I've got a 7 or 8 year old Google Nexus phone. Google stopped updating the OS 5 years ago. The only impact I've noticed is that newer apps won't run on and older OS. For me, however, that really isn't a problem since I use it for making and receiving calls and texts, and checking my email. Right now, I'm in no hurry to lay out hundreds for a new phone, Apple or Android, that will be obsoleted in just a couple years when the vendor abandons it.
Many Android devices of that age and even newer had flaws resulting in the failure to properly validate HTTPS connections as they would accept invalid certificates. As a result, every time I fire up an off the shelf WiFi Pineapple in public and run SSLSplit (not to be confused with Moxies SSLStrip), I get credential after credential, typically starting with e-mail accounts. This is obviously bad because if someone is using an e-mail account on their phone for banking, an attacker could gain access to account recovery.
These are the sorts of transparent attacks you don't notice and which cannot be mitigated with anti-virus or avoiding downloading sketchy apps. The sketchy stuff is already running on the device in the form of the OS and apps you use within it. Note that a large number of these vectors were never publicly disclosed including a vulnerability with Samsung Knox that I reported. When it was in use, the device would accept any cert.
VPN can be a problem, especially on these older devices as those services themselves are vulnerable due to underlying OS issues. In terms of WiFi, keep in mind LTE is effectively broken because of the emergency tower redirection implementation. It's possible for attackers to direct devices to their own OpenLTE tower.
> keep in mind LTE is effectively broken because of the emergency tower
> redirection implementation
And it will fails after only a few message, when the phone modem tries to authenticate the network (MME) and fails. LTE and 3G do have mandatory mutual authentication where the device authenticates the network very early on. It's 2G that's the problem: a 2G network does authenticate the device, but not the other way round, which opens the door to the well known MITM attacks on 2G (stingrays). The worst a LTE/3G rogue cell can do is try to attack the modem during the early non-authenticated messages (send corrupted messages), and waste UE time or jam it. But it can't do MITM.
So if you're paranoid and you can afford it due to good 3G/4G coverage, disable 2G on your handset ;)
And there are tools to avoid even scanning public wifi networks to prevent e.g. in-store tracking, e.g. Smarter WiFi Manager remembers where you've used wifi before based on cell tower locationing, and disables it elsewhere. Works like a charm for me.
> This is obviously bad because if someone is using an e-mail account on their phone for banking, an attacker could gain access to account recovery.
I'm still using a iPhone4 with iOS 5.something on it, it's obviously un-patched or anything like that, the secret is that I don't have any baking applications installed on it nor is my email attached to any recurring payments scheme. The even deeper secret is that I don't have an online baking account set-up with my bank at all, as I don't trust any of the banks with their online security. I chose to eat up the opportunity costs of actually physically going to the the bank over the sometimes illusory security and ease-of-use offered by online banking.
The difference is that you are a well-read HackerNews enthusiast who comments on threads relating to OS security i.e. one of the 0.001%, whereas > 99% of the people affected have no idea what dangers await an out-of-date device.
FWIW, the linked article doesn't track security update status at all. It's graphing percentiles based on API version, which correlates only weakly. A vendor with a correctly patched but old OS would show up as "out of date", but one that missed or is late on important security updates on a recent version is "current".
Two years is completely too short, even three years if you purchase mid-cycle is not enough.
I own Nexus 5X's on Project Fi, one bootlooped and was replaced, the other still going strong after ~20months. I also have a Pixel XL acquired like 7 months ago, both of those should outlive the updates and giving Google the money directly, they should take care of their customers.
Far from an Apple fan boy, the 2016 MBP and 2017 iPad do not worry me about getting forgotten in the ever ongoing updates.
For the 5X's, the were a great deal, and it would cost more than the phone to get into the extended warranties. Not worth it for our purposes. As long as they keep working, we'll keep using them.
