top 50 comments

sorted by: hot top controversial new old
[–] 35 points 2 years ago (46 children)

Anyone using Lineage? How is it?

I’ve got a Pixel 7 and have been wondering

  • source
  • hideshow 46 child comments
  • [–] 60 points 2 years ago (21 children)

    To be honest I do not see any reason to use Lineage with Pixel while there is GrapheneOS... But maybe there will be some users of it: it is always better to have more free open OS

  • source
  • parent
  • hideshow 21 child comments
  • [+] 24 points 2 years ago* (last edited 11 months ago) (5 children)
  • [–] 9 points 2 years ago* (4 children)

    I use GOS and agree with you completely some of the things GOS has done and said in the past should have never happened and hurt GOS more than it helped it. Also on the micro G front You are correct still being debated but as long as Micro G is signature spoofing it is my opinion it is not secure as signature spoofing requires kernel changes that in fact weaken Android's security model.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 17 points 2 years ago (3 children)

    Maybe an unpopular opinion here, the Android security model is based around trusting the vendor of the device or ROM more than the end-user, which I find wrong in principle. The origin of trust needs to be fully in the hands of the owner of the device. Otherwise you take away the self-determination of the users, and that should never be an option when it comes to security.

    Users themselves should be able to give or take away trust however they choose, and if they are unsure on whom to trust for certain things, they should be able to delegate that trust-management to a third-party on their own accord and with the ability to revoke it at any point.

    Everyone is different, and trusts entities to different degrees. For instance I would trust MicroG more to only transmit data that is absolutely required to google servers, than the gapps.

    Also, modifying the kernel is already done by google, in order to provide hardware support, so patching it additionally doesn't automatically make it more or less secure. That depends on what those patches do, and if those patches are properly maintained.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 2 years ago* (2 children)

    Correct but GOS reverses alot of Google patches like always on voice requires kernel privalage it is disabled on GOS etc. But kernel level signature spoofing gives way for a malicious app to spoof as micro g and infect your device and you would never know because micro g requires the same thing to function it is making itself look like Google when it is not google. So using microg opens your device up to allot more ways for it to be compromised and also makes it harder to detect or notice once it is compromised. For me the security risk of kernel level spoofing is way to high to use on a production device used everyday. Also I trust neither Google or microg I only use Foss apps I don't have Sandboxed play services installed at all I just don't use Google anymore.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • [–] 7 points 2 years ago (13 children)

    Graphene has a relatively short support, especially given that the phones for it are completwly unaffordable new so it's effectively shorter than advertised. I am now spoiled by using a device that is not EOL so I think I will be switching when GOS' support ends.

  • source
  • parent
  • hideshow 13 child comments
  • [–] 15 points 2 years ago (12 children)

    GOS Supports the pixel devices for the same amount of time as Google hard to keep a device secure once drivers are no longer being updated. But with Google extending support for pixel 6 and 7 series and the new 7 year guarantee on pixel 8 devices and newer this isn't really a concern anymore. So pixel 7a and fold will be supported until 2028 and Pixel 6 and 6 pro until 2026 pixel 7, 7 pro, and 6a until 2027. Seems like plenty of time for support and that means as long as Google supports it so does GOS.

  • source
  • parent
  • hideshow 12 child comments
  • load more comments (12 replies)
  • load more comments (1 reply)
  • [–] 14 points 2 years ago (15 children)

    its alright, it kept my "supposed to be dead" phone to keep on running with latest stuff, i like the built in firewall, but if you're privicy focused then this is not for you.

  • source
  • parent
  • hideshow 15 child comments
  • [–] 12 points 2 years ago (14 children)

    What privacy issues are you talking about?

  • source
  • parent
  • hideshow 14 child comments
  • [–] 10 points 2 years ago (13 children)

    Once LinageOS is installed your bootloader is always unlocked so anyone who finds your phone if lost owns it. GrapheneOS and a few other ROMs I forget the names of allow the bootloader to be relocked keeping android security model intact allowing the device to still be secure.

