This is true in the sense that most android devices are small/cheap off brand or Chinese devices sold across low-income markets, like Africa and the Middle East. Any mid- or top-tier Android devices, such as Pixels and Galaxy devices which compete directly with Apple, are usually on a monthly security update cadence for at least 3 years.
A new Samsung Galaxy S22 (and above) has 5 years of support. 4 major Android updates and 1 year of security updates. For the Pixel 6/7/Pro (including the cheaper 6a), it's also 5 years, but only 3 major Android upgrades and 2 of security updates.
Not as good as an iPhone (5-6 years), but it's improving.
If you include years where you only get a security update, but not an OS update, then the 2014 iPhone 5s is still supported today, since it's last update was in August.
I don't know how to feel about those "security updates". That iPhone 5s is still running an outdated Safari browser, for example. The device isn't secure.
When I think about long term support, I'm thinking about the kind of support Windows, Linux LTS, etc, provide. When Apple, Samsung, etc, release the type of updates you mention, they're just fixing one of the many security problems the device has.
It's like fixing the lock on a door of a building full of broken windows and call it secure. I guess it's better than nothing, but it's not proper maintenance.
The changelog for iOS 12.5.6 mentions a fix for a Webkit exploit, so I guess Webkit was updated? The current version of Webkit/Safari doesn't run on iOS 12 (released in 2018) though (as far as I'm aware).
On a side note, if we want to use this a proof of good long term support, then Android is even better. Phones running Android 7 (2016) are using the latest Chrome/Webview version (108). The difference is that updates are delivered via the Play Store and not as system updates.
> The difference is that updates are delivered via the Play Store and not as system updates.
You're claiming that the security issue detailed in the article will be fixed through the Play Store, for devices no longer receiving updates from the device maker?
There are advantages to the iOS model of six years of full support followed by security updates for many years later, especially when an actively exploited issue is discovered.
> You're claiming that the security issue detailed in the article will be fixed through the Play Store, for devices no longer receiving updates from the device maker?
Yes. The Webkit equivalent (Webview) is updated via the Play Store ( https://play.google.com/store/apps/details?id=com.google.and... ). A bug on Webview would be fixed with an app update, which doesn't even require a restart. Makes sense if we think about it... we don't need a system update to update Chrome/Firefox/Edge/Safari on our computer.
On iOS, a fix or new features on the email, photos, phone, messages, etc, apps are presented as a security/new OS update. On Android, you get an app update.
It's not only apps, they can also update system parts. For example, if there's an issue with the "module" that deals with media, wifi/bluetooth, etc, Google can issue an update and the phone receives it via the Play Store. This article (scroll down) has a list of all modules that can be updated: https://blog.esper.io/what-is-project-mainline/ . I don't know if it's from Google or the different SoC makers, but they can also update things like GPU drivers on newer devices (the user obviously doesn't see any of this).
And Google can backport features without updates from the brand. For example, during the pandemic, Apple and Google added support for Covid apps... in Google's case, they released an update via the store and every phone going back to Android 6 (2015) got it. That's also how they added support for earthquake detection/warnings, nearby share (similar to airdrop), etc.
> There are advantages to the iOS model of six years of full support followed by security updates for many years later, especially when an actively exploited issue is discovered.
Long term support is good and Apple is ahead here offering 5 or 6 major updates. However, it's important to understand what these "security updates" bring.
The iPhone 5s isn't as secure as the iPhone 14 because iOS 12 isn't supported any more. This security update, which was essentially a browser update, reminds me of Microsoft releasing a patch for EOL Windows XP or Win 7 because some malware was taking computers left and right. They fixed one problem, but many remain and you can't consider XP to be safe.
I have used iPhones before (iPhone 5) and am aware of the benefits of Apple's system updates, but we're screwed when those 5 or 6 major updates end. Your browser might get a patch like this, but it's still outdated and doesn't support new web features. On Android, because they are detached from the system, the device maker could be out of business and your 6 year old device running an old Android build will have the latest Chrome, photo gallery, email, etc.
> A bug on Webview would be fixed with an app update
TFA isn't about web browsers. It's about the security keys for multiple vendors leaking to the public.
>Łukasz Siewierski, a member of Google's Android Security Team, has a post on the Android Partner Vulnerability Initiative (AVPI) issue tracker detailing leaked platform certificate keys that are actively being used to sign malware. The post is just a list of the keys, but running each one through APKMirror or Google's VirusTotal site will put names to some of the compromised keys: Samsung, LG, and Mediatek are the heavy hitters on the list of leaked keys, along with some smaller OEMs like Revoview and Szroco, which makes Walmart's Onn tablets.
These companies somehow had their signing keys leaked to outsiders, and now you can't trust that apps that claim to be from these companies are really from them. To make matters worse, the "platform certificate keys" that they lost have some serious permissions.
that's an important distinction. i don't have an android, but i get the sense that by "supported" we are talking about continuing to receive security updates. i am not sure my assumption is correct, though. do new samsung phones stop receiving security updates in 5 years?
You get at least 5 years of security updates with a new Samsung flagship[0]. During those 5 years, you'll use 4 major Android versions (there's a new one each year, like iOS). The last year of support is essentially security patches for the Android version released in the previous year.
On top of this, since Android 10 (2019), some security and feature updates come directly from Google (delivered via the app store) and continue after the brand stops supporting the device.
