|
|
Log in / Subscribe / Register

Dutch consumer group sues Samsung over Android updates (OSNews)

OSNews reports that the Dutch consumer protection advocacy agency Consumentenbond has sued Samsung, demanding updates for its Android phones. "The Consumentenbond had been in talks with Samsung about this issue for a while now, but no positive outcome was reached, and as such, they saw no other option but to file suit. The Consumentenbond is demanding that Samsung provides two years of updates for all its Android devices, with the two-year period starting not at the date of market introduction of the device, but at the date of sale. This means that devices introduced one or even more years ago that are still being sold should still get two years' worth of updates starting today." (Thanks to Paolo Bonzini)

to post comments

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 20:14 UTC (Wed) by david.a.wheeler (subscriber, #72896) [Link] (36 responses)

Back in 2004-2006, several folks calculated an interesting measure: the % of days in a year where something was vulnerable to at least one publicly-known vulnerability, even if it was updated.

For example, statistics by Scanit’s Browser Security Test group found that 98% of time in 2004 Internet Explorer was vulnerable to dangerous known remote attacks, for which no patch to fix it was available, compared to 17% for Opera and 15% for Mozilla/Firefox. There were only 7 days in 2004 that Internet Explorer was safe from known yet unstoppable remote attacks. This is from "A Year Of Bugs" by scanIT’s Browser Security Test. Since not all vulnerabilities are equal, they only considered the especially dangerous “remote code execution” vulnerabilities, i.e., defects that allow a “malicious web page or e-mail message to execute arbitrary code or OS commands on the viewer’s computer.” They then compared the time from the “public announcement of the vulnerability to the time when the fix is available to the general user population.” For Internet Explorer, “there was only one period in 2004 when there were no publicly known remote code execution bugs - between the 12th and the 19th of October - 7 days in total.” Mozilla and the family (including Firefox, Netscape Navigator and the Camino browsers) has the shortest attack window of opportunity. There were 56 days (15%) in 2004 when there was a publicly known remote code execution vulnerability with no publicly-available patch, and about half of that 15% only applied to MacOS users.

Brian Krebs “Security Fix” column later compiled statistics on vulnerability response times, including those for Microsoft Internet Explorer (IE) and Mozilla Firefox. Security Fix that 78% (284/365) of the time in 2006 Internet Explorer was vulnerable to dangerous known attacks, for which no patch to fix it was available, compared to 2% (9/365) for Mozilla Firefox.

If people did that kind of calculation for Samsung Smartphones, as deployed on typical US carriers, I think they'd find that many phones are at or nearly 100% vulnerable. The problem isn't open source, it's the lack of real openness. For most people there's no practical way to upgrade the Android operating system to a current version.

Then people can buy smartphones based on a METRIC. E.G., if Samsung can't get its phones upgraded, sounds like a great reason to never buy one. Perhaps it's also time for a two-year minimum warranty for the US for consumers. It seems to be working in Europe.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 20:44 UTC (Wed) by prometheanfire (subscriber, #65683) [Link] (2 responses)

This is part of the reason my next phone will be on google's monthly update cycle. Have the reseller be on that cycle for a few months to prove some ability to secure the new phone. ATM it is only google and their nexus line that provide it.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 21:56 UTC (Wed) by job (guest, #670) [Link] (1 responses)

Google is not a guarantee for updates. I bought a Nexus One, and within a year it was out of updates.

That never happened to any other kind of computer I bought.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 22:09 UTC (Wed) by corbet (editor, #1) [Link]

Things have changed quite a bit since the Nexus One days. There is no shortage of room for improvement, but Google does seem to be figuring out that security updates are important.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 20:48 UTC (Wed) by b7j0c (guest, #27559) [Link] (9 responses)

There have been enough exploits to both iOS and Android that one can safely assume it will be many years before either platform settles enough to be hardened against exploits. Both smartphone platforms are insecure. Presently, each new release focuses on new features rather than stability, and as a result, you should not assume future versions will be more secure than present versions.

