Spending €100 to fix a €399 Poco sounds like a very bad deal. I hope prices on budget- midrange Android phones don't go up with these new regulations.
Spending €100 to fix a €399 Poco sounds like a very bad deal. I hope prices on budget- midrange Android phones don't go up with these new regulations.
You can buy a €400 used iPhone and get updates for longer than most brand new Android phones. And by the time that used iPhone stops getting updates, you'll still be able to sell it for some non-zero value, while that budget phone will be worthless and destined to be e-waste.
Comparing LineageOS to actual first party support when the SoC manufacturer has long forgotten your device exists isn't really realistic: you're getting updates in name only. The blobs that run the most important things are frozen in time.
-
Not to mention, if you're willing to put up with that level of limitation, you can get a brand new iPhone SE for $150 too. It'll be locked to a carrier, but that's a lot less limiting than "literally never going to have a meaningful update again"
If I'm running an outdated Android version, my threat model basically can't include any internet or cell connectivity, since an outdated media parser means a bad web page or media message and my phone is the attacker's playground. But an outdated baseband firmware means what, I have to watch out for ne'er-do-wells dodging the FCC with high powered SDRs in my neighborhood who know what model of phone I'm using? In a better world, Lineage could feasibly ship updates for every component, but as far as I can see, one of these is a lot more important than the other, and it's the one LineageOS does take care of.
VPU: https://www.cvedetails.com/cve/CVE-2021-0346/
DSP: https://nvd.nist.gov/vuln/detail/cve-2022-27834
The SoC has a lot more binary blobs than a baseband firmware. It's one thing if the alternative was living like a hermit, but no, the alternative is not supporting an ecosystem predicated on SoC vendors abandoning your advice because it's in their best interest for you to buy a new one.
Android for personal use is a complete non-starter for me today, it's a terrible ecosystem driven on waste with fundamental flaws that will never get fixed because of a misalignment of interests.
Even if you arbitrarily decide only RCEs matter, there's again a lot of binary blobs in a modern device and more importantly they do a lot more than you seem to think.
I'm not sure why Stagefright is your synecdoche for RCE when just a few months ago we got a set of CVEs that made it look like child's play. It turns out your device being exploited via baseband doesn't take SDRs, your baseband today is involved in MMS too:
https://googleprojectzero.blogspot.com/2023/03/multiple-inte...
>they do a lot more than you seem to think.
I do mobile security research, I am well aware of what these devices do. The reason I cite stagefright vulnerabilities as an example is because stagefright is a library that has continued to have vulnerabilities well past the original set you're probably thinking I'm referring to, and vulnerabilities that we have seen exploited in practice. Are there any known worms exploiting the project zero bug you've linked? Because at least from what I've come across, an updated LineageOS install only running apps from F-Droid would not be vulnerable to any non-targeted attack in the wild I've heard of. (Not a rhetorical question, to be clear, it's entirely possible I missed something, and I would love to know more if my understanding it out of date.)