Modern Android is pretty secure
palone.blog
palone.blog
I had a Nexus 4, Nexus 7, Nexus 5X. All which should get top notch security updates. stopped where other platforms kept getting updates.
Just a few days ago I saw on HN some great news for Android (https://news.ycombinator.com/item?id=23692257). but again, this isn't a security update. It a broader security improvement equivalent to a major update on other platform.
While my 1st iPhone SE will get iOS 14, my Nexus 5X is still on Android 8.
you may choose Android for the specs, guess what, your phone will still get deprecated in 2 years
Apple supporting their phones for 5+ years is good, and they should be commended for doing this, but we should be introducing laws to make sure all manufacturers are doing this to a reasonable level.
PNGs are easy to send and in times of Contact Tracing via Bluetooth... well there are certain risks to running unpatched
They get security updates for 3 years (longer for enterprise devices). System libraries and builtin apps such as browser are updated via play store indefinitely.
But how many people _really_ use a phone more than 3 years?
No, neither of these support all android phones, but they each support several.
Other AOSP variants are more secure by an order of magnitude.
That's gonna be a big nope from me then. I was unaware of this, thank you for bringing it up.
I've been mostly unsuccessful trying to find other android variants that appear to still be maintained, would you mind pointing me towards one? I'll probably still wait for the PinePhone, but I'd like to stay knowledgeable on the subject.
I noticed that it only officially supports the Pixel devices.
I've always avoided the Pixel devices because I assumed that the firmware was closed source and therefore a privacy issue, especially coming from google.
However, the FAQ states "These devices meet the stringent privacy and security standards and have substantial upstream and downstream hardening specific to the devices."
Am I mistaken about the Pixel drivers being closed source? If not, how is this statement verified?
"Devices need to be meeting the standards of the project in order to be considered as potential targets. In addition to support for installing other operating systems, standard hardware-based security features like the hardware-backed keystores, verified boot, attestation and various hardware-based exploit mitigations need to be available. Devices also need to have decent integration of IOMMUs for isolating components such as the GPU, radios (NFC, Wi-Fi, Bluetooth, Cellular), media decode / encode, image processor, etc., because if the hardware / firmware support is missing or broken, there's not much that the OS can do to provide an alternative. Devices with support for alternative operating systems as an afterthought will not be considered. Devices need to have proper ongoing support for their firmware and software specific to the hardware like drivers in order to provide proper full security updates too. Devices that are end-of-life and no longer receiving these updates will not be supported."
I saw this part of the faq, but it was a bit beyond my comprehension.
This is an extremely interesting topic to me however, could you point me toward where I could do better research on the topic? I'll keep looking around myself and post something here if I see it for anyone else who's interested.
I'm no expert in this area myself (read as I've been educated by the internet and been too lazy to dig deeper), but I hope this reddit thread[0] leads you to some answers. Daniel Micay is the author of GrapheneOS, formerly CopperheadOS.
[0]: https://www.reddit.com/r/GrapheneOS/comments/bddq5u/os_secur...
This link does seem like a good place to start, thank you much.
If we had a law forcing phone makers to unlock bootloaders once support ends, then we could talk.
Unfortunately true. If you were going to want to use either of these you would have to purchase a phone specifically for it. The only reason I brought these up was the parent comment implying the purchasing of phones anyways.
> If we had a law forcing phone makers to unlock bootloaders once support ends, then we could talk.
Honestly, this would be amazing. This is one of the reasons I haven't purchased a phone yet, and am waiting on the PinePhone to become a viable daily driver.
Google has improved this in the Pixel line, with three years of updates. https://support.google.com/pixelphone/answer/4457705
My original Pixel (2016) received Android 10 last year. That's pretty good.
That's less than $70 per supported year.
That's just entirely unreasonable. I recently dug my original iPhone (now 13 years old) out of a box and it still works fine, but, you can't expect Apple or Android to support 13-year-old devices.
If mobile vendors can't do that, then they should limit support to the expected life span of a the battery under average daily usage conditions, starting on the date that device sales are discontinued. That's certainly less than 13 years.
