14 ms·
LineageOS for microG – Access Google services without closed software
- nsomaru 9y agoAnyone actually using this and can comment on the stability of various apps/services?
- GvS 9y agoThere is wiki page with that info: https://github.com/microg/android_packages_apps_GmsCore/wiki/Implementation-Status https://github.com/microg/android_packages_apps_GmsCore/wiki... looks like it's not stable yet.
- chucky 9y agoThat wiki page was last updated roughly a year ago, I'm suspecting it's not accurate enough to rely on.
- nizzo 9y agoActually is pretty stable right now, the most important features like Google Cloud Messaging and the Maps API v2 work flawlessly. Only certain specific apps give some issues, which usually are fixed in short time.
- pedroaraujo 9y agoI haven't been using this ROM in particular but I have been using MicroG almost since its inception (without any of the official Google stuff installed) and I have to say it's a very smooth and seamless experience. I use Whatsapp, Riot (APK from Google Play with GCM enabled), Google Maps, and a bunch of other apps that depend on Maps and GCM services and all of them work fine. Sometimes I almost forget I don't have GoogleApps installed.
- yummy 9y agoI switched to LOS+OpenGapps from MIUI on my Xiaomi. It's like day and night. Everything just works. Can't name a single problem really.
- corna 9y agoOpenGApps != microG OpenGApps are just the usual bloated proprietary Google Apps, just packaged in a nice and handy way. See https://lineage.microg.org/#faq1 https://lineage.microg.org/#faq1
- yummy 9y agoWell, it's just the Google play services and some other API they are attempting to replace. Not even mentioning poor documentation. But anyway, what's the point if I'm going to use ~10 of proprietary GApps anyway (maps, keep, inbox...) ?
- bubblethink 9y agoThe point is that it's entirely up to you how many google apis you want to use, and at what terms. You aren't installing an opaque google play blob as a system app.
- iuguy 9y agoI'm using a LineageOS Oreo build on a Moto G5s Plus (replacing an iPhone 6) with MicroG and it's like night and day. Everything's ridiculously quick. I've had some minor niggles (which I put down to my lack of knowledge) but it's pretty fantastic. The only thing that doesn't work is the dual lens camera (I don't have the app from the original firmware so I only get one lens). I'm trying to figure out how to rebuild from non-official github repos, then I'll look at setting up a proper automated build of my own.
- Espionage724 9y agoI'm running my own build that's very similar to this fork: https://forum.xda-developers.com/nexus-6/development/rom-lineageos-easy-microg-unifiednlp-t3632360 https://forum.xda-developers.com/nexus-6/development/rom-lin... Works fine for me. I only use Google services to play Ingress and Pokemon GO, and both work without issue with microG.
- grabcocque 9y agoIANAL, but won’t this violate the license terms Google provides for Play services?
- chmod775 9y agoIsn't it under the Apache 2.0 license, allowing modification and redistribution of such? Edit: That license might just be for FOSS components used within google play services, I'm hard pressed to find any specific license anywhere.
- nizzo 9y agoThe whole point of this ROM is not including the Play Services at all. Don't know if it is against their ToS to use the Google services with microG instead of the GApps.
- bubblethink 9y agoIt'll probably violate the ToS of hitting Google's APIs. However, no OEM is shipping these. So there's no one to sue. The responsibility is on the user who flashes this. The code itself is free software. If Google sends a takedown to github or whatever, that would be a PR disaster. More practically though, if this becomes big, it would be trivial for Google to break the APIs.
- morganvachon 9y ago> "it would be trivial for Google to break the APIs" That's the most likely route they will take. It keeps their hands clean, as they can drum up a perfectly valid technical reason to break the API.
- larma 9y agoActually it's not trivial to change server APIs because they don't fully control all the clients (not even all officially supported ones). For example: push notifications are supposed to work without setting up a Google account (if you use a certain Android version). But if you don't log in to your Google account, you're not receiving updates through Play Store, and thus Google can't update the client. Google breaking their claim will upset some of their users (probably not the typical smartphone users, but think of entertainment systems based on Android for example). Also note that most Google ToS don't specifically forbid third party usage (and some also specifically allow them), the only thing that's forbidden is to misuse APIs in a harmful way. Just another example would be the login/account management part of microG, that uses the publicly described OAuth APIs, obviously intended for third-party use.
