200$ laptops can be updated without interaction with the manufacturer, there's no reason phones cannot be the same.
But I of course agree with the overall point, that no interaction with the company should be necessary just to update the OS.
As far as I know, Pixels are the only ones that allow resigning the boot loader chain with your own OS though :/
This prevents all kinds of attacks where people could push things onto your phones OS. In desktop world, this is known as "secure boot".
Many devices will, however, only accept OS signed by their manufacturer - e.g. Apple iPhones/iPads will only boot an OS signed by Apple and noone else. This is why you can't ever run Linux on an iPhone or iPad.
In Android world, many manufacturers allow users to disable this verification (known as "bootloader unlock"). This allows running of non-manufacturer provided OSes (e.g. LineageOS, GrapheneOS, etc.). However, except for Pixels, they don't allow you to supply your own signing key to the bootloader, so you lose the security benefits of the secure boot chain and open yourself to big set of security attacks against your phone.
On a Pixel (at least some of them), you can provide your own signing key and reenable secure boot when installing another OS.
Link to the original announcement: https://calyxos.org/news/2022/04/01/fairphone4-oneplus8t-one...
Link to the feature removal by OnePlus: https://calyxos.org/news/2022/07/06/oneplus-android-12-reloc...
Curiously enough this feature does seem to available for the fairphone 4 too!
GrapheneOS never tried implementing this for OnePlus or FairPhone because it's not the only reason they stick with Pixels. The Titan security chip offers other benefits they want.
Not with a kernel that wasn't provided by the manufacturer you can't. This massively constrains your options. I can pull a Debian or Ubuntu image off their website and install it on any old laptop, but for phones you need an image specifically tailored to each device, and it'll only get kernel updates as long as the manufacturer continues to provide them since they're all bespoke kernel forks per-device.
You see it with a lot of user-facing FOSS as well, like Thunderbird. The recent post about its latest update was full of people shitting on it over, in many cases, fairly trivial details.
Creating stuff that is usable, sustainable, ethical and affordable is very difficult and involves making hard compromises. It's always good to see people trying to do it and depressing when all they get is hate.
You cannot fight against planned obsolescence while supporting the same companies that enable it (Qualcomm with their proprietary drivers tied to ancient Linux kernels). The real solution is GNU/Linux phones relying on FLOSS drivers, which will receive lifetime updates. More details: https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque....
Samsung or Google could support their device for 10 years, they just don't care because their financial incentive skews toward selling new devices. Which I suppose is part of reasoning for picking a Fairphone, you get use your device for longer, wasting fewer resources.
I don't have estimates, but I think it's safe to estimate that there are millions of otherwise perfectly valid phones that either are in use, with serious vulnerabilities (in particular, bluetooth ones) and are not going to be patched, or have been thrown away because of that.
Sure, if most drivers were open source like on desktop linux we could tweak them to work with newer and newer Android versions, but what happens when AOSP gets a computationally expensive update (i.e. embedded ML voice recognition or realistic TTS)? then you would have to create custom versions of AOSP that only have the stuff a particular phone model can handle and this would create and unbareable ecosystem of poorly maintained distributions
You disable those features on lower-spec phones or fall back to a low-resource alternative. If I'm on an older device that can only run eSpeak instead of a more realistic but expensive TTS engine? Fine, I'll run eSpeak! You don't have to bundle everything together into an image for each device. If you want to disable stuff, do it at runtime.
Or if you really need to remove stuff due to storage limitations, have a small manifest that can be used to build an image with unused things excluded. This doesn't have to be "oh we need to make completely custom versions of the OS for each device", this is basically "install these packages, don't install these ones". Modularity!
Most of the vulnerabilities require you to be loading sketchy apps, many of these are checked on Play Store by scanners, so unless you get very unlucky or sideload sketchy apps, probably not a concern. Web view and most other network exposed components are updated from play store, since stagefright they sandboxed all codecs, etc.
It's really not that bad for a typical user to just run an unpatched phone, certainly better than a Windows machine with local admin where downloading and running one executable is all it takes. At least on an unpatched Android device they get some level of sandboxing.
There have been large set of attacks against modems and media decoders that do not require any kind of app installation. iMessage is a constant source of iOS CVEs. Media codecs are a constant source of headaches in the Android world as well and they require a driver update to fix (since most of them are HW decoders).
Pretty much all of the big security issues in the last year required no user interaction on Android or iOS to exploit.
In addition to the sibling post, Bluetooth is another attack vector.
A phone I had to abandon in the past was a Nexus 5X, which I believe has a set of very serious Bluetooth bugs. I don't remember the details, but they were very easily exploitable (as in: either doing nothing, or just keeping the BT menu in the foreground, which is a common operation).
Regular security updates are no longer a nice to have. They're a must. If a company can't provide that they have no business making phones.
Having said that it does look indeed like they've upped their game with the FP4 a lot.
It's not that difficult