zlacker

[parent] [thread] 11 comments
1. j4hduf+(OP)[view] [source] 2025-08-26 14:35:10
It is not so simple!

Play Integrity's highest level of attestation features requires devices to be running a security update which is within a sliding window of 1 year.

LOTS of Android devices have not released a security update in many many years. This forces users to unnecessarily upgrade to higher end OEMs.

Google is effectively pushing out Xiaomi, Huawei, and many others that offer excellent budget options. Google is not just offering you the comfort of not having to fill out CAPTCHAs on your phone, most importantly they are playing monopoly.

replies(1): >>fnimic+W2
2. fnimic+W2[view] [source] 2025-08-26 14:47:06
>>j4hduf+(OP)
Why can't "low end OEMs" release security updates?
replies(2): >>devmor+8b >>donkey+Zj2
◧◩
3. devmor+8b[view] [source] [discussion] 2025-08-26 15:18:55
>>fnimic+W2
They can, it would likely just increase the cost of cheap devices to end users, as the manufacturer now has to provide additional software support and does not want to lose money.
replies(2): >>dabock+Gn >>donkey+9k2
◧◩◪
4. dabock+Gn[view] [source] [discussion] 2025-08-26 16:15:53
>>devmor+8b
One could argue that those “cheap” devices are ewaste from the beginning, and customers needing lower cost mobile devices should be buying more expensive ones used or refurbished.
◧◩
5. donkey+Zj2[view] [source] [discussion] 2025-08-27 06:24:17
>>fnimic+W2
Because they fucking suck. I never heard desktops or laptops being tied to Dell or Asus or what not for run of the mill kernel or os upgrades. If phone makers want to be fucking ass by locking down bootloaders, jealously preventing reversing etc preventing kernel devs etc from doing their own thing then they should accept the just label of being fucking ass or take on the responsibility of supporting it forever.
◧◩◪
6. donkey+9k2[view] [source] [discussion] 2025-08-27 06:26:15
>>devmor+8b
Why does the manufacturer of the phone have to write os upgrades?

I never had to wait on Dell to type apt update and apt upgrade.

replies(1): >>devmor+ri3
◧◩◪◨
7. devmor+ri3[view] [source] [discussion] 2025-08-27 13:58:42
>>donkey+9k2
Because when you buy most smartphones, you're buying a vendor locked device and choosing to stay within their ecosystem. That's how Google has designed their monopoly. Apple is the same way, but non-fragmented.

You've never had to wait for Dell to type apt update and apt upgrade, but MacOS users have to wait for Apple to update their computer.

replies(1): >>donkey+ks3
◧◩◪◨⬒
8. donkey+ks3[view] [source] [discussion] 2025-08-27 14:43:16
>>devmor+ri3
That was my point, this is a self created problem by the manufacturer.
replies(2): >>devmor+uG3 >>j4hduf+ZH3
◧◩◪◨⬒⬓
9. devmor+uG3[view] [source] [discussion] 2025-08-27 15:49:18
>>donkey+ks3
No, it's a prerequisite to doing business.

The OEM phones are cheap because the manufacturer sells them at a loss, recouping money by locking them down and pre-installing certain software.

The alternative is that Google is properly regulated, or cheap smartphones phones don't exist.

replies(1): >>donkey+ih4
◧◩◪◨⬒⬓
10. j4hduf+ZH3[view] [source] [discussion] 2025-08-27 15:56:05
>>donkey+ks3
These manufacturers gladly took in AOSP back in 2011 when it was still truly a great open source project - exactly as the name should require it to be - and also when security requirements were much much lower. Of course to keep up with device security it turns out you need complete control over the whole stack and regular updates anyway, so now these manufacturers are in a pickle of a situation.
◧◩◪◨⬒⬓⬔
11. donkey+ih4[view] [source] [discussion] 2025-08-27 18:58:34
>>devmor+uG3
Its possible the forced apps are a cost recouping mechanism. But how does a phone bootloader being locked down become Google's fault? Does it mandate that for some kind of Android certification?
replies(1): >>j4hduf+PF4
◧◩◪◨⬒⬓⬔⧯
12. j4hduf+PF4[view] [source] [discussion] 2025-08-27 20:52:29
>>donkey+ih4
Yes Google mandates a locked bootloader in order to meet Google Play Integrity's remote attestation. More generally it mandates a perfectly clean and valid secure boot chain. Among a variety of other requirements.
[go to top]