- keypress 9y agoCan someone explain what this? Is it a fork of Android with the Google service apps rewritten? Or just the latter? Could I take an old Android OS and install the alternative Gapps? Yours, confused.
- libeclipse 9y agoIt's a fork of LineageOS, which is the daughter of CyanogenMod, which is a fork of Android. Only difference when comparing against LineageOS is that the OpenGApps package is "free".
- alinspired 9y ago>Only difference when comparing against LineageOS is that the OpenGApps package is "free". Rather GApps (google) functionality is re-implemented from scratch and the necessary means (app signature spoofing) to replace GApps with microG is built into this LOS fork
- sleepychu 9y agoLineage OS is a fork of Android. This is a fork of Lineage which replaces all the binary blobs to make the Google services work with open source code (with the same or similar behaviour). I don't know for sure but probably not, the services aren't UserReplaceable.
- sleepychu 9y agoWhy is this its own fork though? Seems in line with the Lineage mission, shouldn't they just merge in?
- tribaal 9y agoApparently this requires a hole to be punched in the sandbox to allow android apps to "impersonate" other apps (by way of signature spoofing). The lineage folks didn't want to merge it in on grounds of security concerns. (I'm not affiliated with the project, I just read the code reviews because I had the exact same question). EDIT: for those interested: https://review.lineageos.org/#/c/64967/ https://review.lineageos.org/#/c/64967/ and https://review.lineageos.org/#/c/65366/ https://review.lineageos.org/#/c/65366/
- nExXxuS 9y agoMore information: http://blogs.fsfe.org/larma/2016/microg-signature-spoofing-security/ http://blogs.fsfe.org/larma/2016/microg-signature-spoofing-s...
- pedroaraujo 9y agoIn order to use MicroG, it is required to patch the ROM to allow app signature spoofing. People from LineageOS claim that this can be a huge security risk (and they are right) but there is no other way to achieve an implementation like this. So MicroG people created this fork with the patch builtin. More info here: https://github.com/microg/android_packages_apps_GmsCore/wiki/Signature-Spoofing https://github.com/microg/android_packages_apps_GmsCore/wiki...
- corna 9y agoSee https://lineage.microg.org/#faq7 https://lineage.microg.org/#faq7 Also http://blogs.fsfe.org/larma/2016/microg-signature-spoofing-security/ http://blogs.fsfe.org/larma/2016/microg-signature-spoofing-s... is an interesting read
- corna 9y agohttps://lineage.microg.org/#faq6 https://lineage.microg.org/#faq6
- datamoshr 9y agoI was under the impression that lineage doesn't come with this anyway and you had to flash whatever google binaries you wanted. This just seems like they've removed one step. See bullet point on Step 1. on the wiki: https://wiki.lineageos.org/devices/cheeseburger/install https://wiki.lineageos.org/devices/cheeseburger/install
- corna 9y agohttps://lineage.microg.org/#faq3 https://lineage.microg.org/#faq3 LineageOS works without the GApps, but you lose lots of (fundamental) things, like network location and GCM (push notifications). Moreover lots of apps require the GApps API to work (often the Maps API) and crash if the GApps are not installed.
- SmellyGeekBoy 9y agoI've been running LineageOS on my OnePlus 3 for a few weeks now, since the whole data collection furore. It's been absolutely fantastic and I'd wholeheartedly recommend it to anyone. Battery life has been much better and I love all the extra features in their camera app, for instance. I'm not so sure about this though. It seems like they've disabled some very important security features. Their justification of "Lineage obviously hate freedom and are in bed with Google" doesn't sit right with me. Also there seem to be a lot of hoops to jump through just to re-enable the Play Store, which I'd consider basic functionality for any Android device. Still, the pursuit of more freedom is a noble goal and I wish them all the best.
- orf 9y agoCan you run banking applications (or any that do root detection) on LineageOS? And does the dash charger work as expected with the OnePlus?
- keeperofdakeys 9y agoLineageOS no longer comes with root installed, you have to install an extra zip file while flashing to enable it - https://download.lineageos.org/extras https://download.lineageos.org/extras IIRC some root detection mechanisms still check for an unlocked bootloader.
