@pchblk @waldschnecke @murena
e/OS/ is pretty much the worst choice for a smartphone OS in every aspect. e/OS/ massively reduces security and privacy compared to AOSP and almost completely eliminates the security model.
This includes, among other things:
-) No support for Verified Boot (a security-critical feature in Android)
-) Months of delays in security updates
-) Full patches can sometimes take longer than a year
-) Chromium came/comes in a delivery state that has not been updated for months.
-) They once had an Orbot client in use that had not been updated for years
-) There was also an incident where their cloud service mishandled session keys and granted users access to other users' files, then lied to users that the server couldn't see the files, even though there was no E2EE
-) The voice-to-text service from e/OS/ sends data to OpenAI by default ...
This is not a complete list; see also:
https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private
In addition, Fairphone uses some EoL hardware and still lacks important security features.
See also information from Tavi (Android security researcher and former developer of DivestOS):
https://forum.fairphone.com/t/is-fairphone-really-interested-in-sustainability/99302/2
You should take a look at the comparison table from eylenburg, which provides a clear overview of important information about the individual custom OSes:
https://eylenburg.github.io/android_comparison.htm