LineageOS 24.0 (lineageos.org)

390 points by timschumi 16 hours ago

163 comments:

by deng 13 hours ago

I was secretly hoping they'd stop supporting the Pixel 4a so I would have a reason to get a new phone, but no, still there in the list of supported devices. So I guess I'll just keep using that thing another year... Anyway: big thanks to the Lineage maintainers, keeping so many phones from landfill!

by this_user 11 hours ago

If you need a reason, the modem and the baseband firmware have several unpatched vulnerabilities on that model, which is not something that an Android update can resolve.

by throwaway198846 9 hours ago

Is there an easy way to tell if there are unpatched vulnerabilities in my phone's modem and baseband?

by PaulCarrack 8 hours ago

Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.

by holowoodman 7 hours ago

Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them. Usually under ongoing attack, at least by professional phone cracking software vendors and secret services.

by gruez 4 hours ago

>Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them.

Maybe if you include third party android OEMs like samsung, but google pixels are as up to date as you can get.

by aboringusername 4 hours ago

Pixels running GrapheneOS sure, but stock Pixels lag months behind patches that exist but not yet shipped. Check any bulletin and it links to git commits to months ago.

by gruez 3 hours ago

>Check any bulletin and it links to git commits to months ago.

Is there any evidence that the git commits weren't in the ROMs from months ago? The monthly ASB corresponds to when the bugs are publicly disclosed, not when they made it into ROMs.

by grapheneos 2 hours ago

Pixels only ship a tiny subset of the security preview patches early. Samsung ships a subset for their flagship devices too and it's likely larger than Pixels. Samsung lists these patches in their bulletins and you can retroactively figure out which were future Android Security Bulletin patches. Go through the vulnerabilities for September 2026 or October 2026 and search for them in Samsung's bulletin.

The only way to get the full set of security preview patches is through GrapheneOS. It's strange Google doesn't ship more for the Pixel OS but that's the way it is right now. It takes them around 4 weeks to make a release and even longer when including the time for adding changes to it so there's a long delay built into the process. They should fix it but are clearly not prioritizing it without media pressure that's not happening. They do a lot better than other OEMs but that's much different from doing a good job.

by grapheneos 2 hours ago

Android Security Bulletins don't list the vast majority of firmware, driver, HAL and especially Linux kernel vulnerabilities. Those list a large subset of the High and Critical severity Android Open Source Project (AOSP) vulnerabilities backported to older releases along with a tiny portion of non-AOSP vulnerabilities. AOSP vulnerabilities below High and Critical severity aren't backported so those aren't listed. Non-AOSP vulnerabilities for Pixels are covered in the Pixel Update Bulletins with many of those being vulnerabilities in components used by other devices. Each OEM is supposed to make their own equivalent to the Pixel Update Bulletins, but they aren't required to provide those updates to claim the latest patch level.

by andrepd 2 hours ago

In a practical sense, what are the consequences of that? If you're careful about not installing random shit on your phone?

by grapheneos 2 hours ago

It has remotely exploitable vulnerabilities in the firmware, Linux kernel, kernel drivers, userspace drivers and HALs. Those don't require installing anything on your device to exploit. There are publicly available proof of concept exploits for a bunch of these vulnerabilities.

by cookiengineer 6 hours ago

Well, it might be worth it reversing firmwares now with UART pins connected. A lot has changed in (agentic) reverse engineering.

BRB gonna try this out on my old Fairphone

by umvi 8 hours ago

I too have a 4a that is still ticking thanks to Lineage!

The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.

by bronson 7 hours ago

I have stock Android on a Pixel 10 and RCS group texts don't work here either. Some people just can't be added to the group and some people just don't receive the texts.

It's so bad.

by ezst 6 hours ago

What happened there, ... After official support by Google for the 4a stopped, I remember checking LOS out, and found that it wasn't supported there either. Did I hallucinate that, or did LOS resume support afterwards? Or maybe I'm mixing up LOS and graphene

by t_mahmood 5 hours ago

I have a OnePlus 7, and it's chugging along on LOS, otherwise I would be without a smartphone. Heh, fortunately it's still on the supported list

by shayan01 13 hours ago

I wish I could still use my Pixel 4a but the battery is pretty much dead and it's too much money to replace it

by riedel 13 hours ago

Prices here are 13EUR including tools from what I can see.

The only reason I have been switching phones is banking apps: so much for Europe's right to repair..

by deng 13 hours ago

I have yet to find a banking app that refuses to work on LineageOS. The only problem is if you root your phone, in which case you'll have to use Magisk to hide root from those apps, which also works fine so far.

by platinum95 13 hours ago

Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.

by AnthonyMouse 6 hours ago

> Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.

