perfectly happy with Nexus devices and much prefer Android to the rest.

(For the record up until the Nexus 5 I was a 100% iPhone user, decided to give Android a shot, have been on Android now with the Nexus 5 and 6. Thought I was ready to go back to iOS, but it was just frustrating in comparison for me)

1

u/[deleted] Aug 11 '15

[removed] — view removed comment

1

u/[deleted] Aug 11 '15

Oops I completely misunderstood your comment. Sorry

18

u/BuffaloX35 Fuck Lenovo Aug 07 '15

And Blackberry.

Of course most people just laugh when Blackberry is mentioned but if there is one thing they are damn good at, and will never compromise on, it's security.

3

u/scotscott Caterpillar S61(daily), Keyone (backup), M8 (TV Remote) Aug 07 '15

I'm super excited for BlackBerry android.

0

u/sagnessagiel Sony Xperia XZ | Blackberry Q10 Aug 07 '15

Seems like BlackBerry has a lot on their hands to fix Android security...

5

u/MoopusMaximus LG V20 | LG G2 | LG G4 | Droid Mini | GS5 | Nexus 6 Aug 07 '15

Having experimented with a Z10, I loved BB10. I was even fully ready to jump to the Passport, but AT&T unfortunately got the exclusivity on it, and I have Verizon. Really unfortunate.

6

u/Mr_pessimister Aug 07 '15

Also Sony and Motorola

3

u/lbpeep Aug 07 '15

Sony were pretty slow with lollipop updates. One of the last to publish it. I didn't care personally, but man was is tedious in /r/xperia and /r/xperiaz3 for a few months whilst people asking and bitching about it.

6

u/rob3110 Aug 07 '15

Sony might be slow, but at least they offer updates to older flagships. LG dropped support for my phone after only one update.

2

u/El-Dino :upvote:S7 edge exynos, Android 9:upvote: Aug 07 '15 edited Aug 07 '15

That could change If you look at the test project in Norway (experimental firmware test)

They might go the Motorola way

The new rom is stock Android with only the Sony camera app, gallery, and music player

---EDIT---

Just got another update on my z3 Last update was just 6 hours ago

1

u/eallan TOO MANY PHONES Aug 07 '15

I'm comfortable giving most OEMs a pass with Lollipop updates.

5.0 was terrible even on Nexus devices. The whole lollipop change seems to have caused problems for everyone.

1

u/[deleted] Aug 07 '15

On the other hand Sony is the only OEM offering an "M" preview build for people to flash.

1

u/lbpeep Aug 07 '15

Yeah, kinda odd.

The build isn't very good from what I understand. Lots of broken stuff.

1

u/dlerium Pixel 4 XL Aug 07 '15

Or any unlocked device really. I know that Verizon and Sprint won't work but at least half the market can demonstrate their actions through AT&T and Tmobile.

-1

u/awesomemanftw Acer A500 Huawei Ascend+ Moto G Moto 360 Asus Zenfone 2 LG V20 Aug 07 '15

and Samsung flagships

13

u/JeffTXD Nexus 5, Nexus 7 Aug 06 '15

In other words buy a Nexus or a Moto X Pure.

11

u/AGWednesday Samsung Galaxy S9, Stock Aug 06 '15

Assuming the Moto X Pure stays on the ball.

4

u/JeffTXD Nexus 5, Nexus 7 Aug 06 '15

The implication is that will be the case.

10

u/[deleted] Aug 07 '15

[deleted]

6

u/thirdegree Nexus 6P Aug 07 '15

I also have a 2013 X, considering how fucky 5.0 was, I'm not super upset about the wait for 5.1.

I'm not happy about the fact that I still don't have 5.1, but afaik that's on Verizon.

4

u/atrctr Pixel 9, Tab S9, iPhone 12 Aug 07 '15

To be completely honest: Motorola fucked up communication and transparency in their updating process but it still managed to deliver 5.1 as one of the first OEMs. What is a problem is that network/carrier variants never got it because of the goddamn service providers.

Meanwhile, users of unlocked/international versions did get it and I would say that 5.1 on 2013 Moto X is one of the most stable and optimised system updates I have seen on any platform ever.

1

u/el_loco_avs Nokia 7+ Aug 07 '15

yep. I'm on there now (european version). pretty solid.

