3 ms·
Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provid
by lberrymage 4y ago
Yes it does. They ship userdebug builds as production releases, pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.), ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), don't support locking the bootloader to enable verified boot on many supported devices, etc..
- josephcsible 4y ago> They ship userdebug builds as production releases What specific security problem does this cause? > pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.) This is good for security. Not everyone can afford to get a new phone as soon as the vendor drops support, and just because you can't fix everything doesn't mean that you shouldn't fix what you can. > ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates) What's incorrect about it? > don't support locking the bootloader to enable verified boot on many supported devices This isn't really their fault. On most devices, relocking the bootloader with anything non-stock has a high chance of permanently hard bricking.
- aaaaaaaaata 4y ago> This is good for security No, it isn't. It's good for reducing e-waste, your security is on the line. Having the newly shaped and colored Android UI doesn't do anything to fix security issues..
- josephcsible 4y agoSecurity issues can occur in both the device-agnostic Android OS code and in device-specific drivers. Some people are going to continue to use phones after the vendor drops support. Although those people won't get security updates to their device-specific drivers anymore no matter what they do, by using LineageOS instead of their stock ROM, they will get security updates to the device-agnostic Android OS code.
- kelnos 4y ago> pretend to support devices past their vendor EOL They don't "pretend" anything. They are very clear that, after a device no longer gets kernel/driver updates from the manufacturer, they can only provide OS/framework updates. > don't support locking the bootloader to enable verified boot on many supported devices Can you expand on this more? My understanding was that you could do this on Pixel phones, but that no other manufacturer supports adding user keys to the bootloader.
- aaaaaaaaata 4y agoSome do. The point is, it's not as secure to run around with this disabled. No, it's not only about in-person or targeted attacks.
- timschumi 4y ago> They ship userdebug builds as production releases `userdebug` is used to have a few specific debugging capabilities that aren't available on a `user` ROM. Note that this is not the same as the standard `userdebug`, as most security measures that would otherwise get removed are manually reinstated. > pretend to support devices past their vendor EOL (which is impossible since Lineage can't provide security updates for firmware etc.) So... no security fixes at all are better in your opinion? > ship the F-Droid Privileged Extension (which uses an incorrect approach to implementing unattended updates), Where are you getting this from? Neither F-Droid nor its privileged extension is included in the system. > don't support locking the bootloader to enable verified boot on many supported devices There is nothing that inherently prevents you from relocking your bootloader on LineageOS. But technically, something may go wrong at any time, so it neither is officially supported nor endorsed, and the keys necessary for relocking the bootloader are not provided. If someone wants to, they can always just build LineageOS themselves (with all system modifications built-in, because anything else would break the signature), sign it with their own keys, and reconfigure their bootloader to use that key.