Privacy On Phone

Good afternoon:

I always warn you. And even that the updates are not going to be the same and so on.

I even warn it when they tell me. Jolín there is no way to remove this application from my terminal. And you tell them about adb. And that it can cause system problems and so on.

But don’t think I’m dedicated to do those things professionally. Only friends and family who tell me.

But always go or talk to people tell you the same thing. I like the terminal but it says that it has so much storage and then you put mie… That I will never use and you are touching the …

But even if for example you buy a terminal of brand x, for example Xiaomi, Samsung, etc… You also have to rely on their customization layers. And we already know that they bring everything but privacy and other jejeje

Neither does Google, and the Play stuff. They are safe some if (they say), since either you know how to look at the code and interpret it or it is also to trust. And then how many discover that it does everything but well?

A hug

Universal Android Debloater is a user-friendly way to uninstall / disable unwanted apps. You can disable instead of uninstall via settings.

I recommend to build it yourself, easiest way to do is with an Arch Linux based distro and use the AUR package script to build it with pacman / pamac. (Not the -bin package)
More info:
(static archive page cause itsfoss is a javascript nightmare, omg…)


Hell thanks! Installed under Arch via AUR … testing right now…
It also describe what the services are… great!! So , tons of time gained avoiding to search any entry in the net.
Very good tip!

edit: no seriously … you make my day happy. Was almost impossible to gather all the informations for the single service. Probably soon google will nuke github for make this beauty disappear :neutral_face:.

Privacy in general is difficult and only getting harder, the FBI, CIA and NSA have all been hacked previously

It’s always been difficult, there’s really no such thing depending on how you look at it.

We can however limit as much personal data from becoming public as we can. And there are still ways to do this but they are not for everyone.

Government agency’s have high threat models compared to average citizens, 1 of many people trying to get in will always happen.

Good afternoon:

Privacy if you can get it. But in general people have no appreciation for their data.

Since they give it left and right. They don’t even read the terms of the programs etc… Not to say that they do not read the small print of the contracts or loyalty cards that are made …

And then everything is published on social networks. That’s why Facebook, Google and others make a killing.

It is easier to buy a mobile phone and not stop to look at what it collects from us. Already the own brands of terminals. Not to mention Google, Apple, Whatsapp, etc. …

And even more people put them at home. Tell me alexa… Ok Google… Siri…

When there are rooms and programs that do not collect data.

And then a lot of people excuse that they use vpn for privacy. Anyway…

But if it can be achieved, it is increasingly difficult because of that, because of the detachment that people had and have to their data. I always hear the same thing: I don’t have anything to hide… And then why Google has a photo of me from 5 years ago, if I deleted it…

If not look at the evolution of windows itself. How much telemetry they add in each version and nonsense. And the mobiles idem, Xiaomi , Smsung, Oppo, etc etc…

And whoever says that Apple is the best for privacy. In short… Just read the things they put in their terms and conditions. And how many things came to light that they collected and made excuses or covered it up. And they said they stopped there.

Mebos bad that we have the customs rooms, fdroid

A hug

Yeah, install Signal from F-Droid…oh…sorry…host your own…oh sorry. C’mon…

1 Like

Install Conversations from F-Droid, and tell others to do it, and then Conversations will store image/video in user data instead of app data, leaving the files accessible to any other app.

Good afternoon:

Brave search is not the panacea, it has its things: Old URL, redirecting to new...

Nth attack from GrapheneOs people (wonderfall is a known Matrix user of the project) to then promote their own resources.
In short, we must swallow with the idea of giving money to Google, directly or indirectly (second hand) buying their devices, as any other option is ridiculously insecure.
They did it with:

  • Linux phones under the guise of not having Android security features (bootloader, ARM TrustZone, Titan M chip, etc) closed source technologies and on the Pixel mostly provided by Google.
    There is a free implementation of the Titan M chip (Opentitan) but for some reason Google is not interested in adding it to their devices.
    So the keys and passwords are stored, in the case of GOS, on a closed source chip that only Google knows.
    For security, they say do you trust Google? I don’t.

The CalyxtOs project and its MicroG for signature spoofing, whose team only allows it for the aforementioned MicroG component and not the rest of the system, promoting instead proprietary packages (sandboxed Play Services) that in audits (by CalyxtOs people) generate many more connections than the previous one. And it is that a malware in sandbox is still malware…
The fact that a software is open does not mean that it is more secure (it is also an important issue for these groups).
As you well know, I don’t use MicroG but at least its connections are documented and it is open source technology.
I am of the opinion that any software or program is untrusted. That its code is visible/auditable at least gives you the option to look.

An argument against the above, promoted by closed source supporters, is that this is impossible because of the large size of some projects but however the current practice is not to do it in the whole program as a whole but through the Commits that are added from the beginning which is much simpler.