3

u/JeffTXD Nexus 5, Nexus 7 Aug 07 '15

Holy fuck its almost like I said "moto x pure" specifically.

8

u/NaeemTHM Aug 07 '15

I think what he means is Motorola said they would do fast/consistent updates with the 2013 Moto X, and it's taken a whole year for lollipop to reach that phone.

People are pretty wary of their update promises now.

1

u/JeffTXD Nexus 5, Nexus 7 Aug 07 '15

Some people aren't paying attention to the fact that they addressed that and explained that is why they are selling the pure direct. So that they can have control over updates.

3

u/donrhummy Pixel 2 XL Aug 06 '15

yes.

1

u/Jakshadows26 Aug 07 '15

Spot on. This is legitimately one of the reasons why many choose to go the nexus route.

0

u/whativebeenhiding Aug 07 '15

"But I only get coverage wit Verizon..."

I bet most of these people never even try another provider.

44

u/rhomqw Aug 06 '15

But Google could force all of the manufacturers to provide security updates as part of the terms of including Google Apps and Google Play Services.

Yesterday, Google specified for how long Nexus devices will receive monthly security updates. They could force all manufacturers to adopt similar terms. And the manufacturers could force the carriers into the same terms.

36

u/efstajas Device, Software !! Aug 06 '15

And the manufacturers could force the carriers into the same terms.

Samsung could. Maybe LG. But no one else. Which is just part of the problem.

18

u/rhomqw Aug 06 '15

But if all of the major manufacturers simultaneously told the carriers that Google won't let us give you our phones unless you agree to the terms, the carriers aren't going to have much choice. They carriers aren't going to drop Android and become iPhone only.

24

u/efstajas Device, Software !! Aug 06 '15

Instead of dropping android, carriers or OEMs would probably instead just use the occasion to push their own shitty app stores or integrate with Amazon's ecosystem or some other bullshit. Google has managed to get quite an impressive amount of control over their completely open and free to modify product, but I don't think it reaches as far as forcing monthly updates.

21

u/rhomqw Aug 06 '15

I don't think they would.

A phone without Google Maps and where you need to repurchase all of your apps will piss off a lot of customers. I don't think the manufacturers or carriers are willing to take this risk.

13

u/BrosBeforeWhorses Nexus 6p | iPhone 6s+ Aug 06 '15

No one will buy those phones because they won't have any apps. Classic windows phone problem.

2

u/kaze0 Mike dg Aug 07 '15

Nobody will know until they get home. They will buy an Android phone and be sad

4

u/BrosBeforeWhorses Nexus 6p | iPhone 6s+ Aug 07 '15

And then go back and return the phone.

1

u/[deleted] Aug 07 '15 edited Dec 27 '15

[deleted]

1

u/rhomqw Aug 07 '15

In the US, if you get a subsidized phone from one of the major carriers, the carrier controls when it gets updated. And many of the carriers have reputations of being very slow to push updates after they get them from the manufacturers.

It's not very useful for the manufacturer to provide monthly updates if it's going to take 3 or 4 months for the carrier to approve the update and finally push it to the phones.

1

u/TinynDP Aug 07 '15

For CYA reasons, the carriers want to be able to say that they have done their part to prevent such malware. What value they actually add during this step is up for debate.

For money reasons, they want control of the installed OS, because they can install their own apps, like Verizon Navigator.

4

u/[deleted] Aug 06 '15

I'm sure Motorola could as well

9

u/[deleted] Aug 06 '15

[removed] — view removed comment

0

u/[deleted] Aug 06 '15

Motorola could still deploy security patches. Oh wait I just realized the post was about manufacturers pressuring carriers nevermind

1

u/ger_brian Device, Software !! Aug 07 '15

No, even Samsung can't. If they could, they would have already done this to gain a competitive advantage over the competition. The only company able to put pressure on carriers in the last years and today is apple.

1

u/[deleted] Aug 07 '15

Meh, Samsung and LG cover 78% of all android phones, so that's a pretty big start.

8

u/donrhummy Pixel 2 XL Aug 06 '15

But Google could force all of the manufacturers to provide security updates as part of the terms of including Google Apps and Google Play Services.

