# "I have refused to carry any sort of cellular phone" -rms

**URL:** https://discuss.privacyguides.net/t/i-have-refused-to-carry-any-sort-of-cellular-phone-rms/19251
**Category:** General
**Created:** 2024-07-03T13:48:55Z
**Posts:** 75

## Post 1 by @anon99860907 — 2024-07-03T13:48:56Z

I had a brief back and forth with Richard Stallman this week (he’s one of my heroes and has cancer, I wrote him to tell him he is the man). At the bottom of an email reply he said this (we were talking about my kid):

> Soon he will be tempted to demand a snoop-phone full of nonfree software.
> 
> I have refused to carry any sort of cellular phone, because they have nonfree software that can be changed remotely.

**I think he is right** Having tried many combinations suggested here and some not (iOS, Pixel w/ Graphene and Without, Lineage etc..) I feel I’m always giving some actors the keys to my private kingdom… namely:

- **My Phone Carrier** They have all of my calls and texts, my rough location (even with location turned off)
- **Google via Google Play Services** For me, GrapheneOS is unworkable without Google Play Services (if you manage to use it without, God Bless you!)
- **Proton via ProtonMail and ProtonVPN etc…** I’m not mad about this one, I like proton, but they know a lot about me, most is encrypted though, so I’m good.
- **Bitwarden** Not worried about this one either, but worth saying

**If your threat model includes the Government (US in particular), Google or Apple, then you better not use a phone**

_ **Apple or Google, choose one** _ You can avoid giving data to Google (generally) by getting an Apple device (but you’ll probably get pwnd by Israeli Pegasus shit, who knows closed source code), and you can avoid giving data to Apple by using Google devices (probably the safer bet)… but practically can’t avoid picking between the two… GrapheneOS is as close as we can get, which is why it’s recommended, and it CAN be used in a way that leaks nothing to Google, but I doubt many of us here have successfully used it in that way. I have tried my best and it’s very very hard. My favorite tools (Proton and Signal) even require Google Play Services to run, and must be downloaded from the Play Store (or Aurora, which for me is an unnecessary extra step).

_ **If you are using a Phone, the Gov’t can probably snoop** _ (see the thread about the Jan 6 Dragnet)

I think the site does a good job discussing Threat Modeling particularly:

> If you wanted to use the **most** secure tools available, you’d have to sacrifice _a lot_ of usability. And, even then, nothing is ever fully secure.

But it seems sometimes in the forum we shit on each other if we use Stock Android or iOS. Both are not perfect… but no phones are. And in my experience most GrapheneOS setups with Google Play Services will still leaking Google in practice, not quite as much as Stock Andriod… but enough.

# My Setup:

1. Stock Android on a Pixel 6
2. Google Play Store (not Aurora, no need for a man in the middle) and Obtainium
3. RethinkDNS (USE IT!!)
4. Proton Suite
5. Cromite and Tor Browser (w/ ProtonVPN connecting via Rethink and wireguard)
6. Kagi Search w Unlimited
7. Other Apps are either Trusted (full internet access minus dns blocklist), Have no Internet Access (Simple Mobile Tools, or apps like [LM Playground](https://play.google.com/store/apps/details?id=com.druk.lmplayground&hl=en) Where I can have an LLM convo without leaking it to the internet) or connect via VPN (only Tor Browser at this time, I’m willing to sacrifice privacy for speed).
8. Google Maps, because Google is not in my threat model because they can’t be removed (SAD), plus OSMAND and Organic Maps can’t search addresses well still (SAD!)

# My Recommendations:

1. Read the threat model decide whether your goal is really to cut out Apple/Google and the Government… and if you are willing to do what it takes to cut them (either use GrapheneOS ‘fully’ or not carry a phone)
2. Read the [Android](https://www.privacyguides.org/en/os/android-overview/) or iOS guides if you end up using those devices

---

## Post 2 by @Milus — 2024-07-03T18:07:43Z

I don´t get it. From one side you complain about Google and even Sandboxed Google Services are much, on the other hand you use Stock with Pixel 6?

---

## Post 3 by @anon48875053 — 2024-07-03T18:11:34Z

Yeah, doesn’t make sense.

---

## Post 4 by @dumpster — 2024-07-03T18:22:08Z

> [@anon99860907](#):
>
> **If your threat model includes the Government (US in particular), Google or Apple, then you better not use a phone**

Just relegate your secret communication exclusively to secure E2EE communications such as Signal. If you don’t want your cell service provider to be able to identify you, use an anonymous payment method and provide a fake name if required. Keep your phone on airplane mode when at home, so your cell provider doesn’t learn your approximate home address. In general, don’t give info, or give false info.

> [@anon99860907](#):
>
> Google Play Store (not Aurora, no need for a man in the middle) and Obtainium

Aurora isn’t any more of a man in the middle than Obtainium is. Aurora downloads directly from Google Play. Obtainium downloads directly from Github (and other sites).

> [@anon99860907](#):
>
> Kagi Search w Unlimited

As we’ve [discussed here](https://discuss.privacyguides.net/t/kagi-search-engine/14172), Kagi doesn’t offer privacy benefits over free search engines like Brave and Duckduckgo.

> [@anon99860907](#):
>
> Google Maps, because Google is not in my threat model because they can’t be removed (SAD), plus OSMAND and Organic Maps can’t search addresses well still (SAD!)

I use Magic Earth. It’s proprietary, but its privacy policy seems decent.

---

## Post 5 by @anon48875053 — 2024-07-03T18:28:32Z

> [@anon99860907](#):
>
> **My Phone Carrier** They have all of my calls and texts, my rough location (even with location turned off)

They have your calls and messages because you gave it to them, just use Signal or SimpleX.

I also highly doubt that you need to worry about cellular triangulation. Especially if you have purchased your phone in cash and use a prepaid SIM card.

> [@anon99860907](#):
>
> And even when sandboxed, google knows a TON.

And this is the part where you should elaborate, or you’re just spreading FUD.

Also, you complain about sandboxed Google Play Services while using the stock OS, where Google has privileged access to your hardware identifiers and the rest of your system.

> [@anon99860907](#):
>
> **Proton via ProtonMail and ProtonVPN etc…** I’m not mad about this one, I like proton, but they know a lot about me, most is encrypted though, so I’m good.

This is literally the same regardless of what OS you use. In fact, it’s a lot better on a mobile device because of the strong security and permission model. Both of these things are basically nonexistent on desktop OSs.

> [@anon99860907](#):
>
> **Bitwarden** Not worried about this one either, but worth saying

Same as the above.

> [@anon99860907](#):
>
> If your threat model includes the Government (US in particular), Google or Apple, then you better not use a phone

If your threat model includes the government, then you must use GrapheneOS. On desktop, you should be using Qubes OS and, preferably, Qubes-Whonix.

