|
|
Log in / Subscribe / Register

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 1:23 UTC (Thu) by khim (subscriber, #9252)
In reply to: I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic by anselm
Parent article: Dutch consumer group sues Samsung over Android updates (OSNews)

This means that if you point out a software “defect” under the warranty, the best you can hope for is some kind of refund because the dealer is usually not in a position to actually fix the software bug on your behalf unless the manufacturer provides the necessary updates.
Refund is completely fine, too. This would mean that you could just return the phone and get the next one (with new hardware and software) for free.
The manufacturers, of course, are in the business of selling new phones rather than fixing old ones after the fact, so the fact that they don't bend over backwards in order to publish updates for old phones for years on end, distasteful as it might be, should come as no big surprise.
Sure. But if, instead of sale, they would be forced to shell out new phones for free then this wouldn't help them. They may survive while only geeks would do that, but if it'll be well-known fact that you could buy the phone once then replace it with newer model forever citing lack of updates I'm pretty sure ordinary people will follow. At this point manufacturers will be forced to do something. Well, if not and this would just be a way for a select few to be able to update phones for free regularly… that would be good outcome, too.


to post comments

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 13:22 UTC (Thu) by anselm (subscriber, #2796) [Link] (5 responses)

This would mean that you could just return the phone and get the next one (with new hardware and software) for free.

Probably not, since there will very likely be a deduction for your usage of the returned phone. After, say, 20 months you can't expect a refund of the full price that you paid when it was new, since you presumably did get some use out of it in the meantime. If we stipulate for the sake of this discussion that people generally use a smartphone for 3 years, you could hope for a refund of around 45% of the original price.

At this point manufacturers will be forced to do something.

The manufacturers aren't actually part of the statutory-warranty relationship, which is between the consumer and the dealer. Whether manufacturers will “be forced” to do anything at all would depend on the relationship between the dealers and them, where statutory warranty does not apply.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 14:58 UTC (Thu) by khim (subscriber, #9252) [Link] (4 responses)

Probably not, since there will very likely be a deduction for your usage of the returned phone.
Why? The primary remedy is “repair or replace” when product is found defective. Note: it's Ok to replace it with a different product - but said product, of course, must not contain the same defect! Refund is just a fallback for the case where dealer couldn't offer any other remedy. You get your money, dealer get's the goods, what it'll do with them is it's own problem.
Whether manufacturers will “be forced” to do anything at all would depend on the relationship between the dealers and them, where statutory warranty does not apply.
It will depend on the proportion of people who will return goods for return or a replacement. As I've said: if it'll be a nice little way for geeks to have a replacement phone for free on a regular schedule - that would be good enough outcome for me, if many buyers will start doing that then dealers will need to push the manufacturers...

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 15:35 UTC (Thu) by anselm (subscriber, #2796) [Link] (3 responses)

Refund is just a fallback for the case where dealer couldn't offer any other remedy.

It probably depends on the jurisdiction, but at least here in Germany (and probably the rest of the EU) the two official alternatives are either a repair of the actual device or a refund (possibly with a deduction for past usage time). Of course the dealer can offer, as a friendly gesture, to replace the defective product with a different – hopefully non-defective – one and the customer can agree to that, but there is no statutory obligation on either part.

It is safe to assume that if it was really legally possible to get one's mobile phone replaced under the statutory warranty, at no cost to oneself, with a brand-new model after almost two years of use by pointing out security holes in the original software, nearly everyone would be doing it (no geekiness required, just get the “magic words” from your friends or off the Internet), and the manufacturers would probably be much more assiduous about pushing out firmware updates. There are certainly enough security problems to go around. The observation that this doesn't actually seem to be the case should tell us something about the viability of the approach.

(Disclaimer: IANAL.)

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 21, 2016 20:51 UTC (Thu) by kleptog (subscriber, #1183) [Link]

> It is safe to assume that if it was really legally possible to get one's mobile phone replaced under the statutory warranty, at no cost to oneself, with a brand-new model after almost two years of use by pointing out security holes in the original software, nearly everyone would be doing it (no geekiness required, just get the “magic words” from your friends or off the Internet), and the manufacturers would probably be much more assiduous about pushing out firmware updates. There are certainly enough security problems to go around. The observation that this doesn't actually seem to be the case should tell us something about the viability of the approach.

The point of this action by the Consumentenbond is that we shouldn't be treating security bugs as "ok" and that they should be treated as a defect that can be considered for replacement under warranty. Since it apparently isn't clear they're asking the courts for a ruling, but if they win then you will indeed be able to return your device to be repaired or refunded. Obviously if you've been using it for two years already they only have to offer another phone with equal performance to the ones from two years ago, which is usually much cheaper.

So you wouldn't be able to use this to get free new better phones every two years, but it will mean that if your phone hasn't been updated after six months OTA then you can go back and ask to have it replaced with an equivalent model that has been updated.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 25, 2016 8:19 UTC (Mon) by smurf (subscriber, #17840) [Link] (1 responses)

German law (BGB §437 et al.) says that the buyer has a choice of returning the product for full price, or getting part of their money back, consumer's choice, if the seller can't repair the defect.
This however assumes that the security problem is a material defect. "Material" meaning "it matters", i.e. either it significantly impedes your use of the phone, or something that was explicitly promised in advertising / user manual / sales contract is missing (thus the buyer can assert they wouldn't have bought the thing otherwise).
The law does not say whether continuing security updates are material, neither does the phone's advertising or the user manual, and AFAIK there are no relevant court decisions.

Disclaimer: IANAL², but my father was.

I'd like to see "% days vulnerable to publicly-known vulnerabilities" as a smartphone statistic

Posted Jan 25, 2016 9:35 UTC (Mon) by anselm (subscriber, #2796) [Link]

German law (BGB §437 et al.) says that the buyer has a choice of returning the product for full price, or getting part of their money back, consumer's choice, if the seller can't repair the defect.

Yes, but according to §346 BGB, if you as the buyer opt for the return-with-a-refund you still need to pay for the use you had from the device. This doesn't matter a lot if you receive and unpack the thing, find that it's broken, and return it immediately, but if you turn it in for a refund under the statutory warranty after having used it for some considerable time (nearly two years, in the extreme case), you can't expect a full refund.

This however assumes that the security problem is a material defect. "Material" meaning "it matters", i.e. either it significantly impedes your use of the phone, or something that was explicitly promised in advertising / user manual / sales contract is missing (thus the buyer can assert they wouldn't have bought the thing otherwise).

Since smartphone manufacturers – for very good and sensible reasons as far as they're concerned – don't promise or advertise that their devices are completely devoid of security bugs, the $64,000 question is really whether a customer can reasonably expect that if such bugs are in fact found, they will be fixed in existing and deployed devices in a timely manner. Judging from past performance on the part of manufacturers, the answer to that question is likely “no”. The other question is whether it will be believable for a consumer to claim that if they'd only known that there was this terrible security hole in Android they would have bought an iPhone instead (or vice versa), when terrible security holes are found all the time in either platform.

We'll be watching the outcome of that lawsuit with great interest. (Oh, and IANAL either.)


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds