Not only you use Android OS developed by Google, somehow you choose a less open OS distribution, exposing you MORE to Google and their shit, only because you don't want to use their hardware that happens to actually be as open as it gets, including the firmware?
Why do you choose to die on that hill? It's ridiculous!
AOSP is open source and written by Google. If you strictly don't want Google, you don't use Android. But IMO it's a shame because AOSP is actually good.
You could argue that you don't want to buy a Pixel because that would be giving money to Google, but not giving money to Google does not help the good alternatives, does it? IMO, helping the good alternatives means supporting GrapheneOS. The bigger GrapheneOS gets, the more likely it is that they get to work with major manufacturers (they already work with Motorola, which is great).
If you buy a Fairphone and run LineageOS, you are still running Google code (AOSP) and you support Fairphone who do not seem to care so much about security (otherwise they would meet the requirements of GrapheneOS).
Pixels are consistently "third party Android builds friendly", plus GrapheneOS has a list of required security features (beyond their control): https://grapheneos.org/faq#future-devices
e.g. first one in the list:
> Support for using alternate operating systems including full hardware security functionality
GrapheneOS wants users to lock the bootloader (≈enable Secure Boot) after install by providing user signing keys (avb_custom_key) -- that already seems to leave only Pixel, Nothing and Fairphone.
If they're only supported on a single line of devices made by a single company and there are thousands of devices made by hundreds of companies, then that's not industry standard. It might be better than industry standard, and it might be good, but it's hardly common.
Most of the hardware security requirements are met by multiple lines of devices. The issue is, not all of them are met. Many have poor updates or intentionally cripple standard features for anti competitive reasons.
So no, they are not "only met on a single line of devices", in fact Samsung gets super close, but they remove yellowboot support and cripple the device if you unlock the bootloader.
Maybe I didn't put it clear enough: __just the first__ GrapheneOS requirement leaves us with three brands. There's 20+ more items on the list after that, Nothing and Fairphone likely fail on them.
Is the bootloader locked and signed with reasonable keys? If not, you lose the secure boot, which defeats the point of the Android security model.
Do you get manufacturer updates? My experience with /e/OS was that the Stock Android was up-to-date but /e/OS was 4 years behind, on a Fairphone.
> for reasons I do not understand, Graphene OS is very closely tied with Google hardware
One of the requirements is precisely to be able to add custom keys and relock the bootloader, in order to keep the Android security model. Most other phones don't allow that.
Your phone is running proprietary Google DroidGuard blobs in a privileged process every time an app initiates a Play Integrity request.
If you install some Google apps like Google Maps, they are run with more privileges than other apps (their microG fork gives apps elevated privileges when they match certain Google signing key fingerprints).
Also, your device is running a firmware bundle provided by Fairphone's Chinese ODM, including TCL image processing blobs. Your phone will soon run an ancient kernel and firmware tree with many known critical CVEs.
But this all doesn't matter anyway, because security hardening is only for spies and pedophiles according to the CEO of Murena (the company that makes /e/OS).
/e/ OS with Fairphone is the good choice for that. Don't listen to cromka, /e/ OS is now fully open as the only proprietary app was the map one and they just replaced it. So, 100% free software. It is less secure than Graphene but also leaks less data to advertising companies.
> /e/ OS with Fairphone is the good choice for that.
That's debatable. /e/OS is mostly made of AOSP, which is made by Google.
> It is less secure than Graphene
Most definitely, yes
> but also leaks less data to advertising companies.
This is wrong. If you don't use microg on /e/OS or Play Services on GrapheneOS, then it's equivalent. If you use microg, it still contacts the Google servers even though it is an open source reverse-engineered implementation of Play Services. The added privacy there is to go through a proxy, which GrapheneOS offers.
I actually like it better to run sandboxed Play Services through the GrapheneOS proxy, because in my experience it works a lot better than microg.
Really, the only reason to use LineageOS or /e/OS (which are interesting project, really) is that you cannot run GrapheneOS on your phone. If you have the possibility to use GrapheneOS, there is no good reason not to do it.
If you use microg, it still contacts the Google servers even though it is an open source reverse-engineered implementation of Play Services.
Even worse, last time I checked the source code, it downloads Google's proprietary, obfuscated DroidGuard blobs (which they can change between requests) and execute it in the privileged microG process if an app does a Play Integrity request.
I bought a /e/os Fairphone instead.