Earlier quoted context omitted.
Lineage doesn't "break" android security model. It works around OEMs that don't support installing your own keys in the bootloader. Otherwise, security model works the same as any other android. LineageOS's first priority isn't security - it's freedom. Graphene and CalyxOS have security as the first priority - but have only a couple of phones on their support list and they deprecate old devices as soon as they stop r…
Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
What specific security problem does this cause?
> pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.)
This is good for security. Not everyone can afford to get a new phone as soon as the vendor drops support, and just because you can't fix everything doesn't mean that you shouldn't fix what you can.
> ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates)
What's incorrect about it?
> don't support locking the bootloader to enable verified boot on many supported devices
This isn't really their fault. On most devices, relocking the bootloader with anything non-stock has a high chance of permanently hard bricking.