Germany wants smartphone makers to offer 7 years of software updates
xda-developers.com
xda-developers.com
2. The federal election happens later this month. Take this plan with a grain of salt.
3. The original article by heise.de mentions that the federal government will push these plans during negotiation of the EU wide laws. The government thinks that the plans of the commission do not go far enough. However it's unlikely that Germany will implement stricter rules on a national level.
While I'd be happy for this plan to go through, I don't think most of the people will be happy with the side effects. Especially because of the spare parts requirements, I guess manufacturers will
1) Withdraw from EU market. 2) Reduce number of models on offer. 3) Raise prices.
Should it be legal to make cars for poor people without airbags and seatbelts?
And are we really gonna argue that this idea would be for the benefit of the poor people?
2. That would actually be good, the amount of models aims at confusing customers. But also: Why would that happen? Many models can (and do) share the same spare parts.
3. Prices are already as high as they can be. They do not get lowered because production gets less expensive, they get lowered because of competition. This might have an effect on prices if the competition was very high and profit span very thin - which might be the case for the cheapest budget phones. For something like an iPhone? To my knowledge they are already utterly overpriced, as is tradition (https://www.forbes.com/sites/ewanspence/2017/11/08/apple-iph...), then it will have no effect there.
I expect the poorest to benefit the most from extended longevity, since more affluent people "need" the better camera or a more fashionable design the most.
I know quite a few people with >3 year old smartphones, but mostly with custom roms, since stock firmware isn't usable anymore.
2. "longevity" means nothing when most people keep dropping their phone. Even used phones that appear perfect can start bootlooping months after buying because of damage caused by the first owner and the eBay seller won't accept returns by than, even if you could prove it was not caused by you.
Someone who is really clumsy or in a situation where they are much more likely than average to drop their phone should purchase phone insurance.
And for uninsured people who happen to break their phone, it would still be cheaper to repair it than to get a new one. Repaired phones still benefit from longer support lifecycles, and the proposed legislation would ensure that spare parts are affordable and available.
The latter may be a problem but you could still buy an older (mid-cycle) model instead of the latest one and still get updates for years.
Does everyone on hackernews get paid £100k a year and spend over £1,000 on a phone?
You wouldn’t buy a car either without planning for repair costs.
There is also no good reason for the cost of security fixes to vastly increase the cost for manufacturers if they slow down the release cycle for hardware and software. This isn't 2010 after all. The pace of meaningful improvements is considerably slower.
They have a far higher trade in or resale value than any other brand.
It actually causes a bigger second hand market of phones if they have a longer life. Plenty of users still want the latest or there abouts. While others will happily go for the nearly new.
The result of this law would be that cheap phones will get more expensive for no benefit at all and expensive phones will cost the same.
Not even going into the problems with second-hand phones and that poor people de-factor have zero legal rights as they don't have the money to take sellers to court.
Many used phone sellers/marketplaces offer extended warranties on second-hand phones, which risk-averse buyers should purchase.
This thread is about EU law.
In EU you don't have to take sellers to court, you just have to nag customer protection authorities until they do.
It might take some time: Google still hasn't gotten a massive fine for abusing its position in search and ads to kill competing browsers despite my reports but I will not be surprised when it happpens.
PS: come on guys and gals and do write to your local competition authorities. The sooner we can get this sorted the better.
(1) Battery stops holding a charge
(2) The device gets damaged
(3) Cameras get a lot better
The Nexus 6 automatically throttled performance based on battery left, but at some point the battery wore out to the point that less than 1/2 an hour of use got you below that threshold. After that the phone was very laggy and frustrating to use. No way anyone would want 5 years of that experience, updates or not.
As for cost, I don't see why it would have to go up all that much. Apps are already upgradable on phones and much of the OS is hardware independent. So the only real pressure point is with the kernel and other hardware dependent code.
I see this as a big plus. Not a fan of Apple but they did get this one right (at least in the past).
1) Withdraw from EU market - I guess most people dont realise EU as a market itself is 2nd just behind US.
2) Reduce number of models on offer - Parts aren't that different across models.
3) Most likely answer - Although it doesn't cost that much at all. You can still get a 7 years old iPhone 6 repaired, it is just costly, as it did 7 years ago. The incentive pushes you to buy a new Phone.
