← Back to context

Comment by mapontosevenths

2 days ago

I am a user. What does Android 17 do for me that 16 doesn't?

Since about 12 or so, it's been a series of cosmetic changes, bugfixes, and "AI" features.

  • Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that's decreasing. Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release. There have also been far more improvements than those. Being unaware of it doesn't mean it hasn't been done.

  • This is largely untrue.

    You would be missing out on:

    - Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs.

    - Restricted settings for sideloaded apps

    - Null-Cipher rejection and 2G disabling

    - Cell Network Surveillence Alerts

    - Platform Rust Migration

    - Scoped Media

    Among many many unpatched Med and Low severity CVEs that don't get backported.

    • > Minimum Target SDK Enforcement Blocks installation of apps that target ancient versions of Android and legacy APIs.

      Funny to list a user-hostile change as the first “improvement” that comes to mind.

      I guess GP should have said “series of cosmetic changes, and breaks in your UI habbits and a few of your apps deemed too old”.

Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

For those not aware, Android Security Bulletins only cover high/critical vulnerabilities. There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery. There was recently a GrapheneOS thread about it.

  • > There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery.

    These are not rumors. It's an official announcement from Google to OEMs and we have access to it.

  • > Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

    Aren't those back-ported for a while?

    • Android Security Bulletins are a list of the High and Critical severity patches backported to older Android versions. At the time a bulletin is published, the patches have been available to OEMs to ship for 2-4 months. Fairphone is nearly always 1-2 months behind the latest bulletin but it can get much worse over time.

      Android Security Bulletins do not cover the vast majority of Linux kernel security patches. They only cover an extremely small subset tied to Android. The Linux kernel has a massive tsunami of security patches on an ongoing basis. Fairphone 5 and earlier have an end-of-life Linux kernel without security support. They're close to not updating the kernel at all anymore. Their more recent devices will end up in the same situation.

      The Linux kernel is not the only component ending up unmaintained while the devices are still presented as supported.

Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that's decreasing. Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release.

[flagged]

  • Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that's decreasing. Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release.