• 0 Posts
  • 7 Comments
Joined 1 month ago
cake
Cake day: July 27th, 2026

help-circle

  • I have two phones which is only because I wouldn’t be upset if this phone was stolen or lost or broken unlike my main phone. My travel phone is an older and cheap Google pixel phone on which I installed Graphene. I use it regularly to read books from my local library. I do not bring it with me anywhere other than travel. On this phone I also:

    • Do not log into anything other than the library app which uses a random username as the login. No email or anything attached to it beyond my home address.
    • Ensure that ADB is NOT enabled.
    • Require a pin to unlock the phone. No biometrics alone. Ever.
    • Install signal for all communication. Lock it behind a pin that is not my phone unlock pin.
    • Any and all files that I create on this device have their exif stripped and are automatically encrypted using automation software then sent to my S3 bucket or home server depending on the nature of the files and their size after I connect to wifi somewhere.
    • Transfer my service plan to this device.
    • Install apps only from obtanium that are verified to match the hash signatures from the distributor.
    • The phones drive is encrypted
    • While in line for TSA I turn the phone off to which it will remain until I am at my gate.

    I have had issues in the past with TSA and my phone with a “random” search. They requested I unlock my phone. I did not, and requested a warrant and will not speak more than my rights and that I will only speak through legal counsel should they be able to produce a warrant. They searched me and my belongings over the course of a few hours. They can eat my ass.

    In addition all of my personal machines including my steam deck and my laptop are also encrypted and secured using FOSS software including Linux as the OS. I have nothing to hide, but I’m also smart enough to not provide them with anything they could twist out of context or use against me.






  • Depending on what you value and expect from a “more” private device than the main hardware brands and their software these are not particularly secure physically, and to some extent via software. It’s somewhere between pixel flavor of Android and grapheneos. Steps in the right direction. I will be watching for future versions especially as they come to be viable in the US.

    Little reading on what I’m referring without a deep (and albeit opinionated) dive by the graphene team on the hardware, and similar but done by other teams for sailfish specifically.

    https://hivesecurity.gitlab.io/blog/jolla-phone-privacy-threat-model-2026/

    Edit: That is opinionated as in the architectural decisions and trade offs made to reach a certain level of protection not as in bias or “opinions”. Aka software usage of opinionated in the way that a framework might be.

    Edit Two: Listed graphene as the high end of security for our current offerings in the consumer space that are still considered full featured smart phones. iOS is also a contender, but they aren’t as concerned with privacy as grapheneos is. They are a business first. Privacy for them while it does exist is a means to an end. Marketing doing it’s thing.