Problem: even with an alternative operating system, you still don’t get security updates for the baseband firmware, and that thing is a huge remote attack surface that, if compromised, grants the attacker unfettered access to the entire phone.
Some new phones isolate the baseband processor from the rest of the system. Only the small independent phone makers like Librem use such a design, though.
GrapheneOS often picks up security flaws in the android open source project and fixes them before google goes. I won’t claim they fix everything but I’ve seen enough examples of things they fix over AOSP that make me doubt they wouldn’t have fixed something like that (on top of keeping everything updated). Maybe you weren’t referring to Graphene but still worth a shoutout for being a very (the most?) secure operating system.
Problem: even with an alternative operating system, you still don’t get security updates for the baseband firmware, and that thing is a huge remote attack surface that, if compromised, grants the attacker unfettered access to the entire phone.
Some new phones isolate the baseband processor from the rest of the system. Only the small independent phone makers like Librem use such a design, though.
GrapheneOS often picks up security flaws in the android open source project and fixes them before google goes. I won’t claim they fix everything but I’ve seen enough examples of things they fix over AOSP that make me doubt they wouldn’t have fixed something like that (on top of keeping everything updated). Maybe you weren’t referring to Graphene but still worth a shoutout for being a very (the most?) secure operating system.