Come on. Every time the EU tries to implement a consumer protection a whole contingent of people comes here to say that this will cause companies to leave the EU. China is so much worse in terms of constrictive laws and regulations and you can plainly see that companies don't care. They adapt and sell, that's how they work.
Some other examples of non security issues that might require modifications:
* Widespread adoption hosting multiple services on the same IP, relying on SNI for TLS to function. While this is in TLS as well, it's not a security issue. In practice it was adopted slowly enough that it didn't cause many problems
* A quick switch from IPv4 to IPv6 (lol)
* Y2K (happened before smartphones)
* timezone database changes (e.g. if the EU abolishes DST)
* Regulatory changes (e.g. which frequencies the phone may send on)
* A third party service the phone relies on for essential functionality gets shut down
A vulnerability in TLS1.2 would need to be fixed (by implementing TLS1.3) in 7 years under "security patching".
Today, you can often find such new phones on sale, yet already? No security updates. End of support.
So the life of a phone model before you even buy it new, may be years...
Wikipedia indeed no longer supports TLS 1.1, i.e. if the phone didn't receive any updates beyond security updates, it'd be broken.
This seems to have happened around 2019: https://phabricator.wikimedia.org/T238038
I'm honestly surprised, I expected the overlap between "everything new supports this" and "actually turned off" to be bigger.
So realistically, after 5 years without updates, the phone would be a brick. That's still 3 more useful years for people who care about security, and perhaps more importantly, 3 years where people who don't know about the importance of security updates or can't afford to care remain secure. This also assumes no non-security updates at all.
Well, to be fair here, the phone would still be able to make phone calls and send/receive texts, so it would hardly be a brick.
As a practical matter, stuff like supporting a newer version of TLS is at the application, not the OS level, so the user would just have to get an update with their browser to be able to use newer TLS. [1] Supporting newer TLS, for a browser, is little more than recompiling the browser; even stuff like Lynx and newer builds of Dillo have current TLS support.
[1] Windows XP stopped being updated by Microsoft in 2014 [2] but Firefox up until 52.9.0 (2018) runs in Windows XP.
[2] The post-2014 point of sale updates were quite limited in scope, and can not be seen as general OS updates
For the average user who doesn’t know about security, having their phone updated w.r.t. security but having the phone’s built in browser break because it doesn’t work with modern TLS websites would be much better than having them have their phone compromised and critical information given to hackers. They would be able to get a new phone (or download another browser) if they want a modern browser with modern TLS; that’s a very different rodeo than the current situation of “update your phone or have security problems” with phones not even five years old.
On the other hand, nearly every application use the base OS TLS libs and cannot connect anymore to servers that disabled TLS 1.0/1.1 on Android 4.4.
To engineer the app work remotely safely on such vendor-abandoned devices you need to basically assume you're running on a malware or rootkit compromised device, and just hope that by using your self bundled components you'll have better chances to survive in the core wars game because your app is not being specifically targeted.
The lines get blurry. Is a modern browser a feature upgrade or security?
Well, both. But if the vendors really would just sort of fix their old mobile browser, you would still be stuck with a old browser unable to interact with the modern web.
Is it a feature update, that you want to install newer apps? (like another browser)
For this to make sense, it should enable you to update your whole OS of the devicey that it can at least install and update common apps. Otherwise its benefit is very limited.
This is a non-problem nowadays. We have long left the times in which browsers received essential features every few weeks. Using a browser with a feature set from five years ago you can still use all the most-visited websites perfectly fine. At the worst you're unable to use small, non-essential features of some sites. Maybe some ads look less fancy ;-)
Your problem today as a browser user is security against zero-interaction exploits, not missing out on some obscure brand-new CSS features. Security updates are thus what you need first and foremost.
With updates needed.
A modern browser should be a feature upgrade. A browser as modern as the one that came with the device, except without known security issues, should be a required security update.
Coincidentally no one develops the latter without the former, so you get the former, but I don't see that you are entitled to it.
If anything I think the law should be designed such that there's an argument that you are entitled to the version of the browser that came with your device with security updates and without any feature regressions, which is never available today since browsers do choose to remove features on a regular basis.
It's probably not feasible with todays software ecosystem to actually create that constraint... but I still really like the idea.
Often when apps like Facebook are bundled on lower-end Android phones, they are not uninstallable. This means they take internal memory and can't even be moved to SD cards, severely restricting the functionality and durability of those phones. The only way way to fix it is by rooting.
