Google plans monthly security updates for Nexus phones
threatpost.com
threatpost.com
Right, it differentiates Nexus phones from non-Nexus phones and provides a reason to prefer the former (of course, there is no barrier to other phone vendors seeking to negate this advantage by duplicating the process.)
I don't jest. I owned the first Android phone from T-Mobile. I owned every Nexus phone after that up to the Nexus 5. I was tired of being the "abused spouse" who thought Google would change and one day release a product that would actually work properly for longer than a few months.
Purchased an iPhone 5s, haven't looked back. The cost of current Nexus phones are on parity with iPhones (or close enough) that cost is no longer the deciding factor. Why do people continue to put faith in a product that continually fails to deliver?
Google: I want to love your Nexus line and Android. But you're going to have to start treating customers like customers, and not just a necessary evil.
Nexus 5 Android 5.1 Data Connection Issue: https://productforums.google.com/forum/#!topic/nexus/o-UyGEC...
Nexus 5 Android 4.2.2 Data Connection Issue: https://code.google.com/p/android/issues/detail?id=63524
Broken Bluetooth Audio Android 4.2.x: https://code.google.com/p/android/issues/detail?id=39633&q=d...
Improper Handling Of Mobile Radio Causes Battery To Drain Quickly: https://code.google.com/p/android/issues/detail?id=165558&q=...
All currently open (2767) Nexus issues: https://code.google.com/p/android/issues/list?can=2&q=nexus&...
I didn't give up on Android until I had collectively spent thousands of dollars on Nexus phones and continually had problems with each model at some point in time.
Yes, you can jailbreak your iPhone and install unsigned code. You can even set up a compiler toolchain to build your iOS apps, but you shouldn't have to do all of that just to build an app for your phone.
This is not an argument in support of Apple's approach. I just wanted to share what I'd learned about similar concerns.
I want also point out that cost is really not the issue with Android support. As an example, Samsung which has large share of the smartphone market does a very poor job of keeping their phones updated.
The OEMs have to pay developers to implement AOSP on their devices. They reassigning the developers to new devices after a Handset has shipped. Those developers are always working on the next revenue source.
Assigning developers to implement patches on devices that have long since launched does not generate new revenue and it takes them away from developing devices that will generate new revenue.
> The first update is being pushed out today, and the company said that other Android handset manufacturers are planning to follow suit and provide monthly updates to carriers.
Says right in the article that LG and Samsung are on board for monthly security patches as well. What's your little percentage rating at now?
Nexus 4 is receiving updates, it is just about 3 years old now.
Google holds all the cards in solving Androids security patch problem. The fact that they haven't done anything about it says volumes.
> The first update is being pushed out today, and the company said that other Androd handset manufacturers are planning to follow suit and provide monthly updates to carriers. [...] The change from Google, LG, and Samsung [...] Adrian Ludwig, lead engineer for Android security at Google, said the company plans more frequent updates for Nexus users and for other handset makers
> From this week on, Nexus devices will receive regular OTA updates each month focused on security [...] Both LG and Samsung, two of the larger Android manufacturers, have committed to getting those updates to carriers more quickly
As has been pointed out, Google doesn't do this for the fear that the manufacturers will walk and as such has prioritized market share over security.
It would be fantastic if Google was able to have a version of Android that was the same across all capable devices and the manufacturer's customizations are all userland.
The issue is with networks that don't allow non-carrier approved phones. Don't let them shift blame. They've decided to be bullies in their sandbox, so if you get sand in your eyes, take your money elsewhere.
Verizon may have a great network (I wouldn't know, they won't let me bring my own phone and none of their phones interest me). It helps lock customers in, but their phone policies also leave then vulnerable (and roped into an expensive hidden-cost upgrade treadmill).
Why would they do that when they can just sell new handsets? they have no financial intensive to do that, and that's where the android platform fails.
Because for all these manufacturers android is just a free os they don't have to maintain to begin with. They(Most) are not in the business of selling software services. It's up to Google to find a way to force updates upon consumers , or these manufacturers will just blame Google for their problems.
Google owns android , each time an exploit is found it hurts Google, not HTC nor Samsung.
Well, it will hurt the manufacturer too if the flaw is only present in their systems etc.
Android is based on AOSP, which Google does not control because of the license, not sure why especially on HN, people do not seem to understand or want to understand how open source licensing work.
Because they are partisans and the no-updating situation is a stick they can beat the Android with.
AFAIK they did amend those licenses to contain mandatory updates for some time after a device first hits the market, so it's definitely something they're actively trying to improve. It's probably not the easiest thing to solve, because manufacturers might decide to fork Android if they'd go too far, so they have to keep a balance.
AOSP is a software license, and governs contributions and replication. The agreements whereby various vendors get rights to sell and distribute Android devices are between Google and the various vendors. If Google had so chosen they could have added conditions to those agreements whereby vendors would be required to apply security updates within some reasonable amount of time. They did not do so in order to increase their marketshare. This decision hurt the platform, at least insofar as security is concerned.
It was a choice: marketshare vs. security. Google chose marketshare.
I don't think Mr Dong Jin Koh knows what "timely" and "fast" means. Then again, a month is better than months, except I don't think this changes too much if it took them a month to fix something they knew about. Nothing stops them from releasing a security patch in a fifth batch after discovery of a hole...
YMMV based on distro.
Can we get a fix for Logjam yet? It was first reported on May 20 [0], presumably Google knew about it earlier (I know Firefox was given advance notice [1]), yet the latest stable releases of chrome on both mobile and desktop are still vulnerable.
Firefox fixed it on Jul 2 [2], Apple fixed it on June 30 [3]. Can someone explain to me why Google hasn't released a fix to something that affected 10% of popular websites on disclosure day [0]?
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1138554
[2] https://www.mozilla.org/en-US/security/advisories/mfsa2015-7...
(Chrome 44 on Android still vulnerable.)
When things like this happen, both Apple and carriers scrable to fix things. However, Apple has a "special" position by the virtue of it's image, carriers are not going to do the same for everyone.
For example having a boot loader and two different flash areas. One primary area and one secondary then you tick tock boot between the different images. This how routers and CoreOS and XenServer does it.
The kernel can be live patched as of Linux 4.0
It's either that or more open phones where the customers can install and maintain their own operating system. Android stock, Cyanogenmod, Ubuntu phone etc.
Maybe they were just experimenting how long they could keep this laissez faire thing going on until they had to react, and had a plan in the back pocket.
http://www.engadget.com/2015/08/05/samsung-montly-android-se...
I've owned every generation Nexus and the 5 went from being the best phone they've ever made to the worst phone I've ever owned in one fell swoop. :(
Ordered a Moto this time around to see if I can have better luck there.
What, do they not have the bandwidth to send it out at once?
Being able to talk on a phone is kind of important. Is it also important to Google ? Since I don't want to shell-out another two bills for a different phone - please let it be!
However, Google is moving in the right direction IMHO: don't forget that there is this weird thing named "No-Disclosure", so hopefully, you'll get a patched Android even before the bug/flaw is unveiled.
Also, I think that Microsoft have been doing monthly security updates for many years... and once in a while, they push an update early for very severe bugs.