It also appears that both Apple and Google know about some exploits for considerable periods of time before patching.

Mainstream Nexus phones now have a monthly patch cycle. My 5x has already had two such cycles since I purchased it. I assume that such frequent patching is as likely to introduce bugs as to fix them.

In the case of Samsung, the solution is simple: stop buying their phones. both Lenovo (Moto) and Google (Nexus) offer better alternatives. I don't see how this case has any merit, no one is forced to choose Samsung.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 22:02 UTC (Wed) by MattJD (subscriber, #91390) [Link] (8 responses)

> Mainstream Nexus phones now have a monthly patch cycle. My 5x has already had two such cycles since I purchased it. I assume that such frequent patching is as likely to introduce bugs as to fix them.

Considering those patch cycles are specifically security bugs (though there have been some minor bug fixes too I believe), what would you suggest they do instead to provide security updates?

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 1:24 UTC (Thu) by b7j0c (guest, #27559) [Link] (7 responses)

I fully realize that there is no desire for something akin to Debian Stable in the smartphone platform world. If they were to slow down the cycle and focus on stability, the lack of new features would turn off consumers. So, I would recommend they just continue as they are and I will expect and live with bugs.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 2:57 UTC (Thu) by MattJD (subscriber, #91390) [Link] (2 responses)

Right, except those monthly patches are akin to what Debian Stable provides. Google seems to have moved to a yearly (thought they may go back to twice yearly) feature release cycle. Those updates will be huge, and will introduce those bugs. But the monthly patches are smaller and targeted in nature, fixing security bugs (with some other important fixes on the side, not features).

I won't argue your preferences (I run Debian Stable on my servers for that development cycle, so I understand why people want that). I'm just saying those two patches you have received aren't major changes, they are minor fixes targeting security. They seem to be what you want, which is why I was curious you didn't like them.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 16:54 UTC (Thu) by b7j0c (guest, #27559) [Link] (1 responses)

> Right, except those monthly patches are akin to what Debian Stable provides

except mostly done in secret

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Feb 2, 2016 7:55 UTC (Tue) by thestinger (guest, #91827) [Link]

The source code is released alongside the security bulletins and the over-the-air updates and each issue has a CVE assigned to it. There are clear commit messages and no obfuscation. In what sense is it done in secret? It's the standard method of doing vulnerability disclosure is done for open-source projects. There are few open source projects with comparable transparency when it comes to security vulnerabilities.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 22:26 UTC (Thu) by ksandstr (guest, #60862) [Link] (3 responses)

We used to have this, though. They were called "cell phones"; think about it, a telephone you could carry in your (cargo pants) pocket! Weren't any exploits for those things, at least above the baseband ROM...

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 22, 2016 12:30 UTC (Fri) by pboddie (guest, #50784) [Link]

You could do bad things to Nokia phones by sending them SMS messages of a certain kind. Probably other manufacturers' products had similar flaws. I could easily imagine that the Bluetooth stack could have been subverted on those phones, too. Nothing was ever as good as people tend to claim.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 23, 2016 2:11 UTC (Sat) by rahvin (guest, #16953) [Link] (1 responses)

I wouldn't argue they were secure, just that nobody cared to exploit them because they didn't have any value exploited because it was just a phone. A modern smartphone has as much compute power as a computer from the 90's and a persistent internet connection. There is value in exploiting it just for that, let alone all the personal and financial data that they now house.

One of these days someone is going to be held to account in a civil suit for not fixing exploits and it's going to be very ugly for the manufacturers when that liability lands.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 24, 2016 0:32 UTC (Sun) by sbergman27 (guest, #10767) [Link]

Not being a target is as good a security as any. Would you prefer to live in a low-crime neighborhood without a Kevlar jacket, or in a war zone with the best Kevlar jacket money can buy?

