I was secretly hoping they'd stop supporting the Pixel 4a so I would have a reason to get a new phone, but no, still there in the list of supported devices. So I guess I'll just keep using that thing another year... Anyway: big thanks to the Lineage maintainers, keeping so many phones from landfill!
If you need a reason, the modem and the baseband firmware have several unpatched vulnerabilities on that model, which is not something that an Android update can resolve.
Is there an easy way to tell if there are unpatched vulnerabilities in my phone's modem and baseband?
In a practical sense, what are the consequences of that? If you're careful about not installing random shit on your phone?
It has remotely exploitable vulnerabilities in the firmware, Linux kernel, kernel drivers, userspace drivers and HALs. Those don't require installing anything on your device to exploit. There are publicly available proof of concept exploits for a bunch of these vulnerabilities.
Well, it might be worth it reversing firmwares now with UART pins connected. A lot has changed in (agentic) reverse engineering.<p>BRB gonna try this out on my old Fairphone
I too have a 4a that is still ticking thanks to Lineage!<p>The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
What happened there, ... After official support by Google for the 4a stopped, I remember checking LOS out, and found that it wasn't supported there either. Did I hallucinate that, or did LOS resume support afterwards? Or maybe I'm mixing up LOS and graphene
I have a OnePlus 7, and it's chugging along on LOS, otherwise I would be without a smartphone. Heh, fortunately it's still on the supported list
I wish I could still use my Pixel 4a but the battery is pretty much dead and it's too much money to replace it
Prices here are 13EUR including tools from what I can see.<p>The only reason I have been switching phones is banking apps: so much for Europe's right to repair..
I have yet to find a banking app that refuses to work on LineageOS. The only problem is if you root your phone, in which case you'll have to use Magisk to hide root from those apps, which also works fine so far.
Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
> Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.<p>What possesses companies to do things like this? A customer running a current version of LineageOS is going to have <i>better</i> security than running the out of date Android version that came with the phone. An attacker who wants root on something that will run the bank app doesn't have to use a different OS, they can just use any of this month's CVEs to root the "approved" version. Even requiring the latest patches -- which would exclude entirely too many actual customers' phones -- wouldn't stop attackers from controlling their own devices, because they could root the device before installing the patch and then install the patch for the vulnerability they used to get root on the device where they already have it.<p>And attackers who are going to modify the system to carry out an attack inherently have some kind of software development capacity, so measures like this have no effect on them and all they actually do is interfere with the ability of honest normies to replace their out of date OS with a version that is <i>less</i> likely to be compromised by attackers.<p>Are they just taking kickbacks from Google or something?
I suspect that especially banks have paranoid lawyers that probably don't understand the situation entirely, and perhaps because of that, mandate that all means have to be used to prevent non-official builds from being used, so that they cannot be sued (for some reason) if "something" goes wrong. Though I don't know if they are consistent and also apply the same reasoning to phones that don't have active security updates any more.
This is the problem: it was a cat and mouse game always. I managed even strong integrity with keybox stuff and so on. Yes it is possible. But if you really need to do send money or e. g. want to pay with NFC, it gets rather stressful. Yes, I got everything working (Note 10 pro on LOS 23), but never longer than a few month.
There are alternatives to Google Pay in Europe which work on GrapheneOS and it's likely most of those work on a production (user) build of LineageOS with a locked bootloader too. Only a few are specifically permitting GrapheneOS, and those would also be willing to explicitly permit a subset of LineageOS devices too. They'd need to start keeping a bit more of the standard security model and features intact which wouldn't be a large change. They'd mostly just need to make full production builds and start officially supporting locking. Having the privacy and security improvements done by GrapheneOS is in no way a requirement for compatibility with those financial apps.
