De-Googling my phone
piware.de
piware.de
yes, its a devils-advocate position. You might (for instance) have high trust because you know them from hacker traeff you've been on, f2f. I can't have this a-priori knowledge.
From here, this looks no better than "trust google" and in some dimensions looks significantly worse. Of course for the primary goal of "distrust google" it works very well.
(well done btw, its a good, complete list, and has apps I think I too would put on my need-list)
Google: track every detail of your life and use it to serve up ads that support their bottom line. Implements changes that serve themselves at your expense.
F-Droid et al: build cool open-source software cause they like cool open-source software. Implements changes because they make the software better.
2. You may only use apps Apple approves. So no Firefox for you.
This effectively means that Firefox on iOS has no support for extensions or addons like on Android... Because Apple and Safari doesn't allow that.
It's definitely not what people have come to expect from Firefox over the years, but at least I get to seamlessly sync my bookmarks, history and passwords with my desktop browser of choice.
Google’s ecosystem is just as negative as apples walled garden. If you want, you can build and sign your own apps and put them on your device on an iPhone.
> And have to deal with whatever they remove from the next iteration of the device based on their whims and fancies.
I presume you’re talking about the headphone jack, which google followed up by removing from their pixel phone 12 months later? Why does apple get the hate here and not google?
> And the exorbitant price tag.
An iPhone 8 is £699 new right now, and a pixel 2 is £629. An 8 is £48 a month, and a pixel 2 is £53/month on contract (I’m sure there are better deals but I’m on a phone) - it’s disonfeuous to call apple out for having expensive Hugh end devices when the google equivalent is just as expensive.
Off topic. Using F-Droid, you don't need to touch Google's ecosystem.
Absolutely. I still don't get why I can't compile and deploy my own apps on my own devices without paying Apple $99 a year.
I thought it was really cool that you can deploy apps you compile yourself on your device out of the app store without paying the $99 yearly fee but apparently that's not the case.
https://hn.algolia.com/?query=free%20provisioning&sort=byPop...
> There are three levels: $300/yr for "enterprise" allows you to deploy your app on a large number of devices within your organization (and the terms of service are very explicit that the devices must be under your control: not even for testing by a customer at an off-site location unless you are overseeing), $100/yr for an individual or company normal developer license that lets you install your app for testing purposes on up to 100 of your devices for one year (after which point the apps expire and you have to reinstall them), or $0 for truly "free" provisioning (no yearly fee) which lets you install up to three apps (total; not per account: across all free accounts any device can have only three such apps) on a device using a slightly limited set of APIs (for example: no VPN support) which expire every seven days.
> Clearly the free tier is pretty worthless in the grand scheme of things, and being able to write software for you but not being able to legitimately give it to anyone else not also paying the $100/yr "please let me own the piece of hardware you sold me instead of renting it" tax is not really acceptable for people trying to learn to write software as a big part of software is being able to give it to other people. In practice, though, a lot of people are seriously only learning to develop so that one day they can pay the full Apple developer tax and deploy their apps to the App Store under the Apple software approval process, and so it works out: like, to them, software development is all about writing software for Apple hardware under Apple's rules, and that's what Apple wants anyway. The entire scenario makes me feel a little sick: this shouldn't even be legal as far as I'm concerned.
That is the case.
HA! Sure. For $100 a year. And from a Mac.
> I presume you’re talking about the headphone jack, which google followed up by removing from their pixel phone 12 months later? Why does apple get the hate here and not google?
Because Pixel is not the only choice one has inside the Android ecosystem, as opposed to iOS one? Samsung, Sony and others still have the jack afaik.
I agree with you about price though. Apple is no more expensive than others (considering the quality of build).
There is a caveat however, you have to resign it every seven days.
Edit: I also want to say there’s a limit to the amount of apps you can do this with.
It’s not a great solution, but I have a feeling it’s as good as we’ll ever get.
And compiling every app, I'm guessing?
On Android you just download the damn package and install it on the devices.
I would have switched to iPhone if it weren't for that.
You need to trust Apple. What makes you think you can trust them? Remember that Google started life with 'do no evil' as their motto, people tended to trust them as well. Lately, not so much anymore.