What possesses companies to do things like this? A customer running a current version of LineageOS is going to have better security than running the out of date Android version that came with the phone. An attacker who wants root on something that will run the bank app doesn't have to use a different OS, they can just use any of this month's CVEs to root the "approved" version. Even requiring the latest patches -- which would exclude entirely too many actual customers' phones -- wouldn't stop attackers from controlling their own devices, because they could root the device before installing the patch and then install the patch for the vulnerability they used to get root on the device where they already have it.

And attackers who are going to modify the system to carry out an attack inherently have some kind of software development capacity, so measures like this have no effect on them and all they actually do is interfere with the ability of honest normies to replace their out of date OS with a version that is less likely to be compromised by attackers.

Are they just taking kickbacks from Google or something?

by pkal 6 hours ago

I suspect that especially banks have paranoid lawyers that probably don't understand the situation entirely, and perhaps because of that, mandate that all means have to be used to prevent non-official builds from being used, so that they cannot be sued (for some reason) if "something" goes wrong. Though I don't know if they are consistent and also apply the same reasoning to phones that don't have active security updates any more.

by AnthonyMouse 5 hours ago

I feel like "the lawyers told us to do something stupid for no legitimate reason" is just one part of a bureaucracy trying to blame another part for the fact that the bureaucracy itself is doing something stupid for no legitimate reason.

by afavour 5 hours ago

While you’re correct there’s also no ambiguity about who has the final say in that scenario. The lawyers always win out.

by AnthonyMouse 4 hours ago

This is objectively not true because there are companies, even banks, where this level of stupidity has not prevailed. In turn this implies that the others are doing something which is different but possible, and the scoundrel companies could be doing that too.

Even if the something is no more than engaging less fatuous attorneys.

by afavour an hour ago

> there are companies, even banks, where this level of stupidity has not prevailed

Yes, because that particular set of lawyers haven’t said it has to be blocked. Doesn’t mean my statement that lawyers have final say is “objectively not true”.

by Telaneo 3 hours ago

> This is objectively not true because there are companies, even banks, where this level of stupidity has not prevailed.

All it takes for this to happen is the lawyers not knowing.

by riedel 12 hours ago

This is the problem: it was a cat and mouse game always. I managed even strong integrity with keybox stuff and so on. Yes it is possible. But if you really need to do send money or e. g. want to pay with NFC, it gets rather stressful. Yes, I got everything working (Note 10 pro on LOS 23), but never longer than a few month.

by grapheneos 2 hours ago

There are alternatives to Google Pay in Europe which work on GrapheneOS and it's likely most of those work on a production (user) build of LineageOS with a locked bootloader too. Only a few are specifically permitting GrapheneOS, and those would also be willing to explicitly permit a subset of LineageOS devices too. They'd need to start keeping a bit more of the standard security model and features intact which wouldn't be a large change. They'd mostly just need to make full production builds and start officially supporting locking. Having the privacy and security improvements done by GrapheneOS is in no way a requirement for compatibility with those financial apps.

by riedel an hour ago

This really is really a great development. I really just hope that will be true for the new European Digital Identity Wallet as well and we see adoption across multiple industries.

The state for me personally is that my joint bank account with my wife uses a play integrity protected banking app (changing your own a accounts to a better bank is one thing). Also beyond banks things now require proprietary 'secure' TAN apps like my insurance broker. The issue is that for me every a new problem like this popped up and to find solutions take time over and over. Even thing that work now may stop working the next minute because there is no real effort of fintech and its management to keep compatible with niche devices. It is mostly either coincidence or the effort of tech savvy individuals at those companies.

We only can hope that a large group of people including regulators get sanctioned or mandated not to use any US tech even privately so they see little offer is left even inside Europe that is truly sovereign. I gave up for now (after about 10 years exclusive on LineageOS ). I actually bought a pixel to have Graphene as a way out of vendor ROMs again, but I still don't have the energy to switch (alone reregistration all those TAN apps takes ages often involving waiting weeks for stupi snail mail activation letters)

by pimeys 9 hours ago

I just decided to completely stop paying with NFC. I always carry a few cards with me and Wero is already working in a few spots, which requires just your banking app and a working camera.

