3 ms·
OEM ROMs that passed Google certifications and everything have been found in the past to: - Send the content of your clipboard to the internet (OnePlus) - Dis
by phh 3y ago
OEM ROMs that passed Google certifications and everything have been found in the past to:
- Send the content of your clipboard to the internet (OnePlus)
- Disabled SELinux on boot (Asus)
- Allowed any app to be uid 1000, and exploit known for years (Samsung)
- Ignore Linux policy and just picked security-looking patches. And got pwned repeatedly by simply looking at LTS patches. (Google)
As for madaidans-insecurities, they are extremely biased.
Just mentioning microg:
> which allows apps to request to bypass signature verification.
There is EXACTLY *one* app (k k k, two because of Play Store fake too) that bypasses signature verification, and you can VERIFY, which app does it, and WHICH signature it fakes. LineageOS integrated their own microg/fake signature mechanism thanks to Google anti-freedom policy, and you can review their own integration that is even more restricted than what I did (which already is infinitely more secure than what madaidans-insecurities mention): https://review.lineageos.org/c/LineageOS/android_frameworks_base/+/383573 https://review.lineageos.org/c/LineageOS/android_frameworks_...
The final comment in the microg section basically sounds like "oh yeah, that argument could be completely wrong, meh"
- logicprog 3y ago> OEM ROMs that passed Google certifications and everything have been found in the past to That's really good to know to keep things in perspective! Thanks for taking the time to bring that perspective. Although I would say that it seems like LineageOS kind of does all of those kinds of things at once, whereas OEM ROMs might do one or the other each? Or am I wrong? Edit: also, I can't find any info on your ASUS claim, and the OnePlus one seems misleading (it's not some vulnerability or passive background thing that just broadcasts your clipboard, it was an app you could electively use to send clipboard stuff to other computers). > There is EXACTLY one app (k k k, two because of Play Store fake too) that bypasses signature verification, and you can VERIFY, which app does it, and WHICH signature it fakes. I'm not familiar with Lineage OS — does this mean that you know only one app will ever do this and can verify that, so it's just one specific exception to the rule, or is it just that the spoofing was made possible for just that one app, and only one app is known to do it, but any app could without your knowledge in theory? > As for madaidans-insecurities, they are extremely biased. Like I said, their factual knowledge is generally useful, but their framing (including context, so you can get some perspective) and analysis is usually wildly biased IMHO. I wonder what their damage is.
- kasabali 3y ago> I wonder what their damage is. Torvalds' low opinion of on security researchers in general comes to mind.