|
|
Log in / Subscribe / Register

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 20, 2016 22:02 UTC (Wed) by MattJD (subscriber, #91390)
In reply to: I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic by b7j0c
Parent article: Dutch consumer group sues Samsung over Android updates (OSNews)

> Mainstream Nexus phones now have a monthly patch cycle. My 5x has already had two such cycles since I purchased it. I assume that such frequent patching is as likely to introduce bugs as to fix them.

Considering those patch cycles are specifically security bugs (though there have been some minor bug fixes too I believe), what would you suggest they do instead to provide security updates?


to post comments

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 1:24 UTC (Thu) by b7j0c (guest, #27559) [Link] (7 responses)

I fully realize that there is no desire for something akin to Debian Stable in the smartphone platform world. If they were to slow down the cycle and focus on stability, the lack of new features would turn off consumers. So, I would recommend they just continue as they are and I will expect and live with bugs.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 2:57 UTC (Thu) by MattJD (subscriber, #91390) [Link] (2 responses)

Right, except those monthly patches are akin to what Debian Stable provides. Google seems to have moved to a yearly (thought they may go back to twice yearly) feature release cycle. Those updates will be huge, and will introduce those bugs. But the monthly patches are smaller and targeted in nature, fixing security bugs (with some other important fixes on the side, not features).

I won't argue your preferences (I run Debian Stable on my servers for that development cycle, so I understand why people want that). I'm just saying those two patches you have received aren't major changes, they are minor fixes targeting security. They seem to be what you want, which is why I was curious you didn't like them.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 16:54 UTC (Thu) by b7j0c (guest, #27559) [Link] (1 responses)

> Right, except those monthly patches are akin to what Debian Stable provides

except mostly done in secret

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Feb 2, 2016 7:55 UTC (Tue) by thestinger (guest, #91827) [Link]

The source code is released alongside the security bulletins and the over-the-air updates and each issue has a CVE assigned to it. There are clear commit messages and no obfuscation. In what sense is it done in secret? It's the standard method of doing vulnerability disclosure is done for open-source projects. There are few open source projects with comparable transparency when it comes to security vulnerabilities.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 22:26 UTC (Thu) by ksandstr (guest, #60862) [Link] (3 responses)

We used to have this, though. They were called "cell phones"; think about it, a telephone you could carry in your (cargo pants) pocket! Weren't any exploits for those things, at least above the baseband ROM...

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 22, 2016 12:30 UTC (Fri) by pboddie (guest, #50784) [Link]

You could do bad things to Nokia phones by sending them SMS messages of a certain kind. Probably other manufacturers' products had similar flaws. I could easily imagine that the Bluetooth stack could have been subverted on those phones, too. Nothing was ever as good as people tend to claim.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 23, 2016 2:11 UTC (Sat) by rahvin (guest, #16953) [Link] (1 responses)

I wouldn't argue they were secure, just that nobody cared to exploit them because they didn't have any value exploited because it was just a phone. A modern smartphone has as much compute power as a computer from the 90's and a persistent internet connection. There is value in exploiting it just for that, let alone all the personal and financial data that they now house.

One of these days someone is going to be held to account in a civil suit for not fixing exploits and it's going to be very ugly for the manufacturers when that liability lands.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 24, 2016 0:32 UTC (Sun) by sbergman27 (guest, #10767) [Link]

Not being a target is as good a security as any. Would you prefer to live in a low-crime neighborhood without a Kevlar jacket, or in a war zone with the best Kevlar jacket money can buy?


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds