Is it still safe to use as long as apps continue to be updated and is supported by the play store?

How long would you say someone could safely use an Android phone that no longer gets security updates for?

  • danielfgom@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    1 year ago

    Very, very safe. Android security levels are very high. Much higher than iPhone for example, because Google have a dedicated Security team testing it all the time. They even host Hackathons where people are invited to find holes and vulnerabilities.

    In any case Google can send important security updates via the Play Store as well. But most vulnerabilities found are never actually used in reality. They normally require physical access to the device, some kind of computer, complicated techniques. In other words nothing the regular person ever has to worry about.

    If you hear of anyone having a malware issue it’s because they went to a dodgy site and downloaded an APK and installed it manually.

    If you use your brain and only install apps from trusted sources, you’ll be fine.

    (Trusted sources: Google Play Store, F-Droid, uptodown.com)

    • henfredemars@lemdro.id
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      To expand on this, most vulnerabilities that require the vendor to actually participate by providing security updates are specific to your hardware configuration. These kinds of vulnerabilities are less attractive to most attackers because of their specificity. Attackers would much prefer to have a vulnerability that applies to many different victims, not just a specific kind. Android has gone to great lengths to update these commonly targeted components regardless of your vendor support status. Unless you believe you would be specifically targeted, the risk is fairly low.

      I’m not sure it’s fair to put iPhone down. They do take security very seriously, especially physical security with their formally verified bootloader. Not seeking a flame war. I just didn’t think it was accurate. Are we so sure they don’t have individuals focused on iPhone security at Apple? Compromised devices impact their brand image while the same bugs can be used for jailbreaking. I’m sure it’s very important. I interviewed with a team up there that I believe specialized in just that. Just recently Apple implemented an emergency security patching system for their devices to get security updates out even faster.

      Full disclaimer: I use both devices for software development. I have no special preference.