Non-essential or third party apps should be at least un-installable. I'd be ok with a law for that.
But they don't specify an actual period for updates (this will have to be decided by the courts). And, what I find worse, they force the seller to provide the update, not the manufacturer. If the seller is not able to do that (which will be the case most of the time), they can be relieved of their duty.
We're only halfway there.
> they force the seller to provide the update, not the manufacturer.
This (like warranties) is normally because there's no actual relationship between the consumer and the manufacturer. You do enter a contract with the seller, so they can be held liable when the law is broken.
For smartphones this can be different, since they tend to come with EULAs, but not necessarily.
I'm not familiar with the Android world these days, is it still common for mobile carriers to be a bottleneck for updates? If so, it sounds like this could at least be a solution for that.
Some people will argue that this will stifle innovation, because the manufacturers of the latest and greatest won't be incentivized to license their stuff. OK. Essentially I'm describing a bet on openness winning out over proprietary over time.
First one is a very good idea, as older IP law actually holds that interfaces aren't copyrightable. US IP law is schizophrenic on this last point considering the Oracle ruling. E.g. you're free to implement an interface for compatibility.
This is a sad industry-wide mess which should have been fixed long time ago IMO.
It is unfortunately common for an Android device to come with a custom patched 2.x kernel with no plans for 3.x support. Then when a next Android is released it has a hard requirement of 3.x kernel. So no Android update for that SoC/device and no way to port this mess into the newer kernel.
If SoC/peripheral manufacturers only supply "software" as a custom hacked 2.x kernel branch they are basically supplying unfinished PoC-quality un-updatable garbage and such software should have never been released with a production device.
This is non-existent on desktop and laptop space where you often have mainline support for all the essential components.
In my view, one other feasible good step would be to require companies to publish the source code of their phones, ie provide the option for people to download, compile and install the full sw stack. Like this even if manufacturers stop supporting their devices, people can step in and do it. At the very least it would make it easier to support devices than it currently is in third party ROMs
That is definitely not feasible. Vendors are very protective of their code. eg. https://github.com/github/dmca/blob/master/2019/08/2019-08-0...
Representational democracy is supposed to work around the problem of an uninformed electorate. The question should be "if a member of the electorate understood this situation well enough would they care", representatives are supposed to use subject experts to help them answer that question and then use their political expertise to implement laws that move us towards a solution.
It's a big ask, and it doesn't work that well -- politicians often work at what will win them plaudits in the press (or what can be presented as a win, if they control the press), rather than actually doing their job.
Fundamentally though "the electorate doesn't care" is the wrong measure, there are a million things the electorate don't care about but would care about if they had the situation presented to them fully ... we pay representatives and advisors so we don't have to care directly ... that's supposed to be how it works.
Especially if everyone else wanting to play needs to open up as well.
- Release all code necessary for independent developers to provide updates.
- Release updates for 7 years yourself.
Then they can decide what is cheaper for them.
Trying to make those work 2 years later is a huge effort -- probably worth less than just replacing the phones.
Mind you, I agree with you in principle, but I can see how in practice in might all go to shit.
Actually, you do see. The price of your phone would be higher if Qualcomm had to hire competent engineers to make properly designed kernel changes for their hardware.
Or they'll eat that $1 from their profit margins…eh, who am I kidding?
Planned obsolescence is designed to increase TCO
It turns out that getting a bunch of programmers to do careful modifications to some C code base over a couple of months is more work than getting great many thousands of people across multiple companies to manufacture, distribute and sell new hardware to millions of customers.
Why would they? They get paid to put out crap, so they'll continue doing it.
Bottle water continues to come in plastic bottles, even though glass if far cheaper/easier to reuse or recycle. Plastic bottles are literally trash, yet it'll continue being produced if people keep buying it.
Near-disposable phones (both hardware and software) won't stop being manufactured if they continue being in high demand.
SoC makers deliberately do this as a way to force phone manufacturers to buy new chips.
For example, if they release a chipset in 2020, it will ship with Kernel 4.14 (released in 2017). Why ship such an old kernel on brand new hardware you say?
Well Android 11 (also shipped in 2020) supports Kernel 4.14, but you can be pretty sure that Android 12 won't support 4.14. So that means that OEM's can't make android 12 work with that chip without a massive engineering effort (and by the way, a bunch of chipset blobs will be compiled against those kernel headers, so changing kernel versions is pretty much impossible).
