← Back to context

Comment by holowoodman

9 hours ago

Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them. Usually under ongoing attack, at least by professional phone cracking software vendors and secret services.

>Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them.

Maybe if you include third party android OEMs like samsung, but google pixels are as up to date as you can get.

  • Pixels running GrapheneOS sure, but stock Pixels lag months behind patches that exist but not yet shipped. Check any bulletin and it links to git commits to months ago.

    • >Check any bulletin and it links to git commits to months ago.

      Is there any evidence that the git commits weren't in the ROMs from months ago? The monthly ASB corresponds to when the bugs are publicly disclosed, not when they made it into ROMs.

      1 reply →