Tech Behind ThingsHow the ordinary machinery actually works

Software

Why your device stops getting updates long before it stops working

Support ends because a chain of suppliers stops publishing code, not because the hardware became incapable.

A dual screen setup showcasing programming code and image editing software.
Photograph by Pixabay via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Treat the sections below as a sequence. With software support lifetimes, getting the early decisions right makes the later ones much easier.

Before you start

  • Updates depend on drivers and firmware from chip suppliers, not only the device maker.
  • Security patches and feature updates are separate things with separate lifetimes.
  • Stated support periods are increasingly published and are worth checking before buying.

The update chain has several owners

A finished device runs code from the chip designer, the modem supplier, the display and camera vendors and the company whose name is on the box. Each layer must be maintained for the layer above it to ship a fix, and a supplier that stops publishing driver updates blocks everyone downstream.

This is why a device can be abandoned while its processor is still perfectly capable of running current software. It is a supply chain problem dressed up as an obsolescence problem.

Security updates are not feature updates

A security patch closes a specific defect and usually changes nothing you can see. A feature update changes the interface and the capabilities and carries far more risk of breaking something.

The short version: many manufacturers offer a longer window for security fixes than for feature releases, which is a sensible split. A device receiving security patches but no new features is in a supported state, not an abandoned one.

Vulnerabilities are found continuously

Flaws in widely used components are discovered constantly and disclosed on a coordinated timetable so fixes can ship first. Once a fix is public, the defect it repairs is public too, which makes unpatched devices measurably easier to attack. The risk therefore rises after a patch is released rather than before, which is the opposite of intuition.

At the protocol level, a device out of support becomes progressively more exposed with every disclosure cycle it misses.

Why manufacturers set an end date

Testing an update across every model, region and carrier variant is expensive and grows with the size of the back catalogue. Extending support ties engineers to old code instead of new products, and the commercial incentive runs the other way. Regulation in several markets now requires minimum support periods to be stated or provided, and the requirements differ substantially by jurisdiction.

The visible effect has been longer published commitments, which is the useful outcome for buyers.

Alternatives after support ends

Community-maintained operating systems extend the life of some hardware, at the cost of effort and of features that depend on proprietary components. Firmware that cannot be replaced, such as modem and secure element code, remains unpatched regardless of what runs above it.

Mechanically, repurposing a device for a task that does not involve untrusted input, such as a music player or a local sensor display, sidesteps most of the risk. Keeping an unsupported device off the network is the crude version of the same idea and it works.

What to check before buying

Look for a stated number of years of security updates and a separate figure for feature updates. A published commitment is enforceable in a way that a marketing claim about longevity is not. Devices built on widely supported platforms tend to receive community support after the vendor stops, which is worth something.

Mechanically, for anything embedded in a building, such as a doorbell or a thermostat, the support period matters far more than the specification.

The takeaway

The hardware is fine. Someone further up the supply chain stopped shipping code.

Understanding the failure mode tells you more than the feature list does.

Questions readers ask

Is an unsupported phone actually dangerous to use?

The risk rises over time as unpatched flaws accumulate and become publicly documented. It is a gradient rather than a cliff, and it is worst for anything handling messages, payments or logins.

Why can a five-year-old computer get updates when a phone cannot?

Desktop platforms have standardised drivers and a long tradition of vendor-independent support. Phones use tightly integrated custom silicon whose suppliers stop publishing code much sooner.

Softwareupdatessecurityfirmwaresupport
Junko Ishida
Contributing writer, Tech Behind Things

Junko covers batteries, charging and energy density, and is unimpressed by most battery claims.

Also by Junko Ishida