Earlier quoted context omitted.
This. It's actually astounding, albeit hardly surprising, that companies often have zero interest in pushing security patches to devices not being manufactured anymore.
This is why for the first time since I started owning smartphones (2010), I am going to switch to iPhone.
LineageOS will be a continuation of what CyanogenMod was
21–30 of 118 posts
Re: LineageOS will be a continuation of what CyanogenMod was
#22Why is Cyanogen shutting down?
Re: LineageOS will be a continuation of what CyanogenMod was
#23Re: LineageOS will be a continuation of what CyanogenMod was
#24Re: LineageOS will be a continuation of what CyanogenMod was
#25Who's going to make sure LineageOS users get security updates in a timely manner? Is anyone going to be paid to work on it? Any large OSS distribution is going to have a fairly continuous stream of security fixes to ship to their users, and that takes a fair amount of time, and I'm always concerned about whether any new project (okay—it's not quite new, but they have a fraction of the number of developers they did tw…
Blobs incorporate the modem, baseband firmware, bootloaders, and many (most?) of the hardware drivers and imaging drivers.
51% of Android kernel vulnerabilities in vendor drivers are a result of missing or incorrect bounds checks, and over the whole Android kernel, 44% of all vulnerabilities were missing bounds checks, and 12% for null pointer dereference.
Looking across the whole kernel, from Jan 2014 to April 2016, 85% of kernel bugs are born in vendor drivers, with the remainder in the core kernel.
Vendors therefore are shown to write bad code. It's fairly safe to assume this is reflective of the quality of their blobs too - there's certainly a load of vulnerabilities in those if you look at the Android Security bulletins for bugs without a source reference for the fix.
So agreement with your concern, but I'd just like to highlight that custom ROMs are not really a good security solution, as there's just so much to fix (at a kernel level, requiring detailed driver knowledge of the vendor/SoC stuff), and blobs that won't get updated after the vendor abandons the phone.
Ref: https://events.linuxfoundation.org/sites/events/files/slides...
Re: LineageOS will be a continuation of what CyanogenMod was
#26What's the background on this? Why is Cyanogen shutting down?
Re: LineageOS will be a continuation of what CyanogenMod was
#27When exactly will cm shut down? Until when will I be able to get the freshest nightlies of CM14.1?
http://www.androidpolice.com/2016/12/24/cyanogen-shutting-se...
At some point before 31st December (at the latest), according to their blog post. In reality, their website is down right now. Downloads and other sites are up, but the blog is down.
Re: LineageOS will be a continuation of what CyanogenMod was
#28What's the background on this? Why is Cyanogen shutting down?
There was more discussion recently at https://news.ycombinator.com/item?id=13249307 . Incompatibilities in Cyanogen Inc. leadership plus some bad deals, is what I gathered.
What I don't get is why they won't just give up the CM name/domain? Are they pulling an OpenOffice?
Re: LineageOS will be a continuation of what CyanogenMod was
#29Earlier quoted context omitted.
This is why for the first time since I started owning smartphones (2010), I am going to switch to iPhone.
That's not going to fix the problem. Installing updates on an iPhone older than a couple years bogs performance down to unusable levels.
Re: LineageOS will be a continuation of what CyanogenMod was
#30The question is what will ensure the continual non-profitness of lineageOS? The problem is two fold: 1. Get maintainers. 2. Make sure that the high ranking individuals can't just "take the ball and go home", and (however unpopular this opinion may be here), GPL is the only way to ensure that they will never be able to sell out ever again. And especially after the CM/CyanogenOS/Focal/Paranoid Android situation, privat…
One potential issue with CM is that users were signing contributor license agreements (CLAs) to the "project leads" of the "CyanogenMod Project" [1]. While everything is under Apache 2, which ensures it can be used in future, there were plenty of cases where people submitted code under the copyright of the project (see headers which state "Copyright (C) 2016 The CyanogenMod Project").
You are correct with point 2 - if you want to prevent "acqui-hire" type takeovers, you need to ensure that there isn't a tight-knit group of individuals willing to agree and sign over the rights.
This situation would be very, very different if the original CM project had taken a better approach at the start - perhaps forming a 501(c)3 for the holding of the cyanogenmod.org domain and any trademarks/name rights. Then a commercial license could be granted to the incorporated form of CM.
I wish I could find a good primary source, but best I can see at the moment are fairly blog-type news sites [2]. The issue we see here is that the project's stewards were turning their focus from the project to the "commercial spinout", rather than in keeping the project going. At that point, there's little that the contributors could do really - it seemed the leaders had made the decision to build the inc version, despite high profile disagreement. Not sure GPL would fix that, but it certainly helps ensure a community project can live on, even if it won't guarantee it will.
[1] https://review.cyanogenmod.org/static/cla_individual.html
[2] http://www.androidheadlines.com/2013/09/author-cyanogenmods-...