The situation on the phone market is so miserable.
The industry forces us to throw away perfectly fine hardware after just 3 years or so.
The situation on the phone market is so miserable.
The industry forces us to throw away perfectly fine hardware after just 3 years or so.
https://developers.google.com/android/images
I have a Pixel C that will never have an official patch to this exploit. I wonder if this is a user space exploit too, and if so, that would mean there's no technical reason for why they can't update it.
I'll take a look at Postmarket, I didn't know they were working on it. My issue is that I use the tablet primarily as my music workstation, and there are several apps I use that depend on Google Play.
I do have a Pinephone, and I would honestly prefer to use my time to get a matured OS for that.
EDIT: I looked around on PostmarketOS, I did not see anything for the Pixel C? I just saw an external resource on how to boot Linux onto the Pixel C
He was just talking about the wishlist I think, which is this one I guess: https://wiki.postmarketos.org/wiki/Device_Wishlist
But I don't see it there either.
https://www.moneysavingexpert.com/shopping/consumer-rights-r...
You'd only need to do it once to set a precedent, and everyone can get their phones fixed or replaced. The problem is that the law applies to the retailer, not to the manufacturer. As I didn't buy my phone direct, I'd have to get the retailer to replace it, and as I went to a high street retailer who is suffering from competition from Amazon etc, and closing branches, it feels bad to give the problem to them.
If I'd bought the phone from the manufacturer direct, from Amazon, or from a phone network, I'd gladly go ahead with the action because those retailers would have enough clout that the manufacturer would care about loosing their business.
https://www.gov.uk/make-money-claim
I've done it myself and got paid by an intransigent phone retailer relatively promptly after that point. My lawsuit was about a contractual dispute rather than faulty goods though.
”Under EU rules, a trader must repair, replace, reduce the price or give you a refund if goods you bought turn out to be faulty or do not look or work as advertised.”
So, the manufacturer, in the EU, never has anything to do with the consumer, legally.
I think a trader could successfully argue they didn’t advertise the device as secure, that the user didn’t suffer from it or, for devices that are out of warranty, that they don’t need to correct this issue anymore. claiming that it wasn’t ‘faulty’ could be harder, but I’m sure they would try. If a vulnerability isn’t known, is it a fault? Depends on whether its cause was generally known, I would think.
"The legal guarantee covers any defects presumed to have existed at the time of delivery and which become apparent within a period of two years. However, the crucial period is the 6 months after you bought your product:"
https://europa.eu/youreurope/citizens/consumers/shopping/gua...
So I'm assuming the bulk of older phones would no longer be covered?
Since when? Economic theory explains that they are expected to do no more than that, or else they'd leave money on the table.
Not sure what you're referring to. Chapter 11 is a form of reorganization in bankruptcy in US law.
Volkswagen AG (i.e. the VW Group) is an EUR85 billion German company that - despite the massive fines and recall - has been consistently profitable, with a small loss in 2015 due to the aforementioned issue and earned ~EUR12 billion in net profit last year.
watches the plan fail yet again
This is like saying "we dont need regulations in meat packing, every individual can become educated in butchery cleanliness and track the supply chains for the products they buy and everything will be better!"
It's easier to achieve regulation when people care and show that they care. It seems to me, voting now with your wallet is one of the most direct ways to make a case.
> I vote for what I think is best.
Maybe you're an exception, but if you're talking about "vote with your wallet", then the vast majority will actually vote what they think is best for their wallets.
I mean, if you're going to let money decide, then expect the outcome to benefit money.
People say this kind of thing all the time, even on HN. It's a libertarian saw that the FDA is unneccesary and obstructionist. Personally I think it's deranged, but apparently it's an ideological battle that's still being fought.
If you mean "a bunch of relatively new Android phones not getting security updates because their manufacturer doesn't support them", then yes. Apple is actively providing not just security patches but entire feature software updates for the iPhone 6S, which is 4.5 years old at this point.
Did this already happen? I only remember the announcement and then researchers on Twitter complaining that the first one is yet to be seen.
iOS ecosystem. Since Apple is a hardware manufacturer foremost, you notice from the start you aren’t the product. Lots of apps, many of high quality.
Librem/Pinephone : Linux phones. While the hardware is still closed source in certain parts, it’s a step up from what we have now. Librem allows you to install any linux variant you choose.
Zerophone : Build your own phone basically, very cheap to build ($50) , and currently in development.
There is more to a phone than just the cpu.
I'm gonna keep these things running as long as I can, because the prospect of replacing them with something a decade newer but inferior in every meaningful way is simply sad.
LineageOS is the only reason I don't loathe the whole Android ecosystem, to be honest.
Rooting permits applications to have more control over the device at runtime. Some devices require the bootloader to be unlocked to enable rooting, and others do not.
Nokia is the best though: https://www.counterpointresearch.com/nokia-leads-global-rank...
they support even their very old phones to upgrade up to the latest version of Android.
It is missing the Jan & Feb 2020 updates that the Pixel 2 received, but it's plausible the Pixel 1 could still get a patch for this critical issue.
