OnePhoenix

joined 3 days ago
[–] OnePhoenix@lemmy.ml 1 points 22 hours ago

Very informative thank you.

[–] OnePhoenix@lemmy.ml 1 points 1 day ago (2 children)

but I just get SMS 2FA from my bank.

How do you feel about the claims of SMS 2FA not being safe? Does that bother you? Or is it a risk you're willing to take? Genuinely asking because my banking app does the same and I'm not sure how much of a real 'threat' SMS 2FA is.

[–] OnePhoenix@lemmy.ml 6 points 1 day ago

The same as a firearms registry keeps guns out of the hands of criminals?

[–] OnePhoenix@lemmy.ml 6 points 2 days ago* (last edited 1 day ago)

I think it's a lot to do with developing a threat model that works for you, and understanding that, unless you're trying to be Jason Bourne, there's always going to be SOME compromise - the level of compromise again, depends on you.

A couple years ago when I started down this rabbit hole, I was doing EVERYTHING that I read on every privacy blog: I started using GrapheneOS, completely degoogled my phone, didn't use any non-FOSS apps, no location apps, the whole 9 yards.

I soon came to realize I had to find a compromise. I now follow a threat model that best works for me... Naturally there are weaknesses in it, but it's things I'm willing to risk.

  1. I use Element with anyone willing to use it with me. I use QKSMS with anyone else.
  2. I created a separate profile on my phone with Graphene that only has my banking apps. It still uses Aurora store and sandboxed Google services.
  3. I don't live in an area where things like Uber are available so that ones not a problem for me. I just call for a taxi oldschool.
  4. OSMand+. I won't turn it on (or location) until I'm away from my house and already on the way. You can also manually download apps for offline and use it like an old school paper map.
  5. Kind of unrelated but, I use Obsidian for almost everything I keep track of in my life. I document my fitness exploits on Obsidian.
  6. I use a Pixel 8 with GrapheneOS. I use my phone calls as per normal but usually try and text (see #1 above) my phone also has a record button when you call someone - I'll generally record every conversation I have with anyone from any company, etc., which has already saved me some headaches in a few cases where service providers promised something and then didn't follow through and I could go back in the recording and prove they said a certain thing.

A few extras:

  1. I also have an audio recorder on my phone with a shortcut that turns it on when I double tap my screen. I use this whenever I go somewhere strange/alone like a Kijiji meet up or something, get pulled over by the cops, etc. - just for safety/contingency.
  2. I use Kmeet for video chat with family, friends.
  3. I use Pipepipe, Newpipe, etc. for videos and most music.
  4. Proton for VPN
  5. Proton/Tuta for email.
  6. Ente for photos.

That's just my little process... I know some of these aren't directly related to common phone usage but it's how I use my phone daily, so hopefully some of it is interesting to you.