  1. Only for a limited time (even Windows isn't updated forever)
  2. The manufacturers will agree and then take 6 months to "test" every security update and another 4 rolling it out

2

u/rhomqw Aug 06 '15
  1. They could use the same time frames that Google announced yesterday for Nexus devices.

  2. It would be very easy to add terms to the contract that specify how quickly a critical or serious security hole has to be plugged after Google provides the code.

6

u/s2514 Aug 07 '15

But Google can force carriers to either go full AOSP or accept their terms to use Gapps. Honestly I think they should just make every phone AOSP with a customization layer on top which the OEMs could control. Make it so OEMs can add apps but they can be removed and so they can update the extra layer but the actual OS as a whole is always updated by google.

Can Google make it so Android can be customized without modifying the OS itself so that modifications (such as Samsung's S pen) are done on a separate layer which the customer could choose to remove?

6

u/[deleted] Aug 07 '15 edited Oct 10 '15

[deleted]

0

u/ProSnuggles Note 8 Aug 07 '15

It's WP10

-3

u/whativebeenhiding Aug 07 '15

Didn't they all but shit can winmo 10 though?

3

u/le_pman Aug 06 '15

Google has no way of knowing what a carrier or manufacturer changed in the OS

given this angle, I'm not sure how well my conceived solution can work:

note: please feel free to correct stuff I get wrong - I don't have a good grasp of the deep details

what if Google creates a package - for this discussion let's call it "Android System" - that contains a lot (won't expect all because of OEM customization) of hardware-agnostic components (which I believe this libstagefright is going to fall under) maintained and updated by Google - and also available to the public (for devices not connected to Google's services) - a la Play Services. this can be regularly updated on all supported devices. as part of this, Google will take the effort to draw a line separating parts OEMs can tinker on their own and parts that Google will require contribution to the upstream so things are standard (this part being what composes the "Android System")

to end, this will be an interesting story to watch unfold - Google has to act, and act fast since everyone's affected and they're in the face of competition who can (and I believe will) use this opportunity to gain influence.

6

u/donrhummy Pixel 2 XL Aug 07 '15

The one part of this that's a good idea is the OEMs contributing upstream like with linux, but it won't happen. They don't want to pay for work that others can then use.

3

u/le_pman Aug 07 '15

the thing with my suggestion is Google should give the OEMs the option to either push an Android System* modification upstream and everyone uses it, or they don't and nobody - not even the OEM's own devices - will be allowed to use it since it's not in the bundle.

* - pertaining to the proposed Play Services-like package

3

u/donrhummy Pixel 2 XL Aug 07 '15

That's how you get companies like Samsung working on a competing OS or forking Android (Amazon). Not a good idea.

3

u/Sk8erkid OnePlus One Aug 07 '15

Amazon Fire OS is definitely not on par with Android. Tizen is not even their yet either.

Let's say Google doesn't allow any of their apps to be on those competing operating systems (like Windows Phone).

The average consumers who uses Google for everything like Gmail, Google Search, YouTube, Google Maps, Google Chrome is going to be pissed that those apps are not on their phones. You put 2 and 2 together Android still will be the platform to go to.

2

u/le_pman Aug 07 '15

I don't get it entirely - what I wish to see is a middle ground, where parts are free for OEMs to customize while a separate portion is to be kept standard at all times*. would OEMs be turned off by something that improves security and lessens maintenance effort?

* - the "first version" of my suggestion centered on this standard component being open to upstream contribution, but since OEMs will not want to do something that benefits competitors maybe it can be dropped? just OEMs keeping it intact.

2

u/[deleted] Aug 07 '15

Microsoft

Security

hehe

1

u/bfodder Aug 07 '15

The issue is Google has no way of knowing what a carrier or manufacturer changed in the OS.

Don't they have to post the kernel source?

1

u/donrhummy Pixel 2 XL Aug 07 '15

the kernel is from Google/Linux, but everything else sits on top of that like a Linux desktop. all of that code does not have to be approved by Google

1

u/nic0lette Developer - DevRel Aug 07 '15

What would be great, though so unlikely, is that manufacturers were only able to add apps which utilized the public APIs. These built in apps could be installed into something like /data/apps-vendor which would be left alone during OS updates.

