Unlocking the bootloader makes the entire system compromised - an adversary can install malware that persists through reboots or even factory resets, since the security regarding verified boot is disabled; they can decrypt the storage and read, copy it; it is relatively easy for a system to experience privilege escalation, and run admin commands - if the user is aware of it or not.
There’s a few other things, and some of it needs an additional step or two, but most things go from ‘impossible’ to ‘trivial’. And when you’re facing an adversary (be it a rootkit in an apk, law enforcement, or government agencies) that expect you to be knowledgeable about tech, they will take advantage of the potential holes users might make along the way.
Relocking the bootloader is incredibly rare on custom roms; I know of only one that supports it (gos). Every other rom I’ve ever used, so in the 50+ range, doesn’t worry about it. So usually the only way to relock is to revert to factory.
Yeah CalyxOS just came back from a hiatus due to some internal drama, and iodéOS is a French based ROM that is based on LineageOS.
CalyxOS has made some pretty nice QoL changes in the last few years that I really appreciate (Seedvault backups, Per-app, per connection type firewalling, Work profile ootb, VPN sharing over all profiles)
iodeOS offers bootloader relocking on devices that support it, and they support devices longer than Calyx & Graphene for Eco. sustainability, but you do still run the risk of the proprietary hardware drivers having vulnerabilities. I tried it out for a bit but it wasnt for me.
Unlocking the bootloader makes the entire system compromised - an adversary can install malware that persists through reboots or even factory resets, since the security regarding verified boot is disabled; they can decrypt the storage and read, copy it; it is relatively easy for a system to experience privilege escalation, and run admin commands - if the user is aware of it or not.
There’s a few other things, and some of it needs an additional step or two, but most things go from ‘impossible’ to ‘trivial’. And when you’re facing an adversary (be it a rootkit in an apk, law enforcement, or government agencies) that expect you to be knowledgeable about tech, they will take advantage of the potential holes users might make along the way.
Relocking the bootloader is incredibly rare on custom roms; I know of only one that supports it (gos). Every other rom I’ve ever used, so in the 50+ range, doesn’t worry about it. So usually the only way to relock is to revert to factory.
LineageOS via avbroot, CalyxOS and iodéOS all support bootloader relocking.
Even /e/os supports relocking.
Rocking it rn.
Is calyx still a thing? I used to use it years ago. iode is a new one to me :o
Yeah CalyxOS just came back from a hiatus due to some internal drama, and iodéOS is a French based ROM that is based on LineageOS.
CalyxOS has made some pretty nice QoL changes in the last few years that I really appreciate (Seedvault backups, Per-app, per connection type firewalling, Work profile ootb, VPN sharing over all profiles)
iodeOS offers bootloader relocking on devices that support it, and they support devices longer than Calyx & Graphene for Eco. sustainability, but you do still run the risk of the proprietary hardware drivers having vulnerabilities. I tried it out for a bit but it wasnt for me.
Thank you!
No problem :)