Conversation

Replying to and
I was the one that created and maintained it, almost entirely on my own. It offered substantially more privacy and security than the stock OS. It couldn't offer a longer support period since it relied on the same security updates. It's no longer the same thing that it was before.
2
2
Only Nexus and Pixel phones support locking the bootloader with an alternate OS. I'm obviously aware of that since I worked on an alternate OS preserving the security model used by the stock OS and AOSP. There's no point in locking it if the OS being used breaks that security.
2
Third party recovery images like TWRP don't preserve the security model and it's entirely pointless to lock the bootloader. It also prevents updating them since the OS won't be doing it. You're also missing that on modern devices that can have basic security verified boot exists.
1
Nexus 5X/6P and Pixel phones fully support verified boot for other operating systems and enable it when the bootloader is locked. Having a mismatched recovery or a tampered OS (i.e. sideloaded gapps) aren't compatible. LineageOS, etc. don't include verified boot support either.
1
I don't need you to explain to me how this works. You're wasting your time and mine. As I've said, devices without full security updates are a security disaster. Your Nexus 5 is incredibly insecure and easy to exploit, regardless of which insecure ROM you choose to run on it.
1
Nexus 5 stopped receiving support after October 2016. Using a ROM shipping the latest AOSP security patch doesn't fix that, as I've explained, since the vast majority of the driver, kernel and firmware updates aren't available. The firmware and many drivers are closed source too.
1
Your device doesn't have basic security updates for the vulnerabilities disclosed in the monthly bulletins. That's basic security hygiene. There's far more to security than fixing disclosed vulnerabilities and also you're missing years of advances in software / hardware security.
1
Fixing discovered vulnerabilities is basic security hygiene. Your device doesn't even have those basics. It isn't fixed by any ROM. You're in the same position as someone using WinXP in 2018 and trying to justify it by saying a couple out of thousands of bugs got binary patches.
1
Show replies