this post was submitted on 24 May 2025
112 points (94.4% liked)

Privacy

38116 readers
746 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

My current phone is 7 years old, does not support recent android versions, and battery life is becoming atrocious. This feels like right time to change my phone.

Currently, I know of & am considering 3 options:

  • Google Pixel
  • iPhone
  • Samsung Galaxy

I heard that Pixel is the best choice for privacy, despite it being Google^TM. Should I go with it, and install Graphene OS or similar options? The very fact that the name "Google" is attached makes me nervous. Also, I don't think I can trust android, so I would have to install Graphene OS or the like. In the case, app support would be lacking, though.

I am considering iPhone as well, since it has "reputation" of being secure. Of course, Apple can access my data, but that might be a good enough compromise? Honestly, I don't know. It's the best supported option as well - lots of apps support iPhone.

Galaxy is just the one that I am the most familiar with (my current one is Galaxy S8). I don't trust it, though. Do they even make good hardware nowadays?

EDIT: Turns out, Pixel phones are poorly supported by local telecomm companies. It is relatively cheap though. Still worth it?

EDIT2: I heard that data & message is fine, but the call quality is impacted by lack of VoLTE compatibility.

(page 2) 48 comments
sorted by: hot top controversial new old
[–] [email protected] 3 points 5 days ago (1 children)

You should consider buying a flip phone and only put in SIM card when you need it, assuming you can acquire SIM card without your name on it where you live

[–] [email protected] 3 points 5 days ago (1 children)

Flipphones are just less feature, same spying.

[–] [email protected] 5 points 5 days ago (4 children)

These flip phones dont have anything other than a SIM card

load more comments (4 replies)
[–] [email protected] 30 points 5 days ago

I am considering iPhone as well, since it has “reputation” of being secure.

Which doesn't mean private.

Pixel+Graphene is a common suggestion.

For real privacy you can't beat these.

[–] [email protected] 20 points 5 days ago (4 children)

I've been rocking a Pixel 8 pro with Graphene OS for a year and change and it was a great experience after being an iPhone user for 8 years aproximately.

The install process is great, automatic and foolproof, you just need the phone, usb cable (probably came with your phone) and a computer with a Chromium-based browser.

App support hasn't been a problem for me, you can reach for Aurora Store (anonymous Play Store client) if you really need something from there. Otherwise you have F-droid and the usual suspects and also Accrescent, which Graphene offers through its own app store, but barely has anything as of today.

I setup Shelter to have some apps more isolated and being able to just not see them if I want, namely some Microsoft apps I need for work and some that depend o Google's services. Shelter is recommended by privacyguides.org, so you should be fine using it.

I think Pixel/Graphene is probably your best option for security if you need it. Privacy I guess you can achieve many other ways.

load more comments (4 replies)
[–] [email protected] 10 points 5 days ago

Using a Pixel 6 with Graphene here with google services in their sandbox. It's pretty neat, especially with apps like Firefox+uBlock and GrayJay, which let me also block 99% of ads, which was very important to me. I have not had trouble with any banking apps either.

[–] [email protected] 10 points 5 days ago

best choice for privacy [...] “reputation” of being secure

Disentangling privacy and security, and potentially other priorities, e.g. secrecy, anonymity, etc might be important before making suggestion.

Another way to help deciding what is the best choice for you, not necessarily anybody else, is what is your threat model?

An analogy I thought recently is "Are you putting a very tough lock on your door but leaving the windows opened?" or "Are you locking your car but walking outside naked?". The point here is not to imply that people do obvious mistakes but rather that, truly there are people who go to parades naked AND lock their cars. The concerns can be orthogonal and thus must be considered individually. For that I believe thinking about "who the enemy is" as a way to discover your threat model is interesting, namely :

Are you worried by :

  • government getting your private data without your consent?
  • government doing so automatically and cheaply through intermediaries e.g. platforms?
  • government doing so via extremely costly individual security attacks e.g. 0-days, with a "legit" hacker manually doing it?
  • small private companies?
  • platforms?
  • your actual neighbor?

