I was secretly hoping they'd stop supporting the Pixel 4a so I would have a reason to get a new phone, but no, still there in the list of supported devices. So I guess I'll just keep using that thing another year... Anyway: big thanks to the Lineage maintainers, keeping so many phones from landfill!
If you need a reason, the modem and the baseband firmware have several unpatched vulnerabilities on that model, which is not something that an Android update can resolve.
Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.
Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them. Usually under ongoing attack, at least by professional phone cracking software vendors and secret services.
I too have a 4a that is still ticking thanks to Lineage!
The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
I have stock Android on a Pixel 10 and RCS group texts don't work here either. Some people just can't be added to the group and some people just don't receive the texts.
I have yet to find a banking app that refuses to work on LineageOS. The only problem is if you root your phone, in which case you'll have to use Magisk to hide root from those apps, which also works fine so far.
Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
> Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
What possesses companies to do things like this? A customer running a current version of LineageOS is going to have better security than running the out of date Android version that came with the phone. An attacker who wants root on something that will run the bank app doesn't have to use a different OS, they can just use any of this month's CVEs to root the "approved" version. Even requiring the latest patches -- which would exclude entirely too many actual customers' phones -- wouldn't stop attackers from controlling their own devices, because they could root the device before installing the patch and then install the patch for the vulnerability they used to get root on the device where they already have it.
And attackers who are going to modify the system to carry out an attack inherently have some kind of software development capacity, so measures like this have no effect on them and all they actually do is interfere with the ability of honest normies to replace their out of date OS with a version that is less likely to be compromised by attackers.
Are they just taking kickbacks from Google or something?
This is the problem: it was a cat and mouse game always. I managed even strong integrity with keybox stuff and so on. Yes it is possible. But if you really need to do send money or e. g. want to pay with NFC, it gets rather stressful. Yes, I got everything working (Note 10 pro on LOS 23), but never longer than a few month.
I just decided to completely stop paying with NFC. I always carry a few cards with me and Wero is already working in a few spots, which requires just your banking app and a working camera.
I don't even have Google Wallet installed anymore.
Not everywhere, unfortunately. There are places in the world where only accepting digital payments is the norm and they won’t serve you if you pay in physical cash.
Good to know. I'm using N26 and they work just fine in Graphene OS. What I do is I create a private space for the apps needing play services, which I keep locked most of the time. This acts as a separate profile and when locked, the apps including play services are completely off. My main profile uses only open source apps and no play services.
I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
I applied to open an N26 account, and after completing all the necessary documentation they then told me I had to install their app to activate the account. Forget it.
Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.
In Germany that would be market places like eBay or Amazon (i.e. non-originally replacement parts). Original ones go for around 45 EUR (iFixit). But I guess you wouldn't care too much about original parts at that age.
I bet sprinkle beside the bath is ok, but toilet plop is not ( I have seen the second one, I suggest grabbing it without any delay, better grab it working because you have to grab it anyways)
I replaced battery in mine for like 90 EUR and several months in dropped it and broke the screen. Would still use it instead of 9a, love how light and compact the phone was. At least now I have a spare phone to root and do stuff with that I couldn't on my main one.
They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).
Better sandboxing. If one of the programs you apt-get is hacked through supply chain compromise or something, it has full access to all the goodies in your user profile. There are distros that attempt to implement sandboxing but in those distros your browser can't really be jailed properly. Qubes has tighter isolation than android does, but is slower and too much of a hassle for your typical employee or relative.
Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.
Would be interesting for x86-based tablets/convertibles, like for instance an old Lenovo X1. I tried using these with Linux with various different distributions, including PostmarketOS, and it was not a good experience.
I bet soon most of the apps you can only get on a smartphones are gonna require some kind of attestation that is unlikely to be given to your laptop running an "unsanctioned" version of android.
Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.
Opposing remote attestation in full generality is the wrong place to draw the line IMHO. Too many useful capabilities rely on attestation.
For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.
For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.
How will remote attestation prove that you were actually standing on the balcony pointing the camera, and not recording some slop you generated? The analog hole is a real problem.
Don't worry, photographs were being faked before Lee Harvey Oswald.
The optical data will be cryptographically bound to the state of the autofocus mechanism and to the output of a LiDAR scanner.
We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner alongside the optical lenses.