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 21:26 UTC (Wed) by PaXTeam (guest, #24616) [Link] (12 responses)

what's the point of this metric?

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 21:58 UTC (Wed) by Wol (subscriber, #4433) [Link] (11 responses)

Quite a lot. It says whether the vendor is serious about security!

Basically it says "on average a vulnerability is discovered every X days. It takes Y days on average to fix it. Is X greater or less than Y?"

If X is less than Y, then your phone is likely to be permanently vulnerable. If X is greater than Y, then your phone is secure at least some of the time. Yes I know we'd rather it was all of the time, but at least we know they're *trying* to do the right thing.

Cheers,
Wol

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 22:28 UTC (Wed) by PaXTeam (guest, #24616) [Link] (10 responses)

why would a phone be secure on those days when the public doesn't know about a particular vulnerability? doesn't that only describe the public's unawareness but not the security of their phones?

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 0:19 UTC (Thu) by FLHerne (guest, #105373) [Link] (3 responses)

If the maintainers didn't fix a bug because they didn't find it for a few years, that doesn't say much about their general attitude to security. They might have crap code and no testing, or it might have been some really obscure edge-case in an otherwise good project.

On the other hand, if a serious vulnerability is left unpatched for more than a few days _after_ the maintainers are told, you know _for sure_ not to rely on them for security. No excuse for leaving a hole when you know it's there.

---

Also, bugs exploited by widespread malware get reported fairly quickly by reverse-engineering the malware. So the number of publically-known bugs should track the number known to typical malware authors with a few weeks/months' delay.
That's not true for targeted, inconspicuous malware as deployed by governments, but few users complain about that.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 1:16 UTC (Thu) by PaXTeam (guest, #24616) [Link] (2 responses)

> They might have crap code and no testing, or it might have been some really obscure edge-case in an otherwise good project.

that distinction would say very much about that attitude to security. however i don't see how the suggested metric helps here.

> if a serious vulnerability is left unpatched for more than a few days _after_ the maintainers are told, you know _for sure_ not to rely on them for security.

except for certain individuals or teams with single-digit member counts no entity can turn fixes out that fast so it's still not a useful metric because it would make most entities unreliable. and i still don't see how a phone becomes secure on those days when the public is unaware of any particular vulnerability.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 11:42 UTC (Thu) by jospoortvliet (guest, #33164) [Link] (1 responses)

As was pointed out, the metric is not meant to make phones more secure. Just to show how quickly vendors react to known security issues - one aspect of security, among many. I think it is a great idea.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 11:50 UTC (Thu) by PaXTeam (guest, #24616) [Link]

compare your

> As was pointed out, the metric is not meant to make phones more secure.

with Wol's

> If X is greater than Y, then your phone is secure at least some of the time.

clearly there's disagreement already on what this metric is supposed to mean.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 11:00 UTC (Thu) by dunlapg (guest, #57764) [Link] (5 responses)

why would a phone be secure on those days when the public doesn't know about a particular vulnerability? doesn't that only describe the public's unawareness but not the security of their phones?

There's a difference between "public vulnerability" and "private vulnerability". Yes, if there's a vulnerability on your phone, then you are vulnerable, even if that vulnerability has not been published. But the information is not public yet, then the only people who know about it are 1) people who have done the hard work of discovering the bug for themselves, or 2) people who have paid for it (or otherwise acquired it); that's likely to be a very small number of people. The value of a "private vulnerability" (AKA 0-day) lies in the fact that nobody knows about it; every time you use it, every person you tell about it, increases the probability that it will be discovered and patched. So people with a private vulnerability are likely to be careful in the way they use it, to maintain its value.

Only a few people can use a private vulnerability, and they have an incentive to use it very selectively, so your risk from a "private vulnerability" is there, but relatively low (unless you're a high-profile target).