So, the main reason to use a deliberately outdated kernel is to prevent last years chips running next years android release, without the chipset manufacturers permission and a share of the profits.
Binary drivers can be reverse engineered and reimplemented for the new kernel. This takes a lot of effort since it requires following a "proper" clean-room methodology when doing so for interoperability purposes, but is otherwise doable. A complementary approach is to forward port the minimum set of features that's required for Android 12 to the older kernel, in a way that carefully preserves the portions of in-kernel ABI that the binary drivers depend on.
I can see why Android was so popular with OEMs!
You can sometimes run 20 year old drivers, assuming same ISA and that none of the ABI has changed, which does in fact happen, just more rarely. Windows 10 is certainly not compatible with 100% of drivers from Windows 7, let alone XP (20 years ago is 2001, so Windows 2000 is actually likely).
You're assuming that it's actually feasible to keep old devices up to date for that long. It may well not be. It gets substantially harder to maintain old branches the further mainline has diverged from them. The original engineering team has typically long since moved on. The magnitude of the issue, here, can be on the scale of "we now need several times as many engineering teams".
This isn't a matter of "security updates would be better than no security updates". This may potentially be a matter of "security updates for four years is economically feasible, security updates for seven years isn't". (I'm not saying it is infeasible, just that it may well be.)
Don't assume that attempting to solve a problem with a law can only have one possible outcome, and can't possibly have a different outcome instead.
And would be great if they had to also provide a free OS, like postmarketos, lineage, Debian or something like that. It could be very rudimentary without a GUI, just drivers for GPS and Wifi. And they would not have to provide even security updates for that. So I would think that many companies would also prefer that.
And… that's it. Just like that, no more updates. Less than two years after I bought it.
Yeah, you're not gonna get baseband / blob / firmware updates or security patches outside of platform, but the damn thing is 8 years old.
It's not like you can just hack updates together yourself. Not always anyway.
Just because security updates stop doesn't mean your device is immediately insecure and cannot be safely used.
The majority of the phone's actual updates come through Google Play Services.
Meanwhile, I can show you an exploit in the wild that affects virtually all iOS devices even though they're regularly patched up: Jailbreak methods and iMessage zero clicks.
I'm not going to argue that iOS is some super secure fortress of impenetrableness, or that Android is some kind of digital petri dish that becomes immediately infected with the 500 Viruses of Bartholomew Cubbins the moment it connects to wifi. But there are Android exploits documented routinely, some of them are serious, and some of them have been found in the wild.
I have a Nubia phone which runs Pie.
Its last security patch is dated August 5th, 2019.
Play Services and Chrome are fully updated.
Where is there an in the wild exploit that you can point me to? Proof of concept or otherwise. I'll happily load it up in Chrome on my phone and let it compromise my system.
Meanwhile there's a zero click iMessage exploit article still on the first page of HN.
Let's ask ourselves this basic question: If Play Services and Chrome could keep an Android Pie system secure, why does Google bother with a separate security patch date?
> Meanwhile there's a zero click iMessage exploit article still on the first page of HN.
Maybe because it's news and critical Android remote exploits are found often enough to not be news.
Then you should have no problem being able to find one that will exploit my phone. I even gave you the specific Android version AND security patch level to target.
Get at it instead of pointing to the sky and saying "look!"
https://www.cvedetails.com/vulnerability-list.php?vendor_id=...
https://source.android.com/security/bulletin
Enjoy your phone. Or don't. None of us are your mom, so we can't tell you what to do.
> Get at it
Abrasive demands are unpleasantly childish. Not being your mom also means that I don't care if you suffer from your own negligence. You can either keep yourself abreast of Android platform security woes or not. As Captain Planet says, the power is yours.
Thanks for proving my point.
Look at Samsung Galaxy S7 Edge - 5 years old device:
- Released with Android 6.0.1. - Received 7.0 and 8.0 major updates. - Has unofficial 11 support. - Received September 2020 security update.
Cheap device manufacturers unable or unwilling to support software updates should be banned by law. It should be a part of their job. Instead, they often seem to release one "proof-of-work" initial release and then don't care and work on the the next model to repeat the same. Pretty sad.
I know that Apple supports its hardware for seven years in California (and not other US states as far as I know) due to state law. I can’t imagine other manufacturers are immune to this same law.