This really is really a great development. I really just hope that will be true for the new European Digital Identity Wallet as well and we see adoption across multiple industries.<p>The state for me personally is that my joint bank account with my wife uses a play integrity protected banking app (changing your own a accounts to a better bank is one thing). Also beyond banks things now require proprietary 'secure' TAN apps like my insurance broker. The issue is that for me every a new problem like this popped up and to find solutions take time over and over. Even thing that work now may stop working the next minute because there is no real effort of fintech and its management to keep compatible with niche devices. It is mostly either coincidence or the effort of tech savvy individuals at those companies.<p>We only can hope that a large group of people including regulators get sanctioned or mandated not to use any US tech even privately so they see little offer is left even inside Europe that is truly sovereign.
I gave up for now (after about 10 years exclusive on LineageOS ). I actually bought a pixel to have Graphene as a way out of vendor ROMs again, but I still don't have the energy to switch (alone reregistration all those TAN apps takes ages often involving waiting weeks for stupi snail mail activation letters)
I just decided to completely stop paying with NFC. I always carry a few cards with me and Wero is already working in a few spots, which requires just your banking app and a working camera.<p>I don't even have Google Wallet installed anymore.
Good to know. I'm using N26 and they work just fine in Graphene OS. What I do is I create a private space for the apps needing play services, which I keep locked most of the time. This acts as a separate profile and when locked, the apps including play services are completely off. My main profile uses only open source apps and no play services.<p>I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
A plain Lineage install will include "rooted debugging" in the developer options.<p>This is separate from the Magisk root app.<p>I don't believe using the ADB root functionality is problematic. The Magisk app also has a <i>hide</i> mode.
Revolut, UBS, ABN AMRO
Too lazy to do it myself tbh
Perfectly valid answer, I don't understand why people would downvote. It's not a trivial procedure, see <a href="https://www.ifixit.com/Guide/Google+Pixel+4a+Battery+Replacement/139563" rel="nofollow">https://www.ifixit.com/Guide/Google+Pixel+4a+Battery+Replace...</a>
Where can one get one for that price range?
+ screen because you WILL break it
I replaced battery in mine for like 90 EUR and several months in dropped it and broke the screen. Would still use it instead of 9a, love how light and compact the phone was. At least now I have a spare phone to root and do stuff with that I couldn't on my main one.
I was secretly hoping I didn't misread and Linaro wiki would be up again, I really wish we could just install mainline linux on those Android phones...
The 4a is a great phone. So thin and light, and even a headphone jack.
Does LOS provide kernel backports or is it limited to userspace?
The vast majority of kernel vulnerabilities aren't backported to end-of-life devices. Special cases are made for certain vulnerabilities with a lot of media coverage. Firmware, kernel drivers, userspace drivers and HALs on end-of-life devices go without patches in general.
They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).<p>[1] eg. <a href="https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac2d504c3b797" rel="nofollow">https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...</a>
That's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.
That's honestly impressive, enough security for a locked down backup phone.
>Recently, Contributor 0xCAFEBABE introduced a very different kind of generic target that can be run on various types of bare-metal hardware devices.<p>>While it’s still in experimental state, it has successfully booted on:<p>>Common x86_64 PCs<p>>Apple Silicon Macs<p>>NVIDIA DGX Spark<p>>Qualcomm Snapdragon X Series Laptops<p>That actually sounds awesome! Refurbishing old laptops with Android would be a nice choice alongside with Desktop Linux.
Why would someone want android with crappy apps comparing to linux on the old laptop?
Better sandboxing. If one of the programs you apt-get is hacked through supply chain compromise or something, it has full access to all the goodies in your user profile. There are distros that attempt to implement sandboxing but in those distros your browser can't really be jailed properly. Qubes has tighter isolation than android does, but is slower and too much of a hassle for your typical employee or relative.<p>Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.
Would be interesting for x86-based tablets/convertibles, like for instance an old Lenovo X1. I tried using these with Linux with various different distributions, including PostmarketOS, and it was not a good experience.
Running apps that require a phone and are not available for Linux, without putting them on your actual smartphone (if any)
I bet soon most of the apps you can only get on a smartphones are gonna require some kind of attestation that is unlikely to be given to your laptop running an "unsanctioned" version of android.<p>Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.
There are ways to run Android on Linux much more easily than running Linux on Android.
