

“Can run with ease” is a bit questionable with Nura in daily use as a main phone.
Nura is definitely not yet ready for everyone …
In Memex crowd thinking environment for thoughts unthinkable to separate beings, human-machine general intelligence raises superintelligent offspring to help all life.


“Can run with ease” is a bit questionable with Nura in daily use as a main phone.
Nura is definitely not yet ready for everyone …


I wonder which is more secure, expired GrapheneOS or up-to-date lesser AOSP-derivatives with bootloader locking?


LineageOS supports so many old phones, but no verified boot (bootloader relocking).
https://wiki.lineageos.org/devices/
I haven’t tried it, but I used its predecessor CyanogenMod for years without issues.
.
/e/OS (a beginner-friendly derivative of LineageOS) also supports many old phones without verified boot. Some newer ones can verified-boot.
https://doc.e.foundation/devices/
The better supported ones are “official” builds while the others are “community”.
https://doc.e.foundation/devices/?channel=official
I’ve been using /e/OS community release on a Sony phone for 1.5 years. It’s okay. Most apps work with MicroG. Bootloader not lockable, but apps don’t notice.
Some bugs:
.
iodéOS, another LineageOS derivative, has verified boot on some devices:
https://iode.tech/iodeos-official-supported-devices/
I haven’t tried it.


CalyxOS supports some Motorolas:
https://calyxos.org/install/
I haven’t tried it.


Me too, and I wanted it working last year. I considered GrapheneOS on a Google Pixel 9 or 10 Pro with the Google camera app, but installed /e/OS on a Sony Xperia 1 V with the Sony camera app. Relocking the bootloader is forbidden by Sony.

I wish it was Nura OS or NuraOS.


Tor Browser for both security and privacy, but you won’t like it because it’s slow.
Your question combines two separate features in the same way that the nearly useless question “which is the best and the cheapest” does. You could ask for the best quality/price -ratio. You can have great security with no privacy when you use a well-made big tech solution. You can have great privacy with low security when you choose a poorly made, easily hackable open-source solution.


My phone was unnecessarily powerful for me until /e/OS added local offline speech transcription.


Yes, “based on LineageOS, which is based on AOSP”. I do say that in the long piece linked. I cut corners to keep the comment short.


Not sure if the /e/OS Android-compatible AOSP-based operating system on my phone qualifies as FOSS. Surely not Linux despite the kernel - neither does Android.
/e/OS comes with local offline non-cloud voice to text / dictation / speech transcription. How do I get this to other OSs?
It also comes with a slightly customised NextCloud (installable to many OSs), which is full of utilities: the usual cloud tools bundled with Apple, Google, and Microsoft OSs, except the constant surveillance.
https://www.quora.com/How-does-Murenas-custom-e-OS-compare-to-Googles-Android/answer/Harri-K-Hiltunen
(TLDR: /e/OS is open source, beginner friendly, and mostly being developed by a small French company)


Linux mobile … PostmarketOS … as a daily driver … Fairphone 6 is very close
Seems like Jolla phone (or its Sailfish OS on a Sony 10 III) belongs to that group? I haven’t tried it.


phone option outside of big tech
Jolla phone, but people say it’s not an option for everyone (yet).


GrapheneOS - maximum security and privacy for phones and tablets
Notable mention for the beginner-friendly /e/OS (technically inferior compared to GrapheneOS, installable to more devices).
I haven’t tried CalyxOS yet. I had CyanogenMod for a few years before it was LineageOS.


Read-only memory (ROM) is hardware, a chip, or an area on a chip. Flash storage used to store a system image is not read-only, but the term “ROM” has somehow creeped onto it. The definition of read-only in my opinion is that you have to use a separate device to write it, it can’t be writable by the device that uses it, it has to be write-protected in use.
The operating system image colloquially called “custom ROM” is software (firmware) written to flash storage. It’s not read-only and it’s data, not memory hardware. If it were read-only, we wouldn’t need verified boot (bootloader locking) to detect malware edits in it.


Bootloader locking stops web-caught malware from modifying the OS and thereby making itself persistent (reset-resistant).
People with physical access is a different threat.


Not just “evil maid”. Malware could flash a backdoored OS too. Source: https://kevinboone.me/lineage-eos-graphene.html (the comment from GrapheneOS team at the end)
Bootloader locked = Verified boot = Secure boot = only OSs with valid signature can boot.
Not sure if Sony Xperia 10 III is “cheap” yet, but it can run Jolla’s Sailfish OS Linux.
I haven’t tried a Jolla Phone.