7 ms·
Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manu
by brango 9y ago
Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two.
Anyone got any suggestions for options?
- xrisk 9y agoLineageOS has a moderately large selection of supported phones for a custom ROM and it has weekly updates. My two and a half year old Moto E has the October 5th security patches for Android.
- gsnedders 9y ago> My two and a half year old Moto E has the October 5th security patches for Android. But it has very few kernel security patches: https://cve.lineageos.org/android_kernel_motorola_msm8610 https://cve.lineageos.org/android_kernel_motorola_msm8610
- rightos 9y agoLook through the list yourself, but at least on my device, most of those kernel security issues aren't really of significant impact as apps don't have access to the APIs needed to trigger them and they're not remotely exploitable.
- taspeotis 9y ago> I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. You could just ... buy an iPhone and get timely security updates for years. EDIT: Downvote if you want, but if iOS 11 contains this security fix exclusively and not iOS 10, then an iPhone 5s bought on 20 September 2013 is going to get this fix. If Apple release an iOS 10 update and you bought an iPhone 5 on 21 September 2012 you're covered too.
- la_oveja 9y agoand force me to use some propietary-built webkit? Nah, thank you.
- ec109685 9y agoIf you build it yourself, you can use whatever browser you want.
- pritambaral 9y agoCan one install their own web rendering engine on iOS?
- wolfgke 9y agoIn principle yes (if it is not against the app store guidelines). But if submitted as an app, it cannot use JIT compiling for security reasons. This will make the speed of JavaScript execution very non-competitive to WebKit.
- bzbarsky 9y agoIt's not just JIT. Quoting from https://developer.apple.com/app-store/review/guidelines/ https://developer.apple.com/app-store/review/guidelines/ section 2.5.2: Apps should be self-contained in their bundles, and may not read or write data outside the designated container area, nor may they download, install, or execute code, including other apps. So your can't ship a JS interpreter either, even without a JIT. And section 2.5.6: Apps that browse the web must use the appropriate WebKit framework and WebKit Javascript. So you just can't have a web browser not using the built-in WebKit, period. As far as I can tell, you can install a web rendering engine that is not the built-in WebKit, as long as you only use it for HTML/JS that come with your app. At that point the JIT caveat applies.
- wolfgke 9y ago
- NormenKD 9y agoI'm using https://lineageos.org/ https://lineageos.org/ (previously known as CyanogenMod) on most of my older Devices. I think this is as close to an open source OS as you can get right now.
- pritambaral 9y agoDepends on the phone. I'm using a ~ 4 year old phone with LineageOS. I also have a Russian phone whose userland source code was never released, and no open source ROM exists; this phone is swimming in vulnerabilities and languishing in Android 6.
- makomk 9y agoUnfortunately, Google has given app developers a quite powerful tool to disable the use of their apps on non-official OS images, in the form of SafetyNet. So even if you can install an open source version of Android expect a bunch of stuff to no longer work afterwards.
- iam-TJ 9y agoMagisk (/system/less root) currently passes the SafetyNet checks and it, and it's MagiskManager App, are both FL/OSS and hosted on github [0] as well as pre-built images linked from XDA [1]. I'm using it successfully with LineageOS 14.1 (Android 7.1.2). [0] https://github.com/topjohnwu https://github.com/topjohnwu [1] https://forum.xda-developers.com/apps/magisk https://forum.xda-developers.com/apps/magisk
- mtgx 9y agoWhich is probably a game of cat and mouse at best.
- rightos 9y agoNot really - ultimately they're root, Google SafetyNet isn't, it has to run at the application level. Meaning Magisk will always win until remote attestation is enforced. There hasn't been a breaking update since July if I recall correctly and the Magisk developer had it patched in about a day.
- drdaeman 9y agoSafetyNet is not about "official" status, it's about security checks. I'm actually persuaded that I don't need terminal root access on a device (except for system debugging), but rather a firmware signed with my own release keys, and apps that need privileged access baked in.
- rightos 9y agoSafetyNet doesn't actually detect custom ROMs, a stock LineageOS will pass it on most devices at least. It attempts to detect root or modifications to the ROM by malicious software. Certain newer devices have secure boot attestation that may cause SafetyNet to fail unless spoofed to be a different device which does not have such attestation.
- fro0116 9y agoAnother option is OmniROM: http://www.omnirom.org/ http://www.omnirom.org/ Also fairly actively developed and supports a wide range of devices.