11 ms·
I'm curious how secure LineageOS is. It doesn't seem to have the resources of Apple/Google to respond to vulnerabilities. I haven't even found anything on this
by tmoravec 4y ago
I'm curious how secure LineageOS is. It doesn't seem to have the resources of Apple/Google to respond to vulnerabilities. I haven't even found anything on this topic at their website. Googling "lineageos security response policy" haven't found anything useful, either.
How does it compare to flagship Samsungs/Pixels/iPhones? Is it usable in, say, corporate settings that do have some security standards in the vein of "two years old iPhone OK, six years old Android not"?
- aaaaaaaaata 4y agoLineage actively and knowingly break the Android Security Model in order to achieve widespread compatibility and reduce e-waste. Security is not their top competency, nor mission. Check out the pages on GrapheneOS.org, definitely seems they're who you're after.
- josephcsible 4y ago> Lineage actively and knowingly break the Android Security Model Can you provide evidence for this?
- aaaaaaaaata 4y agoAlways start here: https://source.android.com/security/ https://source.android.com/security/ From another subthread: > They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
- josephcsible 4y ago> Always start here: https://source.android.com/security/ https://source.android.com/security/ I don't see any evidence for your claim there. > From another subthread: Replied in that one.
- aaaaaaaaata 4y agoI'm pointing you toward how things are meant to work, not arguing with you or leading you through your research. If you want to skip paying $150 for a Pixel to use on Graphene or Calyx or something halfway decent, and "just use Lineage how bad could it be", be my guest!
- josephcsible 4y agoThe "Support length" table at https://calyxos.org/docs/guide/device-support/ https://calyxos.org/docs/guide/device-support/ shows that CalyxOS supports a bunch of devices even after the vendor drops support. For example, support for the Pixel 4a 5G ends in October 2023, but CalyxOS plans to support it until August 2024. It's unfair to recommend against LineageOS for doing that while supporting other custom ROMs that also do it. Also, for supported Pixels $150 or less, https://swappa.com https://swappa.com only has the Pixel 3a, which loses manufacturer support next month, and the Pixel 4, which loses manufacturer support 6 months from now.
- zekica 4y agoLineage doesn't "break" android security model. It works around OEMs that don't support installing your own keys in the bootloader. Otherwise, security model works the same as any other android. LineageOS's first priority isn't security - it's freedom. Graphene and CalyxOS have security as the first priority - but have only a couple of phones on their support list and they deprecate old devices as soon as they stop receiving vendor updates.
- snvzz 4y ago>LineageOS's first priority isn't security - it's freedom. But, importantly, they also care about security, and you'll get security updates faster and more often than with the vendor's stock ROM.
- aaaaaaaaata 4y agoApplying security patches to something that doesn't even do verified boot seems...hmmm
- snvzz 4y agoSure, because security is boolean. Either something is secure, or it is not. This is sarcasm, to be clear. (on my device, it is possible to just "fastboot oem lock", but that is aside the point)
- lberrymage 4y agoYes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
- josephcsible 4y ago> They ship userdebug builds as production releases What specific security problem does this cause? > pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.) This is good for security. Not everyone can afford to get a new phone as soon as the vendor drops support, and just because you can't fix everything doesn't mean that you shouldn't fix what you can. > ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates) What's incorrect about it? > don't support locking the bootloader to enable verified boot on many supported devices This isn't really their fault. On most devices, relocking the bootloader with anything non-stock has a high chance of permanently hard bricking.
- salawat 4y ago>Android is designed for developers. Security controls were designed to reduce the burden on developers. Security-savvy developers can easily work with and rely on flexible security controls. Developers less familiar with security are protected by safe defaults. In addition to providing a stable platform to build upon, Android gives additional support to developers in a number of ways. The Android security team looks for potential vulnerabilities in apps and suggests ways to fix those issues. For devices with Google Play, Play Services delivers security updates for critical software libraries, such as OpenSSL, which is used to secure app communications. Android security released a tool for testing SSL (nogotofail) that helps developers find potential security issues on whichever platform they are developing. Vs. >Android is designed for users. Users are provided visibility into the permissions requested by each app and control over those permissions. This design includes the expectation that attackers would attempt to perform common attacks, such as social engineering attacks to convince device users to install malware, and attacks on third-party apps on Android. Android was designed to both reduce the probability of these attacks and greatly limit the impact of the attack in the event that it was successful. (Read: Handcuff users to keep them from violating developer expectations and assumptions) >Android security continues to progress after the device is in the user's hands. Android works with partners and the public to provide patches for any Android device that is continuing to receive security updates. (Read: we work with developers (them again)* to provide patches to devices that are convenient to deliver patches to) >More information for end users can be found in the Nexus help center, Pixel help center, or your device manufacturer’s help center. (Read: we take no responsibility for explaining how any developer's use of this power is exercised, ask them!)* >This page outlines the goals of the Android security program, describes the fundamentals of the Android security architecture, and answers the most pertinent questions for system architects and security analysts. It focuses on the security features of Android's core platform and doesn't discuss security issues that are unique to specific apps, such as those related to the browser or SMS app. (Again, even when talking about users, the language drifts back to people we'd lump under developers... who exactly is the User here?) Then this gem: >Verified Boot strives to ensure all executed code comes from a trusted source (usually device OEMs), rather than from an attacker or corruption (oh, is corruption where user programs are classed under?). It establishes a full chain of trust (for whom, OEM's again?), starting from a hardware-protected root of trust to the bootloader (whose root of trust, OEM?), to the boot partition and other verified partitions. Sorry, but the language used to describe all of this completely lets the cat out of the bag on who the Android community holds to be the true benefactors of your "ownership" of a handset. https://source.android.com/security/ https://source.android.com/security/ Straight from the source. Quiet parts emphasized and said out loud by me. Android is the most transparently User/operator hostile piece of Open Source software I have ever had the misfortune of laying my eyes upon. The fact you basically have to be a developer to list and understand the things you need to do to get anything non-trivial done speaks volumes.
- jeroenhd 4y agoLineageOS relies on the open source kernels and pre-existing vendor blobs to run. Qualcom drivers and such won't receive any patches, the best you can hope for is that the driver blobs are extracted by the device maintainer and put into the next build. As for the Android stack itself, LineageOS follow the upstream Android branches very closely where it can. Most vulnerabilities in that stack will probably be shared among devices, so security issues will probably be fixed within a reasonable amount of time. Google's Android patches should also be present in the nearest weekly updates after public release. The lack of official driver and kernel patches make the security of LineageOS a little strange. There are definitely some patches that LineageOS can apply, but in the end they rely on the vendor to publish all the necessary patches, and that can take a while. There's also the fact to consider that out of necessity, the bootloader on the phones is unlocked. Most phones won't allow you to lock it again with your own keys (if you try, you'll often brick the device!) so it's trivial for a malicious actor to flash a new OS full of spyware and key loggers onto the system partition. Having said that, LineageOS supplies weekly updates to my Oneplus One, even though it's showing its age. Neither Qualcom nor Oneplus will ever release any more patches for this device, so for kernel level security I'm boned. However, I still get the latest and greatest Android 11 framework security patches. This should protect the phone against the huge Bluetooth exploit found a few years back despite it being over eight years old now. LineageOS is quite transparent about this, even showing that their device is missing patches right inside the settings (https://www.xda-developers.com/lineageos-trust-centralized-interface-security-privacy/ https://www.xda-developers.com/lineageos-trust-centralized-i...). I don't think you can expect much more from a project run by volunteers. My daily driver phone receives "quarterly" security updates (sometimes off by a month or so) so I'd rate LineageOS above Xiaomi in this sense. The LOS Android stack itself should also be on par with or even better than some flagship phones. Sadly, for the complete picture, Qualcom and other manufacturers determine how secure LineageOS can be. In general, the bootloader lock status and lacking supply of source code are a real pain for open source efforts. Some phones may see a mainline kernel with all of the recent Linux patches as a result of the postmarketOS efforts (https://wiki.postmarketos.org/wiki/The_Mainline_Kernel https://wiki.postmarketos.org/wiki/The_Mainline_Kernel) but cleaning up vendor code and reverse engineering drivers isn't exactly a fast process.
- 4y ago
- ajot 4y ago> I'm curious how secure LineageOS is. It doesn't seem to have the resources of Apple/Google to respond to vulnerabilities. Well, you get weekly updates, and you can see what changes are made. Most of them are security ones, and you're getting them 4/5 times a month vs once per month with stock Android in my previous experience. For example, here you can see the changekog for the Motorola Moto G7 Plus. I don't think this can be compatible woth corporate policies, though. As an end user, I'm more than satisfied.
- raelmebrand 4y agoSecurity is a bit different for different people. If you want to do browsing minimising ads/spying from rubbish lineage is there. Also one can block minimise data, improve battery life by avoiding playstore > corporate settings that do ha Use a dedicated phone
- josephcsible 4y agoSince LineageOS tracks AOSP, they get to piggyback off of Google's security efforts. They tend to release the monthly Android security patches faster than most phone vendors do for their stock ROMs.