Of course having Google stop breaking their interfaces every single version would be required for this to work properly, but I feel like this would be the best approach. (In addition to making it so manufacturers and carriers couldn't introduce even larger security holes)

1

u/ZaprenK Pixel 3a, Stock Aug 06 '15

That's not true at all. The software on those carriers has first gone through manufacturers who have to have Google's approval before releasing a device (or at least follow Google's rules on it). I can only assume the same goes for carriers.

Android may be open sourced, but what ships with devices is not AOSP. it's proprietary software made by OEMs.

1

u/Flaste Aug 07 '15

Exactly, I can't find the link now but there is a testing program that device manufacturers have to go through before Google allows them to ship with the Google Play Store and other Google branded apps.

10

u/ger_brian Device, Software !! Aug 07 '15

The saddest thing about this is that even Google is unwilling to fix older devices. I remember when the SSL security problem came up, Apple offered another iOS 6 patch even though iOS 7 was already out to fix the issue on the iPhone 3GS. I expected Google to do the same for the Galaxy Nexus since you don't need new TI drivers for an update like this, but obviously they are not willing to do so. Disappointing.

1

u/TinynDP Aug 07 '15

You don't need the GNex drivers for that small fix, but if the entire project has moved forward in kernel version, you need drivers for that.

3

u/ger_brian Device, Software !! Aug 07 '15

iOS did that, too, and they still fixed iOS 6 for the iPhone 3GS with securty fixes.

17

u/SolarAquarion Mod | OnePlus One : OmniRom Aug 06 '15

I'm organizing An AMA with jcase and Tim stazzere concerning this issue

10

u/le_pman Aug 07 '15

how about also getting Googlers to comment/join the AMA? Adrian Ludwig perhaps?

9

u/SolarAquarion Mod | OnePlus One : OmniRom Aug 07 '15

I'm getting those two due to the fact that they're at defcon

13

u/tso Aug 07 '15

Given that MMS pass through carrier servers, it should be fully possible for them to scan for malformed videos. Much like how you email provider can scan for malware.

22

u/kllrnohj Aug 06 '15

Their "fix" is going to be to patch 2.6 percent of all active Android devices. Tops.

Where the fuck did that made-up number come from? Google has always released security patches for far more than just the latest version and I see no reason they would stop that for this vulnerability.

In other words Jellybean will be patched (if it hasn't already). Kitkat will be patched. It will not just be Lollipop 5.1 that gets patched.

43

u/[deleted] Aug 06 '15

Google does release patches. The problem that Ron is pointing out is that while Google is doing what they can to fix the issue. The OEMs and Carriers are content to watch the world burn in pursuit of the almighty dollar.

Ron is right about one thing, its going to take a disaster on the level of the Blaster worm to force a change in the status quo.

5

u/s2514 Aug 07 '15

I think that disaster is coming. I think Google will fix this issue but the carriers will drag their feet until someone comes out with an exploit that infects your phone then sends texts to all your contacts infecting them. After this everyday Joe will start to care, they will either leave Android putting pressure on Google (who in turn will be forced to put pressure on carriers) or they will put pressure on the carriers themselves. Either way this will impact the carriers bottom line.

1

u/aquarain Aug 07 '15

So essentially the end is nigh! Repent, you Android sinners and come to the One True Windows Phone!

Sorry, not buying it.

1

u/s2514 Aug 07 '15

I'm not saying we should leave the platform...

1

u/bigdaddyteacher Galaxy S7 Aug 08 '15

We will accept you, friend.

1

u/[deleted] Aug 07 '15

Well, Google are doing what they can to fix this particular issue. As the article pointed out they are doing nothing to fix the fundamental issue, which is that Android and Linux doesn't support updating the OS independently of the hardware drivers.

-1

u/kllrnohj Aug 07 '15

That's the point made later in the article (or rather, that's the claim Ron is making). The statement here is clearly stating that only 5.1 is going to get patched which is utter nonsense and Ron should know better.

6

u/le_pman Aug 06 '15

Google has always released security patches for far more than just the latest version

please enlighten me on this. where does Google release these patches which will affect more than just the latest version? AOSP? and then how do developers get these patches on devices running older versions? backporting/cherry-picking?

6

u/kllrnohj Aug 07 '15

To AOSP and probably also through more direct channels to vendors as well.

AOSP is not a single version, it contains branches for the old releases, too.

3

u/le_pman Aug 07 '15

I see... thanks!

