LineageOS Android Distribution
lineageos.org
lineageos.org
I know I can get unofficial builds, put apart from the sometimes quite severe missing features (calling or camera not or only partially working) I don't want to trust random people on a forum to provide a build of an OS without including malware. It just looks like a prime target for all the intelligence services of the world, and a nice target for hackers. With official builds there's at least some accountability somewhere to mitigate this.
Samsung is similar in this regard, though they get away with it somewhat more than HTC due to demand.
In short, don't complain to/about Lineage. Vote with your pocket and buy more open phones.
I've been using HTC devices for ages, and so far every one of them was dead-simple to unlock: Just go to the HTC developer page and enter your phone ID, get unlock code and enter on phone, done! Naturally HTC will from there on out decline responsibility for bricked phones, but which company doesn't?
> Naturally HTC will from there on out decline responsibility for bricked phones, but which company doesn't?
The fact that this is an accepted norm is another part of the problem. Why "naturally"? Some manufacturers (like Google, Fairphone, Motorola on a limited number of phones) don't void the warranty, but even if none did: why do you think this "naturally" an acceptable thing other than it being the norm?
If you don't damage the hardware by flashing, there's no reason it should be out of warranty. If you do "damage" it because of some malicious hardware fuse installed by the manufacturer, then it seems to me that could reasonably be considered a faulty device.
But flashing itself can also go horribly wrong due to poor bootloader quality etc.
Because I want to be allowed to install software that will damage the phone. Holding the phone manufacturer responsible for code I wrote is not in fact a natural thing to do.
I'm sorry but I'm really struggling to understand what you mean by this. What hardware should I be running the code I write on without fear of voiding the warranty.
If it's the fact I wrote the code that constitutes voiding the warranty, exactly who's code should we be permitted to run on hardware we've purchased? Only code which has been written by/provided by the manufacturer themselves?
What's the precedent for this absurd restriction?
I agree with this wholly. Devices like iphones or the samsung devices are riddled with user-hostile features like KNOX, locked bootloaders, pre-installed payment gardens and proprietary blobs all over along with carrier locked, contractually defined handset ownership agreements.
The state of open smartphones is rather nacient, checking the wikipedia list page[0] there hasn't been a real handset launched in numbers for 3 years. I would describe the availability of these devices at best as Very Poor.
That said, HTC is much better for open firmwares than the big ones like apple or samsung. You can just ask and they will return the bootloader key. Try that with Samsung, they are horrible. Samsung is a very integrated vendor, and it can be quite challenging to develop for these very closed platforms, the software sometimes takes ages.
Case in point the Galaxy s6. The verizon locked phones still have no public bootloader unlock tooling afiak. Quite a hassle.
Currently the only Openish devices you might be able to get soonish are ( In the order of my own arbitrary bias )
- PinePhone (Pre-Production Developer Kits Shipped) [1]
- Librem 5 (Production Batches Shipping) [2]
- Necunos NC 1 (Released, Unavailable?) [3]
Unless I've left any out.
0 - https://en.wikipedia.org/wiki/List_of_open-source_mobile_pho...
1 - https://www.pine64.org/pinephone/
Fairphone 3 doesn't quite fit the bill, but I'd still mention it in lists like these as it is possible to unlock bootloader, the phone is modular so can be repaired, and the Fairphone 2 ran a myriad of OSes (#3 just got released, give it some time).
There some threads here a couple weeks ago and on r/Purism, but it appears they have shipped 0 phones to customers so far. There are just a handful of pre-production units given to employees. Unfortunately it also sounds like they have spent all, or nearly all of the money they raised in crowdfunding, so how they are going to ship all the backorders is unknown.
While some will be happy with one of these three options, some will find it a step too far from mainstream, low maintenance high end options.
With this in mind, it's important to make recommendations across the spectrum, to encourage those not willing to go "all the way" to still go some of the way.
In this area, I'd look at Fairphone (not great on the high end cutting edge tech side for obvious reasons, but decent on openness), Motorola and One+ (both more mainstream high-end options but also not quite as heavy on user-hostility as some competitors).
Google are also quite good in this area, on the hardware side, but given their ownership of the software side and general practices in that area, I'd be in less of a hurry to recommend them.
