>How is this relevant? Yes, in a custom ROM - USER NEEDS TO BE CAREFUL. (i.e) if someone installs random app
It's relevant because it's an exploit vector that can be easily closed with basically zero downside, but for whatever reason it hasn't. Besides the risk of having such holes in the first place, the lack of willingness to fix is indicative of the security culture of the organization as a whole (ie. not very good).
>I am yet to see proof that this causes major meltdown.
It doesn't cause a major meltdown because most people don't use lineageos, so mass infections don't bother targeting them. That doesn't mean the system is actually secure. It's like using netscape navigator to browse the web. It might not cause a "major meltdown", but only because nobody bothers targeting it, not because it's actually secure.
>Assuming a phone was securely installed (after verifying sha/sig) with lineageOS RECOVERY and ROM - it will not accept a build with different sign keys. (i.e) AOSP keys.
Right, but the allegation is that /e/os uses test keys, either intentionally or through incompetence.