Hi all,
I was becoming increasingly concerned by the lack of security patches from Lenovo for the P2. The latest one being November 2017.
I decided to install Lineage OS 15.1 as a way of mitigating these risks and apart from my Barclays banking apps not running because they believe the phone to be insecure. I have been very happy with it, until today when I looked in the Trust section of settings and saw that there appear to be two security patch streams. Platform and Vendor. Platform is "up to date" but vendor is "out of date".
Having done some research it appears that vendor seems mainly to relate to security vulnerabilities in device drivers that have to be implemented by Lenovo (someone please tell me if this is wrong).
Clearly Lineage has addressed the known OS vulnerabilities which must be better than stock having had no updates for over a year.
1 - What vulnerabilities am I exposed to by having out of date vendor updates in Lineage OS?
2 - What are the risks from having an unlocked bootloader?
What can I do to mitigate the above two risks?
The reason I got and love my P2 is the battery life. As far as I can tell there is still nothing on the market that can touch it. However, given the unknowns and complexities around patches and security I am seriously thinking of buying a Pixel 3 and running stock Google.
Please can anyone give me the facts so I can make a decision (I'd rather stay with the P2 as it meets my needs better).
Best regards,
Robert
Related
Hi,
I'm really considering buying a P2 to replace my good old 1st gen moto g. At 300 € here in France, it seems like a really good value.
The only things that could hold me back now are system updates and alternate ROM support. I've read on Reddit that as the phone is only available in some parts of Asia and Europe, the developers community could not be that big. So two small questions :
I've read that the nougat update has just been made available. Is there a Lenovo commitment for Android O, too ? Are there regular security updates since the phone is out ?
Speaking of alternate ROM, if I understand correctly there's currently a LineageOS 14.1 basis that works well beside fingerprint reader and notification LED ? Do you know if there is a chance that the P2 could become an officially supported device for lineageOS ?
Thanks for your answer and all your contributions.
They barely released Nougat 7.0 and you're asking for Oreo? Even flagships like S8 will eventually get Android 8 in Q1 2018 given that Google will release the new OS version in Q3 2017. No regular security updates, till Nougat the phone was on MM with Oct 2016 security patch. Hell you can buy other phone till you're waiting for O. IMO Lenovo won't update P2 to Oreo, as at that time the new P3 should be already out and they'll focus on it and forget about the P2. No word for adding official support for Lineage OS, but that doesn't matter as the unofficial builds are working just fine.
Lenovo giving android O ?? only in dreams
but we have Good developers, and if you are looking official - then AICP is there, Lineage we dont have any info on it as our bro said in above post
if you have managed to use MotoG this many years you would like P2 very much and use longer, Only satisfactory thing in this P2 is BATTERY , other than that SAMSUNGS are better ;(
hate to praise samsungs in this forum but they are better if you have good money ..
---------- Post added at 08:06 PM ---------- Previous post was at 08:04 PM ----------
911-Future_Maker said:
They barely released Nougat 7.0 and you're asking for Oreo? Even flagships like S8 will eventually get Android 8 in Q1 2018 given that Google will release the new OS version in Q3 2017. No regular security updates, till Nougat the phone was on MM with Oct 2016 security patch. Hell you can buy other phone till you're waiting for O. IMO Lenovo won't update P2 to Oreo, as at that time the new P3 should be already out and they'll focus on it and forget about the P2. No word for adding official support for Lineage OS, but that doesn't matter as the unofficial builds are working just fine.
Click to expand...
Click to collapse
bro , did you manage to ROOT your official 7.0 ?? :highfive:
i want to root my stock, but failing .. it gets stuck and goes to BLUE LED ERROR , do you have any suggestions !
Yes I rooted the stock 7.0 just fine with SuperSu 2.79 systemless.
911-Future_Maker said:
Yes I rooted the stock 7.0 just fine with SuperSu 2.79 systemless.
Click to expand...
Click to collapse
What's the point of rooting this phone other than using lucky patcher o just can't see it.
What are your essential root apps.
Ayman ae said:
What's the point of rooting this phone other than using lucky patcher o just can't see it.
What are your essential root apps.
Click to expand...
Click to collapse
First and most important possibility of Ad blocking - which saves your: time bandwidth and money.
There are some other apps which work only with root but this is beyond this discussion.
Ayman ae said:
What's the point of rooting this phone other than using lucky patcher o just can't see it.
What are your essential root apps.
Click to expand...
Click to collapse
I need root for many things. On MM for Xposed, Titanium Backup, Kernel Auditor, DualBoot Patcher, Adblock and more. On Nougat the same arguments without Xposed.
