Live data from Hacker News

LineageOS 23

lineageos.org

111–120 of 188 posts

Re: LineageOS 23

#111
post #75
post #73

Earlier quoted context omitted.

> I'm mostly happy with my GrapheneOS device - but it is absolutely not suitable for mass market. What makes you say that? I run GrapheneOS on a Pixel and had to go through the relative simple flashing process, but if GOS came preinstalled on a device anybody familiar with Android (or even iOS) would be able to use it. Compatibility with Android apps is great too.

Off the top of my head: Lots of banking apps don't work. RCS has only just started working. No "Find My Device" support. Permissions model is difficult to understand - even I struggle with it. Standard launcher has tiny icons which can't be adjusted. Pop on to https://discuss.grapheneos.org/ and see the struggles which users have.

What is the issue with the permission model. It's basically the AOSP permission model. The changes made by GrapheneOS is the user-facing toggle for the INTERNET permission, and the sensors permission.

If people do not want to interface with those features, they can simply skip them, and the permission model will be the exact same as it is on Android.

Re: LineageOS 23

#112

Earlier quoted context omitted.

Why the scare quotes? Graphene’s focus on security is legitimate and well founded. They are the only phone OS that is consistently safe from hacking by the likes of Cellebrite long after all other androids have fallen.

Let's define "more secure" as "preventing a particular behavior that is against the device owner's conscious or unconscious wishes". It would be "more secure" to have a per-application firewall that blocks particular apps from outbound traffic over certain networks or to certain destinations. This prevents a malicious app from consuming roaming data. LineageOS can have that, at the owner's preference. Graphene explic…

>It would be "more secure" to have a per-application firewall that blocks particular apps from outbound traffic over certain networks or to certain destinations. This prevents a malicious app from consuming roaming data.

LineageOS can have that, at the owner's preference. Graphene explicitly forbids it.

Not sure what is meant by forbidding it? GrapheneOS provides per-app network access control via a user-controllable Network permission which is not implemented in AOSP or LineageOS afaik. They do not forbid using local firewall/filtering apps like RethinkDNS (to enforce mobile data only or Wi-Fi only iirc) and InviZible. They only warn that 'blocks particular apps from outbound traffic ..to certain destinations' cannot be enforced once an app has network access which makes sense to me.

>It would be "more secure" to allow backing up apps and all their data. This would mitigate the damage of ransomware. Graphene, again, forbids it (following google guidelines prioritizing the wishes of an app's developer over the device owner).

Contact scopes, storage scopes, the sensors permission and the network permission are examples that show precisely the opposite (GrapheneOS prioritises the device owner over the application developers). To my understanding, the backup app built-in to GrapheneOS even 'simulates' a device-to-device transfer mode to get around apps not being comfortable with data being exfiltrated to Google Drive. That being said, I understand they have plans to completely revamp the backup experience once they have the resources to do so.

Re: LineageOS 23

#113

Note, GrapheneOS seems to have been able to secure partner access to Android early security releases, but this comes with the cost that the source used to make these special "01" builds is private until general availability. This might not be a tradeoff that LineageOS is willing to take; GrapheneOS has provided the option on a recommended opt-in basis. https://discuss.grapheneos.org/d/27068-grapheneos-security-p...

As far as I have heard they have not actually secured partner access for themselves, they just got someone who has access to break their NDA.

I don't know the exact terminology, but they described what they currently have as security partner access or at least advanced access to security patches. To my knowledge they are still working on full partner access that would grant them timely access to the AOSP source code.

Re: LineageOS 23

#114
post #40

Any way to get this to run in a VM? Or should I give up and buy a phone that can handle it and use it through remote desktop tools?

The article to which you're commenting has two whole paragraphs on the newly introduced support for virtualisation and qemu.

Re: LineageOS 23

#115
post #40

Any way to get this to run in a VM? Or should I give up and buy a phone that can handle it and use it through remote desktop tools?

There is a guide on how to set up LineageOS for libvirt (i.e. QEMU) [1], but there exist no prebuilt images at this point in time. [1] https://wiki.lineageos.org/libvirt-qemu

The requirements are monstrous: 300GB storage, 32GB RAM. My everyday working laptop has a 240GB SSD. I've build the kernel, Firefox, and the heaviest packages which I use from sources with a fraction of those resources.

I can't even fathom what the build system is doing in order to require this amount of storage.

Re: LineageOS 23

#116
post #58

I'd love to see a hybrid phone with an embedded stock android for banking, pay and government apps and a regular LinageOS or Linux OS that runs on a separate partition/hw/vm. Like "gluing" two phones together - just better ;) It would be great to run an open OS but having to carry a separate phone for banking/paying is not really a viable option.

Banking, pay and government apps should be a website and work on any device with a web browser.

Re: LineageOS 23

#117
post #116
post #58

I'd love to see a hybrid phone with an embedded stock android for banking, pay and government apps and a regular LinageOS or Linux OS that runs on a separate partition/hw/vm. Like "gluing" two phones together - just better ;) It would be great to run an open OS but having to carry a separate phone for banking/paying is not really a viable option.

Banking, pay and government apps should be a website and work on any device with a web browser.

Lots of them are, in fact. It's not that hard, maybe even easier. What's wrong with the rest of them that require a phone?

Re: LineageOS 23

#118

Somewhat related: I could never get adb in my M1 Air (Tahoe and Sonoma too) to detect any android devices. I have an OnePlus Nord CE 2 Lite 5G. Same cable and everything works fine on Ubuntu and Windows machines. The phone is not getting detected in the "System Information" either. Tried MTP, PTP, USB Debugging, OTG everything. Anyone faced this issue?

Your Chrome-based browser might be blocking the port that adb uses.

Re: LineageOS 23

#119
post #116

Earlier quoted context omitted.

Banking, pay and government apps should be a website and work on any device with a web browser.

Lots of them are, in fact. It's not that hard, maybe even easier. What's wrong with the rest of them that require a phone?

NFC pay in browser? Does that exist?

Re: LineageOS 23

#120
post #81

Well, this looks nice. Tons more devices than Graphene or Postmarket supported. Which hardware should one get to run this? Which hardware is reasonably ethical? Perhaps the Fairphone 5? There are lots of choices from Motorola and OnePlus but I know nothing about them. (Well I remember the old Moto up to Y2k.) Not sure where to buy them.

With reasonable ethical you indeed might want to look into the Fairphones. The Fairphone 6 was reviewed as being a nice improvement over the 5. I'd expect LineageOS to land on that device some time in the future, after all the prior three models are supported. You could wait for that, or settle for the 5. If you want something cheap and easy instead of the Fairphone, the Motorola moto g 5G (2024) looks good. Supporte…

Thanks! Oh, I forgot to ask about the hardware working in the US? Also, does Lineage force you to make an account somewhere?

I see the Murena, which I think is the same hardware. But their page says the bootloader is locked. Hmm, think that's a no-go. https://murena.com/america/shop/smartphones/brand-new/murena...

Post reply on HN