LineageOS is currently installed on 1.5M Android devices
9to5google.com
9to5google.com
Poor people can't afford a new phone every two years.
When in your 80's you dont need or want the constant nagging of apps pestering you when all you want to do is text and call your family and friends.
I use abd to delete/disable every unnecessary useless app and leave them with just 3 apps. Text, phone and contacts. No data or wifi either. A dumb smart phone. Much better than the ageist demeaning Doro big button phones.
They are all amazed how beautifully simple the phones are and with just one or two taps they can text or call anyone.
Have you ever watched an elderly person trying to navigate the complexity of a modern smart phone. Not so smart!
Wouldn't they prefer one or even no taps?
> Have you ever watched an elderly person trying to navigate the complexity of a modern smart phone
Assuming that's a question, then "yes!" It is not at any level designed for what they want to do. The "mother of all demos" talked about children but not seniors. Ever since Engelbart, no one has cared either. Despite the boomers (with boomer cash) ageing out . . .
Children will press things until they figure it out. Adults (moreso as we age) are scared to press things they don't understand.
I have one outlier in my family. He's old, understands less and less about tech. like while ten years ago he was still able to understand how there are multiple Windows open on his laptop belonging to multiple apps, nowadays he starts confusing minimizing and closing apps, can't tell apart wether a program is running or it's just the pinned launch-icon, uses edge, Firefox and chrome interchangably and gets confused.... But at the same time, he still wants to figure everything out himself on both laptop and smartphone which resulted in hilarious mess-ups sometimes. I don't know if it isn't worse than a child. At a certain age a child might still get scared by some of the prompts, I've seen firsthand an 8yo going "oh no this costs money, abort" in panic. I'm not so sure my relative would do that when they think they know what they're doing...
I'm nowhere near 80 or retirement and I have the same sentiment. Add datamining concerns to the list. The modern smart phone can stay off my lawn. I get enough Internet here at my desk.
I think you have the relationship reversed. Supercomputers are closer to Super Nintendos than smartphones.
I've kept with this since, and hope to never need another phone (when this one dies, I'll just get a small camera, or a tablet with a rear camera).
It would actually be nice if they shipped a small phone to get regular developers to care about constrained layouts, and then shipped a Pro Max Tab whatever that was the same proportions, but with everything scaled up.
I even saw some renders of a translucent replacement back for the 5c inspired by the original fruit iMacs[1]. (Shut up and take my money!)
1: https://9to5mac.com/2013/04/03/concept-imagines-low-cost-iph...
They also claim to be against waste and ecologically responsible, yet adopt the worst anti-consumer and anti-environment market practices they can get away with. Hell, they invented some.
Punishment should be being forced to be blindfolded in public for 3 months and should be levied on all senior executives.
I've used an MDM with a kiosk mode for a similar effect. I won't recommend the one I'm currently using because the kiosk launcher crashes every couple of days; still looking for one that works well, and I've tried most of the ones I could find that weren't "call us for pricing"
I don't own a phone that LineageOS supports or I'd try it.
Not everything is an ism. Doro makes phones for people with poor eyesight. Most of those people are old. Glancing at their product catalogue, it doesn't seem much different from what you're doing with Lineage OS. Not everyone will have a geeky son to make a customised Lineage phone. Doro fills a niche. Be thankful someone does.
My father has a Doro handset. I recommended it to him based on a misunderstanding of the advertisement* and have regretted it every since.
The user interface is confusingly designed, with nested menus ten levels deep in which pressing the wrong button can just delete your message, contact etc. without waiting for confirmation. The screen is tiny and low resolution - I have 20/20 eyesight and still can't see what the status icons are supposed to be! It is so awkward to change the ring volume and unclear what mode the phone's in, that my father doesn't trust it not to ring at concerts, so leaves it at home.
All that leads me to the opinion that Doro is just predating on older users and their carers with the idea of being simple and accessible, whilst actually doing absolutely no real UX research. Yet, their 'dumbphones' approach the price of some basic smartphones which have hardware orders of magnitude more powerful.
* This was back when 2G was new, and I incorrectly assumed that it would imply some level of internet capability on any handset new enough to support it. The device in question does not have any internet support.
NFC tags to identify physical objects when one can't read the label are an excellent idea.
https://www.wayaround.com (custom) and https://gototags.com (generic).
There should be law to mandate the UI of any app beyond a userbase of 100M. If you say that would severely restrict apps becoming that big, yeah that would be kind of the point.
It used to feel like being "tech savvy" meant thinking logically as the system designers would have, but now I think it just means being conditioned through years of abuse into knowing the unwritten rules of how to skillfully outmaneuver bullshit interfaces and dark patterns.
