Google Isn’t Fixing Some Old Android Bugs
blogs.wsj.com
blogs.wsj.com
It seems more understandable that way that Google told them to just upgrade to a newer Android version instead.
I bought a Nexus One, and one a half year later it was insecure with no updates. That can never be acceptable. If Debian can ship updates for a five year old distribution, I'm sure Google can. Android is slim by comparison.
This is a real issue and it's Google's platform, they should take action to not leave customers at peril or force them to buy a new device. Google is the only one who has the power to make sure that the updates get all the way to the customers' devices. This might mean exerting pressure on the device manufacturers and operators who make downstream changes to Android.
Otherwise we'll end up with millions of vulnerable devices that could be used (and are currently used) as zombies in botnets.
Google is moving as much stuff out of AOSP and into closed-source Google Apps package as possible for a variety of reasons, not least of which is that it gives them increased leverage over manufacturers by increasing the amount of work they'd have to do to make a forked AOSP device competitive with official Android. This helps them prevent hostile forks as well as enforcing things like updates and not too much mucking around with the UI. This only goes so far, especially when it comes to compelling updates of devices already running obsolete versions.
Both Google and the manufacturers have very little leverage in practice over the carriers, who seem to be the usual stopping block in delaying updates for various unspecified "testing" requirements.
Probably the best thing that could be done overall is Google's already-complete plan to move the web browser, and as much other code as they can, to Play store apps that they can centrally auto-update. But getting that solution onto the vulnerable phones required them to, once again, just upgrade to the newest Android.
I can probably manage to flash it, but the typically phone user probably shouldn't be attempting that. "Just upgrade" is not a valid response when they refuse to push the upgrade to all users.
I have an old Galaxy S3 that Samsung no longer updates, yet these bugs don't effect me because I've replaced the built in browser with Chrome, which still receives regular security updates. What's stopping users of old phones from installing Chrome or Firefox?
Note: I don't.
Wow. How is this even remotely acceptable? I get that they want to focus on the latest and greatest, but leaving 2/3 of your users out in the cold, in 2015's security climate is absolutely insane!
Nevermind the fact that upgrading is a non starter for most users.
This only applies to old devices so the manufacturer sees it as pure cost unless many people get exploited so badly that they will never buy a new model again; similarly the phone carriers only consider this a problem if you leave your contract – and given that the most likely reaction is “Android sucks – I'm buying an iPhone” or “Verizon/AT&T/etc. sucks – I'm switching to the other one” they obviously haven't been feeling much pressure to change.
What we need is a legal fix to avoid them punting the costs onto customers: e.g. not shipping security updates within, say, two months requires the carrier has to unlock your phone and release any remaining contract without penalty. Unless it affects revenue, they're going to continue to treat support as a cost-minimization exercise.
It would seem that's not made OEMs/Carries feel the need to update them.
The manufacturers can't insist that google support older versions with proper patch releases for bugs like this, because they aren't paying for it.
On the other hand, google really can't expect to drive the manufacturers test & release cycles. I expect that even a minor release is an expensive testing effort on their part, so they are understandably reluctant to do this off cycle.
I think this is the point of some of google's recent changes, but it's unclear how well that will work in practice.
If Google takes credit for those phones and stamps its logo of approval on the phone, they need to take the blame for the consequences.
This is one reason the latest Android releases don't have a 'Browser' app and have Chrome as the default (as they should). Granted, some manufacturers probably still have 'browser' because they want more control over their users.
(this was also true in 4.4, except that the 4.4 webview doesn't receive updates other than via a full system update)
The biggest problem Google is facing regarding that is the fact that essentially every OEM creates its own "distro" of Android, which makes it very hard for Google to fix everything. Some of the bugs could be in software of those OEMs.
I think Google should build-in deeper customization frameworks that allows OEMs to customize the OS quite a lot, while still doing it in a "standardized way" that would allow Google to fix the problems.
In a way Google chose this. They could've done what they did with ChromeOS - make Chromium OS open source, but only promote Chrome OS, which is why all OEMs choose the proprietary Google version instead of the open source one. That's how Android should've worked as well. But they probably thought of this too late.
When people talk about Android updates that can include several things:
- Launchers
- Apps (e.g. Camera, Browser, Calculator, and so on)
- Operating system components (services, drivers, etc)
- Linux kernel
A normal Android update has the ability to update all of the above. However most of the user-impacting and security impacting issues are at the "apps" level (since Android apps are largely isolated from the underlying OS via a Java-like VM).
So what Google have been doing is leaving the Kernel and OS components to the OEMs and providing app updates via the Play Store even onto older devices. So now on the Play Store we have:
- Chrome (replaces Browser)
- Google Services (updates a large chunk of APIs)
- Google Search (more APIs, Google Now, and so on)
- Google Voice (more APis, etc)
- Google Keyboard (built in keyboard)
- Gmail (will replace email eventually)
- Google Launcher
- Google Calendar
- Google Camera
- Google Talkback, Text-To-Speech (accessibility)
- Google+ (replaces SMS Messenger)
And so on...
The proper solution would be to put the AOSP version on the store, but keep it open.
Also Google Play Frameworks should be split in the AOSP parts of their libs and the few actually closed parts.
It would have the same effect as the Google Apps in the store, without losing AOSP.
(See e.g. http://arstechnica.com/gadgets/2013/09/balky-carriers-and-sl...)
http://developer.android.com/about/versions/lollipop.html#We...
http://ruby-journal.com/how-to-block-old-ie-version-with-rai...
It's in pretty much everyone's best interests to make those devices as non-functional as possible as fast as possible.
It's a non-issue, as with other bugs Google recently closed as NTBF.
I have an Android phone that works perfectly well and is paid for; I don't have money to burn to buy a new phone. I got it after I bought a Windows 7 computer - which will likely be updated for many years to come. When purchsed, the phone cost almost as much as my computer did. However ... the phone is running version 2.3.3 and can not be upgraded (and has not been updated for a few years now). And most new apps do not support this Android version (and have not for a few years now) so I have given up on visiting the Google Play store. My wife has an identical phone and has not bothered either trying to get new apps for a few years now.
It's a "non-issue" only because Google (which I generally support) has a shitty policy when it comes to supporting old versions of their products.
That leaves you among the small percentage who are in the Google ecosystem, but running an old version of Android. perhaps it was Google fault for OK'ing Google logo devices with trailing-edge OS versions when you bought your phone. But they've fixed that now with Android One and the inexpensive Moto phone.
And, on top of that, if you really want a newer version of Android without buying a new phone, there's a decent chance that CyanogenMod or other aftermarket releases support your device. Google has never stopped anyone from "bootlegging" the Google ecosystem into such configurations.
https://code.google.com/p/android/issues/detail?id=39548
I don't really understand how this has slipped through the cracks; Google has a decent number of MacBooks in their offices last time I was there, so maybe copying files just isn't popular? Either way, it's a pain that the tool is closed source and the maintainer won't maintain it.
that's all they care about, you paying them.