Live data from Hacker News

LineageOS 19

lineageos.org

221–230 of 260 posts

Re: LineageOS 19

#221

Earlier quoted context omitted.

It is a hit or miss for me. But with TopJohnWu gone to google I wonder how long will Magisk last.

AIUI, Zygisk is a Google-approved variety of Magisk. The real issue with SafetyNet bypass is that it's inherently unreliable because Google could at any time require a locked bootloader running stock OEM ROM for passing SafetyNet, so any rooted device would be SOL.

From what I'm reading many newer devices require a locked bootloader, else SafetyNet will fail. So realistically I think that means only Pixel phones could work, since they support relocking the bootloader with a non-stock ROM.

Re: LineageOS 19

#222
post #106

Earlier quoted context omitted.

Lineage doesn't "break" android security model. It works around OEMs that don't support installing your own keys in the bootloader. Otherwise, security model works the same as any other android. LineageOS's first priority isn't security - it's freedom. Graphene and CalyxOS have security as the first priority - but have only a couple of phones on their support list and they deprecate old devices as soon as they stop r…

Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..

> pretend to support devices past their vendor EOL

They don't "pretend" anything. They are very clear that, after a device no longer gets kernel/driver updates from the manufacturer, they can only provide OS/framework updates.

> don't support locking the bootloader to enable verified boot on many supported devices

Can you expand on this more? My understanding was that you could do this on Pixel phones, but that no other manufacturer supports adding user keys to the bootloader.

Re: LineageOS 19

#223

I'm still pissed at Google for locking the bootloader on my Pixel 2. I bought the phone unlocked directly from Google, specifically so that I could install a custom ROM once Google stopped supporting it. But I sent the phone in to repair a broken USB port, and apparently it was Google's policy to send back a phone with a locked bootloader any time you get a repair. I can't even get a response from Google's support ab…

I wonder if you could take Google to small claims court to get some kind of monetary compensation from them. You'd have to figure out how to explain what a locked bootloader is in judge-friendly terms, though.

Then again, Google would probably terminate your Google Account if you did this. And good luck suing Google for retaliation...

Re: LineageOS 19

#224
post #222

Earlier quoted context omitted.

Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..

> pretend to support devices past their vendor EOL They don't "pretend" anything. They are very clear that, after a device no longer gets kernel/driver updates from the manufacturer, they can only provide OS/framework updates. > don't support locking the bootloader to enable verified boot on many supported devices Can you expand on this more? My understanding was that you could do this on Pixel phones, but that no ot…

Some do.

The point is, it's not as secure to run around with this disabled.

No, it's not only about in-person or targeted attacks.

Re: LineageOS 19

#225

Earlier quoted context omitted.

Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..

> They ship userdebug builds as production releases What specific security problem does this cause? > pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.) This is good for security. Not everyone can afford to get a new phone as soon as the vendor drops support, and just because you can't fix everything doesn't mean that you shouldn't fix…

> This is good for security

No, it isn't. It's good for reducing e-waste, your security is on the line.

Having the newly shaped and colored Android UI doesn't do anything to fix security issues..

Re: LineageOS 19

#226

Earlier quoted context omitted.

Always start here: https://source.android.com/security/ From another subthread: > They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to ena…

> Always start here: https://source.android.com/security/ I don't see any evidence for your claim there. > From another subthread: Replied in that one.

I'm pointing you toward how things are meant to work, not arguing with you or leading you through your research.

If you want to skip paying $150 for a Pixel to use on Graphene or Calyx or something halfway decent, and "just use Lineage how bad could it be", be my guest!

Re: LineageOS 19

#227
post #223

I'm still pissed at Google for locking the bootloader on my Pixel 2. I bought the phone unlocked directly from Google, specifically so that I could install a custom ROM once Google stopped supporting it. But I sent the phone in to repair a broken USB port, and apparently it was Google's policy to send back a phone with a locked bootloader any time you get a repair. I can't even get a response from Google's support ab…

I wonder if you could take Google to small claims court to get some kind of monetary compensation from them. You'd have to figure out how to explain what a locked bootloader is in judge-friendly terms, though. Then again, Google would probably terminate your Google Account if you did this. And good luck suing Google for retaliation...

Yeah, someone else suggested a class action, but as you said, retaliation is likely, and I've heard of Google banning entire businesses because an ex-employee's account got flagged, and I just don't want to risk that.

Also, given that you can get a used pixel 2 for under $100, I doubt it'd be worth the trouble in the first place.

Re: LineageOS 19

#228
post #98

I wonder how long until not having a safetynet approved (tm) phone is a serious hindrance in everyday life. Their effort is admirable but I can't help but think the tech world is moving in a different, darker direction.

In theory you can go here [1] and whitelist your phone to have a custom rom on your phone count as play protected. In practice it's another google service that doesn't work and you get no support for it when it doesn't work.

[1] https://www.google.com/android/uncertified/?pli=1

Re: LineageOS 19

#229
post #171

Earlier quoted context omitted.

What apps dont run for you? Everything is working fine for me. Are you also using Magisk with the DenyList enabled?

Uber maps are totally inaccurate when you try to zoom in/out with microG (even with Mapbox), unfortunately had to reinstall GApps because of this. Because of this I'd love to see GrapheneOS' sandboxed Google Play Services shims I'd love to see integrated into LineageOS.

Not sure if this is acceptable to you, but Uber has a web app at https://m.uber.com>. I seem to recall that you have to "request" access in order to use it, but it was an automated rubber-stamp thing. The only downside (besides what you'd expect for a web app vs a native app) is that you can't do fancy things like multiple destinations in one trip, or changing your destination on the fly.

The Lyft equivalent is https://ride.lyft.com>.

Re: LineageOS 19

#230
post #34

Earlier quoted context omitted.

I won't buy a phone that I can't run LineageOS on. MicroG. Life is too short to struggle and play games with the spyware that ships on phones by default nowadays. Better to be able to blow it all away.

> I won't buy a phone that I can't run LineageOS on. MicroG. I won't buy one that doesn't have an aux port. Do you know any lineage-supporting modern phones that have an aux port (and an SD slot, ideally!) by chance?

Google Pixel 5a has aux but no sd card
Post reply on HN