  • source
  • parent
  • hideshow 13 child comments
  • [–] 7 points 2 years ago (5 children)

    Is the bootloader really that important for a lost phone? If someone finds your phone can't they just tear it apart and read the storage with external tools? A locked bootloader sounds more like an anti-tampering measure and not for protecting your phone's content after it's lost.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 8 points 2 years ago

    If someone finds your phone can't they just tear it apart and read the storage with external tools?

    that's not the problem that BL locking solves. this is solved by storage encryption. BL locking solves 2 other problems:

    • helps keeping stolen phone from being wiped, though maybe it's not 100%
    • makes it much harder to plant malware on your phone while it's not with you
  • source
  • parent
  • [–] 5 points 2 years ago (2 children)

    It is largely an anti-tampering measure. Without it you could have things injected into the system. For example, a stalker could install a hidden tracking program as a service and then return your phone without you knowing.

    Iirc it's also a prerequisite for full-disk encryption on modern android. So, without it your user data is available to be dumped in an unencrypted state. Most phone thieves are interested in reselling the phone, so they're provably not going to go through the effort and risk damage to the phone just to dump encrypted data from the chips directly. However, if it's just available unencrypted from fastboot why not dump it? They could get info that could be used to blackmail or scam you or people you know. Or they could just sell the data.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • [–] 2 points 2 years ago*

    No because the data is encrypted especially on Graphene OS and even on stock pixel phones data at rest is fully encrypted and pixel phones also have a onboard security chip as well. So unless you can unlock the user data it would be useless. That is why a locked bootloader is so important it is needed to ensure at rest encryption its a requirement for it.

  • source
  • parent
  • [–] 3 points 2 years ago (5 children)

    That would be a security issue, not a privacy issue. Maybe that was what RelativeArea0 meant but if so I think that confused people because "privacy" implies somehow corpos/the state is spying on you through Lineage

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (2 replies)
  • load more comments (1 reply)
  • [–] 4 points 2 years ago (3 children)

    I was planning to move to Lineage, and eventually GrapheneOS (non Pixel at the moment) but revolut has broken compatibility by enforcing the use of the Play Integrity API, revolut is my main bank so I'm kinda blocked, for now... 🤬

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (2 replies)
    [–] 9 points 2 years ago (8 children)

    I dont get why anyone would use LineageOS on a phone that new and that well supported by custom roms (GraphineOS, /e/os, etc)

  • source
  • hideshow 8 child comments
  • load more comments (3 replies)
    [–] 8 points 2 years ago (6 children)
  • [–] 5 points 2 years ago (3 children)

    Their devs dont really care about security so id say its not safe at all.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 14 points 2 years ago (2 children)

    Any source on this?

    Lineage allows people to have newer android/security patches on end-of-life phones, that's a pretty good security argument.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
    [+] 5 points 2 years ago
    [–] 4 points 2 years ago (17 children)

    I connect my glucometer (Dexcom G6) with my phone and I'm assuming lineage wouldn't work with it.

  • source
  • hideshow 17 child comments
  • [–] [S] 16 points 2 years ago (10 children)

    Lineage is just Android, however, some apps (Usually banking apps are the worst offender) throw a fit running on rooted/custom roms, though it's usually bypass able with varying amounts of effort. I would not expect a glucometer app to have issues, but I've seen apps throw that fit for less in the past.

    Being a medical thing, I'd advise you to pickup a cheap used Android phone that's also on the supported list to test out your app first, or at least have an alternative means of monitoring it

    I did some Google searching and it came up... inconclusive, though the Dexcom website has this blurb on the compatible phones section

    "You can use this app on any OS that meets the minimum requirements, but Dexcom recommends not updating to a new OS before it's listed here."

    And the only minimum requirement for Android is that it's v10. I also didn't see mention of root/or "unauthorized OSes" on that page and alot of the times they will put something like that if a companies app will scan for root/custom roms

    So, you might be fine

  • source
  • parent
  • hideshow 10 child comments
  • load more comments (10 replies)
  • [–] 3 points 2 years ago (3 children)

    Out of curiosity, why do you think it wouldn’t work?

  • source
  • parent
  • hideshow 3 child comments
  • load more comments
    view more: next ›