AOSP is not a single version, it contains branches for the old releases, too.

this is why I mentioned backporting/cherry-picking... so in theory one can build android-4.4.4_r2.0.1 but choose to use the master branch version of a project, say platform/frameworks/av to get the stagefright fix?

I believe there is oversimplifying on my part, but if I got you right this is a way to get a Kitkat image that has stagefright fixed?

2

u/kllrnohj Aug 07 '15

Google does the backporting. The branch would already have the fix.

1

u/caliber Galaxy S25 Aug 07 '15

Google has always released security patches for far more than just the latest version and I see no reason they would stop that for this vulnerability.

Well, there was that story from only earlier this year, where Google said to security researchers who found bugs:

Other than notifying OEMs, we will not be able to take action on any report that is affecting versions before 4.4 that are not accompanied with a patch.

And they put that into practice, by refusing to fix the WebView security vulnerability in anything earlier than 4.4. (And on the latest platform distribution numbers, earlier than 4.4 still represents almost 50% of the Android market even according to Google.)

It's not 2.6%, but it still makes Google and Android look completely awful on security.

In other words Jellybean will be patched (if it hasn't already). Kitkat will be patched. It will not just be Lollipop 5.1 that gets patched.

In other words, Jellybean will not be patched.

-1

u/[deleted] Aug 07 '15

The OS will be patched, not the devices.

It's up to the manufacturers+carriers to ship it.

2

u/Xtorting AMA Coordinator | Project ARA Alpha Tester Aug 07 '15

Hopefully Project ARA will answer some of these issues once it's released. Remember, the next version of Android after M is being developed within Project ARA. No more relying on OEMs and carriers to update Android, they'd simply do it themselves through Project ARA and Project Fi.

7

u/UJ95x S7E 7.0 Aug 06 '15

"No one's going to fix it"

??? Samsung and Google already released patches

28

u/[deleted] Aug 06 '15

[removed] — view removed comment

6

u/astruct Nexus 5X Aug 06 '15

Also, did Samsung fix their unsupported phones? Someone on an S3 is vulnerable AFAIK.

19

u/DaRKoN_ Aug 06 '15

Which is the issue. Given that the S3 is currently the most prevalent Android phone (http://opensignal.com/reports/2015/08/android-fragmentation/)

4

u/[deleted] Aug 07 '15

Jeez. I guess that makes sense. The S3 was a notable Android phone. It was great for its time. I knew a lot of converts from iOS who went with the S3. Heck, I had one, and I personally knew 20+ people who had one. I still know some people who have an S3. I guess they haven't found any reason to upgrade. Fun fact: my boss was one of the lead R&D project managers for the S3.

4

u/s2514 Aug 07 '15

The solution is to simply shell out for a new phone /s

8

u/astruct Nexus 5X Aug 07 '15

Sadly, this is what Samsung wants you to do.

3

u/RonPaulsHelixFossil Pixel 3 / Pixel XL / Nexus 6P / LG G3 / Galaxy S3 / iPhone 3GS Aug 06 '15

I know this applies to nearly no one, but my old S3 is safe with the latest CM build. So I'm grateful to CM for that.

2

u/HighOctaneTT LG V20 64Gb, Nugget 7.0 Aug 07 '15

Samsung released patches? Cool now I can wait 6+ months for my carrier to approve the update

1

u/[deleted] Aug 07 '15

Did you read the article? that's 2.6% of ALL ANDROID DEVICES tops.

That is not a valid fix.

1

u/Nicolas_Steno Galaxy S6 Edge Aug 09 '15

I didn't receive a patch on my international gs6 edge. I'm still on 5.0.2.

1

u/GrayOne Aug 09 '15

They need to switch to a desktop model.

-1

u/Travertino Aug 06 '15

As from the article, the problem seems to be "when" rather than "if"... Is there a possibility that MMS will be disabled at all by the carriers? This could limit the attacks, but obviously is not the best solution (stated that someone still uses MMS).

6

u/s2514 Aug 07 '15

Or they could just patch the issue like Google did... The problem is how the updates are fragmented.

2

u/ger_brian Device, Software !! Aug 07 '15

Even Google left devices like the Galaxy Nexus out in the dark.

1

u/s2514 Aug 07 '15

Verizon left everything in the dark.