I don't even have Google Wallet installed anymore.

by phillc73 8 hours ago

Go even further and carry cash! No technology dependency and "just works".

by pimeys 7 hours ago

I live in Berlin... So naturlich!

by phillc73 6 hours ago

And I’m in Austria. Plenty of businesses still ONLY accept cash. And not just small rural concerns. Had lunch in the city yesterday and the restaurant only accepted cash payment.

by pimeys 5 hours ago

In Berlin they started following the EU law and you can quite often pay with a card. Even in places like biergartens. Still having cash when going to a Kneipe, although last time they also accepted cards which was a bit weird...

by phillc73 3 hours ago

So disappointing really. Won’t someone think of the traditional values.

by latexr 7 hours ago

Not everywhere, unfortunately. There are places in the world where only accepting digital payments is the norm and they won’t serve you if you pay in physical cash.

by phillc73 6 hours ago

And the problem is people stopped paying cash, thus the facility was largely withdrawn. I don’t know what the answer is, but my gut says if cash remains legal tender, businesses should be obliged to accept it as a form of payment.

Otherwise, vote with your wallet wherever possible and prefer those businesses that do accept cash.

by Telaneo 3 hours ago

And even if they theoretically can serve you, one generally doesn't want to be 'that guy'.

I'm glad the option is still there in most places, but it's clear most people don't actually care for cash (neither do I for that matter, other than as a backup solution).

by pimeys 12 hours ago

Good to know. I'm using N26 and they work just fine in Graphene OS. What I do is I create a private space for the apps needing play services, which I keep locked most of the time. This acts as a separate profile and when locked, the apps including play services are completely off. My main profile uses only open source apps and no play services.

I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.

by Semaphor 10 hours ago

N26 also works fine on rooted devices. They don’t randomly block devices like others (besides Revolut, DKB comes to mind).

by phillc73 8 hours ago

I applied to open an N26 account, and after completing all the necessary documentation they then told me I had to install their app to activate the account. Forget it.

Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.

by Semaphor 7 hours ago

That’s not a licensed bank, from what I can see.

by phillc73 6 hours ago

That’s right. Wise works with partner banks. However, their accounts are still covered by up to $250k of FDIC insurance.

by kevin_thibedeau 4 hours ago

Insurance against collapse of the bank. FDIC doesn't insure against fraud because you expanded your trust relationship across multiple third parties with credentials to access your account.

by pimeys 9 hours ago

Just be careful. I locked myself out from my bank when I installed a second phone that did not have sim card yet and had the app in my old phone.

It requires a sim card and cannot be used from multiple phones. So they put you to this endless face scan loop and then lock you out.

by chasil 8 hours ago

A plain Lineage install will include "rooted debugging" in the developer options.

This is separate from the Magisk root app.

I don't believe using the ADB root functionality is problematic. The Magisk app also has a hide mode.

by theodric 8 hours ago

Revolut, UBS, ABN AMRO

by shayan01 13 hours ago

Too lazy to do it myself tbh

by deng 9 hours ago

Perfectly valid answer, I don't understand why people would downvote. It's not a trivial procedure, see https://www.ifixit.com/Guide/Google+Pixel+4a+Battery+Replace...

by toredash 13 hours ago

Where can one get one for that price range?

by riedel 12 hours ago

In Germany that would be market places like eBay or Amazon (i.e. non-originally replacement parts). Original ones go for around 45 EUR (iFixit). But I guess you wouldn't care too much about original parts at that age.

by dopedopedope 12 hours ago

+ screen because you WILL break it

by riedel 12 hours ago

My wife replaced batteries herself with pixel 3a and 6a without any problems (I guess I wouldn't test if they are still waterproof).

by catlikesshrimp 9 hours ago

I bet sprinkle beside the bath is ok, but toilet plop is not ( I have seen the second one, I suggest grabbing it without any delay, better grab it working because you have to grab it anyways)

by Klaster_1 13 hours ago

I replaced battery in mine for like 90 EUR and several months in dropped it and broke the screen. Would still use it instead of 9a, love how light and compact the phone was. At least now I have a spare phone to root and do stuff with that I couldn't on my main one.

by mistyvales 12 hours ago

I recently pulled out my Pixel 3 and forgot how much I liked the form factor.

by DoctorOetker 3 hours ago

I was secretly hoping I didn't misread and Linaro wiki would be up again, I really wish we could just install mainline linux on those Android phones...

by wkjagt 10 hours ago

The 4a is a great phone. So thin and light, and even a headphone jack.

by pavinjoseph 11 hours ago

Does LOS provide kernel backports or is it limited to userspace?

by grapheneos 2 hours ago

The vast majority of kernel vulnerabilities aren't backported to end-of-life devices. Special cases are made for certain vulnerabilities with a lot of media coverage. Firmware, kernel drivers, userspace drivers and HALs on end-of-life devices go without patches in general.

by gruez 8 hours ago

They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).

