LineageOS 21 review: Smartphone sustainability starts with software [video]
9to5google.com
9to5google.com
edit, found this - only for for microG Companion/Services https://review.lineageos.org/c/LineageOS/android_frameworks_...
If you're thinking of using LineageOS, make sure to look up MicroG to see if you can or cannot live without that additional set of apps and libraries:
The LG Velvet is the only "flagship specification" phone I could get in Australia with 5G, a MicroSD card slot and a headphone jack!
3 weeks later LG killed it citing the "other big unnamed Korean electronics giant taking all our market share" and then later promising "2 years of updates guys, we promise!"
At least if we could unlock the fucking bootloader we could port Lineage or Graphene or something to it. But (at least on EU derived models like mine) that never happened
Reluctantly on a Pixel 7 Pro now
https://news.ycombinator.com/item?id=39674827
So the answer is maybe?
Most custom ROMs(including official LineageOS) are as secure, usually even more, than OEM ROMs. There is just one threat model where it is weaker, which is the evil maid. But it is safer on all the other ones (the evil metro wifi, the evil video, the evil app...). (and personally I take the metro everyday, while taking my shower while I have a maid home just doesn't happen)
As for whether banking apps will work, it's entirely dependant on whether your back is trying to serve their customers or not. Most banks I use work just fine on custom ROMs without hacks. But for instance Google Pay is skimming down on costs, and users pay the price for it.
I definitely don't think that's the case. I'd check out the sections on microG and custom ROMs here: https://madaidans-insecurities.github.io/android.html (they're very knowledgeable, so usually factually accurate, but often frame or evaluate things in a very biased way IMHO, so be sure to evaluate the verifiable facts they state for yourself, and your own threat model). They're way more open to exploitation and far less secure than OEM ROMs, typically because of the way they have to pry open security stuff to get their various hacks to work. They are typically much better on privacy, but having your phone, from which you do all your communication and banking, and which has a dense cluster of sensors and transmitters that follow you wherever you go, be more open to exploitation by any random hacker or piece or malware seems like a bad idea to me.
- Send the content of your clipboard to the internet (OnePlus)
- Disabled SELinux on boot (Asus)
- Allowed any app to be uid 1000, and exploit known for years (Samsung)
- Ignore Linux policy and just picked security-looking patches. And got pwned repeatedly by simply looking at LTS patches. (Google)
As for madaidans-insecurities, they are extremely biased.
Just mentioning microg:
> which allows apps to request to bypass signature verification.
There is EXACTLY *one* app (k k k, two because of Play Store fake too) that bypasses signature verification, and you can VERIFY, which app does it, and WHICH signature it fakes. LineageOS integrated their own microg/fake signature mechanism thanks to Google anti-freedom policy, and you can review their own integration that is even more restricted than what I did (which already is infinitely more secure than what madaidans-insecurities mention): https://review.lineageos.org/c/LineageOS/android_frameworks_...
The final comment in the microg section basically sounds like "oh yeah, that argument could be completely wrong, meh"
That's really good to know to keep things in perspective! Thanks for taking the time to bring that perspective. Although I would say that it seems like LineageOS kind of does all of those kinds of things at once, whereas OEM ROMs might do one or the other each? Or am I wrong?
Edit: also, I can't find any info on your ASUS claim, and the OnePlus one seems misleading (it's not some vulnerability or passive background thing that just broadcasts your clipboard, it was an app you could electively use to send clipboard stuff to other computers).
> There is EXACTLY one app (k k k, two because of Play Store fake too) that bypasses signature verification, and you can VERIFY, which app does it, and WHICH signature it fakes.
I'm not familiar with Lineage OS — does this mean that you know only one app will ever do this and can verify that, so it's just one specific exception to the rule, or is it just that the spoofing was made possible for just that one app, and only one app is known to do it, but any app could without your knowledge in theory?
> As for madaidans-insecurities, they are extremely biased.
Like I said, their factual knowledge is generally useful, but their framing (including context, so you can get some perspective) and analysis is usually wildly biased IMHO. I wonder what their damage is.
Torvalds' low opinion of on security researchers in general comes to mind.
https://www.reddit.com/r/LineageOS/comments/o2lswm/banking_a...