• grue@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 hours ago

    It’s ridiculous that this sort of fuckery is even possible, considering that it’s supposed to be Free Software.

  • sabreW4K3@lazysoci.al
    link
    fedilink
    English
    arrow-up
    13
    ·
    7 hours ago

    This is pretty fucking stupid. If OEMs are struggling with monthly releases, punish them, not general users. Android has made massive strides to make releases by OEMS quick and simple.

  • Turret3857@infosec.pub
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    1
    ·
    9 hours ago

    I don’t understand how in the fuck any of this situation makes sense. We’re closing AOSP, but OEMs (Graphene is an OEM now I guess) still get AOSP, but the changes can be reverse engineered… Why? What middle management fuckery is afoot here? Who do we need to be directing hate towards?

    • bus_factor@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      8 hours ago

      They don’t want to disclose vulnerabilities, because they know most people are not going to upgrade their ancient phone?

      • Turret3857@infosec.pub
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        7 hours ago

        Are you being /s? Genuinely, do you really feel just because vulnerabilities aren’t publicly exposed they can’t be exploited?

        • bus_factor@lemmy.world
          link
          fedilink
          English
          arrow-up
          8
          ·
          6 hours ago

          I made a guess at their official reasoning for the policy. I made no comment about my own feelings or beliefs beyond that. And no, I don’t think that would stop anyone.

          Do you have a better guess at why they’re doing this? Because I can’t think of another reason why they’d be sharing the patches but prohibiting disclosure of them.

          • sneaky@r.nf
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 hours ago

            Isn’t that common to not release how a vulnerability can be exploited publicly until you have it patched? Like yeah it won’t stop bad actors familiar with the space, but it would prevent normies like me jumping on the train.