The state of Android updates is still dire
theverge.com
theverge.com
It is indeed dire.
Each new version of Android is typically reaching less and less devices, X months after release.
For example Android M, released in 2015, was on 24% of devices accessing the play store 12 months after release.
Android O, released in 2017, was on 14.6% of devices 12 months after release.
Here's the chart: https://i.imgur.com/yRDIEAs.png
Google stopped releasing these numbers on their developer dashboard, and I think it's possible that the reason is because they're terrible.
[1] https://unlikekinds.com/article/android-updates-are-getting-...
I believe it is hardware vendors that don't want to support update. It is a lot of works (costs) for them with little and no return. It might even be negative returns since a phone with updated OS might delay that user purchase a new phone every 1-2 years.
Apple can incentivise updates much better because they control the whole ecosystem. To achieve this, Google would need to somehow _force_ OEMs to update Android, but the fragmentation makes this a herculean task.
It's one of those old early Android mistakes that were never really fixed. I think the root issue is that they were never even fully acknowledged.
I wrote about this here:
https://dev.to/jmfayard/android-s-billion-dollar-mistake-327...
More fragmented than Android. Continuous updates even for hardware from the year 2000 (a few paid along the way).
"This is why I never want to get new phones or computers" was muttered probably about 15 times in the two hours I was helping her salvage content from the older device.
The release of Android (5.x) was obsolute at initial product release.
There has been no update. There is no update path. The device is locked down to the point that I have been unable to root or re-ROM it.
I'd been under the impression at purchase time that 1) OEM updates would be provided, 2) rooting was possible, and 3) re-ROMing was an option. All three beliefs proved false.
Samsung are directly to blame.
But Google can fix this. Google haven't. Google aren't.
Google can pleasure itself.
Showing the total number of Play Store devices used to calculate each percentage would be useful to compensate for this, but Google is probably reticent to divulge such information.
The vast majority of Android devices in use are Samsung devices though.. judging from my own apps' stats and other stats I've seen around over the years
Thing is, many of them are still happily producing Android 5 and 6 devices.
I think I got 2 years of updates on my TV, and it's not like I'm going to want to throw it out and get a new one, so I have to put up with outdated software.
They are not lying, of course. A well-known advertising company known for its engine[1] has installed a rootkit on it. Of course, this warning is about rootkits Google doesn't trust (either).
If security was the objective, Google could easily improve it without compromising freedom. Let people choose who they trust.[2] Encrypt the OS so attackers can't modify it. Or not telling attackers that there's an unlocked backdoor they can use.
[1] Missing: <s>search<s/>
[2] Technically, Android supports enrolling your own key. But that's optional for device makers and I haven't found any useful documentation. You also still get a warning on boot, this one is yellow.
[3] Replacing it is easy to detect unless you somehow manage to replicate the phone state as it was. Part of that state could even be a kind of reverse password that the phone uses to authenticate itself to it's owner.
It's the same thing around passwords. People don't use weak passwords or reuse their passwords because they don't know any better, they do it because they do not care about whatever is protected by the password. I personally couldn't care less if someone stole my Facebook or that some bad actor may abuse something in my phone to send something to China. These digital things rank very low on the list of my priorities, and like me are a lot of not very technical interested people.
Some people buy cheap phones knowing they won't get updates, we know, we don't care. And we are happy to have the option not to care, we do not want more expensive phone with constant updates, just like we don't want the mandatory use of password managers. If we cared we'd buy/use them.
If the manufacturer still imposes this level of control over the average user, it’s sort of just a worse version of a walled garden, isn’t it?
The real problem with updates is all the crapware that companies like Samsung foist on people. It's shitty software that never works right but still gets delivered and then its brokenness is in the way of an operating system update because of how shitty it is.
I'm not advocating for really any particular way of doing it, but rather just noting how Apple definitely has the opportunity for making OS updates a smoother experience than either Microsoft or Google because of their level of control at the hardware level. Apple doesn't always get it right (see Catalina), but they could do better than they do.
I think there'd be a veritable shitstorm if, say, AT&T suddenly decided to withhold iOS 13 for 6-12 months, while it's effectively SOP for Android devices (where you have manufacturers needing months to release a new version, then providers who delay it even further to test ... something).
Good for you. But those that do care have worryingly few options.
That email comes in so many variants it's really entertaining. Someone is really trying hard to find the magic wording that gets through spam filters and makes people pay. It's not getting through my spam filter sadly, so when I want to read the latest episode I have to go look for it in the spam folder.