> [@anon99860907](#):
>
> _ **Apple or Google, choose one** _ You can avoid giving data to Google (generally) by getting an Apple device (but you’ll probably get pwnd by Israeli Pegasus shit, who knows closed source code), and you can avoid giving data to Apple by using Google devices (probably the safer bet)… but practically can’t avoid picking between the two… GrapheneOS is as close as we can get, which is why it’s recommended, and it CAN be used in a way that leaks nothing to Google, but I doubt many of us here have successfully used it in that way. I have tried my best and it’s very very hard. My favorite tools (Proton and Signal) even require Google Play Services to run, and must be downloaded from the Play Store (or Aurora, which for me is an unnecessary extra step).
> 
> _ **If you are using a Phone, the Gov’t can probably snoop** _ (see the thread about the Jan 6 Dragnet)

This is a bunch of FUD, will not even bother replying.

> [@anon99860907](#):
>
> And in my experience most GrapheneOS setups with Google Play Services will still leaking Google in practice, not quite as much as Stock Andriod… but enough.

Again, elaborate.

> [@anon99860907](#):
>
> Other Apps are either Trusted (full internet access minus dns blocklist), Have no Internet Access (Simple Mobile Tools, or apps like [LM Playground](https://play.google.com/store/apps/details?id=com.druk.lmplayground&hl=en) Where I can have an LLM convo without leaking it to the internet) or connect via VPN (only Tor Browser at this time, I’m willing to sacrifice privacy for speed).

I’m sorry to be the one to break it to you, but unless you’re using GrapheneOS or DivestOS which both allow revoking the network permission, you aren’t blocking apps access to the internet.

---

## Post 6 by @user1 — 2024-07-03T19:37:12Z

> [@anon99860907](#):
>
> My favorite tools (Proton and Signal) even require Google Play Services to run, and must be downloaded from the Play Store

No, they don’t.

---

## Post 7 by @camp — 2024-07-03T19:58:00Z

> [@anon99860907](#):
>
> **My Phone Carrier** They have all of my calls and texts, my rough location (even with location turned off)

_ **This is too excessive for most threat models, but could apply to this scenario.** _

If this is a true concern buy a faraday bag and store your phone when not using it. Only use it at busy areas where there are many other devices to blend in.

In terms of calls and texts, only use privacy respecting apps like Signal.

When you are home, you can use a computer with communications apps instead of your phone. (Prevents phone carrier from knowing your physical address, assuming you bought the phone and SIM cash).

The phone should be placed in the Faraday bag at a busy location before going home.

---

## Post 8 by @anon99860907 — 2024-07-03T20:02:40Z

I’ve given up trying to block Google. For me it can’t practically be done. GrapheneOS is close, but since most apps I use still require Google Play Services I don’t feel it’s worth it for me. (and yes proton doesn’t NEED GPS, but it does for notifications)

@Lukas not trying to spread FUD, I’ll say it this way. The way I use GrapheneOS and the Sandboxed Google Play, it seems as though I’m giving as much info away to Google as on Stock Android. PLUS I have to additionally trust the GrapheneOS team, which I don’t.

> [@Lukas](#):
>
> If your threat model includes the government, then you must use GrapheneOS. On desktop, you should be using Qubes OS and, preferably, Qubes-Whonix.

I disagree on the phone front. I think if your threat model includes the govt you better not use a phone, use a flip burner in a faraday bag or something.

> [@camp](#):
>
> The phone should be placed in the Faraday bag at a busy location before going home.

agree!

In summary

- I hate the privacy tradeoffs on phones
- I don’t like GrapheneOS and the way I end up using it and the way it is still dependent on google (the way I use it)
- I think Stallman’s advice is right for people with extreme threat models, it’s not “Use Graphene OS” it’s “Don’t use a phone”. Luckily my threat model isn’t exterme, so I’ve given up and am using stock android with the privacy tweaks I can live with (like trying to use signal and proton etc…

---

## Post 9 by @anon99860907 — 2024-07-03T20:19:01Z

For more context this is a common point of discussion over on the Free Sofware Foundation forums, they are mostly ‘freedom’ focused not (only) privacy but I think my questioning is reasonable and not just FUD… see Graphene Related posts below

“Living Without Mobile Devices” and “Graphene OS - Good or no?”

 ![Screenshot from 2024-07-03 16-17-05](//forum-uploads.privacyguidesusercontent.com/original/2X/0/0b2e22884dbd3e71fb734492aff594128a90e5d1.png)

---

## Post 10 by @anon48875053 — 2024-07-03T20:42:14Z

Airplane mode accomplishes the same thing as the faraday bag.

---

## Post 11 by @anon99860907 — 2024-07-03T21:13:18Z

It should! But I’d rather trust physics and a physical bag than an ever-changing software stack… and anyone counting on radio silence should probably use both.

---

## Post 12 by @camp — 2024-07-03T21:31:58Z

When you place the phone in airplane mode it pings cell towers stating this. Do you know if this is the case on GrapheneOS as well?

---

## Post 13 by @anon48875053 — 2024-07-03T21:38:04Z

If you enable airplane mode on GrapheneOS then the cellular radio is completely disabled.

---

## Post 14 by @xe3 — 2024-07-03T22:04:25Z

> [@anon99860907](#):
>
> they can’t be removed (SAD)

They can be. But its up to you to decide whether the tradeoffs are worth it for you.

I’d also encourage you not to think in black and white terms, its counterproductive in the context of both privacy and security. Its not useful to think of Google or no Google as a binary choice, There is a huge spectrum between Google’s proprietary stock Android + heavy use of Google apps and services, and zero Google. Not being able to get to true zero shouldn’t lead you to just throw up hands and go full Google (unless that’s your preference)

You are saying your hero is RMS, his whole philosophy seems centered around making hard choices, and being willing to give some things up when they don’t align with your values/ethics. With that in mind, it is surprising to see you so willingly opting for an OS that is neither FOSS nor private, just because the FOSS and private alternatives aren’t perfect or require some tradeoffs. I’m not trying to criticize I’m just genuinely surprised, and don’t understand the logic of choosing arguably the worst option for privacy (stock Android) just because the best options are not perfect. Don’t let perfect be the enemy of good.

> [@anon48875053](#):
>
> ![](https://forum-cdn.privacyguides.net/letter_avatar_proxy/v4/letter/a/ac2f09/48.png) anon99860907:
> 
> > And in my experience most GrapheneOS setups with Google Play Services will still leaking Google in practice
> 
> Again, elaborate.

Specifics are useful, but I don’t think that the above is a particularly controversial thing to acknowledge. Correct me if things have changed but sandboxed play services, just means the same sandbox that applies to normal apps applies to play services also. If you’d be uncomfortable installing an app like Facebook or Whatsapp or something like that on your phone, I think installing sandboxed play services warrants at minimum the same amount of concern/discomfort.

IMO sandboxed play services is a huge step in the right direction for those who can’t or don’t care to use GOS in its default non-GPS dependent state, but I think the term ‘sandboxed’ can give a misleading sense of overconfidence. Unless I’m missing something sandboxed play services should be trusted more or less to the same extent you’d treat any other normally privileged proprietary app from a privacy hostile company.

---

## Post 15 by @anon99860907 — 2024-07-03T22:48:03Z

@xe3 this is helpful.

