• RelativeArea0@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      2
      ·
      9 days ago

      its alright, it kept my “supposed to be dead” phone to keep on running with latest stuff, i like the built in firewall, but if you’re privicy focused then this is not for you.

        • Brad Boimler@startrek.website
          link
          fedilink
          English
          arrow-up
          11
          arrow-down
          1
          ·
          9 days ago

          Once LinageOS is installed your bootloader is always unlocked so anyone who finds your phone if lost owns it. GrapheneOS and a few other ROMs I forget the names of allow the bootloader to be relocked keeping android security model intact allowing the device to still be secure.

          • patatahooligan@lemmy.world
            link
            fedilink
            English
            arrow-up
            7
            arrow-down
            1
            ·
            9 days ago

            Is the bootloader really that important for a lost phone? If someone finds your phone can’t they just tear it apart and read the storage with external tools? A locked bootloader sounds more like an anti-tampering measure and not for protecting your phone’s content after it’s lost.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              8
              ·
              9 days ago

              If someone finds your phone can’t they just tear it apart and read the storage with external tools?

              that’s not the problem that BL locking solves. this is solved by storage encryption. BL locking solves 2 other problems:

              • helps keeping stolen phone from being wiped, though maybe it’s not 100%
              • makes it much harder to plant malware on your phone while it’s not with you
            • CrazyLikeGollum@lemmy.world
              link
              fedilink
              English
              arrow-up
              6
              arrow-down
              1
              ·
              9 days ago

              It is largely an anti-tampering measure. Without it you could have things injected into the system. For example, a stalker could install a hidden tracking program as a service and then return your phone without you knowing.

              Iirc it’s also a prerequisite for full-disk encryption on modern android. So, without it your user data is available to be dumped in an unencrypted state. Most phone thieves are interested in reselling the phone, so they’re provably not going to go through the effort and risk damage to the phone just to dump encrypted data from the chips directly. However, if it’s just available unencrypted from fastboot why not dump it? They could get info that could be used to blackmail or scam you or people you know. Or they could just sell the data.

              • vividspecter@lemm.ee
                link
                fedilink
                English
                arrow-up
                2
                ·
                edit-2
                9 days ago

                Iirc it’s also a prerequisite for full-disk encryption on modern android.

                How modern? It’s still working on Evolution X with Android 14 (although maybe it needs custom rom support).

                It would be a bit less secure since the bootloader itself could be compromised, however (but I wouldn’t be concerned about random thieves/snooping in this case).

            • Brad Boimler@startrek.website
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              1
              ·
              edit-2
              9 days ago

              No because the data is encrypted especially on Graphene OS and even on stock pixel phones data at rest is fully encrypted and pixel phones also have a onboard security chip as well. So unless you can unlock the user data it would be useless. That is why a locked bootloader is so important it is needed to ensure at rest encryption its a requirement for it.

    • pirate-dad@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      9 days ago

      I was planning to move to Lineage, and eventually GrapheneOS (non Pixel at the moment) but revolut has broken compatibility by enforcing the use of the Play Integrity API, revolut is my main bank so I’m kinda blocked, for now… 🤬

        • pirate-dad@lemm.ee
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 days ago

          I may follow suit down the road, I’m even contemplating having a second cheap phone, with a long battery life, only used for revolut, I don’t think I really have any other apps that I couldn’t survive without.

    • IndustryStandard@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      8 days ago

      Upgrading android versions did a surprise factory reset for me. Never used it again after that.

      Custom Roms are only viable if official android support has dropped and you are no longer getting upgrades.

      • EngineerGaming@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 days ago

        Not really. Stock OSes are really bad in terms of privacy, maybe with a few exceptions - I wouldn’t be able to trust them with any personal info. Just like Windows. So a custom one is a must.