I mean if the Linux âfoundationâ was insecure wouldnât that also mean the Android foundation is just as insecure? Android is a Linux distro with an extremely specialized userspace but still linux beneath (I remember when Samsung used to brag about setting SELinux to enforcing before every other OEM and stuff like that).
And then performance of Android on top of ârealâ linux shouldnât be different, weâre not running any sort of emulator or virtual machine, but even if we did use VMs, hardware assisted virtualization and paravirtualization should make the performance close enough to native that you could go as far as pulling a qubes style distro for mobile, but I donât know if anybody is that much paranoid.