In the case of a "public vulnerability", the tables are turned. The vulnerability can be exploited not only to the small number of people who either discovered it or bought it, but to anyone with a basic technical competence. And since it's already public, the optimal behavior is no longer to only use it on select, high-profile targets, but to try to exploit as many people as quickly as you can before it gets patched.

Millions of people can use a public vulnerability, and there's an incentive to use it indiscriminately; so your risk from a public vulnerability is very high, no matter who you are.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 11:59 UTC (Thu) by PaXTeam (guest, #24616) [Link] (4 responses)

maybe my question was ambiguous, but by 'the public' i meant those who would be potential targets, not threat actors. you were describing the latter, not the former, so let me rephrase my question: why would a phone be secure on those days when the potentially victimized/targeted public doesn't know about a particular vulnerability?

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 15:04 UTC (Thu) by dunlapg (guest, #57764) [Link] (3 responses)

I think I answered that in my post.

You're insisting on using the word "secure" like it's a binary thing. It's not. Do you lock the door to your house? Probably. Do you put bars on your windows? Probably not, unless you live in a particularly bad area. So if you lock your doors but don't have bars on your windows, are you "secure"? Well, that's the wrong question; the question is, "What is your level of risk, and is it acceptable?"

On days when a vulnerability exists, but it has not been made public, the risk to the average member of the public is fairly low (for reasons I cover in my previous post). On a day when a vulnerability exists but has been made public, the risk is pretty high. The proposed metric says, "What percentage of days in the last year have you been at high risk?"

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 28, 2016 1:10 UTC (Thu) by nix (subscriber, #2304) [Link] (2 responses)

Of course, for houses there are extra rules. I'd be very happy indeed to throw out the (known-horribly-vulnerable) front door lock on my house and replace it with something tied to a Yubikey Neo's near-field one-time passwords, talking to an authentication server in an embedded box attached to the inside of the door or something like that. But even if I had the skills to do that, I couldn't: my mortgage is tied to house insurance, and no insurer on the planet will insure a house that uses some advanced techie thing rather than a lock.

(But then, it fundamentally doesn't matter that front door locks are insecure -- an attacker who actually wanted to break in could just wait until you go out and go in through the window, and more or less nobody bars their windows to prevent this attack because not feeling like you're living in a prison is generally more important than security against such determined bad actors, particularly given that your stuff probably *is* insured, so a robbery, while very unpleasant, is unlikely to be devastating. I guess the analogue of this for computing is backups to protect against wiping and encryption to protect against theft of secrets -- but this doesn't work very well because with computers the bad guy can lurk over your shoulder, undetected, and steal/wipe all your stuff as soon as you unlock it, something very unlikely to happen in the physical world until they invent invisible burglars.)

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 28, 2016 20:17 UTC (Thu) by johannbg (guest, #65743) [Link] (1 responses)

"something very unlikely to happen in the physical world until they invent invisible burglars."
Those are called ninjas and have been around since sometime between the 12th and 15th centuries ;)

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Feb 10, 2016 20:11 UTC (Wed) by nix (subscriber, #2304) [Link]

That's only relevant if ninjas rob houses often enough for insurance companies to consider them in their policies. If they do where you live, I don't think I want to live there. :)

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 22:09 UTC (Wed) by Wol (subscriber, #4433) [Link]

> Perhaps it's also time for a two-year minimum warranty for the US for consumers. It seems to be working in Europe.

That warranty isn't all it's cracked up to be, but yes it's useful. Most electronic devices in the UK have a 1-year no-quibble warranty. There is also an obligation to be "reasonably free of defects" but the manufacturer could turn round after 13 months and say "you've abused your device. The warranty is void". If you then cough up for an independent check and that says "it's a manufacturing fault", then the shop is liable for the repair and the cost of the test, but most people pay for an "extended warranty" rather than go through the hassle.

