I know nothing!

  • 77 Posts
  • 4.56K Comments
Joined 1 year ago
cake
Cake day: June 26th, 2023

help-circle


  • Possibly linux@lemmy.ziptoPrivacy@lemmy.mlThought on Graphene?
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 minutes ago

    They still have a lot of control though. Also I find that Graphene community thinks it is better than everyone else. I don’t have a problem with people being proud the problem is that Graphene is spreading false information like every other ROM is insecure. That’s not the case especially in terms of security as anything but stock is less secure. From a privacy perspective non google is better than Google but everyone seems to skip over that. People will say “Lineage OS uses Google DNS” but in reality your ISP could be using Google DNS the key it to setup Private DNS which takes only a few minutes to do. Graphene isn’t the only option. In reality there are tradeoffs everywhere.

    The fact that the larger community only knows of Graphene OS and stock is a bit scary.




  • Possibly linux@lemmy.ziptoPrivacy@lemmy.mlThought on Graphene?
    link
    fedilink
    English
    arrow-up
    1
    ·
    14 minutes ago

    Raspberry Pis suck in general as they lack open firmware. You are stuck with the Raspberry Pi kernel and all of its blobs. “Security requirements” is something Microsoft says about Windows 11. If you are concerned about security your best bet is stock software as it is maintained by Google.


  • Possibly linux@lemmy.ziptoPrivacy@lemmy.mlThought on Graphene?
    link
    fedilink
    English
    arrow-up
    1
    ·
    16 minutes ago

    They encourage proprietary software and locked down systems. For instance, they use Google play services instead of microG and they promote the play store. I personally think that F-droid apps are much better from both an software freedom perspective and a privacy perspective. I’m not against people installing proprietary apps as I realize sometimes that is unavoidable but they could at least encourage the use of Foss. Graphene could simply have both F-droid and Aurora store by default and on setup explain the difference. They could even allow the install of Play services instead. However, they don’t even really try. They focus on security which at the end of the day is subjective.




  • You are still missing my point. All phones actively supported by Lineage OS get Android security patches. Those aren’t vendor patches but they do patch the OS and sometimes the kernel.

    For instance, the Pixel 5 was last updated June 28. https://wiki.lineageos.org/devices/panther/

    Not to say that you should still buy it. However, if it cheap it might be worth it.

    Also from the article you linked:

    Although the incident forced LineageOS to take offline all its service, it did not impact the signing keys that authenticate distributions because they are stored on hosts separate from the main infrastructure.







  • Custom ROMs will receive upstream Android security patches but not patches from proprietary components (firmware). For instance, my Moto g7 power has Android security patches from May but the latest vendor security patch level is 2021. (I’m running Lineage OS) I’m curious to know if the older firmware is a problem. I don’t think it is easily exploitable outside of government backdoors. Not that it matters much as I plan on keeping my phone until it dies.