The grim future for LineageOS and custom Android ROMs

I wrote an article that analyzes how LineageOS is used, including the number of builds and installs by device manufacturer, country, version, device release year and status (official, discontinued and unofficial), plus installs per capita. See:
https://amosbbatto.wordpress.com/2025/11/02/lineageos-statistics

I added a section at the end of the article about the threats that I see to the LineageOS project, and frankly the outlook is grim for custom Android ROMs. With the recent changes to the bootloader unlock policies at Samsung, Xiaomi, Realme and ASUS, the brands that LineageOS can be installed on will be reduced from 42.5% of the global smartphone market to just 7%.

Long ago, I predicted that the world would eventually need mobile Linux, because Google would shut down AOSP, if the AOSP derivatives like LineageOS ever became too much of a threat to Google’s profits. While Google has restricted AOSP in a number of ways over the years, I never foresaw the threat if Google pushed the rest of the phone industry to start offering longer support for their phones.

Because the Android phone makers now have to offer longer support for their phones, they are being pushed toward a business model based on the collection of users’ personal data that is used for targeted advertising and the training of AI. While the old business model based on hardware sales and planned obsolescence was horrible for the environment, the new business model is going to be horrible in terms of personal privacy.

I doubt that the restricting of custom Android ROMs to just 7% of the smartphone market will lead to large numbers of people switching to mobile Linux, but it does clearly show the problems with the industry, where people don’t really own their own hardware, because they can’t install the software that they choose on their phones.

10 Likes

LineageOS does not represent all custom Android ROMs.

2 Likes

All the custom ROMs have the same problem that you can’t install them unless you can unlock the bootloader. Regardless of whether you are installing postmarketOS or LineageOS, you don’t really own the hardware if you can’t unlock the bootloader.

However, it is worth pointing out that a large number of the AOSP derivatives are based on LineageOS (I list some of them in the article). LineageOS is like Debian that it has a lot of influence, because it has so many children which are based on it.

4 Likes

I agree with your counterpoints, except that I would not consider unlocking the bootloader sufficient for claiming hardware ownership.

4 Likes

Right, but what @amosbatto wrote was only that “you don’t really own the hardware if you can’t unlock the bootloader”, that’s not saying it’s sufficient.

What would be sufficient for claiming hardware ownership?

How about this: “You have ownership of some hardware if you control it, and you are able to verify that nobody else is controlling it behind your back”? That is, the device cannot contain things that can be manipulated or used by others without the owner being aware of it or being able to stop it.

5 Likes

11 posts were split to a new topic: Obstacles to libre mobile

Controlling the entire fabrication and assembly process of all components used in the product.

As a non-trivial point of correction…

You wrote in your study:

Android was created by Google as a means to collect users’ personal information for Google’s targeted advertising…

Android was not created by Google; it was bought by Google from its creators. (And Google hired those same creators.)

Of course, we know that Google then went on to “enhance” the data collection.

I think you maybe had in mind “developed,” and not “created,” though.

3 Likes

Good point. I changed it from “created” to “developed” in the article.

I looked up the history of Android, and everything that I have found is very vague about the state of the operating system when it was developed by an independent company between Oct 2003 and July 2005 before Google bought the company for $50 million. Android started as an OS for digital cameras and then switched to mobile phones in 2004. Before Google bought the OS, it had no chance of getting used in a commercial product, and it didn’t make its first beta release of the code until Nov. 5, 2007, when Google announced the formation of the Open Handset Alliance. Google didn’t get serious about Android until Apple released the iPhone in June 2007, and it took over a year after that for the first Android phone, the HTC Dream, to be released in October 2008.

3 Likes

I posted somethnig related…
It started with removing the ublock from chrome store, then they locked it out of the browser, now you can get ungoogled chromium with ublock and it still works like chrome. SO they have to snip out fdroid and only allow approved apps.

As for unlocked or unlockable bootloader one consequence of a truly user owned device is that the user CAN put their own bootloader lock and report as locked, maybe a PGP hash to an ident server if you like, as well as owning the various firmwares, FOSS drivers for all components, and a fully owned bootup chain to the FOSS OS.