- petecox 9y agoAnd from the same web page there's an uninstall script to un-root the phone. This is handy if you only need root occasionally, e.g. Titanium Backup, and don't mind messing about in TWRP.
- rightos 9y agoThere's no root builtin, use Magisk with the Hide feature to prevent it from being detected by banking apps and such - even apps using the rather nasty SafetyNet work. With that said, I highly question why any banking app would check root, mine doesn't and it seems to me like even if it did I could still use their website on my phone while rooted or my Windows machine with no sandboxing whatsoever. Requiring it just for the app seems pretty damn pointless.
- floatboth 9y agoI guess that's more convenient than what I've been doing (manually patching Lineage using Tingle to support microG on every update :D)
- als0 9y agoPersonally, don't think it's worth turning off proper signature checking in exchange for shaving off 100MB of proprietary code.
- Espionage724 9y agoSignature Spoofing isn't enabled by-default and can be toggled on a per-app basis. A rogue app installed isn't going to have the ability to spoof another app unless you manually give it the permission.
- corna 9y agoThe signature spoofing in this ROM can be granted only to system privileged apps (so, built in or installed through a ZIP in recovery): the user can't turn it off (why should he?), but no app other than microG can obtain it. In this way you can't even accidentally give this permission to a malicious app.
- jbg_ 9y agoIt does not turn off signature checking. It allows selective, whitelisted system apps to impersonate other apps after a permission is granted by the user. Specifically, it allows the open-source, auditable microG apps to impersonate the closed-source, unauditable Google Play Services apps.
- morganvachon 9y agoAs much as I like the idea of running an Android device without gapps while remaining fully functional, and I feel this fork goes out of its way to attempt to remain secure, I just can't get past the fact that it's still a security hole. Eventually some bad actor is going to hammer at this hole until he finds a way in, then it's game over, restart from scratch. I think the larger problem, the one that caused the microg gang to go this route, is the increasing control Google wants to hold over their platform. Fanatics always promote Android as the "open source alternative" to iOS and Windows Phone, but if you have to strip out so much proprietary gunk that it renders the device unusable, how can they claim it's open source with a straight face? Sure, the core Android code and kernel is still open, but there's a huge difference between being able to boot a device and actually using it daily.
- amluto 9y agoI'm rather puzzled by all the fuss about this signature spoofing thing. As far as I can tell, the microg team has not proposed what seems to me to be the obvious solution: allow signature spoofing for system apps and their downloaded replacements only. So users can't install a signature-spoofed app unless they do it as root or using a .zip update. No risk of users clicking the wrong box or being dumb. Heck, one of LineageOS's review comments even offered this as a potential option with no meaningful reply. What am I missing? Edit: here's the review comment: > Adnan Begovic > Oct 8, 2015 > > Patch Set 2: > > Also "dangerous" doesn't limit third party apps from using it, you'd have to limit this explicitly to system|signature if you wanted any realm of a security model. That doesn't sound like "politics" to me. That's a spot-on reply.
- SifJar 9y agoSounds like they do this: https://lineage.microg.org/#faq7 https://lineage.microg.org/#faq7 > Moreover, to further strengthen the security of our ROM, we modified the signature spoofing permission so that only system privileged apps can obtain it, and no security threat is posed to our users.
- amluto 9y agoSure, but did they submit a patch like that to Lineage OS? As far as I can tell, they didn't.
- larma 9y agoThe patch was submitted, it's unfortunately not visible to the public: https://review.lineageos.org/194562 https://review.lineageos.org/194562
- deleted 9y ago[deleted]
- petecox 9y agoIt seems like such a small one method change, in the context of forking an entire distro. I wonder if PackageManagerService is hard coded in many places, rather than using XML dependency injection. If the latter then may it be possible to override the method in a subclass, e.g. MicroGPackageManagerService and distribute the change via a once-only installable zip? That way Lineage OS doesn't need to break security, only downstream.
- Espionage724 9y agoHow long did this fork exist? I've been providing a similar fork for the Nexus 6 for a little while: https://forum.xda-developers.com/nexus-6/development/rom-lineageos-easy-microg-unifiednlp-t3632360 https://forum.xda-developers.com/nexus-6/development/rom-lin...
