4 ms·
> That's irrelevant on Android because system apps can be updated without touching the /system partition, if the .apk is signed with the same key. The system wi
by faust201 11mo ago
> That's irrelevant on Android because system apps can be updated without touching the /system partition, if the .apk is signed with the same key. The system will store the updated .apk file in /data/app, but otherwise grant it privileged permissions that only system apps can get. That's how google play services can update itself and still keep its privileged status, even though the phone OS hasn't been updated in years.
How is this relevant? Yes, in a custom ROM - USER NEEDS TO BE CAREFUL. (i.e) if someone installs random app - signed by AOSP keys (and that ROM was installed by AOSP keys) it will get installed.
I am yet to see proof that this causes major meltdown.
Reg complete ROM- Except for this: https://wiki.lineageos.org/signing_builds#changing-keys https://wiki.lineageos.org/signing_builds#changing-keys
Assuming a phone was securely installed (after verifying sha/sig) with lineageOS RECOVERY and ROM - it will not accept a build with different sign keys. (i.e) AOSP keys.
- gruez 11mo ago>How is this relevant? Yes, in a custom ROM - USER NEEDS TO BE CAREFUL. (i.e) if someone installs random app It's relevant because it's an exploit vector that can be easily closed with basically zero downside, but for whatever reason it hasn't. Besides the risk of having such holes in the first place, the lack of willingness to fix is indicative of the security culture of the organization as a whole (ie. not very good). >I am yet to see proof that this causes major meltdown. It doesn't cause a major meltdown because most people don't use lineageos, so mass infections don't bother targeting them. That doesn't mean the system is actually secure. It's like using netscape navigator to browse the web. It might not cause a "major meltdown", but only because nobody bothers targeting it, not because it's actually secure. >Assuming a phone was securely installed (after verifying sha/sig) with lineageOS RECOVERY and ROM - it will not accept a build with different sign keys. (i.e) AOSP keys. Right, but the allegation is that /e/os uses test keys, either intentionally or through incompetence.
- palata 11mo ago> Yes, in a custom ROM GrapheneOS is an alternative OS, that keeps the same security model as Android. It's not a "custom, hacked thing that disables the security". > Assuming a phone was securely installed (after verifying sha/sig) with lineageOS RECOVERY and ROM - it will not accept a build with different sign keys. (i.e) AOSP keys. Do you know which keys are used by Lineage? My understanding is that some phones running Lineage use the testing keys. Simply because some phones don't allow "custom keys". But that means that it defeats the point of the signing. Are you saying that the signing is useless in Android?