[flagged]

Perhaps the fact that iPhones are run by a multi trillion dollar company while GrapheneOS is an open source project with less employees than an Apple store has something to do with NATO approval. They are not going to approve a device that people have to install the OS themselves. I would base the security of an OS based on expert security researchers, not certain government agencies decisions.

iPhones are probably the most secure off the shelf phones you can buy, but based on leaked documents it's clearly inferior real-world security compared to a Pixel running GrapheneOS. Apple and Google have copied many security features from GrapheneOS like the reboot timer.

GrapheneOS is built from the ground up with a primary priority placed on security. GrapheneOS has much more robust USB port hardening. You can see the full list of features added on their website. Apple bolts on some additional security features in lockdown mode but they are mostly fixes to Apple's services which have large attack surface like iMessage. Additionally they are all built together and not on by default which makes the users willing to use it way lower.

Any independent reasons for your claim besides appeal to authority?

Apple can at any time push a hostile "upgrade" that will remove or disable the claimed security features. You don't control the operating system, and can't trust that it isn't backdoored, especially given Apple's record[0].

[0] https://en.wikipedia.org/wiki/PRISM

> The iPhone

Probably the latest models. Cop told me they have problems cracking those. Older models not so much, that's pretty common knowledge.

Is this because of vulnerabilities baked in the HW (or bootROM or any other unpatchable area)? What’s the situation on older Pixels? Are they generally safer than an iPhone for HW issues? It’s expected that given a few years some vulnerabilities will crop up for most hardware.

So then the best chance for security is to stay up to date with everything, including the latest HW model. At least this gives an attacker a window of only ~1 year to find and exploit a vulnerability.

[flagged]

Source: I made it up