Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With iOS we have to trust/hope that Apple is doing the right thing. With Android we can audit the code. Yes, the early permissions model left a lot to be desired, and was subsequently revised. But we could always look at the OS source to see where things might be leaking. Unless, of course, these things are happening in the Google Framework level, at which point, we have to trust/hope that Google is doing the right thing.


Unfortunately more and more functionality has been moved into the closed-source Google Framework over the past few years. Some of this is a result of Android's terrible update situation: the only way for Google to get new software to many Android users is through software they can update, unlike the OS which OEMs control. But the fact that Google hasn't open sourced the Google Framework tells a lot about how "open source" Android really is. I wish we had a decent open source phone OS out there, since I don't trust Apple to produce good software (and increasingly, hardware) and I don't trust Google... well, I just don't trust Google. Our current duopoly is a pretty awful situation for consumers.


You can audit Android and see that it leaks like a sieve. Ever seen “read phone state and identity”?


I'll take your word for it, but my point is that you _can_ audit it. You can't audit iOS.


Well, you can’t audit the proprietary hardware drivers most android manufacturers use or the many proprietary apps from google etc that sit on top of android or the changes that the carriers make.

I remember when I was an Android developer dealing with several issues relating to the fact that one carrier put a proxy in the networking stack.

Here is a recent example:

https://www.theregister.co.uk/2016/11/15/android_phoning_hom...


You can audit iOS. Security researchers do it all day long.


audit the code?


AOSP is a far cry from Android. You can audit Chromium too, but in the transition to Chrome you have no idea what they changed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: