Iimpawu zohlaziyo lwe-firmware yezixhobo eziphathwayo

Ukuba ngaba ukuhlaziya i-firmware kwifowuni yomntu kuxhomekeke kuye wonke umntu ukuba azenzele isigqibo.
Abanye abantu bafaka i-CyanogenMod, abanye abavakalelwa njengomnini wesixhobo ngaphandle kwe-TWRP okanye i-jailbreak.
Kwimeko yokuhlaziya iifowuni eziphathwayo, inkqubo kufuneka ifane, kungenjalo neRagnarok iya kubonakala imnandi kubantu be-IT.

Funda ngezantsi malunga nendlela oku kwenzeka ngayo kwihlabathi "loshishino".

Iimpawu zohlaziyo lwe-firmware yezixhobo eziphathwayo

Ubuso obufutshane Ngaphandle

Izixhobo eziphathwayo ezisekwe kwi-iOS zifumana uhlaziyo oluqhelekileyo olufana nezixhobo zeWindows, kodwa kwangaxeshanye:

  • uhlaziyo lukhutshwa kancinci rhoqo;
  • Uninzi lwezixhobo zifumana uhlaziyo, kodwa hayi zonke.

I-Apple ikhupha uhlaziyo lwe-iOS ngoko nangoko kuninzi lwezixhobo zayo, ngaphandle kwezo ezingasaxhaswanga. Kwangaxeshanye, iApple ixhasa izixhobo zayo ixesha elide. Ngokomzekelo, i-iPhone 14s ekhutshwe ngo-6 iya kufumana uhlaziyo lwe-iOS 2015. Ngokuqinisekileyo, kukho iingxaki ezithile, ezifana nokunyanzeliswa kokunciphisa izixhobo ezindala, ezithi, kuthiwa, zenziwe ukuba zinganyanzeli ukuba uthenge ifowuni entsha, kodwa ukwandisa ubomi bebhetri endala ... Kodwa nakweyiphi na imeko, oku kungcono kunemeko nge-Android.

Ngokusisiseko i-Android yi-franchise. I-Android yokuqala kaGoogle ifumaneka kuphela kwizixhobo zePixel kunye nezixhobo zohlahlo lwabiwo-mali ezithatha inxaxheba kwinkqubo ye-Android One. Kwezinye izixhobo kukho i-derivatives ye-Android kuphela - i-EMUI, i-Flyme OS, i-MIUI, i-UI enye, njl. Kukhuseleko lwesixhobo esiphathwayo, le yantlukwano yingxaki enkulu.
Umzekelo, "uluntu" lufumana obunye ubuthathaka kwi-Android okanye kumalungu enkqubo aphantsi kwayo. Okulandelayo, ubuthathaka bubelwa inombolo kwi-database ye-CVE, umfumani ufumana umvuzo ngenye yeenkqubo ze-bounty zikaGoogle, kwaye kuphela emva koko i-Google ikhupha i-patch kwaye ibandakanya ukukhululwa kwe-Android elandelayo.

Ngaba ifowuni yakho iya kuyifumana ukuba ayiyoPixel okanye inxalenye yenkqubo ye-Android One?
Ukuba uthenge isixhobo esitsha kunyaka ophelileyo, mhlawumbi ewe, kodwa hayi ngoko nangoko. Umenzi wesixhobo sakho kusaza kufuneka abandakanye isiziba sikaGoogle kwi-Android yakhe yokwakha kwaye ayivavanye kwiimodeli zesixhobo esixhaswayo. Iimodeli eziphezulu zixhasa ixesha elide. Wonke umntu kufuneka ayamkele kwaye angafundi i-database ye-CVE kusasa ukuze angonakalisi ukutya kwabo.

Imeko enohlaziyo olukhulu lwe-Android idla ngokuba mbi nangakumbi. Ngokomyinge, inguqulelo entsha enkulu ifikelela kwizixhobo eziphathwayo ezinesiko le-Android ubuncinci kwikota, okanye nangaphezulu. Ke uhlaziyo lwe-Android 10 oluvela kuGoogle lwakhutshwa ngoSeptemba ka-2019, kunye nezixhobo ezivela kubavelisi abohlukeneyo ababenethamsanqa ngokwaneleyo lokufumana ithuba lokuhlaziya balufumene kude kube ngehlobo lika-2020.

Abavelisi banokuqondwa. Ukukhutshwa kunye nokuvavanywa kwe-firmware entsha yindleko, kwaye kungekhona encinci. Kwaye ekubeni sele sithengile izixhobo, asiyi kufumana imali eyongezelelweyo.
Konke okuseleyo kukuba ... ukusinyanzela ukuba sithenge izixhobo ezitsha.

Iimpawu zohlaziyo lwe-firmware yezixhobo eziphathwayo

Ukwakhiwa kwe-Android evuzayo evela kubavelisi ngabanye kubangele ukuba uGoogle atshintshe i-architecture ye-Android ukuhambisa uhlaziyo olubalulekileyo ngokuzimeleyo. Le projekthi yayibizwa ngokuba yi-Google Project Zero, malunga nonyaka odlulileyo babhala ngayo kwiHabrΓ©. Eli nqaku litsha, kodwa lakhelwe kuzo zonke izixhobo ukusukela ngo-2019 ezineenkonzo zikaGoogle. Abantu abaninzi bayazi ukuba ezi nkonzo zihlawulelwa ngabavelisi bezixhobo, abahlawula i-royalty kubo kuGoogle, kodwa bambalwa bayazi ukuba akuphelelanga kwintengiso. Ukufumana imvume yokusebenzisa iinkonzo zikaGoogle kwisixhobo esithile, umenzi kufuneka angenise i-firmware yayo kuGoogle ukuze ijongwe. Kwangaxeshanye, uGoogle akayamkeli i-firmware ene-Androids zakudala ukuze ingqinwe. Oku kuvumela uGoogle ukuba atyhale iProjekthi yeZero kwintengiso, eya kuthi ngethemba yenze izixhobo ze-Android zikhuseleke ngakumbi.

Iingcebiso kubasebenzisi beenkampani

Kwihlabathi loshishino, kungekhona kuphela izicelo zikawonkewonke ezikhoyo kwiGoogle Play kunye ne-App Store esetyenziswayo, kodwa kunye nezicelo eziphuhliswe ekhaya. Ngamanye amaxesha umjikelezo wobomi bezicelo ezinjalo uphela ngexesha lokusayina isatifikethi sokwamkelwa kunye nentlawulo yeenkonzo zomphuhlisi phantsi kwesivumelwano.

Kule meko, ukufakela uhlaziyo olutsha lwe-OS kudla ngokubangela ukuba izicelo ezenziweyo ziyeke ukusebenza. Iinkqubo zoshishino zimisiwe, kwaye abaphuhlisi baphinda baqeshwe de kubekho ingxaki elandelayo. Kwenzeka into efanayo xa abaphuhlisi beenkampani bengenalo ixesha lokulungelelanisa izicelo zabo kwi-OS entsha ngexesha, okanye inguqulelo entsha yesicelo sele ikhona, kodwa abasebenzisi abakayifaki. Ngokukodwa, iinkqubo zeklasi zenzelwe ukusombulula iingxaki ezinjalo EMU.

Iinkqubo ze-UEM zibonelela ngolawulo olusebenzayo lwee-smartphones kunye neetafile, ukufakwa ngokukhawuleza kunye nokuhlaziya izicelo kwizixhobo zabasebenzi beselula. Ukongeza, banokubuyisela umva inguqulelo yesicelo kuleyo yangaphambili ukuba kuyimfuneko. Ukukwazi ukubuyisela umva uguqulelo luphawu olulodwa lweenkqubo ze-UEM. NoDlalo lukaGoogle okanye iVenkile yeApp ibonelela ngolu khetho.

Iinkqubo ze-UEM zinokuvala ukude okanye zilibazise uhlaziyo lwe-firmware yezixhobo eziphathwayo. Ukuziphatha kuyahluka ngokweqonga kunye nomenzi wesixhobo. Kwi-iOS kwimowudi egadiweyo (funda malunga nemowudi yethu FAQ) ungalibazisa uhlaziyo ukuya kwiintsuku ezingama-90. Ukwenza oku, misela nje umgaqo-nkqubo ofanelekileyo wokhuseleko.

Kwizixhobo ze-Android ezenziwe yi-Samsung, unokuthintela uhlaziyo lwe-firmware simahla okanye usebenzise inkonzo eyongezelelweyo ehlawulwayo ye-E-FOTA One, apho unokucacisa ukuba yeyiphi i-OS updates yokufaka kwisixhobo. Oku kunika abalawuli ithuba lokuvavanya kwangaphambili ukuziphatha kwezicelo zeshishini kwi-firmware entsha yezixhobo zabo. Ukuqonda ubunzima bale nkqubo, sibonelela abathengi bethu ngenkonzo esekwe kwiSamsung E-FOTA One, ebandakanya iinkonzo zokujonga ukusebenza kwezicelo zoshishino ekujoliswe kuzo kwiimodeli zesixhobo ezisetyenziswa ngumthengi.

Ngelishwa, akukho kusebenza okufanayo kwizixhobo ze-Android ezivela kwabanye abavelisi.
Unokwalela okanye uhlehlise uhlaziyo lwabo, ngaphandle kokuba mhlawumbi ngoncedo lwamabali othusayo, anje:
"Basebenzisi abathandekayo! Musa ukuhlaziya izixhobo zakho. Oku kunokubangela ukuba izicelo zingasebenzi. Ukuba lo mthetho waphulwa, izicelo zakho kwinkonzo yenkxaso yobugcisa AYISAYI kuqwalaselwa/imanyelwa!”.

Enye ingcebiso

Landela iindaba kunye neeblogi zenkampani ezivela kubavelisi beenkqubo zokusebenza, izixhobo kunye namaqonga e-UEM. Kulo nyaka nje uGoogle wagqiba ukwala ukusuka ekuxhaseni enye yeendlela ezinokwenzeka eziphathwayo, ezizezi zilawulwa ngokupheleleyo isixhobo esineprofayile yomsebenzi.

Emva kwesi sihloko side kukho le meko ilandelayo:

Ngaphambi kwe-Android 10, iinkqubo ze-UEM zazilawulwa ngokupheleleyo isixhobo И abasebenzi iprofayile (isikhongozeli), equlethe izicelo zeshishini kunye nedatha.
Ukuqala nge-Android 11, ukusebenza kolawulo olupheleleyo kunokwenzeka kuphela Okanye isixhobo Okanye iprofayile esebenzayo (isikhongozeli).

UGoogle uchaza izinto ezintsha ngokukhathalela ubumfihlo bedatha yomsebenzisi kunye ne-wallet yayo. Ukuba kukho isitya, ke idatha yomsebenzisi kufuneka ibe ngaphandle kokubonakala kunye nolawulo lomqeshi.

Enyanisweni, oku kuthetha ukuba ngoku akunakwenzeka ukufumana indawo yezixhobo zenkampani okanye ukufaka izicelo ezifunwa ngumsebenzisi emsebenzini, kodwa azifuni ukubekwa kwisitya ukuze kuqinisekiswe ukukhuselwa kwedatha yenkampani. Okanye ngenxa yoku kuya kufuneka ulahle isitya ...

UGoogle ubanga ukuba olu fikelelo kwindawo yobuqu luthintele i-38% yabasebenzisi ekufakeni i-UEM. Ngoku abathengisi be-UEM bashiywe ukuba "batye oko bakunikayo."

Iimpawu zohlaziyo lwe-firmware yezixhobo eziphathwayo

Silungiselele izinto ezintsha kwangaphambili kwaye siza kubonelela ngoguqulelo olutsha kulo nyaka Ifowuni ekhuselekileyo, eya kuthathela ingqalelo iimfuno ezintsha zikaGoogle.

Iinyani ezincinci ezaziwayo

Ukuqukumbela, iinyani ezimbalwa ezaziwayo malunga nokuhlaziya ii-OS eziphathwayo.

  1. I-Firmware kwizixhobo eziphathwayo ngamanye amaxesha inokuqengqeleka umva. Njengoko uhlalutyo lwamabinzana okukhangela lubonisa, ibinzana elithi "indlela yokubuyisela i-Android" likhangelwa rhoqo kunokuthi "uhlaziyo lwe-Android." Kubonakala ngathi ukuxutywa akunakubuyiselwa umva, kodwa ngamanye amaxesha kunokwenzeka. Ngokobuchwephesha, ukukhuselwa kwe-rollback kusekelwe kwi-counter yangaphakathi, enganyukiyo ngayo yonke inguqulo ye-firmware. Ngaphakathi kwexabiso elinye lale counter, ukubuyisela umva kunokwenzeka. Yile nto i-Android imalunga nayo. Kwi-iOS imeko yahluke kancinane. Ukusuka kwiwebhusayithi yomenzi (okanye izibuko ezingenakubalwa) unokukhuphela umfanekiso we-iOS wenguqulelo ethile yemodeli ethile. Ukuyifakela ngocingo usebenzisa i-iTunes, i-Apple kufuneka isayine i-firmware. Ngokuqhelekileyo, kwiiveki ezimbalwa zokuqala emva kokukhululwa kwenguqulo entsha ye-iOS, i-Apple isayinisa iinguqulelo zangaphambili ze-firmware ukwenzela ukuba abasebenzisi abasebenzisa izixhobo zabo emva kohlaziyo babuyele kwisakhiwo esizinzile.
  2. Ngexesha apho uluntu lwasejele lwalungekasasazeki kwiinkampani ezinkulu, kwakunokwenzeka ukutshintsha inguqulelo ye-iOS ebonisiweyo kwenye yezintlu zenkqubo. Ngoko kwakunokwenzeka, umzekelo, ukwenza iOS 6.2 ukusuka iOS 6.3 kunye nomva. Siza kukuxelela isizathu sokuba oku bekuyimfuneko kwelinye lala manqaku alandelayo.
  3. Uthando lwendalo yonke lwabavelisi benkqubo ye-firmware ye-Odin ye-smartphone ibonakala. Esona sixhobo silungileyo sokudanyaza asikenziwa.

Bhala, masithethe...mhlawumbi singanceda.

umthombo: www.habr.com

Yongeza izimvo