Best Custom Android ROM for Security Bulletines

I'm interested in switching to Android from the iPhone. Mainly due to insane used prices. One of the biggest concerns for me is security. With the iPhone I know that most likely for the next five or six years I will get latest iOS and security patches on the same day as they are released.

However, with Android I may have to wait months for a patch after Google releases it. If the manufacturer ever releases it.

As my interest in switching to Android is price, quality and aftermarket case options. I'm looking at a used Samsung Galaxy S6. As I know that Android 7 will likely be the last update from Samsung and they have an abysmal update timeline anyways. I'll root it and use a custom ROM. As custom ROMs are updated more regularly and typically support major phones for many more Android revisions. I'm ignoring most other Android phones due to the lack of aftermarket case options. I want to be able to use waterproof, form fit bumper cases (like the Lifeproof Fre).

Which leads to my question. Which custom ROM is best from a security standpoint?
- Fastest at applying Google's monthly Android security bulletins
- Doesn't have trackers sending my private info to the ROM maker (I know this is unavoidable with any mobile OS but I'm more comfortable with just Google or Apple having this access without adding in some small third party)

Ideally I would just use a Google Nexus or Pixel as they get immediate (or near immediate) updates. Unfortunately Google's support for them is horrible and prices are too high. Support is horrible as they only seem to support them for two to three years with Android updates. Prices are too high as I can get a similar generation iPhone for about the same price. Which will be supported longer. As I prefer iOS, I'd just stick with the iPhone.

There are just so many custom Android ROMs. It's hard to know which is crap and which is good.
 
if you looking for quick security updates then your options a nexus 5X, 6P, or one of the google pixel phones. all of the updates for these phones are controlled by google. i have a nexus 6P and i get updates at the start of every month. custom ROMS do come out with new versions a lot like lineage but that doesn't mean they have the latest monthly security patch every release
 


I already mentioned why the Nexus and Pixel are not an option. Google doesn't support them long enough. Their used prices aren't tempting enough. Given their history. In all likelihood the Nexus 5 and 6 will be dropped with Android 8. While the 5x and 6p will likely be dropped with 9.

Hence the custom ROMs. As I'm looking for an option that gives a longer use life. While still getting a fast phone and OS updates. One can get 7.1 on an ancient Galaxy S2. The Galaxy S6 line was popular enough to have good case options. Knocking most other used former flagship phones out of contention.

If there isn't a good option. I'd rather just stick with the iPhone. It's just tempting to see such a fast and feature rich used Galaxy S6 32GB for $175. When a used iPhone 6S 64GB costs $350 (for some reason 32GB seems to cost more used). But it is all for naught if I can't get security patches and OS updates in a reasonable time frame for at least the next three years. If there isn't a considerable savings. I prefer iOS to Android.

If only Google could get Android to install on phones like Windows for PC. Where you can install the vanilla OS on practically any phone using generic drivers (with the installer containing drivers for fairly common hardware). Then download and install drivers manually or use a Google update service to find and install missing drivers. With phone space being an issue. It could then delete all unused drivers from the device.
 
I think you're overrating "Long term support". Apple already dropped support for iPhone 4 and earlier, and it makes sense, in the same way as Google (or Samsung) are dropping support for earlier phones: It takes efforts, which are better directed at new developments, rather than trying to install Windows 10 on i486.

If you are so obsessed with security - why would you trust a developer of custom ROM with your data more than you would trust Google / Apple? How long that developer will be interested in issuing ROMs for your (eg) five year phone, when there are much better toys to work with?

Then - rooting your phone opens it wide and deep for exploits, known and unknown.

And your dream of "installing Android like you install Windows" - just forget it. At lease for next couple of years.
 


Perhaps Apple has spoiled me with their long term support. iOS 10 still supports the iPhone 5. Four to five years is not unreasonable for OS updates. If the hardware is perfectly capable of running the OS at a good speed.

Now I don't see why I need to defend my position. I didn't ask for a debate. I just asked a simple question and this thread is being derailed. If someone knows the answer I would like to know that answer. Rather than spending several hours researching the topic. As I'm sure there are Android lovers here whom read about this stuff all the time and are aware of articles or alerts about one ROM distro or another.

Which custom ROM is best from a security standpoint?
- Fastest at applying Google's monthly Android security bulletins
- Doesn't have trackers sending my private info to the ROM maker (I know this is unavoidable with any mobile OS but I'm more comfortable with just Google or Apple having this access without adding in some small third party)
 

nobodyknowsme44

Prominent
Sep 21, 2017
1
0
510


Dropping support is part of any Android device, but the Nexus 5X and 6P are expected about 2 more years of security updates. If you are really that concerned with security, I would recommend you check out Copperhead OS. You get none of the Google apps that can introduce spyware, and a lot of security patches and updates rolled out quickly, and their focus is purely security only, but you´ll need to use one of the devices supported by the OS from the company, which right now is Pixel, Pixel XL, Nexus 5X, and Nexus 6P