New podcast episode: Put some privacy in your smartphone! 📣 🎧

How can you use an Android smartphone while protecting your privacy? Who should you turn to for more privacy-friendly Android alternatives?
Can you install Linux on your phone?

With @fla from @Framasoft , we answer these questions!

👉 https://www.projets-libres.org/en/podcast/smartphone-put-privacy-in-your-smartphone/

#podcast #opensource #privacy #eos #iodeOS #calyxos #postmarketos #fairphone #commown #murena #ubuntutouch #grapheneos

@projetslibres_podcast @Framasoft The claims made about GrapheneOS in this interview are extremely inaccurate. It heavily misrepresents the purpose of GrapheneOS and what we've worked on for years. The claim GrapheneOS is a security project rather than a privacy project is misinformation. Contacts are specifically brought up and yet our Contact Scopes feature is ignored. @fla knows GrapheneOS is a privacy project. He replied to a thread with our response to this misinformation only 4 days ago...
@projetslibres_podcast @Framasoft @fla /e/ doesn't keep up with providing standard Android privacy patches and protections. It doesn't provide features comparable to the added privacy protections in GrapheneOS including but not at all limited to Storage Scopes, Contact Scopes, Sensors toggle, per-connection Wi-Fi MAC/DHCP privacy and far more. /e/ has a bunch of default connections to Google services and gives highly privileged access to those. It also bundles other invasive services in the OS.

@projetslibres_podcast @Framasoft @fla GrapheneOS heavily improves privacy compared to the Android Open Source Project in contrast with /e/ heavily reducing it.

GrapheneOS is far ahead of the standard pace for privacy patches instead of behind and we fix many privacy weaknesses ourselves. We've fixed a bunch of Android VPN leaks and many forms of data leaks to apps.

Since GrapheneOS is a serious privacy project, we have to put substantial work into security too because privacy depends on it.

@projetslibres_podcast @Framasoft @fla /e/ tries to provide privacy by bundling a small blocklist of domain names solely used for ads and analytics. This doesn't do anything to address the most privacy invasive behavior by apps which happens via their own services. It doesn't stop apps sending data to arbitrary third parties from their servers or even client side. It can't block anything without the app using a dedicated domain for the unwanted behavior which usually isn't how things are done.

@projetslibres_podcast @Framasoft @fla The domains they block are a tiny subset of domains used for those purposes and do not stop the most privacy invasive behavior by apps.

Apps and SDKs have also increasingly bypassed DNS blocklists via DNS-over-HTTPS resolvers, hard-wired IP addresses and most of all moving connecting to third party APIs to their servers where they don't need to leak their API keys.

DNS filtering works fine on GrapheneOS but isn't a viable approach to protecting privacy.

@projetslibres_podcast @Framasoft @fla Exodus Privacy uses a very similar approach to label apps as having trackers based on whether they include a library from a small list they've decided as trackers. Many of those decisions are dubious and it misses that the most privacy invasive behavior by apps isn't done that way. It also has extremely inaccurate labelling of permissions misleading users about how that works. Here's a great example of both with Facebook Lite:

https://reports.exodus-privacy.eu.org/en/reports/com.facebook.lite/latest/

Report for com.facebook.lite 505.0.0.8.102

Known trackers, permissions and informations about this specific version of this application

εxodus
@projetslibres_podcast @Framasoft @fla According to Exodus Privacy, there's no tracking being done by Facebook Lite. This is the information about trackers which is provided to users within /e/ when they use their Play Store frontend. They're telling users one of Facebook's main apps isn't tracking them. They're also certainly not stopping the tracking via their DNS blocklist. The list of permissions shown there and by /e/ is also extremely inaccurate and misleading. It doesn't work that way.

