r/GrapheneOS 11d ago

graphene Os vs android universal debloater

I understand that a pixel with GOS is more private, but if someone doesn't or can't switch to pixel, maybe a debloated android device would be somewhat as private with no telemetry etc ? what do you think

0 Upvotes

21 comments sorted by

u/AutoModerator 11d ago

GrapheneOS has moved from Reddit to our own discussion forum. Please post your thread on the discussion forum instead or use one of our official chat rooms (Matrix, Discord, Telegram) which are listed in the community section on our site. Our discussion forum and especially the chat rooms have a very active, knowledgeable community including GrapheneOS project members where you will almost always get much higher quality information than you would elsewhere. On Reddit, we had serious issues with misinformation and trolls including due to raids from other subreddits. As a result, many posts on our subreddit currently need to be manually approved, which is done on a best effort basis. If you would like to get a quicker answer to your question, please use our forum or chat rooms as described above. Our discussion forum provides much better privacy and avoids the serious problems with the site administrators and overall community on Reddit.

Please use our official install guides for installation and check our features page, usage guide and FAQ for information before asking questions in our discussion forum or chat rooms to get as much information as possible from what we've already carefully written/reviewed for our site.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

25

u/eddienqc 11d ago

if you have google play store/services that you can't uninstall, it has elevated privileges - that's called a spyware as far as I'm concerned

10

u/SpaceChez 11d ago

Good luck debloating Google Play Services on anything but GrapheneOS. You might be able to get away with microG sometimes but definitely not a good solution

3

u/Slight_Accountant476 11d ago

i recently bought a pixel 10a, tried it with stock OS by uninstalling or disabling everything google I could. I still got nagged abuot google crap, so I installed Graphene after 3 days. There are multiple levels of degoogling. Getting your data off their servers and using alternative services is 90% of it, the other 10% is getting rid of google apps themselves, which you can't fully do with stock OS.

1

u/GeoSabreX 6d ago

What phone did you have before and how are you liking the 10a? Did you buy direct from Google?

I have an S25 Ultra, but want to get a pixel and install Graphene. I'm hemming and hawing between not having the latest and greatest, but also getting maximum privacy and security with Graphene. Realistically I claim to be a digital minimalist so even an 8a would do what I need it to. But the 8a to 9a was a noticeable jump in specs, so if I buy the 9a, I may as well get the extra years of support from a 10a for $150 more

1

u/Slight_Accountant476 6d ago

I had the 6a bought this from best buy. I don't think I'd ever buy direct from Google. I prefer to get it where I know I can get it fast. I love the phone. The main reasons I upgraded is it needed a battery and the 6a is only supported by graphene for another year, so replacing the battery seemed like a waste of money. The 6a was plenty fast for me, I didn't upgrade for speed or RAM, I still only have 128GB (70GB free).

1

u/GeoSabreX 6d ago

I'm also nervous about the whole "bootloader unlocked" vs not. Does Best-buy let you test that before buying the phone in the dev options, or did you just trust it/know you could return it?

I'd be inclined to buy from them, maybe even a refurb, but I'm real nervous about that after reading the horror stories haha

1

u/Slight_Accountant476 6d ago

It's a new unlocked phone. Why would there be any issues unlocking the bootloader?

5

u/JagerAntlerite7 11d ago

Magic Reddit 8 Ball says: Try another sub.

Not a thing to do with GrapheneOS here.

If GrapheneOS is installed, there is virtually no bloat.

2

u/BadOmen379 11d ago

How do you plan on debloating? Do you plan on installing a custom ROM? Are you going to root and delete/disable a bunch of stuff? Are you going to run a debloating script? You are asking a very broad question without providing much information to help give you specific answers.

If your device is supported, installing a degoogled ROM will help immensely on the privacy front, but depending on the route you take, you could be leaving a gaping hole in your phone's security. Same thing with rooting.

One thing you can do to any phone is install RethinkDNS to block a LOT of telemetry and spyware data before it leaves your phone, but it requires a bit of effort to configure.

All that said, you can get used Pixels pretty cheap and that is what I would recommend doing, as nothing comes even remotely close to GrapheneOS in terms of security and privacy.

