Android Recommendations Should Reflect Real Life, Not Just Worst-Case Threat Models

Even these deveces wouldn’t meet that absurd criteria. Phones in this context are a disposable items provided by the employer.

Actually depending on what happens these devices can survive that.
I was live there while they presented and demonstrated their devices on a congress.

For neo banks like revolut, this is not gonna cut it

Besides some functionality tends to be locked in the app, for example in Bank of Cyprus they didn’t have quickpay it was app exclusive, then later was it added into the web app

There’s also the fact that you need the app to have secure transaction verification, without the app the same bank I use for example again, uses SMS OTP to verify your payment which we all know SMS OTP is insecure, sure bank of Cyprus has thought of this and added a second step verification by asking your password (which is unfortunately just a 6 digit pin, what a nightmare for security, besides the point) but the point stands, and it’s an extra step over having the app that with 2 clicks you can get a transaction verified over multiple clicks and insecure sms

If your phone is worn on a lanyard then it shouldn’t be run over by a crane. If it still happens the phone will be the least of your worries :rofl:

This thread was supposed to be about everyday situations, not worst case scenarios BTW.

2 Likes

ok, we should recommend stock android so that every single feature of every single bank app works. (sarcasm)

at the end of the day people need to decide for themselves if it’s worth it to care about their privacy and take steps towards it. some technology cannot be used in a privacy respecting way.

i truly feel that for people who don’t want to make any changes or sacrifices, they should just switch from gsuite to proton, get an iphone, run it in lockdown mode, and call it a day.

we can’t hand hold every single person through their unique use case of some technology they still want to use even though it doesn’t respect privacy. these are individual choices.

2 Likes

I think you misunderstood

saying “Just use the web app” is not viable when there’s a lot of variable or nuances when it comes to that statement

Even if let’s say you do decide to use Bank of Cyprus’s web app, Revolut’s web app is not even considered a usable web app, You can barely do anything with it not even the basic things, therefore requiring the app to do even basic things

If it was as simple as “Use the web app”, we wouldn’t even be reporting on app compatibility with banking.

I’ll use myself and example

I appreciate the convenience of Google Pay but purely because it doesn’t work on GOS, I just use the traditional method of tap to pay, Because I would much rather keep GOS than sacrifice it, when Revolut and my bank works just fine in GOS, There I may be sacrificing a little but at least I did not give up GOS.

In conclusion: Nuances/Variables matter

Besides good luck telling your average joe to “just use the web app”, I think most or some would spite you for saying that and go “No, I’ll just use the app, it’s fine thanks” or something like that

I don’t think anyone really grasps the idea of using the web app of their banking (in average joe context if this gets lost). Not mentioning the other things I’ve already mentioned

we can’t hand hold every single person through their unique use case of some technology they still want to use even though it doesn’t respect privacy. these are individual choices.

Okay, then let’s remove this forum and use just the KB.>
Because if we do not individualize then the KB is enough and a Forum is too much.
Again, my point was not about not recommend GOS or generally say you should use Samsung, my point was about how absolutistic this forum is.

If you have a contactless payment card why does GOS compatibility matter? I only use cash but introducing an intermediary service, such as Google Pay, feels counterintuitive.

It’s fine to debate, but people are talking about things without offering technical evidence that more private OSes can be installed (other than GOS) than the OS that comes with the phone.

By uninstalling Google Play Services you don’t automatically achieve privacy. When you provide technical evidence, perhaps the PG team will take these proposals seriously.

1 Like

these are not serious privacy proposals. they are proposals from people who want to think you can uninstall half of the google spyware and then ask google nicely to not harvest and sell 100% of all data that goes through the phone. it doesn’t work like that. if people don’t want to use gos, they should use apple and be done with it.

At this point, i feel like you just want to tone policing the forum.

And you are wrong as well

On this thread, user clearly state that user dont want Pixel and iPhone. You don’t see people replying with “Don’t want Pixel or iPhone? Screw you then!”.

Well, nicotiu and Nathan inform the user about the risk of using Samsung. But with good reason!

I’m still unsure what change that brinerustle and Onscreen5341 hoping.

Add alternative hardware vendor in PG official recommendations?
Can’t do that because that will just give user false sense of privacy.

Make forum member to stop shilling pixel and iPhone?
There no other alternatives that worth to recommend.

Add hardening guide for every hardware vendor?
Who is going to write that tho, there too many brand selling mobile phone and each have their own settings to turn off.

I think we already have enough guide in official website.

I will use myself as example:

I read PG website,
Teaching me more about privacy and security
PG recommend Pixel, VPN, etc

I look at my own wallet “dang im broke. And Pixel isbanned in here. Aint no way i pay for pixel and VPN”

It is what it is, i guess

So I bought Chinese brand. Knowing its privacy risk, thanks to PG
And i implemented what i can (filtering DNS, using Brave, etc) based on my own individual limitations and preferences.

6 Likes

Welp, it’s kinda off topic but i admit I made a mistake.

I’m stupid!

I unlocked my current phone bootloader and install other distro by random maintainer with permissive SELinux for privacy. Without reading more deeply about the security risk…

Previously i also think nothing wrong with custom rom. Like “its more private!”, “I’m not important enough to be hacked!”.

Wrong.

If we use analogy: security is the bucket and privacy is the water. If you punch holes in the bucket, the water leaks out. It doesn’t matter how ‘private’ the water was.

