For Lineage OS, they maintain the kernels released by the vendors and backport patches to them. But this often means that the backports only address the publicized CVEs and might gloss over a lot of changes between kernel versions that might not have had famous bugfixes. A lot of patches don't end up in a kernel, and often while the version number reads of that of a modern kernel, only a small percentage of the patches in that kernel release was applied compared to the upstream kernel. For this it's important to note that the kernel doesn't have a clean separation between "bugfix" and "CVE fix" for patches, this is already a problem that their officially maintained LTS versions have.
From the security point of view you are definitely better off than staying on something that's unpatched, but I have to mirror what parker_mountain is saying. It's way _way_ better to just get an iPhone as that also gives you modem security updates for half a decade. I am really unhappy about the lack of freedom these devices give me, but I have switched to an SE one year ago. It's just such an incredibly good TCO for really good security.
LineageOS has improved a lot over the years, and Android 12 (10+ with GSI images) finally has a working OTA update workflow.
But honestly, the "Android is not Android" problem is hard to communicate and endusers have so many pitfalls.
If you tell them "oh yeah I actually use RethinkDNS as an adblocker, combined with Fennec via F-Droid and its uBlock Origin extension that only somewhat works on mobile due to their messy UI" then you lost already 99% of users that will never figure out how to flash their device with the custom ROM, let alone understand what you just said.
It's so sad that you also have to tell them "but use only one of maybe 10 devices, all other Android devices are either totally outdated with their kernel or cannot be supported anymore"... and when I read your comment I kind of have to agree with your point.
iPhones have zero maintenance. It's a golden cage but it's a well built one, and most users just don't want to spend days and weeks learning how to maintain their smartphone.
Also, I thought I recognised your username. I use at least one of your crates. Thanks for those, too! :)
Good security when you cannot turn WiFi and mobile data off because it has to talk to mothership ?
However, DivestOS might be very different from the stock OS from Google. You might consider using LineageOS with Google Apps (MindTheGapps) if so.
* https://divestos.org/pages/devices#device-walleye
Your threat model might be different but I don't get out of bed for anything but RCE personally, let alone spend a penny.
For sure, if you're paranoid or a high-value target, update, buy a new phone. But normal users don't need to care unless there's actually something on the line.
https://twitter.com/maddiestone/status/1395004346996248586
Not sure what to say about encouraging users to throw caution to the wind. We got to this point of such good exploit mitigation because it's good for everyone for these devices to be secured.
An average user installing apps from Play Store has nothing to worry about for those. That's kind of the point.
It's great for these devices to be patched - I'd love it if Google would take more control over the ecosystem to be able to patch this sort of thing, but it's much worse for users to just throw out otherwise working devices with limited-to-no real-world security issues.
If you can use Windows without it getting full of malware, you can handle unpatched Android LPEs too.
Keep in mind, Webview, browsers, email clients, etc are patched via app update mechanisms.
Yes, this is still a risk - if you tend to install random apks from the internet and disable Play Protect or run across an undetected modification of the relevant exploit code. But most users don't do that.
Personally I have never seen any friends or relatives get malware on their phone that gets outside the app sandbox (ie. Uninstalling the bad app seems to solve the issue). Compare that to MS Windows where it seems common for regular users to have malware infested systems.
It bums me out that them doing this hasn’t been effective in shaming everyone else into following suit.
Just like if your lawnmower exploded with a known flaw, you would sue the lawnmower manufacturer.
Plenty of apps and networking in Europe and Asia.
I wonder if Apple views the "iPod" branding as being more associated with gaming and consumption and therefore less important from a security standpoint. I don't think I necessarily would agree with such a stance when the exact same hardware can carry sensitive stuff like a password manager, banking and medical apps, and so-on. But I imagine their telemetry showed that that overwhelmingly wasn't the case, so it was easy not to prioritize it.
Even after official support completely ends, Apple tends to go back and issue patches for active exploits. The nine year old iPhone 5s just got another security update a couple of months ago.
It was released May 2019, and it just received its latest security update (15.7.3) January 23, 2023. Presumably that is not the last security update for iOS 15.
I’m not aware that Android gets anything like this, even in the era of Google Play Services.
(Yes, I know: get a better ad blocker, etc. — I'd rather have fewer weak links, though, and a lack of basic OS updates is a pretty big weak link.)
With the state of software development today, I'd be more worried about how many other holes they've added in the process of fixing something or introducing unwanted new "features"[1].
