You should also avoid buying phones preloaded with /e/ OS (sometimes branded as the Murena phones). /e/ OS in itself is extremely insecure, engaging in security bad practices that include, but are not limited to, not supporting verified boot; shipping userdebug build; shipping months-old version of Chromium; and bundling years-old version of Orbot into their operating system, then marketing it as “Advanced Privacy”. There was also a recent incident where their cloud service mishandled session keys and gave users access to other’s files, then proceeded to mislead users that the server cannot see their files, despite there being no end-to-end encryption.
You should also be very wary of low quality privacy branded phones like the Freedom Phone, BraX2 Phone, Volta Phone, and the like. These are cheap Chinese phones with the Mediatek Helio P60 from 2018, which has already reached or is near end-of-life. Needless to say, you should also avoid any vendor...
https://privsec.dev/posts/android/android-tips/
lots more tips at the link.
#lel
You should also be very wary of low quality privacy branded phones like the Freedom Phone, BraX2 Phone, Volta Phone, and the like. These are cheap Chinese phones with the Mediatek Helio P60 from 2018, which has already reached or is near end-of-life. Needless to say, you should also avoid any vendor...
https://privsec.dev/posts/android/android-tips/
lots more tips at the link.
#lel
privsec.dev
Android Tips
Android is a very secure and robust operating system out of the box. This post will be less of a “hardening guide”, but more of a non-exhaustive list of tips when it comes to buying and using Android phones.
Android Devices Recommended Phones Google Pixel…
Android Devices Recommended Phones Google Pixel…
https://nitter.net/GrapheneOS/status/2081837057433915603
/e/ is a highly problematic fork of LineageOS very poor privacy and atrocious security. People would be far better off using standard LineageOS one of the better supported devices. An iPhone is far more private and drastically more secure than Murena products.
/e/ lacks crucial standard privacy and security patches. It has many months and even years of delays to provide those. Nearly all the devices they support lack most Linux kernel, driver and firmware updates. They don't keep up with those for any devices. They don't keep up with Android, Chromium or Linux security updates anywhere either. Many severe patched privacy and security vulnerabilities are left wide open for months and even years with /e/. They heavily mislead their users about what's patched and how long they take to ship it.
/e/ also doesn't provide important standard privacy or security protections. It lags years behind on providing the current generation protections and disables many of the most important ones. An operating system failing to protect against known privacy weaknesses does not have reasonable privacy.
/e/ includes their own privacy invasive services and sends user data to third party including OpenAI without consent. Despite how it's marketed, it includes many Google services with privileged integration into the OS. They have their own privacy invasive services including user tracking with unique identifiers in their update client.
Their own supposed privacy features are incredibly flawed and do not provide what they claim. A small list of blocked domains omitting everything used for useful functionality does not stop tracking by apps or services. It leaves the most privacy invasive behavior of apps and services intact and is trivially bypassed in multiple ways even for what it does cover. Apps and services only need to use the same domains for functionality as tracking to avoid it which is already largely what they do. Apps and services also already widely deploy bypasses for this naive domain-based filtering even for domains dedicated to tracking. /e/ would have you believe that a DNS blocklist is a game changing approach. There are better implementations including RethinkDNS available for use elsewhere.
More information:
community.e.foundation/t/voi…
codeberg.org/divested-mobile…
eylenburg.github.io/android_…
discuss.grapheneos.org/d/241…
/e/ and their for-profit company Murena have repeatedly pushed anti-privacy talking points from authoritarians claiming devices with strong privacy and security are for criminals and pedophiles. Here are 2 examples where Gaël Duval says that himself about privacy/security hardened devices in general:
nitter.net/GrapheneOS/status/2040…
clubic.com/actualite-604786-…
/e/ and Murena many of the same anti-privacy talking points as France's current government and national law enforcement. They've aligned themselves with authoritarians in the country where they're based instead of opposing it. There are dozens of examples where they falsely claim GrapheneOS are mainly useful to criminals and mainly used by criminals. That's more extreme than the claims by France's national law enforcement cracking down on secure devices. They've gone so far to align themselves with anti-privacy authoritarians that they're ahead of them.
