this post was submitted on 28 Jun 2024
61 points (93.0% liked)
Privacy
32103 readers
892 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I am not sure if there is an example of that specific situation as it would be pretty odd for a phone to be receiving security patches but not firmware updates.
Anyway its not super relevant as the Pixel 5 does not receive firmware or security patches anymore.
OP also seems to be inferring he suggested to his friend to use a very specific security / privacy OS that does not recommend using that model phone anymore for the exact reasons I mentioned. Plus the model is only receiving partial support as a stop gap for users to have time to get a newer model and won't be supported much longer anyway.
Custom ROMs will receive upstream Android security patches but not patches from proprietary components (firmware). For instance, my Moto g7 power has Android security patches from May but the latest vendor security patch level is 2021. (I'm running Lineage OS) I'm curious to know if the older firmware is a problem. I don't think it is easily exploitable outside of government backdoors. Not that it matters much as I plan on keeping my phone until it dies.
Not sure where your getting your information but the Pixel 5 has not gotten Android updates or security updates in over 7 months.
There are tons of examples of exploits being used to target EOL phones as its common for people to not care about these updates, or be misinformed, so they are easy targets.
If OP or anyone else wants to use an EOL phone that's fine but, don't pretend its a smart security practice. Although even if I were to use an EOL phone, LineageOS doesn't have the greatest background and isn't really degoogled
You are still missing my point. All phones actively supported by Lineage OS get Android security patches. Those aren't vendor patches but they do patch the OS and sometimes the kernel.
For instance, the Pixel 5 was last updated June 28. https://wiki.lineageos.org/devices/panther/
Not to say that you should still buy it. However, if it cheap it might be worth it.
Also from the article you linked:
Those are partial security patches (its not in the same ballpark as a non EOL phone).
Even non EOL phones are usually updated dangerously slow when it comes to LineageOS.
Some more sources, not sure why I'm even adding them as you seem hell bent to believe LineageOS is secure regardless of the facts.
https://eylenburg.github.io/android_comparison.htm
https://www.kuketz-blog.de/lineageos-weder-sicher-noch-datenschutzfreundlich-custom-roms-teil4/
If my device is so insecure why haven't I been compromised? Your "facts" are only important if it promotes Graphene OS.
Lmao putting facts in quotes does not makes them less true. Figures, that when confronted with reality you would immediately start relying on logical fallacies.
Just because you are more at risk of being compromised does not mean you will be compromised. This is obvious.
You don't have to respond if your just going to be a child about it.
I think lineage is a good operating system for a limited exposure use cases. Like a project phone on a safe network, or as a webcam, or is like a embedded hardware controller. But not on the raw internet, not processing raw internet data, not with open Wi-Fi, not with open Bluetooth.
Even with all of that, it should still be segmented from the rest of the network