I hear many people say that the Google Pixel is good for privacy, but is it?
I’m asking this because I find it weird, of all the companies, Google having the most “privacy”.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
Pixels get verified boot and bootloader relocking for custom roms like grapheneos as well, so you can be sure your device isn’t compromised even with a privacy respecting custom rom. I guess this is what most people refer to… Oh, and Pixels are probably going to get security patches for the kernel as well as the vendor blobs unlike many other vendors…
pixels have the highest hardware security of all Android phones, which increases privacy potential. assuming you keep the stock os and default Google settings, though, it’s about the same as any other.
Google also has good support for alternative OS’/Android forks, which is likely where that claim is leading to.
Google One is the marketing people are probably referring to for privacy.
The pixel has the default function for DNS over HTTPS and their Google One offering has a VPN to “protect” your data. Both of those are sold as privacy measures.
I see a lot of responses here seem kinda out of touch with the actual functionality of the phone and what marketing pushes Google does.
Google Pixel has the most support for security, which relates to privacy. It does “phone home,” but likely only to Google. Removing all the Google software and installing GrapheneOS further hardens the security and vastly improves the privacy by stopping the “phoning home.”
https://grapheneos.org/faq#future-devices
Who the actual fuck said this to you? Google is one of the worst companies for privacy.
I mean i guess with a pixel, you’re just being spied on by Google rather than Samsung + Google if you buy a samsung android, so in that sense, sorta? But saying a pixel is good for privacy in general is an absolutely ridiculous statement.
It’s because you install another OS on it
deleted by creator
Google Pixel hardware is focused on providing a private relationship between the user (your data and behavioral patterns) and Google.
Depending on your threat model you can flash custom roms to enhance your privacy and security posture.
A lot of folks here seem to be of the “…just flash GrapheneOS and you’re good…” crowd but it’s not that simple and there are trade-offs that impact usability and user experience.
There are a lot of interesting projects out there to choose from. Best advice is to work-up your real world threat model and do your reasearch.
You may find Louis Rossman’s experience with GrapheneOS relevant: https://www.youtube.com/watch?v=4To-F6W1NT0&t=1
Here’s a few links to help get you started - there are many android projects. I am not affiliated nor am I explicitly endorsing any of these projects.
CalyxOS https://calyxos.org/
LineageOS https://lineageos.org/
HavocOS https://havoc-os.com/
ResurrectionRemix https://resurrectionremix.com/
DerpFest https://derpfest.org/
PixelExperience https://wiki.pixelexperience.org/
GrapheneOS https://grapheneos.org/
I would add iodéOS to that list
https://iode.tech/en/
Then let each user choose what they like
Yeah the developer is very dramatic, but the project itself is still amazing. He did step down from lead, but the dude is a genius programmer. I’m still very confident on having it on my phone. I was using CalyxOS before, which I really like, but the sandboxed play services were a really killer feature for me on GrapheneOS.
Just install GrapheneOS. The only things that don’t work on it are Google Pay and Android Auto.
I’d argue yes.
I see Google as a known unknown, where as various other Chinese phones are unknown unknowns.
I acknowledge I have western bias, but the propaganda, human rights violations and control of the CCP is well understood.
At the very least Pixel let’s you flash an alternative OS.
Basically every Chinese phone has a great custom rom support
Xiaomi phones used to be good for custom ROMs, but now they try to stop you unlocking the bootloader by making you wait an unreasonable amount of time after first registering the device with them before you can unlock. Many of the other vendors are even worse.
So from that perspective, Pixel devices are not a terrible choice if you are going to flash a non-stock image.
Waiting a bit has been normal for years already. And it’s not a big deal at all. It’s to stop reselling the phones
Wait times are as high as 2 months (depending on how old the phone model is, etc…), and even as a regular Xiaomi customer, their support never seem to allow anyone to skip the wait, even if for example they broke their old phone and want to set up a new one like the old one (ask me how I know). During that period, MIUI is like a data collection honeypot, sucking up your PII and serving you ads.
It might be ‘normal’ now to Xiaomi customers to wait to be able to unlock the phones that they have paid for and own (perhaps in the same sense someone in an abusive relationship might consider getting hit ‘normal’ because it has been happening for a while), but the idea that the company who sold you the phone gets some say on when you get the ‘privilege’ of running what you like on it, and make you jump through frustrating hoops to control your own device, is certainly not okay.
If they just wanted to stop reselling phones with non-Xiaomi sanctioned malware / bloatware added, making the bootloader make it clear it is unlocked (as Google does, for example) would be enough. Or they could make a different brand for phones that are unlocked, using the same hardware except with a different logo, and let people choose if they want unlocked or walled garden.
However, they make money off selling targeted ads based on information they collect - so I’m sure that they probably don’t want to do any of those things if they don’t have to, because they might disrupt their surveillance capitalism.
Ok, wall of text aside. Now I’m sure you’re bsing. It’s never been 2 months or even longer. Literally every Xiaomi or Poco is that you register and then you wait 1 week and then unlock with the pc. No weird ass wait times. You don’t even have to use it. I have done this for like 8 models old and new already. The Mi unlock app doesn’t even have software for other times.
Also the bootloader does display that it’s unlocked. But even with a ‘warning’ most people wouldn’t care and that’s what Xiaomi still wants to prevent.
Here’s another source about 2 month wait times sometimes, if you don’t believe me: https://www.xda-developers.com/xiaomi-2-month-wait-unlock-bootloader/. It has never personally been 2 months for me, but it has been over a week before for me, and their support team refused when I asked nicely to shorten it despite the fact my daily driver phone was broken and I couldn’t restore my LineageOS from backup - I just had to wait. That’s why I don’t buy Xiaomi stuff any more.
The wait time is determined by their servers, which sends a cryptographically signed certificate specific to the serial number of the device that the bootloader reads. The key to sign the certificate stays on their servers, and the client just calls to the server, and either gets a response saying to wait for this much longer, or containing the certificate. Xiaomi explicitly call it ‘apply for unlocking’ (e.g. see the title of https://en.miui.com/unlock/index.html), as in, they think it is their right to decide who gets to decide what runs on my hardware I’ve bought from them, and us mere consumers must come begging to them and ‘apply’ to unlock.
The bootloader is designed not to boot anything except MIUI without the certificate from the unlocking tool. While there are open source clients (like https://github.com/francescotescari/XiaoMiToolV2) they still work by calling Xiaomi’s server to get the unlock code, so if you want to run anything except Xiaomi’s MIUI (which is a bad idea from a privacy perspective), you kind of do have to use it (at least their server). The only way around it would be if someone found a vulnerability in the bootloader or the processor itself that allows for the ‘treacherous computing’ aspect of the boot to be bypassed without the certificate - and as far as I’m aware there isn’t a reliable approach yet for that.
Graphene only supports Pixels officially because of how easily you can unlock the bootloader
it’s because of the Titan M chip, not because of ease of bootloader unlocking. Pixel’s have much higher hardware security with only iPhones and their secure enclave matching it afaik.
That’s not the only reason, you can also unlock the bootloader of a FairPhone very easily and they’re still not supported.
And rootkits on the chips. If not now then when.
Here’s your tinfoil hat
I LOVE GRAPHENEOS
Yes, it is. I mean, GrapheneOS is the gold standard for privacy&security, but even stock Pixel is a good step up. Think of it like this: on stock Pixel, only Google is tracking you, not Google + Samsung, or Google + Xiaomi. Just Google. It’s guaranteed to be a step up from all other Android phones, stock or not.
