4 ms·
Unlike GrapheneOS (which I recommend you use if you can) and CalyxOS, my project https://divestos.org https://divestos.org is tested working on 30+ devices.
by SubzeroCarnage 5y ago
Unlike GrapheneOS (which I recommend you use if you can) and CalyxOS, my project https://divestos.org https://divestos.org is tested working on 30+ devices.
- atatatat 5y agoVery cool! Few quips: Silence was last updated (on F-Droid) a year ago — is this project secure//being maintained? & Mozilla-cousin browser: you're going to lose the security clout these days unfortunately.
- SubzeroCarnage 5y agoSilence is sadly no longer maintained, but it still seems to work for now. I will eventually replace it. Re Mozilla: I do state on my browser comparison page that Chromium browsers are more secure. Also the Bromite repository is included in F-Droid by default on DivestOS.
- atatatat 5y agoVery cool! Thanks for stopping in here!
- atatatat 5y agoProps on bringing verified boot to those devices Lineage can//will not, and doesn't tell users clearly that they could have it with other options.
- SubzeroCarnage 5y agoThat is a limitation of Lineage only because they choose to cater to users who want root (which usually modifies /system) and to support flashing Google Apps.
- summm 5y agoWhy would having root itself rule out secure boot? It's just that they refuse to offer root themselves, and only as a result of that refusal one has to use system modifications to gain root. In a sense this is the opposite of your claim: they do explicitly not cater to root users.
- SubzeroCarnage 5y agoVerified boot is only enforcing on -user builds. Lineage ships -userdebug builds. Furthermore Lineage's official root addon writes to /system. You can't have any additional changes to system or else verified boot won't boot. You can't have it both ways as it stands. That isn't to say they are incompatible, you can compile-in root support before the system hashes are generated and then you can have a locked bootloader with verified boot with root support. But you cannot make any additional changes to /system with that root power afterwards.
- zozbot234 5y ago> But you cannot make any additional changes to /system with that root power afterwards. Not a showstopper, as modern root solutions like Magisk support "systemless" root, via file system overlays.
- SubzeroCarnage 5y agoI am not sure how systemless root interacts with verified boot. I've never tried it myself.
- commoner 5y agoInstalling Magisk requires you to patch the bootloader or recovery image, which would break verified boot: https://topjohnwu.github.io/Magisk/install.html https://topjohnwu.github.io/Magisk/install.html The only way to preserve verified boot with Magisk is for the bootloader or recovery image to have Magisk compatibility built-in prior to signing. I don't think any flavor of Android that supports verified boot is currently doing this.