If only a project existed to support devices beyond what the original manufacturers were willing to put out with singular consistent releases across all hardware.
Oh yeah, Lineage.
If only the company that made the OS actually supported the effort to perpetually support devices with a single OS the way Android should have been from day 1.
The problem is that you have to trust Lineage's (just an example) developers and release process. If you want Google Apps installed you need to trust another 3rd party like http://opengapps.org or https://microg.org/.
At this point I'm not so sure what's better: an updated OS or one full of known exploits.
Like I said, it was just an example. I don't have the time or knowledge to review an entire custom ISO and after that another ISO from the Gapps provider that I choose. I'm sure there are some tricks to cut down the review process time but anyway.
It's a trade-off. I'm installing custom software to improve security, but at the same time, can I trust that this solution won't be a source of malware?
I hope this didn't came out as accusatory, I was just trying to show another aspect of using custom ROMs.
It didn't - I'm mostly curious what people's thoughts are on things.
For what its worth, the mirror selection software we're using [1] won't send you to a mirror that has a modified file. If a mirror is doing something malicious (and that doesn't catch it), builds are signed and can be verified [2]. Obviously there's some level of trust involved (build infrastructure isn't auditable, android builds aren't reproducible).
Oh yeah, Lineage.
If only the company that made the OS actually supported the effort to perpetually support devices with a single OS the way Android should have been from day 1.