- bubblethink 9y agoWhile this is cool, I feel that this will always be a second class citizen at whims of Google, who can break or change their APIs any time. What would it take to provide a proper API replacement that apps can target instead of google play services ? i.e., not spoofing but providing a legit alternative. If I have a spare server for instance, can I set up a GCM like server that can relay messages instead of them going through Google ?
- anilgulecha 9y agoIt's not going to be completely at Google's whim, as disabling a certain API/interface means older proper-android devices will also fail. So microg is banking on it's API interface being fine, given Google's interface, for business reasons, has to be fine.
- amelius 9y agoBut isn't Google auto-updating on all devices, including old ones?
- Arnt 9y agoOnly mostly. I don't know why. Lack of space on some phones maybe, or they could be configured to autoupdate via wifi only but never see wifi. Whatever the reason, if you use google play services, you'll see a few devices with old versions that don't update even though there is a newer version for that OS version.
- s17n 9y agoThis allows developers to use new api calls and have their apps work on old devices, it doesn't let google break existing apis without breaking apps. They aren't like recompiling the whole play store against every new google play services build or something.
- amelius 9y agoWhat I basically want, and have been wanting for years, is to run Linux on my phone, and run Android apps (∗) inside a sandbox (that works on both my phone and my desktop computer). But I guess it is too much to ask. (∗) for the occasional banking/railway app
- muxator 9y agoI am perfectly fine with plain LineageOS and no Play Services at all. But, then, I am fine with just Firefox and some instant messaging app. If I need other apps, I install them with Yalp store or F-droid. Lots of them run fine without Play Services (including Google Maps). The phone is fast, the battery lasts a lot, slightly better security
- ivan_ah 9y ago+1 for not needing Play Services. I've been running a free Android, and so far every app installed has worked fine, except push notifications, but I see that as a feature—less interruptions. Can you recommend a good free gmail client? The default email app doesn't work well with gmail -- double sends every time.
- burner47 9y agoI use K-9 Droid without any issues with gmail. https://f-droid.org/packages/com.fsck.k9/ https://f-droid.org/packages/com.fsck.k9/
- tomlong 9y agoSame here, it's great. Integrates with OpenKeychain as well for the best PGP/GPG workflow on a phone.
- deleted 9y ago[deleted]
- distances 9y agoMaybe you'd want to migrate away from Gmail too if you're happy without Play Services? I've been happy with Fastmail, and their import from Gmail worked without hiccups.
- Sylos 9y ago> Lots of them run fine without Play Services (including Google Maps). And there's also OsmAnd, which I think deserves a try. I haven't used Google Maps in a few years, but I initially switched, because OsmAnd was much more reliable with offline maps. I've also heard people say that they've found OsmAnd's maps to be better, especially in more secluded areas. https://f-droid.org/app/net.osmand.plus https://f-droid.org/app/net.osmand.plus
- headmelted 9y agoFrom the FAQ: Q) "Wait, on their FAQ page I see that they don't want to include the patch for security reasons. Is this ROM unsafe?" A) "No. LineageOS' developers hide behind the "security reasons" shield, but in reality they don't care enough about the freedom of their users to risk to upset Google by giving them an alternative to the Play Services... Moreover, to further strengthen the security of our ROM, we modified the signature spoofing permission so that only system privileged apps can obtain it, and no security threat is posed to our users." This is such a petulent attitude towards what sound like well-founded objections to the outright spoofing of Google signed apps that I'm just plain out already. Also, using the phrase "no security threat is posed to our users" in ANY context is blindingly arrogant, and pretty irresponsible to boot.
- ksk 9y agoDid you try understanding or asking them why they made those choices, and whether your interpretation is accurate?
- xg15 9y agoThey gave an explanation of the security issue, along with a (rather unhelpful) link to LineageOS' stance on the matter and explained which defenses they employed to keep it secure (put it behind a permission prompt that is only available for system apps) This seems reasonable to me. How is this more dangerous than, e.g., giving an app permission to continously track your physical location?
- headmelted 9y agoThat's comparing apples to oranges. One is replacing signed system components, the other is volunteering to share whereabouts with a third party. The biggest concern with this is that Google has the resources (and pressure) to get something so central to the security model correct. I've no inside information on how Google develops Play Services, but I imagine they have quite stringent policies with regards to testing and peer review. The actual functionality of Play Services is only one part of the work that goes into delivering it to your phone, and it's a lot of trust to place in anyone to get something like that right (considering the personal, security-sensitive information we keep on our phones now). My point was that the FAQ was a big red flag for me in thinking that the developers grasp this aspect of what they're proposing here.
- AlexandrB 9y agoI am utterly baffled by this project. What's the benefit of using open source software to access a completely closed-source set of services? If you're going to trust Google with your data anyways why would you care whether you're running a Google binary blob on the device?
- corna 9y agomicroG also reimplements the Google Maps APIs (using OpenStreetMaps) and the Location APIs (with different backends, like Mozilla Location Services or a local offline database). The main Google-based service is Google Cloud Messaging, which is disabled by default in microG. As you can see, microG doesn't strictly depends on the Google cloud services.
- AlexandrB 9y agoThanks, this explains things a bit. I think I just misunderstood the scope of this since I'm not in the Android ecosystem.
- blablablaat 9y agoI can't use Signal or my local railway app without Google Cloud Messaging. So I have two choices: - Don't use them - Install Google crapware package - Install microG, which supplies the APIs so other apps can function normally
- kasbah 9y agoSignal can now work without GCM, they merged an alternative that uses websockets.
- Espionage724 9y agoThe only Google-related services I'd like to use on my phone is account log-in for Pokemon GO and Ingress. My options are a 120MB+ package of proprietary Google apps with max permissions to do whatever and run in the background, or a 4MB microG package with very limited permissions.
- blablablaat 9y agoFinally! Until now after each LineageOS update I had to connect phone to adb, and patch with tingle or needle to re-enable signature spoofing. Great solution, shame the LineageOS devs won't just add this as an flashable zip or configurable option.
- segmondy 9y agoThis reminds me of what Linux and WINE for Linux was to MS Windows. It's a fight against a closed eco-system. I applaud them, and hope to give it a try.
- sturmen 9y agoThe FAQ states I should shoot them an email to get my device added to the support list, but I can't seem to find the email address… Am I blind? Can someone point me to it?
- nExXxuS 9y agoOpen a github issue or comment in here. That was obviously a point we were missing :-)
- j_s 9y agoThis sounds great but they lost me immediately as a near-complete rookie with no list of supported devices. Maybe someone else will will find this useful: https://wiki.lineageos.org/devices/ https://wiki.lineageos.org/devices/ Can this properly support Google Fi and their network-switching magic? Preliminary research claims it's possible. https://www.reddit.com/r/Nexus6P/comments/5qusmn/lineage_os_and_project_fi_does_it_work/ https://www.reddit.com/r/Nexus6P/comments/5qusmn/lineage_os_... if you install it from the play store you need to make sure that Project Fi has all of it's permissions granted
- Animats 9y agoWhat's the point? If you're using Google services, you're a slave to the mothership and they know what you're doing. So why use a different layer of middleware to access them? I use F-Droid because I don't want to use Google services. I do miss voice dialing, though.
- Brakenshire 9y agoYou're mixing up microG with OpenGApps. microG for instance can do Assisted GPS location searches, but allows you to choose your own Location Services provider, Mozilla instead of Google. It's not just a middleware to access the same Google services.
- Brakenshire 9y agoCan't you just install microG services from F-Droid on any LineageOS phone? Why doesn't that have the same issue with spoofing?
- geekamongus 9y agoI have a Pixel XL (first gen) on Google Project Fi. Do I need LineageOS?
- alinspired 9y agocan't answer your question, but there is no official LineageOS for any Pixel (1st or 2nd gen). There are unofficial ones
- fithisux 9y agoIs it possible to use microG with Android x86 on netbooks?
- sanbor 9y agoIs this going to try to install updates every day? It sounds like too much.
- msdocs 9y agoI tested a few apps that required gapps like uber and transit and both would load a map but would crash and fail
- JepZ 9y agoI wish Google would put and end to this by releasing the code for their Android services and slowly force the Android manufacturers to open source all future drivers. Please Google, don't be evil.