And I've had trouble claiming on the warranty. It wasn't that difficult, but I had to kick up a stink - the device was about four months old when it failed. Unfortunately, it had been sale stock as a discontinued item. So the shop refused to take it back for repair, and didn't want to replace it - they had an agreement with the manufacturer and the consumer - me - slipped through the crack. They were quite happy to refund it, but the equivalent item would have cost me £20 more to buy, and I objected. When I kicked up a fuss, a manager got involved and as soon as he saw my point of view - that they were refusing to honour a legal warranty - it got sorted no problem. But I shouldn't have had to kick up a fuss.

Cheers,
Wol

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 0:29 UTC (Thu) by anselm (subscriber, #2796) [Link] (8 responses)

Perhaps it's also time for a two-year minimum warranty for the US for consumers. It seems to be working in Europe.

The problem with this is that the statutory two-year minimum warranty is based on a relationship between the consumer (you) and the dealer, not the handset manufacturer. This means that if you point out a software “defect” under the warranty, the best you can hope for is some kind of refund because the dealer is usually not in a position to actually fix the software bug on your behalf unless the manufacturer provides the necessary updates. (The manufacturers, of course, are in the business of selling new phones rather than fixing old ones after the fact, so the fact that they don't bend over backwards in order to publish updates for old phones for years on end, distasteful as it might be, should come as no big surprise.)

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 1:23 UTC (Thu) by khim (subscriber, #9252) [Link] (6 responses)

This means that if you point out a software “defect” under the warranty, the best you can hope for is some kind of refund because the dealer is usually not in a position to actually fix the software bug on your behalf unless the manufacturer provides the necessary updates.
Refund is completely fine, too. This would mean that you could just return the phone and get the next one (with new hardware and software) for free.
The manufacturers, of course, are in the business of selling new phones rather than fixing old ones after the fact, so the fact that they don't bend over backwards in order to publish updates for old phones for years on end, distasteful as it might be, should come as no big surprise.
Sure. But if, instead of sale, they would be forced to shell out new phones for free then this wouldn't help them. They may survive while only geeks would do that, but if it'll be well-known fact that you could buy the phone once then replace it with newer model forever citing lack of updates I'm pretty sure ordinary people will follow. At this point manufacturers will be forced to do something. Well, if not and this would just be a way for a select few to be able to update phones for free regularly… that would be good outcome, too.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 13:22 UTC (Thu) by anselm (subscriber, #2796) [Link] (5 responses)

This would mean that you could just return the phone and get the next one (with new hardware and software) for free.

Probably not, since there will very likely be a deduction for your usage of the returned phone. After, say, 20 months you can't expect a refund of the full price that you paid when it was new, since you presumably did get some use out of it in the meantime. If we stipulate for the sake of this discussion that people generally use a smartphone for 3 years, you could hope for a refund of around 45% of the original price.

At this point manufacturers will be forced to do something.

The manufacturers aren't actually part of the statutory-warranty relationship, which is between the consumer and the dealer. Whether manufacturers will “be forced” to do anything at all would depend on the relationship between the dealers and them, where statutory warranty does not apply.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 14:58 UTC (Thu) by khim (subscriber, #9252) [Link] (4 responses)

Probably not, since there will very likely be a deduction for your usage of the returned phone.
Why? The primary remedy is “repair or replace” when product is found defective. Note: it's Ok to replace it with a different product - but said product, of course, must not contain the same defect! Refund is just a fallback for the case where dealer couldn't offer any other remedy. You get your money, dealer get's the goods, what it'll do with them is it's own problem.
Whether manufacturers will “be forced” to do anything at all would depend on the relationship between the dealers and them, where statutory warranty does not apply.
It will depend on the proportion of people who will return goods for return or a replacement. As I've said: if it'll be a nice little way for geeks to have a replacement phone for free on a regular schedule - that would be good enough outcome for me, if many buyers will start doing that then dealers will need to push the manufacturers...

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 15:35 UTC (Thu) by anselm (subscriber, #2796) [Link] (3 responses)

Refund is just a fallback for the case where dealer couldn't offer any other remedy.

