Live data from Hacker News

LineageOS will be a continuation of what CyanogenMod was

lineageos.org

31–40 of 118 posts

Re: LineageOS will be a continuation of what CyanogenMod was

#31
post #25

Who's going to make sure LineageOS users get security updates in a timely manner? Is anyone going to be paid to work on it? Any large OSS distribution is going to have a fairly continuous stream of security fixes to ship to their users, and that takes a fair amount of time, and I'm always concerned about whether any new project (okay—it's not quite new, but they have a fraction of the number of developers they did tw…

Not directly an answer, but one of the big issues with security patches for custom ROMs is the amount of patches they don't (read can't) ship. The proprietary blobs are very often not patched when the device is vendor-supported, and once it reaches end of life from the vendor (but the community ROMs give devices significantly extended longevity), there's no more patches to these blobs. Blobs incorporate the modem, ba…

Oh, that's totally true—though for many having some secure updates would be better than none, especially given the number of kernel bugs that are only locally exploitable (i.e., if the rest of the system is up-to-date, locally exploitable issues are less, but not none, of a concern).

One thing I wish there was more visibility of is "is this device still getting security updates", because there's often almost no visibility about that (and while you obviously can't say the vendor won't fix future vulnerabilities, you can say whether the vendor has fixed all known vulnerabilities), even online, yet alone anything pushed to the device to let its user know it is no longer secure.

e.g., http://web.archive.org/web/20161224231459/https://wiki.cyano... is the old CyanogenMod wiki page for the Galaxy S2: the last "development channel" (i.e., unstable) build is 2016-12-18, the last "release channel" (i.e., stable) build is 2015-11-16. There is nothing on the device page to suggest the stable build is known to be insecure (though given the number of Android bugs found in the last year unquestionably is!), yet alone anything about upstream vendors dropping support for the device and the unstable build being known to be insecure too. How is LineageOS going to do better than that? That's a damn low bar.

Re: LineageOS will be a continuation of what CyanogenMod was

#32

Earlier quoted context omitted.

There was more discussion recently at https://news.ycombinator.com/item?id=13249307 . Incompatibilities in Cyanogen Inc. leadership plus some bad deals, is what I gathered.

tl;dr Cyanogen Inc failed, and is pivoting away from ROMs. What I don't get is why they won't just give up the CM name/domain? Are they pulling an OpenOffice?

I suspect this was one of their biggest/only assets. I wonder (purely from a thought experiment point of view) how the original spin-out could have gone if the project had kept the name in trust and granted a worldwide exclusive license for a period of X years, where X was longer than the initial investment term, with a renewal option.

On the other hand, given what's gone down between both sides lately, it seems the split is somewhat less than civil, and holding onto the name and killing off the "annoying project which resents and criticises the company" might be suitably vindictive and designed to cause inconvenience to the project.

Re: LineageOS will be a continuation of what CyanogenMod was

#34
post #25

Who's going to make sure LineageOS users get security updates in a timely manner? Is anyone going to be paid to work on it? Any large OSS distribution is going to have a fairly continuous stream of security fixes to ship to their users, and that takes a fair amount of time, and I'm always concerned about whether any new project (okay—it's not quite new, but they have a fraction of the number of developers they did tw…

Not directly an answer, but one of the big issues with security patches for custom ROMs is the amount of patches they don't (read can't) ship. The proprietary blobs are very often not patched when the device is vendor-supported, and once it reaches end of life from the vendor (but the community ROMs give devices significantly extended longevity), there's no more patches to these blobs. Blobs incorporate the modem, ba…

[deleted]

Re: LineageOS will be a continuation of what CyanogenMod was

#35
post #25

Earlier quoted context omitted.

Not directly an answer, but one of the big issues with security patches for custom ROMs is the amount of patches they don't (read can't) ship. The proprietary blobs are very often not patched when the device is vendor-supported, and once it reaches end of life from the vendor (but the community ROMs give devices significantly extended longevity), there's no more patches to these blobs. Blobs incorporate the modem, ba…

Oh, that's totally true—though for many having some secure updates would be better than none, especially given the number of kernel bugs that are only locally exploitable (i.e., if the rest of the system is up-to-date, locally exploitable issues are less, but not none, of a concern). One thing I wish there was more visibility of is "is this device still getting security updates", because there's often almost no visib…

Absolutely - userland is the easiest to exploit, as it's fairly common across all devices (thanks to CTS and standardisation of the runtime) - that's why stagefright was such a big deal!

Definitely agreed - I've thought about making such a list to give visibility of this before, but it would be more of a user-submitted list (perhaps with link-up to screen scraping of OEM web pages for the ones that list the latest version).

What held me back was the sheer complexity of working out whether a device still gets updates - take Samsung as an example; the user says "I have a Galaxy S6". Depending on their geographical location this might be a carrier-free G920I or G920F. If they are in the US, it could then be one of about 5 or 6 variants, and there's even a G920W8 for Canada.

User wants to know if "Galaxy S6" is safe and secure, but even different regional firmwares of the same SKU might not be getting pushed security updates. And some US carriers (Verizon, ATT) are notorious for not pushing out updates to users. And then finally when you figure out the version on a given phone, you need to try to decide if the fact the device is still on October 2016 security patch means it's unsupported or not.

Often Samsung are lagging 2 to 3 months behind on some SKUs, making it even harder to tell. The same is true for many other OEMs - Sony have a pretty complex system of ROMs for each region, meaning you have carrier and non-carrier ones, and they can be on different versions.

To make this happen, we'd ideally need a single worldwide firmware without carrier changes/tweaks/influence. Until then, I suspect it would be too complex to help users work out if their device was being supported.

Re: LineageOS will be a continuation of what CyanogenMod was

#36

So is it time to buy a phone instead of my OnePlus One as it won't be updated anymore?

Beware of this if you are on a OPO running a Cyngn firmware:

https://www.reddit.com/r/oneplus/comments/5k8ppv/former_cyan...

Not really a brilliant source, but I'd be inclined to believe it in this case. It fits with my understanding of the situation.

Re: LineageOS will be a continuation of what CyanogenMod was

#37

Earlier quoted context omitted.

Yet somehow most stock ROMs are worse at maintaining security patches.

This. It's actually astounding, albeit hardly surprising, that companies often have zero interest in pushing security patches to devices not being manufactured anymore.

If/when it becomes a risk they must mitigate against (be that a financial or reputational risk), I guess they will.

Heck, until stagefright, Google didn't even release security bulletins. It was nigh-on impossible to keep track of all the vulnerabilities They only released security patches in new version releases. That wasn't good for vendors.

Now Google has pushed forward, and it's the turn of OEMs. They shipped patches to StageFright due to the massive bad PR (headline news in many countries, was a talking point amongst even the vaguely tech savvy).

Unless regulated or they feel they will lose money by not doing so, I don't imagine anything changing soon unfortunately. Qcom and other SoC makers are part of the problem too, since they try to drive chipset sales by only supporting older chipsets for a short time.

Re: LineageOS will be a continuation of what CyanogenMod was

#39

The name doesn't exactly roll off the tongue.

I agree -- it's almost as clumsy to pronounce as cyanogenmod, and the meaning isn't particular inspiring or evocative. HeritageOS? AncestryOS? FamilyOS? DerivationOS? Why do I want to use it, now?

Re: LineageOS will be a continuation of what CyanogenMod was

#40
post #30

The question is what will ensure the continual non-profitness of lineageOS? The problem is two fold: 1. Get maintainers. 2. Make sure that the high ranking individuals can't just "take the ball and go home", and (however unpopular this opinion may be here), GPL is the only way to ensure that they will never be able to sell out ever again. And especially after the CM/CyanogenOS/Focal/Paranoid Android situation, privat…

GPL is the route that OmniROM tried to go down, in order to attempt to ensure that the ROM remained community focused and true to its roots. One potential issue with CM is that users were signing contributor license agreements (CLAs) to the "project leads" of the "CyanogenMod Project" [1]. While everything is under Apache 2, which ensures it can be used in future, there were plenty of cases where people submitted cod…

That's the point. You can't aquihire Linux.

You can aquihire Linus, you can take his team, but any code you develop "in house" is going to have to go public anyways (because no one owns enough of the code).

Post reply on HN