I am increasingly conscious of security and privacy. I don’t want my data or telemetry being sent to google or Facebook, and I want to make sure my device is encrypted and not readable by anyone other than me.
Is there a standard go-to guide on securing an android device with these types of goals in mind? Is true privacy possible without having to install Graphene?
“True” privacy is up to you and what you do with your phone. By default Android uses some Google services impossible to remove without changing ROM, like Google Play Services, SUPL and PSDS.
What you can do for other apps and services is what I’ve done with my old phone (not GrapheneOS compatible):
Is Android encrypted by default, or does it depend on the device vendor?
I remember reading time ago that Google enforces file-based encryption by default on Android which gets decrypted on first unlock when you boot your phone.
Try to look up in your settings for “encrypt”, then you should find the option “Encrypt Phone” with or without the label “Encrypted”.
Anyway this defends you only from an “hands-on” attack with physical access to the phone.
I prefer grayjay! It’s great and it has a good-ish desktop version