Maybe if you include third party android OEMs like samsung, but google pixels are as up to date as you can get.
Is there any evidence that the git commits weren't in the ROMs from months ago? The monthly ASB corresponds to when the bugs are publicly disclosed, not when they made it into ROMs.
The only way to get the full set of security preview patches is through GrapheneOS. It's strange Google doesn't ship more for the Pixel OS but that's the way it is right now. It takes them around 4 weeks to make a release and even longer when including the time for adding changes to it so there's a long delay built into the process. They should fix it but are clearly not prioritizing it without media pressure that's not happening. They do a lot better than other OEMs but that's much different from doing a good job.
BRB gonna try this out on my old Fairphone
The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
It's so bad.
The only reason I have been switching phones is banking apps: so much for Europe's right to repair..
What possesses companies to do things like this? A customer running a current version of LineageOS is going to have better security than running the out of date Android version that came with the phone. An attacker who wants root on something that will run the bank app doesn't have to use a different OS, they can just use any of this month's CVEs to root the "approved" version. Even requiring the latest patches -- which would exclude entirely too many actual customers' phones -- wouldn't stop attackers from controlling their own devices, because they could root the device before installing the patch and then install the patch for the vulnerability they used to get root on the device where they already have it.
And attackers who are going to modify the system to carry out an attack inherently have some kind of software development capacity, so measures like this have no effect on them and all they actually do is interfere with the ability of honest normies to replace their out of date OS with a version that is less likely to be compromised by attackers.
Are they just taking kickbacks from Google or something?
Even if the something is no more than engaging less fatuous attorneys.
Yes, because that particular set of lawyers haven’t said it has to be blocked. Doesn’t mean my statement that lawyers have final say is “objectively not true”.
All it takes for this to happen is the lawyers not knowing.
The state for me personally is that my joint bank account with my wife uses a play integrity protected banking app (changing your own a accounts to a better bank is one thing). Also beyond banks things now require proprietary 'secure' TAN apps like my insurance broker. The issue is that for me every a new problem like this popped up and to find solutions take time over and over. Even thing that work now may stop working the next minute because there is no real effort of fintech and its management to keep compatible with niche devices. It is mostly either coincidence or the effort of tech savvy individuals at those companies.
We only can hope that a large group of people including regulators get sanctioned or mandated not to use any US tech even privately so they see little offer is left even inside Europe that is truly sovereign. I gave up for now (after about 10 years exclusive on LineageOS ). I actually bought a pixel to have Graphene as a way out of vendor ROMs again, but I still don't have the energy to switch (alone reregistration all those TAN apps takes ages often involving waiting weeks for stupi snail mail activation letters)
I don't even have Google Wallet installed anymore.
Otherwise, vote with your wallet wherever possible and prefer those businesses that do accept cash.
I'm glad the option is still there in most places, but it's clear most people don't actually care for cash (neither do I for that matter, other than as a backup solution).
I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.
It requires a sim card and cannot be used from multiple phones. So they put you to this endless face scan loop and then lock you out.
This is separate from the Magisk root app.
I don't believe using the ADB root functionality is problematic. The Magisk app also has a hide mode.
[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...