The technology need not be 100% tamper-proof to affect society: there is a huge difference between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and a few prompts and the claim that anyone with years of technical training and experience could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that can be used to create falsely attested recordings and that Apple hasn't caught on yet.
It is difficult to push back agaisnt banks. My bank started charging for some in site transactions and even some help desk. "We are migrating to online banking"
jart unfortunately seems to have had some kind of a mental breakdown involving a hard rightward religious/political pivot around June according to their latest twitter and github activity. They most recently posted a video of the police breaking down their bedroom door. Very sad to see
It can be complicated. I don’t remember the whole story, but I think on the older Xperias you’d have to take care to reinstall the proprietary drivers and there were keys that could be permanently lost and then you’d be out of some of the enhancements.
While not great, a private space or work profile with Shelter can work in a a pinch. I use it e.g. WhatsApp, where I just need three people, but which is almost unusable if you don’t give it the permission.
It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.
GrapheneOS actually feels just like LineageOS, except that it has faster upstream updates, better security, and greater usability...
I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.
Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.
Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well.
Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.
I think they are referring to that LineageOS by and large (there are probably exceptions) does not have support for relocking the bootloader. Some apps refuse to work with an unlocked bootloader (but there are ways around it).
Absolutely love this project for keeping my OnePlus 6T alive.
Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.
Just see out of touch with reality this section is compared to the insanse community work on Apple Silicon across whisper.cpp/mflux/llama.cpp/MLX/Exo & way more
I was secretly hoping they'd stop supporting the Pixel 4a so I would have a reason to get a new phone, but no, still there in the list of supported devices. So I guess I'll just keep using that thing another year... Anyway: big thanks to the Lineage maintainers, keeping so many phones from landfill!
If you need a reason, the modem and the baseband firmware have several unpatched vulnerabilities on that model, which is not something that an Android update can resolve.
Is there an easy way to tell if there are unpatched vulnerabilities in my phone's modem and baseband?
Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.
Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them. Usually under ongoing attack, at least by professional phone cracking software vendors and secret services.
I too have a 4a that is still ticking thanks to Lineage!
The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
I have stock Android on a Pixel 10 and RCS group texts don't work here either. Some people just can't be added to the group and some people just don't receive the texts.
It's so bad.
I wish I could still use my Pixel 4a but the battery is pretty much dead and it's too much money to replace it
Prices here are 13EUR including tools from what I can see.
The only reason I have been switching phones is banking apps: so much for Europe's right to repair..
I have yet to find a banking app that refuses to work on LineageOS. The only problem is if you root your phone, in which case you'll have to use Magisk to hide root from those apps, which also works fine so far.
A plain Lineage install will include "rooted debugging" in the developer options.
This is separate from the Magisk root app.
I don't believe using the ADB root functionality is problematic. The Magisk app also has a hide mode.
Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
> Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
What possesses companies to do things like this? A customer running a current version of LineageOS is going to have better security than running the out of date Android version that came with the phone. An attacker who wants root on something that will run the bank app doesn't have to use a different OS, they can just use any of this month's CVEs to root the "approved" version. Even requiring the latest patches -- which would exclude entirely too many actual customers' phones -- wouldn't stop attackers from controlling their own devices, because they could root the device before installing the patch and then install the patch for the vulnerability they used to get root on the device where they already have it.
And attackers who are going to modify the system to carry out an attack inherently have some kind of software development capacity, so measures like this have no effect on them and all they actually do is interfere with the ability of honest normies to replace their out of date OS with a version that is less likely to be compromised by attackers.
Are they just taking kickbacks from Google or something?
This is the problem: it was a cat and mouse game always. I managed even strong integrity with keybox stuff and so on. Yes it is possible. But if you really need to do send money or e. g. want to pay with NFC, it gets rather stressful. Yes, I got everything working (Note 10 pro on LOS 23), but never longer than a few month.
I just decided to completely stop paying with NFC. I always carry a few cards with me and Wero is already working in a few spots, which requires just your banking app and a working camera.
I don't even have Google Wallet installed anymore.
Go even further and carry cash! No technology dependency and "just works".
I live in Berlin... So naturlich!
Not everywhere, unfortunately. There are places in the world where only accepting digital payments is the norm and they won’t serve you if you pay in physical cash.