I’m not holding Apple up to be some paragon of virtue, but it was easy for me to find what they write on the subject: https://support.apple.com/en-us/HT201624
This makes devices more expensive? The prices will be higher but the value you get also. I'm talking about companies which uses adhesive strips and unusual screws with tiny buckles (Apple - iPhones) or the ones which glue the display onto the baseboard (Google - Pixel). Or companies which used to provided user-replaceable batteries with notches, which now uses screws inside the device (okay!), but now also a firmware to ensure that the user won't get a replacement battery some years later (Lenovo - ThinkPad). Otherwise Lenovos ThinkPads are good example, step-by-step manuals, explosion diagrams, well maintained replacement-part numbers...and yes, more expensive.
Not everyone values repairability.
10 mm vs 7-8 mm for class leading phones. Maybe the Xcover Pro is rugged enough to use it without a case/sleeve ("Drop-to-concrete resistance from up to 1.5 m"), so it might end up being thinner in practice.
It's definitely thicker. But not double.
Why should the rest of us pay for your preferences?
Why should _we_ pay for _your_ preferences?
Yours is the position of applying state force to make them do something they don't want to - the burden to justify is entirely yours.
A big enough majority of people wants it, anyway, to vote for representatives that write these laws. I'm sure there is a small minority of oppressed Randians who suffer terribly from all of this.
That is the reason why Microsoft was able to dominate the desktop market. Now wonder, the number of professionals on the desktop market is low. Despite the harmful effects of the UNIX-Wars, Linux managed slowly to take leadership of servers, super-computing and some professional devices (Lenovo ThinkPads, Dell Developer Edition).
Naturally some consumer test boards would hint on long term effects and consumers would adapt ("Don't buy car X from Z, it has problems with the engine after 40.000 km.") computing is very fast changing and one bad decision can bound you for years. A large base of Windows users cannot switch, they are not able to switch because they bought sadly hardware from a vendor with not open drivers, or a specially crafted bureaucracy. Of course XMPP existed and was more secure but WhatsApp was more comfortable. And even despite Signal is better, they sheer group pressure is extreme. And your Apple-Music account and all the invested money on the App-Store and your GMAIL-Account...
Interesting enough, if you don't buy the most expensive device you get replaceable batteries. If you buy rough phones ("professional") you get replaceable batteries.
Industry is quite good teaching leymans what the have to buy "blingbling" and then just lock-in the buyers. Of course they would appreciate repair ability - they just don't know it better at time. It actually US which fail to help them before they are in the next trap. Schools now using foreign clouds and Zoom. Holy...why we failed to show them Matrix and Jitsi? Why we didn't improved comfort?
>But as a society, we could value reparability
Only if there is large enough individuals who value reparability.
>And laws are there to enforce what the society values
That laws exist when there is enough individuals to support it.
That is irrelevant to the discussion at hand. Yes, free repairability would be fun, but as everything comes with a cost, values are encoded as trade offs between desirable outcomes, rather than the desirable outcomes themselves. When some desirable outcome is not obtained in society, almost always the reason is that there are other tradeoffs being made. So society values affordability, competition, performance, longevity, quality, repairability, customizability -- and that's just on the product side. Then these product trade offs compete against things like labor market protections, use of resources for competing products, etc.
When Apple decides to solder RAM into the motherboard, it is making a trade off between performance and repairability. When Tesla chooses megacasting that might result in a fender bender totaling your car, they are choosing reliability and lower production costs over repairability. Just bemoaning that some product is less repairable and that society values repairability so therefore some dark force must be working to subvert society's values is not a useful or insightful analytical approach. Everything boils down to tradeoffs.
This would either create a market where companies will sell the license to support old products to other companies, or old hardware and software would finally be able to be supported by the community. There wouldn't be a need to reverse engineer or develop stuff in a "clean room" for fear of litigation.
No, it makes them cheaper by pushing back planned obsolescence.
yea funny story about that. I have a google pixel 3 xl. Was in great condition. No cracks or issues. So I'm in the medellin airport waiting for my flight to Lima when I'm talking to a friend and notice that a crack is forming alongside my phone. To my horror, the battery decided to swell open so far that it cracked open the cell case. Here I am with a phone that as far as I know, is about to shit the bed and I'm in the middle of a foreign country on my way to ANOTHER foreign country with no way of activating a new phone. (google fi requires the phone be in america during activation.)
