Android vs. iOS re: my threat model

Hi friends,

After some deliberation I’ve opted against GrapheneOS. The inability to bank, and the seemingly precarious access to the Twitter and Instagram apps make it a no-go for me. I frequently have to access my bank account on the go, and need to use social media apps to engage with my region’s politics.

If I’ve misunderstood GrapheneOS here, please correct me.

My threat model pertains to people connecting my alias (on social media platforms where I engage politically) to my actual identity. Namely, I do not want my employer knowing, and if they were to find out, I want plausible deniability. Lastly, I’m not thrilled about corporations accessing my data, but am willing to make this sacrifice if it means I can engage politically.

So what is more secure? iOS with Nord VPN, using the Instagram, Twitter, and Bluesky apps, or Android (Samsung - maybe a Pixel), using Nord VPN, brave browser (with settings optimized for privacy)? On both OS I will have location services turned off, and opt out of as much data collection as possible.

Right now I’m leaning iOS, but I really prefer android, and really like the galaxy ultra series.

1 Like

I use GrapheneOS and my bank apps work fine. I would double check I’d your bank apps are supported on GOS before writing it off.

Social media should probably work as well if you install the (sandboxed) Google Play services. I would search around the GOS before a bit more on this.

Luckily this has less to do with the OS and more about good alias management. GOS may not offer as much benefit here.

Don’t do that. Read the PG recommended VPNs and take it from there.

Personally, my OS tier for phones is:

GrapheneOS > iOS > Android

2 Likes

GrapheneOS would be good for separating identities because of the profiles feature. I don’t see a way to robustly achieve your goals on iOS.

Profiles are ideal because you can change your behavior based on the profile and they include customizable colors which you can mentally model to easily know what kind of activity is being done in that profile.

The profiles have separate VPN slots which there’s no equivalent feature for on iOS and I’m not sure there’s any way you could separate IPs on iOS besides using browser methods like Onion Browser.

On iOS, apps can see each other which could cause a problem and they have permanent identifiers.

On GrapheneOS, you can use profiles or private spaces (apparently they are the same thing under the hood) to prevent inter-profile-communication and apps listing other apps.

The inability to bank

Have you checked your banking apps specifically? Over 90% work.

I heard that a main Twitter dev said they would roll out a fix for this and there’s an app overhaul announced so that could contain the fix.

I’ve also found PWAs are much better on GrapheneOS than on iOS. PWAs would be better for you anyway. There’s no problems with PWAs with Twitter or Instagram and you wouldn’t have to install Google Play Services or worry about compatibility. It seems Instagram works fine, though.

1 Like

I don’t know much about this, except for one thing: Android is pretty good for plausible deniability if someone gets physical access to your device. Having app clones, hidden apps, and a system cloner makes life a lot easier when you need a secure setup without micromanaging specific apps and notifications. They’re still detectable if someone digs, but you won’t accidentally expose them.

It’s great not having to worry about who might see your screen—whether that’s coworkers, partners, or airport security in a country with strict policies.

Other than that, I agree with @overdrawn98901

IMO, since you’re looking to use social media *apps*, I’d personally recommend iOS with the social medias in different Safari profiles instead, this would grant MUCH better privacy than using the apps, and you can install uBlock Origin Lite. In my experience it feels very close too native apps in Safari, while the android browsers I’ve tried have always felt much worse.

1 Like

There’s absolutely no robust plausible deniability on GrapheneOS /Android besides the duress pin, which has the evidence problem.

1 Like

There’s absolutely no robust plausible deniability

They’re still detectable if someone digs, but you won’t accidentally expose them.

The IG app works fine, though(?)

Thanks for your engagement.

I looked up some stuff on banking, and it appears my bank works with Graphene. This being said, it’d be a huge pain if it didn’t.

My issue with apps in browser is that I wouldn’t get notifications, and I am very, very active. To lose that functionality would be a huge pain.

Re: Nord. Yes, I acknowledge that Nord is not recommended, but Proton is. I was planning on using Proton’s cheapest plan for email, cloud services, and a VPN. On that note, is there something nefarious about Nord I should know?

Re: alias management, would you please elaborate for my benefit?

And thank you for your tiered answer re: OS.

Oh yeah? Notifications and all? What about bluesky and X?

Thanks for your response :slight_smile:

Yeah! And I don’t use either of the others too so I can’t tell you for sure :sweat_smile:

1 Like

To be clear - and i may be misunderstanding you here - I’m not worried about someone getting to my phone. I just don’t want my employer to pull up a post I’ve made under an alias and have proof it’s connected to me, either by IP or device ID or whatever.

Not all VPNs have a no log policy, and if you’re gonna choose a VPN, might as well choose one that’s recommended to reduce risk of logging. Some of them also use shady residential proxies as well.

1 Like

Do canadian banks TD, Scotia, and CIBC work? Where do you find this info?

My concern about PWAs is the lack of notifications. I’m extremely active and want notifications.

One more question:

How nimbly can you switch between profiles? I rather don’t want to have to switch. To have everything right there on one desktop matters to me.

Thanks for your response!

Do notifications work?

Oh interesting. Okay, easy to switch to proton. I like their suite of services.

Very nimbly. Just pull down your notifications area, pull down again to show the settings, and the user switcher is right there. Then just tap the user you want to go to & in about 4 seconds you have your other user in front of you.

Most apps use FCM for their notifications. FCM works, but requires for the Google Play suite to be installed in the profile. So just install & set up the Google Play suite once per profile & your notifications will work just fine.

Good luck on your privacy journey. :smiling_face:

1 Like

Mind me for being a bit daft here, but I’m having trouble navigating the thread. Is this about notifications on apps, or PWAs as well? Having notifications from PWAs would be amazzzing.

+1 for Android, profiles will give you a better compartmentalization between identities. I’d also try out GrapheneOS to see if your bank app works as some of them do work fine. If not you can see if their web app is functional on mobile. Only after the mobile and web apps fail on GrapheneOS should you consider using stock Android.

Pixels are always better than Samsungs. They contain less bloat, are more secure, and give you the option to switch to and from GrapheneOS as needed.

Kinda off-topic but it’s best to switch to a recommended VPN service as soon as your NordVPN subscription runs out.