5 ms·
Maybe I can help, I have written this in google context, but it is general privacy enabled configuration. This is what I am using: https://lineage.microg.org/
by _o_ 8y ago
Maybe I can help, I have written this in google context, but it is general privacy enabled configuration.
This is what I am using:
https://lineage.microg.org/ https://lineage.microg.org/
(get rid of google play (and save 1/3 of battery)) apps have a dependancies to google framework and just not having it breaks lots of stuff (this is google true vendor lock-in). Microg is opensource reimplementation of it, but it needs patches into android to fake its file signatures. And lineage microg takes care about it)
First thing, get rid of your gmail/android account, register new account with 3rd party email provider. If you are buying phone, check xda-developers which has most support from ROM builders as you don't want, for instance, Samsung ROM. Only than go for hw specifications. Root phone (don't be afraid, it is nothing special, companies are scaremongering here), flash recovery TWRP (imagine it as "bootloader" for android), flash lineage microg.
From here, you start playing with OS.
- Replace dns server (root required) 8.8.8.8 with other (I use my own but there are plenty privacy oriented like ccc.de)
- Install yalp store (replaces play store, buy things using browser, if developer drm doesnt support verifying that you have bought its app, break it using lucky patcher or demand money back)
- Install xposed framework, install netguard, install xprivacylua (one of rare developers I trust for this, due to his privacy work), pay him donations to get pro versions (I have my own versions of those two built and a tad modified)
- use netguard logging to block all the fishy urls that system is calling (gps service, block complete network access,...)
- take special care about firefox, block all privacy details using xprivacylua, install webapi manager add-in, learn to use it.
- You have set up base os now start using it and block everything that is trying to be contacted using microg. Lineage is by no means clean but you can silence it. Dont trust system apps, broadcom drivers are, for instance, contacting their servers. Dont start installing apps until you have done it, later you will get huge noise from apps. Take a day or two and just use phone normal features blocking everything that seems faul (google ntp servers,...)
- For those who havent noticed it yet (or reversed a few of apps), most of android applications are demanding crazy lot of permissions. The reason is that in they have ~1/3 of developer code any 2/3 of spying code, from ad providers to trackinb and analytics and simply code that "just" needs to access your contacts =/. So... for every application you install, start it with everything blocked (netguard + xprivacylua) and work your way trough allowances. Don't give any app allow for internet if it doesn't need it, fake all the details to app that doesnt need them (South Pole is a nice place to be for gps coordinates)...
To really unhook yourself from google, you will need a server, I came to the point where all google domains are blocked (I mean ALL, not just google.*), all my comunication from all my computers/devices is passing server (i have two ways of doing it, either vpn or ssh tunnel) where communication is cleaned, http (+https mitm) over squid with huge blocklist, caching cdns forever,... and having squid in separate routing table (ok, its freebsd fib but close enough) with openvpn client, so also my ip is gone. I am completely self hosted (own "cloud" for webdav,webcal, files; mailserver; searx;...) and...
.. I am not missing anything that google has to offer, I am using android apps, but without google.
I would really recomend doing it, if you aren't familiar with networks, OS,... it will take a year, two, five, but you will learn a lot.
I have probably forgot about lots of details but please ask it, if you are interested.
Just for a taste, my google data export is 28kb (bought apps,...) after few years. What about yours? :)
Some links you might use:
https://lineage.microg.org/ https://lineage.microg.org/
http://repo.xposed.info/ http://repo.xposed.info/
https://www.xda-developers.com/ https://www.xda-developers.com/
https://www.netguard.me/ https://www.netguard.me/
https://github.com/M66B/XPrivacyLua https://github.com/M66B/XPrivacyLua
- nefariousoctopi 8y agoNice summary, thanks. Do you think, that there is a chance to get Google Hangouts running with microG? It's required by my current employer unfortunately.
- _o_ 8y agoTry it. Once you have TWRP on your phone, you can backup your whole phone (including ROM) to SD card and later revert it back if it doesn't work. I can't tell without installing and I have strict policy of no google / facebook (actually anything related with social media) apps on my phone. Or try to find OSS alternative
- mkesper 8y agoXposed shouldn't be used carelessly, see e.g. here: https://www.reddit.com/r/Android/comments/1y4u1p/can_xposed_mods_harm_my_device/ https://www.reddit.com/r/Android/comments/1y4u1p/can_xposed_...
- _o_ 8y agoWell, as long you are using only xprivacylua, it shouldn't be a problem. I have reviewed the code for it and netguard (doesnt need root) and it is clean (for netguard there are some callhome functionalities, but it doesn't submit anything relevant back or doing something fishy - I am talking only for paid version). Also Bokhorst is donationwaring it, so there is a money trail to physical person. Regarding softbricking, TWRP should solve that.