The answer to those questions will then provide you a more limited set of options. Basically I would argue only the 3rd option ties tightly with security but that's up to a certain extent and companies like Pegasus shows that it can also be done at scale, for profit. Still, AFAICT it wasn't done for a random person BUT that was few years ago.

Anyway one you go through options, e.g. iPhone vs Android vs deGoogled Android vs Linux phone vs dumb phone you will see your usage itself will have to change. This is not necessarily a bad thing but it is not something most people will think about initially.

I suggest then to... try. I know it's not the answer you want but what you are asking for, I believe, is genuine change. It is about the technology, yes, but it also is about your habits. Consequently it is a process with some success, failures, cascading changes and thus IMHO must be iterated on.

It is worth it though.

[–] [email protected] 3 points 5 days ago* (last edited 5 days ago)

I bought a Fairphone 3 and put LineageOS on it a few years back and can recommend it. LineageOS is less secure than GrapheneOS as far as I can tell but the privacy aspect is there, as you have a completely degoogled phone. I have some friends that have the same setup on the newer Fairphones and they are also very happy and have a smoother experience than me, because it is a newer phone.

Fairphone is an European country that has a move to open source (https://www.fairphone.com/en/open-source/).

To the compatibility and functionality:

  • SMS and Calling is no problem, VoLTE works and as SMS app I recommend QUICK.
  • AppStore I recommend F-Droid and Aurora Store. With Aurora Store you can download and install all apps that are on the Google Store. Just check, that your Banking Apps and so on support non-Google-Android OSs as some people I know had to switch back because some banks and services only work with Google Services (and that is a shame in my opinion, a Bank should NEVER be dependent on other companies for transactions and authentication. I for my part switched bank because of such a thing.)
  • microG can be used to use apps that need Google services, I do not use it but friends use it and are happy

In general you will find an replacement for every app you now use that is from a big company. Open Source came a long way and most alternatives are even better in my opinion.

[–] [email protected] 0 points 5 days ago

Privacy finished with the first Smartphone

[–] [email protected] 1 points 5 days ago

I'm currently testing lineageos on a oneplus 6t since it is dirt cheap (from 50€$) ob ebay.

So far my track record has been:

  • Around 6 months of daily use
  • wifi, bluetooth, lte, gsm all work without issues
  • calls work 99% (same as iphone)
  • headset needs usbc bc no headphone jack. Works with adapter but so far only for music
  • camera works, qr codes work
  • nfc works but without google services, ive found no oayment provider thay supports it
  • around 16 hrs of battery life under normal use
  • no ads in os (or browser, thanks to ublock)

As with all custom roms, you need to unlock the bootloader and if you dont encrypt, you should not do anything on the phone that cant ever be found by a third party, say law enforcement. I would argue that the majority of phones with a locked bootloader arent any better but apparently, if you want that extra security, graphene on a pixel seems to be much more fitting. I have heard of issues with reliability so I'll stick with lineage.

I do develop for and did try postmarketos (actual linux) and I love it. But its absolutely not end user ready from last time i used it. If you tinker and want to help, postmarketos deserves your help but please dont use it as a daily and expect more than 80% reliability. Its for people who love linux and want it to become the real deal and who can manage their frustrations.

[–] [email protected] 7 points 5 days ago

I think you're mixing privacy with security, iPhone is secure but it's not private, it's slighty more private than Google Android but not what would you call private.

Samsung can soft brick your phone so basically backdoor.

Google Pixel with custom ROM like GrapheneOS or CalyxOS is considered to be best in terms of privacy.

Another cheaper alternative if you don't want to give money to Google or spend too much is Motorola G32, G42, G52 with CalyxOS but to unlock bootloader you have to make account on their website.

[–] [email protected] 0 points 5 days ago

In EU, I would recommend a xiaomi. Cheap, bootloader unlockable (which breaks security a little since you cant relock), but they are a gamble in terms of reliability.

