4 ms·
I'm surprised not so many people know about DivestOS[0]. It's the best option IMO if you don't have a google pixel for grapheneOS. Has similar support to lineag
by replete 2y ago
I'm surprised not so many people know about DivestOS[0]. It's the best option IMO if you don't have a google pixel for grapheneOS. Has similar support to lineageOS which it is based on. Same developer made Mulch and Mull web browsers. Monthly security updates. Obviously none of the hardware security features grapheneOS offers, but many other features, binary deblobbing, private DNS, MAC randomization etc.
Also, if you're handset model supports relocking, you can use banking apps etc.
[0]: https://divestos.org https://divestos.org
- janice1999 2y agoHere's an interesting comparison against other alternatives like /e/: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm
- aaravchen 2y agoNice table, though a couple of the things are a bit out of date on Calyx, and Divest depends a lot on which device you're talking about. I'm assuming you're a GrapheneOS proponent, because I noticed you rarely used "Google" as the answer to anything on Graphene even though that often is the answer. Graphene is very clear they're a security focused OS, and will consider privacy secondarily. The sandboxed Google Play is excellent for security, and provides the maximum equivalent compatibility possible with ASOP, but it's far less private than microG, which is only a little reduced by some of the extras GOS includes. Divest and Calyx are privacy focused first, and hardened security second. They use microG for the privacy, and actually take a number of the Graphene security patches. They're focused on making a device people can actually use while remaining relatively private. Obviously very different use cases and considerations between the two sets of projects. My personal experience is that Graphene is very interested in deep system changes to improve security, but is inconsistent in whether Google is considered trusted or not (mostly for cases when it's convenient/inconvenient). The occasional privacy-specific feature gets thrown in too, which is usually excellent, but user experience is pretty low priority, and almost anything but the ultra hardened use case isn't really of much interest. Throwing raw GApps in as a sandboxed app is a perfect example, it's a great security limitation that it's sandboxed, but a haphazard privacy choice where Google is mostly considered "trusted" as a privacy source ("just don't use it if you want privacy"). The unfortunate reality is that most phones have huge usability problems if you don't have something acting as part of the GApps, e.g. location takes 5+ minutes to lock in on GrapheneOS without GApps if you haven't locked it in recently, and won't ever lock in if you try to use an app relying on GApps (almost all of them). I'm personally more focused on privacy than ultra hardened security since I'm not a journalist under threat by nation state actors (Graphene is ideal for that use case). To be more clear you might consider splitting Graphene into 2 columns, 1 without GApps installed and 1 with.
- replete 2y agoGood table. The device support for DivestOS will improve with device/cash donations, its basically a one-man project. SZ compiles all the monthly builds on his own machines, its quite an undertaking. From what I understand there's been a fair amount of drama in the de-googled OS space. My experience with DOS has been exceptional and I'd encourage anyone who uses it to donate towards SZs ongoing efforts. It's pretty amazing what he's achieved on mostly his own.