I bought a Nexus One, and one a half year later it was insecure with no updates. That can never be acceptable. If Debian can ship updates for a five year old distribution, I'm sure Google can. Android is slim by comparison.
I bought a Nexus One, and one a half year later it was insecure with no updates. That can never be acceptable. If Debian can ship updates for a five year old distribution, I'm sure Google can. Android is slim by comparison.
This is a real issue and it's Google's platform, they should take action to not leave customers at peril or force them to buy a new device. Google is the only one who has the power to make sure that the updates get all the way to the customers' devices. This might mean exerting pressure on the device manufacturers and operators who make downstream changes to Android.
Otherwise we'll end up with millions of vulnerable devices that could be used (and are currently used) as zombies in botnets.
Google is moving as much stuff out of AOSP and into closed-source Google Apps package as possible for a variety of reasons, not least of which is that it gives them increased leverage over manufacturers by increasing the amount of work they'd have to do to make a forked AOSP device competitive with official Android. This helps them prevent hostile forks as well as enforcing things like updates and not too much mucking around with the UI. This only goes so far, especially when it comes to compelling updates of devices already running obsolete versions.
Both Google and the manufacturers have very little leverage in practice over the carriers, who seem to be the usual stopping block in delaying updates for various unspecified "testing" requirements.