For some cheap phones even without the backdoor the some system components are unstable leading to a subpar experience.
For some cheap phones even without the backdoor the some system components are unstable leading to a subpar experience.
Are they trustworthy?
The centralised (corporatocracy) version of "trust" that is prevalent today one of the biggest obstructions to freedom IMHO.
But it felt that the community is far away from having plausible sources and builds.
I can understand that ultimately this begins with kernel sources that are already just a ZIP archive on some website.
Most are, yes, and the community is pretty good at pointing out the ones that aren't.
But the real question is are they any less trustworthy than Google itself and the phone manufacturers? From what I've observed, they are more trustworthy that that crowd.
Most ROMs are based off of either AOSP or lineage. The list of unofficially supported devices is huge. Since, most devices share the same SOC's they're usually just forked off of each other with gradual tweaks. The Sony open device project is semi supported by sony but doesn't share any code with the stock images.
So, that really just leaves the bootloader. How much attack surface does the boot rom actually provide? I feel like most vendors would probably just assume a backdoored system or boot partition. Your boot rom would have to accommodate for all kinds of potential Android versions. It sounds like a lot of effort for a corner case so not really worth the effort.
RedWolf [0] and OrangeFox [1] are both forked from TWRP and provide more features than upstream. Cyanogen and Lineage recovery are based on AOSP, again, with more features than upstream.
Also, don't get me started on the terrible security hygeine of the actual ROM distribution practices.