Less dangerous, for sure...
And get locked in another walled garden? Erm... no thank you.
You can appreciate the longevity and continued support of an iPhone without having an Apple Watch. You can appreciate a MacBook for its OS (pre Catalina anyway) and build quality (I'm still running a 2014 model -- though I have read about recent models' issues) without having an iPhone to pair it with. To be fair, you cannot appreciate an Apple Watch without an iPhone at all since it won't do anything, and I'm no the fence about AirPods and how well they do outside the Apple world.
My point is, once you're in the ecosystem, you notice a lot of little things that may make your life easier. Are they great? Yeah absolutely. Are they what sells the product? In my opinion, not at all. Unless it happens to pinpoint your exact use case (I need to lock and unlock my MacBook 30 times a day and I'm tired of having to enter a password, I want my Apple Watch to unlock it), it's the product itself that will most likely convince you. The way they neatly play together at times is just the cherry on top, like when you notice your computer and phone now share a clipboard. That's awesome, but not a single selling point for anyone.
Now, I will be the first one to say: iTunes sucks. So, if you do buy an iPhone, it makes sense IMO to shed out the extra 99ct a month for iCloud storage.
I didn't want my comment to sound like I'm saying Apple does it best. I just wanted to drive the point home that I don't think it's mainly the ecosystem that makes Apple devices fun to use.
As a side note, I wasn't talking hardware that lasts 5 years. We all know most devices on the market now can pull that off, bar one battery-replacement. I was rather talking continued software updates, where iOS is certainly in the lead.
Edit: just re-read your comment and you were talking Apple computers specifically. Oh well :)
I feel like that only furthers my original point though. I didn't want to argue that Apple does it best, only that you can enjoy their devices without being fully bought into the ecosystem.
The current options include all Nokia smartphones, Motorola One line, and Xiaomi Mi A line.
For the best hardware and 5G support, I would look at Nokia 9.2 (Snapdragon 8--) and Nokia 8.2 (Snapdragon 7--) releases this year.
The best deal is to buy 6 months after the release, when most Android devices become heavily (30-40%) discounted, but are still quite new.
I prefer Android over iOS because of the freedom to install open-source OS-level ad-blockers, such as Blokada[1], which greatly improve privacy and battery life.
That's true. Just like Samsung, Huawei, OnePlus, and any other Android manufacturer except Nokia, Xiaomi maintains its own Android ROM, called MIUI[1]. It's not as vanilla as Android One, but at least it also receives monthly security patches.
> Among which is the need to "sign up" online for bootloader unlock and wait for a timeout period. They do this because resellers used to ship bootloader-unlocked versions with "unofficial" mods of sorts, often with customers being none-the-wiser. Not an issue on the 'Mi A' line, for whatever reason.
It's not an issue with Xiaomi Mi A line, because Xiaomi's reputation is not affected as much if there is something wrong with a smartphone that is not running its custom ROM.
Nokia has only recently started allowing to unlock the bootloader of some of the models, and has a similar process[2].
And any custom Android ROM requires drivers to be able to completely support the hardware of a particular device.
[1] https://www.howtogeek.com/241012/safetynet-explained-why-and...
Librem/Pinephone : Linux phones. While the hardware is still closed source in certain parts, it’s a step up from what we have now. Librem allows you to install any linux variant you choose.
Zerophone : Build your own phone basically, very cheap to build ($50) , and currently in development.
Also FWIW, the problem has zilch to do with "Android" per se - pre-Android mobile Linux was even worse. It's embedded platforms in general.
Having a "standard" OS interface for the phone, where there is just one OS image for a given OS version, and that image could be installed on any phone - now that would be the true alternative, which I would be delighted to vote for with my wallet.
Project Treble is working towards this, in a way. But it's a huge hack that's still dependent on lots of weird AOSP-specific stuff, and doesn't even give you a "single" OS image for every device - the "proper" image for your device varies by baseline AOSP support (7, 8, 9, 10), "A" vs. "A+B" boot and of course 32-bit vs. 64-bit architecture. Nowhere near "UEFI-based PC" territory.
Sure, but each PC is also 'unique' in that sense, in fact I'd happily bet that there are more different kinds of hardware combinations for PCs than there are android phone models. And yet, that never was a problem.
for i in range(256):
poke(i,magic1)
if peek(i) == magic2:
found!
256 probes in all is not that bad, and real-world probing would only try a handful of commonly used addresses, making it even faster.Phone SoCs on the other hand have many peripherals memory-mapped, (meaning there are millions/billions addresses to 'probe'), plus there are things like power sequencing, GPIO enable lines that need to be asserted, and clock-sources configured before peripheral would even respond at all. Oh, and that GPIO, or power controller, or clock source themselves might be accessible via an i2c chip speaking its own protocol, so you need to initialize those first, etc, etc.
All of this complexity could be described via linux "devicetree" subsystem, and devicetrees are in a usable state for some hardware (although DT itself is often a labyrinth to navigate). Thing is - factory software for most phones have been extremely slow to adopt DT, and even some that do use DT, don't do it in a particularly portable way.