Mozilla browser, and its lack of security on Android, highlighting that it has nothing of “isolation” which is a lie Browsers - DivestOS Mobile

It only lacks Per-Site Process Isolation, as long as we enable privacy.firstpartyisolate in about:config

  • Any LineageOs ROM because in many cases they do not have firmware updates (remembering that the same in GOS are from Google and closed source) or that the open bootloader is a tremendous security hole (true in part, especially if someone has physical access to the device) but nevertheless the bootloader in GOS is from Google, also proprietary code (to be honest all are, except in Linux phones)

  • In the FAQ of his website he says that Linux is insecure and that he expects to switch to a microkernel in the future (coincidentally Fuchsia is…)

  • And now it’s the turn of F-Droid where they highlight its security problems, they recommend the Google store, directly or through Aurora, or their own store in development.
    As for the aforementioned F-Droid and said document, in summary:

  • They mention F-Droid signatures to packages commenting that we need to add another trusted source.
    The F-Droid team analyzes the apks, in the source it says in a rudimentary way, although I don’t think so but it is always improvable, to make sure they pass their evaluation criteria.
    Then, this website compares this practice to the keys stored in Google’s cloud for the Play Store (which I consider an added privacy issue).
    To my knowledge, I have never read of a serious security issue with the F-droid store.

Mozilla browser, and its lack of security on Android, highlighting that it has nothing of “isolation” which is a lie Browsers - DivestOS Mobile

It only lacks Per-Site Process Isolation, as long as we enable privacy.firstpartyisolate in about:config

  • Any LineageOs ROM because in many cases they do not have firmware updates (remembering that the same in GOS are from Google and closed source) or that the open bootloader is a tremendous security hole (true in part, especially if someone has physical access to the device) but nevertheless the bootloader in GOS is from Google, also proprietary code (to be honest all are, except in Linux phones)

  • In the FAQ of his website he says that Linux is insecure and that he expects to switch to a microkernel in the future (coincidentally Fuchsia is…)

  • And now it’s the turn of F-Droid where they highlight its security problems, they recommend the Google store, directly or through Aurora, or their own store in development.
    As for the aforementioned F-Droid and said document, in summary:

  • They mention F-Droid signatures to packages commenting that we need to add another trusted source.
    The F-Droid team analyzes the apks, in the source it says in a rudimentary way, although I don’t think so but it is always improvable, to make sure they pass their evaluation criteria.
    Then, this website compares this practice to the keys stored in Google’s cloud for the Play Store (which I consider an added privacy issue).
    To my knowledge, I have never read of a serious security issue with the F-droid store.

They give Signal as an example, which refuses to get the app into F-Droid. This would give for another debate, when they deliberately hide their apk on the web and urge you to use the Play Store.
On top of that, if you have a ROM without gapps they make you go through a Google recaptcha, not to mention their connection to firebaseinstallation whose blocking crashes the installation.
The Signal team argues, on the other hand, the delay in the actus (something legitimate), that they can not have stats, crash reportings, etc, that is, more data from its users.

-Compatibility with old APIS. The F-Droid team says it wants to support very old phones. It is undeniable security problems that this entails but they do not want to leave without possibilities to people who can not or do not want to buy a phone leaving in the lurch these people without resources. Technically, if these apps do not have access to the internet, the problem would be solved.
Again, security above all else.

Lack of best practices. Being able to add repos is a security issue according to them. Certainly, but it also gives you that freedom, with all that it entails.
They mention TLS certificate pinning and give the Play Store as an example. It would be ideal if they implemented it, but they base their argument on the fact that since the Play Store has it (and the GOS apps repo) and they don’t, that’s another point against it.
Or the absolete “signature schemes” and PGP. I agree. F-Droid team argues lack of developers, a pity. I hope this will change, why deny it.

  • Or the outdated version of F-droid available. Its developers comment that for stability. They are a small team and prefer this to possible software bugs.
    As soon as we update repos new versions will be released, and if we mark also unstable this “problem” is mitigated.

  • The misleading permissions method. There is not much to scratch here. They criticize that F-droid gives more info about what applications can do and that can overwhelm the user.
    They put as a “good example” the Play Store…

-Conclusion according to them. Use the Play Store, try Aurora but not with anonymous account or that we use the GOS repo with their apps, mix of open and proprietary.
In short, it brings out the security issues of the platform and masks, softens or hides the privacy issues of the alternatives.
Personally I will continue to use F-Droid

Sorry for the long-windedness.

As you may have guessed, I don’t want, nor do I feel like trying GrapheneOS.
I could go into much more detail about the reasons but I think it is starting to be evident to many people that all that glitters is not gold.
However, don’t talk bad about them in forums or specialized privacy media, whether they are constructive criticisms or not, because you will be banned (I have been).

It already seems quite hypocritical on my part to be pulling Android ROMs to give money to Google over revaluing their devices not to mention their practices discrediting other possibilities, attacking them, setting themselves up as the only option in security and mobile privacy.

As long as there is still fdroid we will be safer. Then the rest will have us or want to have more controlled by the lack of interest of the people of their data. And so on. If not look at the continuous connections on the web that come out of google, facebook, and others …

About search engines. I like it:


Besides, I don’t know what they have in store for us in Europe with the 2030 agenda. Nothing good in terms of privacy. Otherwise, I don’t know why the EU is doing La UE lanza su propio 'YouTube' y propio 'Twitter' (basado en Mastodon, que no deja de sumar usuarios desde la llegada de Musk).

