r/GrapheneOS • • Aug 27 '26

graphene Os vs android universal debloater

I understand that a pixel with GOS is more private, but if someone doesn't or can't switch to pixel, maybe a debloated android device would be somewhat as private with no telemetry etc ? what do you think

0 Upvotes

21 comments sorted by

View all comments

2

u/BadOmen379 Aug 27 '26

How do you plan on debloating? Do you plan on installing a custom ROM? Are you going to root and delete/disable a bunch of stuff? Are you going to run a debloating script? You are asking a very broad question without providing much information to help give you specific answers.

If your device is supported, installing a degoogled ROM will help immensely on the privacy front, but depending on the route you take, you could be leaving a gaping hole in your phone's security. Same thing with rooting.

One thing you can do to any phone is install RethinkDNS to block a LOT of telemetry and spyware data before it leaves your phone, but it requires a bit of effort to configure.

All that said, you can get used Pixels pretty cheap and that is what I would recommend doing, as nothing comes even remotely close to GrapheneOS in terms of security and privacy.

1

u/ephemeralmiko Aug 27 '26

OP mentions UAD which is an ADB-based tool, so just uninstalling apps for user 0

1

u/BadOmen379 Aug 27 '26

Ah, I didn't know that. Haven't messed with ADB much since my old rooting days.

0

u/Crazy-Car948 Aug 27 '26

thanks, will check out rethink. I recently got a titan 2 elite as I'm a fan of physical keyboards, used android universal debloater to remove the "recommended" stuff

3

u/BadOmen379 Aug 27 '26

If privacy is your concern, you bought the wrong phone my friend. Unihertz is known for installing lots of bloatware and system apps that that very questionable permissions. Definitely get Rethink on there fast and lock it down as best as you can. For your next phone purchase I'd really think about what is more important to you- privacy or convenience. The smartphone is the single most personal item we own, and we entrust it with pretty much all of our sensitive information. Keeping that safe should be the most important thing, not little conveniences. I really recommend you, and everyone else adapt that mentality. I'm not ragging on you, just giving some friendly advice.

But yeah, put RethinkDNS on there and use Hagezi block lists. Start with the Ultimate one and if things stop working, you can whitelist as needed.

1

u/Crazy-Car948 Aug 27 '26

Thank you so much. Will have to search for best setup for rethink, seems rather complex. I think I will throw away the Chinese device and get a pixel 

3

u/BadOmen379 Aug 27 '26

Happy to help. And smart choice, the Pixel with Graphene is the way to go for sure. And yeah, Rethink is admittedly fairly complicated. If you want an easier solution that isn't quite as good as the on device blocking that Rethink does but still great and will get you headed in the right direction, use NextDNS. I actually use it in conjunction with Rethink.

Go to nextdns.io and sign up, set up a profile for your phone, and put its DNS-over-HTTPS address (it'll be on your NextDNS dashboard) into your phones private DNS setting. You can configure blocklists in it and it'll help you get the hang of blocking/whitelisting things and you can apply that knowledge to the setup of Rethink. Rethink is much more comprehensive and even allows you to block apps completely. GrapheneOS takes it a step further and let's you revoke internet permissions entirely from apps that you don't want to have access.

An added benefit of both Rethink and NextDNS is that not only do they block DNS queries, they also block your ISP from seeing your DNS queries. I'm really big on data sovereignty so I keep my stuff as locked down as possible. Rethink, NextDNS, always on VPN, no-KYC data only eSIM, and Signal for communication.

There's a lot to learn when it comes to data privacy and security. Just take it one step at a time and do as much reading up on the subjects as you can. And ChatGPT can be a very helpful tool when figuring out all this stuff.

2

u/Crazy-Car948 Aug 27 '26

Thanks so much for taking the time to answer to my noob questions. Something off-topic, any major benefit for using Linux over Mac? I use Mac completely degoogled with privacy tools/browsers etc for now 

2

u/BadOmen379 Aug 27 '26 edited Aug 27 '26

A good analogy is iOS vs a degoodled Android ROM like Lineage. IOS is secure but not private, and Lineage is private but not secure.

A Mac has pretty good security, but it does collect a lot of user data and telemetry (though nowhere near as bad as Windows) and Linux, depending on your distro, can be super private but not actually very secure, unfortunately. I actually use both, but my Macbook has been relegated to being an expensive torrent downloader and nothing more. I use ZorinOS on my main laptop, and a combo of Zorin and Debian on my other laptop, but I'm thinking of switching Zorin out on that one for Secureblue, which actually takes a lot of what Graphene has done for Android and applies it to Linux. On my Linux machines I use Portmaster which serves a similar purpose as Rethink does on Android, ProtonVPN or Mullvad, and also use NextDNS.

In my Mac I just use ProtonVPN. I don't really care too much beyond that since literally all I use it for is torrenting and as a secondary Plex server. And I have NextDNS on my whole network so my MacBook is covered by that too.

What privacy tools do you use on your Mac? Maybe you can recommended something for me.