• 8 Posts
  • 128 Comments
Joined 1 year ago
cake
Cake day: September 1st, 2023

help-circle















  • TL;DR Unless you’re being persecuted, I’d say the most important criteria is picking a modern phone actively supported by a ROM. Samsung, OnePlus, LG, FairPhone, … they’re all fine.

    What’s your threat model? Most likely, if you’re just a normal dude, the most you’ll have to fear is someone stealing your phone and trying to replace the OS on the phone. Probably every modern Android phone protects against that with secure boot. If somebody wants to read your data, IINM every modern Android phone has encryption activated by default meaning so do modern ROMs.

    If you have somebody knowledgeable enough to start attacking your phone by opening it and messing with hardware, you’ve got an entirely different problem and if they want to get in, they will. Either physically through you (a wrench can reveal your password), a 0-day (iPhones were hacked through iMessage by text messages the user never saw aka zero click), or through some yet unrevealed vulnerability if you’re that important.



  • I believe the devs of GrapheneOS have tailored their requirements to target Google Pixel phones for one simple reason: there aren’t enough devs to help them support other phones. They probably owned Pixels and started development on them, got specialized in them and didn’t want to branch out as that costs lots of time.

    There’s nothing wrong with that. The only issue I find with their reasoning is all the claims they make of Google Pixels being the only secure Android phones in existence. It’s detrimental because non-techies will just repeat that to death because they don’t know better - just like Appholes repeating that iPhones are the most secure phones out there and Apple cares about privacy. It’s free advertisement for Google. So people head out and give Google more money than their data would ever be worth and they do it repeatedly every few years because it’s “common knowledge” that Google Pixels are the most secure phones out there.

    The worst thing about that is that Google didn’t have to do anything. Had Google made those claims, people would be wary, but this is an independent group and because of that, people give it credence.

    Not saying GrapheneOS is a shit project - it definitely isn’t, just the claims and free advertisement these devs are giving Google is bad.

    CC BY-NC-SA 4.0