It probably depends on the jurisdiction, but at least here in Germany (and probably the rest of the EU) the two official alternatives are either a repair of the actual device or a refund (possibly with a deduction for past usage time). Of course the dealer can offer, as a friendly gesture, to replace the defective product with a different – hopefully non-defective – one and the customer can agree to that, but there is no statutory obligation on either part.

It is safe to assume that if it was really legally possible to get one's mobile phone replaced under the statutory warranty, at no cost to oneself, with a brand-new model after almost two years of use by pointing out security holes in the original software, nearly everyone would be doing it (no geekiness required, just get the “magic words” from your friends or off the Internet), and the manufacturers would probably be much more assiduous about pushing out firmware updates. There are certainly enough security problems to go around. The observation that this doesn't actually seem to be the case should tell us something about the viability of the approach.

(Disclaimer: IANAL.)

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 20:51 UTC (Thu) by kleptog (subscriber, #1183) [Link]

> It is safe to assume that if it was really legally possible to get one's mobile phone replaced under the statutory warranty, at no cost to oneself, with a brand-new model after almost two years of use by pointing out security holes in the original software, nearly everyone would be doing it (no geekiness required, just get the “magic words” from your friends or off the Internet), and the manufacturers would probably be much more assiduous about pushing out firmware updates. There are certainly enough security problems to go around. The observation that this doesn't actually seem to be the case should tell us something about the viability of the approach.

The point of this action by the Consumentenbond is that we shouldn't be treating security bugs as "ok" and that they should be treated as a defect that can be considered for replacement under warranty. Since it apparently isn't clear they're asking the courts for a ruling, but if they win then you will indeed be able to return your device to be repaired or refunded. Obviously if you've been using it for two years already they only have to offer another phone with equal performance to the ones from two years ago, which is usually much cheaper.

So you wouldn't be able to use this to get free new better phones every two years, but it will mean that if your phone hasn't been updated after six months OTA then you can go back and ask to have it replaced with an equivalent model that has been updated.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 25, 2016 8:19 UTC (Mon) by smurf (subscriber, #17840) [Link] (1 responses)

German law (BGB §437 et al.) says that the buyer has a choice of returning the product for full price, or getting part of their money back, consumer's choice, if the seller can't repair the defect.
This however assumes that the security problem is a material defect. "Material" meaning "it matters", i.e. either it significantly impedes your use of the phone, or something that was explicitly promised in advertising / user manual / sales contract is missing (thus the buyer can assert they wouldn't have bought the thing otherwise).
The law does not say whether continuing security updates are material, neither does the phone's advertising or the user manual, and AFAIK there are no relevant court decisions.

Disclaimer: IANAL², but my father was.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 25, 2016 9:35 UTC (Mon) by anselm (subscriber, #2796) [Link]

German law (BGB §437 et al.) says that the buyer has a choice of returning the product for full price, or getting part of their money back, consumer's choice, if the seller can't repair the defect.

Yes, but according to §346 BGB, if you as the buyer opt for the return-with-a-refund you still need to pay for the use you had from the device. This doesn't matter a lot if you receive and unpack the thing, find that it's broken, and return it immediately, but if you turn it in for a refund under the statutory warranty after having used it for some considerable time (nearly two years, in the extreme case), you can't expect a full refund.

This however assumes that the security problem is a material defect. "Material" meaning "it matters", i.e. either it significantly impedes your use of the phone, or something that was explicitly promised in advertising / user manual / sales contract is missing (thus the buyer can assert they wouldn't have bought the thing otherwise).

Since smartphone manufacturers – for very good and sensible reasons as far as they're concerned – don't promise or advertise that their devices are completely devoid of security bugs, the $64,000 question is really whether a customer can reasonably expect that if such bugs are in fact found, they will be fixed in existing and deployed devices in a timely manner. Judging from past performance on the part of manufacturers, the answer to that question is likely “no”. The other question is whether it will be believable for a consumer to claim that if they'd only known that there was this terrible security hole in Android they would have bought an iPhone instead (or vice versa), when terrible security holes are found all the time in either platform.

