02-17-2022, 08:33 AM
(02-16-2022, 07:09 PM)bookwurmx Wrote: Hi,
I have a question, what is now the most secure option for using PinePhone?
I am using now days a Google Pixel with Graphene OS and Calyx OS, but I want to look now for other options.
What I also doubt about is the full disk encryption, which distro has the best security and encryption?
But is the file encryption from Android not better than a full disk encryption? .. I hope some can help to give a good answer to those questions
probably mobian, i haven't installed it using full encryption though. i think arch might be good alternate. keep in mind that, firwall is usually not enabled or installed by default.
my background: i just usually want to get rid of google, facebook and others, also their accounts and software, also i want to control device's bootloader and software. those are enough for me in most cases.
however, android might have some things better than pp o.s.. every android app runs on isolated environment, which is not the case in pinephone operating system. although linux has isolation program to help that. generally speaking you get more control of software with pinephone and it's not necessarily more secure.
modem chip firmware also has nasty bug which is not present in opensource firmware. it's present in quectel firmware, also the latest 30.004.30.004.
some people seems to believe that full encryption is a perfect solution. full encryption may protect some things, but if someone hacks inside pp remotely when o.s. is running, intruder sees all the files like that. full encryption protects if phone is shut down or locked.
there is also physical security, sounds little dumb, but if you can secure device physically all time, then in my view full encrpyption is near useless. physical security is also issue with bootloader, pinephone bootloader is easily bypassable, therefore it's easy to reuse device if it's stolen.