I think that the only viable phone where you truly own the phone and where there will be longterm support is by putting GrapheneOS on to a Pixil phone. That’s like, if you want to escape the devil, the only way is to go directly to the devil himself. You have to buy a Pixil phone directly from Google. If you buy the Pixil from any carrier, the boot loader will be locked and you’ll never get in to it. Installing GrapheneOS is very easy if you buy the phone directly from Google. You can easily unlock the bootloader by sliding a swich in developer mode. Then go to a website on your PC, plug your phone into the PC via USB, and click install from the PC. It’s that easy. Just wait for the installation to complete and the phone to reboot and you’re then done. You own the phone, there is nothing Google left on it at that point (except for the hardware). You do not register with anyone nor login anywhere. But I highly recommend that you at least lock your screen with a password.

If you want Google Apps, you have to install all of the Google stuff first. That’s like saying “please Google, take me back”. But the phone will be hardened. Google has no Admin privileges on that phone. You can download and install all of the Google apps anonymously from the Aurora store. The apps are forced to behave properly in GrapheneOS. Each app is in its own private isolated sandbox. Apps can not talk to each other without you setting up those permissions yourself first. No apps can phone home to its developer, nor to Google. You’re the boss.

GrapheneOS is loaded with several features that are not available anywhere else. I have set up four profiles on my GrapheneOS phone. When I login as Admin, I can do anything. When I use my work profile, I have access to my employer’s network and the tools that they intend me to have access to. If the IT department at work tries to take control of my phone, that won’t work. I could choose to let them control my work profile. If they become too intrusive, I can just erase my work profile and tell them they need to provide me with a work phone. When I login as a Google user, I can run all of the Google apps, but can’t access any files from my other profiles. When I login to my private profile, I can do anything except I can’t run any Google apps. None of these profiles can access any files or settings from a different profile. If I wanted to, I could set up a profile for a family member and loan them my phone. Without my passwords, they could not login to any of my profiles. But they could login to their own profile and use the phone with the permissions that I set up for them. If someone at the airport demands that I give them my password, I can give them a password that erases the phone’s encryption keys which keys can never be restored. But I could later unlock the password protected bootloader and reflash a new installation of GrapheneOS to the phone and start over. If I keep my personal files backed up to my PC, then after such a fresh install, I can then also restore my lost files from the incident at the airport.

I’m pretty sure that any app that inherently needs internet access in order to function could also phone home.

The known “phone home” addresses can be blocked. So you’re telling the app “we’ll let you have internet access, but we won’t let you phone home”. However your point is well taken. Some apps won’t work anymore when you lock them down too tightly. GrapheneOS did however, block many aspects of the Google framework. The Google framework doesn’t come installed. But GrapheneOS was created with the assumption that many users will install the Google framework. There are several settings that you can make in GrapheneOS with respect to Google. I’ll paraphrase here as I can’t remember those setting names. But they range from “Don’t trust Google at all” to “Let Google do anything it wants to do”, and everything in-between. And these settings are all decided on a per-app basis. So if you really want a certain app to work and that app requires full access before it will work, you can give that app full access, while keeping all other Google apps locked down tightly. I also keep the Google framework disabled all of the time, except I turn it on before I use any Google app. Then I turn it back off when I am done using that Google app. Some spying probably does occur. If you log in to Google itself or in to Amazon, maximum spying will occur. So never install any app directly from the Google Play Store.

Install all of your Google apps anonymously from the Aurora Store. You will likely find significant backlogs when using the Aurora Store. Everyone shares the same anonymous Google login. You never see that login. But sometimes you have to try again later. Sometimes I’ll see no slowdown in the middle of the night. And updates are easier to download than are new apps, downloaded from scratch.

That’s a bad assumption. The assumption should be that people want to be free from google.

I have very little respect left for GrapheneOS after seeing them argue that iphones are “secure”. They are just way too BigTech-friendly for my taste. My impression is that they don’t genuinely care about freedom (they seem to not even understand the concept of freedom), they only care about what they call “security” which they think you get by allowing BigTech companies to own you.

