07-16-2022 08:33 AM
07-18-2022 01:29 AM
GT500No we arent, because depending on manufacturer that patch has been applied way before the google patch has (as demonstrated above). This is why you can't really compare microsofts updates to googles security updates.https://zentalk.asus.com/en/discussion/comment/219246#Comment_219246
We appear to be talking about two different things here. You're talking about how long it takes Google to patch a vulnerability, and I'm talking about how long it takes device manufacturers like ASUS to give us those patches. With most operating systems updates like that come directly from the company that makes the operating system (Windows Updates for instance), however with Android the device manufacturer needs to deliver the updates to the customer' devices via firmware updates. Most device manufacturers have been publishing monthly firmware updates for their devices for 5-10 years now, but ASUS appears to be going back to refusing to do that just like they used to.
Even if Google takes a while to patch a vulnerability they don't usually make information about it publicly available until they've patched it. Once a vulnerability is patched and the information about it is public knowledge, it becomes trivial to make exploits for it (unless it is difficult to exploit) and the vulnerability can be weaponized by malicious actors. It is important that device manufacturers deliver these patches to their customers' devices in a timely manner, and waiting several months to do so leaves customer devices vulnerable for an extended period of time.
The patch level of your phone tells you which patches are installed. That's its purpose, as documented by Google (the makers of Android).
View post
07-18-2022 02:30 AM
DanishbluntThe manufacturer can't patch a vulnerability that Google doesn't if they aren't even updating their devices. ASUS isn't even giving us the monthly security updates that Google is releasing, whereas Samsung is giving their customers those monthly security updates. Also, just because Samsung patched a vulnerability before Google did doesn't mean that ASUS is doing the same thing.https://zentalk.asus.com/en/discussion/comment/219251#Comment_219251
No we arent, because depending on manufacturer that patch has been applied way before the google patch has (as demonstrated above). This is why you can't really compare microsofts updates to googles security updates.
Sometimes ASUS doesnt update the security patch from google because they already did before google added it inside their security package. Much like samsung added the fix for the vulnurability mentioned above long before google did.
You cannot compare lets say a redmi phone with security patch july with a samsung with security patch july, the samsung has way more fixes and patches than the redmi. If all phones were streamlined, like windows updates are then ud have a good point, however they arent, the difference in exposure to vulnurabilies is massive.
if you want fixes, unlock bootloader and flash kernels like kirisakura and a custom OS like lineageOS.
View post
07-18-2022 03:50 AM
GT500Wrong. everyone has access to the repos, if google ignores commits that are important to the security, then it's not the manufacturers problem. They can recompile their firmware as much as they want.https://zentalk.asus.com/en/discussion/comment/219253#Comment_219253
The manufacturer can't patch a vulnerability that Google doesn't if they aren't even updating their devices. ASUS isn't even giving us the monthly security updates that Google is releasing, whereas Samsung is giving their customers those monthly security updates. Also, just because Samsung patched a vulnerability before Google did doesn't mean that ASUS is doing the same thing.
As for LineageOS, a volunteer would have to make firmware images for your device, and ASUS phones don't usually get support from them. Oddly enough someone does appear to have made a firmware image for the ROG Phone 3, however I don't want to risk bricking my phone in the hopes that I'll somehow get better support from an open source project via firmware images made by a volunteer.
View post
07-18-2022 04:35 AM
DanishbluntYou seem to be quoting random articles about how Google didn't patch a vulnerability fast enough, and claiming that this is somehow proof that third-party phones are somehow more secure than vanilla Android even if they don't bother distributing security patches every month. I'm reasonably certain that you don't know what you're talking about, and I think it's time to end this conversation and stop hijacking this topic.https://zentalk.asus.com/en/discussion/comment/219265#Comment_219265
Wrong. everyone has access to the repos, if google ignores commits that are important to the security, then it's not the manufacturers problem. They can recompile their firmware as much as they want.
ASUS did patch before google did on some occasions. You can verify that yourself on their kernel sources on the support page.
GSI Roms are always compatible from the getgo, so you could also use those, LineageOs was just an example from my side. Also there are way more roms than you think:
https://www.youtube.com/watch?v=ypeWCFiHhrE
Also another issue alltogether, you seem to be under the impression that being up 2 date every month is somehow significantly more secure than every 2 months, I hate to dissapoint you but the amount of vulnerabilities that are high and critical are still extremely high after you updated to the very latest security update. Wheter you have 3500vulnurabilities or 3450 doesnt really change that much.
Another thing u're completely disregarding is this:
https://www.samnews24.com/2022/07/07/samsung-july-2022-security-patch-details-released/
Depending on system youll be exposed to even more exploits and the manufacturer have to deal with them on their own as well. For all you know Oneplus might have an insanely critical exploit from their side while your android secure package might be updated to July.
Google sometimes cant really be bothered to add critical fixes either:
Honestly, I dont even know why you make a big deal out of it. wheter its 1 month or every 1.5month, makes no difference.
View post
07-18-2022 01:26 PM
trevorjr84How brave of you to still want a phone from ASUS after this shitshow.https://zentalk.asus.com/en/discussion/62072/fix-for-volte-on-android-12-for-rog-phone-3
Thanks for being honest. It's a shame Asus didn't let it's customers know that the were issues with this update. Or if Asus knew there were issues... Address them BEFORE the release. Pathetic honestly... Definitely delaying my ROG phone 5 order.
View post