If you don't feel these issues are valid or think they don't matter Apple can be an option but it does not make sense to portray them as the solution which 'just works'.
I think you're missing the part where a user benefits from their services.
I mean, it's not as if users get nothing out of this arrangement. The vast majority of users feel they're getting a good deal. Just because you don't think it's a good deal for you, don't impose it on others.
Google Home Page and Reader are the big two... both extremely popular, and plenty of opportunity there. Hell, at this point, I'd like to see Google offer a website similar to what I get on my phone's new tab screen now (articles of interest). I find it hard to actually trust any google services beyond search and gmail (only hoping they don't nix gmail without a LOT of notice).
That said, by my quick count, only about 18% of the F-Droid packages are reproducible right now.
nokogiri https://verification.f-droid.org/ -e '$_.css("a").each{|a|puts a.text}'|sed -n 's/\.txt$//p'|sed 's/.*\.//'|sort|uniq -ct. annoyed german
One gains knowledge, not trust, from studying governance and audit structures.
> From here, this looks no better than "trust google" and in some dimensions looks significantly worse.
In what concrete way(s)?
How does a bad app get removed? Who decides? When?
https://www.zdnet.com/article/phony-android-security-apps-in... https://blog.malwarebytes.com/cybercrime/2017/11/new-trojan-... https://thehackernews.com/2017/12/google-playstore-malware.h... https://thenextweb.com/hardfork/2018/04/20/google-play-crypt...
Are we lacking a UI? Kernel? Apps? Interest? Interface with existing closed-source apps? Is stock Android too good?
I recently bought a Nexus 5 for the purpose of running Ubuntu Touch. It arrived yesterday and I look forward to try Ubuntu Touch on it.
But a huge part of why I liked the N900 was the physical keyboard. What is the puri.sm stance on that?
A lot of hardware support on these devices is proprietary in some way. Mostly proprietary firmware, some proprietary kernel drivers and some proprietary userland daemons or drivers.
Most hardware doesn't have support in the mainline Linux kernel, u-boot, mesa etc.
These are improving slowly as people do reverse engineering of proprietary components and the FLOSS enthusiast community does the work of getting hardware support mainlined. Some vendors also do mainlining work too and some employ folks to work on FLOSS drivers (Broadcom RPi VC4/VC5 for example).
Some related links are gathered on this page:
really. we are back to being limited to one OS because of drivers.
this is also the reason lineageOS and other android roms can't just keep updating older phones to new releases. they need the oem to upgrade so they can extract drivers from the binaries.
So now, for each device, you have to port desktop Linux [3] to whatever generation kernel it came with.
Debian, in contrast, can assume that you're using the standard modern kernel.
[1]. I mean that it should work as a phone, not just a small tablet. So if it can't make phone calls, it ain't a phone. All the more so if you want a working GPS and Camera.
[2]. I would have said Gnu/Linux but postmarket is based on Alpine which is based on busybox/muslc and not gnu.
[3]. Anything which issues syscalls is fair game, so, for example, if your oldest phone you want to maintain is six years old, then you have to back port every single program (and library!) to work on a random seven year old kernel.
Even back porting android user space (which is mostly Java and doesn't interact directly with the kernel) is a huge pain (and sometimes is actually that hard that the maintainers just give up). Porting back Debian?
Replicant is working on creating a fully free software distribution of Android, rather than trying to provide a desktop-style Linux.
Porting programs isn't generally a huge deal. Most devices on postmarketOS currently use the old downstream kernel, and most things run fine on it.
The main problem is that a lot of peripherals require closed source drivers and firmware. For instance, very few devices have support for hardware-accelerated graphics or wireless connectivity, both of which are necessary on a mobile device.
A lot of the issue is that most devices have poor, if any, mainline kernel support. That means you have to rely on the downstream vendor kernel, which is almost always hopelessly out of date. (For instance, the downstream kernel for my OnePlus One is at 3.4 from 2012.)
