6
submitted 1 month ago* (last edited 1 month ago) by DeathByBigSad@sh.itjust.works to c/android@lemmy.world
top 9 comments
sorted by: hot top controversial new old
[-] Godort@lemmy.ca 3 points 1 month ago

Practically? Basically none at all.

If someone got physical access to your phone, they could install another OS without your knowledge.

[-] Blue_Morpho@lemmy.world 1 points 1 month ago

Malware could over write the bootloader allowing it to sit unnoticed forever.

[-] tomyhaw@lemmy.world 1 points 1 month ago

The way I understand it is the bootloader is built in security on the soc itself similar to tpm? In some regards phones are safer than computers in this way. If you leave your laptop out someone can tamper with the os, same with an unlocked bootloader. Safe from governments you shouldn't use a phone if that's your worry.

I don't even have a lock on my phone

[-] Ilandar@lemmy.today 1 points 1 month ago

That's ultimately for you to decide. No one here can tell you whether or not it's likely that someone will gain unsupervised, physical access to your phone.

[-] mazzilius_marsti@lemmy.world 0 points 1 month ago

Its been a while since I used LineageOS on my OG Pixel (sailfish). I remember you have to install the custom bootloader like TWRP to flash the ROM and there was this thing with A and B partitions. Not sure if things change....

With an unlocked bootloader, whoever gets your phone can do the weird Vol Up + Power button combos to flash enter the TWRP bootloader. I couldnt recall correctly, but it is possible they can view / delete your data right within the TWRP screen. Not sure about transferring them off of your device.

OTOH, a locked bootloader wouldnt allow you to do this. There is no way to enter a flash a different ROM.

The thing with unlocked bootloader like LineageOS, especially in my case an OG Pixel, is that you can still flash the official Pixel OS in case Lineage starts to mess things up. LineageOS leaves the bootloader unlocked, so you can still flash.

I'm talking about the case where your phone is completely bricked, i.e. cannot open phone. So you can just use platform-tools to reflash. With Graphene, i guess it is more difficult in this case?

[-] frongt@lemmy.zip 0 points 1 month ago

If someone gains access to your device they could alter or replace the OS without your notice, called an evil maid attack.

If the bootloader is locked, they'd have to have the phone OS booted and screen unlocked, then unlock the bootloader, which wipes the device.

[-] nathan@piefed.alphapuggle.dev 1 points 1 month ago* (last edited 1 month ago)

If this is part of your threat model and you are using lineage on a device that supports avb_custom_key then you can sign it yourself before flashing

[-] lka1988@sh.itjust.works -1 points 1 month ago

If you have to ask, then you aren't important enough to actually be worrying about this kind of thing.

If you were that important, then you would already know the answer to your question.

[-] NaibofTabr@infosec.pub -2 points 1 month ago

This is relatively minor. The bigger risk when running a downstream OS is that the team does not have the finances, the staff, or the broad-ecosystem visibility to support their own security research and development in any functional capacity, and there is an unavoidable delay in integrating security updates from the upstream OS.

This is a big problem. It makes running any small-team derivative OS a high-risk choice.

this post was submitted on 01 Sep 2025
6 points (100.0% liked)

Android

31998 readers
25 users here now

DROID DOES

Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


We are Android girls*,

In our Lemmy.world.

The back is plastic,

It's fantastic.

*Well, not just girls: people of all gender identities are welcomed here.


Our Partner Communities:

!android@lemmy.ml


founded 2 years ago
MODERATORS