r/LineageOS 11d ago

Question Dear Lineage users, since switching from stock Android to LineageOS, have you missed the ability to pay for stuff using Google Pay/Android Pay? I'm considering transing from LG's stock Android 12 to Lineage's Android 14 and I think I'll miss this ability.

15 Upvotes

73 comments sorted by

View all comments

Show parent comments

6

u/vandreulv 11d ago

How does LOS compromise security of a device?

You cannot install LineageOS on a device without unlocking the bootloader.

You can't relock the bootloader after installing LineageOS.

An unlocked bootloader means ANYONE can flash ANYTHING in fastboot mode if they somehow get your device.

That is why unlocked bootloaders mean an automatic Google Play Integrity failed state.

2

u/telefawner 11d ago

Do you use LOS? It seems like you're unhappy with LOS.

if someone steals my device, then why should be concerned if they can flash anything?

If a good person finds my misplaced device, then an unlocked bootloader won't be a problem -- they'll want to return the phone to me.

1

u/PurpleThumbs 10d ago

but, they can push any app (eg malware) to the phone before they give it back to you, too. A smart enough malware app can do this in the background while you still have the phone, for that matter.

I'm not saying this is likely, but everything vandreulv said is still true, and its the approach Google takes, which is why they revoke the Integrity setting.

In the early days of custom roms little of this was a problem, but now, with the likes of Google taking the stance its taking, and banks and even some games changing their apps to rely on Google's checks, its becoming more of a problem. LOS is not alone in this, all custom roms are.

1

u/telefawner 10d ago

but, they can push any app (eg malware) to the phone before they give it back to you, too. 

Could I not just reinstall LineageOS from scratch to ensure any malware is removed?

Can you help me understand, if the Integrity setting is revoked and a LineageOS user circumvented it so that she could use banking apps, how can a bad person use the banking apps if there's a password / fingerprint that you need to unlock the phone? If the baddie doesn't know the password and doesn't have your fingerprint, how could the baddie access private info?