I hate how accurate this is, especially on mobile
You'll always need a password and some difficult second factor for your Apple/Google account, but when you've got that sorted, the rest becomes do much easier.
They usually don't even notice that button. And if they do, they certainly don't understand that it needs to be pulled up...
Another big issue is that buttons and input fields are often not clearly recognizable as one.
I'm only in my 40s, still very hands on in tech and I still struggle with some applications. It's gotten to the point where I now loathe most web-based and mobile applications.
No thank you.
There are laws to force architects to make their buildings accessible to people with disabilities, so I don’t see why it would be shocking to force companies that generate revenues from apps with a certain amount of user base to make their apps accessible.
Gross. No thanks.
If you don't like the UI of an app, just use something else for cryin' out loud.
When I visit my bank account online I'm met with full page advertisements for other services from the bank and I have to hunt around to find the tiny gray 'No thanks' text before I can even get to my accounts. And from there, I'm met with constantly changing UI patterns and abstract hieroglyphic icons instead of plain text like it should be.
There are a lot of ways to pay bills. You named one that you happen not to like.
It's like telling a wheelchair user to just use another station or form of transport. If you have global reach, you have global responsibilites. And the end goal wouldn't even be regulated apps - it should simply be too complex to create apps with such a reach. Forcing open protocols instead of proprietary gardens. This is what the messaging interoperability of EU's DMA act is also supporting.
Because there isn't a monopoly on chat apps. What you're asking for sounds like rules for the sake of more rules. I can think of more than half a dozen chat apps offhand: Signal Messenger, Whatsapp iMessage, all manner of IRC clients, Slack, Teams, stock SMS, Discord, Matrix/Element, Telegram, Session, and so on and so on.
We're not talking web search here, the market for chats is diverse and competitive. You got walled gardens, open source, and everything in between with a bunch of different UI's.
It's low effort to implement: just add the appropriate tags if they're not there, throw some i18n at it, then test it on different screen sizes.
This can probably happen on the OS level with some design guidelines.
But on LineageOS you can update through all the updates for the major Android version (mostly ASB fixes and some new features here and there) by clicking a button from the Updater menu, courtesy of Android's A-B dynamic partitioning update system.
https://github.com/LineageOS/android_packages_apps_Seedvault
We got lots of time on our hands.
(I am writing this on a Redmi note 10 with lineage 21)
I came to my bank to discuss a mortgage and I saw them log into their environment. A nice Windows environment with bright blue title bars and big red X buttons. In other words, Windows XP for which even the long term extended support has long since passed.
Only because hardware attestation is not yet a thing on desktop browsers. Google and Microsoft are working hard to change that, though.
I'm using it with microG, bootloader relocked, and it seems to pass SafetyNet this way – at least the apps that didn't work on Lineage seem to work here. (I haven't yet tried Google Pay, though – I think it will require proper GApps.)
Edit: by the way, banks requiring hardware attestation is probably a U.S. thing – in the EU and ex-USSR countries banks seem to not care about that at all (although some don't like it when you root your phone).
They set the vbmeta header flags field to 0x3, which effectively turns off all of AVB (Android Verified Boot). I'm guessing they do this because they want to allow the system partition to be writable (eg. for folks who flash additional things on top of LineageOS).
With unmodified LineageOS, if you configured the bootloader to use LineageOS' public key and relocked it, there would be no security benefit. To enable AVB's signature checks, the flags field needs to be set to 0, which requires re-signing LineageOS with your own key.
I wish they weren't so pedantic about that. At the moment if you even mention microg in the lineage channel you get insta-banned.
As you say their hard stance is not doing them any good with Google anyway, they're ignored either way. And MicroG is a really good solution which can replace google services like cell-based location with much more privacy-sensitive alternatives. They even implemented the corona bluetooth protocol during the pandemic! The only place it uses google's services is for push notifications, necessary because most app server infrastructure doesn't have the ability to communicate with anything else. But it does so in the most privacy-sensitive way possible.
At least the good folks at https://lineage.microg.org/ provide a great fork with microg built in.
Here in UK, using microG, banking apps for Nationwide, Starling, Revolut, HSBC all work with no issues.
Generally, I face no issue using any app.
Location services and notification both work reliably.
As I replied below, everything I need works, including a number of banking apps.
I used to use Lineage OS with microG, but now I use iode, very similar.
Note, I never patched or installed something besides microG ever, so my experience is as close to pure microG experience as possible.
The only problem is that the process of installing an alternative OS on a phone is very technical -- much more than installing Linux on a PC, and even that is too much for most users.
