What about the Exynos RCE bugs? Now that they are patched they are secure again or how is this supposed to work? What about the intentional backdoor unearthed in the pixel phone (the sim swap thingy)? Who was that for?
My problem is, as a user, whose expertise is not 100% security, how can a layman decide which device to trust? Trust the neighbor, trust the expert who thinks is an expert, but doesn't see his own limitations, trust the newspapers parroting whatever they find (or their security advisor), trust the marmots or trust the looks, because you don't know what the silicon does. You might know one domain, but not multiple ones, like you might know the IT domain, but doesn't know the underlying physics domain, so you might think the phone is secure in the IT domain, but since you don't know jackshit about the physics, you have to again rely on someone's advice.
The iPhone is locked down tight, even security experts have complained in the past because analysing the core internals is cumbersome. But that's a double edged sword, when you can't even get basic info about phone's status without resorting to some hacking shenanigans.
Any way to know your firmware has not changed? How come there are zero tools for the layman to verify the status of his device? You don't know whether your usb's firmware is intact, whether your motherboard is a-ok and the list goes on.
According to newspapers, it is/was the panacea of security (iPhone), yet sec bugs after sec bugs are coming out all the time. You don't even have complete control over the phone, since the software switches (like wifi) are not actually disabling the wifi circuitry.
How come banks are sitting on ancient systems and are seemingly fine?
Should you trust zerodium's bounty prices, should you trust exploit brokers? (they ought to see what's an emmentaler right?)
Encrypted secure phones? Look how many criminals got caught, by putting their trust blindly into something, that someone parroted about how secure that is.
GrapheneOS says they are secure, but where are tools that show you that yes we do this and that and that solves these kinds of attacks, thwarted these attacks in the past, demonstrated?
Or should I go with an old blackberry? What about this article?
https://www.theverge.com/2016/4/14/11434926/blackberry-encry...
Should you consider Mikko's advice. Use a phone that is made by a country, whose intelligence agency is not a threat to you? But how do you know that a phone, which is made in X country is actually controlled by that country's IA? And how do you know which IA is not a threat to you? :DDDDD Do you even have to fear against a nation state's capabilities or since they have unimited budget you are fucked when somehow get in their crosshairs?
It's like flipping a coin, putting your trust into someone's solution blindly.