Both of my banking apps work fine with a rooted GrapheneOS phone. If you want to have full control over your phone like you would a Linux laptop, to customize it to your own preferences and maximize privacy, there is nothing else gives you the same amount of control over the device that you bought and paid for.
The fact that people pay $1000 for a device and then not be able to fully uninstall pre-installed crapware nor fully block it from the internet is depressing.
Personally I reject with extreme prejudice the android security model (it's my &#^@ device not the vendor's). But I don't generally want to grant any apps root. Lineage strikes a nice balance by providing root adb.
Moreover, most of root tools and ROMs are rather poorly written and glued together with other forum scripts which you have no way of checking if they're not malware. (There are exceptions.)
So no, "safe" it's not and never has been. The tradeoff might be worth it for you as a user though.
> The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).
The way to do that is to take the hit and recreate your 2FA codes in an opensource app like Aegis or Stratum.
Data is broken on both sides of the port? (if you rotate the plug 180° it should use the other pins on the USB-C)
(probably the broken USB port)
https://xdaforums.com/t/the-holy-grail-universal-no-bl-root-...
Side note, it's quite ironic, google being so heavily anti-root is forcing people to opt for root access via more hidden ways, making it easier to avoid root being detected.
(but would love to verify and use)
Apple makes $200B per year from selling the iPhone alone. Plus the services they sell on it, plus deals like the one with Google, plus app store ads, plus cross-selling of other hardware ...
I have one too.
Not because I like the hardware too much. Pixel phones are much nicer, they don't wobble when you put them on a table. Not because I like the software too much. Android is much more to my liking with more freedom to customize it.
But because I have the feeling Apple takes security more seriously.
I wish there was some kind of security arena like there is LLM arena for AI. That gives hard facts about the security track record of phone manufacturers.
So far only Apple achieved this by ensuring a walled garden around their ecosystem, securing additional revenue-share for every single 3rd party app and every transaction of the user.
All other vendors are structurally prevented to properly compete in services, and have to rely on Google paying some minor revenue-share on Services, while having only limited control over the user-experience to distinguish themselves...
Nope nope nope. LLMs helped you do something cool, great. You can still speak for yourself. Stop outsourcing your humanity to a chatbot.
> In practice the coverage of each chain is exactly the set of devices the OEM chose to ship the vulnerable component on.
Wonderful insight, Claude. "The vulnerability covers exactly the devices that are vulnerable".
Not being able to update an app on it is a rarity.
What we're seeing is marketing/branding and a genuine for-show effort, all the while they do not audit their code outside some for-show technologies (Siri AI in the cloud).
So the point I am making is that it's all observational bias. You want actual objective security, use GrapheneOS.
And I'm saying this as an iPhone user.
I personally prefer seeing real advancement that integrate both hardware and software like their EMTE[1] which no other vendor has had the balls to implement.
And I say that as a GOS user! My next phone will definitely be an iPhone, mostly because I cannot deal with the terrible Tensor SOC. My G4 overheats for nothing! Shameful
[1] https://security.apple.com/blog/memory-integrity-enforcement...
This might make Apple look like the more secure option but the reality may be different because Android is more scrutinised.
If you are sceptical consider these examples: (1) some versions of Apple silicon have unpatchable security defects, (2) Apple at one point decided to not contact up to 500M users affected by a supply chain attack in China due to "language difficulties".
I didn't find about OEMpocalypse from Google talking about their security issues, I found from calif.io. Security researchers don't wait for companies to "talk about their security".
> but the reality may be different because Android is more scrutinised.
This is famously why Linux appears to be less secure than Windows, right? Because Microsoft doesn't talk about their security while Linux is more scrutinized?
> In the simplest of terms, with the bug, if you created a new APFS (Apple File System) encrypted volume on High Sierra, and set anything at all as the password hint, then your password was stored as the hint. In plain text.
But Google phones had those too.
That's why I said I "feel" like Apple takes security more seriously. And that I wish there were hard facts. Statistics of number of bugs by severity. Independently verified.
Realistically intelligence agencies aren’t too interested in my grandma, but malware/scams/bloatware absolutely are.
--> If the total potential is an increase in sales of 100k units at ~450 USD/device, there is no fiscal justification for a stock-trading company to actually build such a product. That's why e.g. the EU keeps mandating more and more of this, they "artificially" create the need for it because the market doesn't do it itself.
2. They don't have a comparable service revenue-ecosystem to Google, not even remotely.
Even in sum across their entire mobile ecosystem, the majority of service-revenue their products generate is actually Google's service revenue of the Android ecosystem, of which they get a miniscule revenue-share via Google's RSA program.
The only substantial revenue is still generated at the hardware time-of-sale only, which needs to finance the lifecycle maintenance of the product. So the objective becomes to sell a critical-mass of hardware to sustain the maintenance of the device.
And then, the next level: The market-pressure for in-time software-maintenance can only be fulfilled by not deviating too much from Google's baseline (minimizing the effort of upgrading to newer Android versions). Not deviating from Google's baseline means either contributing back any disruptive changes to Google for integration in the baseline or (more likely) to not disrupt the smartphone landscape on platform-level at all.
Disrupting with hardware innovation only works either on very-large scale or on small-scale, because either you can contract a component supplier for a huge volume of a component exclusive for you, or you pick a innovative component which cannot be supplied in huge quantity yet (and is therefore out of reach for larger brands)
As result, the established players on the smartphone market don't make any more innovative leaps, because the risk/benefit ratio for the ROI is just not there.
--> Vendors ship devices based on common hardware available at that time, combined with software available at that time.
Chinese vendors changed the game a bit by announcing devices with innovative hardware which then never reached the global market, because the components were not available at-scale yet (under-display camera, wrap-around displays, new battery composition, 5G,...) --> This was a game-changer because e.g. Samsung, Apple, Motorola, LG would not announce a device they knew they can't launch at-scale. Oppo, Xiaomi et al could do a limited run for a device-launch in China, with chinese component-suppliers shipping to assembly-factories in China with low ramp-up costs.
So the difference isn't about taking things "more seriously", but in the fact that you take marketing from Apple more seriously.
That's not the same.
(Note: There's plenty of proof that Apple does take security more seriously than Samsung, Xiaomi & Co. in the article, but your feelings aren't it.)
The secret looks something like this:
JBSW Y3DPF QQHO ....
(usually fairly short unless its google)
Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate
Longer support windows are possible and would mean people wouldn't be left behind without updates for problems like this.