Android Phones Are Safer Than You Think, Says Google's Head Of Android Security.

All sorts of things that should be decoupled and easy to change and test aren't.

I'm not really sure what you mean. Applying the security updates is already quite easy. I work on Android OS development including kernel development and things like QA full-time, so I'm aware of what needs to be done.

ARM can't detect hardware to boot up modular drivers so when Qualcomm gives up on a chip it's effectively dead from the perspective of any commercial entity with hard liability.

You're tying together things that aren't related. Using device trees instead of hotplugging / auto-detection isn't a significant issue. Qualcomm giving up on an SoC platform is a problem because no one else is realistically going to take over serious maintenance of their open-source components and there are a lot of proprietary components where that's not possible. Laptops / desktop firmware, etc. is usually abandoned ASAP, but different standards are applied there. No one really thinks about issues like privilege escalation / remote code execution via firmware bugs and malware persistence via firmware bugs doesn't really matter when the operating systems don't even try to make use of stuff like verified boot anyway.

/r/Android Thread Parent Link - digitaltrends.com