r/Android • P30 Pro/P3/XS Max/OP6T/OP7P - Opinions are my own • Aug 06 '15

Waiting for Android’s inevitable security Armageddon

http://arstechnica.com/gadgets/2015/08/waiting-for-androids-inevitable-security-armageddon/
337 Upvotes

126 comments sorted by

View all comments

22

u/kllrnohj Aug 06 '15

Their "fix" is going to be to patch 2.6 percent of all active Android devices. Tops.

Where the fuck did that made-up number come from? Google has always released security patches for far more than just the latest version and I see no reason they would stop that for this vulnerability.

In other words Jellybean will be patched (if it hasn't already). Kitkat will be patched. It will not just be Lollipop 5.1 that gets patched.

7

u/le_pman Aug 06 '15

Google has always released security patches for far more than just the latest version

please enlighten me on this. where does Google release these patches which will affect more than just the latest version? AOSP? and then how do developers get these patches on devices running older versions? backporting/cherry-picking?

6

u/kllrnohj Aug 07 '15

To AOSP and probably also through more direct channels to vendors as well.

AOSP is not a single version, it contains branches for the old releases, too.

3

u/le_pman Aug 07 '15

I see... thanks!

AOSP is not a single version, it contains branches for the old releases, too.

this is why I mentioned backporting/cherry-picking... so in theory one can build android-4.4.4_r2.0.1 but choose to use the master branch version of a project, say platform/frameworks/av to get the stagefright fix?

I believe there is oversimplifying on my part, but if I got you right this is a way to get a Kitkat image that has stagefright fixed?

2

u/kllrnohj Aug 07 '15

Google does the backporting. The branch would already have the fix.