Murena is a for-profit company with the founders and owners of it being the same people who run /e/. /e/ includes for-profit paid Murena services and is built for Murena to sell devices with it. Despite being made for profit, /e/ receives millions of euros in government funding from governments which have spent years cracking down on legitimate privacy products:
> The European Union has subsidized us to the tune of several million for this project.
projets-libres.org/en/podcas…
#lel
/e/ is a highly problematic fork of LineageOS very poor privacy and atrocious security. People would be far better off using standard LineageOS one of the better supported devices. An iPhone is far more private and drastically more secure than Murena products.
/e/ lacks crucial standard privacy and security patches. It has many months and even years of delays to provide those. Nearly all the devices they support lack most Linux kernel, driver and firmware updates. They don't keep up with those for any devices. They don't keep up with Android, Chromium or Linux security updates anywhere either. Many severe patched privacy and security vulnerabilities are left wide open for months and even years with /e/. They heavily mislead their users about what's patched and how long they take to ship it.
/e/ also doesn't provide important standard privacy or security protections. It lags years behind on providing the current generation protections and disables many of the most important ones. An operating system failing to protect against known privacy weaknesses does not have reasonable privacy.
/e/ includes their own privacy invasive services and sends user data to third party including OpenAI without consent. Despite how it's marketed, it includes many Google services with privileged integration into the OS. They have their own privacy invasive services including user tracking with unique identifiers in their update client.
Their own supposed privacy features are incredibly flawed and do not provide what they claim. A small list of blocked domains omitting everything used for useful functionality does not stop tracking by apps or services. It leaves the most privacy invasive behavior of apps and services intact and is trivially bypassed in multiple ways even for what it does cover. Apps and services only need to use the same domains for functionality as tracking to avoid it which is already largely what they do. Apps and services also already widely deploy bypasses for this naive domain-based filtering even for domains dedicated to tracking. /e/ would have you believe that a DNS blocklist is a game changing approach. There are better implementations including RethinkDNS available for use elsewhere.
More information:
community.e.foundation/t/voi…
codeberg.org/divested-mobile…
eylenburg.github.io/android_…
discuss.grapheneos.org/d/241…
/e/ and their for-profit company Murena have repeatedly pushed anti-privacy talking points from authoritarians claiming devices with strong privacy and security are for criminals and pedophiles. Here are 2 examples where Gaël Duval says that himself about privacy/security hardened devices in general:
nitter.net/GrapheneOS/status/2040…
clubic.com/actualite-604786-…
/e/ and Murena many of the same anti-privacy talking points as France's current government and national law enforcement. They've aligned themselves with authoritarians in the country where they're based instead of opposing it. There are dozens of examples where they falsely claim GrapheneOS are mainly useful to criminals and mainly used by criminals. That's more extreme than the claims by France's national law enforcement cracking down on secure devices. They've gone so far to align themselves with anti-privacy authoritarians that they're ahead of them.
Murena is a for-profit company with the founders and owners of it being the same people who run /e/. /e/ includes for-profit paid Murena services and is built for Murena to sell devices with it. Despite being made for profit, /e/ receives millions of euros in government funding from governments which have spent years cracking down on legitimate privacy products:
> The European Union has subsidized us to the tune of several million for this project.
projets-libres.org/en/podcas…
#lel
NoGoolag
Video
Gaël Duval is the founder and president of the /e/ foundation along with the CEO of #Murena. #Duval and his organizations have consistently taken a stance against protecting users from exploits. In this video, he once again claims protecting against exploits is for only useful pedophiles and spies.
https://nitter.net/GrapheneOS/status/2040887784253141142
Translation to English:
> There's the attack surface, on that front we're not security specialists here, so I couldn't answer you precisely, but from the discussions I've had, it seems that everything we do reduces attack surface. However, we don't have a "hardened security" approach, we aren't developing a phone for pedo(censored) so they can evade justice. So there aren't difficult things to check if the memory is corrupted, really hardened security stuff that could clearly be useful for executives, in the secret service, or whatever. That's not our goal, our goal is to start from an observation: today our personal data is constantly being plundered and that wouldn't be legal in real life with the mail or the telephone, we want to change that. So we are making you a product that changes that by default for anyone.