I have lasted for a few months with Graphpene before I quit (I’ve tried a handful of times) here are the basic apps I need:

Apps that I like, are recommended here, but are not available to install outside of the play store, (or Aurora store, which is the play store with a man in the middle) and complain to me about missing Google Play Services when installed on GOS:

- Proton Calendar
- Proton Drive
- Proton Mail
- Signal

Do Not Require Google Play Services, I can get these easily with Obtainium and Github, which I like better than Aurora.

- Bitwarden
- Cake Wallet
- Librera
- Obtainium
- ONLYOFFICE Documents
- Rethink
- RTranslator
- Standard Notes

So, I’m willing to try again, what do I do? Just install via Aurora store and keep Sandboxed GPS off? Put Proton in a separate profile and install GPS there? Use Molly instead of Signal (yet another man in the middle?) Help me out and I’d be happy to give it a try and report back.

Aurora just feels gross and insecure… it’s a vibe and that’s not helpful maybe… but if all of this stuff didn’t complain about missing GPS and was installable from source with Github/Obtainium I would be all over it.

---

## Post 16 by @seize — 2024-07-03T23:54:06Z

Just FYI, but all proton apps for android can be download ed from [here](https://protonapps.com/) and if I remember correctly, fetching apks from the above URL with obtainium is relatively painless.

---

## Post 17 by @anon99860907 — 2024-07-04T00:32:07Z

I see signal does the same thing [Signal \>\> Signal Android APK](https://signal.org/android/apk/)

What a relief. Either I’m an idiot (likely) or they weren’t doing this last time I tried GOS.

Either way thank you @seize

---

## Post 18 by @exaCORE — 2024-07-04T00:37:25Z

GOS has an option for Sandboxed play services and sandboxes Google Play Store. You can use that. Also, instead of Signal, you can use Molly FOSS if you dont want play services. Its worked well for me so far

---

## Post 19 by @anon99860907 — 2024-07-04T02:21:33Z

@xe3 @Lukas I did it, so very sexy.

 ![Screenshot_20240703-221218](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3295079e0980cf99066f8e0a75b7213ec58d4a77.png)

I am happy I landed here, but it felt pretty cumbersome to get here. GOS by providing no alternative seems to push users to download the cancer that is Sandboxed Google Play as if that’s the only way to get apps, The alternative being F-Droid (unsafe), and Aurora (maybe safe but gross to me). I can get all of this shit with obtainium (or just by hand-downloading APKs) directly from the source without extra men in the middle… so nice. so fun. so private. I’m not sure how many other people on the forum would benefit from a schooling on how to get apps without instantly downloading GPS, but this was definitely a helpful exercise for me.

I’ll still end up setting up an alternative profile that isolates the cancerous shit I might need to download (Android Auto for my newish car, unfortunately and a few other proprietary things I need maybe once a week) but I feel way more in control now. I’ll still probably end up sending _a little bit of data_ to Google. but less than I was earlier today.

Thanks to the helpful folks quoted below:

> [@xe3](#):
>
> sandboxed play services should be trusted more or less to the same extent you’d treat any other normally privileged proprietary app from a privacy hostile company.

> [@camp](#):
>
> In terms of calls and texts, only use privacy respecting apps like Signal.

> [@Lukas](#):
>
> unless you’re using GrapheneOS or DivestOS which both allow revoking the network permission, you aren’t blocking apps access to the internet.

> [@dumpster](#):
>
> relegate your secret communication exclusively to secure E2EE communications such as Signal.

---

## Post 20 by @olanography — 2024-07-04T03:44:49Z

Thanks for this! I was wondering where I would get all of their downloadable APKs for Obtainium since they don’t have everything on GitHub. I might use this.

One thing that’s stopping me, though, is the fact that some updates might be a bit slow. I noticed one time that they released updates for Proton VPN on the play store _before_ GitHub, which I found odd.

Also, I am wondering if this website is officially operated and maintained by Proton? I am trying to look for a backlink on Proton’s official website but can’t seem to find any. I guess I could do something with the SHA256 fingerprints that they show on that website, but not tech savvy enough to know what to do.

edit: Actually, it looks like the download links are directly from official Proton sources, so it should be all good on that end, but the issue of slow updates remain. Probably won’t use it. The calendar download link, for example, is still using the old \<[protonmail.com](http://protonmail.com)\> domain. I really wish they would open source the APKs.

---

## Post 22 by @anon48875053 — 2024-07-04T06:26:11Z

That’s the whole point of sandboxing and permission control, so you don’t have to trust the apps that you install. That’s why you don’t need an antivirus for your phone, apps don’t just gain full access to the OS by just installing or launching them like they do on desktop OSs.

---

## Post 23 by @anon48875053 — 2024-07-04T06:32:33Z

Just install sandboxed Google Play Services and use your phone normally without unhinged “Google is spyware” nonsense.

It seems that you lack the technical knowledge of how things work on GrapheneOS, etc. and just rely on Google is spyware mentality.

If something is spyware, then you have to prove it. If you say that sandboxed Google Play Services will be “leaking to Google a lot,” then you need to elaborate and explain what exactly does it leak or it’s just FUD that doesn’t help neither you nor the forum members.

---

## Post 24 by @anon48875053 — 2024-07-04T06:50:37Z

> [@anon99860907](#):
>
> The alternative being F-Droid (unsafe)

Unsafe but used by 58% percent of Privacy Guides community including @jonah: [How do you obtain your Android applications](https://discuss.privacyguides.net/t/how-do-you-obtain-your-android-applications/18099)

The percentage would be a lot higher, but F-Droid only includes FLOSS apps, and the proprietary ones are only on the Play Store.

One more thing is that a large percentage of people just read that article and decided that “F-Droid is bad” without properly threat modeling for themselves.

More reading: [Are F-Droid security concerns still valid or have they been mitigated? - #4](https://discuss.privacyguides.net/t/are-f-droid-security-concerns-still-valid-or-have-they-been-mitigated/18842/4)

> [@anon99860907](#):
>
> I’m not sure how many other people on the forum would benefit from a schooling on how to get apps without instantly downloading GPS, but this was definitely a helpful exercise for me.

Not many because Obtainium isn’t a proper app store like F-Droid or the Play Store, and it doesn’t have any inclusion criteria like those two. You can install and find any garbage on the internet.

Some reading: [Obtainium (Android App Downloader) - #34 by SkewedZeppelin](https://discuss.privacyguides.net/t/obtainium-android-app-downloader/295/34)

[https://discuss.privacyguides.net/t/over-100-000-infected-repos-found-on-github-im-concerned-as-i-use-obtainium-as-recommended/17180](https://discuss.privacyguides.net/t/over-100-000-infected-repos-found-on-github-im-concerned-as-i-use-obtainium-as-recommended/17180)

> [@anon99860907](#):
>
> I’ll still end up setting up an alternative profile that isolates the cancerous shit I might need to download (Android Auto for my newish car, unfortunately and a few other proprietary things I need maybe once a week) but I feel way more in control now. I’ll still probably end up sending _a little bit of data_ to Google. but less than I was earlier today.