We'll be watching the outcome of that lawsuit with great interest. (Oh, and IANAL either.)

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 16:26 UTC (Thu) by fest3er (guest, #60379) [Link]

I thought federal law already required manufacturers who sell products in the US to continue to support those products for five years after they stop manufacturing them.

Dutch consumer group sues Samsung over Android updates (OSNews)

Posted Jan 20, 2016 20:48 UTC (Wed) by pbonzini (subscriber, #60935) [Link]

FWIW, I think the last two paragraphs of the article go a bit over the top. I don't see why anything but security fixes would have to be provided under warranty, hence it makes no sense to say "If this means they can no longer sell outdated, crappy hardware because newer Android versions would be too slow - so be it".

The press release in fact mentions specifically how "software updates are vital to keep
smartphones secure", so it should be a pretty reasonable position.

Dutch consumer group sues Samsung over Android updates (OSNews)

Posted Jan 22, 2016 1:40 UTC (Fri) by pr1268 (guest, #24648) [Link] (2 responses)

If the Consumentenbond prevails in their lawsuit, then I envision Samsung (and other device manufacturers) building a software self-destruct mechanism into the phone that is invoked automatically two years after the phone is first activated with a properly-provisioned SIM card (i.e. date of sale as mentioned in the article).

Having a bricked two year-old smart phone in one's possession would be incentive enough to buy a new one. Or so it would seem...

I applaud the Consumentenbond's actions here; it's just that I don't see this ending nicely for consumers either way.

Side note: My personal experience with a Galaxy S3 purchased in December 2012 was that it didn't receive updates after around April 2015 (estimated; I don't remember exactly when)—I can't say for sure if this was intentional forced obsolescence on Samsung's / Android's fault, or a software bug exposed by a failed update occurring about that time (the phone stopped updating all apps installed, not just the Android system, and plus the phone behaved erratically, draining the battery in one or two hours). I've since replaced / upgraded.

Dutch consumer group sues Samsung over Android updates (OSNews)

Posted Jan 22, 2016 12:36 UTC (Fri) by pboddie (guest, #50784) [Link] (1 responses)

If the Consumentenbond prevails in their lawsuit, then I envision Samsung (and other device manufacturers) building a software self-destruct mechanism into the phone that is invoked automatically two years after the phone is first activated with a properly-provisioned SIM card (i.e. date of sale as mentioned in the article).

That will just land them in even more trouble, because there will be a need to indicate the device's "forced obsolescence" which the manufacturers will probably not do. Can you sell a phone that lasts for two years for the same price as one which lasts, say, five years? And even if they do note the limited lifespan (probably in small print), it may be ruled that this contradicts reasonable expectations, anyway.

Dutch consumer group sues Samsung over Android updates (OSNews)

Posted Jan 24, 2016 23:18 UTC (Sun) by pr1268 (guest, #24648) [Link]

That will just land them in even more trouble, because there will be a need to indicate the device's "forced obsolescence" which the manufacturers will probably not do.

If the forced obsolescence were imposed, then I'm certain that {Android | service provider} would have to give ample notice to the consumer, assuming the device manufacturer would not. If not by law1, then certainly so as to not sully their good name with a horrible user experience.

Interesting side note: Two years is the "magic number" that has historically been the duration of subsidized phone contracts in the USA—but all the major providers here have moved away from that model to a "lease-to-buy" plan. Which lasts for... yep, two years2.

1 I'm certain it's enshrined in contract law about customer notification of expiration of service agreements after a pre-determined finite time period. At least in the USA.

2 Apparently, that's the maximum time over which you can spread the lease payments; Verizon (and T-Mobile, and I believe AT&T) will allow you to purchase the phone outright, or even pay off the balance anytime during the lease period.


Copyright © 2016, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds