3 ms·
> Can I use my banking software with all the security bells and whistles? Most custom ROMs(including official LineageOS) are as secure, usually even more, th
by phh 3y ago
> Can I use my banking software with all the security bells and whistles?
Most custom ROMs(including official LineageOS) are as secure, usually even more, than OEM ROMs. There is just one threat model where it is weaker, which is the evil maid. But it is safer on all the other ones (the evil metro wifi, the evil video, the evil app...). (and personally I take the metro everyday, while taking my shower while I have a maid home just doesn't happen)
As for whether banking apps will work, it's entirely dependant on whether your back is trying to serve their customers or not. Most banks I use work just fine on custom ROMs without hacks. But for instance Google Pay is skimming down on costs, and users pay the price for it.
- npteljes 3y agoFrom a usability standpoint, the reasons don't matter, many of the banking apps are unusable, full stop. This is something that someone has to reckon with, if they want to venture into the custom OS land.
- logicprog 3y ago> Most custom ROMs(including official LineageOS) are as secure, usually even more, than OEM ROM I definitely don't think that's the case. I'd check out the sections on microG and custom ROMs here: https://madaidans-insecurities.github.io/android.html https://madaidans-insecurities.github.io/android.html (they're very knowledgeable, so usually factually accurate, but often frame or evaluate things in a very biased way IMHO, so be sure to evaluate the verifiable facts they state for yourself, and your own threat model). They're way more open to exploitation and far less secure than OEM ROMs, typically because of the way they have to pry open security stuff to get their various hacks to work. They are typically much better on privacy, but having your phone, from which you do all your communication and banking, and which has a dense cluster of sensors and transmitters that follow you wherever you go, be more open to exploitation by any random hacker or piece or malware seems like a bad idea to me.
- phh 3y agoOEM ROMs that passed Google certifications and everything have been found in the past to: - Send the content of your clipboard to the internet (OnePlus) - Disabled SELinux on boot (Asus) - Allowed any app to be uid 1000, and exploit known for years (Samsung) - Ignore Linux policy and just picked security-looking patches. And got pwned repeatedly by simply looking at LTS patches. (Google) As for madaidans-insecurities, they are extremely biased. Just mentioning microg: > which allows apps to request to bypass signature verification. There is EXACTLY *one* app (k k k, two because of Play Store fake too) that bypasses signature verification, and you can VERIFY, which app does it, and WHICH signature it fakes. LineageOS integrated their own microg/fake signature mechanism thanks to Google anti-freedom policy, and you can review their own integration that is even more restricted than what I did (which already is infinitely more secure than what madaidans-insecurities mention): https://review.lineageos.org/c/LineageOS/android_frameworks_base/+/383573 https://review.lineageos.org/c/LineageOS/android_frameworks_... The final comment in the microg section basically sounds like "oh yeah, that argument could be completely wrong, meh"
- logicprog 3y ago> OEM ROMs that passed Google certifications and everything have been found in the past to That's really good to know to keep things in perspective! Thanks for taking the time to bring that perspective. Although I would say that it seems like LineageOS kind of does all of those kinds of things at once, whereas OEM ROMs might do one or the other each? Or am I wrong? Edit: also, I can't find any info on your ASUS claim, and the OnePlus one seems misleading (it's not some vulnerability or passive background thing that just broadcasts your clipboard, it was an app you could electively use to send clipboard stuff to other computers). > There is EXACTLY one app (k k k, two because of Play Store fake too) that bypasses signature verification, and you can VERIFY, which app does it, and WHICH signature it fakes. I'm not familiar with Lineage OS — does this mean that you know only one app will ever do this and can verify that, so it's just one specific exception to the rule, or is it just that the spoofing was made possible for just that one app, and only one app is known to do it, but any app could without your knowledge in theory? > As for madaidans-insecurities, they are extremely biased. Like I said, their factual knowledge is generally useful, but their framing (including context, so you can get some perspective) and analysis is usually wildly biased IMHO. I wonder what their damage is.