If you genuinely only use the phone features of the phone, that doesn't matter anywhere near as much. You only need to update if someone finds something like a text messaging buffer overflow. That sort of thing generally makes the news these days.
I, like the parent poster, am running the latest update for my phone. Yes, I know I'm a walking vulnerability, but short of purchasing a new phone, there is nothing I can do about it. IIRC, updates for my device were cut off before it was even out of warranty, and I'm sorry, I'm not dropping — I can't drop — $600 every year and a half on new hardware just to get new software. Vendors need to support devices for the actual lifetime of the device.
It's really not your fault. But collectively we should care more about this and hold vendors accountable for continued security of devices they sold us.
AFAIK Microsoft and Red Hat are the only ones who do a good job of patching security bugs on older OSes.
You don't have to drop $600 every year and a half. Which would only be $34 a month over that period.
You can drop $600 every 3 years with google devices and have monthly security updates. You could save $17 every month for that 3 year time to buy the next phone.
If you want to stay secure you will, if it not a priority you wont.
The Pixels are incredibly overpriced given the hardware. I bought a Nexus 6P when they got under $400 and I honestly don't know what I'll do a year from now.
KRACK is essentially irrelevant, the security models of the OS and any sane applications will assume that the network is compromised (e.g. starbucks wifi).
I've got a Samsung S4 laying around that I hadn't used for years (it's 4 1/2 years old). Recently I fired it up just to check some things. As expected, it still runs beautifully for normal Web use across all sites. Other than the small form factor (which some people may prefer), it's easy to see how consumers might stick to older phones.
except for the old android I don't see any problems with my S4, so I'll be using it for another 2 years. And I actually prefer that size, it's easy to use with one hand
The S3 and S4 were pretty nice! Very slow flash, like every other Android back then, but good screens and very capable GPUs. (Since then screen size increases have outpaced GPU speed bumps, so modern phones don't always draw any faster.)
It's remarkable how fishy the whole ecosystem around Android ROMs and flashing tools really is.
95% of the posts are in barely comprehensible English. Seemingly every guide tells you to run a random binary from a file sharing host or generic domain.
As a rule, source code is non-existent. Downloads are attributable to a forum handle in the best case. Oh and you have to run it with elevated privileges to both your host computer and the device. Even the shadier warez communities have more accountability and trust.
In my opinion Google has really done a huge disservice by dropping support for their devices so rapidly and condoning planned obsolescence by handset manufacturers. They are directly responsible for channeling a significant fraction of Android users into this mess.
Yep. It's better than it was - most XDA developers understand what a GPL violation is.
I imported my Galaxy S8+ to save over $400AUD on retail. This meant I needed to find a ROM on an obscure site to flash to the phone using a stolen (?) piece of factory software. I can only trust my phone because a Samsung in default configuration won't accept a "modified" update - only one from and signed (?) by Samsung themselves.
Android is as mature as Windows XP, every vendor has their own where they customised everything and no-one has a pristine one. And also the pre-installed ROM is also often the same quality as the warez.
I trust the community on XDA composed of actual users and developers who are also users, more than the faceless corporation whose profit largely comes from extracting as much of your personal information as possible and monetising it.
They're not anonymous, they're pseudoanonymous, which also means carrying a reputation; and if anyone tries to deceive, the community is not entirely full of idiots, unlike what a lot of others in this subthread seem to imply --- all it takes is for someone to find out and provide proof, and the news will spread widely.
The fact that people seem to be scared of and are basically unwilling to make their own decisions of trust in deference to central authorities says a lot about the state of society today... "distributed trust" and communual free sharing was the norm, until companies started to herd users into their walled gardens and control them by using the "security" argument.
We are talking about a Nexus here so I can't really say that since it's Google but otherwise there's no guarantee that the ROM you have pre-installed does not have malware either.
Yes and I'm sure that most people have both the time and the technical acumen to go through every line of the source code and ensure that there are no security vulnerabilities