@projetslibres_podcast @Framasoft @fla /e/, Murena and their supporters have spent years misleading people about GrapheneOS. They heavily push the false claims that it isn't a privacy project, isn't usable, isn't broadly compatible with apps and isn't useful to regular people. /e/ and Murena have repeatedly claimed GrapheneOS is only useful to criminals and spies. Here's the leader of both /e/ and Murena stating that as a broader claim about hardening in general:

https://grapheneos.social/@GrapheneOS/116353973732143171

@GrapheneOS @projetslibres_podcast @Framasoft @fla I think it's consequent to only have a small block list because if they would have a bigger one which blocks more invasive trackers, and more security they couldn't claim that your system is only for pedophiles.
My 10 cent
The interviews from the CEO of /e/os basically state that they can't take security and privacy serious. Else they would contradict themselves and that makes the entire system a half-hearted approach.
@GrapheneOS @projetslibres_podcast @Framasoft @fla I'm using /e OS on my Fairphone 4. I want to switch to Graphene, but I don't know how, and I'm scared of losing all my stuff.

@FelixTheAnimator @GrapheneOS @projetslibres_podcast @Framasoft

You need to backup your data first and then put them back in the phone after the installation. If you're not too technical, I'm sure there can be someone in your area to help you.

@FelixTheAnimator @GrapheneOS @projetslibres_podcast @Framasoft @fla I dont think you can install GrapheneOS on a Fairphone, only Pixel devices are officially supported:
https://grapheneos.org/faq#supported-devices
I suggest buying a used Pixel, installing GrapheneOS on it, playing around, then migrating your stuff over when you are comfortable. Nice and slow - nothing to be scared of. Graphene is very easy to install if you follow the official instructions.
GrapheneOS Frequently Asked Questions

Answers to frequently asked questions about GrapheneOS.

GrapheneOS
@FelixTheAnimator @[email protected] @projetslibres_podcast @Framasoft @fla you cannot, GrapheneOS founder hates Fairphone because they provide phones with /e/OS and because they are European.
@lajuste Well damn. I have one & I'm in the States. You sure there's no way to fix it?
@FelixTheAnimator it's not about fixing, it's about a project decision so just stay with /e/OS it work and it is olan to be supported with Android security updates for a lot of years, probably more longer than the official support
@GrapheneOS
Second time I try to follow this account, and second time I get a week of bashing against competitors instead of promoting your vision and merits. You even boost those posts. Infinite noise/signal. How unfortunate.
Will try again in a couple years.

@ideaferace @GrapheneOS Correcting false claims about the project is not bashing competitors, especially since projects like /e/OS, iodéOS, and CalyxOS which the GrapheneOS project account sometimes mentions aren't competitors to GrapheneOS, these projects are not what they claim to be.

As for the “brouhaha,” well, unfortunately that’s sometimes the effect of social media, but many people don’t visit the official website.

Some good source that might interest you :

https://www.kuketz-blog.de/grapheneos-der-goldstandard-unter-den-android-roms-custom-roms-teil7/

https://www.synacktiv.com/en/publications/exploring-grapheneos-secure-allocator-hardened-malloc

https://www.sciencedirect.com/science/article/pii/S2666281726000053?via%3Dihub

An underestimated aspect of GrapheneOS : It provides a solid base for reducing addiction on social media and useless stuff.

GrapheneOS: Der Goldstandard unter den Android-ROMs – Custom-ROMs Teil7

Keine Frage: GrapheneOS ist derzeit das sicherste und datenschutzfreundlichste Custom-ROM bzw. Android-System.

@Xtreix yeah, it's a common problem with social activity. I'm not here to spectate fights, not to check their website craving every update.
Tant pis.

@GrapheneOS @projetslibres_podcast @Framasoft @fla Very glad that you are fighting misinformation on this matter! So unacceptable for a podcast trying to give you good publicity to call GrapheneOS a "security project".

Unbelievable! We can't let this go on any further, they need to be shamed for years to come for the spread of this blatant misinformation with the scope of attacking and harassing GrahepeneOS!

#JusticeForGrapheneOS

@GrapheneOS And you really think that a thread on a niche microblogging platform helps promoting your product and vision? Don't you have a homepage to put your beef on which you could link instead of filling the timeline of your followers?

I'm interested in GrapheneOS, not whatever beef you have with others.