Familiarity<p>App consistency<p>Upstream app availability and release cycle<p>Security.
Games is one use case. I play the iOS version of Balatro on my Mac.
Much better security. Sandboxing and app isolation actually works on Android.
I wouldn’t want to run Linux or windows on my phone lol.
That sounds suspiciously like jart...
I'd say quite the opposite. jart has been very focused on specific things. While the contribution mentioned looks more butterflying amongst target.<p>(@0xcafebabe: ADHD high-five, I've got almost the same target list, except I'm playing with their NPUs)
jart unfortunately seems to have had some kind of a mental breakdown involving a hard rightward religious/political pivot around June according to their latest twitter and github activity. They most recently posted a video of the police breaking down their bedroom door. Very sad to see
It does sound rather... cosmopolitan.
Looks really promising. Once hardware codecs and camera support arrives it might be useful for old laptops. <a href="https://github.com/LineageOS/android_device_mainline_generic/blob/lineage-24.0/docs/status.md" rel="nofollow">https://github.com/LineageOS/android_device_mainline_generic...</a>
I love LineageOS. I have been using Lineage and previously Cyanogen for many years. This is how Android is meant to be.
I wish Lineage did a better job at explaining which <i>new</i> devices are supported. Lineage clearly supports a lot of devices and device types, but most are ancient or specific models with a known hack to unlock the bootloader. A short list of recommended devices in each category (phone, TV, tablet), that can be bought new today, would go a long way.
There's a search engine here <a href="https://wiki.lineageos.org/devices/" rel="nofollow">https://wiki.lineageos.org/devices/</a> (see filters).<p>Not a lot of them unfortunately.. but with current bootloader unlocking situation, only newer motorolas seem to be missing... OnePlus 15 was added (or is in the making)
I think every device is supported by different people rather than a single org which is maybe why they don't feature some devices.
It's time to bring back Privacy Guard. GrapheneOS is up and coming. Lineage needs to take empowering users with security controls seriously.
When I had kids I noticed that the camera quality was quite bad (e.g. on Samsung Galaxy S5 or S7), so I basically switched back to stock.<p>Is this still the case? My guess is that Lineage doesn't get the drivers necessary for better quality maybe.
It can be complicated. I don’t remember the whole story, but I think on the older Xperias you’d have to take care to reinstall the proprietary drivers and there were keys that could be permanently lost and then you’d be out of some of the enhancements.
I managed to install gcam on my LOS phone, and quality was way better
Is that a Lineage problem or a Samsung problem?
Not all of the builds seem live. Pixel 9 Pro has 24.0, but Pixel 9 has 23.2, for example.
Does the BMW smart key system work on Lineage OS?
I am not sure, but here is my take on cars and smart phones: don't. Cars already spy on users through their onboard cellular modem. The last thing that you want is BMW or some or carmaker accessing, in addition to that, data on your phone, or using it to exfiltrate data if you removed/disabled the car's cellular modem.
Why are you guys skipping Mi 8 SE? while still supporting older versions than that :thinking_face:
Just trying to understand the reasoning for it.
It's an open source community project; the devices they support are what the maintainers own.
Because you didn't do it.<p>Just trying to understand why that's a mystery :thinking_face:<p>Who do you think "you guys" is exactly? You guys is you. You can port it to your chosen device and be the maintainer for that device and then we can thinking face wonder why you didn't give us some other device we wish was supported.
Someone has to maintain it. ;)
I am happy with my Poco F3 with lineageos.
Also converted my moms phone, and works better for sure than that chinese crap bloat
Cool; See if this is the time I try using a cuttlefish target + webrtc remoting to drive all those cute privacy intruding apps.
the only thing keeping me from jumping from GrapheneOS is contact and storage scopes. :(
I'm definitely open to trading some security/privacy features in favour of some QoL features Lineage had last time I used it - moving the clock back to the right (<i>where persistent notifications belong</i>) and power button for flashlight. It's a shame this has to be a "or" but as I use a burner phone when crossing borders anyway...
