(Also Android got some additional security/privacy features after Android 4)
I don't know of any critical examples of #1 that I would need to protect against where upgrading is my only solution (maybe I'll upgrade if I find one). #2 can be mitigated at the app level (see my reply to the other comment here) and probably faster so than the update you'd receive. #3 can't really be mitigated by phone updates. #4 is impractical since cells are behind carrier-grade NATs and don't have dedicated IP addresses to be reachable via the internet. And #5 just involves updating the app, not the OS or hardware.
If you can give me an example of an actual attack that cannot be prevented without upgrading the hardware or the OS, I would find that far more convincing than a hypothetical.
Otherwise, how is this a justification for upgrading your phone? It seems like you may have forgotten what the argument even was. I was arguing against routine 1-2-year upgrades, not against the entire concept of upgrading for something wiht a serious security vulnerability. If a serious exploit appears in the wild and your only solution is to upgrade -- by all means, go for it. But is that the case here? And this happened periodically every 1-2 years for you to justify upgrading equally often?
B) Yes, in Android patch level July 2017 and iOS 10.3.3.
You're on Android 4, so your phone is vulnerable. If you use your phone for anything important, I'd suggest getting that new phone ASAP.
[1] https://en.wikipedia.org/wiki/Stagefright_(bug)#Mitigation
What? Chrome and Firefox protect against it [1]... do you not use either?
[1] https://www.howtogeek.com/225834/stagefright-what-you-need-t...
A good chunk of he video on the internet is mp4, so how would you know if you were playing an mp4 or not?
So just for 2017 there are:
- 326 code execution vulnerabilities
- 221 memory overflow bugs
- 114 memory corruption issues
- 309 privilege escalation bugs
http://www.cvedetails.com/product/19997/Google-Android.html?...
Granted, I'm sure a lot of these CVE are very low risk, and some are duplicates (because CVE). But there were a couple of notable really bad security issues. But this is just the Android, not all the of dependencies Android has.
StageFright was already mentions, and there has been a couple of iterations of this already, stemming from different bugs in a parsing library used with MMS. Included in this is a remote code execution and an privilege escalation.
Another fun one is Broadpwn, which is rather new one and was disclosed as BlackHat US this year. Its effects both iOS and Android and can be wormed trivially. It targets a widely used Broadcomm wifi chipset, and does not require _any_ user interaction. A malformed SSID broadcast allows for remote code execution. And when I say any user interaction, you can walk by something broadcasting this and you're infected.
To put it another way: if you learn of a very serious exploit like this in the wild and an upgrade is the only way to solve it -- by all means, go ahead and upgrade. I'm not saying you should never upgrade, nor am I saying serious security vulnerabilities cannot pop up. But neither in any way implies you need a periodic 1-2-year hardware/OS refresh. A refresh could be justified in 1 day or in 10 years; it just depends on what the actual threats and mitigations are. Remember what the original discussion was about: it was about whether the periodic refresh is justified.
As for the rest of those (StageFright and other attacks) -- I've addressed them in other comments. See here: https://news.ycombinator.com/item?id=15040745
This is the same reason why I don't run a computer OS at home that isn't patched to the latest security updates. I am not going to run windows XP at home and just disable / find workarounds for every single one of the probably-thousands of risks. That's insane.
The ol' security through tech press approach. Seriously though, you can't have the security of your devices dependent on whether or not someone has come up with a catchy name for their exploit. The exploits with names like broadpwn and stagefright are the exceptions, not the rules, there are plenty of critical CVE's that have never had cool names or tech articles written about them. Even if an exploit has a cool name and some press, what if people don't upvote it when it gets posted here (or reddit/wherever)?
As you're clearly entirely clueless about security, how do you know this?
If you primarily get your security news via the press, how do you know that they aren't simply missing most things?
No, this is fucking stupid. Most security related bugs get zero visibility, Linux for example still has a policy to quietly patch them.
Well, now I'm definitely convinced...
> Most security related bugs get zero visibility, Linux for example still has a policy to quietly patch them.
Most security bugs don't need your attention either, because they don't have widespread exploits.
Read the prior comments; don't just curse in reply to a single sentence while ignoring all the prior context.
But if you do anything interesting with your life this simply isn't an useful argument.
1. Android is kind of tricky though, as firmware updates generally come from the carrier not the manufacturers, and even if its from the manufacturers its still down stream of the actual patches. But the factor is kind of moot if a phone isn't getting security upgrades.
2. Google has been trying to decouple security and firmware updates, but this is only on more recent phones.
As for how much of an issue this is. Its kind of impossible to tell. It been out for less than a month at this point. And of course there are all the devices that are now unsupported and will not receive updates.
Ok for StageFright. Do you have those enabled? How many users do you think will?
For StageFright: I assume by "enabled" you mean "disabled"? Yes, I've already mitigated; it took me like 30 seconds. See this comment [1]. I'm not claiming laymen would or should do this, but I wasn't making that claim originally either. I was responding to someone on HN who presumably understands something about technology and who felt guilty about buying phones and polluting the planet periodically just for the security updates. I'm saying he's most likely already more than capable enough to solve that problem without any tangible negative effects to himself. I'm doing that myself and it's working fine for me, I'm not losing any time to this at all, and I don't think I'm any better with phones than he is. It's completely possible and won't really cost you anything at all (it'll save you money and save the planet garbage); you just need to find the willpower. For a non-techy person the story might be different.
But you've got a point about newer apps becoming more demanding of the CPU. Ideally, this trend continues to slow down (Moore's law is essentially over) and software engineers start to find ways to do more with less. There's plenty of room to optimize most software out there, but historically very little incentive to do so. That's changing, or it should.
In the meanwhile, an expensive long-lasting phone should make it possible to upgrade the CPU and/or GPU in a phone for a fraction of the price of the whole phone, so that the phone can be used at its full potential for its complete lifetime. A similar provision applies to batteries, which usually die after a couple of years and would need to be replaced once or twice during the lifetime.
Frankly, I haven't been able to keep a phone long enough for the software to become obsolete because the hardware breaks after 1-2 years. So I want Essential to succeed. A long-lasting phone made with durable materials and with many years of guaranteed software updates is the product we need, if someone dares to make it.
Also, being able to fine-tweak app permissions is a huge plus for getting Android 6+ phone.
I've switched to Nexus 5x at the beginning of this month. Current price is around 250€, and I basically gained all the features of flagship models (fast charging, good camera, up to date software, security updates for a year from now etc).
But, up until that point, I refused to install apps that I would be scared of what would happen if they were compromised (so, nothing business-related) and apps that are asking me permissions that I don't want to allow them (as an example, no Facebook app what so ever).
Been that way ever since I became a smartphone user, which, because of my privacy fears and dissatisfaction with current market options didn't happen until like two years ago.
Regarding someone stealing your phone: I don't understand what this has to do with OS or hardware updates. You can put a PIN on your phone and encrypt it. Perfectly possible on older versions of Android.
Regarding fine-tweaking app permissions: Privacy Guard and XPrivacy do the same thing. Why necessarily update the OS? And in any case, why constantly keep updating the OS past Android 6 where this feature was introduced?
Or fixes that close doors left open.