Luckily in Lima, I was able to track down someone that could doa. replacement. This phone was clearly not designed to be repaired as I saw him slowly melt layers of glues and pull apart different pieces to do the actual battery replacement.
He managed to get it working but now the finger print reader isnt' working. So here I am currently in latin america with a phone that has a cracked case and a broken fingerprint reader. I'm waiting till I can stomach coming back stateside to replace this phone because repairability was never a concern.
The future ought to be something like PinePhone (but with better hardware) that can be customized to run a variety of OS with consumables such as batteries easily user replaceable.
...like apple and its recent focus on services?
Which should incidentally make sense since they'd be still supporting because of the said law anyway.
Another side effect is this may also discourage them from churning pointless new models year after year with minor spec bumps.
They'd never abandon a working business model like that
Indeed they are, but planned obselescence should quite simply be illegal. For sure it'll hurt some businesses, but it's better for everyone else.
Also they're famous for making their products hard to repair. It's hard to find spare parts, hard to find their custom screw heads, and hard to tear everything apart. You can't even remove the battery without tools which is very user-hostile, bad for the environment, AND was a pattern "popularized" by Apple, because if any other hardware manufacturer had dared to do that, they would have sold exactly ZERO phones.
All in all, Apple is close to the worst manufacturer i can think of to get inspiration from, although on specific topics (eg. LCD screen solidity) they are definitely not the worst.
Often it's because of lack of app support, which is in turn because of lack of updates. Of course some people will always want the latest phone, but there are plenty of people that don't, and the second hand market is thriving. This is especially true in countries with lower income levels. I went on a trip to South America a few years ago, and most of the young people seemed to be using iPhone and android phones from top-tier manufacturers, but several generations old.
First, let's remind that LineageOS does not run on 15 year old smartphones (and they drop support for a device when there is no upstream support from vendors on the same Android version).
One issue is that unlike x86/x86_64, there is no generalized abstraction platform (similar to BIOS/UEFI/ACPI description tables) that enables "one kernel to rule them all" i.e. you need some custom adjustments on your kernel for your SoC and board. Since a few years we have device-tree which improves a lot the situation, but I understand it does not cover everything (i.e. there would still be some missing aspects compared to UEFI/ACPI with regards to hardware description. Maybe some embedded experts can comment ?). Besides it is still not always implemented in chipset vendor's BSP which sometimes still rely on board files (where the data is not easy to extract from a binary kernel, noting that a lot of low-end OEMs do not properly comply with GPL and do not publish their sources)...
Nope, they drop support when the community runs into issues with a particular model that it's impractical to fix. Upstream vendor support helps but is not required in any way.
Device tree "doesn't cover everything" because some device components are yet to be supported in the mainline kernel. Once mainline support is added, that enables a 'universal' kernel to provide that support via the device tree.
Windows on Arm devices use UEFI + ACPI, including Windows Phone starting from Windows Phone 8 (2012!). That allowed even the latest releases of Windows 10 Mobile to work on totally unsupported devices (1st gen WP8 devices) when that existed.
It's not an Arm problem, it's that the Android world didn't bother really tackling the problem for a long time.
For ACPI, the vendors themselves tend to avoid changing bindings between generations for Windows there. Compounded with a stable driver ABI, things continued to work stably within all of Windows Phone (NT based, 8.0 to 10)'s lifetime, which had security update support until December 2019.
Windows RT 8.1 still gets security updates today, and will continue to do so until January 2023.
Linux not managing to standardize on a proper driver ABI _or_ stable bindings with the drivers in the kernel tree is just a Linux problem, and doesn't even affect other kernels on the platform, which mandate ACPI or something else.
> There is completely unlike how x86 works where everything really is standardized and you don't need specific drivers operate every peripheral on the board
Nope, on x86, the meaty bits like the GPU and such do not have a stable register interface or anything remotely near that between generations. :)
On Arm systems, the interrupt controller (GICv2/3/4), timer (arch timer, since Cortex-A7/A15), IOMMUs (SMMU) and other standard devices were standardised since ages now (Apple is their own bubble and doesn't apply to this discussion). One of the remaining issues so far is PCIe hardware quirks/erratums, but that's getting solved.