Good to know. I'm using N26 and they work just fine in Graphene OS. What I do is I create a private space for the apps needing play services, which I keep locked most of the time. This acts as a separate profile and when locked, the apps including play services are completely off. My main profile uses only open source apps and no play services.
I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
N26 also works fine on rooted devices. They don’t randomly block devices like others (besides Revolut, DKB comes to mind).
I applied to open an N26 account, and after completing all the necessary documentation they then told me I had to install their app to activate the account. Forget it.
Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.
That’s not a licensed bank, from what I can see.
Just be careful. I locked myself out from my bank when I installed a second phone that did not have sim card yet and had the app in my old phone.
It requires a sim card and cannot be used from multiple phones. So they put you to this endless face scan loop and then lock you out.
Revolut, UBS, ABN AMRO
Too lazy to do it myself tbh
Perfectly valid answer, I don't understand why people would downvote. It's not a trivial procedure, see https://www.ifixit.com/Guide/Google+Pixel+4a+Battery+Replace...
Where can one get one for that price range?
In Germany that would be market places like eBay or Amazon (i.e. non-originally replacement parts). Original ones go for around 45 EUR (iFixit). But I guess you wouldn't care too much about original parts at that age.
+ screen because you WILL break it
My wife replaced batteries herself with pixel 3a and 6a without any problems (I guess I wouldn't test if they are still waterproof).
I bet sprinkle beside the bath is ok, but toilet plop is not ( I have seen the second one, I suggest grabbing it without any delay, better grab it working because you have to grab it anyways)
I replaced battery in mine for like 90 EUR and several months in dropped it and broke the screen. Would still use it instead of 9a, love how light and compact the phone was. At least now I have a spare phone to root and do stuff with that I couldn't on my main one.
I recently pulled out my Pixel 3 and forgot how much I liked the form factor.
The 4a is a great phone. So thin and light, and even a headphone jack.
Does LOS provide kernel backports or is it limited to userspace?
They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).
[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...
>Recently, Contributor 0xCAFEBABE introduced a very different kind of generic target that can be run on various types of bare-metal hardware devices.
>While it’s still in experimental state, it has successfully booted on:
>Common x86_64 PCs
>Apple Silicon Macs
>NVIDIA DGX Spark
>Qualcomm Snapdragon X Series Laptops
That actually sounds awesome! Refurbishing old laptops with Android would be a nice choice alongside with Desktop Linux.
Why would someone want android with crappy apps comparing to linux on the old laptop?
Better sandboxing. If one of the programs you apt-get is hacked through supply chain compromise or something, it has full access to all the goodies in your user profile. There are distros that attempt to implement sandboxing but in those distros your browser can't really be jailed properly. Qubes has tighter isolation than android does, but is slower and too much of a hassle for your typical employee or relative.
Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.
Would be interesting for x86-based tablets/convertibles, like for instance an old Lenovo X1. I tried using these with Linux with various different distributions, including PostmarketOS, and it was not a good experience.
Running apps that require a phone and are not available for Linux, without putting them on your actual smartphone (if any)
I bet soon most of the apps you can only get on a smartphones are gonna require some kind of attestation that is unlikely to be given to your laptop running an "unsanctioned" version of android.
Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.
>I bet soon
With this attitude it's almost inevitable. Politics can stop the corporate-OS attestation apocalypse. If it happens, it's on us.
Opposing remote attestation in full generality is the wrong place to draw the line IMHO. Too many useful capabilities rely on attestation.
For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.
For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.
How will remote attestation prove that you were actually standing on the balcony pointing the camera, and not recording some slop you generated? The analog hole is a real problem.
Don't worry, photographs were being faked before Lee Harvey Oswald.
The optical data will be cryptographically bound to the state of the autofocus mechanism and to the output of a LiDAR scanner.
We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner alongside the optical lenses.
The technology need not be 100% tamper-proof to affect society: there is a huge difference between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and a few prompts and the claim that anyone with years of technical training and experience could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that can be used to create falsely attested recordings and that Apple hasn't caught on yet.
It is difficult to push back agaisnt banks. My bank started charging for some in site transactions and even some help desk. "We are migrating to online banking"
There are ways to run Android on Linux much more easily than running Linux on Android.
Much better security. Sandboxing and app isolation actually works on Android.
Familiarity
App consistency
Upstream app availability and release cycle
Security.