I'm always scared of messing up the delicate process of custom recovery installation, custom ROM installation and rooting. Some of the hardware variations are essentially unknowable outside of seeing if it works or if it's bricked.
Having said that, there are four functioning LineageOS phones in my household.
If you plan on installing Lineage, I strongly recommend buying Motorola phones that can be rooted very easily.
The best experience is probably with Google and maybe OnePlus, but I did not have any myself recently.
mtkclient [0] would let you skip the whole 7/14 days thing (also: unrestricted partition dumping/flashing). Though there are chances of ending up with soft/hard brick (normally possible to revert back to working state as long as you have backups), and there may be no support for your specific chipset/device/software revision at all.
WA works fine. Messenger works fine, Spotify etc., they all work. The only app I've found so far that doesn't work - logs me out five minutes after disabling the Play store - is the ChatGPT app.
Aside: my phone is so much better for my mental health since I've done this. The constant desire to research things is quieted. Now, if I really need to look something up I open TickTick and set a reminder to do it later on my laptop.
Most of the banking or payment applications baulk at getting a whiff of Lineage. You are then forced to play a cat and mouse game which is quite stressful. It is sad that ROM customisation (and rooting) is stigmatised in the Android world.
Or use the web version instead of the app.
If so you can get a Yubikey and use Yubikey authenticator on a LineageOS device and it will work fine with all of those services. It follows the same standard as Google Authenticator and is a drop-in replacement.
I will install LineageOS once I need apps that my old phone no longer supports. I ordered the MitID backup key generator in case their app doesn't work, but I'd prefer not to need to carry it.
1. https://www.reddit.com/r/sweden/comments/ocd6v0/bankid_med_l...
Anyway I use Microg and don't have any google services on my phone so it's worth it.
Having a young population is also a big incentive for banks and government to invest in relatively newer tech.
I'm using lineage on a OnePlus 5. It's old but works perfectly!
I'm currently using an old PixelExperience build which takes some efforts to hide it's unlocked/custom rom status (right now it passes basic but not strong attestation). What I really wonder about is while we don't have the software environment that the OS isn't tightly coupled to the handset (i.e. generic system images) where the optimums are for security if someone doesn't regularly upgrade phones to maintain support from the original manufacturer. The most recent official android for my phone is 8, I'm running 9, so that's at least 5 and a half years old.
From a glance at XDA there's a collection of 11-14, however that brings up another issue of being able to establish trust in whoever is building your OS. Is an individual volunteer graciously building the latest version producing a recent version better than an older build from an established organization like lineage, or better than the ancient official build. Would my phone be seen as more secure by restoring older software and relocking.
There's a number of factors in balance here I'd love to hear views on from someone involved in consumer bank app security, as much as they're able.
That OnePlus 9 had some weird issues that eventually got resolved but it took a while. Important to differentiate between an OS that builds for a phone and one that actually works for a phone, but there's not usually a ton of reviews for the latter.
Try a Pixel 5, 6, or 7.
It is a more serious project than LineageOS in the sense that they take security very seriously and they take their development more professionally too. There are no disadvantages to using GrapheneOS compared to LineageOS.
You can see a comparison here: https://eylenburg.github.io/android_comparison.htm
Do you have a current guide for installing it?
As an example, Graphene even recommends not using Firefox [0]. I actually still do, but I understand their rationale and it's very well presented. The way they explain such things in clear English is very helpful and hopefully indicative of a similar amount of consideration being made elsewhere in the project.
If you want it cheaper, I also have good experiences with Motorola phones. Unlocking requires you to register, but you can use a throwaway mail account and it has worked for me so far many times. Just make sure the device is officially supported by Lineage, I have very mixed experiences with unofficial ports.
Stay clear of anything from Xiaomi. Unlocking is a nightmare and you have to wait weeks to get your unlock code.
0. https://calyxos.org/news/2022/07/06/oneplus-android-12-reloc...
First time I needed to wait 2 weeks. Second time, I made the mistake of using the same Mi account and had to wait 4 weeks, because I did not know each time you unlock something your waiting time doubles. If your phone for whatever reason looses the Mi account connection, everything gets reset and you start from scratch.
It's not the end of the world, but 300$ will also give you a pretty decent Motorola Moto G phone, which are way easier to unlock (all you need is a mail address, and you'll get your unlock code instantly).
I recently upgraded from a used beryllium (Poco F1) with a dying battery to a used, but pristine dubai (Edge 30) and have been very happy with that choice.
