Live data from Hacker News

LineageOS 22

lineageos.org

61–70 of 166 posts

Re: LineageOS 22

#61
> Android 15 introduced several complex changes under the hood...

> Android’s move to trunk-based development, and the subsequent growth in size of Android’s QPRs (Quarterly Platform Releases) have made our job magnitudes harder! As a byproduct we must rebase our entire code-base every 3 months.

> Sadly, Google also has a habit of introducing deprecations or outright removing code that older devices rely on with little advanced notice...

Google trying new tactics to move Android from open-source to "source available, lol"?

Re: LineageOS 22

#62
post #61

> Android 15 introduced several complex changes under the hood... > Android’s move to trunk-based development, and the subsequent growth in size of Android’s QPRs (Quarterly Platform Releases) have made our job magnitudes harder! As a byproduct we must rebase our entire code-base every 3 months. > Sadly, Google also has a habit of introducing deprecations or outright removing code that older devices rely on with litt…

> Google trying new tactics to move Android from open-source to "source available, lol"?

It seems to be the opposite - more of AOSP internal development moving out into the open. QPR's are getting more frequent releases than the old AOSP code-drops.

(Tbh I do think that AOSP has always had way too much churn for a sensible system. A Linux phone should just work, and share as much of its codebase as possible with Linux systems running on other device classes; distributions like pmOS and Mobian - and quite possibly Debian Mobile in the future - are working towards this goal.)

Re: LineageOS 22

#63
post #42

Earlier quoted context omitted.

Isn’t that significantly on the Linux kernel not having stable driver ABIs?

They could also contribute to the Linux kernel like normal companies instead of shipping half broken binary blobs.

That's a really backwards way of thinking about software distribution. It's like Debian's idea that every piece of software in existence should be packaged for Debian (and Suse, Red Hat, Fedora, Ubuntu, etc.).

I don't package any of the software I write for Debian because I don't want to have to jump through their hoops. I don't blame device manufacturers for wanting to avoid jumping through Linux's hoops. Especially with having to deal with Linus.

Nobody likes Apple's app review process do they? I don't think device driver writers should have to go through that.

(I also wish they would open the code but not having a stable driver ABI clearly doesn't make that happen.)

I think a valid reason for not having a stable driver ABI is that it's a mountain of work and makes everything else more difficult. But I've never heard anyone give that as the reason.

Re: LineageOS 22

#64

Earlier quoted context omitted.

Some would consider a Google device as malware out of the box. At least you know who is spying on you I guess.

Given the fact that all phones have closed-source baseband firmware and are hooked up to vulnerable networks running ss7, they've got worse things to worry about if they're using a phone anyway.

It's not all or nothing. That's like saying you might as well smoke 20 cigarettes since you are already smoking 10.

Re: LineageOS 22

#65
Cool

My old oneplus 5T battery has just failed and I have bought a second hand Motorola edge 20 pro, which is supported for lineage 22.

Installing lineage has not got harder.

Only three extra adb commands:

fastboot flash dtbo dtbo.img

fastboot flash vendor_boot vendor_boot.img

and to populate the A-B slots:

adb -d sideload copy-partitions-20220613-signed.zip

Installation has remained pretty much the same process for years since I first installed it on my old Samsung S4 and motorola G3 and more recently my old pixel 4A and pixel 6A.

Long live Lineage

I dont like the /e/OS launcher (Bliss) either.

Lawnchair is in Droid-ify - izzyondroid repo

Re: LineageOS 22

#66

Earlier quoted context omitted.

I used to spend so much time flashing different ROMs, and even cooking a few modifications of my own. These days I find it much easier just to buy first-party devices like a Pixel and just move on with my day. They seem to have the least 'gotchas' in my experience. Stuff is unlocked, it gets updates, and doesn't have bloat/malware baked in.

Some would consider a Google device as malware out of the box. At least you know who is spying on you I guess.

Google is one of the lightest offenders in the ecosystem. Remember that any other Android device is going to have Google PLUS the manufacturer junkware. Pixels can also be de-rooted with custom firmware installed, and graphene is hella polished.

Re: LineageOS 22

#67
post #47

Earlier quoted context omitted.

Often device drivers specific to the model of handset are only available as pre-compiled binary blobs, and will not run with any future kernel release without herculean effort to reverse engineer them and implement a shim. This effectively ties the hardware to a single kernel release. The practice makes ewaste of otherwise perfectly usable devices, and should be illegal.

Any devices that fare better in this regard?

Not really, no. For manufacturers it is faster to just write the drivers once for their chip, and release them targeting to an exact Linux kernel version rather than actually writing good enough code that it goes through the LKML process and gets merged into mainline. It costs money to update the drivers later on and it especially costs money to mainline them later on.

Re: LineageOS 22

#68

I still buy devices based on the likelihood that they will be supported by LineageOS. Good to see them continuing along.

Out of curiosity, what do you buy? I had Xiaomi last and bought another one recently and they have made it pretty much impossible to unlock the bootloader. Apparently limited number of unlocks at 12am Beijing time. I have tried a few times, read through all the complaints and the community forums, and Xiaomi can very kindly just fuck off. It used to be really good value for money as the hardware is great. But without…

[deleted]

Re: LineageOS 22

#69
post #13

Earlier quoted context omitted.

Out of curiosity, what do you buy? I had Xiaomi last and bought another one recently and they have made it pretty much impossible to unlock the bootloader. Apparently limited number of unlocks at 12am Beijing time. I have tried a few times, read through all the complaints and the community forums, and Xiaomi can very kindly just fuck off. It used to be really good value for money as the hardware is great. But without…

Samsung has its own bootloader. Some people get it to work with AOSP/LineageOS, but it is an extra pain. So I avoid Samsung for LineageOS. This is a list of support devices https://wiki.lineageos.org/devices/ I installed LineageOS on a Motorola Edge a bit back. One problem is it takes a bit of time for a device to get officially supported by LineageOS. By the time it is, stores are often selling the next generation o…

My device is currently not supported, their FAQ about this is needlessly passive aggressive, though I can assume there's a reason.

Re: LineageOS 22

#70
post #32

Earlier quoted context omitted.

Good to know, as I still use an S5e as my comic reader. It's not getting security updates anymore, but to be honest it's not like I'm running banking software on it, so I don't care as much about malware risks as, say, my phone. It's still plenty speedy on stock firmware.

What would be the attack vectors for malware on a tablet? I’m genuinely curious how crucial updates are for older devices.

For example, there could be a web-based attack that would target unpatched webviews. This could be a maliciously prepared webpage or image on the web, favicon etc, and this piece of data could be distributed by an ad network, for example. So, browsing the internet with an out of date browser or webview could pose this risk.

Another issue is escalation. Again, we are in a speculative realm, but if a device is affected like how I described it above, it could then be the foot in the door for other attacks, like scanning the local network, and finding other devices to target, some of which might be also out of date, or be more trusting to a local device, than to an internet device. Like a router, for example, or a NAS with a passwordless LAN file share activated.

Another usage of an exploited device is it joining into a botnet, that then is rented out for any purpose the buyer would want, distribution of files, acting as a proxy for others, participating in a DDOS attack.

Thing is, most of this is automated actually. The devices on the internet are constantly scanned by automated means for vulnerabilities.

Post reply on HN