Games is one use case. I play the iOS version of Balatro on my Mac.
I wouldn’t want to run Linux or windows on my phone lol.
That sounds suspiciously like jart...
jart unfortunately seems to have had some kind of a mental breakdown involving a hard rightward religious/political pivot around June according to their latest twitter and github activity. They most recently posted a video of the police breaking down their bedroom door. Very sad to see
I'd say quite the opposite. jart has been very focused on specific things. While the contribution mentioned looks more butterflying amongst target.
(@0xcafebabe: ADHD high-five, I've got almost the same target list, except I'm playing with their NPUs)
It does sound rather... cosmopolitan.
Looks really promising. Once hardware codecs and camera support arrives it might be useful for old laptops. https://github.com/LineageOS/android_device_mainline_generic...
I love LineageOS. I have been using Lineage and previously Cyanogen for many years. This is how Android is meant to be.
Not all of the builds seem live. Pixel 9 Pro has 24.0, but Pixel 9 has 23.2, for example.
When I had kids I noticed that the camera quality was quite bad (e.g. on Samsung Galaxy S5 or S7), so I basically switched back to stock.
Is this still the case? My guess is that Lineage doesn't get the drivers necessary for better quality maybe.
Is that a Lineage problem or a Samsung problem?
It can be complicated. I don’t remember the whole story, but I think on the older Xperias you’d have to take care to reinstall the proprietary drivers and there were keys that could be permanently lost and then you’d be out of some of the enhancements.
I managed to install gcam on my LOS phone, and quality was way better
Yes, best chance is to get BSG's version from https://www.celsoazevedo.com/files/android/google-camera/ and install manually.
Why are you guys skipping Mi 8 SE? while still supporting older versions than that :thinking_face: Just trying to understand the reasoning for it.
It's an open source community project; the devices they support are what the maintainers own.
Someone has to maintain it. ;)
I am happy with my Poco F3 with lineageos. Also converted my moms phone, and works better for sure than that chinese crap bloat
Cool; See if this is the time I try using a cuttlefish target + webrtc remoting to drive all those cute privacy intruding apps.
the only thing keeping me from jumping from GrapheneOS is contact and storage scopes. :(
Don't forget proprietary security patches are only open sourced 3 months after -- GOS has them due to their partnership with Motorola.
A sufficiently motivated threat actor will have them (the exploits) too.
Unless you are using the most expensive flagship of a few Android brands, you are also vulnerable anyways
It's optional.
While not great, a private space or work profile with Shelter can work in a a pinch. I use it e.g. WhatsApp, where I just need three people, but which is almost unusable if you don’t give it the permission.
It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.
GrapheneOS actually feels just like LineageOS, except that it has faster upstream updates, better security, and greater usability...
I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.
Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.
Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well.
Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.
GrapheneOS does not have circle battery.
> LineageOS really should be based directly on GrapheneOS.
What would that achieve?
GOS => security, usability
LOS => most security, most usability, breadth of support
GrapheneOS is significantly more private, secure, and usable than LineageOS.
Actually LineageOS has less usability due to AOSP bugs, no GMS, unlocked boot loader, etc. The weak security is cost of wide support.
Could you explain how the ability to unlock a bootloader makes a device less usable?
I think they are referring to that LineageOS by and large (there are probably exceptions) does not have support for relocking the bootloader. Some apps refuse to work with an unlocked bootloader (but there are ways around it).
i'm fine with that "less security" as my threat model does not include crossing the US border.
Absolutely love this project for keeping my OnePlus 6T alive.
Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.
But there arnt any official new builds for OnePlus 6t same with my OnePlus 6 due to the Strict eBPF & Kernel Requirements
Are you running unofficial builds right now ?
Doesn't OnePlus 6/6T have good "close to mainline" kernel support already? Why wouldn't it work within LineageOS eBPF/version requirements?
Untill 22(Android 15) yeah but compared to the manufacturer this is insane.
What even is there in Android 17 to talk about, same old UI, no non-google AI features to run on-device without root
AICore? Not sure what you mean if not this.
https://developers.google.com/ml-kit/custom-models
Just see out of touch with reality this section is compared to the insanse community work on Apple Silicon across whisper.cpp/mflux/llama.cpp/MLX/Exo & way more
[flagged]
[flagged]