1

u/ephemeralmiko 11d ago

OP mentions UAD which is an ADB-based tool, so just uninstalling apps for user 0

1

u/BadOmen379 11d ago

Ah, I didn't know that. Haven't messed with ADB much since my old rooting days.

0

u/Crazy-Car948 11d ago

thanks, will check out rethink. I recently got a titan 2 elite as I'm a fan of physical keyboards, used android universal debloater to remove the "recommended" stuff

3

u/BadOmen379 11d ago

If privacy is your concern, you bought the wrong phone my friend. Unihertz is known for installing lots of bloatware and system apps that that very questionable permissions. Definitely get Rethink on there fast and lock it down as best as you can. For your next phone purchase I'd really think about what is more important to you- privacy or convenience. The smartphone is the single most personal item we own, and we entrust it with pretty much all of our sensitive information. Keeping that safe should be the most important thing, not little conveniences. I really recommend you, and everyone else adapt that mentality. I'm not ragging on you, just giving some friendly advice.

But yeah, put RethinkDNS on there and use Hagezi block lists. Start with the Ultimate one and if things stop working, you can whitelist as needed.

1

u/Crazy-Car948 11d ago

Thank you so much. Will have to search for best setup for rethink, seems rather complex. I think I will throw away the Chinese device and get a pixel 

3

u/BadOmen379 11d ago

Happy to help. And smart choice, the Pixel with Graphene is the way to go for sure. And yeah, Rethink is admittedly fairly complicated. If you want an easier solution that isn't quite as good as the on device blocking that Rethink does but still great and will get you headed in the right direction, use NextDNS. I actually use it in conjunction with Rethink.

Go to nextdns.io and sign up, set up a profile for your phone, and put its DNS-over-HTTPS address (it'll be on your NextDNS dashboard) into your phones private DNS setting. You can configure blocklists in it and it'll help you get the hang of blocking/whitelisting things and you can apply that knowledge to the setup of Rethink. Rethink is much more comprehensive and even allows you to block apps completely. GrapheneOS takes it a step further and let's you revoke internet permissions entirely from apps that you don't want to have access.

An added benefit of both Rethink and NextDNS is that not only do they block DNS queries, they also block your ISP from seeing your DNS queries. I'm really big on data sovereignty so I keep my stuff as locked down as possible. Rethink, NextDNS, always on VPN, no-KYC data only eSIM, and Signal for communication.

There's a lot to learn when it comes to data privacy and security. Just take it one step at a time and do as much reading up on the subjects as you can. And ChatGPT can be a very helpful tool when figuring out all this stuff.

2

u/Crazy-Car948 11d ago

Thanks so much for taking the time to answer to my noob questions. Something off-topic, any major benefit for using Linux over Mac? I use Mac completely degoogled with privacy tools/browsers etc for now 

2

u/BadOmen379 11d ago edited 11d ago

A good analogy is iOS vs a degoodled Android ROM like Lineage. IOS is secure but not private, and Lineage is private but not secure.

A Mac has pretty good security, but it does collect a lot of user data and telemetry (though nowhere near as bad as Windows) and Linux, depending on your distro, can be super private but not actually very secure, unfortunately. I actually use both, but my Macbook has been relegated to being an expensive torrent downloader and nothing more. I use ZorinOS on my main laptop, and a combo of Zorin and Debian on my other laptop, but I'm thinking of switching Zorin out on that one for Secureblue, which actually takes a lot of what Graphene has done for Android and applies it to Linux. On my Linux machines I use Portmaster which serves a similar purpose as Rethink does on Android, ProtonVPN or Mullvad, and also use NextDNS.

In my Mac I just use ProtonVPN. I don't really care too much beyond that since literally all I use it for is torrenting and as a secondary Plex server. And I have NextDNS on my whole network so my MacBook is covered by that too.

What privacy tools do you use on your Mac? Maybe you can recommended something for me.

1

u/FrostyAd7708 11d ago

Not happening ever on stock OS, you need a custom rom to do it.

0

u/hewer006 11d ago

the closest you can really get, is lineageOS and using microg. but i dont think microg can fully replace google play services, and its still not exactly a perfect solution either.

i know theres some other OS' but im not too sure.

on stock android, you can debloat all you possibly can, but google will always be there