There is a security question I have been having regarding /e/OS (and I guess Lineage as well). For at least some devices, /e/OS (and again, probably Lineage) use the Google test keys instead of their own signing keys.
Doesn't that mean that I could write an app, sign it with those keys (they are public, since they are for testing), and then have it behave like a "system" app on those devices? Isn't that how a system app proves to the system that it is, in fact, a system app?
I can understand the "I am not paranoid and I don't really mind about an evil maid attack, so I don't need to relock my bootloader". But isn't it risky to use the Google test keys to sign the whole system?
Not trying to criticise Lineage and /e/OS here: I'm hoping that someone knowledgeable about this will be able to help me understand the actual risks.
Lineage is better and Graphene is obviously the gold standard which provides better privacy and security for normal people. The author is wrong in thinking you gotta be some journalist to use it. GrapheneOS is for everyone
A rather uninteresting and shallow comparison, for this audience.
udev4096•38m ago
I would never recommend this article for anyone looking for comparison. It's wrong in so many ways. Your opinions are highly biased and it's an extremely poor attempt to make GrapheneOS look bad. For a factual and technical comparison, I would suggest this blog post series: https://www.kuketz-blog.de/android-grapheneos-calyxos-und-co...
It's well written and focuses on facts rather than poorly made assumptions
palata•58m ago
Doesn't that mean that I could write an app, sign it with those keys (they are public, since they are for testing), and then have it behave like a "system" app on those devices? Isn't that how a system app proves to the system that it is, in fact, a system app?
I can understand the "I am not paranoid and I don't really mind about an evil maid attack, so I don't need to relock my bootloader". But isn't it risky to use the Google test keys to sign the whole system?
Not trying to criticise Lineage and /e/OS here: I'm hoping that someone knowledgeable about this will be able to help me understand the actual risks.
udev4096•37m ago
Lineage is better and Graphene is obviously the gold standard which provides better privacy and security for normal people. The author is wrong in thinking you gotta be some journalist to use it. GrapheneOS is for everyone
palata•5m ago