Problem: even with an alternative operating system, you still don’t get security updates for the baseband firmware, and that thing is a huge remote attack surface that, if compromised, grants the attacker unfettered access to the entire phone.
Some new phones isolate the baseband processor from the rest of the system. Only the small independent phone makers like Librem use such a design, though.
GrapheneOS often picks up security flaws in the android open source project and fixes them before google goes. I won’t claim they fix everything but I’ve seen enough examples of things they fix over AOSP that make me doubt they wouldn’t have fixed something like that (on top of keeping everything updated). Maybe you weren’t referring to Graphene but still worth a shoutout for being a very (the most?) secure operating system.
I’m talking about the baseband, the device that talks to the cell network (among many other functions). It has its own closed-source firmware, no open-source substitute for that firmware exists, and it has full access to the entire system, bypassing the CPU and OS. Installing a different OS will not stop attackers from exploiting vulnerabilities in the baseband firmware and taking over the phone.
Problem: even with an alternative operating system, you still don’t get security updates for the baseband firmware, and that thing is a huge remote attack surface that, if compromised, grants the attacker unfettered access to the entire phone.
Some new phones isolate the baseband processor from the rest of the system. Only the small independent phone makers like Librem use such a design, though.
GrapheneOS often picks up security flaws in the android open source project and fixes them before google goes. I won’t claim they fix everything but I’ve seen enough examples of things they fix over AOSP that make me doubt they wouldn’t have fixed something like that (on top of keeping everything updated). Maybe you weren’t referring to Graphene but still worth a shoutout for being a very (the most?) secure operating system.
I’m talking about the baseband, the device that talks to the cell network (among many other functions). It has its own closed-source firmware, no open-source substitute for that firmware exists, and it has full access to the entire system, bypassing the CPU and OS. Installing a different OS will not stop attackers from exploiting vulnerabilities in the baseband firmware and taking over the phone.