Study: Android Phone Makers Skip Google Security Updates without Telling Users

Discussion in '[H]ard|OCP Front Page News' started by Megalith, Apr 15, 2018.

  1. Megalith

    Megalith 24-bit/48kHz Staff Member

    Messages:
    12,474
    Joined:
    Aug 20, 2006
    Germany’s Security Research Labs (SRL) has revealed that some Android smartphone manufacturers are intentionally misleading users into thinking that their devices have the latest security patches, even when some of them fail to install. Worse, some vendors have exercised “deliberate deception” by moving patch dates forward instead of providing any actual updates.

    In the findings due to be presented at the Hack in the Box security conference in Amsterdam on Friday, the researchers said of the 1,200 smartphones tested, some manufacturers may miss one or two patches from the monthly security updates, but others may miss many more. Failing to update their smartphones with the latest security updates is one thing, but SRL found that some simply lie about installing any patches at all.
     
    Big_Rig_Stig likes this.
  2. jfreund

    jfreund Gawd

    Messages:
    891
    Joined:
    Sep 3, 2006
    I'm running crDroid on my Nexus 6p, and it's been updated 3 times already this month.
     
  3. IdiotInCharge

    IdiotInCharge Not the Idiot YOU are Looking for

    Messages:
    6,928
    Joined:
    Jun 13, 2003
    And once again I'm a happy Pixel owner.
     
    Unter Dog, Zarathustra[H] and jfreund like this.
  4. Zarathustra[H]

    Zarathustra[H] Official Forum Curmudgeon

    Messages:
    25,315
    Joined:
    Oct 29, 2000
    Yeah, but in some cases they are saying that updates are being sent out, but they are skipping one or more of the security patches. So, you get an update, but you don't get the security patch as part of that update :(

    I'm not familiar with crDroid though. IN general I'd imagine this applies more to OEM images.
     
  5. Big_Rig_Stig

    Big_Rig_Stig Gawd

    Messages:
    970
    Joined:
    Jan 24, 2018
    All this while AT&T rolls out non-security updates that do nothing but break already-working apps...
     
  6. dgingeri

    dgingeri 2[H]4U

    Messages:
    2,770
    Joined:
    Dec 5, 2004
    I have 2 Pixel 2 phones, one on Project Fi for my personal phone and one on Verizon for my work phone. My work phone has been updated once in the last 3 months, while my personal phone has updated 4 times in 2 and a half months. I think Verizon is holding back updates.
     
    Big_Rig_Stig likes this.
  7. Big_Rig_Stig

    Big_Rig_Stig Gawd

    Messages:
    970
    Joined:
    Jan 24, 2018
    It's the only way Verizon has to brick your phone & force you into a new one.
     
  8. katanaD

    katanaD [H]ard|Gawd

    Messages:
    1,520
    Joined:
    Nov 15, 2016
    imagine, if you will, a device that didnt NEED constant security updates..
     
    Big_Rig_Stig likes this.
  9. Big_Rig_Stig

    Big_Rig_Stig Gawd

    Messages:
    970
    Joined:
    Jan 24, 2018
    Cue KatanaD disappearance in 3...2...1...
     
  10. katanaD

    katanaD [H]ard|Gawd

    Messages:
    1,520
    Joined:
    Nov 15, 2016

    End users.. will always make sure i have a job


    hahaha
     
  11. daglesj

    daglesj [H]ardness Supreme

    Messages:
    4,822
    Joined:
    May 7, 2005
    I've given up caring if honest. I buy a phone, use it for three years and get another one. Never install masses of apps, always restrict the permissions to the minimum and never had an issue.
     
  12. Exavior

    Exavior [H]ardForum Junkie

    Messages:
    9,436
    Joined:
    Dec 13, 2005
    Might as well imagine all humans dead for that to happen again
     
    Shadowed likes this.
  13. Uvaman2

    Uvaman2 2[H]4U

    Messages:
    2,462
    Joined:
    Jan 4, 2016
    Well, if they are at least looking into the update and checking pros cons in their hardware, not to terrible I think, kind of delaying Ms update for severs I guess.
     
    Last edited: Apr 17, 2018
  14. IcePickFreak

    IcePickFreak [H]ard|Gawd

    Messages:
    1,031
    Joined:
    Dec 1, 2010
    That's easy, because I had one. ;)
    celly.gif