How de-Googled is Lineage OS?
kevinboone.me
kevinboone.me
Additionally the guide I've seen referenced the most (from Reddit, which a popular Youtube video is directly based upon and which this article covers the main points of) suggests an outdated HTTPS URL which no longer works. I'd imagine many are just blindly copying adb settings and encountering problems (the burden of which often falls onto LineageOS community support as people spend time trying to identify an issue).
they are a data selling company. anybody now or in the future who deems that data valuable can acquire it. worrying about such data falling into the wrong hands sooner or later is not paranoid but knowing history and learning from it.
i agree that if you are serious about de-Googling that GrapehenOS is a much better fit not to mention superior security, however that is only the first step.
A GNU/Linux smartphone is an even better fit for this. GrapheneOS uses Google hardware and AOSP written by Google.
https://forums.puri.sm/t/the-current-state-of-the-librem-5-i...
https://forums.puri.sm/t/nine-months-librem-5-as-my-only-pho...
> such as Signal
I saw people using Signal on the forums, but Signal intentionally doesn't directly support ARM desktop GNU/Linux, so it's not straightforward AFAIK.
> and a banking app
This depends on the bank. Some banks allow to use their apps with Waydroid.
The battery life is terrible and the software still buggy as hell.
It's a great host for Linux phone development though. I haven't had any major problems with the hardware being unstable or anything along those lines.
But once you start expecting the whole package to function more as a primary phone than a portable devkit you're using to further the state of Linux phones, it gets ugly pretty quick IME.
The Furi Labs FLX1 sounds like a much better option: https://furilabs.com/shop/flx1/
The development of their phone was extremely slow, but today they ship within 10 days.
> there's no way I'm paying $1K for a phone that has just 3GB RAM and 32GB storage in 2024
Fair enough, although I don't know about any other GNU/Linux phone with all free drivers and mainstream Linux support (which effectively means lifetime updates).
Why GNU? Their runtime stack isn't exactly known as the best fit for constrained devices like a smartphone.
They have more memory and processing power than a normal computer from 20 years back, even 10 years back.
Why I consider smartphones constrained is unimportant here, though. The question isn't whether GNU libs/utils can run on a smartphone. The question is why the person above said GNU specifically.
I'm trying to suss out whether they are aware of some special case that would make GNU better than e.g. musl on a phone, or were just repeating a bit of that "GNU/Linux" rant that was (incorrectly, I think) attributed to Stallman. If it's the former, it seems like information worth sharing.
Concerning the battery life, we need to improve it for laptops, too, anyway. Also, currently, it already allows to have a one day of use, which is mostly sufficient.
[0] https://puri.sm/posts/my-first-year-of-librem-5-convergence/
GrapheneOS has has many more feature that AOSP/LineageOS lack (https://grapheneos.org/features) and also 0 google connections unlike LineageOS (https://grapheneos.org/faq#default-connections)
>some of graphene's touted features are geared towards being able to use google's services
and they are 100% optional and opt-in by default
For example years ago I opened an issue around runtime-patching applications (https://github.com/GrapheneOS/os-issue-tracker/issues/284) and was told it didn't make sense in the OS.
Putting aside the validity of arguments on either side of that issue, runtime patching allows me to very quickly excise large swaths of anti-privacy code across every app on my phone.
If I was to switch to GrapheneOS I'd have to accept that I'd be giving up a fair amount of privacy for the added security.
How about GrapheneOS connections?
Zero or non-zero?
"By default, GrapheneOS only makes remote connections to GrapheneOS services and the network provided DNS resolvers. There aren't any analytics/telemetry in GrapheneOS. The only information revealed to the GrapheneOS servers are the generic device model (such as Pixel 7 Pro) and OS version which are necessary for obtaining updates. The default connections provide the OS and apps with updates, set the system clock, check each network connection for internet connectivity, download a global database (does not vary based on location) with predicted satellite locations when using Location and obtain attestation chain signing keys for the hardware keystore needed for the hardware-based attestation feature."
- Giving money to Google
- Using hardware that is ultimately controlled by Google
- Hardware replacement costs every time Google support runs out, instead of when the hardware stops working
- Ongoing environmental impact from replacing your hardware every time Google support runs out
It might make sense to accept those problems if your threat model can only be addressed by Graphene, but for the rest of us, something else might be a better (and more responsible) choice. At least for now.
I would love to see non-Google devices with the features that GrapheneOS requires.