Besides just being out of date, the vendor kernels require binary drivers and Android-specific services to use a lot of peripherals. For instance, the graphics driver Freedreno is compatible with my OnePlus One's GPU. However, Freedreno isn't compatible with the version of KGSL that the downstream kernel supports. That meant that my only options, if I wanted hardware-accelerated graphics, were to use Halium or mainline my device.
That's not even getting into bringing up WiFi, LTE, and actual phone capabilities, which are still a ways out as far as open source software is concerned.
its "if you know people, maybe you are safe to use what they do" not "because you don't know x use y, you don't also know.
ie, I "know" as much about google, as I do about debian people
(btw, I run a lot of debian hosts. I also run google cloud hosted stuff)
I dont trust anyone working with debian or google.
but debian I can be sure if someone saw a bug/malware happening or in the source, I'd benefit from that. with closed systems the source option is gone. also nobody can report a ISP MitM the binary packages because no one knows the actual build output.
so, trust noone, but acept that open source gives you an edge. always.
Also, WhatsApp has long supported compressed file backups (non-cloud) for a while now.
People who provide meaningful value are worth a little extra effort.
FTR i dont game or media watch on my phone. For me a phone is a mobile device for getting things done when im not at my desk. I use a Blackberry DTEK60.
The apps I use: APKpure for getting apps - great selection and its fast. But you do need to know which ones need GPlay Services before downloading. work : Blackberry Hub - use this for work and service integration. Simply the BEST bar none - and yes I am huge fan of BB devices and yes i do/have owned and used everything else. email : MailDroid - for personal email. photos: Simple Gallery - photos txt: YAATA - sms/mms pCloud: cloud storage riot.im: messaging with a few friends and family + calls T-UI: a power saving and very efficient UI for android TurboClient: ftp client - fastest way to move files between pc/Mac and phone
Have loaded and will try some of the author's suggested apps as well. Im not anti-google, just need to have my apps work all the time whether im in Hongkong or China.
Previously i used the xiaomi store for apps on local phones, and phones bought elsewhere and it worked a charm - looks first on its own store and then has option to search elsewhere for the apk. Worked faultlessly for me until i decided to switch to APKpure because the signing in F-Droid and its occasional blocking became a pain for me.
Unfortunately, this does not solve verification of the apk signature. As far as I understand it, Android uses something similar to "trust on first use" [2] with apk signatures, so verifying the signature before first installation should be sufficient for most people.
[1]: https://github.com/matlink/gplaycli [2]: https://developer.android.com/studio/publish/app-signing
It is additional work, i now only do it for more important apps.
http://pokevision.site/clash-of-lights-apk-download-free-lat...
It's even worse if you're supposed to have YT Red as a Google Play Music subscriber, but they don't enable that functionality in almost any country.
Anyway, worth a look if you just want to ditch the Youtube app.
https://infinity0.github.io/droid-hacks/
I go into a bit more detail than the OP does, though with less-flowing prose.
Might as well apply data capturing to yourself and reap its benefits
Surely once Google sell your data, or access to it, then you're in no better position than of above else were selling it? Google release it into the wild, presumably, just like other companies do.
Please consider using default scrolling
Scrolling works perfectly in Firefox 57 on Linux.
It's most definitely your problem.
Edit: problem is overflow-y: auto
I'd be curious to know if anyone has had any positive experiences with any of the non google/apple OS phones or if there is a comparison out there as I'm so fed up with that duopoly. Apple has terrible battery life and intentionally obsoletes their expensive equipment every year. Not to mention they rip off third party devs (its why theres no amazon store app). Googles design on the other hand is so bad it takes forever to figure out how to do something stupidly simple like turn a text message pic into your background or it even tries to kill you with a full screen text wall pop up on google maps when driving over a bump. You find the tiny dismiss and then... bump again...
Is this available on F-droid? I didn't see it there.
I did figure out a way to sync org mode files between laptop and phone with low latency (unlike with Syncthing) running Unison inside Arch Linux inside Termux, using git to automatically merge conflicts. It's a little crazy, but seems to work? Maybe will do a write-up at some point.