Better go with a Pinephone if everything that's been written about Librem as a company is even half-true.
If I have $200 to spend on a phone, I will not buy a low-end 2019 $200 phone.
I will buy a used (or new-old-stock) flagship that was $700 when it came out a few years ago, and is now $200 on the used market.
The older flagship will have similar specs to today's low-end junk, but also all the enthusiast support, better accessory availability, and probably better build quality overall, because it was originally intended to be the highest of the high-end.
I've saved hundreds of dollars of technology on trivial home repairs instead of buying replacements.
That means there is no Android or Apple device on the market today that accomplishes what you say.
The only phones that are out there that can do that are the Pinephone and Librem 5. I have beta devices of both, and while I am extremely excited to see them mature and turn into daily drivers, the fact is neither can actually be a daily driver today.
Can you name one smartphone device with open internals? I'd love to buy one, but I don't think they exist. From Replicant's recommendations [1]:
If compromising on privacy/security is not an option, or anything serious is at stake (e.g. political activism or journalism in a sensitive area), it is advised to avoid using a telephony-enabled device at all.
My impression from the smartphone market is that phone platforms have become less open, not more, over the last ten years. The PinePhone isn't generally available yet, and the Librem 5 current iterations don't have working audio calls.
[1] https://www.replicant.us/freedom-privacy-security-issues.php...
Mainline Linux:
https://pocket.popcorncomputer.com/
Mainline Linux + high-level hardware documentation:
* The barrier of entry is very high: You need a top-tier manufacturing system and supply chain. An operating system. An entire suite and market of applications. All of the apps users expect and rely on (mail, navigation, Facebook, chat, Instagram, etc.) must be supported. The hardware is only profitable if you manufacture at very high scale.
* Information asymmetry is very high. Users have almost no insight into how secure one platform is versus another. In fact, they have access to paradoxical information. The most secure platforms are the ones with the most transparent security flaw handling, but those are also the ones that appear the least secure because the vulnerabilities are more widely reported.
* Products are nowhere near commoditized. A phone is a very large constellation of hardware, operating system, and software features. There is no apples to apples comparison between phones. Maybe you like the camera on one but not the screen on the other. One has better apps but the other a more stable OS.
This is not a market where consumer choice will effectively drive solutions to diffuse problems.
"Voting with your wallet" only leads to good outcomes if the incentives are right. I mean it's money, the VAST majority of it is spent not for the greater good but for small, inefficient egotistical purposes.
Phones are not usually in that state unless the BT settings screen is open. Otherwise it would drain excess battery in normal use.
While scanning for devices, a phone reveals the Mac address. There are other ways to know the Mac address too.
Almost every month there are security patches for "critical" problems. Just skim throught the blog pages. This is Jan 2020 for example: https://source.android.com/security/bulletin/2020-01-01
Consider this: if I remember correctly somebody on HN was saying that in these days the average time from releasing a patch and exploit found in the wild is 4 days.
Consider that the patches hit the open source code a lot before they are deployed.
Consider that beside Google, any other Android phone manufacturer take around a month before releasing the patches even on current models.
The situation has no easy solutions.
Still the biggest problem. For my PC I can install updates on a daily basis. For my smartphone, I can be happy if there are any updates at all.
The old iPhone is going to work as well as, if not better than, a new android device - Apple tends to be about 5 years ahead of Qualcomm in performance, and they actually service their devices. My mom is using my iPhone 6S from 2015 that feels about as snappy as my 2018 XR. And that feels snappier than a pixel 4.
Very few people are software developers so the Mac req to develop is a non-issue.
[1] https://www.zdnet.com/article/no-gpl-apps-for-apples-app-sto...
And then, to actually develop software, I would have to work on this mac operating system. I don't know who came up with their keybindings and shortcuts, but it's an absolute inconsistent mess when compared to any other OS. Whenever I have to touch a mac to assist a coworker it's utterly frustrating.
Possibly because of things like this; when a vulnerability isn't going to get patched, churn (with new hardware running newest OS) protects the ecosystem against mass-compromise.
We can bemoan the lack of patches, but who's paying for the patches?
When you can make a ridiculous profit on a flagship phone and sell it for $500-700 (say, a OnePlus, for a good example), but they sell it for $800-1400 (Samsung, Apple, et al), then what am I paying for? It's supposed to be for better support and a smoother experience when things go wrong.
You know who has historically stabbed me in the back the least? OnePlus. I'm not going to say it has been perfect, but for a phone I spent $550 on, they've screwed me far less times than other alternatives would have.
So, we are paying for the patches to be delivered on a meaningful schedule for more than 3 years. I seem to be getting it what I paid for, and you don't.
There is something massively wrong with this picture.
You are paying for 5 years of updates.
And a superior phone.
The worst part is that people keep using the phones because are not tech savvy or grossly underway the risk and they do not feel that they need to spend money on a new phone.