Contact Scopes and Storage Scopes are a small subset of the privacy features provided by GrapheneOS. It's also adding major privacy improvements on a regular basis including the recently added secure paste feature and ongoing fixes for upstream Android VPN leaks. There are many other privacy features beyond those.<p>Privacy heavily depends on security. GrapheneOS greatly improves both privacy/security patches and privacy/security protections. The sole reason for the focus on security in GrapheneOS is because it's a privacy project. It has no other reason to work on security.<p>Android 17 was released in June 2026 and has been required for full standard Android privacy and security patches since then. Only a subset of the patches Google deems to be High or Critical severity are backported. Keeping up with the standard backports and major updates is important but increasingly inadequate.
Don't forget proprietary security patches are only open sourced 3 months after -- GOS has them due to their partnership with Motorola.<p>A sufficiently motivated threat actor will have them (the exploits) too.
GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.
It's optional.
Unless you are using the most expensive flagship of a few Android brands, you are also vulnerable anyways
Pixels provide the same security features and updates for the budget 'a' series devices as the regular ones. Pixel 8a is one of the recommended devices for GrapheneOS since it still meets all the current era security standards and still has over 4.5 years of updates remaining despite being 3 generations old due to starting with 7 and launching after the initial set of 8th gen devices.<p>Motorola will be working towards providing the same thing as part of our partnership with them, but we're starting out with the high end flagship devices due to those currently being required for it.
GrapheneOS actually feels just like LineageOS, except that it has faster upstream updates, better security, and greater usability...<p>I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days. LineageOS really should be based directly on GrapheneOS.
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.<p>Here's a hint: GrapheneOS has paid developers working on it full-time, while LineageOS is done by people in their spare time. Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well. And lastly, LineageOS supports roughly 10x the number of devices. It's significantly easier if you restrict yourself to Pixels.
GrapheneOS doesn't receive early access to security patches via Motorola. We receive those through a different partner. We were already doing security preview releases prior to Motorola giving us access to their repositories which don't contain those.
<i>Also, GrapheneOS has a collaboration with Motorola and through that gets for instance early access to security patches, and probably other things as well.</i><p>Just for clarification (your points are very valid): the GrapheneOS developers have stated on several occasions that they getting embargoed patches from another OEM than Motorola.
LineageOS code can update pretty fast, but the problem is they want to do refactors, and also that bringing up a hundred outdated devices is difficult.
GrapheneOs is limited to some specific devices, LOS is all about supporting as much hardware as possible. Theybhave different target
> I don't understand why it took LineageOS so long to update to AOSP 17, while GrapheneOS managed to update to 17 in just 3 days.<p>GrapheneOS does not have circle battery.<p>> LineageOS really should be based directly on GrapheneOS.<p>What would that achieve?
GOS => security, usability<p>LOS => most security, most usability, breadth of support
Actually LineageOS has less usability due to AOSP bugs, no GMS, unlocked boot loader, etc. The weak security is cost of wide support.
Could you explain how the ability to unlock a bootloader makes a device less usable?
GrapheneOS has even less usability on my Oneplus 7T Pro, in fact it has none
i'm fine with that "less security" as my threat model does not include crossing the US border.
GrapheneOS is significantly more private, secure, and usable than LineageOS.
You're losing a lot more than that:<p>- secure app spawning (huge because without it, many hardening improvements are useless)<p>- extremely secure memory allocator<p>- fully enabled MTE on shiba and newer<p>- relockable bootloader<p>- stronger forensics resistance<p>- more trustworthy developers (ever heard of LOSCoins?)<p>- rapid support for new Pixels<p>- lightning fast security updates faster than most OEMs/ODMs<p>- built-in TTS without GMS<p>- real GMS that isn't priv-app<p>and so much more
While not great, a private space or work profile with Shelter can work in a a pinch. I use it e.g. WhatsApp, where I just need three people, but which is almost unusable if you don’t give it the permission.<p>It’s a bit more annoying but also isolates stuff like photos etc. by default, so you don’t have to think about it.