[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...

by grapheneos 2 hours ago

That's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.

by pavinjoseph 5 hours ago

That's honestly impressive, enough security for a locked down backup phone.

by grapheneos 2 hours ago

It's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.

by haunter 13 hours ago

>Recently, Contributor 0xCAFEBABE introduced a very different kind of generic target that can be run on various types of bare-metal hardware devices.

>While it’s still in experimental state, it has successfully booted on:

>Common x86_64 PCs

>Apple Silicon Macs

>NVIDIA DGX Spark

>Qualcomm Snapdragon X Series Laptops

That actually sounds awesome! Refurbishing old laptops with Android would be a nice choice alongside with Desktop Linux.

by zx8080 12 hours ago

Why would someone want android with crappy apps comparing to linux on the old laptop?

by dolorian 7 hours ago

Better sandboxing. If one of the programs you apt-get is hacked through supply chain compromise or something, it has full access to all the goodies in your user profile. There are distros that attempt to implement sandboxing but in those distros your browser can't really be jailed properly. Qubes has tighter isolation than android does, but is slower and too much of a hassle for your typical employee or relative.

Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.

by deng 9 hours ago

Would be interesting for x86-based tablets/convertibles, like for instance an old Lenovo X1. I tried using these with Linux with various different distributions, including PostmarketOS, and it was not a good experience.

by ale42 12 hours ago

Running apps that require a phone and are not available for Linux, without putting them on your actual smartphone (if any)

by amlib 9 hours ago

I bet soon most of the apps you can only get on a smartphones are gonna require some kind of attestation that is unlikely to be given to your laptop running an "unsanctioned" version of android.

Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.

by bluebarbet 9 hours ago

>I bet soon

With this attitude it's almost inevitable. Politics can stop the corporate-OS attestation apocalypse. If it happens, it's on us.

by catlikesshrimp 8 hours ago

It is difficult to push back agaisnt banks. My bank started charging for some in site transactions and even some help desk. "We are migrating to online banking"

by Brian_K_White 4 hours ago

It was trivial for me to choose a couple of different local credit unions instead of any bank. I don't need any app, but their apps both do work on my rooted lineage phones. Their websites work on my firefox with ublock origin on linux.

A long time ago when I was young and not yet thoughtful I had a variety of regular big name banks like Citi and BofA etc.

It was the easiest thing in the world to just choose a different one that works for me.

by hollerith 8 hours ago

Opposing remote attestation in full generality is the wrong place to draw the line IMHO. Too many useful capabilities rely on attestation.

For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.

For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.

by bronson 7 hours ago

How will remote attestation prove that you were actually standing on the balcony pointing the camera, and not recording some slop you generated? The analog hole is a real problem.

Don't worry, photographs were being faked before Lee Harvey Oswald.

by hollerith 7 hours ago

The optical data will be cryptographically bound to the state of the autofocus mechanism and to the output of a LiDAR scanner.

We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner.

The technology need not be 100% tamper-proof to have a large effect on society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and some prompts and the claim that anyone with years of training and experience in cutting-edge microelectronics could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that can be used to create false attestations of recordings -- particularly because in a high profile instance such as a repeat of the Rodney King beating, Apple engineering would tend to be very interested in examining the device used to make the recording.

by AnthonyMouse 6 hours ago

> We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner alongside the optical lenses.

The iPhone Pro starts at $1199.

Moreover, LiDAR is essentially a laser that emits at a particular wavelength and a camera that detects that wavelength, so it could be fooled by pointing it at a screen that emits at the same wavelength, which in turn could be an ordinary screen with something in front of it that converts light at a wavelength it emits to the one the LiDAR sensor is expecting.

And that's if you insist on using light. The LiDAR sensor itself is an analog piece of hardware that converts the light into an electrical signal, so if you substitute its electrical output as the input to the signing hardware then it signs whatever you want and never knows the difference.

The hardest part about this is probably creating a credible depth map of a generated 2D image, which is the part that doesn't require signatures or attestation.

> The technology need not be 100% tamper-proof to affect society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and a few prompts and the claim that anyone with years of technical training and experience could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that Apple's engineers have not detected yet that can be used to create falsely attested recordings.

Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.

Moreover, isn't "most people can't do this but some people still can" actually worse? It's a system for providing undue credibility to the forgeries from the people who can do it.

Without even making most legitimate images more credible, since most phone cameras don't have fancy LiDAR hardware.

by hollerith 5 hours ago

>The iPhone Pro starts at $1199

The camcorder used to record the Rodney King beating also probably cost at least $1199. LiDAR will spread to cheaper smartphones if enough consumers start to value it, and many (maybe most) consumers will do if it becomes necessary for the consumer to retain the ability to make recordings that can be used as evidence.

