Top
Best
New

Posted by timschumi 16 hours ago

LineageOS 24.0(lineageos.org)
390 points | 163 commentspage 2
user2722 11 hours ago|
Cool; See if this is the time I try using a cuttlefish target + webrtc remoting to drive all those cute privacy intruding apps.
marshymarsh 12 hours ago||
the only thing keeping me from jumping from GrapheneOS is contact and storage scopes. :(
grapheneos 2 hours ago||
Contact Scopes and Storage Scopes are a small subset of the privacy features provided by GrapheneOS. It's also adding major privacy improvements on a regular basis including the recently added secure paste feature and ongoing fixes for upstream Android VPN leaks. There are many other privacy features beyond those.

Privacy heavily depends on security. GrapheneOS greatly improves both privacy/security patches and privacy/security protections. The sole reason for the focus on security in GrapheneOS is because it's a privacy project. It has no other reason to work on security.

Android 17 was released in June 2026 and has been required for full standard Android privacy and security patches since then. Only a subset of the patches Google deems to be High or Critical severity are backported. Keeping up with the standard backports and major updates is important but increasingly inadequate.

SpecialistK 1 hour ago|||
I'm definitely open to trading some security/privacy features in favour of some QoL features Lineage had last time I used it - moving the clock back to the right (where persistent notifications belong) and power button for flashlight. It's a shame this has to be a "or" but as I use a burner phone when crossing borders anyway...
user2722 11 hours ago|||
Don't forget proprietary security patches are only open sourced 3 months after -- GOS has them due to their partnership with Motorola.

A sufficiently motivated threat actor will have them (the exploits) too.

grapheneos 2 hours ago|||
GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.
imkac 11 hours ago||||
It's optional.
realusername 8 hours ago|||
Unless you are using the most expensive flagship of a few Android brands, you are also vulnerable anyways
grapheneos 2 hours ago||
Pixels provide the same security features and updates for the budget 'a' series devices as the regular ones. Pixel 8a is one of the recommended devices for GrapheneOS since it still meets all the current era security standards and still has over 4.5 years of updates remaining despite being 3 generations old due to starting with 7 and launching after the initial set of 8th gen devices.

Motorola will be working towards providing the same thing as part of our partnership with them, but we're starting out with the high end flagship devices due to those currently being required for it.

realusername 1 hour ago||
Interesting, I didn't know about that. Props to Google for bringing the security updates for the cheaper devices as well.
imkac 12 hours ago|||
GrapheneOS actually feels just like LineageOS, except that it has faster upstream updates, better security, and greater usability...

I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.

deng 9 hours ago|||
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.

Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.

grapheneos 2 hours ago|||
GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.
microtonal 8 hours ago||||
Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well.

Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.

qikp 2 hours ago|||
LineageOS code can update pretty fast, but the problem is they want to do refactors, and also that bringing up a hundred outdated devices is difficult.
t_mahmood 5 hours ago||||
GrapheneOs is limited to some specific devices, LOS is all about supporting as much hardware as possible. Theybhave different target
timschumi 10 hours ago||||
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.

GrapheneOS does not have circle battery.

> LineageOS really should be based directly on GrapheneOS.

What would that achieve?

user2722 11 hours ago|||
GOS => security, usability

LOS => most security, most usability, breadth of support

imkac 11 hours ago|||
Actually LineageOS has less usability due to AOSP bugs, no GMS, unlocked boot loader, etc. The weak security is cost of wide support.
Borealid 8 hours ago|||
Could you explain how the ability to unlock a bootloader makes a device less usable?
microtonal 8 hours ago||
I think they are referring to that LineageOS by and large (there are probably exceptions) does not have support for relocking the bootloader. Some apps refuse to work with an unlocked bootloader (but there are ways around it).
jamespo 1 hour ago||||
GrapheneOS has even less usability on my Oneplus 7T Pro, in fact it has none
spaqin 9 hours ago|||
i'm fine with that "less security" as my threat model does not include crossing the US border.
user2722 6 hours ago||
You're conflating local data extraction with security vulnerabilities remotely exploitable via WhatsApp or RCE du jour. Don't.
HybridStatAnim8 6 hours ago|||
GrapheneOS is significantly more private, secure, and usable than LineageOS.
qikp 2 hours ago|||
You're losing a lot more than that:

- secure app spawning (huge because without it, many hardening improvements are useless)

- extremely secure memory allocator

- fully enabled MTE on shiba and newer

- relockable bootloader

- stronger forensics resistance

- more trustworthy developers (ever heard of LOSCoins?)

- rapid support for new Pixels

- lightning fast security updates faster than most OEMs/ODMs

- built-in TTS without GMS

- real GMS that isn't priv-app

and so much more

jurf 11 hours ago|||
While not great, a private space or work profile with Shelter can work in a a pinch. I use it e.g. WhatsApp, where I just need three people, but which is almost unusable if you don’t give it the permission.