You can also look at

By the way, and speaking of Chrome, you will like this.
Below is a link to download it:

It’s a comic that highlights the privacy issues with Chrome and Google in general: Un cómic de Google presumía de las fortalezas de Chrome en 2008. Este nuevo cómic se ríe de su privacidad ahora

Since it doesn’t work, because there must be quite a few people looking at it, you have to pull it from (and/or download it): (gives error due to saturation)

You can also look at LibreWolf vs Firefox: Comparing the Privacy Heroes of Open-Source Browsers

I’m sorry for all the tocho but to hear about Graphe…


A hug

1 Like

Tnx Galle for the contribution. Lots of this informations are really difficult to be found.

Good afternoon:

I think I got a little excited, but backwards when I read graphe…

I’m sorry for all the rambling and for my English. But my bilirubin went up without realizing it jejejeje

A hug

You don’t trust your other apps? Why did you install them? Terrible decision you’ve made…

Like the post said, use a separate profile then, if you need some of those.

You do realize that a chat app means you have to chat with other people, and you can’t control what apps others install?
This is a basic feature that should have been done a long time ago, the developer just doesn’t want to implement it and said he has it as a low priority.
Really? then recommending Conversations is a low priority for me.

Just use Signal, and as much as it pains me, Element / Matrix

Just use Whatsapp then, same features that you like. Others can export your files anyway, you can’t deny that to them.


People already understand the difference between leaving it in the app and exporting it. (and export it encrypted as a backup is possible)
This is not an excuse for not implementing a high(should be) priority feature.

You know perfectly well that other apps like Signal and Telegram have it, even Monocles chat, a fork, has it although partially (no export)

Gotta choose your fights, and winners, yes. Centralized services are worse imho.

FYI, Conversations has a toggle that monocles uses (right?) but without export it’s pain, it’s hostile to the user, keeping data hostage. Just like centralized services want it…to make you dependant of them.

Centralized services are worse imho.

Except when one almost daily uses centralized, non-free Microsoft github, and Gitlab. :laughing:

“Do as I say, not as I do” for you.

1 Like


I’m guilty of that. git was great, then hiring managers “had” to see public GitHub, and now folks are jumping ship to GitLab as a compromise.

It’s hard to unravel the hosted services crap now. Colleges / Universities are steeped in Office365, and I guess I shouldn’t be surprised how many companies have GSuite now. iCloud doesn’t seem to be used outside personal use. Because so many institutions have handed over everything to Google / Microsoft’s “services”, it’s hard to escape as employees / students.

1 Like

Good afternoon:

Neither Github nor Gtilab can be trusted. Since now many are escaping to Gitea or Codeberg.

After the messaging applications. No matter how encrypted the message is. Then if you upload the backup to Google, icloud. Well… But even without uploading them if whatsapp is so eager to accept the new terms of data transfer to Facebook … Well, the encryption will not be very reliable. But if not, the US and the EU already agree La UE y EEUU llegan a un acuerdo para poder transferir datos personales | Tecnología or La UE y EEUU acuerdan volver a transferir datos personales, garantizando la privacidad

Besides, I don’t know at world level. But in other parts of the world mobile phone rates, usually have unlimited minutes of calls. Then use applications like whatsapp, which are anything but private or secure. If in addition almost the most searched for the network is: how can I enter the whatsapp or facebook of my partner, friend or so …

For example I like the way of Silence for sms. That if you send one encrypted and the other does not have the application. And even if you have it, if you don’t accept the encryption, everything comes out except the text.

Then on the web you see a lot of Google amp.

Or else they are already spying on us with Pegasus Así funciona Pegasus, el programa espía que pone en jaque al Gobierno de coalición de Sánchez

In the end they want us submissive and with everything from us. Watched by cameras and so on.

Or for example in Spain with covid. That was different the code of the application in the Google store. That in Github. But as far as privacy is concerned…

We will have to get to make carbon phones. Without camera, microphone, etc… Or even put a headset with the cable cut so that they do not hear you or others.

But that is the same as people do not read on the webs about cookies. Simply accept and that’s it. But if you read it, it comes out of everything…

For example using a firewall Afwall+ style that you can give or remove permission to access both wifi or data. It helps with privacy. And in strange connections to call it that way.

Which for example gives me a doubt. It is because even the customs room. In the phone application comes out of SIP calls. Because for example you look in App Manager and there is active.

What I do not know if in future versions of the application Fdroid. You could remove the Nearby option. Or do not have access to Bluetooth or NFC. This would already be a tipzo more for Fdroid.

Best regards

Yes, sad, right?

How many devs did you convince to move?

How many apps did you uninstall because of these reasons?

We can go on in circles, yet here we are trying to do our best of this situation.

Subject above was messaging, not F-Droid, bringing this into that helps this discussion how? Repeating the same things like Cpt. Obvious helps how?