The reason a standard android phone thus including GraphineOS and Pixels will never really be secure is because it has an integrated modem and a non-free boot process. The integrated modem means that memory is shared and the modem can access all memory via DMA there is no fixing this unless the system takes a big performance hit by encrypting RAM access. Pinephones and Librems use a modem module, the connection is via command and audio lines but the modem has it’s own unconnected OS the pinephone even has had 75% of the modem OS hacked out and replaced with free open source software. The bootup for most phones is also a black box, who knows what is happening on a graphine-pixel until the OS itself loads. Librems and Pinephones have free open souce auditable bootup chain you know what stuff is happening even before the main OS loads. The choice is Graphine which does it’s best by encrypting some parts and the battery lasts longer or you can choose the REAL freedom phones where you know your privacy is enforced and no part of the OS is accessable if you set the optional calamares full disc encryption.
GraphineOS sounds good until you educate yourself the weaknesses, it is still far better than stock and has more developers but it by the nature of it’s bootup and modem at a minimum will always provide many tools to defeat the user and help hackers, corporations, and the police state. Live with appropriate paranoia, we are in the dark future cyberpunk timeline, act like you care and stick with the hardware-software combination that really works; right now the only qualifiers are Pinephone and Librem NOT GraphineOS unles sthey make a port for a freedom phone and Pixel will never qualify by it’s nature.
As for google it is reasonably easy to blacklist the DNS and IP addresses associated with this and other problematic orgs.

I agree that the Pixil phones are not completely free from the Google ecosystem. And unlike the Librem 5, the Pixil hardware is nowhere close to being FSF compliant. But GrapheneOS is the closest thing to free that you will ever find on Android. Google did not design or create GrapheneOS. The Android Open Source Project created GrapheneOS. They take the base Android OS and try hard to make the phone secure, which includes keeping Google out.

To design GrapheneOS with the assumption that people will install the Google stuff in to it shouldn’t threaten anyone. If you don’t install Google access stuff in to your GrapheneOS, then all of the anti-Google stuff that was designed-in to the OS is of no threat to you. But if you do install all of that Google stuff, then at least GrapheneOS is on your side. Google is more or less kept in its own cage, forced to serve only you, and is not allowed to phone home. It’s not a perfect solution. But it is currently the best solution.

Several Librem 5 users try to install virtual Android operating systems in to their Librem 5, to run Google apps in Android, inside of PureOS. Several Librem 5 owners try to run Google programs directly in PureOS, using compatability layers. Both methods significantly compromise their Librem 5 security. The GrapheneOS method is safer and much easier.

The only perfect solution is to not use any Google apps. You can do that in GrapheneOs too. But if you’re committed to not using any Google apps, then the Librem 5 is the best choice.

1 Like

Back in the Neo900 days I was somewhat driving the appropriate paranoia campaign, modularized modem with power kill switch and the POCSAG pager in idea(became Joerg’s hacker interface) was me, then purism and pine added more kill switches, I had some back and forth with RMS, he was interested but he wanted all non-upgradable components(no firmware upgrades) so he could call them hardware, that was all were missing to meet his purity test. Teh Librem RAM trainer ROM chip if it had the write-protect fuses blown would probably qualify per RMS. IDK maybe he is thinking evil maid attacks but I like upgradable firmware as long as I control the upgrades and can review the new code. Back then he checked and answered emails you could probably reach out.

I am not sure about that, I have done it, it is not great but not terrible, but I would rather just never boot microg no-google waydroid in the first place, I have it for emergencies,maybe route all Google related traffic through TOR or a VPN and keep that toggled to block most of the time unless really required. I get it students and employees seeem to need to have apple/android apps for their life, and then there are the now batch of closed IMs and voip that everyone likes. But nobody wants to use TOX because not enough people use TOX, and they love that all of their messaging apps just harvest their phonebook to find contacts as if that is OK.

Is anyone running GraphineOS on waydroid?

I had to laugh… GrapheneOS on Waydroid, on the Librem 5. How many levels of paranoia do we need to satisfy here? I am not laughing at you, because I don’t think the idea is bad. But I doubt that the Librem 5 has enough RAM and CPU power to do that kind of heavy lifting.

Perhaps the idea works on different hardware e.g. on your desktop/laptop.

Having not used Graphene I am curious how much heavier it is than the normal LineageOS that runs reasonably well in Waydroid. I end up having to customize the Linage quite a bit installing Microg and other anti-google tweaks before I consider it ready. And then I almost never boot it up, but I have an install sitting at what I would consider ready should I need it considering the few hours of work required to get there.