I don't mind giving Google, or any other company, my money. Especially not in exchange for something like hardware. What I object to is giving Google (or any other entity) my data.
About software support, isn't that true for all devices and all manufacturers? Google guarantees 7 years of android updates and security patches, which is way better than most competitors, and Graphene adds in some years of extended support.
Not to mention that once all support is over, if you don't care about the fact that firmware, kernel and vendor code will never be updated, you can still switch to LineageOS, which still has nightly builds even for the first Pixel with extremely updated security patches.
The only valid point is that hardware is controlled by Google. There could be some sort of extremely-low-level backdoor or spyware, and we would never know. That's also true of each and every other CPU, modem or device with vendor-specific code.
If this statement is incorrect, please give me a pointer where I can buy user data from Google, and I'll correct my statement.
I used to work for a media agency’s analytics dept and we got feeds from G, F, and others we dumped into a giant DB for modeling and analysis of our clients ad reach effectiveness.
Why would anyone who's serious about de-Googling opt for a ROM that only runs on Google phones?
and with GrapehenOS there are 0 google connections https://grapheneos.org/faq#default-connections
And to be clear, every other big tech company operates on this same logic. "Tracking" to both Apple and Google is this really specific technical definition rooted in the same-origin policy of web browsers, in the same way that "malware" to Apple is "anything we didn't sign, including useful developer tools, third-party JIT compilers, and games that won't pay us 30% of their microtransaction sales". In fact, this sort of "we'll protect you from the competition's - and ONLY the competition's - malfeasance" bullshit is why Google isn't allowed to block third-party cookies. The UK CMA is legally enshrining third-party cookies - at least in Google browsers - because all of Google's own privacy posturing with that was just to shut off the data flow in Chrome.
- get an officially supported phone with easily unlocked bootloader (which usually means: Pixel or OnePlus)
- get the LineageOS&MicroG bundle from https://download.lineage.microg.org, which should really be more advertised
- don't root your phone, because that'll definitely require more effort fuzzing around with Magisk and Zygote deny lists etc.
There are of course apps that won't work with MicroG, period. Anything requiring hard DRM (Netflix EDIT: according to below list, it's actually working now, but I cannot test), games (Pokemon Go for instance), also quite a few banking apps, so if you can't live without some of those, check beforehand for instance on
https://community.e.foundation/t/list-apps-that-work-or-do-n...
Not that I see many ads because I block them of course. I even use a pihole to filter all my android phone traffic and it's very effective against in-app ads on android. In most cases even the whole bar where the ads would have appeared is gone so the app uses the full screen space.
You also get the benefit of weekly security updates over the rather irregular ones with LOS4microg.
If you use network locations, unfortunately that still requires LOS4microg or the microg installer for Magisk module.
Usually, Google would determine this location based on its database of networks and there's no way to set another location provider without installing microg as a system app or patching Android.
The microg installer I mentioned [1] does this configuration so you can use microg as your network locations provider.
https://github.com/nift4/microg_installer_revived?tab=readme...
If it results in you buying a T-shirt, it might have been more relevant to you than an ad for something you didn't need. But if it results in you, say, not voting, that would also be considered a success.
There's an old saying in advertising: "I know I'm wasting half of my advertising dollars. I just don't know which half".
The main point of targeted advertising is to avoid wasting money showing ads to people who will almost certainly not purchase your product, and redirect the money to ads shown to people who are more predisposed to purchasing your product.
Examples of the former include showing ads for Depends to teenagers, or for McDonalds happy meals to the elderly. Examples of the latter would be gaming PCs for people who own lots of video games.
Monthly security updates too.
This feels like an issue for the EU to step in on, a functional duopoly created by apps for essential services that almost everyone needs requiring one of 2 platforms to work.
Never going to happen, for the same reason the EU forced Apple to open the NFC chip: They're working for European businesses, not European people. European banks depend on a having a trustable platform for their apps. They are going to lobby hard against such rules because they don't want to be overrun by fraud.
Maybe Apple will help you out if you're lucky. They seem to hold a grudge, and maybe they will lobby the EC for such a rule just to fuck over the banks who forced them to open up the NFC chip.
The vast majority who run a degoogled phone knows what they're doing. And it's such a niche phenomenon anyway. They're not going to be overrun by anything.
The reality is that it is extremely painful to spend minutes locating satellites -- it is a battery drain and very difficult to deal with, almost in every case you need to use GPS (location, navigation etc). It is a dealbreaker for me personally and probably most of people.
