You can buy a ready to use phone on their web site or you can install the OS on a compatible phone of your own. I have installed this on about 10 phones (all Motorola) for friends and family. Here is an example of one that I just put together as a Christmas present.
https://www.amazon.com/Motorola-T-Mobile-Unlocked-XT2113-2-S...
As a de-Googled phone, the Google Play store doesn't work but that's no big loss because I can get any software I need from F-Droid and Aurora Store.
https://divestos.org/pages/devices#device-fp4
Super happy with it, but yeah no headphone jack, but i have it with the usb-c convertor.
It's everything that the average Joe really needs for only $99 refurbed. As I said above, I just installed e/OS on one as a Christmas present. It runs very smooth and fluid, better than stock because the background Google spyware crap is gone.
It's the loss of an entire ecosystem worth of apps.
If you want an inexpensive phone that will get five or six years of first party support with security updates after that, go with an iPhone SE.
The original $399 version got six years of OS updates and just got another security update last month. That's $67 per year that got both an OS update and security update.
No, it's not. With very few exceptions, the Aurora store pulls apps from Google Play. About the only thing I have seen missing from Aurora store is a few super strict banking apps but you can usually just use their web site.
This isn't so bad if you use a privacy focused ROM and create a special, single purpose Google login that is only used for app purchases. I also suggest keeping a Google gift card for the occasional purchase.
Privacy invasion doesn't really kick in until you start re-using your Google login and your phone/apps are reporting back to Google on a regular basis with your location, device IMEI, advertising ID, hardware fingerprint, email address, browsing/search history, banking/purchase details (aka Google Pay), etc..
He literally just said that he used the Aurora store as an alternative. If you don't know what that is, it is basically an anonymous version of the Play Store. Highly recommended
And check your vibe meter, it is acting up. The main person behind this was the creator of Mandrake Linux.
Termux is the one android exclusive software I can't live without and they managed to fuck even that up by killing processes indiscriminately in order to save battery or whatever. If there's no solution by the time my phone dies, my next one will be an iPhone.
Wait a minute, will something like this really come to Android phones? I guess that installing a custom rom will become impossible at the same time?
If this happens, then there truly isn't going to be much point in using an Android phone over an iPhone
Android already provides a mechanism for apps to refuse to run on modified devices, it's called SafetyNet and is widely used for example by banking apps. Currently, it's usually possible to trick it, but with hardware attestation it will become practically impossible.
The simple solution --- install the bank's web site as an app.
Go to the site, click the browser menu button (3 dots on Android or up arrow on iOS) and select "Add to Home Screen". You now have a link icon on your phone that looks and acts just like any other app.
Some banks (Chase for example) offer a "Progress Web App" which removes the browser interface elements so the causal observer can't even tell it's not a native app.
https://www.howtogeek.com/342121/what-are-progressive-web-ap...
Google has been doing this for quite some time to prevent unlocked devices from accessing the Play Store. The solution is to avoid Google Play --- along with all other Googly things.
If your solution is to just be less secure go ahead, but don't complain when services don't want to serve you or treat you different since you are less secure than the other users.
> don't complain when services don't want to serve you or treat you different since you are less secure than the other users
Hell no. They should not be allowed to discriminate against me just because I chose to own my system. They should not even be able to figure out what software I'm running, to say nothing of "treating me different".
"Don't want to serve us" unless we let them invade and own our machines? Please. This should be illegal.
App developers don't care if you own your system. They just want a way to prove that the device their app is running on is secure and that the client has not been modified. If there was a way for you to prove that to them they wouldn't mind.
>They should not even be able to figure out what software I'm running, to say nothing of "treating me different".
They just want to know that the client has not been tampered with so that they know you are not going to shall user's tokens, scrape people's information, or mondo automated actions as a bot. A signal that you are using the vanilla client makes you much more trust worthy to a service.
>"Don't want to serve us" unless we let them invade and own our machines?
Apps aren't invading your machine. They just want some guarantees about the environment they are operating in. The information that they get from you is the package's name, certificate, version, whether it's from the play store, whether your device passes integrity checks, and whether the app is properly licensed.
> They just want a way to prove that the device their app is running on is secure and that the client has not been modified.
Contradictory. If I own the system, I can obviously modify it and everything running on it. Including your app. Therefore what they want is proof that I don't own the system.
> They just want to know that the client has not been tampered with
"Tampered with" -- there's that language again. Owning my computer is not "tampering", it is freedom.
> They just want some guarantees about the environment they are operating in.
Who cares what they want? It's my machine, I decide what they get. If they get anything at all. If I want them to believe they are running on a clean environment, that's what they should believe.
> The information that they get from you is the package's name, certificate, version, whether it's from the play store, whether your device passes integrity checks, and whether the app is properly licensed.
"Integrity" checks? Rooting my phone does not violate its "integrity". If anything it restores it.
Certificates? Store? Licensing checks? Look at all this crap that must be installed on "my" system just to give you your "guarantees". My phone's gotta come out of the factory pwned at the hardware level for your "guarantees" to be worth anything. It has to come with a full root of trust from the firmware to the bootloader to the operating system to each individual app just to prevent my "tampering". But you're seriously claiming apps aren't invading our machines.
An app "wanting" anything is invasion enough.
I disagree. You can have control in modifying your system, but the software just needs a way to prove that the security features it assumes are true. There could be a way for it to analyze the changes you made and decide whether or not it should trust your system.
>"Tampered with" -- there's that language again. Owning my computer is not "tampering", it is freedom.
It's someone else's software. You may own your computer, but you don't own the YouTube client. Google owns the YouTube client. Tampering with Google's client is tampering.
>"Integrity" checks? Rooting my phone does not violate its "integrity". If anything it restores it.
No, it does not. One part of Android's security model is that app's have storage that only they can access. Take for example a 2FA app which stores it's private key in this location. This makes it so that you must physically have your phone in order to get a 2FA code. This is the "something you have" part of 2FA. Rooting your phone violates the integrity of the system because now someone can just become root and steal the private key. Now they can generate 2FA codes without physically having the device with them. It then becomes another "something you know."
>My phone's gotta come out of the factory pwned at the hardware level for your "guarantees" to be worth anything.
These are security features. Your phone is less secure without them. It's not pwned.
>An app "wanting" anything is invasion enough.
Everyone wants something. Every business transaction includes both parties wanting something from the other.
Why wouldn't an app require this? Banks want it because "fraud", streaming services want it because "piracy"... You can come up with pretty much any reason for any "rightsholders" to want control over our computers. If WhatsApp starts requiring this, it's either accept Google control or my phone turns into a paperweight.
Damn how i hate to write that: At least on Android you can turn off WI-Fi and mobile data, unless iOS which keeps it enabled "for system services".
You realize that Apple is still doing the tracking, just not allowing third parties?
Apple is in a league above Amazon in protecting user privacy. It is the most privacy-conscious firm out there. Apple only stores the information that is necessary to maintain users’ accounts.
https://stockapps.com/blog/google-tracks-39-types-of-private...
The problem is companies like Google and Facebook, which track users across the web and relentlessly spy on everything they do.
Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online.
>Of course, Google has been able to track your location using Google Maps for a long time. Since 2014, it has used that information to provide advertisers with information on how often people visit their stores. But store visits aren’t purchases, so, as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases.
https://www.technologyreview.com/2017/05/25/242717/google-no...
It doesn't just show ads based on current search terms. It uses your install and usage history to show personalized ads. https://www.macrumors.com/2022/10/22/apple-announces-more-ap...
The difference between Android and iOS is that with Android, you don't have to use spying services from Google or Apple. With iOS, you are required to use spying services from Apple.
> Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online.
Google gets your purchase history whether you use Android or iOS. iOS is strictly worse for privacy.
> Apple only stores the information that is necessary to maintain users’ accounts.
The difference is clear.
It's impossible to take this seriously.
Google, literally has surveillance capitalism as it's entire business model.
You have no choice but to let Google get your purchases (except maybe via some opt out with your card issuer). You do have a choice not to send your app usage to Apple and Google, but only if you use Android.
As far as whether Google or Apple is worse for surveillance capitalism, only the former (and Microsoft and Mozilla) lets me opt out of them collecting my SSID location. That is yet another reason iOS is worse for privacy than Android. Even worse, it is impossible to get your location on iOS without also sending your location to Apple.
No, I'm just not gullible enough to buy into such a ridiculous premise.
Spying on users is Google's entire business model.
What does that have to do with anything? On Android, I can use as few Google apps as an iOS user. Even better, I can use fewer spying Apple apps. Apple's entire business model is marketing to gullible users who hand over their money and their data.
You get the usability of Android with (optional)sandboxes google services/microg.
Almost all apps work and its really usable.
Sounds interesting. Goes and looks it up.
>>From: $1,999.00
You must be joking...
This is the cost of Librem 5 USA (made in USA) [0], not Librem 5 (made in China) [1]. Also, I preordered it for $600 a long time ago, and sometimes you can buy from resellers for a similar price [2].
[0] https://puri.sm/products/librem-5-usa
[1] https://puri.sm/products/librem-5
[2] https://forums.puri.sm/t/librem-5-for-sale-eu-630-eur/19445
I suppose that helps a little. I seem to have incorrectly assumed that the USA model was intended for use in the USA, not simply assembled there. Still crazy expensive. For that price I'd expect it to come with a keyboard and mouse and replace my Thinkpad altogether.
You have my attention.
....
[goes and looks it up]
Niiiiice. Reads more...
https://puri.sm/posts/what-is-mobile-pureos/
The only problem I'm seeing is this is all Gnome and I'm a big Mate desktop guy. I wouldn't really have a desktop replacement unless I could get the traditional desktop back. Still this situation is a much better one than I originally feared. I'll be watching this closely. Thanks for educating me.
Lots and lots of people say they don't want to be tracked by ad companies. But how many are willing to open their wallets to make it happen? I'd say you can judge how sincere their commitment is by that.
The linked source has a lot of stuff that is done "in the future" and basically all of those "in the future" suggestions, are inferior to what AOSP has had for years.
The document lists some of the drawbacks of Librem 5, such as the use of memory-unsafe languages, and then blames Android for also relying on the same memory-unsafe languages and even some Android-specific components written in memory-unsafe languages. The fact is that Android has tons of mitigations specifically for this problem, which Librem 5 completely lacks. They're not comparable in that way. Librem 5 basically exposes the entire Linux kernel attack surface, whereas Android has multiple layers of protection between userspace and the Linux kernel. Apps written in memory safe language, proper app sandboxes, hardened memory allocator, extremely strict SELinux policies, CFI, PAC, ShadowCallStack, etc.
The only nice thing Librem 5 has, are the killswitches, but do those really matter at this point?
For example, if you do not trust the manufacturers in China, you can verify the schematics, or order Librem 5 USA. Or, if you suspect your device is compromised, you can rely on the kill switches to make sure you are not tracked or listened to. Can you do these on Android? I'm sure there are known vulnerabilities for the latter on the black market.
Another example: If you use the smart card to read or sign your emails, you can be sure that even a hacked or stolen unlocked phone would not allow the attackers to manage your email identity.
People who say that Librem 5 is less secure than Android do not take into consideration that threat models can affect it a lot. You cannot simply declare "it's insecure" without considering the threat models. Also, I guess if you are fine with the security of your GNU/Linux laptop, which you take with you, you should be also more or less fine with the Librem 5 security.
I am not even speaking about the freedom benefits. Also, there is no security and privacy without freedom (https://puri.sm/posts/why-freedom-is-essential-to-security-a...). In the long term, Google is heading toward the walled garden on Android, just like Apple does. I would not bet on it for the future. If you care about security more than freedom and need Android-style security now, then Librem 5 is not for you.
You can block some of their access but it's hard from airtight.