Live data from Hacker News

LineageOS 19

lineageos.org

151–160 of 260 posts

Re: LineageOS 19

#151

I'm still pissed at Google for locking the bootloader on my Pixel 2. I bought the phone unlocked directly from Google, specifically so that I could install a custom ROM once Google stopped supporting it. But I sent the phone in to repair a broken USB port, and apparently it was Google's policy to send back a phone with a locked bootloader any time you get a repair. I can't even get a response from Google's support ab…

The same thing happened to me, and I wrote an angry blog post about it[0] It is not OK for Google to lock me out of a phone that I own! LineageOS (running on a different device) has changed the game for me. It has been a smoother, more accessible Android experience, and I'm so grateful to the developers who make it happen. [0] https://jacobhall.net/2022/01/29/000177

Unfortunately, Lineage has abandoned a large number of previously-supported devices, so this latest version will be met with some dismay.

The primary reason is the loss of iptables, and the older kernels that do not support eBPF.

U.S. carriers are also moving to VoLTE, and this is not supported on any Samsung devices at all. AT&T has already made the move, and published a list of allowed devices.

It's sad to see them go.

Re: LineageOS 19

#152
post #92

Earlier quoted context omitted.

This is less useful than it sounds because there’s no integrated night vision, unlike even the cheapest ip cams. So really only works as a webcam.

How do you manage the battery? I would be afraid of a fire after x years being on all the time. Note that I have no specific knowledge on the subject ; it's quite possibly a fear without any reasonable ground. But I had a cheap speaker that I used with a Chromecast audio to listening to podcasts ; I left it always on and... I came back just in time one night, the speaker was producing a large dark smoke. I almost put…

I'd say most smartphones are powered on 24/7 during their regular phone lifetime. Not much would change by turning a phone into a 24/7 webcam, if viewed from that angle. Then again, CPU load would certainly be higher when used as a webcam.

Re: LineageOS 19

#153
post #37
post #10

I wish that LineageOS could accept the "signature spoofing" patch that is needed for microg (possibly with a toggle switch that would be "off" by default), so that we could avoid the need for the less-frequently-updated https://lineage.microg.org/ and properly install apps from Play Store without the Google Service Framework (that essentially give root access to Google on your smartphone). (and actually I also wish t…

You can install apps from Play Store through Aurora store without GSF. But I agree with your sentiment.

You can’t install paid apps and your google account can be terminated at any point for using Aurora store. So it’s out of the question for a lot of people

Re: LineageOS 19

#154
post #26

Earlier quoted context omitted.

I'm getting bi-weekly updates on LineageOS for MicroG (Xiaomi Poco F3), which I consider more than enough.

I have a Oneplus 5T (dumpling) and get much less frequent updates (which puzzles me : I though they would have an automated build system i.e. that all supported devices would have exactly the same updates at the same time...)

I have yet to jump to lineage with the 5T, does it run well? I've had so many phones have glitches like random reboots etc. before, I'm hesitant.

Re: LineageOS 19

#155
post #149

Earlier quoted context omitted.

I believe the reason Lineage doesn't do this (along with things like SafetyNet spoofing/passing) is to stay on the right side of Google et al. This way there's never a threat of a legal shutdown à la Vanced. If Lineage was backed by big foundations/folks with deep pockets that could change. I have no idea why GrapheneOS takes this risk, but am grateful to them nevertheless for the code.

Perhaps I'm not understanding the issue - what legal standing does Google have to object? "Terms of service violation"?

Partly that, but also a lot of/all of Google Services Framework is proprietary Google code. Other implementations reverse-engineer and modify it afaik. Google probably doesn't go after them because they're small, but LOS is the largest such organization and would be an easy target if Google were to sue.

And also, even if it's technically legal, it's such lawsuits/slappsuits can entirely bring down an organization as legal fees can be very expensive. They probably want to err on the side of caution so that Google can't, and wouldn't care to, sue them.

Re: LineageOS 19

#156

Earlier quoted context omitted.

How do you manage the battery? I would be afraid of a fire after x years being on all the time. Note that I have no specific knowledge on the subject ; it's quite possibly a fear without any reasonable ground. But I had a cheap speaker that I used with a Chromecast audio to listening to podcasts ; I left it always on and... I came back just in time one night, the speaker was producing a large dark smoke. I almost put…

I'd say most smartphones are powered on 24/7 during their regular phone lifetime. Not much would change by turning a phone into a 24/7 webcam, if viewed from that angle. Then again, CPU load would certainly be higher when used as a webcam.

Old phones with that streaming software run hot, in my experience, so this is certainly very sub-optimal for the battery and safety compared to just normal use.

Having it plugged in, OTOH, probably doesn’t matter. There’s safety IC to prevent overcharging. Actually fully draining, mechanical damage, water damage etc. are more dangerous, which can happen during normal use anyway.