What a weird take. I see it the other way round: if you can run GrapheneOS, run GrapheneOS, period. If you can't, then there is a really cool project called LineageOS that you probably can run, and you should look into it :-).
It's not quite that simple. I don't use GOS because GOS and I have mutually incompatible views of user control. I prefer that <i>I</i> control my phone, they say I can't be trusted with that.
That's an inaccurate portrayal of our approach and especially how it compares to LineageOS. LineageOS does not provide app or user accessible root accessible either. As a counterexample to your narrative, GrapheneOS provides full manual and automatic call recording functionality internationally while LineageOS restricts it based on region.
It's really not; you've argued extensively with me that the moment a user can run an app with root the whole system is insecure. LOS sadly doesn't ship anything but `adb root` by default (although... they do that, so yes they do ship "user accessible root"), but they're still less hostile about it.<p>Anyways, since you're here perhaps you can answer my question from the other subthread: If I flash GOS and then flash Magisk on it, how hard is it to stay unbricked? Is it as easy as declining to relock the bootloader once, or is the system going to actively fight me on every boot?
Indeed, LineageOS doesn't officially support rooting *at all* anymore. They also ban Magisk from their communities IIRC.
In which ways does GOS not let you control your device? I'm curious because to me intalling GOS felt very liberating (compared to stock)
You can root Graphene. It's not something the developers condone as it breaks their view of security, but it can be done.
I suppose it depends how hard it tries to relock the bootloader; if I can tell it once to not do that then perhaps it's fine, but I don't want to risk a misclick soft bricking the device.<p>Although as an extension of that - I'm hesitant to use software written by people with such a philosophical difference. It might work today, but I wouldn't trust it to work tomorrow.
Same thing can be said for LineageOS too.
Yes this is probably a good summary. If you have a fairly recent Pixel, there is probably no reason to pick Lineage over Graphene. But Lineage covers far more devices and device types, including ancient ones.
Absolutely love this project for keeping my OnePlus 6T alive.<p>Such sad state of affairs for Android. They dropped the ball on making any working edge deep learning inference framework. iOS is way better at this of all things. For being an OSS platform the amount of rigidity in not letting users customize to the fullest without rooting is just tragic.
But there arnt any official new builds for OnePlus 6t same with my OnePlus 6 due to the Strict eBPF & Kernel Requirements<p>Are you running unofficial builds right now ?
Doesn't OnePlus 6/6T have good "close to mainline" kernel support already? Why wouldn't it work within LineageOS eBPF/version requirements?
>Doesn't OnePlus 6/6T have good "close to mainline" kernel support already?<p>Source? Lineageos lists kernel version as 4.9, which definitely isn't "mainline".<p><a href="https://wiki.lineageos.org/devices/enchilada/" rel="nofollow">https://wiki.lineageos.org/devices/enchilada/</a>
Untill 22(Android 15) yeah but compared to the manufacturer this is insane.<p>What even is there in Android 17 to talk about, same old UI, no non-google AI features to run on-device without root
AICore? Not sure what you mean if not this.
[flagged]
[flagged]
The alibi open source version of android that only runs on hardware in the +1000 USD range.<p>A bargain for a test device or a daily driver for the not so wealthy.<p>You want to change something? Want to be recognized for making anything better?<p>Port it on sub $200 devices.<p>That's where the masses are.<p>That's where you start the degoogle revolution. Where you can build a sustainable business.
You might be confusing LineageOS with GrapheneOS.<p>The device that I am typing this on (which runs LineageOS) cost me around $170 new.
GrapheneOS has support for all non-end-of-life Pixels including the budget 'a' series which are available at low prices for new devices. We don't continue indefinitely supporting devices lacking updates to firmware, drivers, HALs and in practice also upstream kernel updates once those become unreasonably insecure. We do provide extended support past end-of-life but we stop once we believe it's doing more harm than good by encouraging people to use insecure devices and especially to buy those to use it against our advice. It's a privacy and security project so we can't reasonably have official support for devices where it's highly insecure.
?<p>Did you even check the device list? Half of the chinese models are $200 or less. It's never been a price question