Transcription in French:
> Il y a la surface d'attaque, là pour le coup on est pas des spécialistes de la sécurité, donc je ne pourrais pas te répondre avec précision, mais des discussions que j'ai eu, il semblerait que tout ce qu'on fait, ça réduit la surface d'attaque. Donc oui, probablement ça aide. Par contre, on a pas une approche "sécurité durcie", on développe pas un téléphone pour les pédo(bip) pour qu'ils puissent échapper à la justice. Donc il y a pas des trucs pas possibles pour voir si la mémoire est pas corrompue, des trucs de sécu vraiment durcis qui pourraient être utiles clairement pour des dirigeants, dans les services secrets ou que sais-je. C'est pas notre but, notre but c'est de partir d'un constat, aujourd'hui nos données personnelles sont pillées en permanence et ça serait pas légal dans la vraie vie avec le courrier ou le téléphone, on veut changer ça. Donc on vous fait un produit qui change ça par défaut pour n'importe quelle personne.
/e/ and Murena repeatedly claim privacy/security hardened devices are mainly for criminals and pedophiles. They've also been falsely claiming GrapheneOS is mainly used by criminals for years alongside misleading people about what it provides. That's why we began providing our perspective in response. Fairphone gave a weasel worded media statement supporting Murena in this and other involvement.
https://nitter.net/GrapheneOS/status/2040887784253141142
https://www.clubic.com/actualite-604786-murena-e-os-interview.html
https://nitter.net/GrapheneOS/status/2
#lel
https://nitter.net/GrapheneOS/status/2040887784253141142
Translation to English:
> There's the attack surface, on that front we're not security specialists here, so I couldn't answer you precisely, but from the discussions I've had, it seems that everything we do reduces attack surface. However, we don't have a "hardened security" approach, we aren't developing a phone for pedo(censored) so they can evade justice. So there aren't difficult things to check if the memory is corrupted, really hardened security stuff that could clearly be useful for executives, in the secret service, or whatever. That's not our goal, our goal is to start from an observation: today our personal data is constantly being plundered and that wouldn't be legal in real life with the mail or the telephone, we want to change that. So we are making you a product that changes that by default for anyone.
Transcription in French:
> Il y a la surface d'attaque, là pour le coup on est pas des spécialistes de la sécurité, donc je ne pourrais pas te répondre avec précision, mais des discussions que j'ai eu, il semblerait que tout ce qu'on fait, ça réduit la surface d'attaque. Donc oui, probablement ça aide. Par contre, on a pas une approche "sécurité durcie", on développe pas un téléphone pour les pédo(bip) pour qu'ils puissent échapper à la justice. Donc il y a pas des trucs pas possibles pour voir si la mémoire est pas corrompue, des trucs de sécu vraiment durcis qui pourraient être utiles clairement pour des dirigeants, dans les services secrets ou que sais-je. C'est pas notre but, notre but c'est de partir d'un constat, aujourd'hui nos données personnelles sont pillées en permanence et ça serait pas légal dans la vraie vie avec le courrier ou le téléphone, on veut changer ça. Donc on vous fait un produit qui change ça par défaut pour n'importe quelle personne.
/e/ and Murena repeatedly claim privacy/security hardened devices are mainly for criminals and pedophiles. They've also been falsely claiming GrapheneOS is mainly used by criminals for years alongside misleading people about what it provides. That's why we began providing our perspective in response. Fairphone gave a weasel worded media statement supporting Murena in this and other involvement.
https://nitter.net/GrapheneOS/status/2040887784253141142
https://www.clubic.com/actualite-604786-murena-e-os-interview.html
https://nitter.net/GrapheneOS/status/2
#lel
Nitter
GrapheneOS (@GrapheneOS)
Gaël Duval is the founder and president of the /e/ foundation along with the CEO of Murena. Duval and his organizations have consistently taken a stance against protecting users from exploits. In this video, he once again claims protecting against exploits…