Do you know how and why they will be isolated? If they will be at all.

Edit: I forgot to mention that if you installed some Proton apps from their site, not GitHub, then they might not update automatically because Obtainium just uses web scraping for these kinds of downloads.

---

## Post 25 by @anon99860907 — 2024-07-04T10:30:37Z

> [@anon48875053](#):
>
> Just install sandboxed Google Play Services and use your phone normally without unhinged “Google is spyware” nonsense.

No Thanks! I apprecaite the advice but don’t think my request is unreasonable. I want to run GrapheneOS and don’t want to run Google Play Services (at least on my main profile). I’m sorry you think that’s pointless, but it makes me feel very happy.

> [@anon48875053](#):
>
> It seems that you lack the technical knowledge of how things work on GrapheneOS, etc. and just rely on Google is spyware mentality.

100% true, and this is where the Freedom and Privacy stuff start to become conflated, and I’m sorry if that annoys you.

> [@anon48875053](#):
>
> Airplane mode accomplishes the same thing as the faraday bag.

Back to this quote from you, This MIGHT be true today, but might not be after an OTA update, I want to be in control as much as I can, and I don’t want to have to dig into the details of GrapheneOS every time to see if they are actually turning off my radios or if they are actually sandboxing google, I’d rather just not install GPS and use a faraday bag. I didn’t start this conversation with a practical question… I started it with something like:

“RMS thinks all phones are unfree” and “I think he is right and most of you are dependent on google” and “I’ve given up and am using stock Android” and y’all rightly told me I was being silly, but I think my ideal of using at least a profile on my phone (if not the whole thing) without GPS is reasonable from both a privacy and a freedom perspective.

Looking through the FSF Archives there are others like me trying to achieve a simlar setup, and I think we should be allies and I think our concerns about installing GPS are reasonable, and just telling us to shut up and install it isn’t super helpful, but I get where you’re coming from and appreciate you particpating in the conversation anyway.

Here’s a quote from an FSF staff member x-posted from their forum

> I am daily driving GrapheneOS and I really appreciate what the developers have done with it.
> 
> GrapheneOS is not FSF RYF perfect by any means, but the decisions result in being able to use modern flagship Android phones with a quality user experience. It is definitely a giant leap up the freedom ladder from Stock Android.
> 
> The install can be done through the command line (like every other rom) or through a webpage using Chromium. The web installer is the most user-friendly way that I have ever seen to flash a rom.
> 
> With multiple profiles, you can choose when and where you install a sandboxed and minimized Google services such as Google Play Store. My main profile only has defaults and F-Droid apps. I have a secondary profile that cannot make or receive calls that has sandboxed Google apps. In practice, I pretty much only use that account to access to my gym. I have not tested whatsapp, but I would assume it would work. LineageOS and other roms have an all-or-nothing approach to adding Google back in. I really appreciate the additional segmentation that GrapheneOS allows.
> 
> The auditor app give the option for remote attestation which I have not seen from any other roms. The remote attestation server can be self-hosted, but I have not done this.
> 
> The first few things I would recommend doing with a fresh install is to open vanadium, download F-Droid, install F-Droid, install a Firefox fork of your choosing, replacing the Vanadium link with your Firefox choice, and then install NeoStore (an alternative F-Droid frontend), configuring NeoStore to autoupdate apps, and disabling the extra NeoStore repositories.

His approach seems less elegant to me than 100% obtainium but I’m cool with it. I think we can all have our flavor here. Anyway thanks again for the help.

---

## Post 26 by @pinkandwhite — 2024-07-04T10:52:49Z

I _like_ firefox, but using it on mobile while fission is still not complete, among other security holes, is just not great really

---

## Post 27 by @anon48875053 — 2024-07-04T11:04:46Z

> [@anon99860907](#):
>
> No Thanks! I apprecaite the advice but don’t think my request is unreasonable. I want to run GrapheneOS and don’t want to run Google Play Services (at least on my main profile). I’m sorry you think that’s pointless, but it makes me feel very happy.

Not wanting to run Google Play Services is reasonable, I don’t want to have it on my phone either, but making baseless claims about Google Play Services and Google in general isn’t okay.

You also ignored my question:

> [@anon48875053](#):
>
> Do you know how and why they will be isolated? If they will be at all.

Anyway, let’s move on.

> [@anon99860907](#):
>
> 100% true, and this is where the Freedom and Privacy stuff start to become conflated, and I’m sorry if that annoys you.

I’m someone who uses F-Droid, advocates for F-Droid, and advocates for software freedom where possible and where it makes sense.

If you care about software freedom, then you will care about this:

Both Signal and Proton Mail come bundled with Google’s proprietary libraries for FCM notifications. Signal also uses Google Maps as a location provider.

I will not reply to any FSF stuff, their focus is software freedom, not privacy and security. It would be unfair, in my opinion.

One last thing, you ignored a lot of things in my previous posts, which also included some of my questions to you.

---

## Post 28 by @anon99860907 — 2024-07-04T11:35:06Z

> And even when sandboxed, google knows a TON.

This is wrong, I deleted it.

> [@anon99860907](#):
>
> GrapheneOS is as close as we can get, which is why it’s recommended, and it CAN be used in a way that leaks nothing to Google, but I doubt many of us here have successfully used it in that way. I have tried my best and it’s very very hard. My favorite tools (Proton and Signal) even require Google Play Services to run, and must be downloaded from the Play Store (or Aurora, which for me is an unnecessary extra step).

The part about needing the Play Store/ Aurora is wrong (thank God!) But the first bit is _kinda_ right still. As you said:

> [@Lukas](#):
>
> Signal and Proton Mail come with Google’s proprietary libraries for FCM notifications. Signal also uses Google Maps as a location provider.

and from your poll 50% of people are using Google Play Store, and 25% Aurora. So about half of Graphene users are giving Google some data, which is what I’d like to avoid as much as possible.

> [@Lukas](#):
>
> I will not reply to any FSF stuff, their focus is software freedom, not privacy and security. It would be unfair, in my opinion.

Totally fine, (and btw I’m not advocating for firefox or anything like that @pinkandwhite ) I’m not trying to say they are right, I am trying to find a solution that solves my Privacy question and my Freedom question at the same time.

> [@Lukas](#):
>
> Do you know how and why they will be isolated? If they will be at all.

Sorry I didn’t answer this one. From just using them the separate profiles will only keep one copy of an app per phone (the “Google” user can be given permission to install apps and overwrite the “Non-Google” user, and CAN run in the background (I turn this off so the profile should be off when I am not using it) and it CAN be given access to calls and texts… but doesn’t have to be. It seems like separate profiles are a tiny step above putting everything on one profile, the main benefit being I can ‘turn off’ the google profile when I am not using it (meaning Sandboxed Google Play is still installed but not running), but when it’s on it seems to have almost the same access as it would if it were all installed on one profile… maybe that’s your point. I have also seen odd stuff like if I had a VPN on my nongoogle profile, the VPN settings would affect Android auto on my Google profile (because the main profile was running in the background, I guess). I’d be happy to be enlightened if you’d like.

