I was secretly hoping they'd stop supporting the Pixel 4a so I would have a reason to get a new phone, but no, still there in the list of supported devices. So I guess I'll just keep using that thing another year... Anyway: big thanks to the Lineage maintainers, keeping so many phones from landfill!
If you need a reason, the modem and the baseband firmware have several unpatched vulnerabilities on that model, which is not something that an Android update can resolve.
Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.
I too have a 4a that is still ticking thanks to Lineage!
The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
I have stock Android on a Pixel 10 and RCS group texts don't work here either. Some people just can't be added to the group and some people just don't receive the texts.
I have yet to find a banking app that refuses to work on LineageOS. The only problem is if you root your phone, in which case you'll have to use Magisk to hide root from those apps, which also works fine so far.
Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
This is the problem: it was a cat and mouse game always. I managed even strong integrity with keybox stuff and so on. Yes it is possible. But if you really need to do send money or e. g. want to pay with NFC, it gets rather stressful. Yes, I got everything working (Note 10 pro on LOS 23), but never longer than a few month.
I just decided to completely stop paying with NFC. I always carry a few cards with me and Wero is already working in a few spots, which requires just your banking app and a working camera.
I don't even have Google Wallet installed anymore.
Not everywhere, unfortunately. There are places in the world where only accepting digital payments is the norm and they won’t serve you if you pay in physical cash.
Good to know. I'm using N26 and they work just fine in Graphene OS. What I do is I create a private space for the apps needing play services, which I keep locked most of the time. This acts as a separate profile and when locked, the apps including play services are completely off. My main profile uses only open source apps and no play services.
I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
I applied to open an N26 account, and after completing all the necessary documentation they then told me I had to install their app to activate the account. Forget it.
Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.
In Germany that would be market places like eBay or Amazon (i.e. non-originally replacement parts). Original ones go for around 45 EUR (iFixit). But I guess you wouldn't care too much about original parts at that age.
I bet sprinkle beside the bath is ok, but toilet plop is not ( I have seen the second one, I suggest grabbing it without any delay, better grab it working because you have to grab it anyways)
I replaced battery in mine for like 90 EUR and several months in dropped it and broke the screen. Would still use it instead of 9a, love how light and compact the phone was. At least now I have a spare phone to root and do stuff with that I couldn't on my main one.
They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).
Better sandboxing. If one of the programs you apt-get is hacked through supply chain compromise or something, it has full access to all the goodies in your user profile. There are distros that attempt to implement sandboxing but in those distros your browser can't really be jailed properly. Qubes has tighter isolation than android does, but is slower and too much of a hassle for your typical employee or relative.
Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.
Would be interesting for x86-based tablets/convertibles, like for instance an old Lenovo X1. I tried using these with Linux with various different distributions, including PostmarketOS, and it was not a good experience.
I bet soon most of the apps you can only get on a smartphones are gonna require some kind of attestation that is unlikely to be given to your laptop running an "unsanctioned" version of android.
Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.
Opposing remote attestation in full generality is the wrong place to draw the line IMHO. Too many useful capabilities rely on attestation.
For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.
For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.
How will remote attestation prove that you were actually standing on the balcony pointing the camera, and not recording some slop you generated? The analog hole is a real problem.
Don't worry, photographs were being faked before Lee Harvey Oswald.
It is difficult to push back agaisnt banks. My bank started charging for some in site transactions and even some help desk. "We are migrating to online banking"
jart unfortunately seems to have had some kind of a mental breakdown involving a hard rightward religious/political pivot around June according to their latest twitter and github activity. They most recently posted a video of the police breaking down their bedroom door. Very sad to see
It can be complicated. I don’t remember the whole story, but I think on the older Xperias you’d have to take care to reinstall the proprietary drivers and there were keys that could be permanently lost and then you’d be out of some of the enhancements.
While not great, a private space or work profile with Shelter can work in a a pinch. I use it e.g. WhatsApp, where I just need three people, but which is almost unusable if you don’t give it the permission.
It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.
GrapheneOS actually feels just like LineageOS, except that it has faster upstream updates, better security, and greater usability...
I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.
Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.
Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well.
Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.
I think they are referring to that LineageOS by and large (there are probably exceptions) does not have support for relocking the bootloader. Some apps refuse to work with an unlocked bootloader (but there are ways around it).
Absolutely love this project for keeping my OnePlus 6T alive.
Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.
Just see out of touch with reality this section is compared to the insanse community work on Apple Silicon across whisper.cpp/mflux/llama.cpp/MLX/Exo & way more
The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
It's so bad.
The only reason I have been switching phones is banking apps: so much for Europe's right to repair..
This is separate from the Magisk root app.
I don't believe using the ADP root functionality is problematic. The Magisk app also has a hide mode.
I don't even have Google Wallet installed anymore.
I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.
It requires a sim card and cannot be used from multiple phones. So they put you to this endless face scan loop and then lock you out.
[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...
>While it’s still in experimental state, it has successfully booted on:
>Common x86_64 PCs
>Apple Silicon Macs
>NVIDIA DGX Spark
>Qualcomm Snapdragon X Series Laptops
That actually sounds awesome! Refurbishing old laptops with Android would be a nice choice alongside with Desktop Linux.
Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.
Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.
With this attitude it's almost inevitable. Politics can stop the corporate-OS attestation apocalypse. If it happens, it's on us.
For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.
For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.
Don't worry, photographs were being faked before Lee Harvey Oswald.
App consistency
Upstream app availability and release cycle
Security.
(@0xcafebabe: ADHD high-five, I've got almost the same target list, except I'm playing with their NPUs)
Is this still the case? My guess is that Lineage doesn't get the drivers necessary for better quality maybe.
A sufficiently motivated threat actor will have them (the exploits) too.
It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.
I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.
Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.
Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.
GrapheneOS does not have circle battery.
> LineageOS really should be based directly on GrapheneOS.
What would that achieve?
LOS => most security, most usability, breadth of support
Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.
Are you running unofficial builds right now ?
What even is there in Android 17 to talk about, same old UI, no non-google AI features to run on-device without root
Just see out of touch with reality this section is compared to the insanse community work on Apple Silicon across whisper.cpp/mflux/llama.cpp/MLX/Exo & way more