(That’s what the bug reference in a reply to this comment is about)
I tried restarting the app/ refresh email threads, but it didn't fix the visual bug. I'm not sure if the bug is still present today as the email thread has been buried down and I couldn't care enough to follow up on it. I'm just glad it didn't actually send my draft when somehow the app displayed my draft version as sent.
Note that I'm not a user of K9, I'm just describing similar buggy encounter with Gmail desktop and its android app. I only noticed this that one time and just shrug it off due to me turning off apps auto update. Usually I only update manually when I really think I need to and after carefully reading each change logs.
If you do need an app from the Google Play Store in a pinch, Yalp Store gives you access to that, and most of them work well enough. For the occasional app that really needs Google Spy Services, I keep an older 'burner' phone around which runs the factory-default build of Android.
I get a bit of solace knowing it's open source... But I certainly won't be crawling through the code and compiling.
I hope others do...
It's like Chromium on Debian. It's Google code compiled by Debian
Could you not say the same about any Android ROM?
As for reliability, I have notifications for email (using K9 Mail and IMAP idle), XMPP (Conversations), and Signal. Emails (using IMAP idle) always reach me within a second or so. Occasionally, Signal messages will take hours to reach me, but I suspect that's not a problem with the websocket connection to my phone, as others running Signal (on a Google-laden phone) have had the same issue.
I might be wrong but isn't it simply about building a tcp connection whenever Internet is available or changes, and the server will push whenever there's something new? You don't need a single thing polling (which would indeed save power) if the server is pushing. Recently I learned that sleeping (power-conserving) clients are even part of the WiFi spec, so that an access point will hold onto messages for some time until the client is listening again. I assume this is just some ms, but still.
Some time ago MicroG[1] was set to solve that problem, but I don't know how far they have come.
[1]: https://microg.org
Google apps/Gapps is what MicroG replaces. Gapps is an optional, separate install not included in LineageOS. Location services etc are part of that.
MicroG works well, I use it on one Android device and have another using LineageOS without either Google apps or MicroG. Both devices are extremely useful and capable and do everything I require, but I've never let myself become dependent on any Google services in the first place (despite having been a web dev for almost 20 years).
A couple of other recommendations:
Try using amazon app store as they have some commercial apps and don't use google
KeepPassDroid - and use syncthing to sync Skype (on amazon)
The two that I have problems with are uber which use to allow you to use their web interface and google maps replacement. I ended up with a burner phone after a while...
I really hope that one day institutions like public transport operators and public service broadcasters publish they apps in google-free stores. I don't want to depend on the Google Playstore one day because there's no other way to purchase an electronic ticket or to use tv on demand services.
However, I do see the number of ROMs built for my phone has increased a lot, so maybe I should try something else?
You can also use GPG keys embedded on the Yubikey for encrypted emails via OpenKeychain and K-9.
[1]: Still not sure if some sequence of commands looked like I intended to delete stuff, or if it was a bug that has since been fixed.
Still nice to control my syncing and files with Resilio.
The only security flaw I see is that it is written in PHP, which makes it harder for the devs to write secure code, but not impossible.
I would recommend Yalp Store instead, it works pretty well.
If you have your phone in a dock with the screen on it's usable. Also the search is pretty bad and forget looking up most stores by name.
a manually updated web browser... what could possibly go wrong?
Personally in terms of security, I would worry more about the Essential-specific builds, not general LineageOS releases. For example, a quick search shows LOS having the KRACK vulnerability seemingly patched the same month after public disclosure.
As for my distinction between Essential builds vs. general LOS builds, bear in mind LOS has not reached Official status for the Essential phone and is very unlikely to within the foreseeable future, primarily due to the difficulty in decoupling Google services from the OS. BUT! If the Essential LineageOS Discord channel is any indication, maintenance and updates are super active. And, the (volunteer-run) support is VERY helpful. Keep in mind, they are supporting LineageOS on Essential, not necessarily cases of rooted devices.
Furthermore, rooting isn't a 1-click process at this time, either. You'll have to bust out the computer terminal, run some adb/fastboot commands, and do a couple additional things that get your hands dirty.