But Qualcomm isn't interested in making their Linux drivers work with their ACPI definitions, they are stable between generations on Windows though, and not changed needlessly over there. (which allowed us to work to bring AArch64 Windows on the Lumia 950/950 XL using drivers from other SoCs too)
Also for what it's worth, Qualcomm does update their ACPI definitions between SoC generations. They also fork their drivers to match. If there was a stable driver ABI they could probably do the same on Linux but that's not an option.
On server, ARM vendors went the PC route and just adopted standard interfaces used servers (pcie, sata, etc). This is large departure from SoCs targeting phones, tablets, and iot.
The biggest concern there is the PEP power management mechanism instead of using what ACPI provides.
> This is because things like buses, storage and display are standardized
That's a rosy view of x86. Quite some laptops ship with Intel RST set up such as stock Windows wouldn't boot on them before adding that driver. Display (frame buffer) is standardised too as UEFI GOP, but that no longer applies when the GPU driver takes over of course. Storage controllers & USB bindings are standardised too.
Doing a Qualcomm driverless boot on those platforms is very much possible, with storage and USB available, enough to install the OS and make it reach the desktop.
(and on a side note, as far back as the Snapdragon 810, PCIe was very much used. The Lumia 950 (XL) had their Wi-Fi controller over a PCIe bus.)
Qualcomm having "stable" bindings is a choice they've made. There is nothing forcing them to do that. The point is that they could not do that, because they know all images built for their phones will be specialized.
Qualcomm may use PCIe for one off peripherals, but it is not the bus used for most peripherals.
You can also get away with ugly hacks and sub par devs. Doesn't matter anyways, you got all the money from selling the SoC, software is an afterthought.
(I do agree to longer enforced support on devices nevertheless)
Basic video is the keyword, on its heyday of GNU/Linux drivers it was capable of OpenGL 4.1 with hardware video decoding, then it got replaced with a driver that does OpenGL 3.3 and that is about it, thankfully the Windows drivers have been kept up to date.
We'd need an open spec SoC for that.
The "Android Enterprise Recommended" program provides "rugged devices" with five years of "90-day security updates". (see: https://static.googleusercontent.com/media/www.android.com/e... )
The Nokia XR20 is one of these devices, it was released in August 2021. However according to https://www.nokia.com/phones/en_int/security-updates it is not guaranteed to receive security updates after August 2025. Something is wrong.
I’d love to see the same thing applied to lightbulbs - instead of throwing away the entire bulb because 1/n leds have failed, be able to replace the failed led. I’ve seen a number of YouTube videos where a guy tears down “burnt out” led bulbs and every time he’ll find a single led that is dead or dying and he’ll bypass it and the bulb works fine. However he usually destroys the plastic bulb piece getting it open - would be great if those screwed or snapped on.
Extending something like this to software and security updates is a promising idea.
For other vendors, that would actually be a feature. It would incentivize hardware manufacturers to stop bundling bad/broken Androids with their hardware, open the bootloader and partner with serious free-software organizations who won't break your system or backdoor it. If you really want to roll out broken software for your customers and not give them a choice, pay up.
For the open source upstreams... I've heard they accept patches. If not, the source is open, the downstream vendors can fix that. They can even put together a pool, pay into it together, and use the pooled money to develop (and hopefully upstream) a patch...
This is what government is for.
Reasonable (security) updates could, for example, include a timely reaction to published vulnerability, A (responsible) disclosure process etc.
Environmentalism and sustainability are the political motivation but are not legally required afaik.
If this legislation starts to get the SOC manufacturers and device manufacturers to play ball, I think it could be a huge win.
But the manufacturers are changing device drivers like the I change my socks. The community can't keep up.
Also, we can't expect the community to thrive when installing a custom OS on phones is relegated to die-hard enthusiasts by manufacturers who constantly make the experience worse.
EDIT: Many of those phones also lose capabilities users might care about by unlocking: playing DRM'd media, using banking apps... That all inhibits OS customisation.
Most people who use phones don't even know what an OS is.
That mentality isn't there with phones, because historically it hasn't been easy to do more than a factory reset. If right-to-repair initiatives make repairing phones a normal thing, that could very well extend to phones in the right environment.
- All devices should come with unlocked bootloader. No exceptions.
- OS updates should be mandated for a certain period. Especially security updates.
- Standardisation: An open standard API for device drivers should be mandated for the hardware components used so that system developers can easily create support for any OS, and don't need to resort to reverse engineering.