I'm certainly not trying to fanboy here (Samsung cameras suck [0]), just pointing out that all manufacturers are intrinsically inclined to deploy some user-hostile features. "Voting" with your wallet doesn't particularly move their needles.
[0] More precisely their software support sucks, making the picture quality terrible. https://news.ycombinator.com/item?id=21082561
AICP really let me down only once: I'm semi-religiously doing the weekly security updates. Once that broke the installation, because it was a major version upgrade (I think Oreo to Nougat). I suppose I should have wiped and installed it manually, but the AICP update center just enqueued it like a regular security update.
There are unofficial builds of this [1] but lineage doesn't want to endorse this approach, even though that's technically how they support all recent devices.
https://forum.xda-developers.com/project-treble/trebleenable...
And that still means that with five images you target several hundreds (probably thousands) devices. More than lineage will ever support
And drilling down to the most popular phone for your country seems to turn up a fairly well supported model. I ended up with a Moto Z2 Force (https://wiki.lineageos.org/devices/nash) for pretty cheap, and I've been happy with it.
This is the reason that I've only bought Google's handsets. Easy to unlock and always excellent ROM support. Flawless LineageOS support and I have also very good experiences of GrapheneOS (former CopperheadOS).
I buy them when the next model (or the model after that) is out for a fraction of the price. Couldn't care less about getting the latest phone these days. At this level they're pretty much all the same to me.
Only thing to look out for is Google's crappy long term support and security fixes (which even GrapheneOS relies on). For my current Pixel 1 device OS updates were supposed to run out over a year ago. Still, Android 10 was "just" released for the Pixel 1...
Huh? The most recent Google phone with LineageOS support is the Pixel. The first one, from 2013.
Why is it some communities still work like this? With Android dev, sometimes there's even some source on GitHub, but still a forum post is the main place to find the latest version, with the actual download from some questionable-looking download site. If you're lucky they include sha hashes at least.
I've installed a handful of custom ROMs on 3 or 4 devices - most recently resurrecting my old TF101 to run modern Firefox - but I don't think I've ever seen anything like an automated build for one of these. Really, many don't even post source code.
Is there anyone doing this type of Android dev in a "modern" best practices way like most other open source (public git, CI, maybe issue tracker and pull requests)? Why doesn't this catch on more?
For my own ROM [1] I spent days and a hundred of euros optimizing the cost of building by trying various cloud providers (fwiw my current best spot is scaleway GP instance with 600GB local SSD). As of today, I'm still at 6€ per builds (For standard ROM devs, that should be cut down to 2€ I'd say). There is simply no way I can afford a CI. (well if someone wants to give me money for that, please do!) I do my best to isolate components and have at least some kind of CI where I can, but that's hard work (And doing CI is my day job, and I consider myself rather good in it)
Even android's own CI is very far from what you'd call a modern CI. They basically just build master once every hour and pray for the best, and let the build cop fix that. They do have a mechanism where they try to build CLs in batches, but "try" is the keyword.
[1] https://github.com/phhusson/treble_experimentations/wiki
I have always had the same issue with hackintosh and DD-WRT.
I run DD-WRT on a router, a kong build, but always have the lingering doubt about security.
LineageOS has allowed me to use my perfectly fine phone much much longer than the normal upgrade cycle. And this has saved me money.
More importantly my phone remains in use rather than being thrown away and a new one purchased saving about 4 phones from landfill (my guess based on a 2 year upgrade cycle).
Apple with all their environmental goodness claims locks their phones down from both custom rooms and from re-use after donation. Most donated phones have an iCloud lock with no way to contact the previous owner to request an unlock,
OnePlus actually does a pretty fine job of supporting even their "older" models. The OP3 and OP3T were running up-to-date "stock" OS's not too long ago.
I remember the first one coming out (and haven't kept track of how many there have been) but I honestly don't think I do anything that needs more than what the first one would give me.
(I actually have a Motorola One, which is on the 'Android One' mostly-stock long-term upgrade committment, and was about £150 new 18mo ago? £100 phone or less would be plenty powerful enpugh, I just paid a bit more to know I'd get the upgrades, and thought the fingerprint reader might be useful. (It is.))
