top | item 30507403

(no title)

nosedief | 4 years ago

neither of the two are great. MicroG stands in conflict with Android's security model by spoofing Google app signatures and being a deeply privileged app compromising the whole system's security.

CalyX has is constantly harassing and bullying other privacy-focused projects, causing incredible harm to the privacy and security community. It also has been missing updates for 4 months recently, making it a terrible choice for anyone.

discuss

order

toastal|4 years ago

> Wait, on their FAQ page I see that they don't want to include the patch for security reasons. Is this ROM unsafe?

> No. LineageOS' developers decided not to include this patch for various reasons. The signature spoofing could be an unsafe feature only if the user blindly gives any permission to any app, as this permission can't be obtained automatically by the apps. Moreover, to further strengthen the security of our ROM, we modified the signature spoofing permission so that only system privileged apps can obtain it, and no security threat is posed to our users.

LineageOS for microG FAQs (https://lineage.microg.org/)

h4waii|4 years ago

This should be a show-stopper for anyone considering microg.

https://github.com/microg/GmsCore/issues/1567

Security is an afterthought for most Android distributions and most software built around them. I went from years of self building AOSP and LineageOS, and after a long hard look at why I was doing it, I stopped and installed GrapheneOS.

While it's an extremely opinionated project and borderline hostile, I trust the developers to do things correctly and will continue to use and recommend for security-conscious individuals.

dmw_ng|4 years ago

> deeply privileged app compromising the whole system's security

doesn't this also describe Google Play Services?

jhoho|4 years ago

> CalyX has is constantly harassing and bullying other privacy-focused projects, causing incredible harm to the privacy and security community. It also has been missing updates for 4 months recently, making it a terrible choice for anyone.

You actively harass and bully by not providing any sources for your claims. That's bad for an open, fact-based discussion and is opposed to how I percept the community. What are your claims based on? Can you provide any sources? As far as I know, CalyxOS tries to maintain a quite neutral temper: https://www.reddit.com/r/CalyxOS/comments/pmguwi/grapheneos_...

You can read the details of CalyxOS' implementation of microG here: https://calyxos.org/docs/tech/microg-details/

> Made the permission signature|privileged so only system apps signed with the right key, or privileged system apps with an explicit allowlist for this permission can use it.

> Hardcoded the signature to be spoofed instead of letting the application specify it.

> Only allowed the microG packages, GmsCore and Store to spoof signature. Both of these are included as system apps on CalyxOS so simply checking against the package name is enough.

That doesn't sound like that much of a risk to me. Esentially, it's a tradeoff between privacy and usability that microG tries to solve/soften. For example, it came in handy, when standalone Open-Source implementations of Google's contact tracing approach weren't available yet. microG quickly implemented it so official apps worked.

kornhole|4 years ago

Check out GrapheneOS.org. You can optionally install a sandboxed Google Play services. I want CalyxOS to survive, but they are falling behind security updates.