• antler@feddit.rocks
    link
    fedilink
    English
    arrow-up
    0
    ·
    4 months ago

    Iirc E/OS is based on Lineage, but takes a horrifying long time to patch in security updates on top of Lineage’s already somewhat laggy patches. If you choose to use it make sure you’re aware of that going in.

    Also, like IIGxC said it’s a android. Maybe slightly more private that most stock versions on most phones. But that’s like saying [insert Linux distro] is better than Linux.

    • 9tr6gyp3@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      4 months ago

      LineageOS will only patch Android. It will not patch hardware vulnerabilities after the device no longer has support from the manufacturer.

      Both of these OSes are dangerous for privacy and security.

        • StrawberryPigtails@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 months ago

          There is no option. There is too much variation in the various phone chips for the hardware hacking community to reverse engineer more than a bare handful. And as soon as the hardware has been reverse engineered, it will never be used again by a manufacturer making the exercise largely pointless.

          Add to that, the fact that Qualcomm actively discourages long term support of their chips….

          • kronarbob@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 months ago

            That’s why Fairphone choose a QCM6490 for the fairphone 5. It’s far from being the best, but it has longer term support than mainstream oriented SOC.

            Since the SOC will probably be enough for most of users, it’s not a bad option I guess.

        • SolidGrue@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          4 months ago

          Get a new phone the vendor does support.

          Firmware patching is applying low-level firmware to the modem or baseband, similar to a BIOS update on a desktop or server. These binary libraries are (a) proprietary, and (b) opaque to the user (meaning they’re not documented like normal software)

          Once a vendor drops support for a platform, that’s it, that’s the end of the line. The device will still work, but any, glitches, firmware vulnerabilities, or updates for network-side changes will no longer be addressed.

          • EngineerGaming@feddit.nl
            link
            fedilink
            English
            arrow-up
            0
            arrow-down
            1
            ·
            4 months ago

            This is just not realistic though, as the support is so short. You cannot buy phones ever few years. Only thing you can realistically do is apply at least Lineage and exercise caution.

            • jet@hackertalks.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 months ago

              Denying reality isn’t realistic either.

              Knowing your threat model and being aware of your tradeoffs and decisions is useful. Maybe security isn’t more important than longevity, but the phone owner should be making a deli rate choice.

              With the new pixels having 7 years of support things are improving. It would be nice for them to open source the hardware specs at the end of the support window…

              https://support.google.com/pixelphone/answer/4457705

              • AbidanYre@lemmy.world
                link
                fedilink
                English
                arrow-up
                0
                arrow-down
                1
                ·
                4 months ago

                Who’s going to be digging into the depths of a 5+ year old phone on the off chance they can find a baseband vulnerability though?

                Even if they do find something, the number of people for them to exploit is probably going to be vanishingly small.