> [@Lukas](#):
>
> One last thing, you ignored a lot of things in my previous posts, which also included some of my questions to you.

If you want to close this thread with some takeaways feel free to discuss for me the takeaways are as follows:

1. **You Don’t NEED Google Play Services on Graphene** \* You can run GrapheneOS reasonably with Obtainium only and get Signal, Proton and other privacyguides stuff running well without installing Google Play Services
2. **Privacyguides forum users are split ~50/50 on whether to use the Play Store or Not** It seems ~50%+ or so of privacyguides users ([How do you obtain your Android applications](https://discuss.privacyguides.net/t/how-do-you-obtain-your-android-applications/18099)) might choose to install Google Play Services so they don’t have to deal with the headache (and risks of downloading junk via obtainium), and probably Google is not in their theat model, which is fine.
3. **Graphene is the best way to cut off network access for the OS and Apps** Graphene should be doing what it says when it shuts off Network access to apps, and Airplane mode in Graphene should be as good as a faraday bag.
4. **Graphene is more tinfoil hat friendly than I originally assumed** Graphene CAN REASONABLY be used in a way that leaks nothing to Google, but it’s not necessarily the most popular way to use it.

IDK how else to say it, or if I missed something important… but you can close us out if you like @Lukas

---

## Post 29 by @anon48875053 — 2024-07-04T12:07:12Z

> [@anon99860907](#):
>
> GrapheneOS is as close as we can get, which is why it’s recommended, and it CAN be used in a way that leaks nothing to Google, but I doubt many of us here have successfully used it in that way.

Why are we focusing on not leaking anything to Google? You need to threat model properly and decide which things you’re fine giving to Google and which ones you aren’t, then act accordingly. Trying to not leak anything to Google is both unrealistic and probably useless.

> [@anon99860907](#):
>
> As you said:
> 
> ![](/letter_avatar_proxy/v4/letter/a/8d6e62/48.png) anon48875053:
> 
> > Signal and Proton Mail come with Google’s proprietary libraries for FCM notifications. Signal also uses Google Maps as a location provider.

Proton Mail is working on a notification implementation that is independent from Google.

Molly has a version that doesn’t have Google’s proprietary libraries for FCM and uses OpenStreetMaps instead of Google Maps as a location provider.

In any case, these libraries are useless without Google Play Services, and FCM is only used to wake up both Signal and Proton Mail so they can send a notification, so notifications aren’t leaked to Google.

The only issue is software freedom.

> [@anon99860907](#):
>
> and from your poll 50% of people are using Google Play Store, and 25% Aurora. So about half of Graphene users are giving Google some data, which is what I’d like to avoid as much as possible.

There is nothing wrong with giving some data to Google.

Also, not all the people that voted use GrapheneOS, some of them might be using stock OSs that come with the Play Store.

> [@anon99860907](#):
>
> Sorry I didn’t answer this one. From just using them the separate profiles will only keep one copy of an app per phone (the “Google” user can be given permission to install apps and overwrite the “Non-Google” user, and CAN run in the background (I turn this off so the profile should be off when I am not using it) and it CAN be given access to calls and texts… but doesn’t have to be. It seems like separate profiles are a tiny step above putting everything on one profile, the main benefit being I can ‘turn off’ the google profile when I am not using it (meaning Sandboxed Google Play is still installed but not running), but when it’s on it seems to have almost the same access as it would if it were all installed on one profile… maybe that’s your point. I have also seen odd stuff like if I had a VPN on my nongoogle profile, the VPN settings would affect Android auto on my Google profile (because the main profile was running in the background, I guess). I’d be happy to be enlightened if you’d like.

VPNs are per profile, you can use 10 different VPNs in 10 different profiles.

The main advantage that user profiles provide is that apps in the same profile can communicate with each other using IPC, but both of the apps have to agree to it. This is where user profiles come in because apps can’t communicate with apps that are in a different profile.

This advantage will be gone when GrapheneOS releases their IPC scopes feature.

> [@anon99860907](#):
>
> **You Don’t NEED Google Play Services on Graphene** \* You can run GrapheneOS reasonably with Obtainium only and get Signal, Proton and other privacyguides stuff running well without installing Google Play Services

Would recommend F-Droid instead of Obtainium, but sure.

> [@anon99860907](#):
>
> **Privacyguides forum users are split ~50/50 on whether to use the Play Store or Not** It seems ~50%+ or so of privacyguides users ([How do you obtain your Android applications](https://discuss.privacyguides.net/t/how-do-you-obtain-your-android-applications/18099)) might choose to install Google Play Services so they don’t have to deal with the headache (and risks of downloading junk via obtainium), and probably Google is not in their theat model, which is fine.

A lot of them have no choice because they use an OS that already comes with Google Play Services.

> [@anon99860907](#):
>
> **Graphene is the best way to cut off network access for the OS and Apps** Graphene should be doing what it says when it shuts off Network access to apps, and Airplane mode in Graphene should be as good as a faraday bag.

DivestOS is just as good for these things.

I would recommend you to read all of these if you haven’t already:

> **[GrapheneOS features overview](https://grapheneos.org/features)**
>
> Overview of GrapheneOS features differentiating it from the Android Open Source Project (AOSP).

> **[GrapheneOS usage guide](https://grapheneos.org/usage)**
>
> Usage instructions for GrapheneOS, a security and privacy focused mobile OS with Android app compatibility.

> **[GrapheneOS Frequently Asked Questions](https://grapheneos.org/faq)**
>
> Answers to frequently asked questions about GrapheneOS.

A lot of good quality information in these links above.

---

## Post 30 by @jerm — 2024-07-04T12:47:40Z

I wonder what would happen if you didn’t close the faraday bag correctly or there is a small hole in it…

How do you even test if you got a decent quality faraday bag?

> [@anon99860907](#):
>
> Use Molly instead of Signal (yet another man in the middle?)

It is called a “third-party” and not MITM (Man-in-the-middle)

---

## Post 31 by @anon48875053 — 2024-07-04T12:59:14Z

> [@jerm](#):
>
> I wonder what would happen if you didn’t close the faraday bag correctly or there is a small hole in it…
> 
> How do you even test if you got a decent quality faraday bag?

Get a faraday box, problem solved.

---

## Post 32 by @jerm — 2024-07-04T13:02:09Z

> [@anon48875053](#):
>
> DivestOS is just as good for these things.

I couldn’t find any info about airplane mode on [divestos.org](http://divestos.org). However, I found [How silent is airplane mode with DivestOS · Divested-Mobile/DivestOS-Build · Discussion #221 · GitHub](https://github.com/Divested-Mobile/DivestOS-Build/discussions/221).

Are there plans to add “features” page like GOS? @anon63378630 thanks :smiley:.

---

## Post 33 by @anon63378630 — 2024-07-04T13:06:12Z

@jerm see [https://divestos.org/pages/technical\_details#details](https://divestos.org/pages/technical_details#details) and [https://divestos.org/pages/faq](https://divestos.org/pages/faq)

---

## Post 34 by @anon32558482 — 2024-07-04T16:55:27Z

The average person doesn’t have to worry about Pegasus due to the insane cost of running the software.