@GrapheneOS

It's hard enough for every alternative OS to find people to use it. It's even harder when those alternatives are fighting against each other. Also I don't care who started it and who's right. This is not a childrens sandbox and you are not five years old. Get your shit together, make a statement on your website, post that statement and move on.

@truhe We're providing accurate information about GrapheneOS and how it compares to another operating system. The reason we're doing that is because they've spent years misleading people about GrapheneOS and are continuing to do it. If they stop misleading people about GrapheneOS including in these kinds of interviews, then we won't need to post responses addressing it. GrapheneOS has been massively harmed by concerted efforts to mislead people about the purpose, features and approach we have.
@truhe /e/ and Murena have done a huge amount of harm to us by widely propagating their false claims about GrapheneOS privacy, usability and app compatibility. They've misled many people into believing it isn't a privacy project, isn't usable, isn't compatible with most apps and much more. GrapheneOS is a privacy project providing a much higher level of privacy than they do along with great usability and far broader app compatibility. We're addressing it because it has greatly harmed us.
@truhe The thread we posted is certainly about GrapheneOS. It provides very useful information about why we approach things in the way we do with features like Contact Scopes rather than DNS filtering. We post these threads to directly address content misleading people about GrapheneOS. A group attacking us is being provided with a platform to make inaccurate claims about GrapheneOS without it being challenged and without us having an opportunity to directly respond, so we're responding here.

@truhe GrapheneOS exists to protect the privacy of our users. That includes protecting people from sophisticated attacks on their privacy by corporations and states. GrapheneOS doesn't exist to simply provide an alternative to mainstream options. We aren't inherently on the side of other projects providing alternatives.

The anti-privacy talking points from Gaël Duval in the video at https://grapheneos.social/@GrapheneOS/116353973732143171 aren't an isolated incident but rather /e/ and Murena have been saying it for years.

@truhe /e/ and Murena have repeatedly claimed GrapheneOS is only useful to criminals and spies. During the recent state-sponsored smearing of the GrapheneOS project in the French media, Gaël Duval assisted with pushing their false narrative that GrapheneOS is only useful to criminals. These groups aren't on the same side as us. Their primary goal is earning as much money as they can with privacy as a way to brand and market devices. They're undermining the privacy movement and aren't allies.

@GrapheneOS You now wrote five mentions to me explaining the beef you have and repeating the arguments, after I said, that using threads on a niche microblogging platform is not the best way, and neither is talking about everything the others do wrong (to you).

I followed your account to get news on Graphene OS and what I'm getting is some war between forum trolls. I get your point, I get why your doing it, but seeing this from an outside perspective where I'm just interested in getting news

@GrapheneOS about my next smartphone OS, this feels out of place and not helpful.
@truhe is it posssible that you are confusing a rss feed of news from a website with a social media platform where people talk to each other? @GrapheneOS
@truhe If we hadn't posted about it, you wouldn't be aware of /e/ and Murena holding the views they do on people wanting to protect themselves from privacy and security vulnerabilities. There are clearly benefits to us spreading the word about it. Many people have misled into believing GrapheneOS is not a privacy project by these groups and we're addressing it directly. We can also post more content about our privacy features, and we are mentioning those as part of these posts too.

@GrapheneOS
I think the point was not to post thr information, but rather where/how.
It was suggested to post the full explanation on the website/blog and link it with a short introduction on the fediverse.

A suggestion which i also agree with.
@truhe

@truhe @GrapheneOS

Maximizing users at all costs is not the goal. These OSs are not alternatives to GOS and do not compare in the slightest. Why is it you turn a blind eye to scams committing crimes against GOS, and thats not called fighting, but GOS defending themselves is?

"Also I don't care who started it and who's right."
I mean, do I even need to comment on this? Seems pretty clear how disgusting this is to say.

This is not a childrens sandbox, and you are in no position to talk down to them like some parental figure. This is real, and your apathy to their adversity is disappointing.