At least for Qualcomm-based phones, make sure to have the phone's stock ROM provision IP Multimedia Services (IMS) with your MNO/ISP, so that (you increase your chances that) VoLTE/VoWIFI will work also with LineageOS.
Unfortunately I won't be able to the same on mine, because I need my banking apps to work for two-factor authentication.
Just one bank in my area allows for a hardware key and I don't have an account there.
It appears that I'm forced to have an up-to-date device with its original OS to do banking.
I do sympathize with other posters with their experience of Safety Net and Device Integrity checks forcing them to not use banking and payments apps, but going through XDA or Telegram clears up this confusion of which ROM passes these checks OOB without any fiddling.
I've decided that I won't play this custom ROM security nightmare game anymore and will get any Pixel device with GrapheneOS in the future. Often, it's just one guy developing each ROM for each device.
It seems to be the only image that works with Waydroid (the Android environment for Linux tablets), but I am not super comfortable entering my passwords into a project I don't know much about.
This article has some good info about the security of LineageOS, although the biggest complaint comes from the physical security implications of unlocking the bootloader.
Since it's running in an emulator, I'm less concerned about bootloader and adb. More concerned about keyloggers, malware, etc.
A device you are most likely to lose, break or get stolen by virtue of being outside of your home for much of the day.
I agree it's pretty crazy.
Take a random device like Google Pixel [1] it runs on a 4.4 kernel, long outdated and no longer maintained by Google. You can explore the code [2] however you are not going to be getting critical security updates (such as those issued by Qualcommm or any closed source blobs/firmware etc, and those released as per the pixel/android security bulletins).
Lineage is more about 'hacking' a kernel and making it work with the latest AOSP when the official software support ends. It's more vulnerable to exploits than a continuously supported device (although even devices that are 'in support' by the OEMs can often be depressingly behind things like patches etc).
Google is trying to fix this within the ecosystem (GKI, Apex etc) but at least as far as custom ROMs go...yeah, don't store state secrets on such a device ;)
[1]: https://wiki.lineageos.org/devices/sailfish/
[2]: https://github.com/LineageOS/android_kernel_google_marlin
Are there devices which graphene supports which aren't fully patched on lineage? AFAIK graphene is just outright not supporting devices without current kernel updates, while lineage does best effort on the long tail, meaning that on the same device they'll have the same kernel.
[0] https://privsec.dev/posts/android/choosing-your-android-base...
My next phone will be some kind of dedicated Linux one so I can finally finish killing big tech in my life.
Google wages a war against us using 3rd party apps as a proxy. They are pretending that Play Integrity API (previously SafetyNet) protects the user, and recommend it to app developers.
What can you do against this? Before trying anything to circumvent PlayIntegrityAPI/SafetyNet, start by opening a ticket (sending a mail, adding a comment on play store, whatever) to the app maker that your using, and tell them you use a more secure OS than the one provided by your manufacturer, and that their use of Play Integrity API reduces your personal security. If even 10% of 1.5M LineageOS users open tickets, that should be enough to actually get back to a manager of said app that will actually decide what to do with it.
As some small proofs that Play Integrity API IS NOT about security, but about enforcing Google/OEM monopoly on the device you own:
- Play Integrity API didn't care about permissive SELinux for a very long time (even though that's trivial and non privacy-invasive to test), I don't know whether it's still the case.
- https://twitter.com/MishaalRahman/status/1752734296400379957 Play Integrity API punishes you for using a custom kernel
- To this day, it is still trivial for an attacker to bypass Play Integrity API. It has became annoying for the community who would rather do useful stuff. A full-time attacker just need to spend their day scouting for approved firmwares and re-use them
- I can extract the "key attestation" certificate (""ultimate level"" of Play Integrity API) of a Google-made device (a quite recent device, it has been upgraded up to Android 13), because real security is hard, and this key is still valid. Of course most other OEMs are worse in that regard, so if it's doable for Google-made devices, imagine what an attacker can do to simply target the weakest OEM. (hint: they simply publish those certificates over the internet)
tl;dr they spent all their headcount on enforcing that the firmware the user is using is the google/oem one, and none on enforcing the security of the firmware.
What do you mean by that? The secure boot chain (all the way from the boot ROM) must not be broken for "hardware-backed" Play Integrity to pass. How could you reuse firmware with that in mind?
I don't think I'll make the switch so long as it's still supported by the manufacturer, but maybe after they drop support I'll finally be able to give it a shot.
Now how can we get that number to 3m?
VoLTE also has ended the lives of many devices as 3g networks have shut down. Samsung's VoLTE isn't supported in Lineage, so that vendor is gone.
There could be a few reasons.