- Copyright restrictions on software code should be valid only for a certain period and become public domain (open source) after that. (It should definitely not be 75+ years of copyright that is currently mandated for films and books).
Agree, but I would say it differently : users ought to be able to push their own keys while keeping the "secure boot" feature. e.g. "fastboot key push <key>"...
> An open standard API for device drivers should be mandated
You would also need to convince kernel devs to reconsider the "stable api nonsense" ideology... (https://www.kernel.org/doc/html/latest/process/stable-api-no...)
But what if some software update “bricks” or regresses your device in some way?
I’ve had video games even that have become unusable after software updates.
At least in Norway that causes you to get your device either fixed for free, or you get a new one. Any item you can expect to last at least five years, are covered. So for example, if you have a harddrive die after 4 years, you get a new one.
But android vendors can update the kernel version too, eg once along with android major version upgrade and then stay on LTS updates only, adds up to more than 7 years.
Just looking at the iPhone release list, I we should be doing something like full product support for at least 5 years, full software support for 7 years, security updates for 10 years (iPhone 5 and up).
Then said I’d go further.
Everybody else can ride (Android) Google's coat tails.
Specification and source code for drivers would be even better, but harder to get.
If a vendor supplies bad security updates after six years, I can demand proper updates or perhaps my money back in return for my insecure device.
If the software is open source i may not receive any updates regardless.
If the software is open source, anybody can update it. I use a cellphone from 2012 whose manufacturer abandonned a few years after release. This year alone I got 2 updates for it because I'm running the e.foundation /e/ OS. This wouldn't be possible had AOSP not being open source or its bootloader was locked.
This market exists for more than a decade now, people have had the time to see how it works and how makers behave. It will be nice to always have official commitments (some makers already commit to timelines), but I don’t expect them to be different from the effective support time we already have.
It would be nice if manufacturers had to make them easily replaceable too.
This development has made non-user-replaceable batteries much more bearable.
What's a "sufficient" update?
I can imagine companies just updating whatever models they want to but the older model updates just being cosmetic to save costs.
It would push hardware manufacturers to produce good reliable hardware instead of 10 crappy new phones every year, and to partner with reliable systems developers/vendors instead of pushing their own broken-in-1000-ways Androids.
Also bringing up the original iPhone is a strawman, as that's not going to be supported by this law any more than it is today, newly released phones however are. And since technological progression has slowed down a lot in the last few years that really shouldn't be that hard.
No, but most people also don't need SoCs which performance doubles every 2 years. If the software was properly written and optimised (which would be more common if the firmware developers expected the hardware to have a long lifespan), there would be no reason any phone manufactured in the last 7 years to be sluggish. Anyway most people just want their basic apps to work (e.g. phone, emails, whatsapp, agenda, hotel booking, photos, maps, chat, music player, etc.), none of which should require a very powerful CPU or tons of RAM...
Why? My Nokia N9 is still my daily driver. Only the lack of software updates is making it less and less useful.
Since July, you now have to pay customs & al on goods coming from outside the UE, which wasn't always the case before. But regarding those kind of requirements, would they apply since the seller is not located in Germany (or within the UE) ?
So it seems like new sales would be hit but in favour of second hand phones? That seems like the right thing - more use of products that can be repaired and maintained for longer is good, right?
Poor people de-facto don't have those legal rights, only what the seller is willing to allow.
[1] https://europa.eu/youreurope/citizens/consumers/shopping/gua...
Spare parts, schematics and whatever tooling is required or GTFO.
Probably I'm native, but also wonder, why there is no single manufacturer that offers payed updates after product EOL. Like subscription service, canonical is offering after LTS release is EOL.
Smartphone makers don't sell new phones with a higher price tag and the guarantee of 7 years of software updates, likely because consumers would prefer a lower price and no guarantee.
Thus, the law would effectively force people to buy something that they don't want.
I read this as requiring some software on the device to be updated every now and again for 7 years. I believe most Androids receive updates on the bundled Google apps for approximately that time period.
The article isn't the proposed law, which probably has a more precise requirement.
If it were me, I'd require software updates for devices with known vulnerabilities putting a typical user at risk. And software updates to allow for newer standards compatibility (eg TLS, WiFi protocols, API versions for apps) where typical users are likely to be impacted by not having the new version.
I would start the 7 year countdown from the date that the device disappears from most shops (so exclude specialist eBay stores that allow enthusiasts to buy old devices).