Here's some interesting statistics to look at and compare...
https://www.cvedetails.com/product/462/Microsoft-Windows-98s... - 30 RCEs in 7 years
https://www.cvedetails.com/product/739/Microsoft-Windows-Xp.... - 276 RCEs in 20 years
https://www.cvedetails.com/product/32238/Microsoft-Windows-1... - 664 RCEs in 8 years
https://www.cvedetails.com/product/102217/Microsoft-Windows-... - 157 RCEs in 2 years
More relevantly:
https://www.cvedetails.com/version-list/1224/19997/1/Google-...
However that ignores the fact that publicly known exploits are more dangerous for the average user than zerodays.
Well, I'm not. If he wants to daily drive Windows 98 because it had fewer documented RCE vulns, godspeed to him---and he probably will be more secure, just by virtue of good ol' security through obscurity---but that is not a reasonable solution for 99.999howevermanyninesyouwant% of computer users today.
The rate of finding exploits and what the definition of a vulnerability is really what has changed - now the definition of is much broader while at the same time, exploitability has dropped off due to mitigation in modern operating systems, compilers and CPUs. Overall, we get far more exploits, but far less of significance.
Sure, I have to take some responsibility for poor digital hygiene or whatever, but I don't think that negates Google's awful management of this. I shouldn't _have_ to be vigilant/proactive to stay safe in something as basic as this.
Aside: Google spams me with all kinds of noise in notifications these days; couldn't they at very least put something in there saying "by the way, your device is now EOL; buy a new one"? Ockham's razor suggests to me that a _lot_ of people are running unsupported devices still, and Google doesn't want the collective backlash of putting that uncomfortable reality in people's faces.
That's not really the same thing as "updates for at least 5 years". The date the device first went on sale in the US isn't particularly relevant. They'll still sell it to you long after that, and then end support not long after it's out of warranty. That's what happened to mine.
The lessons I'm learning here (if I'm running a first party OS) are:
- Check very carefully how long different vendors actually support their devices. Google is pretty rubbish on this front, it turns out.
- Always buy the latest model when buying a new phone, even if it doesn't have anything I need, or I'll just have to "upgrade" twice as frequently instead.
[1] https://www.cnet.com/tech/mobile/iphone-se-4-reportedly-back...
but.. their old phone is still operating fine, it isn't even affected by the Samsung modem exploit, and best-of-all the pixel 2 is well supported by many third-party Android roms.
Parent literally has one of the best supported older phones available for third party OS installation (which, incidentally, is what parent was asking about..)
so, in the interest of e-waste/recycling/keeping old things going I hope they reconsider the value of their already-owned hardware and how it may still continue to serve them.
>so, in the interest of e-waste/recycling/keeping old things going I hope they reconsider the value of their already-owned hardware and how it may still continue to serve them.
In the interest of security, both theirs and the people they communicate with, I hope they consider upgrading their device to something that has a very long lifespan of active security updates.
Every year I'm more disappointed by Google on pretty much every front. They really do seem to have jumped the shark.
If I do decide to upgrade...
Unfortunately I can't stand iOS. No kidding, I'd rather have a Nokia 5110. I've tried repeatedly, thinking "I'm just not used to it", but there's too much about the design philosophy that I find actively obnoxious. Strangely, I don't have this problem with macOS.
Maybe I can find another Android vendor with a better support policy, or if none of them are any good then just suck it up and buy the very newest of whatever to at least push the planned death of my device back a couple more years.
I'm getting a bit sick of this treadmill. I don't buy the defence some people offer that it's too much work to support the older devices. Having a security-only backports release series for old devices would be _trivial_ compared to the enormous piles of money Google sets on fire for shits and giggles on a daily basis. It's planned obsolescence, plain and simple.
That's how i feel with iOS and macOS, the whole design philosophy and UX feel alien to me, and makes me hate every actual issue I encounter even more.
> I'm getting a bit sick of this treadmill. I don't buy the defence some people offer that it's too much work to support the older devices. Having a security-only backports release series for old devices would be _trivial_ compared to the enormous piles of money Google sets on fire for shits and giggles on a daily basis. It's planned obsolescence, plain and simple.
From what I've understood, it's mostly the hardware components' vendors' fault - Qualcomm and co that provide the SoC and modem. It's their firmware which isn't kept up to date by the manufacturer (because it isn't easy to do so), thus phone lifecycle is inherently limites. There have been massive recent advances in that area though, with on one hand more vendors (MediaTek, Samsung) that could maybe be forced to compete and thus have to differentiate from one another, but also big changes to Android and the way updates are done, to keep firmware/driver/kernel updates as simple as possible to develop and roll out. We can see the effects with multiple Android vendors (e.g. Google, Samsung) now supporting phones for much longer. So hopefully soon things will improve.