Earlier quoted context omitted.
It is a hit or miss for me. But with TopJohnWu gone to google I wonder how long will Magisk last.
AIUI, Zygisk is a Google-approved variety of Magisk. The real issue with SafetyNet bypass is that it's inherently unreliable because Google could at any time require a locked bootloader running stock OEM ROM for passing SafetyNet, so any rooted device would be SOL.
LineageOS 19
221–230 of 260 posts
Re: LineageOS 19
#222Earlier quoted context omitted.
Lineage doesn't "break" android security model. It works around OEMs that don't support installing your own keys in the bootloader. Otherwise, security model works the same as any other android. LineageOS's first priority isn't security - it's freedom. Graphene and CalyxOS have security as the first priority - but have only a couple of phones on their support list and they deprecate old devices as soon as they stop r…
Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
They don't "pretend" anything. They are very clear that, after a device no longer gets kernel/driver updates from the manufacturer, they can only provide OS/framework updates.
> don't support locking the bootloader to enable verified boot on many supported devices
Can you expand on this more? My understanding was that you could do this on Pixel phones, but that no other manufacturer supports adding user keys to the bootloader.
Re: LineageOS 19
#223I'm still pissed at Google for locking the bootloader on my Pixel 2. I bought the phone unlocked directly from Google, specifically so that I could install a custom ROM once Google stopped supporting it. But I sent the phone in to repair a broken USB port, and apparently it was Google's policy to send back a phone with a locked bootloader any time you get a repair. I can't even get a response from Google's support ab…
Then again, Google would probably terminate your Google Account if you did this. And good luck suing Google for retaliation...
Re: LineageOS 19
#224Earlier quoted context omitted.
Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
> pretend to support devices past their vendor EOL They don't "pretend" anything. They are very clear that, after a device no longer gets kernel/driver updates from the manufacturer, they can only provide OS/framework updates. > don't support locking the bootloader to enable verified boot on many supported devices Can you expand on this more? My understanding was that you could do this on Pixel phones, but that no ot…
The point is, it's not as secure to run around with this disabled.
No, it's not only about in-person or targeted attacks.
Re: LineageOS 19
#225Earlier quoted context omitted.
Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
> They ship userdebug builds as production releases What specific security problem does this cause? > pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.) This is good for security. Not everyone can afford to get a new phone as soon as the vendor drops support, and just because you can't fix everything doesn't mean that you shouldn't fix…
No, it isn't. It's good for reducing e-waste, your security is on the line.
Having the newly shaped and colored Android UI doesn't do anything to fix security issues..
Re: LineageOS 19
#226Earlier quoted context omitted.
Always start here: https://source.android.com/security/ From another subthread: > They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to ena…
> Always start here: https://source.android.com/security/ I don't see any evidence for your claim there. > From another subthread: Replied in that one.
If you want to skip paying $150 for a Pixel to use on Graphene or Calyx or something halfway decent, and "just use Lineage how bad could it be", be my guest!
Re: LineageOS 19
#227I'm still pissed at Google for locking the bootloader on my Pixel 2. I bought the phone unlocked directly from Google, specifically so that I could install a custom ROM once Google stopped supporting it. But I sent the phone in to repair a broken USB port, and apparently it was Google's policy to send back a phone with a locked bootloader any time you get a repair. I can't even get a response from Google's support ab…
I wonder if you could take Google to small claims court to get some kind of monetary compensation from them. You'd have to figure out how to explain what a locked bootloader is in judge-friendly terms, though. Then again, Google would probably terminate your Google Account if you did this. And good luck suing Google for retaliation...
Also, given that you can get a used pixel 2 for under $100, I doubt it'd be worth the trouble in the first place.
Re: LineageOS 19
#228I wonder how long until not having a safetynet approved (tm) phone is a serious hindrance in everyday life. Their effort is admirable but I can't help but think the tech world is moving in a different, darker direction.
Re: LineageOS 19
#229Earlier quoted context omitted.
What apps dont run for you? Everything is working fine for me. Are you also using Magisk with the DenyList enabled?
Uber maps are totally inaccurate when you try to zoom in/out with microG (even with Mapbox), unfortunately had to reinstall GApps because of this. Because of this I'd love to see GrapheneOS' sandboxed Google Play Services shims I'd love to see integrated into LineageOS.
The Lyft equivalent is https://ride.lyft.com>.
Re: LineageOS 19
#230Earlier quoted context omitted.
I won't buy a phone that I can't run LineageOS on. MicroG. Life is too short to struggle and play games with the spyware that ships on phones by default nowadays. Better to be able to blow it all away.
> I won't buy a phone that I can't run LineageOS on. MicroG. I won't buy one that doesn't have an aux port. Do you know any lineage-supporting modern phones that have an aux port (and an SD slot, ideally!) by chance?