Do we agree that the Android security model is baked into AOSP? Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well?
Assuming they share a big part of the security model, how would it "not make sense" to compare them? If AOSP is the baseline, saying that /e/OS is often weakening the security model and GrapheneOS is hardening it is a way to compare them. That makes complete sense to me.
> Or would you say that the Play Services bring the security model to Google-certified Android, GrapheneOS implements its own security model from scratch, and LineageOS as well?
Yes I would say that most of the security decisions are not baked into AOSP and every rom brings their own decisions.
Assuming they share a big part of the security model, how would it "not make sense" to compare them? If AOSP is the baseline, saying that /e/OS is often weakening the security model and GrapheneOS is hardening it is a way to compare them. That makes complete sense to me.