Alternatively, the manufacturer could just unlock the boot loader after the official support period ends and provide the community with the resources they need to support the device.
Some people will continue to use their device until it is no longer functional. Either they can't afford frequent upgrades, or they're trying to reduce electronic waste, or whatever. It's wrong to strand those users on an unsafe platform.
Pixels are getting better, and Samsung flagships are getting their OS updates for 2-3 years and an additional 2 for security patches. That is.. barely good enough in my eyes.
Who needs security when the apps do it by design.
Check your firewall logs, or use a root/no-root firewall, it's frightening.
Edit: click the screenshots at https://play.google.com/store/apps/details?id=eu.faircode.ne... to see an example. Fourth picture "Access attempts"
The only downsides I have seen to this method are it's slightly annoying to initially install and if github goes down (where the pac is hosted), phone network connectivity goes down until it comes back up.
It would be cool if app stores showed which apps require network access and which don't.
https://play.google.com/store/apps/details?id=app.greyshirts...
For example it helped me find a trustworthy e-mail client (K-mail) by only allowing network access to my email server.
This kind of software can also be difficult to get right. There may be ways to easily bypass it.
If Google did this, I'd seriously consider going back to Android.
It's a shame Android doesn't allow vpn chaining though, because netguard creates a local vpn connection you can't use it with an actual vpn simultaneously.
I think the author could take the same engine and create a new so that just blocks trackers and Facebook and people would gladly pay for it.
You can hardly compare coreutils to smartphone apps.
As someone who deals with Android fragmentation daily, you wouldn't believe how hard it is to support the whole ecosystem. Disliking analytics I can understand, but crash reporting adds measurable improvement in the quality of software.
> You can hardly compare coreutils to smartphone apps.
Indeed; coreutils works on an absurd variety of unix-family systems, is copyleft, respects privacy, and is high-quality. If smartphone apps were more like coreutils, we'd all be better off.
> As someone who deals with Android fragmentation daily, you wouldn't believe how hard it is to support the whole ecosystem. Disliking analytics I can understand, but crash reporting adds measurable improvement in the quality of software.
I do understand where you're coming from; while I don't have skin in that game, I'm passingly aware of the remarkable ways that vendors break their systems. And honestly, if you get user consent, I don't actually have a problem with having the app report problems to you. It's just the "send information about the user's system without asking" thing that I object to.
Gimp: https://bugzilla.redhat.com/show_bug.cgi?id=1828800
I wouldn't call it auto-reporting when the user has to agree first; consent is the sticking point. (Same for abrt) (granted, I should have been more precise and I suppose that is automated in a sense; I took "automatic" to mean "without asking")
Here's an interesting article that goes in depth about the concept: https://dwheeler.com/secure-programs/Secure-Programs-HOWTO/o...
It's interesting to see how they call out repositories specifically for different manufacturers (ex. Samsung, Sony).
That's where Google and it's advocates have failed to understand what security is. Security is keeping something safe. And with the amount of data exfiltration Google's default platform plus the apps it allows and encourages do does not do a good job securing your information.
When a user installs an app that does behavior they didn't expect or intend to permit, that's a security issue, even if the platform APIs allowed it.
The difference in how Apple and Google approach Web APIs discussed a couple days ago highlights this: Google added a ton of APIs that lets websites do stuff with your computer, Apple decided they are risky and chooses not to implement them. Google would say the user has to give permission for those APIs to be used, so there's no security flaw if a website uses them maliciously: The user gave permission. Whereas, Apple would recognize the benefits to the user are minimal compared to the risk when the user grants permission unintentionally, which happens all the time for other web APIs like push notifications and even extension installs.
Practical security and technical security are two different things. Google does not even comprehend the former, while receiving wide accolades for their expertise at the latter, as in this article.
I am going to bite. You are just biased. Google adds more APIs because it doesn't have much interest in limiting some features to Play store, because Play is a such small part of their revenue. Apple would benefit if things are only possible through native apps because sweet 30% rent.
That said Google isn't exactly dumb but they aren't well organised in terms of Android - some areas get focus while others not. They even made it harder for external contributers of Android Open Source Project by following Google style monorepo patterns.
