Skip to content
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. I'm confused by your latest update @calyxinstitute @calyxos but perhaps I'm missing something.
Welcome to Caint!

Issues? Post in Comments & Feedback
You can now view, reply, and favourite posts from the Fediverse. You can click here or click on the on the navigation bar on the left.

I'm confused by your latest update @calyxinstitute @calyxos but perhaps I'm missing something.

Scheduled Pinned Locked Moved Uncategorized
privacysecurity
2 Posts 1 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Sean O'BrienP This user is from outside of this forum
    Sean O'BrienP This user is from outside of this forum
    Sean O'Brien
    wrote last edited by
    #1

    I'm confused by your latest update @calyxinstitute @calyxos but perhaps I'm missing something.

    Doesn't Android allow for there to be an intermediary "bridge" / migration release signed with both old and new keys, if there is no key compromise *and* you folks just pushed an OTA update with the old key?

    AFAIK this is how LineageOS does it.

    #privacy #security

    https://calyxos.org/news/2025/08/27/last-ota-update-before-new-calyxos-release/

    Sean O'BrienP 1 Reply Last reply
    1
    0
    • R ActivityRelay shared this topic
    • Sean O'BrienP Sean O'Brien

      I'm confused by your latest update @calyxinstitute @calyxos but perhaps I'm missing something.

      Doesn't Android allow for there to be an intermediary "bridge" / migration release signed with both old and new keys, if there is no key compromise *and* you folks just pushed an OTA update with the old key?

      AFAIK this is how LineageOS does it.

      #privacy #security

      https://calyxos.org/news/2025/08/27/last-ota-update-before-new-calyxos-release/

      Sean O'BrienP This user is from outside of this forum
      Sean O'BrienP This user is from outside of this forum
      Sean O'Brien
      wrote last edited by
      #2

      @calyxinstitute @calyxos You could even generate a third keypair and use that for releases after the audit, so that the latest keys were never on a release with the old ones you're concerned about.

      This all seems like something to worry about only if the current private key was compromised / exposed and you said that didn't happen.

      1 Reply Last reply
      1
      0
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • All Topics
      • Popular
      • World
      • Users
      • Groups