16
submitted 1 week ago* (last edited 1 week ago) by MTK@lemmy.world to c/cybersecurity@sh.itjust.works

Hi, I have a pixel 4a that I love and works great (with CalyxOS) I bought it when it came out and I really don't want a new phone, but...

Security updates from google stopped for the 4a about a year and a bit ago, and for the last year I have been slowly getting more and more anxious while trying to ignore it. I'm still getting the android security updates (software) for another year or so (thanks calyx!) But I'm not getting the firmware security updates anymore.

I'm experienced in the field of cyber security and I feel like I'm in denial because I really really don't want to buy a new phone.

Please tell me if I really should get a new phone or not...

My threat model would be just an average person but with the added paranoia of knowing too much about privacy and security, and my avoidance of getting a new phone is mostly rooted in zero-waste ideology and the pure hate towards google for forcing me to stop using a great phone that would otherwise probably be usable for another few years.

you are viewing a single comment's thread
view the rest of the comments
[-] smpl@discuss.tchncs.de 5 points 1 week ago

Your system is fully updated from at least the kernel/initramfs and up. Next you're running a system that has additional security measures.

So this breaks down to: What is firmware and are you aware of any issues in it? If no then there's no reason to get a new phone.

I'm not aware of any firmware security issues for any Android phone assuming firmware is pbl, sbl, aboot, modem or on-chip and even if there was they would be hard to exploit given your up to date and hardened system, but that's all theoretical and also apply to any new phone you would purchase.

[-] MTK@lemmy.world 1 points 1 week ago

Thank you ๐Ÿ™

this post was submitted on 11 Dec 2024
16 points (94.4% liked)

Cybersecurity

5834 readers
150 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS