The other projects who support some of these older devices have numerous issues as noted here: https://divestos.org/index.php?page=patch_levels#osSecurity
Edit: also of note: DivestOS currently provides monthly updates spanning seven versions of Android, I don't know of any other project doing that specifically.
Don't get me wrong, it's terrific that security patches are backported to such ancient versions of Android by those working on DivestOS and it's a great option for devices that aren't supported by GrapheneOS, LineageOS, et al.
https://gitlab.com/divested-mobile/firmware-empty/-/blob/mas...
This is indeed an issue and is documented on multiple places of the website.
Patching everything else is the best harm-reduction for this.
Now if you're buying a device planning to run it, that's fine, but it really does limit its usefulness.
I recently got an unofficial build of LineageOS running on a Nexus 4 (mako) device and I was positively surprised with the speed it can run modern software. But this is an unofficial build that is also broken on some essential points, such as WiFi.
For these old devices, Graphene is not an option and if there are others targeting the same devices as DivestOS (which I will surely be checking out soon) I have yet to see them.
Not sure what you mean about their ecosystem, I personally don't have an eCloud account. They have a NextCloud integration that I don't use but could work with your self-hosted instance.
So yeah, no lock-in as far as I can tell.
With /e/OS I haven't seen such a thing, it just feels like a nice community.
Then I've seen exchanges between the GrapheneOS author and some Calyx people on some GitHub issue, and they were borderline insulting each other. At this point is difficult for me to believe that somehow the GrapheneOS author is always the victim. And if that's the case, then that's bad for the CalyxOS community anyway.
Maybe that's misinformation, and they all love each other. Maybe not. How could I tell? What I see is that I would not want to be part of such discussions.
It's always a question of threat model. The /e/OS experience is perfect for me, and I am convinced it is much more likely to reach my friends than e.g. GrapheneOS, which is much more into security (at the cost of UX).
In the end it's good to have the alternative, and to realise that they target different profiles.
Do realize that combined with their Advanced Privacy app which routes users over Tor, it can very well result in HTTP only connections being MiTM'ed.
I've seen it with some of my own users recently and their RSS feeds being hijacked.
I ask /e/ team every month to do something about it and they don't, yet users keep trumpeting them and buying devices from them. It is downright negligent of them.
I use Firefox, not their chromium-based browser. I can't mention an app that I use that is using a WebView though... I remember there was one, but I could set it up to use my browser. I use their PDF reader, I'll have to check that.
> Do realize that combined with their Advanced Privacy app which routes users over Tor, it can very well result in HTTP only connections being MiTM'ed.
I don't route over Tor.