@HybridStaticAnimate A better comparison would be a marketing channel fighting with another marketing channel while people expected other content on that channel. The cause is valid, but are constant posts here the best way to react? It feels like watching two youtube channels fighting with each other. Where are the articles on the homepage correcting everything, which could stay online and be linked from here?

@truhe

Its not a better comparison, the official GrapheneOS accounts are not marketing and are not intended for marketing. Defending wont stop until the attacks stop. And yet I notice a distinct lack of criticism aimed at the agressors.

Mastodon has a tiny character limit so GOS has to break up the posts. Its easier to cram nonsense into one post than it is to properly refute it. The website isnt for this purpose.

@HybridStaticAnimate The "lack of criticism" aimed at the aggressors in my case results in not buying or using their products. I don't need every detail to come to this conclusion, just the information, that they say secure devices are only for pedos, criminals and spies. This is the talking of german right wing parties like CDU and AfD, which I won't tolerate.

@truhe @GrapheneOS

Why do you automatically assume the goal is promotion? GrapheneOS is not a business and doesnt provide a product. Youre trying to downplay serious issues with implicitly juvenile descriptors to make it seem frivolous, but its not. Last I checked, providing accurate information for others to educate themselves was a good thing.

@HybridStaticAnimate Last time I checked they announced a long term partnership with Motorola preloading Graphene OS starting 2027. So it's also about promotion. And I'm not against correcting false claims, but ALL I'm seeing here is a beef I'm absolutely not interested in and never is a microblogging platform a good way to correct those things in many threads over many days. They have a homepage, which they don't use. They don't even mention Motorola on their page.

@truhe

This is not accurate. They announced a partnership with Motorola but they did not announce devices with GrapheneOS preinstalled, whether or not they can do that still needs to be determined. And if they cant, thats fine, that was never a requirement of the partnership.

Money isnt exchanging hands. GrapheneOS does not currently profit from this. Youre falsely tying this to promotion. Its just an announcement on future plans.

And GrapheneOS doesnt yet support Motorola devices so there is little reason to put it on any page.

This isnt beef, and your interest in the situation is irrelevant. Countering misinformation at the source is an effective method and has been better than other methods for a very long time. People are going to blindly believe the first thing they read or hear if its not countered, and they arent going to go to an unrelated page that they have no idea exists.

@truhe @HybridStaticAnimate No, that's an outrageously false claim. We've been debunking misleading claims by Murena and /e/ on GrapheneOS for several years and they've been engaging in it far longer than that. Unlike Murena, GrapheneOS isn't a for-profit business with the goal of promoting products to make as much money as possible. A major part of our goals is informing people about privacy, security and GrapheneOS which we're doing with these threads addressing inaccurate info about it.
@GrapheneOS I understand that. I will unfollow you then, because I wanted to get news on Graphene OS, not corrections of stuff Murena said and wish you and your project the best. I'm eagerly waiting for next year for non-Google phones arriving for GOS to switch to it 💜.

@GrapheneOS @projetslibres_podcast @Framasoft

Thank you for pointing contact scopes, I was not aware of this feature. We have edited the transcription to reflect this. Thanks for your work on Graphene, and have a nice day.

@fla @projetslibres_podcast @Framasoft Contact Scopes is one of the core features of GrapheneOS and is shown in any prompt for contacts access. Storage Scopes is a similar feature for the media and storage permissions. Similar features for Camera, Microphone and Location are being developed by us. Android has a standard Mock Location feature but we want to replace that with a per-app Location Scopes implementation.

The podcast and article still wrongly claim GrapheneOS isn't a privacy project.

@fla @projetslibres_podcast @Framasoft How is GrapheneOS not a privacy project when it adds much stronger privacy protections, keeps up far better with standard privacy patches/protections and puts far more care into the services being private?

There's a third party comparison between AOSP-based operating systems at https://eylenburg.github.io/android_comparison.htm which has sections on both privacy and the default Google services included in the Android Open Source Project and additional ones which are being added.

Comparison of Android-based Operating Systems

Comparison of Android-based Operating Systems

@fla @projetslibres_podcast @Framasoft

> However, there is not a lot that is being done about privacy.