>it could be fooled by pointing it at a screen that emits at the same wavelength

LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.

>substitute its electrical output as the input to the signing hardware

The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.

How do I know so much about iPhone hardware? I don't, except I know that Apple is widely believed to be the world's leader in hardware security, so I strongly suspect that every single data path in a recent iPhone is encrypted before it leaves any IC.

>Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.

The web server behind the site would have to be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable that iPhone Pro. Specifically, they will be able to determine its ID number (term?) from the attestation, and I'm pretty sure they already have the ability to disable an iPhone by ID number.

>Moreover, isn't "most people can't do this but some people still can" actually worse?

If Apple cares and is willing to expend the necessary engineering resources, then anyone (other the Apple itself) who makes any sort of notable or economically important or culturally important use of their ability to create a false attestation will retain the ability for only a brief time.

The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days. I expect Apple could exert a level of control over "camera remote attestation" similar to the level of control it has already achieved over which OSes (and which apps) can run on its iPhones. In general, these "technical regimes" are designed to make it easy for the engineering organization to recover from exploits as soon as the organization becomes aware of the exploit.

Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)? If not, then what is your alternative to "technical regimes" reliant on remote attestation similar to the regime I just described?

by AnthonyMouse 4 hours ago

> LiDAR might spread to all smartphones if its starts to become important to society.

You expect $50 phones to have LiDAR hardware?

> LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.

That's assuming you're trying to detect the pulse rather than sending back photons with particular timing from when you expect it to come. Notice that you can also try more than once and only publish the image where you got the timing right.

You also have the advantage because you can have something which is directly in front of the sensor but is sending back photons later than that because you're pretending to be something which is further away.

> The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.

With the right equipment you can affect electrical signals within an IC without disassembling it.

Or you can disassemble it. It doesn't have to be easy when only one person has to do it.

> The web server behind the site would be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable the iPhone. Specifically, they will be able to determine ID number (term?) of the iPhone from the attestation data, and I'm pretty sure they already have the ability to disable an iPhone by ID number.

So they set up an apparatus where they can put any such a phone, buy them in bulk and resell them immediately after use for the same price they paid. Then most are never detected and even if a few of them are, Apple is only disabling the phone of the innocent third party buyer, likely outside of the return window, and thereby negatively impacting the resale value of their own brand.

Also, your premise was that this would be in every phone and then they're not buying late model iPhones, they're getting e-waste phones with dead batteries or cracked screens by the pallet for ~free to use once on their way to the scrapper.

> The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days.

You're assuming they publish their methods for Apple to patch instead of setting up the service to sign images without documenting exactly how they do it.

And also that every phone OEM cares to that extent, which they obviously don't.

by bigyabai 4 hours ago

> I know that Apple is widely believed to be the world's leader in hardware security

That's a pretty rich qualification. "I know" suggests you can prove it, but you have to qualify it with "believed" because you can't. You can't cite anyone that audited Apple's source code, or ask a knowledgeable stakeholder for a credible architectural understanding. You haven't written an exploit, or reverse-engineered one.

It's purely faith. You're making an argument "you know" based on the loyal assumption that Apple's marketing is correct. You could be citing security theater muppets for all you know, but apparently your argument isn't contingent on veracity or transparency.

> Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)?

Yes? Do you really want a purity spiral where people that get abused, subjected to police brutality or sexually assaulted are discredited because they're too poor for a LIDAR camera? I would lobby day and night for this two-tiered evidence system to be reversed because it would force the miscarriage of justice as a marketing gimmeck for iPhone technology. It's not a scalable, holistic, trustworthy, accessible, or safe option for anyone, let alone Americans. There is not a single company in the United States that can implement a system like this protected from domestic or foreign adversaries.

Truly, go fuck yourself if you genuinely think this false dichotomy is the only worthy perspective.

by ale42 an hour ago

What about actual cameras? I still have to see one with a LiDAR.

by satvikpendem 11 hours ago

There are ways to run Android on Linux much more easily than running Linux on Android.

by ggm 12 hours ago

Familiarity

App consistency

Upstream app availability and release cycle

Security.

by stasomatic 9 hours ago

Games is one use case. I play the iOS version of Balatro on my Mac.

by fph 10 hours ago

Much better security. Sandboxing and app isolation actually works on Android.

by aucisson_masque 7 hours ago

I wouldn’t want to run Linux or windows on my phone lol.

by silisili 12 hours ago

That sounds suspiciously like jart...

by phh 12 hours ago

I'd say quite the opposite. jart has been very focused on specific things. While the contribution mentioned looks more butterflying amongst target.

