> while offering just three years of security updates, after which you basically have to throw the thing away
Nope, you don't.
It's just that somehow techies seem to have gotten this meme into their heads that an unpatched life isn't worth living. Can't update my phone within 1 microsecond of a patch being released? I guess I might as well just die. Much safer than risking the << 1% chance of getting malware on it, and everyone knows malware is worse than hell.
> The repairability sounds nice, but it is very irrelevant compared to the limited software updates.
I had an Android phone that didn't have OS updates for several years and... it was just fine. I was only forced to finally upgrade to get better reception on other bands it didn't support. If the hardware could keep pace I would've easily kept it with its current OS for another half decade, until apps just got so bloated that I couldn't use it anymore.
> Imagine buying a Windows laptop and only receiving three years of security updates
That's a bad analogy for so many reasons. Android's security is WAY more hardened than Windows's, your phone's apps (including your [likely] Chrome browser) would still get security updates, and even with Windows this isn't as horrifying as you're suggesting. (I've done much worse.)
I build Android apps for a living. Let me tell you, the majority of users are on "outdated" OS versions. You have to support 5-7 years of Android releases to cover a substantial part of the Android user base. The app I'm currently working on requires a minimum version of 6.0 — this came out in 2015. I still test my apps on a Nexus 5.
Many people would buy a phone that will never receive a single update. The software it came with is the only software it'll ever run. And they're fine with that. They see software updates as an annoyance and I fully understand them.
I you look at that data then you can see that the oldest version with any significant usage is v8.1. But even that is quite low, and you might do quite well in not supporting anything older than v9.0.
What management? I decide this kind of thing myself in that project. The app is open-source and for a nonprofit. I don't see much reasoning to drop Android versions above 6.0 because there aren't that many API changes that would make a difference for my case. It's not like supporting 4.x or 2.x, the "you gotta carry the reimplementation of a substantial part of the UI framework with your app" kind of annoyance. The app in question doesn't even use appcompat. The apk is around 3 megabytes.
> Tell your management that usage of v6.0 is as good as gone, and you are wasting resources in doing any work to keep support for it
How do you say this without any knowledge whatsoever about the type of app they work on, or their target audience? v6.0 alone is almost 2% of users based on that chart. In fact if you include everything before v8.1, you seem to get something like 8% of users. What if their app, say, provides the poorest people access to public transportation? Would you really just drop 8% of people on the floor in any scenario?
Exactly this. Even if your demographic is the same as the chart, dropping 2% of users can be the difference between profit and destruction. Maybe it's margins that you'll save but keeping those users, possibly bad reviews, maybe market share over a competitor, there's plenty of reasons supporting older versions is not a definitive "waste."
Is it a pain to support old SDKs? Yep. But that doesn't make it inherently a waste of time to do so.
You have to weigh in the quality improvement of the app that you can provide by not limiting yourself to old apis, and also the resources that you can spend on improvement now that you aren't spending as much effort doing support for old versions.
>> Can't update my phone within 1 microsecond of a patch being released? I guess I might as well just die. Much safer than risking the << 1% chance of getting malware on it, and everyone knows malware is worse than hell.
Malware can indeed be worse than hell. Have you ever had your bank account hacked? Or your email account broken into? Or your identity stolen and had to deal with dozens of credit cards being registered and then hit the limit under your name?
I’ve had friends (and family) deal with such things, and you know what? I’ll do anything to minimize the risk for myself, including throwing away an expensive gadget that can no longer receive updates for some totally arbitrary reason.
> Malware can indeed be worse than hell. Have you ever had your bank account hacked? Or your email account broken into? Or your identity stolen and had to deal with dozens of credit cards being registered and then hit the limit under your name?
To be honest - as an older-phone user, that's part of why I never access email on my phone, nor my bank account. I see my phone as something that's basically insecure, and take into account (no pun intended) the possibility that other people will be able to access its contents.
I realize, though, that many old phone users don't hold this view necessarily.
My phone has a large amount of software written and installed by Google and by Xiaomi, both of which I absolutely don't trust; and it also has software which I do trust - but trust to spy on me, like Meta's WhatsApp...
> Malware can indeed be worse than hell. Have you ever had your bank account hacked? Or your email account broken into? Or your identity stolen [...]
I've never been to hell (I think?)... I suppose I can't assume you're the same, but I'm pretty confident I would much rather deal with, say, a stolen identity, than go to hell.
Most people's risk-tolerances including many life-threatening dangers they face on a daily basis... like getting hit while jaywalking, having their phone igniting in their hands and burning their homes down, dying in an earthquake, etc. If you can't tolerate the same risks as most other people, then great, you have lots of alternative options to choose from. It's not like Nokia is preventing you from imposing your will on yourself or your family.
> It's just that somehow techies seem to have gotten this meme into their heads that an unpatched life isn't worth living.
Do you wish to hear the endless stream of CVE numbers that allow remote exploitation, including Wi-Fi and Bluetooth module vulnerabilities that don't even require an active Internet connection?
Have you ever tried to expose a new server to the Internet and watched the endless barrage of probing requests coming seemingly within seconds?
Have you been a target of DDoS coming from unpatched appliances and modems?
The only place for an unpatched phone is offline, within Farady cage.
Well, I agree partly. I'm also on a phone which doesn't receive security updates anymore. I don't know how risky that is. However, it seems clear that longer security updates are much more desirable than increased repairability. Most people won't need to repair their phone, apart from changing the battery after a few years. Especially not when it is a cheap phone anyway, where any repair cost is likely higher than a new phone would be. So a device with longer security updates seems still better than this increased repairability.
Nope, you don't.
It's just that somehow techies seem to have gotten this meme into their heads that an unpatched life isn't worth living. Can't update my phone within 1 microsecond of a patch being released? I guess I might as well just die. Much safer than risking the << 1% chance of getting malware on it, and everyone knows malware is worse than hell.
> The repairability sounds nice, but it is very irrelevant compared to the limited software updates.
I had an Android phone that didn't have OS updates for several years and... it was just fine. I was only forced to finally upgrade to get better reception on other bands it didn't support. If the hardware could keep pace I would've easily kept it with its current OS for another half decade, until apps just got so bloated that I couldn't use it anymore.
> Imagine buying a Windows laptop and only receiving three years of security updates
That's a bad analogy for so many reasons. Android's security is WAY more hardened than Windows's, your phone's apps (including your [likely] Chrome browser) would still get security updates, and even with Windows this isn't as horrifying as you're suggesting. (I've done much worse.)