Let's say I do have the infinite amount of time necessary and the technical expertise to conduct an audit of a custom ROM. Is every single person who's interested in privacy and security required to do their own audit?
If I publish my findings, why should anybody ever believe me? Who am I to tell anybody how safe it is? If you think it's so safe, why don't you do an audit and prove it to those of us with doubts instead of expecting us to do it?
Oh, right. You're operating on faith on these groups of people that you don't know who don't have any processes in place to ensure that what they're doing is safe for their users.
I'd very much like my next phone to run Linux (i.e. be a Pinephone) though.
I like the idea, but it's a deeply frustrating experience right now. Basic table-stakes features I have come to assume from both Android and iOS platforms just aren't there yet.
It's a frustrating chicken egg problem... I want the thing to succeed, but my smartphone is so critical to my day-to-day that I can either wait for it to get better or invest the time into having it suck on toast while I improve it.
I'd also have to figure out some more specifically personal stuff like alternatives or Matrix bridges for apps I 'need to' use to communicate with certain people.
Why again? Android is already free and open source and Linux doesn't have good answers for the proprietary goodies
It's not without trying either, I've worked on and off on a terraform provider for Android - currently apps only but with some vague intention to try to manage as much of settings as possible (not much, AIUI). It's just not meant to be used like that though, of course, and I wish Linux was a viable enough option that, at least among nerds already using Linux for work if nothing else, it didn't need to be justified for use on phones.
It doesn't need to. The feasible short-term target is feature parity with de-googled AOSP roms, which would still make it plenty useful in a "daily driver" scenario.
Nevermind that many of the apps that Google ships as part of Google Play are not receiving security audits outside of Google, Google is not committing to regularly audit their apps or publish the results, and these apps function as black boxes on your phone, with privileges that most other apps do not have.
This is the real problem, not the lack of security audits.
It is depressing, but phones are unique in that they need to work flawlessly in an emergency which I think is a factor in preventing people from straying from the path "well-travelled".
This is much to my lament as well, because I would love to feel more free to experiment with phone operating systems and hardware addons.