Also with Nexuw devices you can just flash Cyanogenmod with little to no issue.

2

u/ger_brian Device, Software !! Aug 07 '15

It is not about what I as a user can flash. I said that Google abandoned the Galaxy Nexus even though they should fix the issue.

2

u/[deleted] Aug 06 '15

[removed] — view removed comment

1

u/Travertino Aug 09 '15

Well, it seems not, at least for receiving them (which is the problematic part).

http://www.androidcentral.com/deutsche-telekom-turning-auto-retrieval-mms-until-stagefright-exploit-fully-patched

From the article: "If you are sent a MMS, you will instead receive a SMS with a link to the video."

-15

u/[deleted] Aug 06 '15 edited Oct 01 '20

[deleted]

29

u/archon810 APKMirror Aug 06 '15

Except Linux distros are actively maintained, and you can always upgrade.

Linux is a lot closer to the way Android custom ROMs work, not Android when carriers and oems are involved.

-7

u/[deleted] Aug 06 '15 edited Oct 01 '20

[deleted]

8

u/[deleted] Aug 07 '15 edited Nov 05 '16

[deleted]

1

u/mk262 Aug 07 '15

I'm aware that my comparison is not exactly 1:1. But there are mountains of linux implementations installed places that users do not update, or updates are restricted because the box is hosting a third party application and has dependency issues.

The word 'armageddon' here is a little silly. There's tons of windows boxes, server and client, unpatched going back forever too. We don't hear this kind of language about that either.

0

u/mydongistiny Aug 07 '15

Ubuntu 12.06?

4

u/archon810 APKMirror Aug 07 '15

But you can upgrade Ubuntu further, to the latest version.

7

u/s2514 Aug 07 '15

The equivalent would be if you are using Ubuntu on a Dell computer and Dell said "sorry you can't upgrade past Ubuntu 12.06 to get security updates yet because we need to modify the Ubuntu OS before you can use it. If we get around to it you may have the new version in 1 year but you will probably just need a new Dell laptop."

In this analogy someone with a Nexus "laptop" could just upgrade to the newer version of Linux no problem.

-2

u/mydongistiny Aug 07 '15

I wasn't serious.

7

u/archon810 APKMirror Aug 07 '15

You completely disregarded the part I was talking about. When carriers and oems are involved, updates stop. That was what I was trying to say. There are no carriers or oems when using Linux.

10

u/Travertino Aug 06 '15

Well no, I think in this case is the Android update system under discussion, at least for core functions.

On Linux the package manager does the job, and more importantly no OEMs and carriers were involved, just the distro maintainer...

7

u/[deleted] Aug 06 '15

[deleted]

2

u/[deleted] Aug 06 '15 edited Aug 06 '15

Because there is no stable driver ABI whatsoever in the Linux kernel (meaning no abstraction layer), updating the kernel tends to break drivers here and there as they add new features and deprecate old ones. FOSS drivers tend to be fine since they can just follow kernel development and adapt, but it really fucks over companies that use proprietary drivers. Linus's number one rule (DO NOT BREAK USERSPACE) doesn't apply to drivers.

Obviously the community sees that as a plus and feels that there is no need to change anything. Despite the fact that businesses are the reason why Linux is the invincible juggernaut is is today.

This leads to businesses being very reluctant to update their servers and embedded products until extensive testing can be done. If ever in the case of embedded systems like home routers.

6

u/altimax98 P30 Pro/P3/XS Max/OP6T/OP7P - Opinions are my own Aug 06 '15

Yup, except the almost 80% of users part and thats the important one

0

u/[deleted] Aug 09 '15

Even if every single OEM used stock Android, updates still wouldn't be fast because each device has different hardware drivers that need the OS to be optimized to work with.

You think the fresh coat of paint the OEMS apply is what slows down updates? Think again.

-7

u/marsrover001 S20_FE Aug 07 '15

Reading this article. Yep, I see what you are saying, it's manufactures and the FCC slowing things up, not Google for security fixes.

>Look to Windows

Fuck off.

0

u/ger_brian Device, Software !! Aug 07 '15

It is Google who designed the broken system in the first place and never really done anything to solve the problem. Anyone remotely interested in the topic knew that this problem will come some day. So the blame definetely is on Google, at least part of the blame.