If you use T-Mobile and have the money for a Pixel 2, I would just go with that. Essential has widely varied reception for T-Mobile users. Mine for example simply doesn't work much of the time that it says I have full signal, and it flat out drops incoming calls and text messages with absolutely no indication whatsoever that anybody even tried to contact me.
I kind of regret my choice in phone to replace my aging, problematic N5.
Pretty healthy pool of LineageOS phones "out there." https://wiki.lineageos.org/devices/
This is what I am using: https://lineage.microg.org/ (get rid of google play (and save 1/3 of battery)) apps have a dependancies to google framework and just not having it breaks lots of stuff (this is google true vendor lock-in). Microg is opensource reimplementation of it, but it needs patches into android to fake its file signatures. And lineage microg takes care about it)
First thing, get rid of your gmail/android account, register new account with 3rd party email provider. If you are buying phone, check xda-developers which has most support from ROM builders as you don't want, for instance, Samsung ROM. Only than go for hw specifications. Root phone (don't be afraid, it is nothing special, companies are scaremongering here), flash recovery TWRP (imagine it as "bootloader" for android), flash lineage microg.
From here, you start playing with OS.
- Replace dns server (root required) 8.8.8.8 with other (I use my own but there are plenty privacy oriented like ccc.de)
- Install yalp store (replaces play store, buy things using browser, if developer drm doesnt support verifying that you have bought its app, break it using lucky patcher or demand money back)
- Install xposed framework, install netguard, install xprivacylua (one of rare developers I trust for this, due to his privacy work), pay him donations to get pro versions (I have my own versions of those two built and a tad modified)
- use netguard logging to block all the fishy urls that system is calling (gps service, block complete network access,...)
- take special care about firefox, block all privacy details using xprivacylua, install webapi manager add-in, learn to use it.
- You have set up base os now start using it and block everything that is trying to be contacted using microg. Lineage is by no means clean but you can silence it. Dont trust system apps, broadcom drivers are, for instance, contacting their servers. Dont start installing apps until you have done it, later you will get huge noise from apps. Take a day or two and just use phone normal features blocking everything that seems faul (google ntp servers,...)
- For those who havent noticed it yet (or reversed a few of apps), most of android applications are demanding crazy lot of permissions. The reason is that in they have ~1/3 of developer code any 2/3 of spying code, from ad providers to trackinb and analytics and simply code that "just" needs to access your contacts =/. So... for every application you install, start it with everything blocked (netguard + xprivacylua) and work your way trough allowances. Don't give any app allow for internet if it doesn't need it, fake all the details to app that doesnt need them (South Pole is a nice place to be for gps coordinates)...
To really unhook yourself from google, you will need a server, I came to the point where all google domains are blocked (I mean ALL, not just google.*), all my comunication from all my computers/devices is passing server (i have two ways of doing it, either vpn or ssh tunnel) where communication is cleaned, http (+https mitm) over squid with huge blocklist, caching cdns forever,... and having squid in separate routing table (ok, its freebsd fib but close enough) with openvpn client, so also my ip is gone. I am completely self hosted (own "cloud" for webdav,webcal, files; mailserver; searx;...) and...
.. I am not missing anything that google has to offer, I am using android apps, but without google.
I would really recomend doing it, if you aren't familiar with networks, OS,... it will take a year, two, five, but you will learn a lot.
I have probably forgot about lots of details but please ask it, if you are interested.
Just for a taste, my google data export is 28kb (bought apps,...) after few years. What about yours? :)
Some links you might use:
I can't tell without installing and I have strict policy of no google / facebook (actually anything related with social media) apps on my phone. Or try to find OSS alternative
Regarding softbricking, TWRP should solve that.
I'm out of the loop, what happened with Mozilla?
This is exactly what I was looking for.
edit : I used this for reference https://gist.github.com/ramann/62abe0b266bb8c3e8483c7c7ca60f...
Thanks
freeotp is also crap compared to andotp and name other alternatives are questionable and seem author has no clue about android/apps
And also in general. I often see articles where there really are completely random images in them to fluff things up... Like "Oh you're reading some technical article? Here have some people sitting on a bench eating ice cream!" Why?