My GOS doesn’t have Google services and I use both Proton and Signal. I trick is to use You Have Mail for Proton and Molly instead of Signal. Both run in the background all the time but they are very easy on the battery.

Simple Mobile Tools was bought out by an ad company last year. You might was to switch to their forks from Fossify. Of course SMT most likely isn’t nearly as bad as a stock Pixel.

---

## Post 35 by @anon99860907 — 2024-07-04T17:44:11Z

> [@anon32558482](#):
>
> I trick is to use You Have Mail

This looks like a cool project. Thanks for noting. For now (in the past 12 hours since re-installed GOS) it looks like the Proton apps downloaded directly from their site are running fine without GPS, I _think_ I can live without push notifications, but if not I’ll consider running this as well.

> [@anon32558482](#):
>
> Molly instead of Signal

I ran molly before, as a hack for my dual-sim phone to support 2 Signal services at once (which worked very well)… I’m sure it’s fine but would like to avoid allowing unnecessary third-parties (thanks @jerm for the right term ) if i can. **It also looks like the official signal app is able to support push notifications without GPS** I’ve only been running it for a few hours but it’s been fine… and I see many closed tickets like this one [Signal without Google play services: unreliable receiving of messages · Issue #9073 · signalapp/Signal-Android · GitHub](https://github.com/signalapp/Signal-Android/issues/9073)

> [@anon32558482](#):
>
> Simple Mobile Tools was bought out by an ad company last year.

Thank you for the advice. Luckily I don’t need any of the simple mobile tools (or Fossify versions) if I run GOS, as their native Contacts, Gallery, etc… are all pretty good. I wish Graphene itself would publish more of their apps on the Play Store so noobs can try out some free software, Camera and PDF are nice but might as well add contacts, phone, gallery, keyboard, launcher etc… probably not enough hours in the day for them though.

Also thanks to @anon63378630 for joining in. This thread has been very helpful to me. I’m just trying to

> _“take back (some) control of [my] device”_

and trying to precisely define what ‘some’ means. Thanks all for your patience with me and help. I’m pretty happy with the setup as of this morning, and my spirit feels better, I can continue my convo with RMS and the FSF crowd with my head held a little higher lol,

---

## Post 36 by @anon48875053 — 2024-07-04T17:48:23Z

> [@anon99860907](#):
>
> Thank you for the advice. Luckily I don’t need any of the simple mobile tools (or Fossify versions) if I run GOS, as their native Contacts, Gallery, etc… are all pretty good. I wish Graphene itself would publish more of their apps on the Play Store so noobs can try out some free software, Camera and PDF are nice but might as well add contacts, phone, gallery, keyboard, launcher etc… probably not enough hours in the day for them though.

Apps, Auditor, Camera, Info, PDF Viewer, and Vanadium are developed by GrapheneOS. The rest are just basic AOSP apps.

While the dialer is a basic AOSP app too, GrapheneOS has implemented call recording for it in a secure, simple, and robust way. Call recording is a rare thing these days, but GrapheneOS gives you that option.

---

## Post 37 by @anon99860907 — 2024-07-04T18:19:19Z

> [@anon48875053](#):
>
> The rest are just basic AOSP apps.

Does one need to build these projects themselves to get the APKs or are they readily available? I remember struggling to find an AOSP keyboard to replace gboard (when I was using stock). Same thing with the launcher, I love the AOSP launcher as well. Very Clean.

---

## Post 38 by @anon63378630 — 2024-07-04T18:21:34Z

> [@anon99860907](#):
>
> and trying to precisely define what ‘some’ means.

In the context of DivestOS, it means a) the devices are still proprietary hardware with proprietary software blobs and b) it makes more than a few opinionated choices, but you’re welcome to compile it yourself.

---

## Post 39 by @anon48875053 — 2024-07-04T18:23:46Z

All of those apps are only getting the bare minimum maintenance and security updates, and they are sample apps that are meant to be replaced as part of any serious variant of Android.

The only reason why GrapheneOS comes with them is because they have limited resources to develop their own apps, and third-party apps are mostly GPL-3 licensed.

---

## Post 40 by @wojciechxtx — 2024-07-04T18:40:16Z

> [@anon32558482](#):
>
> The average person doesn’t have to worry about Pegasus due to the insane cost of running the software.

Not to mention expertise required to operate it… :smile:

---

## Post 41 by @anon99860907 — 2024-07-04T18:42:18Z

> [@anon48875053](#):
>
> these apps are meant to be replaced

I see a little reference to something like this in the GOS user guide…

> We plan to replace AOSP Gallery with a standalone variant of the gallery we’re developing for the Camera app in the future.

What are the recommended replacements? I’d prefer some open stuff over Google Messages if possible, but am happy to hear what the good folks at Privacy Guides use. I’m also happy to be that guy that doesn’t do sms group messages very well and converts ppl to signal.

---

## Post 42 by @anon99860907 — 2024-07-04T18:47:52Z

I saw this too [https://discuss.privacyguides.net/t/what-is-your-private-phone-setup/](https://discuss.privacyguides.net/t/what-is-your-private-phone-setup/)

Seems like the jury is out on SMS, and things like QKSMS aren’t necessarily recommended over the AOSP messages app. Does privacyguides have a GrapheneOS guide for these replacements that we apparently need? That would be lovely.

---

## Post 43 by @anon48875053 — 2024-07-04T18:51:24Z

> [@anon99860907](#):
>
> Does privacyguides have a GrapheneOS guide for these replacements that we apparently need?

You don’t need to replace those apps if they work for you.

---

## Post 44 by @xe3 — 2024-07-04T19:46:29Z

> [@anon99860907](#):
>
> I see a little reference to something like this in the GOS user guide…

I believe what Lukas meant is that _Google and/or Android broadly_ considers those placeholder apps, not that GrapheneOS specifically recommends replacing them.

This is in my opinion one of the more insidious aspects of Android as an ““open source”” project. AOSP is indeed open source, but it has been designed in such a way that in its open form it is quite anemic, and the AOSP apps receive little attention, and a lot of dependence on proprietary apps like Google Play Services is build in by design for even basic core features of a smartphone. This is one of my biggest frustrations with Android (open source, designed to depend on closed source for basic functionality).