For false sense of privacy, I end up:

  • Shifting my trust from a trillion-dollar corporation (who wants my data for ads) to a stranger (who might be incompetent or malicious)
  • Risking targeted by a 14-year-old with ChatGPT running a automated script and bots that infects thousands of phones to steal credit card numbers, crypto wallets, or just to use my phone as part of a botnet.
  • If thief got my phone, they can flash a modified recovery image. They can bypass my lock screen, dump my memory, or install a keylogger to catch my bank PIN.
  • When my phone actually got malware, SELinux be like “Oh, that’s against the rules. I’ll make a note of it in the log file.” …Lets it happen anyway.

So like other people already said: You cannot have privacy without security. If your OS has holes, ‘Privacy’ is just a sticker you put on the phone to make yourself feel better while the data leaks out the back.

Recommending okay-ish hardware and software may mislead inexperienced users, overwhelm them with choices, and create a false sense of privacy instead of actually helping them.

4 Likes

My argument was never about Samsung. You are bringing this up and I don’t want discuss it further.

My original comment got silently deleted and the Mods are ignoring me. For me that’s enough to end the discussion.

I never say what is your argument is.

I linked that Samsung thread in response of your absolutistic claim.

To showcase:

  1. “absolutistic” claim is inaccurate.
  2. Other forum members can indeed give alternatives when the OP clearly specified that OP don’t want iPhone and Pixel.
  3. From nicotiu and Nathan respond, we can see there is clear reason why something is not in PG official recommendations.

Absolutism implies ignoring evidence or nuance but forum member’s stance is aligned with risk assessment and technical standards, not ideological inflexibility.

From a security & privacy standpoint, restricting recommendations to safe options is responsible, not absolutist.

1 Like

Tell that to the guy deciding between Fairphone and Pixel while also stating that they had a very low threat model, we still inisisted on a Pixel despite the correct answer being “It depends on what you value the most”

That is the definition of absolutism right here

Source

1 Like

The only reason they were considering a Fairphone was to remove the battery to ensure it is really off. Pixel with GOS in a Faraday bag is the solution, as suggested in the first comment.

If Fairphone supported GOS I would never buy a Pixel again. Their ‘threat model’ was significant to remove the battery and brick the device on a regular basis btw. There was never a choice.

3 Likes

I agree with this. There should be general recommendations for people who can’t (or don’t want to) get a Pixel phone (or even iPhone). I think the general recommendation for now is to just stick with the phone and the OS you have.

I think the consensus was that repairability is not worth the security and privacy trade-off that Pixel + GrapheneOS offers. They had a choice between either phones. But I’m sure most of us said Fairphone is a decent option. IF Google Pixel isn’t available (or too expensive) in your region, but you can get a Fairphone, that wouldn’t be a bad choice.

3 Likes

One thing I’ve realized while reading through these discussions is that it’s all so speculative. Yes there’s talk about threat models and some past incidents of non-GOS custom roms or phone firmware not being up to date, but no-one is explaining what the concrete threats of using non-GOS roms or phones like a Fairphone are. The closest thing I’ve seen here is the mention that an unlocked bootloader allows installed apps to modify the system. Please correct me if I missed something.

I once saw someone say that using banking apps on a non-GOS custom rom is like walking around with an open wallet, and this is the kind of baseless FUD that bugs me. If the rom is receiving the monthly android security patches, there’s no way it’s that bad (obviously you have to trust that there’s nothing fishy happening with the rom itself).

Like if we were dealing with houses here, I’d get the sense that an underground bunker is the only option because it’s objectively the best one for privacy and security, while all the other options are like living in a house made of glass, with a blinking neon light that says “Please come and rob me”.

I’m not that technical myself, so when you make claims about other than Pixel+GOS, I’d appreciate concrete explanations (or links) for what the concrete threats are and why Pixel+GOS are better.

4 Likes

Google.

If you’re here, you know why.

1 Like

honestly for my goals for me it is not as simple as “De-google” at this point, in fact i did kind of break that ethos to be able to use my smartwatch and Message RCS E2EE in which RCS E2EE is well worth the sacrifice for better security and privacy on something that basically you can use with any android user.

As GrapheneOS themselves said, they’re not about avoiding google, if you choose to avoid google and it doesnt sacrifice your own convenience or something like that, that’s fine (besides my secondary profile has always been about apps like banking and things I wanna avoid looking that im forced to stay like viber and does have play services, my main is a no account play services setup purely for those 2 usages (smartwatch and RCS E2EE android-to-android). But it is about being able to use them in a more private and secure sense (exhibit a: sandboxed instead of privileged google play services/store/framework exhibit B: contact scopes allowing to bypass whatsapp’s required contact permission without giving up any of it, exhibit C: whenever IPC Scopes comes out, Exhibit D: Seperated users for apps you dont trust on your main or are forced to use or isolation. Shall I go on?)

1 Like

I think that just called biased :stuck_out_tongue:

  • OP in torn between repairability vs privacy
  • Ask questions in forum that focused on privacy and security.
  • Forum member recommends maximum privacy choice.

Obviously X forum will have X bias and Y forum have Y bias, that is normal.

“It depends on what you value the most” for me is equivalent of “figure it out yourself”. Especially in context of question like that.

Like bro, I’m asking because I’m in dilemma! I won’t asking any questions if I can figure it out myself! XD

Lastly, who is this “we”? At the end of the thread is literally PG staff saying pick whatever you want but be mindful.

4 Likes