Live data from Hacker News

LineageOS 19

lineageos.org

211–220 of 260 posts

Re: LineageOS 19

#211
post #106

Earlier quoted context omitted.

Lineage doesn't "break" android security model. It works around OEMs that don't support installing your own keys in the bootloader. Otherwise, security model works the same as any other android. LineageOS's first priority isn't security - it's freedom. Graphene and CalyxOS have security as the first priority - but have only a couple of phones on their support list and they deprecate old devices as soon as they stop r…

Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..

> They ship userdebug builds as production releases

What specific security problem does this cause?

> pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.)

This is good for security. Not everyone can afford to get a new phone as soon as the vendor drops support, and just because you can't fix everything doesn't mean that you shouldn't fix what you can.

> ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates)

What's incorrect about it?

> don't support locking the bootloader to enable verified boot on many supported devices

This isn't really their fault. On most devices, relocking the bootloader with anything non-stock has a high chance of permanently hard bricking.

Re: LineageOS 19

#212

Earlier quoted context omitted.

> Lineage actively and knowingly break the Android Security Model Can you provide evidence for this?

Always start here: https://source.android.com/security/ From another subthread: > They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to ena…

> Always start here: https://source.android.com/security/

I don't see any evidence for your claim there.

> From another subthread:

Replied in that one.

Re: LineageOS 19

#213
post #103

Earlier quoted context omitted.

I really like LineageOS, but this is partly on them as well. They are the most popular ROM and they do very little to make this situation easier. With this situation I do not mean the install itself - actually there they do a lot, the documentation for officially supported devices is really good (and you often do not need TWRP anymore, the lineage recovery is cleaner). But I mean everything else you mention: Rooting,…

What's the problem with VoLTE?

Seems like it does not work with all devices and it also depends on the provider. It creates lots of uncertainty.

Re: LineageOS 19

#214
post #173

Earlier quoted context omitted.

You didn't need to transfer application data, swapping ROM/OS shouldn't touch that.

Doesn't unlocking the boot loader delete everything?

Sorry I was ignoring that unlocking the bootloader will do that.

However if you're flashing a ROM or upgrading an already unlocked phone you do not need to format it.

Re: LineageOS 19

#215
post #180

Earlier quoted context omitted.

>LineageOS's first priority isn't security - it's freedom. But, importantly, they also care about security, and you'll get security updates faster and more often than with the vendor's stock ROM.

Applying security patches to something that doesn't even do verified boot seems...hmmm

Sure, because security is boolean. Either something is secure, or it is not.

This is sarcasm, to be clear.

(on my device, it is possible to just "fastboot oem lock", but that is aside the point)

Re: LineageOS 19

#218
post #187
post #75

If you are reading this, thank you for backporting to kernel 4.4! My phone is only a year and a half old. I'll just wait for the OpenGapps to have at least an unofficial 12.0 version to upgrade, so I can keep using the minimal Gapps required and not bloat my phone with crap I'll never use like Gmail or Youtube.

MindTheGapps is a decent alternative that supports Android 12.

I know, but don't they include a very big collection of GApps? I only need the pico distribution from OpenGapps.

I could install everything and then uninstall via adb, but still, I'd rather wait.

Re: LineageOS 19

#219
post #98

I wonder how long until not having a safetynet approved (tm) phone is a serious hindrance in everyday life. Their effort is admirable but I can't help but think the tech world is moving in a different, darker direction.

[deleted]

Re: LineageOS 19

#220
post #98

I wonder how long until not having a safetynet approved (tm) phone is a serious hindrance in everyday life. Their effort is admirable but I can't help but think the tech world is moving in a different, darker direction.

For me, it already is. I use Google Pay extensively, which checks SafetyNet during regular operation, and I hear the Netflix app even disappears from the Play Store if the phone fails SafetyNet. (Sure, you can install it from APKMirror or whatever, but...) I expect some other banking apps on my phone wouldn't work either.
Post reply on HN