To be fair, newer Android phones have Factory Reset Protection[1], which is pretty much 1-to-1 clone of iCloud lock.
If someone donates a phone, isn’t clearing the phone and releasing the “iCloud lock” typical practice? Otherwise the phone has negative value, in that it is simply toxic waste.
I had a Fairphone 2 before and I used LineageOS on it. Then I decided to change it, got a second hand OnePlus 5, installed again LineageOS and it's just the same thing, except the phone is faster and doesn't have a few hardware bugs.
I actually choose the OnePlus also because all OnePlus models seem to be well supported by LineageOS, which is probably related to the fact the OnePlus releases quite a lot of things as open source[1] (another good reason for the choice). On top of that, it seems to have a good quality/price ratio. I am quite happy of the choice.
The problem is it seems to be past its prime. It dropped support for mainstream phones more and more and is currenly limited to either very old handsets or rather exotic manufacturers.
The most recent Samsung S series they support is from 2014, almost six years ago. CM and LOS were also popular on the Nexus 4 and 5, these were completely dropped as well and even the successors do not have a recent Android version at this point.
All of this coupled with long delays of moving to the most recent Android version. Many phone were still on Nougat LOS, when there was already Pie.
From a security perspective, custom roms are still worth it.
And those are the painful ones, since drivers have kernel access. The security situation on Android is really less than ideal :/
You know, maybe I was lucky or hit some weird Window, but they used to have S7 Lineage OS on there and I still run it on mine.
Yep, this is a pretty serious problem; even if you want to purchase a "supported" device, the odds you'll get feature upgrades aren't great. The list of currently supported devices is quite small, and many of those don't receive any maintainer edition - they're just letting the weekly automatic builds happen. So there's not really any hope that the Nexus 5X, for example, will ever get Android 9, let alone Android 10, with LineageOS. It's stuck on LineageOS 15.1.
If you want to go to less trusted ROM sources, like PixelExperience, you can do that... but unlike LineageOS where you're likely to get ignored by maintainers, trying to keep the phone on its latest version means that things are broken half the time. Currently the Nexus 5X is hardly usable with the PE ROM.
It's really a sucky experience currently if you want to buy a smartphone for longevity. Everything is built around the wasteful and expensive 2-year upgrade market, and since that's the most profitable, we're not likely to see improvements soon.
Magisk/stock is what I've been using of late.
I get the security concern in that case, tbf, but not when it's some entertainment app.
Like how GrapheneOS has focused on Pixel 2 and Pixel 2 XL.
LineageOS is an hacker/enthusiast thing, it will always remain niche regardless of how easy to use you make it.
If this thing ever breaks or dies I'll probably get a Zenfone 6 (I recall Asus actually openly distributed kernel sources with the express purpose of helping out the open source ROM community) and I'm excited to see how LineageOS runs on that.
Also from my past experience: LineageOS don't care about privacy, Google DNS & internet connectivity checks points to Google servers; probably the telemetry works too.
About quality: very different results, highly depends from device. In mostly cases - camera apps quality is horrible 'cause vendors doesn't provide any code.
I don't know about the DNS, but Gapps don't come preinstalled, so I'd be surprised if it sent telemetry to Google by default. Either way, I'm sure it's possible to disable/redirect those things.
As for privacy in general, they offer a pretty unique feature that allows you to forcibly block granular app permissions after the fact, after granting them for the install. Because this isn't iOS it'll break some apps that don't handle it gracefully, but it's nice to have the option.
But yes, if you're trying to run Android in a privacy-minded way at all, you'll be making some sacrifices.
Simply set up your default search engine to DDG or whatever you want and your LineageOS phone will send exactly nil to Google.
Another option is to use microG, a derivative of LineageOS that re implements parts of google play services with open source and throws out the rest. YMMV, but I have used it and my phone worked, excepting some apps' notifications because they use google cloud messaging. I never signed in anywhere with a google account, but I did have google maps installed (I haven't found a good replacement on Android). Google probably got rather little info from me, but they did get my location sometimes.
I agree that most people probably need Google Play because the apps they use aren't available anywhere else.
But then again most people probably don't have the skills to install LineageOS to begin with.