Contrast to Apple where mobile OS is their core business and they have to do it well.
I am pretty confident my next phone will be an Apple device. I was an Android fan, purchased all google/nexus devices starting with the G1. I had problems with many of those devices. I have switched to Samsung, but the amount of garbage on the phone still annoys me. Therefore, it is time to try iOS.
What I really like about OnePlus is their software. It's hands down the best Android version ever created. Love their additions to vanilla OS.
- https://www.xda-developers.com/oneplus-6-bootloader-protecti...
- https://www.xda-developers.com/two-critical-oneplus-33t-boot...
While OxygenOS is smooth and not bloated and their phones are cheaper than other flagships (in some markets at least), their security record isn't the best.
And they had other security issues, both with their phones and servers. I'm sure you can find more info with a quick search.
OnePlus makes good phones, but this thread is about Android security... and they don't have the best record.
I admit this is a niche issue, but it's critical for me.
Samsung Pay is OK, and I love the magnetic stripe emulation, but I hate that I need to auth again even though I've already unlocked the phone.
Also don't know what are people's problem with Touchwiz. It's a launcher, why are people so anal about a launcher? It does what it's supposed to do and stays out of the way.
I chose Samsung because of the value it brings in software, particularly Knox and support for app containers. Their hardware ecosystem is also quite fleshed out, although I haven't buy into it yet.
No other phone manufacturer comes close in terms of value.
I don't even know how one would really measure these things in a reliable and objective way. Do we compare it to IOS or Windows or ChromeOS or MacOS? Which version of Android and so on.
The post picks out the best things about Android, nothing wrong with that, but isn't that just ignoring all the problems with Android? I agree though, Android is pretty secure, but so is everything else.
Well in my case, I use Debian as my main operating system on my Desktop. Debian is great, but as a classical desktop OS it does not have those cool security things like app sandboxing, permissions management (camera acces etc) and stuff like that. Which makes sense, since mobile Operating Systems were designed from the ground up way later and also seem to move at a faster pace. The fact alone that almostt all ANdroid Apps run in the JVM and are written in memory safe languages is a huge plus that the GNU/Linux family does not have. (Solely speaking about security, I wouldnt want my /bin/sh to be in java)
In my particular case, it suprised me to find out that my android is the most secure device I own. Thus the title (and the intention to wrote this post).
So yeah, misleading title. Kinda. My Bad. Updated the title
If that's true, is there a TailsOS equivalent for phones?
That being said, privacy factors are primarily user-choice in that it is the optional apps and programs that compromise privacy, even if the privacy breaches are less-than-voluntary, as seen in the recent clipboard skimming scandal. Making an OS more secure by limiting unauthorized access to information like the clipboard is both more secure and more private.
For me improved security was more synonym to degraded performance.
--most drivers and hardware specifications are proprietary, and probably secret under NDA
--most bootloaders are cryptographically locked and controlled by vendor
--necessary wifi and cellular modem hardware is the same, and are also patent minefields even in the foundational platonic ideals of design, as is mobile graphics hardware
--the modems are subject to regulatory requirements that they be secured from modification by the user/owner of the device
Secure in this context means secure from the user and device owner, which can arguably be for good reason -- think of an ATM kiosk, for example.
So no "tails for phones" yet, but people are trying. Check out postmarketOS, lineageOS, replicant, sailfish. Last I tried things were still kind of science project, like 90's style linux.
To be clear, I see some measure of compromise as totally reasonable if one's goal is to get on an open os...
A wi-fi only Android tablet that doesn't require proprietary blobs to run vanilla Linux might do.
The article says that modern Android security is pretty good, listing a number of Android's security features and recent improvements, but the author never tries to make the case that it's "the most secure device you own".
There's also zero comparison between Android and any other operating system that would be required to support the HN title's conclusion.
Also, Android isn't a device, it's an operating system. An operating system is only as good as the devices it's put on; a deeply insecure device isn't going to magically be made better just be installing Android on it.
The original headline was "Android might be the most secure device you own".
Read here: https://news.ycombinator.com/item?id=23714416#23716962
I always thought it was an os by Google based on aosp(also Google..).