---

## Post 45 by @anon63378630 — 2024-07-04T20:35:06Z

> [@xe3](#):
>
> _Google and/or Android broadly_ considers those placeholder apps

I wrote a thing about this back in 2016:

- Google has slowly been dropping support for many projects under AOSP. Recent releases of Android haven’t actually added many user visible features to Android itself, most of those features are actually apart of Google Apps.
  - Examples:
    - 6.0 = Now on Tap
    - 5.0 = Android Wear Integration
    - 4.4 = Google Now and Google Play Store
    - 4.1 = Google Now
    - All older versions implemented features that were available in AOSP

  - What’s been (partially) dropped and what it was replaced with:
    - Browser =\> Chrome
    - Calendar =\> Google Calendar
    - Clock =\> Google Clock
    - Launcher =\> Google Now Launcher
    - Gallery =\> Google Photos
    - Camera =\> Google Camera
    - Keyboard =\> Google Keyboard
    - Phone =\> Google Phone
    - Contacts =\> Google Contacts
    - Sound Recorder =\> Google Sound Recorder
    - Calculator =\> Google Calculator

---

## Post 46 by @anon48875053 — 2024-07-04T20:38:16Z

> [@xe3](#):
>
> This is in my opinion one of the more insidious aspects of Android as an ““open source”” project. AOSP is indeed open source, but it has been designed in such a way that in its open form it is quite anemic, and the AOSP apps receive little attention, and a lot of dependence on proprietary apps like Google Play Services is build in by design for even basic core features of a smartphone. This is one of my biggest frustrations with Android (open source, designed to depend on closed source for basic functionality).

App developers choosing to develop their apps in a way that depends on Google Play Services and then only publish those apps to the Play Store is their fault, not the operating system’s fault.

---

## Post 47 by @xe3 — 2024-07-04T20:53:50Z

> [@anon48875053](#):
>
> App developers choosing to develop their apps in a way that depends on Google Play Services and then only publish those apps to the Play Store is their fault, not the operating system’s fault.

Choosing to build basic functionality which apps are _intended_ to rely on, into proprietary Google Play Services and other proprietary Google system apps instead of AOSP itself is a conscious choice that Google made and continues to double down on. This is in my eyes a very deliberate choice on Google’s part, akin to a dark pattern at the development level.

App developers _can_ go out of their way to cater to the 0.1% of us who care about free software, and/or transparency, and/or privacy, but most developers (including even many somewhat privacy focused projects) take the path of least resistance or rely at least partially on proprietary Google stuff.

---

## Post 48 by @anon63378630 — 2024-07-04T21:12:54Z

Android Studio also repeatedly tries to add Play Services and other libraries as dependencies when creating a new project.

And I don’t think you can use the standalone Android plugin in IntelliJ Community anymore either.

And a fair bit of example code for eg. location expects you use the compat layer from GMS.

---

## Post 49 by @anon48875053 — 2024-07-04T21:24:03Z

Android is still an amazing operating system, and nothing else comes close to it.

It’s licensed under a permissive license.

It’s very secure, unlike desktop operating systems.

AOSP is a lot more private than iOS.

While most Linux distributions are privacy-friendly themselves, they don’t have strong privacy protections from third-party apps and services, and Android is literally the best at this. The sandboxing and permission model is just a chef’s kiss.

GrapheneOS, in my opinion, has by far the best privacy and security while not heavily sacrificing usability and performance, and GrapheneOS is obviously based on AOSP.

F-Droid alone has over 4,000 completely FLOSS apps that don’t have any proprietary dependencies and can be built almost exclusively using FLOSS tools.

Android is lovely.

---

## Post 50 by @anon63378630 — 2024-07-04T21:37:09Z

I just wish the “Linux phones” focused on having well functioning Android as opposed to the current blob filled devices. Would still have downsides like lack of secure boot, but would be vastly superior with regards to mobile app availability.

---

## Post 51 by @anon46412288 — 2024-07-05T14:21:04Z

just a question : why are you ignoring your own advise about not using a phone?

also avoid simple mobile tools, they got bought out by an ad company called ZipoApps. Use [Fossify’s forked versions instead.](https://github.com/FossifyOrg)

---

## Post 52 by @anon46412288 — 2024-07-05T14:30:04Z

> [@anon48875053](#):
>
> It’s licensed under a permissive license.

Wouldn’t agree with this, I hate how Android hardware companies avoid copyleft. The Linux kernel has tons of open source drivers included with the kernel, and on desktop various manufacturers contribute upstream (Yes, even there, companies like NVIDIA and Broadcom don’t open source their drivers, but that’s considerably less common than with chipset makers on Android), and both Intel and AMD contribute a LOT, Intel being the biggest overall contributor to Linux in general (opposed to, say, Qualcomm, which has never done so for Android. [This won’t be the case for their laptop CPUs though.](https://www.qualcomm.com/developer/blog/2024/05/upstreaming-linux-kernel-support-for-the-snapdragon-x-elite)). Most of them are GPL licensed as well. The copyleft nature is much better, unless we end up with the Android driver situation.

I will say I don’t know the exact details, but I’m pretty sure there is some layber between the Linux kernel and blob drivers so it doesn’t violate licenses as well. And of course, each chipset has its own forked kernel with blob drivers included.

---

## Post 53 by @anon48875053 — 2024-07-05T14:44:57Z

If Android wasn’t permissively licensed, then iOS would rule the world.

---

## Post 54 by @anon99860907 — 2024-07-05T14:46:16Z

Yeah, I guess I framed the first post poorly… I agree with RMS that if your threat model is similar to his you just shouldnt use a phone… but I don’t have such an extreme threat model so this became a long conversation about how to use GrapheneOS and apps suggested by privacyguides without using Google Play Services which is what I’m doing now.

---

## Post 55 by @pinkandwhite — 2024-07-07T00:23:33Z

I do want to call out that it’s not a threat model that drives Mr Foot Gunk’s choices, it’s the “freedom at all costs” ideology. No one is trying to hack his shit, and if they were, they’d have a pretty easy time given the security issues with most libre alternatives to mainstream linux tooling.

---

## Post 56 by @anon99860907 — 2024-07-07T02:14:26Z

> [@pinkandwhite](#):
>
> given the security issues with most libre alternatives to mainstream linux tooling

For sure. Anyone using garbage tools will get owned.

Dr Foot Gunk in particular doesn’t online bank, pays cash, and PGPs his emails left and right. Historically he uses some [insane email proxy system to ‘browse’ the web](https://lwn.net/Articles/262570/) and disables javascript on every site he sees etc… While your point is true for libre idealists in general, it’s probably not true for RMS in particular.

(And also he is 100% making those choices bc FREEDOM! not bc threat model… but I was trying to use the lingo to keep the convo flowing.)

---

## Post 57 by @anon48875053 — 2024-07-07T06:55:51Z

> [@anon99860907](#):
>
> Dr Foot Gunk in particular doesn’t online bank, pays cash

Because banks suck and cash is based.

---

## Post 58 by @Camerart — 2024-07-07T07:20:56Z

Hi, did you know that a cell phone can be located by timing the signal, so the phone is a cetrain distance from a tower, and where does it cross houses. This is where you most likely live.  
C

---

## Post 59 by @anon48875053 — 2024-07-07T07:25:20Z

This is called triangulation, and you need to be pretty paranoid to worry about it unless you’re in the US, where your location is sold to everyone willy-nilly.

---

## Post 60 by @Camerart — 2024-07-07T07:41:32Z

Hi L,  
True, but, triangle is normally used when there are two towers, but I’m talking about using only one tower, and the distance from it.

It could be called paranoia, but some of us prefer to be private, nothing more.  
C

---

## Post 61 by @anon48875053 — 2024-07-07T07:45:55Z

Knowing the distance from one tower is completely useless.