(@0xcafebabe: ADHD high-five, I've got almost the same target list, except I'm playing with their NPUs)

by silver_silver 8 hours ago

jart unfortunately seems to have had some kind of a mental breakdown involving a hard rightward religious/political pivot around June according to their latest twitter and github activity. They most recently posted a video of the police breaking down their bedroom door. Very sad to see

by jelloroll42 5 hours ago

Jart had a hard rightward pivot shortly after occupy Wall Street where they were advocating for forming militias and pushing for Eric Schmidt for dictator. Obviously they're tremendously talented but they've always been kooky verging on unwell.

by arcanemachiner 9 hours ago

It does sound rather... cosmopolitan.

by chronogram 12 hours ago

Looks really promising. Once hardware codecs and camera support arrives it might be useful for old laptops. https://github.com/LineageOS/android_device_mainline_generic...

by khkjlhgkl 13 hours ago

I love LineageOS. I have been using Lineage and previously Cyanogen for many years. This is how Android is meant to be.

by drnick1 4 hours ago

I wish Lineage did a better job at explaining which new devices are supported. Lineage clearly supports a lot of devices and device types, but most are ancient or specific models with a known hack to unlock the bootloader. A short list of recommended devices in each category (phone, TV, tablet), that can be bought new today, would go a long way.

by zb3 4 hours ago

There's a search engine here https://wiki.lineageos.org/devices/ (see filters).

Not a lot of them unfortunately.. but with current bootloader unlocking situation, only newer motorolas seem to be missing... OnePlus 15 was added (or is in the making)

by colordrops 4 hours ago

I think every device is supported by different people rather than a single org which is maybe why they don't feature some devices.

by kevin_thibedeau 4 hours ago

It's time to bring back Privacy Guard. GrapheneOS is up and coming. Lineage needs to take empowering users with security controls seriously.

by hobo123 11 hours ago

When I had kids I noticed that the camera quality was quite bad (e.g. on Samsung Galaxy S5 or S7), so I basically switched back to stock.

Is this still the case? My guess is that Lineage doesn't get the drivers necessary for better quality maybe.

by solarkraft 9 hours ago

It can be complicated. I don’t remember the whole story, but I think on the older Xperias you’d have to take care to reinstall the proprietary drivers and there were keys that could be permanently lost and then you’d be out of some of the enhancements.

by spacebeer 10 hours ago

I managed to install gcam on my LOS phone, and quality was way better

by deng 9 hours ago

Yes, best chance is to get BSG's version from https://www.celsoazevedo.com/files/android/google-camera/ and install manually.

by yjftsjthsd-h 6 hours ago

Is that a Lineage problem or a Samsung problem?

by hobo123 5 hours ago

Might be Samsung's lack of openness, but in the end it's my problem.

by Scene_Cast2 9 hours ago

Not all of the builds seem live. Pixel 9 Pro has 24.0, but Pixel 9 has 23.2, for example.

by t1234s 5 hours ago

Does the BMW smart key system work on Lineage OS?

by drnick1 4 hours ago

I am not sure, but here is my take on cars and smart phones: don't. Cars already spy on users through their onboard cellular modem. The last thing that you want is BMW or some or carmaker accessing, in addition to that, data on your phone, or using it to exfiltrate data if you removed/disabled the car's cellular modem.

by khaled4vokalz 11 hours ago

Why are you guys skipping Mi 8 SE? while still supporting older versions than that :thinking_face: Just trying to understand the reasoning for it.

by yjftsjthsd-h 6 hours ago

It's an open source community project; the devices they support are what the maintainers own.

by Brian_K_White 3 hours ago

Because you didn't do it.

Just trying to understand why that's a mystery :thinking_face:

Who do you think "you guys" is exactly? You guys is you. You can port it to your chosen device and be the maintainer for that device and then we can thinking face wonder why you didn't give us some other device we wish was supported.

by arcanemachiner 9 hours ago

Someone has to maintain it. ;)

by dankobgd 11 hours ago

I am happy with my Poco F3 with lineageos. Also converted my moms phone, and works better for sure than that chinese crap bloat

by user2722 11 hours ago

Cool; See if this is the time I try using a cuttlefish target + webrtc remoting to drive all those cute privacy intruding apps.

by marshymarsh 12 hours ago

the only thing keeping me from jumping from GrapheneOS is contact and storage scopes. :(

by SpecialistK 43 minutes ago

I'm definitely open to trading some security/privacy features in favour of some QoL features Lineage had last time I used it - moving the clock back to the right (where persistent notifications belong) and power button for flashlight. It's a shame this has to be a "or" but as I use a burner phone when crossing borders anyway...

by grapheneos 2 hours ago

Contact Scopes and Storage Scopes are a small subset of the privacy features provided by GrapheneOS. It's also adding major privacy improvements on a regular basis including the recently added secure paste feature and ongoing fixes for upstream Android VPN leaks. There are many other privacy features beyond those.

