Google's business model is selling ads, all the data collection is so they can charge more for the ads they sell. The more you trust the platform, the more info you'll willingly give to Google, the more they can charge for ads. The more you trust your phone, the more you'll use your phone, the more chances Google has to collect information. They don't need to directly "spy" on you using means outside the normal data collection where you give them data. Thus, while I agree the "just trust me bro" attitude is borderline incompetence when it comes to security. I'm unconvinced that Google would take the risk of attempting to spy on anyone out of band.
The RTOS could be used to leak your location, the fact that you're using a VPN, any nonVPN traffic, and call traffic.
Yes, it could... so can the default software on android, and so can your ISP (DPI is shockingly powerful). But, what's the risk there? How does knowing the ratio of traffic I send and receive being VPN, or TLS encrypted expose me to additional risk?
So forgive me if I'm a little skeptical that Graphine OS.
Comments
Google's business model is selling ads, all the data collection is so they can charge more for the ads they sell. The more you trust the platform, the more info you'll willingly give to Google, the more they can charge for ads. The more you trust your phone, the more you'll use your phone, the more chances Google has to collect information. They don't need to directly "spy" on you using means outside the normal data collection where you give them data. Thus, while I agree the "just trust me bro" attitude is borderline incompetence when it comes to security. I'm unconvinced that Google would take the risk of attempting to spy on anyone out of band.
Yes, it could... so can the default software on android, and so can your ISP (DPI is shockingly powerful). But, what's the risk there? How does knowing the ratio of traffic I send and receive being VPN, or TLS encrypted expose me to additional risk?
I haven't looked in a long time so my memory is completely gone, but does GraphineOS not build their own Trusty OS image? https://android-review.googlesource.com/admin/repos/q/filter... What am I missing from why GraphineOS can't be trusted?
Afaik, Trusty OS is closed source.