logoalt Hacker News

dathinabtoday at 3:20 PM3 repliesview on HN

it's not that simple

to promise 5 year of security updates your SoC needs to also have that support for that time frame + part of your developmeant/production time (as you can't the last steps of development/production before that chip is released). Lastly you need to add the duration during which you promise the 5 years security updates.

to put it simple for a 5 year guarantee you need ~8 better 10 year support for the SoC, measured from is release date

a lot of phone SoC (which tend to get Android porting priority by their producer) have shorter support. Hence why the fp5 had a SoC from a product line designed for industrial embedded appliances instead of a phone SoC...

but the main reason is likely simpler:

They are relatively small and likely will updated FP5, 6,6+ to Android 16 roughly at the same time to not have to support multiple major Android versions for the same time.

Still as long as Android 15 still gets security this doesn't matter too much. Recent major Android version IMHO often have been more disruptive then helpful. At least for me, but my guess it's this applies widely for the kind of audience which pay more because they plan to actual have the same smartphone in use for more the 3 years ;)


Replies

microtonaltoday at 5:07 PM

Still as long as Android 15 still gets security this doesn't matter too much.

It does matter, because Android Security Bulletins only contain fixes for high/critical vulnerabilities. But all the other vulnerabilities can be useful in exploit chains. Add to that that ASBs have a three month embargo, but GrapheneOS and Samsung roll all/some patches out before they are in a security bulletin. So phones like the Fairphone have critical/high CVEs have been known for up to three months for anyone that looks.

but the main reason is likely simpler:

I think the main reason is that they do not do most hardware and software development by themselves, it's done by their Chinese ODM T2Mobile, for which Fairphone is probably just another customer.

Everything is at glacial speed. For instance, Android 16 on FP6 has some IPv6 bugs that breaks WiFi connections after a few minutes for a substantial number of their customers [1]. Six months later, they still haven't been able to properly fix it.

[1] The issues itself is probably not restricted to WiFi, it's that some brands of WiFi routers trigger one or more of the condition. One of which is sending a router advertisement with a lifetime of 0 for the IPv6 prefix used by the network. The connection handling code goes in a state where it misses the next prefix advertisement.

artisinaltoday at 3:24 PM

That sounds horrible. I can understand why Apple makes their own chips with the practices that these SoC manufacturers are getting away with.

Perhaps the EU can step in and force these SoC companies to change their way of working so that a user can simply install Android 17 with a few clicks regardless of their hardware (to a point). Like how desktop computers work.

show 1 reply