Android phone security

I think it would be interesting to see a blog post regarding Android security and manufacturers in overall. This could even go more in-depth about custom roms and their security and the compromises that for example open bootloader might cause.

For example, is user data safe on Xiaomi phones? The phones (as with other manufacturers) connect a lot to manufacturer's servers, which can be seen via firewall or DNS blocker in the home network. Usually most of this communication is checking for updates or diagnostic data (opened applications screen time etc.). How could the user protect him or herself? Could the F-secure android app also analyze a bit the amount of data that is being sent and where?