Privacy heavily depends on security. GrapheneOS greatly improves both privacy/security patches and privacy/security protections. The sole reason for the focus on security in GrapheneOS is because it's a privacy project. It has no other reason to work on security.

Android 17 was released in June 2026 and has been required for full standard Android privacy and security patches since then. Only a subset of the patches Google deems to be High or Critical severity are backported. Keeping up with the standard backports and major updates is important but increasingly inadequate.

by user2722 11 hours ago

Don't forget proprietary security patches are only open sourced 3 months after -- GOS has them due to their partnership with Motorola.

A sufficiently motivated threat actor will have them (the exploits) too.

by grapheneos 2 hours ago

GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.

by imkac 11 hours ago

It's optional.

by realusername 8 hours ago

Unless you are using the most expensive flagship of a few Android brands, you are also vulnerable anyways

by grapheneos 2 hours ago

Pixels provide the same security features and updates for the budget 'a' series devices as the regular ones. Pixel 8a is one of the recommended devices for GrapheneOS since it still meets all the current era security standards and still has over 4.5 years of updates remaining despite being 3 generations old due to starting with 7 and launching after the initial set of 8th gen devices.

Motorola will be working towards providing the same thing as part of our partnership with them, but we're starting out with the high end flagship devices due to those currently being required for it.

by realusername an hour ago

Interesting, I didn't know about that. Props to Google for bringing the security updates for the cheaper devices as well.

by imkac 11 hours ago

GrapheneOS actually feels just like LineageOS, except that it has faster upstream updates, better security, and greater usability...

I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.

by deng 9 hours ago

> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.

Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.

by grapheneos 2 hours ago

GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.

by microtonal 8 hours ago

Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well.

Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.

by qikp 2 hours ago

LineageOS code can update pretty fast, but the problem is they want to do refactors, and also that bringing up a hundred outdated devices is difficult.

by t_mahmood 5 hours ago

GrapheneOs is limited to some specific devices, LOS is all about supporting as much hardware as possible. Theybhave different target

by timschumi 10 hours ago

> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.

GrapheneOS does not have circle battery.

> LineageOS really should be based directly on GrapheneOS.

What would that achieve?

by user2722 11 hours ago

GOS => security, usability

LOS => most security, most usability, breadth of support

by imkac 11 hours ago

Actually LineageOS has less usability due to AOSP bugs, no GMS, unlocked boot loader, etc. The weak security is cost of wide support.

by Borealid 8 hours ago

Could you explain how the ability to unlock a bootloader makes a device less usable?

by microtonal 8 hours ago

I think they are referring to that LineageOS by and large (there are probably exceptions) does not have support for relocking the bootloader. Some apps refuse to work with an unlocked bootloader (but there are ways around it).

by jamespo an hour ago

GrapheneOS has even less usability on my Oneplus 7T Pro, in fact it has none

by spaqin 9 hours ago

i'm fine with that "less security" as my threat model does not include crossing the US border.

by user2722 6 hours ago

You're conflating local data extraction with security vulnerabilities remotely exploitable via WhatsApp or RCE du jour. Don't.

by HybridStatAnim8 6 hours ago

GrapheneOS is significantly more private, secure, and usable than LineageOS.

by qikp 2 hours ago

You're losing a lot more than that:

- secure app spawning (huge because without it, many hardening improvements are useless)

- extremely secure memory allocator

- fully enabled MTE on shiba and newer

- relockable bootloader

- stronger forensics resistance

- more trustworthy developers (ever heard of LOSCoins?)

- rapid support for new Pixels

- lightning fast security updates faster than most OEMs/ODMs

- built-in TTS without GMS

- real GMS that isn't priv-app

and so much more

by jurf 11 hours ago

While not great, a private space or work profile with Shelter can work in a a pinch. I use it e.g. WhatsApp, where I just need three people, but which is almost unusable if you don’t give it the permission.