Unfortunately Mozilla was the biggest one and they just shut theirs down. But there's a plugin for apple's and you can also use one that automatically caches cells wherever you have been, which works really great if you end up in the same places a lot.
I don't care about the de-Googling as much but I'm considering wiping to something freer, maybe Lineage OS. How destructive is that going to be?
[0] It doesn't do it when I take a picture with the camera (mCameraSoundForced=false) and I'm in a country where that would be unnecessary anyway.
I mean, you do you but that's kind a extreme.
All that code and settings live in a protected partition. If I have to root my phone for this at least I'd like it to be nicer to hack on.
TFA mentions Lineage and Graphene. Are these the only realistic alternatives these days? Why would one choose one over the other?
If you need Google services and just want an OS closer to ASOP, I'd recommend Lineage. If you want a de-Googled device and are okay with the limitations that comes with, go with Graphene.
I've been using Graphene for a few years now and have always been happy with it.
On the maps topic: other than finding locations via address, OsmAnd+ is better than Google Maps in my opinion. Even tells you what lanes to be in ahead of time when driving. I'm pleasantly surprised by it. Sure, you also lose out on the traffic heatmaps, but that's an acceptable loss to me as it means my phone isn't part of a spyware botnet anymore. Plus my state runs its own traffic heatmap website. If I need to see it, I can go there.
When it comes to security (and privacy), GrapheneOS blows LineageOS out of the water in pretty much every way, e.g.:
- Arbitrary-length encryption passphrases
- General security hardening: Memory hardening, sandbox hardening etc.
- Non-rooted (i.e. much higher security barriers for malicious apps to take over control over your phone)
- No userdebug mode (LineageOS ROMs are often development builds which weaken the security of the OS, see e.g. https://github.com/GrapheneOS/os-issue-tracker/issues/284#issuecomment-690417436 )
- Fully secured boot chain (in other words: A thief won't be able to do much with your phone)
- Sandboxing of Google services (*if* you want to use them), i.e. Google no longer has admin access to your phone
- Being able to restrict internet access for certain apps (that's a huge one in my book)
- Being able to grant apps access only to select contacts from your contact list (contact scopes), and only select files/folders (storage scopes)
See https://grapheneos.org/features for a much longer list.Now that I'm thinking about it, some of the above features have become so natural to me, that I find it wild that other AOSP-based ROMs (including Google's) don't have them. Moving away from GrapheneOS would be incredibly painful for me.
I think we might get there unless fuchsia and google abandon the Linux kernel completely - for a more apple like lockdown - but I don't think we're there yet.
It's a shame that the mobile phone market is such a complete and utter shitshow. Can't root your device because a boatload of apps will stop working. Can't have an unlocked bootloader because other apps will stop working. You effectively have a choice between two walled gardens (and never the twain shall meet!), with varying degrees of privacy violations.
How did we let it come to this? For a brief moment we had the glorious N900 and Maemo ecosystem, but that's all gone now. Open phones seem impossible now.
Sailfish OS still seems to be going, and latest and installable on Sony Xperia 10 V. Though that is based on Meego which was what replaced Maemo and ended up on the Nokia N9 and was no longer Debian based IIRC.
Tizen OS was the other offshoot of Meego and Samsung was working with it, but they appear be abandoning it.
I never had the chance to pick up a compatible device try them out.
I tried Sailfish for a while, but it got progressively slower and I vaguely remember some weird Russian involvement?
Sure, but it's perfectly understandable. Look at it from the other side: When the majority of your fraud comes from rooted devices and a tiny minority of your users have rooted devices... why would you not ban rooted devices?
I suspect the majority of fraud comes from users doing silly things without paying attention, like wiring that money the CEO asked them over text. Or from running hopelessly insecure devices which aren't actively receiving security updates.
This is true, LineageOS is mainly used by people that end up installing Google Play Services afterwards. They have said themselves that 90+% of people install it on top of Lineage.
They are also very afraid of pissing Google off, and thus they are extremely against MicroG which is an open-source phone-side API for Google Play that is more privacy preserving. For example it replaces the location service with alternatives and supports firebase push messaging without sharing too much data. But Lineage hate it, if you so much as mention it in their IRC channel you get insta-kicked.
I view Lineage not really as a privacy ROM but more as a long term support ROM for the people that want normal Android with Google but their phone has fallen out of support from the vendor.