Wow the fact that this is considered good is depressing
Wait since when a monopoly is preferable to a duopoly? As far as I’m concerned if I can’t have 0 companies to spy on me I’d rather have them all fight each others in the data space…
In this case they don’t fight, they exploit your data in different ways and if one of the exploiters isn’t arsed to keep your data secure then everyone gets it and it’s not just corporate actors profiting from you but more harmful actors including scammers using your data.
Technically it is just better than the worst possible case, which is two companies or more spying on you instead of one that was already spying on you. It is still bad but better than the worst case.
Google claims to do some processing on their own tensor chip locally so it might reduce some data being sent to Google, but it doesn’t limit them from tracking you. With Pixel, you are only being tracked by Google and not Samsung or other manufacturer
Not sure how I should feel about that. It’s highly likely any party engaged in tracking activities will try to grab as much data as they can. So a non-Google device seems like it would be doing twice the amount of data collection.
But considering Google also controls the hardware design of the Pixel, it wouldn’t surprise me if they have some additional tricks up their sleeve.
What we really need is a full open-source phone, including firmware. Maybe we’ll get there one day.
Yeah. I thought it was weird, but the stock Pixel is very secure, and if you install Graphene OS, it is even more so. Additionally, Graphene OS sandboxes The Playstore Apps, and gives you much more control over what the Apps you install are allowed access to. You have to go way out of your way to make it less private than the stock OS, and you pretty much can’t make it less secure than the stock OS.
You can get almost anything that works on the stock Pixel working on Graphene OS except for Google Wallet and the Android drive app. Banking Apps work, Google Apps work (but you might as well try to use alternatives).
I had an iphone for years, but after using Graphene OS for the past 3 months, I can honestly say I’ll do everything I can to not go back.
GrapheneOS on a Pixel 7 is one of the best decisions I ever made. You can sandbox the shit out of all apps and granularly control the permissions in addition to outright cutting off network access to apps that would otherwise be doing background telemetry garbage all the time.
If you’re terminally online and just can’t imagine life without all the first party Google apps, you’ll disagree with me. But otherwise it is a great decision. F-droid and Aurora Store are awesome. (You can still manually install and use stuff like the Google camera app, Maps and others. Just never sign in to first party G Apps, be careful with your permissions etc. and you’ll retain 90% of the functionality while not having the privacy downsides.)
I’ve been using LineageOS+MicroG with very little google software (only maps) and it’s been working great. Any reason I should switch to Graphene? I noticed the main dev seemed to have some disputes and interesting personality characteristics, so I was a bit hesitant to adopt. I also had an irrational “I wouldn’t be surprised if 3 letter agencies are involved” vibe about Graphene, but nothing concrete.
removed by mod
That’s quite a statement, are you sure about that? The Graphene team has done a considerable amount of work sandboxing the environment of Google Play, both in memory, permission structure, and IO access that MicroG completely blows past. Given how the Graphene sandboxing works, I actually can’t think of a scenario where the statement that MicroG is more private than Graphene sandboxed Google Play. In either scenario you don’t have to log in, so I’d much rather have an environment that has been isolated than tooling that still has tendrils reaching into the main OS itself (MicroG).
Yeah one important key is not logging in. If you use Aurora store to install apps, and don’t log into any Google apps, Google can’t be certain of your identity enough to tie it to your previous Google account. I guess they could probabilistically match you based on stuff like your location in Maps app vs. a previous normie device known to be “you”.
One thing I’d like to test is the implications if you log into Gmail on the hardened Vanadium browser and then log out. I would think it would still be pretty safe on Graphene because Google would have no access to other apps activities on the device and even location requests don’t get routed to Googles geolocation service unless the user specifically turns that back on.
Does the Gmail app work in grapheneOS?
Gmail will work fine, including push notifications, assuming you enable Google Play Services. Using either will of course come at the cost of privacy.
Yes it should although you may not get notifications of emails. I’d use ProtonMail or Tutanota instead anyway.
Not the stock os. You need to flash something else and relock the bootloader to take advantage of the pixel