It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.

by palata 6 hours ago

What a weird take. I see it the other way round: if you can run GrapheneOS, run GrapheneOS, period. If you can't, then there is a really cool project called LineageOS that you probably can run, and you should look into it :-).

by yjftsjthsd-h 4 hours ago

It's not quite that simple. I don't use GOS because GOS and I have mutually incompatible views of user control. I prefer that I control my phone, they say I can't be trusted with that.

by grapheneos 2 hours ago

That's an inaccurate portrayal of our approach and especially how it compares to LineageOS. LineageOS does not provide app or user accessible root accessible either. As a counterexample to your narrative, GrapheneOS provides full manual and automatic call recording functionality internationally while LineageOS restricts it based on region.

by yjftsjthsd-h 2 hours ago

It's really not; you've argued extensively with me that the moment a user can run an app with root the whole system is insecure. LOS sadly doesn't ship anything but `adb root` by default (although... they do that, so yes they do ship "user accessible root"), but they're still less hostile about it.

Anyways, since you're here perhaps you can answer my question from the other subthread: If I flash GOS and then flash Magisk on it, how hard is it to stay unbricked? Is it as easy as declining to relock the bootloader once, or is the system going to actively fight me on every boot?

by qikp 2 hours ago

Indeed, LineageOS doesn't officially support rooting *at all* anymore. They also ban Magisk from their communities IIRC.

by agile-gift0262 2 hours ago

In which ways does GOS not let you control your device? I'm curious because to me intalling GOS felt very liberating (compared to stock)

by yjftsjthsd-h 2 hours ago

I'm mostly talking about their stance on root. Certainly I agree GOS is vastly better than stock.

by drnick1 4 hours ago

You can root Graphene. It's not something the developers condone as it breaks their view of security, but it can be done.

by yjftsjthsd-h 3 hours ago

I suppose it depends how hard it tries to relock the bootloader; if I can tell it once to not do that then perhaps it's fine, but I don't want to risk a misclick soft bricking the device.

Although as an extension of that - I'm hesitant to use software written by people with such a philosophical difference. It might work today, but I wouldn't trust it to work tomorrow.

by qikp 2 hours ago

Same thing can be said for LineageOS too.

by drnick1 4 hours ago

Yes this is probably a good summary. If you have a fairly recent Pixel, there is probably no reason to pick Lineage over Graphene. But Lineage covers far more devices and device types, including ancient ones.

by villgax 13 hours ago

Absolutely love this project for keeping my OnePlus 6T alive.

Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.

by jokowueu 12 hours ago

But there arnt any official new builds for OnePlus 6t same with my OnePlus 6 due to the Strict eBPF & Kernel Requirements

Are you running unofficial builds right now ?

by zozbot234 6 hours ago

Doesn't OnePlus 6/6T have good "close to mainline" kernel support already? Why wouldn't it work within LineageOS eBPF/version requirements?

by gruez 4 hours ago

>Doesn't OnePlus 6/6T have good "close to mainline" kernel support already?

Source? Lineageos lists kernel version as 4.9, which definitely isn't "mainline".

https://wiki.lineageos.org/devices/enchilada/

by timschumi 3 hours ago

SDM845 has increasing support in mainline Linux, but the current official LineageOS builds still rely on the vendor-provided kernel, which is why that is still listed on the wiki.

by villgax 9 hours ago

Untill 22(Android 15) yeah but compared to the manufacturer this is insane.

What even is there in Android 17 to talk about, same old UI, no non-google AI features to run on-device without root

by satvikpendem 11 hours ago

AICore? Not sure what you mean if not this.

by villgax 9 hours ago

https://developers.google.com/ml-kit/custom-models

Just see out of touch with reality this section is compared to the insanse community work on Apple Silicon across whisper.cpp/mflux/llama.cpp/MLX/Exo & way more

by Grimeton 4 hours ago

The alibi open source version of android that only runs on hardware in the +1000 USD range.

A bargain for a test device or a daily driver for the not so wealthy.

You want to change something? Want to be recognized for making anything better?

Port it on sub $200 devices.

That's where the masses are.

That's where you start the degoogle revolution. Where you can build a sustainable business.

by timschumi 3 hours ago

You might be confusing LineageOS with GrapheneOS.

The device that I am typing this on (which runs LineageOS) cost me around $170 new.

by grapheneos 2 hours ago

GrapheneOS has support for all non-end-of-life Pixels including the budget 'a' series which are available at low prices for new devices. We don't continue indefinitely supporting devices lacking updates to firmware, drivers, HALs and in practice also upstream kernel updates once those become unreasonably insecure. We do provide extended support past end-of-life but we stop once we believe it's doing more harm than good by encouraging people to use insecure devices and especially to buy those to use it against our advice. It's a privacy and security project so we can't reasonably have official support for devices where it's highly insecure.

by haunter 3 hours ago

?

Did you even check the device list? Half of the chinese models are $200 or less. It's never been a price question

Data from: Hacker News, provided by Hacker News (unofficial) API