Comment by artisinal

2 days ago

The recently released Fairphone 6+ runs on Android 16. I had to look that up on Wikipedia, their website doesn't even clearly state that. Android 16 is 14 months old at the moment. Android 17 was released to manufacturers 6 months ago and had a general release 2 months ago.

So why does a brand new phone run an operating system from over a year ago? Does it really take over 6 months to update a phone to a new version of Android?

How am I supposed to believe a company is committing to supporting a phone for a long time when at release it already runs outdated software?

I am a user. What does Android 17 do for me that 16 doesn't?

  • Since about 12 or so, it's been a series of cosmetic changes, bugfixes, and "AI" features.

    • Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that's decreasing. Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release. There have also been far more improvements than those. Being unaware of it doesn't mean it hasn't been done.

    • This is largely untrue.

      You would be missing out on:

      - Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs.

      - Restricted settings for sideloaded apps

      - Null-Cipher rejection and 2G disabling

      - Cell Network Surveillence Alerts

      - Platform Rust Migration

      - Scoped Media

      Among many many unpatched Med and Low severity CVEs that don't get backported.

      1 reply →

  • Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

    For those not aware, Android Security Bulletins only cover high/critical vulnerabilities. There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery. There was recently a GrapheneOS thread about it.

    • > There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery.

      These are not rumors. It's an official announcement from Google to OEMs and we have access to it.

    • > Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

      Aren't those back-ported for a while?

      2 replies →

  • Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that's decreasing. Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release.

  • [flagged]

    • Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that's decreasing. Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release.

I belive you are mistaken. Android 17 final was "released" 6-7 weeks ago.

But Google being Google, this release is pretty much useless until Samsung et al deal with all bugs and performance issues, which will take 2-4 months.

  • As a Linux, macOS and Windows user it’s really strange to me that you can’t just install the latest OS on your device. Even my iPhone updates to the latest version as soon as it’s released.

    • I dont know. Does your Linux distribution immediately upgrade to the latest kernel when Linus releases a new one?

      Besides, the phone software is highly optimised for the specific hardware. It is not a generic software like Windows

      4 replies →

Certification takes time and probably overlaped with the phone development. Fairephone is small compared to e.g. samsung and they describe themself more "stable" and long-term support than bleeding edge.

  • Fairphone 5 and earlier also have end-of-life Linux kernel branches without security support. Fairphone's more recent devices are headed to the same situation. In practice, the same thing happens with other components beyond the Linux kernel.

    Fairphones have 1-2 months of delay for partial security backports to older releases from the beginning and much longer delays for full updates. Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that subset is decreasing.

    Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release.

Even worse: Google actually does four releases releases per year (major and QPRs), of which QPR2 is also provided to OEMs. Only Samsung and GrapheneOS roll out QPR2 releases.

[flagged]

  • If this were genuinely 100% a Qualcomm limitation, I'd expect every Snapdragon 7s Gen 4 phone to be similarly stuck. But Motorola's Edge 70 Fusion uses the same SoC and was already in Android 17 beta testing in February, and Nothing's Phone (4a) and OnePlus Nord CE 6 are also slated for Android 17. So it seems the SoC isn't inherently preventing Android 17.

    • SoC vendor (and correcting myself, every componet vendor, such as camera, touch screen, flash controler, etc) must make the drivers available TO YOU to ship to your customers. picking out binary blobs and reusing is what grapheneos does, and ia highly frowned uppon and will get you blacklisted