911-Future_Maker said:
I need root for many things. On MM for Xposed, Titanium Backup, Kernel Auditor, DualBoot Patcher, Adblock and more. On Nougat the same arguments without Xposed.
Click to expand...
Click to collapse
I hope xposed will come to nougat soon, then i will swich to nougat
Can you guys point me in the right direction. I'm currently on rr remix but my security updates are from September 2017, how do it get the latest security updates?
Thanks!
BrickMe?Naw said:
Can you guys point me in the right direction. I'm currently on rr remix but my security updates are from September 2017, how do it get the latest security updates?
Thanks!
Click to expand...
Click to collapse
You got that from settings > about? That's from the ROM base. You could update firmware to get any that are provided for that, but otherwise you'll have to wait for the developer to update the ROM with a new base.
Truthfully though, it's nothing to worry about. Concern with new possible exploits are mostly overblown. They are discovered by security companies and more times than not, hackers haven't discovered it themselves yet.
Got it, thanks bro!
Recently when OnePlus team released some news about upcoming Pie upgrade on their forums, i wonder if Google had made Treble mandatory on devices that upgrade to Pie now?
AFAIK when they upgrade to oreo last year, they never enable Treble on OP3 as Google didn't made it mandatory...
Thanks!
Noo. It was mandatory for phones which came with oreo out of the box and pie out of the box. Op3 came with marshmallow out of the box
For newer phones launching with Oreo (or any later versions), Treble support is necessary to pass VTS (therefore get the checks needed for the phone to use Gapps).
However, this was (and is) never the case for upgrades. There is also no change in this rule, and I imagine OnePlus wouldn't bother with it.
Hello. Recently I thought some sort of security issue came up with the pixel 2xl, and you had to be on the latest security patch to be safe. Are old ROMs that don't have this new security update vulnerable?
Not updated rom have security issues.
borthbrushtoothpaste said:
Hello. Recently I thought some sort of security issue came up with the pixel 2xl, and you had to be on the latest security patch to be safe. Are old ROMs that don't have this new security update vulnerable?
Click to expand...
Click to collapse
Just saw this, but obvious answer is obvious. If you need the latest security patch to be safe, then old ROMs without the latest security patch aren't safe to use. They are therefore vulnerable.
gothicVI has applied the android monthly security updates from google , for the last several months to all versions of LineageOS for the moto potter.
Thank you for keeping our phones up to date !
https://androidfilehost.com/?a=show&w=files&flid=272434
Nivead said:
gothicVI has applied the android monthly security updates from google , for the last several months to all versions of LineageOS for the moto potter.
Thank you for keeping our phones up to date !
https://androidfilehost.com/?a=show&w=files&flid=272434
Click to expand...
Click to collapse
I have updated the link in the official thread, thanks for providing the link.
Awesome! Thanks for the security updates.. Badly needed for my lineage 16 (android 9) .
I am avoiding android 10 till twrp can do proper restores etc..
thank you
Nivead said:
gothicVI has applied the android monthly security updates from google , for the last several months to all versions of LineageOS for the moto potter.
Thank you for keeping our phones up to date !
https://androidfilehost.com/?a=show&w=files&flid=272434
Click to expand...
Click to collapse
Can we expect security updates from dev till the end of 2020?
By the way big thanks to gothic for keeping potter updated and alive.
Aj_$tyle$ said:
Can we expect security updates from dev till the end of 2020?
By the way big thanks to gothic for keeping potter updated and alive.
Click to expand...
Click to collapse
Google puts out the updates, in general; every month or as needed. I have no communications with the developer GothicIV. I just check his web site and if the security updates are there, I download and apply to my phone.
GothicIV posted September 2020 updates yesterday (19th).
October 2020 security updates are available...
November 2020 security updates available.
December 2020 security updates are available
Hey there,
I have attempted to update to the 3 most recent security patches (Oct 25, Nov 7, Dec 13) for LineageOS 16.0 (potter) provided by gothicVI, but after successfully flashing them my phone bootloops back to TWRP 3.4.0.0 after trying to boot system for a few minutes.
I have logcat logs for each security patch boot attempt.
I am currently stuck on the Oct 9 security patch as it is the latest version that will boot on my phone.
Where I can get help with this?
gothicVI is awesome, so far Moto G5 Plus seems pretty much abandoned, pixel experience lags too much on my 2gb ram variant. Time to buy a new phone but for now gonna use this.
carlasan said:
I am avoiding android 10 till twrp can do proper restores etc..
thank you
Click to expand...
Click to collapse
Is that the only issue? I flashed crDroid 6.13 from the latest twrp with no problems so far. Any issues besides restore I should be aware of if I decide to move to another rom?