These security updates Apple, Samsung, etc, release years after the phone reaches end-of-life are a bit misleading. The update for the iPhone 5S fixed an exploit on Webkit, but everything else remains unpatched. Same with the update Samsung released for the Galaxy S7 (released before they had a 5 year support policy)... it fixed a GPS bug. That's it.
So while these updates are better than nothing, it's important to understand that the device is not up-to-date or secure.
---
[0] The 50-100 dollars device sold in low income markets won't have the same level of long term support as $500+ devices. We can't compare them to Apple here as Apple doesn't compete in that market.
I'll repeat myself: long term OS support is better on iPhones. With this said, we must look at what the "security updates" are fixing.
Above you mentioned that the 5S received a security update in August. According to the changelog, all they fixed was an exploit on Webkit (essentially the browser). They didn't even update Webkit/Safari to the latest version (it doesn't work on iOS 12).
Do you know how Android would handle that security update? A simple app update via the Play Store, no restart required. Someone running Android 7, which was released 2 years before iOS 12, is using the latest version of Webview/Chrome (108)... in this regard, Android is actually better than iOS.
There's a big difference between iOS and Android here. On iOS, things like Safari, Photos, Camera, Mail, etc, are part of the system and fixes/new features are presented as part of an updated OS. On Android these things are updated individually via the store and, if applying the same thinking as Apple, receive many "major updates" and many "security updates" every year.
Another point to consider when comparing updates is that since Android 10 (2019) different parts of the system get updates directly from Google ( see: https://blog.esper.io/what-is-project-mainline/ ). A security update for WiFi/Bluetooth, for example, may not need a system update from the OEM.
Android's fragmentation problem forced Google to come up with other ways to update Android. Even for features, many (eg: the alternative to airdrop, a feature to detect/warn about earthquakes, covid app support, etc) are backported to outdated devices without Samsung, etc, releasing system updates.
I don't deny that Android is messier behind the scenes than iOS or am even saying that you should buy an Android device... but it's not as bad as you seem to think.
Samsung improved it's update process (and probably pipeline?) dramatically in the past years[1] and the software became much better and more polished.
I received the Android 13 update in November and less than two weeks later another security update. This indicates to me that they roll out updates as fast as possible. Normally I get the monthly security update in the first half of the month.
EDIT: I should probably mention that I usually only buy Samsung's flagships but the midrange device are getting the same treatment AFAIK.
> I should probably mention that I usually only buy Samsung's flagships but the midrange device are getting the same treatment AFAIK.
I really don't have that kind of money to just drop on a phone that will inevitably fall from my pocket and break because it's too damn big. My phones cost less than 200€, and since they aren't samsung they get timely updates.
It got better in the past 2 years. The latest Pixel or Samsung gives you 5 years of support. 3 major updates + 2 years of security updates on the Pixel and 4 major updates + 1 year of security updates on a Samsung. An iPhone gets you 6 major iOS updates, I think.
It's taken them up to the past 2 years to still be this much less than a competitor? We've had smart devices like this since 2007. It took 13 years to get to a point of still being inferior.
Apple didn't start with 6 years of support. Everyone keeps improving.
Android has to play catch up because of the way it works and because OEMs don't control everything. Apple develops their own SoC, while most Android OEMs have to use a SoC from Qualcomm or Mediatek... which also need to support new Android versions. All this is improving... slowly. In other areas it has been better than iOS for years (eg: apps like the browser receive updates via the app store even after end-of-life, same with some Android features).
Everything has trade-offs. A $500 Windows laptop gets better support than my $3500 Macbook Pro, and we've had laptops for a long, long time. Still, I own a Mac. I also use Android because it lets me do more than iOS.
If Qualcomm stops supporting a particular chipset version after N years, all the Android OEMs that use Qualcomm chips can't do anything about it. Apple, however, builds their own SoCs, so they can support them as long as they want.
Google has recently managed to strike some better deals with Qualcomm to get updates for 5 years for the latest crop of Pixel devices. I agree it's still not as good as Apple, but that's just how market forces work, and shows you who has the most leverage.
I don't think anyone is trying to "impress" anyone; merely stating the facts as they are.
> Google has recently managed to strike some better deals with Qualcomm to get updates for 5 years for the latest crop of Pixel devices
The last 2 generations of Pixels use Google's own SoC (developed with Samsung?) called Tensor[0].
Google deserves some criticism here. The main force behind Android is now behind Apple and other Android brands. Samsung uses a mix of Qualcomm and Exynos, and their flagships get 4 major Android updates. OnePlus, which relies on Qualcomm and Mediatek, will do the same for "selected devices"[1]. A Pixel 7 only gets 3 major updates... at least the phone receives security updates for 5 years, but they need to improve.
I agree with this.
5 years seems like plenty until smartphones sufficiently plateau resulting in longer ownership.
I believe this is another case of HN's biases versus the 80-90% that the major players actually build for.
And ironically, I highly doubt the majority of the users here on HN use their devices through their EOL. They just like the idea, philosophically.
I'm still using my iphone 6s plus from 2015. Smartphones sufficiently plateaued for me a long time ago. It's a shame the rest of you fine folks find everything so inefficient ;-)
I'm guessing there's a generational aspect to this as well, and if the devices are the person's only compute device. The assumption on my part is that the younger users are the ones to upgrade quickly as it is upgrading their only compute device. For someone like me, I'll always prefer a desktop/laptop to use for the sheer usability aspect. I just hate the small screen and hunched over posture of using a phablet-like device. That's me and my opinion, and we all like different things.