How does this hold up against an actual comparison of what's offered? GrapheneOS closely keeps up with current privacy patches and protections, while the other 3 operating systems lag far behind.

GrapheneOS provides Contact Scopes, Storage Scopes and other major enhancements to privacy while the others don't do much beyond increasingly ineffective DNS filtering that's easy to bypass.

@projetslibres_podcast @fla @Framasoft Every product mentioned here but GrapheneOS is highly insecure, Postmarket and Ubuntu Touch are based on GNU/Linux, which lacks of many modern hardens, such as memory safety, application sandbox and verified boot.

Btw Android is a Linux distro.

CalyxOS, /e/OS and iodeOS are outdated in security patches and major AOSP releases. They also contain non-free privileged Google binaries.

https://privsec.dev/posts/linux/linux-insecurities/

https://xcancel.com/search?f=tweets&q=from%3AGrapheneOS+Linux

Linux Insecurities

There is a common misconception among privacy communities that Linux is one of the more secure operating systems, either because it is open-source or because it is widely used in the cloud. However, this is a far cry from reality. There is already a very in-depth technical blog explaining the various security weaknesses of Linux by Madaidan, Whonix’s Security Researcher. This page will attempt to address some of the questions commonly raised in reaction to his blog post.

@a53bdb @projetslibres_podcast @fla @Framasoft this is fake information you are trying to push, Calyx I will not answer as the project is on old, but for the others they provide all of the updates if the Android and Chromium security chanel and maintain up to date the apps as long as security is concerned. GrapheneOS FUD will not change how popular the others projects are and GrapheneOS just cannot compete as they only work on Pixel phones, and only as long as Google is helping.
@a53bdb @projetslibres_podcast @fla @Framasoft on the other side you have /e/OS and IodéOS who can work on old pixel and on non Google hardware, they should just stopping attacking and FUD others projects if they what to be integrated in the others communities.
Same advice for you.

@lajuste @projetslibres_podcast @fla @Framasoft Google is not helping GrapheneOS all time. Please stop confusing attacks and pointing out the facts. /e/OS and iodeOS can’t ship major releases and security patches. They are also less security than LineageOS. If you think GrapheneOS is wrong, give your own proofs.

https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private

Devices lacking standard privacy/security patches and protections aren't private - GrapheneOS Discussion Forum

GrapheneOS discussion forum

GrapheneOS Discussion Forum
@a53bdb @projetslibres_podcast @fla @Framasoft GrapheneOS only supports the devices as long as Google supports it as they just copy paste Google updates and don't do it herself, it's explains why they are completely dependent on the help of Google to provide security to GrapheneOS and why they stop providing updates if the device is too old and is abandoned by Google.
@lajuste @projetslibres_podcast @fla @Framasoft What are you talking about? Security patches, firmwares and drivers are always from stock OS or OEM. Every alternative OS is the same.
@lajuste @projetslibres_podcast @fla @Framasoft If /e/OS and iodeOS want to join real privacy community, they should make something useful and stop attacking GrapheneOS. Same advice for you.

@a53bdb @projetslibres_podcast @fla @Framasoft look at how many time they talk about GrapheneOS and attack it, and now do the same and count how many time GrapheneOS account (who hides Daniel Micay) is mentioning others projects to attack them.

/e/OS, iodéOS, CalyxOS, LineageOS, PostmarketOS, UBtouch, microG and many other projects don't give a fuck about Graphene, but sometimes they have to answer critics and Micay answer again with a 10 post attack.

@a53bdb @projetslibres_podcast @fla @Framasoft it make people talk about Graphene yes, but also the others ROM and as any critics of Graphene leads you to harassment, no debate is possible, it burn the public image of #GrapheneOS for most of the people ban by Micay.
@lajuste @projetslibres_podcast @fla @Framasoft Why is it that when others spread lies about privacy and security, GrapheneOS is not allowed to debunk? When GrapheneOS criticizes others with evidence, it is called attacking?