• 0 Posts
  • 38 Comments
Joined 17 days ago
cake
Cake day: June 21st, 2024

help-circle



  • LineageOS for microG is a custom build which already includes the patch to enable signature spoofing. This still means that microG is running with root privileges. It btw also includes the F-Droid privileged extension, which is yet another app running with elevated privileges and adding unnecessary attack surface. Installing microG is the quick and easy workaround to get Google Play services, but it’s more like a dirty hack that reduces security. GrapheneOS is currently the only ROM that properly integrates the official Google Play Services using the Android app sandbox. This also increases app compatibility, and it’s the reason why most banking apps work without any issues on GrapheneOS, while they are broken on Lineage, Calyx and other ROMs that use microG.













  • Calyx is pretty insecure by default, it removes some default AOSP security features and is very slow to push security patches. And it doesn’t include any of the GrapheneOS security features like hardened SELinux, a hardened kernel, secure app spawning, hardened Chromium browser and WebView or hardware-based integrity attestation. It also uses a very flawed Google Play services implementation (microG) which requires root and has worse app compatibility.