you may choose Android for the specs, guess what, your phone will still get deprecated in 2 years
you may choose Android for the specs, guess what, your phone will still get deprecated in 2 years
PNGs are easy to send and in times of Contact Tracing via Bluetooth... well there are certain risks to running unpatched
Apple supporting their phones for 5+ years is good, and they should be commended for doing this, but we should be introducing laws to make sure all manufacturers are doing this to a reasonable level.
No, neither of these support all android phones, but they each support several.
Other AOSP variants are more secure by an order of magnitude.
That's gonna be a big nope from me then. I was unaware of this, thank you for bringing it up.
I've been mostly unsuccessful trying to find other android variants that appear to still be maintained, would you mind pointing me towards one? I'll probably still wait for the PinePhone, but I'd like to stay knowledgeable on the subject.
I noticed that it only officially supports the Pixel devices.
I've always avoided the Pixel devices because I assumed that the firmware was closed source and therefore a privacy issue, especially coming from google.
However, the FAQ states "These devices meet the stringent privacy and security standards and have substantial upstream and downstream hardening specific to the devices."
Am I mistaken about the Pixel drivers being closed source? If not, how is this statement verified?
"Devices need to be meeting the standards of the project in order to be considered as potential targets. In addition to support for installing other operating systems, standard hardware-based security features like the hardware-backed keystores, verified boot, attestation and various hardware-based exploit mitigations need to be available. Devices also need to have decent integration of IOMMUs for isolating components such as the GPU, radios (NFC, Wi-Fi, Bluetooth, Cellular), media decode / encode, image processor, etc., because if the hardware / firmware support is missing or broken, there's not much that the OS can do to provide an alternative. Devices with support for alternative operating systems as an afterthought will not be considered. Devices need to have proper ongoing support for their firmware and software specific to the hardware like drivers in order to provide proper full security updates too. Devices that are end-of-life and no longer receiving these updates will not be supported."
I saw this part of the faq, but it was a bit beyond my comprehension.
This is an extremely interesting topic to me however, could you point me toward where I could do better research on the topic? I'll keep looking around myself and post something here if I see it for anyone else who's interested.
I'm no expert in this area myself (read as I've been educated by the internet and been too lazy to dig deeper), but I hope this reddit thread[0] leads you to some answers. Daniel Micay is the author of GrapheneOS, formerly CopperheadOS.
[0]: https://www.reddit.com/r/GrapheneOS/comments/bddq5u/os_secur...
This link does seem like a good place to start, thank you much.
If we had a law forcing phone makers to unlock bootloaders once support ends, then we could talk.
Unfortunately true. If you were going to want to use either of these you would have to purchase a phone specifically for it. The only reason I brought these up was the parent comment implying the purchasing of phones anyways.
> If we had a law forcing phone makers to unlock bootloaders once support ends, then we could talk.
Honestly, this would be amazing. This is one of the reasons I haven't purchased a phone yet, and am waiting on the PinePhone to become a viable daily driver.
They get security updates for 3 years (longer for enterprise devices). System libraries and builtin apps such as browser are updated via play store indefinitely.
But how many people _really_ use a phone more than 3 years?