zlacker

[return to "F-Droid Fake Signer PoC"]
1. bsimps+nc[view] [source] 2025-01-04 00:41:44
>>pabs3+(OP)
Tangential, but:

I often wonder how secure these open source projects actually are. I'm curious about using Waydroid in SteamOS, but it looks like it only runs LineageOS (apparently a derivative of CyanogenMod).

I know that people claim that open source is more secure because anyone can audit it, but I wonder how closely its security actually interrogated. Seems like it could be a massive instance of the bystander effect.

All of it gives me a bias towards using official sources from companies like Apple and Google, who presumably hire the talent and institute the processes to do things right. And in any case, having years/decades of popularity is its own form of security. You know anyone who cares has already taken shots at Android and iOS, and they're still standing.

◧◩
2. okanat+Oe[view] [source] 2025-01-04 01:02:27
>>bsimps+nc
I think most of the Open Source projects are inadequate from security PoV but they are not at a place that can do harm.

Android is extremely complex so I think many of the custom ROMs possibly have some security rookie mistakes and quite a bit security bugs due to mishmash of drivers. Android is still better than most of the Linux distros due to its architecture though. The default setup of many distros doesn't have much isolation if at all.

◧◩◪
3. yjftsj+WF[view] [source] 2025-01-04 06:29:41
>>okanat+Oe
> so I think many of the custom ROMs possibly have some security rookie mistakes and quite a bit security bugs due to mishmash of drivers

I would easily believe that many Android systems have vulnerabilities owing to the horrific mess that is their kernel situation. That said, I personally doubt that aftermarket ROMs are worse than stock, as official ROMs are also running hacked up kernels.

◧◩◪◨
4. ignora+4K[view] [source] 2025-01-04 07:32:22
>>yjftsj+WF
> ...owing to the horrific mess that is their kernel situation.

Do you mean OEM drivers or the Android Kernel, specifically?

Google invests quite a bit on hardening the (Android Commons) Kernel including compile-time/link-time & runtime mitigations (both in hardware & software).

Ex: https://android-developers.googleblog.com/2018/10/control-fl...

◧◩◪◨⬒
5. yjftsj+4Y1[view] [source] 2025-01-04 21:38:56
>>ignora+4K
The drivers; last I heard, literally every Android device on the market was using a forked kernel in order to support its hardware. And Google keeps trying things to improve that situation, but... https://lwn.net/Articles/680109/ was ~9 years ago and since then not even Google themselves have managed to ship a device running a mainline kernel. Supposedly it should get better with their latest attempt to just put drivers and user space, but 1. I haven't heard of any devices actually shipping with an unmodified kernel, probably because 2. AIUI that doesn't cover all drivers anyways.
[go to top]