[–] [email protected] 2 points 5 days ago

What apps do you need? Do you know that app support is lacking on GOS or just think it? I would go with Pixel8a and GOS.

[–] [email protected] 2 points 5 days ago

pigeon with paper that lights itself on fire when human skin touches it

[–] [email protected] 1 points 5 days ago* (last edited 5 days ago) (4 children)

GrapheneOS tested and I ended up going back to Apple.

It’s good in concept but in reality you’re just forced to used play services because most apps require it, but you lose mobile payment and access to some apps because you’re not running a whitelisted OS. App makers don’t give a fuck because custom ROM users are fewer than Linux users, and we all know most software and games don’t give a fuck about Linux users.

Stock GrapheneOS also feels like a jump in the past in terms of UI and accessibility. I felt like I was always going out of my way to make it somewhat usable.

The Pixel also has a battery that doesn’t last long and poor charge retention on idle (Android phones do be like that though). I found out that many tasks cause it to heat a lot. Something like updating an app takes ages and shows visual bugs, like no progress indicator.

I hate Apple but at least I trust that they don’t sell my data to everyone, and they have a good UI.

If the end it’s about how much you’re willing to trade your convenience for privacy. I realized I wasn’t ready.

load more comments (4 replies)
[–] [email protected] 11 points 5 days ago

Not advice, just an anecdote I switched to grapheme (pixel 8a) not long ago and its really great I haven't even been tempted to go back. I think its a great choice

[–] [email protected] 11 points 6 days ago

Pixel unlocked and install grapheneOS or lineageOS

[–] [email protected] 1 points 6 days ago
[–] [email protected] 25 points 6 days ago (4 children)

Just to let you know, GrapheneOS uses AOSP (the base Android system) and sandboxed Google Play Services, making it compatible with 90% of all Android applications. From what I've heard (don't take my word for it), the apps that have the least compatibility / more breakage are banking ones.

[–] [email protected] 5 points 5 days ago (1 children)

It does not "use" AOSP, it's built on AOSP, like every Android device.

AOSP is like the foundation of any Android OS.

[–] [email protected] 7 points 5 days ago

Yes, that was a poor choice of words on my part; I do apologize about that.

[–] [email protected] 8 points 6 days ago (1 children)

While this tends to be true, the vast majority of the banking app incompatibilities are overcome with a simple app-specific toggle.

[–] [email protected] 5 points 6 days ago (5 children)

Which toggle is that and does it work with cash app?

[–] [email protected] 8 points 5 days ago (2 children)

Exploit Protection Compatibility Mode. It's a setting that relaxes this particular security enhancement for a given app.

It's worth knowing that NFC payments do not work with Graphene currently.

[–] [email protected] 4 points 5 days ago (3 children)

Oh I didn't know NFC payments were not working. No workaround?

load more comments (3 replies)
load more comments (1 replies)
load more comments (4 replies)
[–] [email protected] 3 points 6 days ago

Yeah, the problem is with the one banking app I frequent.

load more comments (1 replies)
[–] [email protected] 3 points 6 days ago (2 children)
[–] [email protected] 2 points 6 days ago

Telegraph with One Time Pad

[–] [email protected] 2 points 6 days ago
[–] [email protected] 40 points 6 days ago (3 children)

Please note: You must buy the "Unlocked - Works with any carrier" version of the Pixel via Googles website (or from a reputable source that ensures it is/was not carrier locked). Anything else will have a permanently locked boot loader and no way to install Graphene.

[–] [email protected] 4 points 5 days ago

I got my Pixel 7 from T-Mobile.. The OEM unlocking toggle shows up in developer settings. An internet search implies I have a unicorn.

[–] [email protected] 11 points 6 days ago* (last edited 6 days ago) (3 children)

Oh my, that sounds difficult. What does "permanently locked bootloader" mean? I was just going to buy at local phone shop..

EDIT: Turns out, local phone shop does not sell Google Pixel. Gotta buy from official google store..