So I think what's far more important than choosing strong passwords is choosing different ones for each account.
In my experience, people don't want updates until they want some emoji, app, UI animation etc. that is highly desired but they cannot have it.
When they encounter such a situation, they hate it and feel bad for their poor choice of device. It is very off-putting when you cannot have that small thing that all your friends have without making a serious investment of time and money to upgrade to a new device.
iOS users very rarely have those bad experiences, when the new iOS is out even many non-technical users will get excited because they will be exploring the new shiny features and designs with their friends and nobody is left out. If some feature is missing, they will understand that their device is old but they will still get some shiny things and almost never missing stuff that is alienatingly bad.
This is quite often false from my experience talking with people using bad passwords. The most frequent reason seems to be a basic misunderstanding of the problem, i.e. "But who would ever think of trying and manage guessing CowMilk76$ as my password."
So it mostly boils down to not being aware of computer assisted cracking, let alone modern cracking techniques with rules and statistics. They are imagining someone targeting them specifically, using their own hands and imagination. From that perspective, it is quite ludicrous to think someone would be able to crack CowMilk76$ as their password practically.
I'm not sure what the answer is, but longer and more complicated passwords aren't.
These days, most people I know, both on the iOS and Android side of things, approach updates with a resigned sigh of "what are they going to make me relearn for no reason this time?" with a healthy pinch of "man I hope this doesn't break anything." If Apple/Google owned up to this reality, maybe the updates would be smoother.
Its astounding what older devices are capable of with the right software. I installed the community supported version of ubuntu touch on a nexus 5 phone which is about 7 years old now and was stunned to see it was buttery smooth. This device was running faster than my pixel 2. Even web browsing and web youtube worked fine. Apart from the horrible camera and lack of an sdcard slot you could actually use this as a main phone quite easily.
except it has none of the apps you need if you belong to 99% of typical users.
People don't really need most installable apps. Just about every tool I use has a mobile website/PWA.
Some users might "need" Snapchat and Instagram (if we really stretch the meaning of "need"), but not 99% of them. A person who is willing to use old phones is probably more likely to not use those apps. I'm sure that many people wouldn't use them if it made their old phones work better. People who want those other kinds of entertainment apps can still spend money on new phones if they want.
You would probably find your days more productive and enjoyable if your phone didn't support the general garbage people install.
And since smart phones can run different apps, it’s not about the “one true phone”.
It’s like the old Slashdot feigned ignorance meme “Do people still watch TV? I haven’t owned a TV in 10 years”.
On monitor I choose what to watch, on TV I am forced to watch what someone else chosen.
I didn't own a TV ever (well, since I went to college), I see it only in my parents house when I visit.
Back then, they were also essentially the same technology (cathode ray tubes), but the TV had tuner and some analog circuitry to decode the signal.
The only way I see this could be done is if every oem committed to standard shapes for every part but that would never happen because they shape and layout of a phone is the only way they can make visual changes so people know its a new phone.
That's not the only logically sound story one can tell. Another story might be: porting OSes to old hardware raises their resale value, which means your new phones won't be competing against a cheaper version of itself. And people will be willing to pay more if they trust the phone they buy can be sold years later, or handed down their family.
I am on Android 10 and honestly I wish I didn't update. The update bricked by phone until I went in the bootloader to reset it to delete my data. Was it great to have it on day 1 (essential ph-1)? Maybe 5 years ago I would say yes, but now no. It wasted 2 hours of my time. Next time I will buy a phone with a good camera instead.
My experience with Android 9 was similar, but didn't break anything. The UI changes were just not good. I personally know the reason (worked with some of them) - all (unfortunately really all, no idea why this wasn't fixed) designers at Google are Apple users and have a bit if Apple envy. Apple can change the UX for everyone and make users get used to it (even if it is less efficient for everyone, which it is). Why wouldn't Google be able to do it? So Android had the best app switcher, but converged to the iOSish variant. I wish Google would just ignore Apple like Microsoft does it in their Windows.
In a similar way, most journalists are Apple users and there is one "right" way to do things. So we get this nonsense in articles and blogs.
Given the current state of infosec, any OS that has not received any security update for a year or two is doomed to become a sitting duck for malware. Device security is a whack-a-mole game where new vulnerabilities are found daily and security updates are the only way we have to keep our computers secure.
