Live data from Hacker News

LineageOS 23.2

lineageos.org

41–50 of 64 posts

Re: LineageOS 23.2

#41
post #11

Earlier quoted context omitted.

Because it is more profitable for smartphone makers if you need to buy a new one. Unless there's legislation to force them to allow enrolling new keys or otherwise disabling secure boot, the abuse will continue.

This is true; there is additionally a valid argument that there is security benefit to locking down the bootloader. I don’t like locked down bootloaders, but I get the argument.

Yes, locked bootloaders secure the profits of the manufacturers who want to run crapware on your device for their benefit.

The hardware is theoretically yours but they won't allow you to use it in the way you want, it's shocking.

Re: LineageOS 23.2

#42
post #6
post #5

Earlier quoted context omitted.

LineageOS isn't unsigned, it just happens to be signed by keys that are not "trusted" (i.e., allowed - thanks for the correction!) by the phone's bootloaders.

thats effectively the same thing. The whole point of the majority of PKI (including secureboot) is that some third party agrees that the signature is valid; without that even though its “technically signed” it may as well not be.

>thats effectively the same thing.

No it's not. "Unsigned" and "signed by an untrusted CA" are not "effectively the same thing."

Re: LineageOS 23.2

#43
post #6

Earlier quoted context omitted.

thats effectively the same thing. The whole point of the majority of PKI (including secureboot) is that some third party agrees that the signature is valid; without that even though its “technically signed” it may as well not be.

>thats effectively the same thing. No it's not. "Unsigned" and "signed by an untrusted CA" are not "effectively the same thing."

To the bootloader? They absolutely are.

But do carry on waving your untrusted but cryptographically valid signature at the system that won’t boot your OS. I’m sure it’ll be very impressed.

Re: LineageOS 23.2

#44
post #40
post #37

Earlier quoted context omitted.

I don't know what's going on in this thread. Of course PKI needs some root of trust. That root HAS to be predefined. What do people think all the browsers are doing? Lineage is signed, sure. It needs to be blessed with that root for it to work on that device.

They're assuming PKI is built on a fixed set of root CAs. That's not the case, as others have pointed out - only for major browsers. Subtle nuance, but their shitty, arrogant tone made me not want to elaborate.

"Subtle nuance" he says, after I've spent multiple comments explaining that bootloaders reject unsigned and untrusted-signed code identically, whilst he and others insist there's some meaningful technical distinction (which none of you have articulated).

Then you admit you actually understood this the entire time, but my tone put you off elaborating.

So you watched this thread pile on someone for being technically correct, said nothing of substance, and now reveal you knew they were right all along but simply chose not to contribute because you didn't like how they said it.

That's not you taking the high road, mate. That's you admitting you prioritised posturing over clarity, then got smug about it.

Brilliant contribution. Really moved the discourse forward there.

Re: LineageOS 23.2

#45
post #44
post #40

Earlier quoted context omitted.

They're assuming PKI is built on a fixed set of root CAs. That's not the case, as others have pointed out - only for major browsers. Subtle nuance, but their shitty, arrogant tone made me not want to elaborate.

"Subtle nuance" he says, after I've spent multiple comments explaining that bootloaders reject unsigned and untrusted-signed code identically, whilst he and others insist there's some meaningful technical distinction (which none of you have articulated). Then you admit you actually understood this the entire time, but my tone put you off elaborating. So you watched this thread pile on someone for being technically co…

You seem angry. Perhaps some time away from the message boards would be beneficial.

Re: LineageOS 23.2

#46
post #45
post #44

Earlier quoted context omitted.

"Subtle nuance" he says, after I've spent multiple comments explaining that bootloaders reject unsigned and untrusted-signed code identically, whilst he and others insist there's some meaningful technical distinction (which none of you have articulated). Then you admit you actually understood this the entire time, but my tone put you off elaborating. So you watched this thread pile on someone for being technically co…

You seem angry. Perhaps some time away from the message boards would be beneficial.

Still not elaborating on that "subtle nuance," I see.

Re: LineageOS 23.2

#47

I'm still running this on my OnePlus 6T, purchased refurbished from ebay for $60. Runs fine. Using it degoogled, I'm not sure if e/OS or similar alternatives have any advantage. It can run PostmarketOS as well which I might play with at some point. The 6t allows bootloader locking if I sign it with my own keys, but I haven't tried that yet. A shame it is less supported on newer devices, but these older devices meet m…

Without any additional security patches something like the 6T will sound problematic for a lot of people here.

Maybe you care less about your software security and data on your phone?

Re: LineageOS 23.2

#48

I enjoyed LineageOS for years on my Samsung S4 until it finally broke from a fall. It's a shame there was no image to install on my new Xcover 7, but not unexpected as it was a newly released phone. But I doubt there will be an alternative/stripped Android available for this model as I haven't seen anything supporting a Xcover version anywhere. Best I can hope for is eventually a support for rooting and de-installing…

Note that Samsung devices with OneUI 8 remove bootloader unlocking altogether, making it impossible to 'root' the device or load LineageOS on it. The Xcover 7 is a newly released Samsung device that will most likely receive that update (it's live already in some regions), and even if you tried to stay on OneUI 7 the community is just unlikely to support it (as with other Samsung devices that are in the same boat toda…

I don’t understand why. Surely the person likely to install Lineage will simply avoid modern Samsung phones, whereas the average user remains unaffected. So all Samsung gets is a tiny drop in sales and worse public image amongst some users?

Re: LineageOS 23.2

#49
post #47

I'm still running this on my OnePlus 6T, purchased refurbished from ebay for $60. Runs fine. Using it degoogled, I'm not sure if e/OS or similar alternatives have any advantage. It can run PostmarketOS as well which I might play with at some point. The 6t allows bootloader locking if I sign it with my own keys, but I haven't tried that yet. A shame it is less supported on newer devices, but these older devices meet m…

Without any additional security patches something like the 6T will sound problematic for a lot of people here. Maybe you care less about your software security and data on your phone?

The 6T has mainline kernel support. Arguably, you shouldn't treat your phone as a secure device anyway. It's basically a toy from a real security POV.

Re: LineageOS 23.2

#50
post #11

Earlier quoted context omitted.

Because it is more profitable for smartphone makers if you need to buy a new one. Unless there's legislation to force them to allow enrolling new keys or otherwise disabling secure boot, the abuse will continue.

Third party roms also do not include all the bloatware and spyware they are loading into the phone, they aren't a fan of losing control.

** Spyware and bloatware that they are being paid to load onto the phone unfortunately
Post reply on HN