Form that committ, it seems to me that LOS is finally allowing signature spoofing for microg (under certain conditions). Have they finally changed their mind?

5 points
*
permalink
report
reply
1 point
*

Cool, but I wonder why they finally agreed on signature spoofing. IIRC, the were quite adamantine on not allowing it.

permalink
report
parent
reply
3 points

I don’t know but the nature of the patches shifted over time. I believe initially, they allowed any app (or any system app?) to spoof signatures which I’d also agree to not allow. The current patches only allow it for the Google Play services and Play Store which is a much smaller attack surface.

permalink
report
parent
reply
4 points

Big if true! I am going with LineageOS4microg for more than a year now, just because it is not possible to get a decent location working on pure LOS without Gapps.

permalink
report
reply
3 points

Sweet! Though it does say that it only works when

  • Build is debuggable (userdebug/eng)

I wonder how many custom ROMs ship like this to the end user

permalink
report
reply
4 points

AFAIK all custom roms are released as userdebug build.

permalink
report
parent
reply
2 points
*

Pretty sure GrapheneOS isn’t. Though I would expect most “tinker ROMs” to be userdebug though.

permalink
report
parent
reply
2 points

I don’t know. Mine (surya) says “userdebug” under kernel version. Is it the same?

permalink
report
parent
reply

Community stats

  • 12

    Monthly active users

  • 78

    Posts

  • 243

    Comments

Community moderators