Earlier quoted context omitted.
The bad thing in general is the dependence on Google policy for all AOSP distros. Joining those programs might long term worsen the situation. IMHO, it could be worth the fight if GrapheneOS could win their (rather legal/lobbying) battle to obtain play integrity certification by following security closely (which is a joke IMHO because EOL phones with not updates for years also get integrity). Google releasing easily…
We have the sources for the patches which is how they get applied the source tree. We have both the regular releases and security preview releases so it's easy to see what was changed since it's a small amount of code: currently 59 security patches for Android 16, similar to the size of typical Android security patches, although 1 was already public elsewhere so we applied to the regular release. > does not even incl…
> Trusting third parties with this is a privacy and security risk.
Trusting Google with this is a privacy risk.