[–] [email protected] 4 points 5 days ago

"Permanently locked bootloader" means you can't unlock the bootloader so you can flash a different OS. If you can't unlock the bootloader, you can't flash. A lot of phones are like this, like Samsung's galaxy series. I got really fucked by Samsung with the S10 because of this. You need to buy a specific type of phone and security patch if you want to flash. I went with the Pixel bought unlocked from Google so I could use GrapheneOS. It was very easy to unlock the bootloader and then relock it back. I noticed you said the pixel does not have good reception in your country, I would look more into this before going with it if this is the case.

[–] [email protected] 4 points 6 days ago (1 children)

I usually just buy them used.

[–] [email protected] 6 points 6 days ago (1 children)

You have to look for the unlocked version though. They usually sell for a little bit more but it's worth paying the extra.

[–] [email protected] 1 points 5 days ago (1 children)

Where can the seller check if it is the unlocked one?

load more comments (1 replies)
[–] [email protected] 14 points 6 days ago

Actually, if you buy a Pixel, you need to get the "google edition" version, which google sells directly. If you're buying used, specifically search for the "google edition" version. I have a Pixel 6 Pro running Graphine OS and I love it. It's not difficult to install.

load more comments (1 replies)
[–] [email protected] 66 points 6 days ago* (last edited 6 days ago) (6 children)
  1. Pixel, and immediately install GrapheneOS.
  2. A Linux based phone, like the PinePhone or Purism 5, and run your Android apps (if desired) inside Waydroid.
[–] [email protected] 8 points 5 days ago

I didn't realize that Purism phones don't have internationally compatible modems. As someone who travels a lot, that's unfortunately a dealbreaker.

[–] [email protected] 1 points 5 days ago (3 children)

Does GrapheneOS support inTune Company Portal and work profiles? I would love to switch but my work requires these to install teams and outlook

[–] [email protected] 6 points 5 days ago* (last edited 5 days ago)

GrapheneOS affords you the ability to have completely isolated and distinct phone profiles, where you can install all your required work apps. They are installed separate from your main profile, kind of like second or third phone. No need for a completely different device.

GrapheneOS instantiates an improved version of this feature that Android already offers. It's a great way to keep things separate. I do the same. Who wants to stuff their pockets or bags with more phones?

You can read about that here.

[–] [email protected] 6 points 5 days ago* (last edited 5 days ago) (7 children)

The best solution in that situation is to have a work phone and a personal phone. If your own private phone cannot install the work apps then it's up to your employer to ensure you have the tools you need for your work.
From an IT Security perspective that is what your employer should want too as that allows them to confiscate the phone if letting you go.

load more comments (7 replies)
load more comments (1 replies)
[–] [email protected] 2 points 6 days ago (2 children)

Por que no los e/OS with a Morena phone?

[–] [email protected] 18 points 6 days ago

e/OS is miles behind GrapheneOS and even CalyxOS. I see no reason to go that route if you'll be much better served by any modestly modern Pixel phone and GrapheneOS.

load more comments (1 replies)
load more comments (3 replies)
[–] [email protected] 34 points 6 days ago* (last edited 6 days ago) (1 children)

In my opinion, the Google Pixel with GrapheneOS is considered the gold standard in terms of security and privacy. While I am not fully knowledgeable about its capabilities, it offers a comprehensive suite of security features.

The iPhone is also a viable option. You can easily swap between iCloud to a more secure encrypted provider for both cloud storage and photo backups. Additionally, any notes application can be replaced with a more secure alternative.

Samsung phones can support a range of operating system images that can be flashed, including LineageOS. However, I am not fully aware of all the available options.

[–] [email protected] -1 points 5 days ago (2 children)

The iPhone is also a viable option

🤭

[–] [email protected] 7 points 5 days ago

iPhone 15 (the most recent model without AI) is perfectly adequate for most people.

[–] [email protected] 6 points 5 days ago

lol idk what you find amusing about that but okay

load more comments
view more: ‹ prev next ›