Re: LineageOS 19

#157

I'm curious how secure LineageOS is. It doesn't seem to have the resources of Apple/Google to respond to vulnerabilities. I haven't even found anything on this topic at their website. Googling "lineageos security response policy" haven't found anything useful, either. How does it compare to flagship Samsungs/Pixels/iPhones? Is it usable in, say, corporate settings that do have some security standards in the vein of "…

Lineage actively and knowingly break the Android Security Model in order to achieve widespread compatibility and reduce e-waste. Security is not their top competency, nor mission. Check out the pages on GrapheneOS.org, definitely seems they're who you're after.

>Android is designed for developers. Security controls were designed to reduce the burden on developers. Security-savvy developers can easily work with and rely on flexible security controls. Developers less familiar with security are protected by safe defaults.

In addition to providing a stable platform to build upon, Android gives additional support to developers in a number of ways. The Android security team looks for potential vulnerabilities in apps and suggests ways to fix those issues. For devices with Google Play, Play Services delivers security updates for critical software libraries, such as OpenSSL, which is used to secure app communications. Android security released a tool for testing SSL (nogotofail) that helps developers find potential security issues on whichever platform they are developing.

Vs.

>Android is designed for users. Users are provided visibility into the permissions requested by each app and control over those permissions. This design includes the expectation that attackers would attempt to perform common attacks, such as social engineering attacks to convince device users to install malware, and attacks on third-party apps on Android. Android was designed to both reduce the probability of these attacks and greatly limit the impact of the attack in the event that it was successful. (Read: Handcuff users to keep them from violating developer expectations and assumptions)

>Android security continues to progress after the device is in the user's hands. Android works with partners and the public to provide patches for any Android device that is continuing to receive security updates. (Read: we work with developers (them again)* to provide patches to devices that are convenient to deliver patches to)

>More information for end users can be found in the Nexus help center, Pixel help center, or your device manufacturer’s help center. (Read: we take no responsibility for explaining how any developer's use of this power is exercised, ask them!)*

>This page outlines the goals of the Android security program, describes the fundamentals of the Android security architecture, and answers the most pertinent questions for system architects and security analysts. It focuses on the security features of Android's core platform and doesn't discuss security issues that are unique to specific apps, such as those related to the browser or SMS app. (Again, even when talking about users, the language drifts back to people we'd lump under developers... who exactly is the User here?)

Then this gem:

>Verified Boot strives to ensure all executed code comes from a trusted source (usually device OEMs), rather than from an attacker or corruption (oh, is corruption where user programs are classed under?).

It establishes a full chain of trust (for whom, OEM's again?), starting from a hardware-protected root of trust to the bootloader (whose root of trust, OEM?), to the boot partition and other verified partitions.

Sorry, but the language used to describe all of this completely lets the cat out of the bag on who the Android community holds to be the true benefactors of your "ownership" of a handset.

https://source.android.com/security/

Straight from the source. Quiet parts emphasized and said out loud by me.

Android is the most transparently User/operator hostile piece of Open Source software I have ever had the misfortune of laying my eyes upon. The fact you basically have to be a developer to list and understand the things you need to do to get anything non-trivial done speaks volumes.

Re: LineageOS 19

#158
post #94
post #82

I just switched to LineageOS 18 w/ MicroG and oh my lord is this stuff still complicated. I'm fairly familiar with this stuff and yet still it took me many hours to set everything up correctly. To be clear, this is not the fault of LineageOS, this is simply the state of the FOSS Android environment and the fact that Google has no interest in supporting this setup whatsoever, to put it mildly. Not only is it complicat…

You could just run an unrooted LineageOS? What exactly are you getting out of a rooted phone that you couldn’t get with a straight LineageOS install?

[deleted]

Re: LineageOS 19

#159
post #149

Earlier quoted context omitted.

Perhaps I'm not understanding the issue - what legal standing does Google have to object? "Terms of service violation"?

Partly that, but also a lot of/all of Google Services Framework is proprietary Google code. Other implementations reverse-engineer and modify it afaik. Google probably doesn't go after them because they're small, but LOS is the largest such organization and would be an easy target if Google were to sue. And also, even if it's technically legal, it's such lawsuits/slappsuits can entirely bring down an organization as…

Is this your speculation or is that their stated reasoning?

Re: LineageOS 19

#160
post #40
post #10

I wish that LineageOS could accept the "signature spoofing" patch that is needed for microg (possibly with a toggle switch that would be "off" by default), so that we could avoid the need for the less-frequently-updated https://lineage.microg.org/ and properly install apps from Play Store without the Google Service Framework (that essentially give root access to Google on your smartphone). (and actually I also wish t…

Having the sandboxed Google Play services would be wonderful. I'm currently using LineageOS with microG and Aurora store, but quite a lot of apps do not properly run with microG. Having some kind of fallback alternative in a second user or even better a work profile would be great.

What apps dont run for you? Everything is working fine for me. Are you also using Magisk with the DenyList enabled?
Post reply on HN