TechToDown All articles
Investigative Tech

Security Theater: Inside the Software Updates Quietly Crippling Your Old Devices

TechToDown
Security Theater: Inside the Software Updates Quietly Crippling Your Old Devices

Photo by Photo by Zulfugar Karimov on Unsplash on Unsplash

When your phone notifies you that a critical security patch is available, the socially responsible instinct is to install it immediately. You're protecting yourself, your data, your family. That's the implied contract. What the notification does not mention — what it is not legally required to mention — is that the update may simultaneously throttle your processor, compress your battery's effective lifespan, or quietly retire a handful of features your device handled without complaint just the day before.

This is not a conspiracy theory. It is a documented, recurring phenomenon that has drawn regulatory scrutiny in Europe, spawned class-action litigation in the United States, and produced a cottage industry of reverse engineers dedicated to mapping exactly what changes when a manufacturer pushes a patch. The evidence is substantial. The corporate accountability is not.

The Update That Wasn't Just an Update

In late 2017, Apple acknowledged what users and independent researchers had suspected for months: its iOS updates contained code that deliberately reduced processor clock speeds on iPhones with degraded batteries. The company framed this as a protective measure — preventing unexpected shutdowns — which was technically accurate but conspicuously incomplete as a public explanation. The throttling had been applied silently, without user notification or consent, and it happened to coincide with the launch cycle of newer, more expensive hardware.

Apple ultimately paid $500 million to settle a class-action lawsuit. It introduced a battery health dashboard and, for a period, offered discounted battery replacements. What it did not do was fundamentally alter its approach to software update transparency. The settlement resolved the legal exposure without establishing an enforceable precedent that would compel the company — or any of its competitors — to disclose performance trade-offs before users accept a patch.

That legal gap remains wide open today.

Reverse Engineers Are Keeping Score

In the absence of mandatory disclosure, a loose network of independent analysts has taken on the work that regulators have not. Using benchmarking tools applied to devices before and after update installations, these researchers have built longitudinal performance records that reveal patterns the manufacturers' own patch notes never mention.

Don Vandemark, a software performance analyst based in Austin, Texas, has been running systematic benchmarks on consumer devices for nearly six years. His methodology is straightforward: identical hardware units, controlled environments, standardized test suites applied immediately before and immediately after a manufacturer-issued update. The results, he says, are rarely ambiguous.

"The thermal throttling thresholds change. The background process scheduling changes. You'll see a device that was rendering a standard web page in 1.2 seconds suddenly taking 1.9 seconds after a patch, and the patch notes say nothing about performance adjustments," Vandemark explained. "The companies will tell you that's the security overhead. But the overhead is never quantified, never disclosed in advance, and it almost always disproportionately affects hardware that's two or three generations old."

This disproportionality is the crux of the accountability question. Security overhead is real — encrypting more data, running more verification checks, and closing exploit pathways all consume computational resources. But independent analysts argue that manufacturers have significant discretion in how they implement these measures, and the choices they make consistently favor outcomes that make older hardware feel inadequate.

The Plausible Deniability Architecture

What makes this practice so difficult to prosecute — legally or in the court of public opinion — is the layered ambiguity built into how updates are communicated. A patch note that reads "improved memory management and security enhancements" is technically defensible regardless of what the update actually does to device performance. No law in the United States currently requires a manufacturer to disclose that a security patch will reduce a device's benchmark scores by a measurable percentage.

The Federal Trade Commission has broad authority to pursue unfair or deceptive trade practices, but it has historically been reluctant to engage with software update conduct in a systematic way. The agency's 2022 report on commercial surveillance touched on data practices but did not substantively address the performance implications of mandatory or strongly encouraged updates.

State attorneys general have shown more appetite for the issue. A coalition of state-level investigations into planned obsolescence practices was quietly assembled in 2023, though no enforcement actions had been publicly announced as of this writing. The European Union's Right to Repair legislation, which came into force in 2024, includes provisions requiring manufacturers to maintain software support for longer periods — but it stops short of mandating transparency about what that software actually does to performance.

What the Companies Say — and Don't Say

TechToDown reached out to Apple, Google, and Samsung for comment on their update disclosure practices. Apple and Samsung did not respond. A Google spokesperson provided a statement noting that Android updates are subject to internal quality assurance processes and that performance impacts are evaluated before release. The statement did not address whether those evaluations are made available to consumers.

This silence is itself informative. Companies that genuinely believed their update practices were beyond reproach would have strong incentive to say so clearly and specifically. The absence of detailed, transparent response suggests an awareness that detailed scrutiny is not in their commercial interest.

The User Left Without Recourse

For the average American consumer, the practical situation is grim. Declining a security update is increasingly difficult — some devices pester users with daily notifications, others restrict access to certain applications or services until the update is installed. The choice, such as it is, amounts to accepting potential performance degradation or accepting potential security exposure. Neither option is acceptable, and neither should be the only options available.

What would genuine accountability look like? Researchers and consumer advocates have proposed several measures: mandatory pre-installation disclosure of any performance benchmarks affected by an update, independent third-party auditing of patch notes against actual update code, and a legal distinction between security-critical updates and performance-altering updates that happen to carry a security label.

Until any of those measures exist, the update notification on your screen is asking you to trust a company with a financial interest in your dissatisfaction. That is not a security patch. That is a business model wearing one as a costume.

TechToDown will continue tracking legislative developments and independent research on this issue. If you are a software engineer or performance analyst with documented evidence of update-related performance changes, contact our editorial team securely.

All Articles

Related Articles

The Delete Button Lie: What Cloud Platforms Actually Do With Data You Think Is Gone

The Delete Button Lie: What Cloud Platforms Actually Do With Data You Think Is Gone

Charging Chaos by Design: The Hidden Industry Strategy Behind Your Drawer Full of Useless Cables

Charging Chaos by Design: The Hidden Industry Strategy Behind Your Drawer Full of Useless Cables

The Privacy Illusion: How Silicon Valley Learned to Sell Surveillance as a Feature

The Privacy Illusion: How Silicon Valley Learned to Sell Surveillance as a Feature