PS: There is a great fork from MicroG itself: https://lineage.microg.org/ . Of course not using Google at all is even better but the problem is that most app backends only speak to Firebase (google) for their push messaging.
> I don’t like Google knowing so much about me, but I don’t believe Google’s data collection is directly harmful to me. My disapproval of Google’s activities (and I know Google is not the only culprit) is mainly one of principle.
For me it's not about harmful or not. I just don't want to be spied upon, whether I receive negative effects from it or not.
> I don’t want to be a source of revenue for Google, or to legitimize their behaviour by my own inaction. I don’t want Google to make the Internet more of a hellscape that it currently is.
Well Google and their model of tracked advertising goes hand in hand with enshittification. They're responsible (though not single-handedly) for establishing the model of 'the user is not the customer but the product'. Kowtowing to their services will certainly make things worse.
They are? I thought that was GrapheneOS. (Not commenting on which side is "correct".)
I don't think LineageOS has any issue with GrapheneOS or the other way around. They're not really fishing in the same pond. GrapheneOS is a security hardened OS for pixel phones only, whereas LineageOS is more like a long term support ROM for as many devices as possible.
The one thing that didn't work well was Location services when my wife and I travelled to Walt Disney World. The My Disney Experience app worked great for the most part, but occasionally I would get errors related Location claiming that I was outside of the country. Uber worked fine though. Fortunately we were travelling together and had her phone to fall back on when we needed it.
Besides, GrapheneOS already supports the native Google Play Services (with additional sandboxing), so I have a hard time seeing how MicroG would help here. (I used MicroG on LineageOS for years and it certainly wasn't without bugs.)
Also, regarding what GP wrote, I haven't encountered a single app in a long time that wouldn't run on GrapheneOS.
In Norway practically any place that accept cards also accept Google/Apple pay - as all pos terminals support "tap"/NFC as does practically all debit/credit cards issued here.
I was recently on vacation in France - and only needed my phone there as well.
> Do you not carry a wallet?
No. [Ed: no longer, no]
> What happens if your phone dies?
Either I don't buy anything - or I'd borrow a usb-c charger from the person behind the bar/at the restaurant etc.
I can see how this could be a deal breaker for some.
Speaking only for myself, personally, I'm 42 years-old and have been a very slow adopter of smart phones in general. GrapheneOS let me feel like it's finally my phone and I've started using it more. Mostly as an mp3 player while exercising, and I've got an open source password manager that I've started using a lot. But I've never been comfortable with the idea of my phone replacing my wallet. I mean, sure it can do everything that my wallet can do but it's also susceptible to malware or attack and if I lose it then not only do I lose all of the data on my phone but I lose access to my identification and payment methods as well? That is a terrifying prospect to me. I don't like the idea of single points of failure. Losing my wallet would ruin my day. Losing my phone would suck but nothing catastrophic would happen. For most people losing both would be a nightmare scenario.
But I don't even do online banking on my phone. I probably could. I choose not to.
National/Banking id/2fa would be a deal breaker probably - all infrastructure is built around smartphone apps now - and it's a challenge to find an alternative (ie hardware token issued by the bank).
There nominally is a national id system with printed 2fa codes - but my impression is that it is fading in favour of the banking id system. Except for a few government services like social security, where it remains a viable alternative.
For online payments, with a credit/debit card the banking id 2fa system is practically required to spend money online.
So basically it's a situation where you need the smartphone anyway, but wallet is optional.
I'll admit to not really understanding what about the AOSP is inherently bad other than being maintained by Google. To my understanding, it's only the GApps binary that remains shrouded in sinister mystery, and obviously that's not present in Lineage.
16 character max for a decade is a juicy rainbow table for the small cost of a few petabytes, something most law enforcement is easily capable of paying for.
Between the devils I know I much prefer my apple mobile devices, even with a fix applied I wonder about the intentions of a team that ignored security concerns for over a decade (both Alphabet and Lineage)
Surely the kdf is salted and not prone to rainbow table attack? If it is, that's a flaw on its own - and much more serious than a 16 character limit?
log2((2*26+10+10)^16) ~98bits of entropy - that's nothing to sneeze at?
I don't know that market well, but it seems like you should be able to run a virtual cloud android devices as a digital twin. secure hardware is a honeypot. disposable hardware with keys you manage is the best possible.
For example, what happens when someone just takes your disposable handheld in your model of private Android?
not much but it's a start