It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.

palata 6 hours ago|||
What a weird take. I see it the other way round: if you can run GrapheneOS, run GrapheneOS, period. If you can't, then there is a really cool project called LineageOS that you probably can run, and you should look into it :-).
yjftsjthsd-h 4 hours ago|||
It's not quite that simple. I don't use GOS because GOS and I have mutually incompatible views of user control. I prefer that I control my phone, they say I can't be trusted with that.
grapheneos 2 hours ago|||
That's an inaccurate portrayal of our approach and especially how it compares to LineageOS. LineageOS does not provide app or user accessible root accessible either. As a counterexample to your narrative, GrapheneOS provides full manual and automatic call recording functionality internationally while LineageOS restricts it based on region.
yjftsjthsd-h 2 hours ago|||
It's really not; you've argued extensively with me that the moment a user can run an app with root the whole system is insecure. LOS sadly doesn't ship anything but `adb root` by default (although... they do that, so yes they do ship "user accessible root"), but they're still less hostile about it.

Anyways, since you're here perhaps you can answer my question from the other subthread: If I flash GOS and then flash Magisk on it, how hard is it to stay unbricked? Is it as easy as declining to relock the bootloader once, or is the system going to actively fight me on every boot?

qikp 2 hours ago|||
Indeed, LineageOS doesn't officially support rooting *at all* anymore. They also ban Magisk from their communities IIRC.
agile-gift0262 2 hours ago||||
In which ways does GOS not let you control your device? I'm curious because to me intalling GOS felt very liberating (compared to stock)
yjftsjthsd-h 2 hours ago||
I'm mostly talking about their stance on root. Certainly I agree GOS is vastly better than stock.
drnick1 4 hours ago|||
You can root Graphene. It's not something the developers condone as it breaks their view of security, but it can be done.
yjftsjthsd-h 3 hours ago|||
I suppose it depends how hard it tries to relock the bootloader; if I can tell it once to not do that then perhaps it's fine, but I don't want to risk a misclick soft bricking the device.

Although as an extension of that - I'm hesitant to use software written by people with such a philosophical difference. It might work today, but I wouldn't trust it to work tomorrow.

qikp 2 hours ago|||
Same thing can be said for LineageOS too.
drnick1 4 hours ago|||
Yes this is probably a good summary. If you have a fairly recent Pixel, there is probably no reason to pick Lineage over Graphene. But Lineage covers far more devices and device types, including ancient ones.
villgax 13 hours ago||
Absolutely love this project for keeping my OnePlus 6T alive.

Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.

jokowueu 12 hours ago||
But there arnt any official new builds for OnePlus 6t same with my OnePlus 6 due to the Strict eBPF & Kernel Requirements

Are you running unofficial builds right now ?

zozbot234 6 hours ago|||
Doesn't OnePlus 6/6T have good "close to mainline" kernel support already? Why wouldn't it work within LineageOS eBPF/version requirements?
gruez 4 hours ago||
>Doesn't OnePlus 6/6T have good "close to mainline" kernel support already?

Source? Lineageos lists kernel version as 4.9, which definitely isn't "mainline".

https://wiki.lineageos.org/devices/enchilada/

timschumi 3 hours ago||
SDM845 has increasing support in mainline Linux, but the current official LineageOS builds still rely on the vendor-provided kernel, which is why that is still listed on the wiki.
villgax 9 hours ago|||
Untill 22(Android 15) yeah but compared to the manufacturer this is insane.

What even is there in Android 17 to talk about, same old UI, no non-google AI features to run on-device without root

satvikpendem 12 hours ago||
AICore? Not sure what you mean if not this.
villgax 9 hours ago||
https://developers.google.com/ml-kit/custom-models

Just see out of touch with reality this section is compared to the insanse community work on Apple Silicon across whisper.cpp/mflux/llama.cpp/MLX/Exo & way more

yamir61 7 hours ago||
[flagged]
opengears 15 hours ago||
[flagged]
Grimeton 4 hours ago|
The alibi open source version of android that only runs on hardware in the +1000 USD range.

A bargain for a test device or a daily driver for the not so wealthy.

You want to change something? Want to be recognized for making anything better?

Port it on sub $200 devices.

That's where the masses are.

That's where you start the degoogle revolution. Where you can build a sustainable business.

timschumi 3 hours ago||
You might be confusing LineageOS with GrapheneOS.

The device that I am typing this on (which runs LineageOS) cost me around $170 new.

grapheneos 2 hours ago||
GrapheneOS has support for all non-end-of-life Pixels including the budget 'a' series which are available at low prices for new devices. We don't continue indefinitely supporting devices lacking updates to firmware, drivers, HALs and in practice also upstream kernel updates once those become unreasonably insecure. We do provide extended support past end-of-life but we stop once we believe it's doing more harm than good by encouraging people to use insecure devices and especially to buy those to use it against our advice. It's a privacy and security project so we can't reasonably have official support for devices where it's highly insecure.
haunter 4 hours ago||
?

Did you even check the device list? Half of the chinese models are $200 or less. It's never been a price question