In a perfect world, UI-and-features-related updates would be optional while security updates would be seamless. Also in a perfect world, older OS releases would receive long term security support and you should not have to upgrade to a more recent release to be secure.
Alas, we do not live in a perfect world. Apple doesn't provide any easy way to accept security updates but refusing others. Android just doesn't seem to provide a seamless update experience, either for security updates or not.
So you should really apply security updates, and if it takes getting other updates for that, then so be it.
If I were in control of the Android update release cycle I'd try to force this separation, but I'm sure it's more complex than it seems.
Still, the ideal, as ever, probably lies somewhere between the status quo and my over simplified dream!
You weren't forced to upgrade. It was offered and you accepted. You would have still got security upgrades on V9 (from Google) for some time. Many people don't get an upgrade, let along a choice of refusing it.
Re UX, you don't have to use gestures. You can opt into the "traditional" three-button system.
the three buttons no longer work as before - e.g. long press no longer does split-screen. Furthermore, the UX before was cards one on top of each other, the open app is the topmost. The current "logic" is with cards sideways. Which is ugly, non-intuitive and copied from iOS. If you move left to take another card, suddenly your previous card does not remain on the right side. How is this intuitive? Even from business perspective this does not make sense, because once I got used to the new non-intuitive and less efficient UI, the switching costs to iOS for me will be lower.
When you say non-intuitive, you're not talking about intuition. Holding a button for split screen not intuitive, it's just something you've learnt. Rows vs piles of cards are essentially the same thing, each with slight benefits.
Reforging muscle memory is an inconvenience, but if Google thinks it has a better UX (copied or not) for non-indoctrinated users, maybe it's worth learning another way.
And the similar-UX business case works both directions.
We wouldn't have the things you're hanging onto without that sort of development.
This would mean that you'd have to commit to a stable ABI for device drivers, forever.
The only phone I know which fits this description is the Librem 5. Unfortunately it would currently be a lot cheaper to just buy second hand android phones every 2 years than to buy one of these but hopefully they can get the price down later.
5 years of support for a driver ABI seems achievable though. Especially for basic things like proximity sensors, touch screens, buttons etc.
How often is the ABI for a button going to change?
I can't think of any open source software vendor that is able to force its customers to accept strict policies, because forking is always an option.
Windows updates work for years because manufacturers maintain Windows drivers for their hardware. The Android ecosystem is more like the Linux desktop one -- each manufacturer sells a different Android distribution with their own custom stuff mixed in.
This is a pretty weak argument against doing the right thing by taking control of system updates. Even stock Android devices stop getting updates very quickly because of how tightly coupled to the hardware drivers Android is. It doesn't have to be that way.
Linux doesn't. So OS updates leave behind old drivers.
So manufacturers don't have to do anything for their drivers to continue working on Windows, and it is often the case that updates will stop shortly after hardware is released.
— Greg Kroah-Hartman <greg@kroah.com>
https://www.kernel.org/doc/html/latest/process/stable-api-no...
Amazon is doing okay with cheap tablets but their phone was a failure.
Last I checked a big issue was Qualcomm doens't support their SoC for very long so manufactures have to tweak each devices 'tree' (it's unique kernel and drivers) for each kernel update.
The whole point of project treble was to disconnect the Android version from the kernel version so that manufactures could keep using the existing kernel and drivers and would only have to recustomize the new OSI to their liking.
Turns out a lot of device manufactures still don't see much value in providing timely updates since the general public doesn't even know what version their currently running and are just as likely to hate an update than like it.
Personally, I feel Google's sluggishness to enforce update policies or change how Android works is out of fear that Samsung will break completely and launch their own app store and not have the Play Store, or rather Play Services which is what Google needs if they want to power many of their online platforms (where do you think Google map road conditions come from?, Or that feature that shows how busy restaurants are?). Without play services on every Android device, Android looses it's profitability.
I think you may be mixing up “ABI” and “API”. If you change internal kernel APIs, you’d break a lot of code and have to go in and fix it. If you change the ABI, you just have to recompile. The ABI does change pretty often and as a rule of thumb there is no effort to keep it stable, the way you would if you were writing a shared library (which ideally has both a stable API and ABI). Drivers in the kernel are not broken because they are recompiled with the rest of the kernel. Kernel modules from different kernel versions ARE broken and this is why we have DKMS.
But just to talk about what happens here—Apple is the only developer of the XNU kernel, and they have a fairly short list of iOS SKUs in the history of iOS, and only a small portion of those get iOS 13 support—something like 12 iPhone models. So the support for all of these devices is right on the mainline kernel development tree.