---

## Post 62 by @Camerart — 2024-07-07T07:51:36Z

Hi L,  
A distance circle around the tower most likely crosses only one house, and this is most likely yours.  
C

---

## Post 63 by @anon48875053 — 2024-07-07T08:06:43Z

Cellular towers broadcast their signal all around them, in all possible directions.

If I drive you to the cell tower and tell you that the target is 2 km away from this cell tower, then I take out the map, draw 2 km long lines in four directions, and then make a circle.

Now we have a circle with a radius of 2 km, and I tell you that your target is at the edge of that circle. How useful would that be? Useless.

---

## Post 64 by @Camerart — 2024-07-07T08:16:19Z

Hi L,  
Ok, have it your way, but this is not as you describe.  
C.

---

## Post 65 by @anon46412288 — 2024-07-07T08:31:59Z

I guess that is one way to put it. (but also Google brought every non-Apple manufacturer to form Open Handset Alliance forward Android harder - There was a good chance that Symbian could have taken off had it not been for Android’s rapid development and Nokia’s ignorance of Smartphones)

---

## Post 66 by @session.fraction — 2024-07-07T10:41:15Z

The only Google products I use at this point are Maps and Photos, which I plan to phase out once I upgrade to an iPhone next year.

---

## Post 67 by @anon48875053 — 2024-07-07T10:44:52Z

Upgrade from what?

---

## Post 69 by @anon48875053 — 2024-07-07T11:02:44Z

> [@anon99860907](#):
>
> iOS devices are fine

They’re fine in terms of security, not overall.

---

## Post 70 by @anon63378630 — 2024-07-07T14:03:26Z

> [@anon48875053](#):
>
> Cellular towers broadcast their signal all around them, in all possible directions.

They actually use multiple directional antennas and the specific antennas that get used are known to both the tower and the device.  
This is used to refine location data.  
See [https://scdn.rohde-schwarz.com/ur/pws/dl\_downloads/dl\_common\_library/dl\_brochures\_and\_datasheets/pdf\_1/LTE\_LBS\_White\_Paper.pdf](https://scdn.rohde-schwarz.com/ur/pws/dl_downloads/dl_common_library/dl_brochures_and_datasheets/pdf_1/LTE_LBS_White_Paper.pdf)

> OTDOA is the positioning solution of choice when GNSS signals cannot be used due to a lack of a clear line of sight. OTDOA uses neighbor cells (eNB’s) to derive an observed time difference of arrival relative to the serving cell.

> OTDOA is the method of choice for urban and indoor areas, where (A-)GNSS will not provide its best or no performance at all. Another method for position estimation in LTE is Enhanced Cell ID (E-CID), based on Cell of Origin (COO). With COO the position of the device is estimated using the knowledge of the geographical coordinates of its serving base station, in terms of LTE the eNB. The knowledge of the serving cell can be obtained executing a tracking area update or by paging. The position accuracy is in that case linked to the cell size, as the location server is only aware that the device is served by this base station.

> [@anon48875053](#):
>
> Knowing the distance from one tower is completely useless.

You can actually get a fairly accurate location with just one tower:

> E-CID with estimating the distance from 1 base station.  
> In addition, the antenna array configuration has a key impact to the AoA measurements. Basically the larger the array, the higher the accuracy

---

## Post 71 by @anon48875053 — 2024-07-07T14:20:54Z

Any estimates on how accurate it can be? When only using one tower.

---

## Post 72 by @session.fraction — 2024-07-07T14:56:26Z

I have a Pixel 7 right now. i want to get iPhone 15

---

## Post 73 by @session.fraction — 2024-07-07T15:07:46Z

I’m sorry to hear about your app. I think it’s fun to tinker with devices but I feel like I just want something that works and I could reasonably expect some privacy from. I don’t feel comfortable using specifically Google products knowing that they donate to anti-lgbt lawmakers, promote hateful misinformation on Youtube and search, and run ads produced by influential hate organizations. Apple of course is not perfect either and has their own problems, but they are the next best option.

---

## Post 74 by @anon48875053 — 2024-07-07T15:15:32Z

Both Google and Apple are equally horrible.

This is only two days ago: [Apple shows how little they give a fuck about its users and removes leading VPNs from the Russian App Store](https://discuss.privacyguides.net/t/apple-shows-how-little-they-give-a-fuck-about-its-users-and-removes-leading-vpns-from-the-russian-app-store/19301)

[How Tim Cook Surrendered Apple to the Chinese Government](https://www.youtube.com/watch?v=Ev9_oDHNf-4)

[Apple Has a Slavery Problem](https://www.youtube.com/watch?v=5yqRZo4usjk)

[Apple is becoming an ad company despite privacy claims](https://proton.me/blog/apple-ad-company)

[How Apple uses anti-competitive practices to extort developers and support authoritarian regimes](https://proton.me/blog/apple-app-store-antitrust)

I’m barely scratching the surface here.

---

## Post 75 by @beantaco — 2024-07-08T03:10:38Z

> [@anon48875053](#):
>
> I also highly doubt that you need to worry about cellular triangulation. Especially if you have purchased your phone in cash and use a prepaid SIM card.

The risk might be low, but people who get caught in a geofence warrant can get into some [real trouble](https://www.nytimes.com/interactive/2019/04/13/us/google-location-tracking-police.html). Having an anonymous SIM/device (IMSI and IMEI) might help, but an anonymous SIM/device caught in a geofence warrant would get further investigation. An anonymous SIM/device is still trackable, and it would take changing IMSI and IMEI frequently (impractical) or staying in offline mode all the time (defeating the purpose of having a SIM) to prevent this. Further, it is impossible or extremely difficult to acquire an anonymous SIM in many jurisdictions these days.

Don’t forget Wi-Fi signals can be tracked too.

> [@Camerart](#):
>
> A distance circle around the tower most likely crosses only one house, and this is most likely yours.

> [@anon48875053](#):
>
> Cellular towers broadcast their signal all around them, in all possible directions.
> 
> If I drive you to the cell tower and tell you that the target is 2 km away from this cell tower, then I take out the map, draw 2 km long lines in four directions, and then make a circle.
> 
> Now we have a circle with a radius of 2 km, and I tell you that your target is at the edge of that circle. How useful would that be? Useless.

A 2 km circle wouldn’t be an impossible area to investigate (depending on how motivated and resourced the adversary is), so not completely useless, but, not very useful. Even a zero-thickness distance circle would unlikely cover just one house, and the radius estimated from signal power and round-trip time would have large error. Location estimated using multiple cell towers (multilateration) would have much smaller error. The more cell towers involved, the better the estimate.

Cell towers send and receive from all directions, but they are not purely omnidirectional. They have directional antennas fitted. Sets of three 120-degree antennas are common, in which case the location estimate approximates a 120-degree arc instead of a circle.

In urban environments, if you’re in range of one cell tower then you’re probably in range of another. If a phone in range of any cell tower, it would be foolish to think that it cannot be located.
