• N.E.P.T.R@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      18
      ·
      5 days ago

      AOSP is fully open source. Google certified Android isn’t.

      Sailfish is proprietary Linux. Gapps Android is proprietary AOSP. GrapheneOS is fully open-source and AOSP-based.

      I stand by my point. Never use a proprietary OS of you care about your privacy. I don’t like proprietary Linux distros.

      • Valmond@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        1
        ·
        4 days ago

        I think soon you can have a fully functional phone without apple, google etc. So Graphene is the only one today, what do you think about fairphone (I don’t know which os it uses)?

        • N.E.P.T.R@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 days ago

          Fairphobe is neat but I’d never use it. Underpowered device, weak hardware security. It seems it can run many OSes, idk which it comes with.

          I only recommend GrapheneOS as a mobile OS because it takes phone security seriously. With the rise of surveillance capitalism and fascism, people need devices with strong security guarantees.

          I don’t recommend Linux phones because often lack of basically any security. Desktop OSes have very different threat models compared to mobile OSes. Desktop linux (which Linux phones basically still are) lack strong software security because nothing is properly isolated and it is trivial for malware to exploit 0days or run persistent under your user (I can link to my comment on the insecurity of desktop Linux, which applies to most desktop OSes). Android has protected against most of the recent Local Privilege Escalation attacks present in the Linux kernel (eg copyfail) because of its security design. Pre-emptive security practices are important.

          There is no privacy without security. There is no privacy without open source.

        • boonhet@sopuli.xyz
          link
          fedilink
          arrow-up
          1
          ·
          3 days ago

          For the foreseeable future it’ll unfortunately only be fully functional in countries where you don’t use a mobile auth and signing service. Which, okay, I can skip in my country and use an ID card instead, but then I have to have a card reader on me whenever I need to sign into any government services or bank