This is not how Android development works. You generally have a bunch of different manufacturers, who get a team of engineers to get a fork of the Linux kernel working on each device, and then they drop it and move on to the next one. There will be various binary blobs involved, and integrating the changes back upstream or downstream ends up being a pain.
And just to return to the original point, the Linux kernel developers are actively hostile to any attempts to make the kernel ABI stable enough for binary blob drivers to work. This is not a question about whether it is technically possible.
In contrast, Qualcomm gives the OEMs a copy the custom Linux kernel that works with their SoC[1]. The OEMs then use that source to build their kernel, probably making minimal changes to it. Once Qualcomm stops selling that SoC, they stop releasing updates to their custom kernel because there's no pressure from OEMs to keep it patched.
[1] eg. https://github.com/MiCode/Xiaomi_Kernel_OpenSource/tree/ceph...
I'd expect it to be technically possible, and for Google not too difficult, to pick a version of the Linux kernel module ABI to define as the Android module ABI, and then for newer kernels with newer kernel module ABIs add an adapter layer that can translate from the old ABI to the new ABI.
— Greg Kroah-Hartman <greg@kroah.com>
https://www.kernel.org/doc/html/latest/process/stable-api-no...
And fuck the billions of people with CVEd kernels because of it; they're just collateral damage, right? /sigh/
Classical Linux drivers are considered legacy on Trebelized devices.
https://source.android.com/devices/architecture/hal#hal-modu...
The big problem is that in spite of having a standard ABI, Google does not require OEMs to actually push updates, so everything stands as before for consumers, while OEMs have even lower development costs.
Hasn't Samsung already tried that with Tizen (and didn't do well), which was also put on its Gear smartwatches?
The most representative public data for a US centric app is Mixpanel's [1]. This has lined up with most of the apps I've worked on more closely than Google's own dashboard [2].
If I were starting an app today with no data, I would set my minSDK to Lollipop (21). If I had an existing app I'd be dropping support of any version used by <1-3% of my user base.
[1] https://mixpanel.com/trends/#report/android_os_adoption [2] https://developer.android.com/about/dashboards
Tablets get less love than phones too. That said, my recent expriences have been better than prior, but still somewhat dire.
"two years and its junk" is a pretty bad rule. it feels like formalized planned-obsolescence.
Things like settings UI can be fixed for all vendors so that we don't get confused everytime we get a different phone! I hope fushcia does it this way!
Such a standard is expected in commercial software because businesses won't tolerate expensive disruptions to placate a vendor's vanity. If Google were serious about maintaining a healthy Android ecosystem, they'd make platform upgrades mandatory and transparent. Launcher and interface "upgrades" can and should be optional.
As far as I know, Microsoft continues to fret over backward compatibility with software that's probably older than their median employee, because their customers expect nothing less. Moreover, customers demand a consistent experience and have very little tolerance for arbitrary workflow disruption (a point forcibly driven home by the crash and burn of Windows 8, in case it wasn't already obvious enough).
RHEL releases are supported for more than 10 years and they function essentially identically the entire time, somehow without leaving users in the breach to contend alone against a decade's worth of crashes and security flaws, and believe it or not, there are specialized and boutique platforms that take this type of thing even more seriously.
"Don't break the user's shit" is not only possible, it's the baseline expectation from any profesionally-managed platform.
Then we have Google saying "Hey, upgrade your OS and we'll change the whole interface, break a third of your software, and force you to learn this weird new 'no buttons' thing because buttons aren't in this year. No takebacks." When that's all vendors have to offer, it's not a surprise that consumers avoid upgrades like the plague.
While Apple is definitely closer to the Google side of the fence here, they've paid a high price for it over the decades, penetrating only those industries where the appearance of eccentric creativity is a larger asset than consistent productivity. Since iOS devices are primarily a status symbol, it appears the combination of getting the hottest thing and feeling compliant with the overlords in Cupertino is sufficient upgrade motive for the ever-dwindling number of iOS users.
Google should know their audience of "everyone else" well enough to know that for most people, that dog just don't hunt. Maybe it's time for Microsoft to draw its claws out of Nokia and see what happens if they take another pass at the market.
But at the same time, I think Google wants to sell it's own phones and competes with other Android manufacturers.
That's conflict of own Google interests.
And "other manufacturers" mostly care about their sales, - they don't really care about Android OS success - that's for Google to care.