In the GrapheneOS forum, I encountered a claim that F-droid is insecure (and not good at privacy as well). These links (and more) were given as an evidence:
- https://privsec.dev/posts/android/f-droid-security-issues/
- https://xcancel.com/GrapheneOS/status/1883895255142932816#m
- https://github.com/obfusk/fdroid-fakesigner-poc
While there are some attitude against FOSS app, I think the arguments are generally sound and in good-faith. Which makes me confused, as I've been hearing good words about F-droid in lemmyverse.
I am not good at assessing arguments, so I want to ask you guys for more aspects and information.
Also, if not F-droid, what should I use? Is Aurora store, a frontend of play store, not fine to use as well?
My current phone is 7 years old, does not support recent android versions, and battery life is becoming atrocious.
This feels like right time to change my phone.
Currently, I know of & am considering 3 options:
- Google Pixel
- iPhone
- Samsung Galaxy
I heard that Pixel is the best choice for privacy, despite it being Google^TM. Should I go with it, and install Graphene OS or similar options? The very fact that the name "Google" is attached makes me nervous. Also, I don't think I can trust android, so I would have to install Graphene OS or the like. In the case, app support would be lacking, though.
I am considering iPhone as well, since it has "reputation" of being secure. Of course, Apple can access my data, but that might be a good enough compromise? Honestly, I don't know. It's the best supported option as well - lots of apps support iPhone.
Galaxy is just the one that I am the most familiar with (my current one is Galaxy S8). I don't trust it, though. Do they even make good hardware nowadays?
EDIT: Turns out, Pixel phones are poorly supported by local telecomm companies. It is relatively cheap though. Still worth it?
EDIT2: I heard that data & message is fine, but the call quality is impacted by lack of VoLTE compatibility.
It might still be possible to compare ciphertexts and extract information from there, right? Welp I am not sure if the whole scheme is secure against related attacks.
Yeah, the problem is with the one banking app I frequent.