Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Security updates: 3 years of monthly security updates

That is such a let-down! If Nokia is serious about sustainability, it needs to make it 5y+.

I get it, it is not easy. But with the proliferation of malware and exploits, after 3y (since release, not purchase) this phone is nothing but a liability.



That just refers to the security updates that require a full firmware update. I think people get focussed on that because they’re used to the iPhone where that’s only way to fix security issues. On android, the majority of security issues are patched immediately and silently through the play store, so that continues pretty much for the life of the phone.

In other words, updates are much less important on android than they are on the iPhone.


Here's the security bulletin for January: https://source.android.com/docs/security/bulletin/2023-01-01

How do I determine which, if any, of these is fixed via the Play store update mechanism?


The bulletin specifies only CVE-2023-20912 as being fixed by Play Store. https://source.android.com/docs/security/bulletin/2023-01-01...


I'm puzzled ... I can understand why the BLE drivers would still require a firmware update (and that is fine since drivers for older hardware shouldn't be much of a problem), but why wouldn't all of the Framework vulnerabilities be handled via Play Store updates. I believe that all of the Framework is updatable in this way. Perhaps it's because that is not true of Android 10 so they need to address it in a firmware update anyway?


Wow. So "the majority of security issues are patched immediately and silently through the play store" seems catastrophically incorrect.


Well, yes, I have to agree. See the other comment I just posted. My understanding is that they are at the point (at least now with Android 13, which is what the Nokia will presumably ship with) that they can update most of userland (and even graphics drivers though that requires vendor participation), so they should be able to address Framework vulnerabilities, which is the critical discrepancy here.


> so that continues pretty much for the life of the phone.

I'm on a Pixel 1 with Android 10. Last security update it got was from October 2019 which is about three years after the phone was introduced.

Is this supposed to be different on newer Android versions?


That refers to the formal (full firmware) updates, I'm talking about security updates that get pushed to the phone without you having to do anything.

It started with the browser component many years ago, and has grown its coverage with each version. The limitations are mainly in the kernel, but they now even do graphics drivers this way (though that requires vendor cooperation, unlike everything else), but you wouldn't have that with Android 10.

This capability has steadily grown to cover more of the OS over time, particularly recently, so unfortunately, Yes, Android 10 does have much less of this ability then later versions.


> That refers to the formal (full firmware) updates, I'm talking about security updates that get pushed to the phone without you having to do anything.

It is called "Android security patch level", that is not a full firmware update. It may still be something else than you have in mind, though. (How) can I check the patch level of the security updates you are relating to?


My understanding of this capability is that it started with the browser component and grew from there, suggesting that it happens automatically and there is nothing you need to check. But someone has pointed out that all the Framework vulnerabilities are still listed as being addressed by full, old-fashioned security updates, so I must admit that there is something I'm missing here.


It isn’t. The situation is so dire on Android right now


Never had an iPhone.

I don’t know what comes through Play Store, only thing it tells me is that specific app was updated.

All I know is that my cell phone vendors tells I am not getting more security updates.

Consumers should not understand CVEs to feel safe.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: