Scams & verification
Does your “secure” device actually do what it claims?
A large part of the “privacy / secure phone” market is dressing: a cheap, no-name device, re-badged and sold at 3–5× its price with unverifiable promises. Here is how these scams work, how to spot them, and how we can verify a device you already own — with evidence.
The most common techniques
Re-badging no-name hardware
A generic phone/router from a Chinese OEM is bought wholesale, given a brand and a skin, then resold at 4× the price. The hardware is ordinary; only the price and the pitch change.
Security theater
Buzzwords with no substance: “military-grade”, “NSA-level encryption”, “unhackable”, “100% anonymous”. No threat model, no source, no acknowledged limits. These terms are red flags, not guarantees.
Invented or irrelevant certifications
“Certified secure” logos that point to no standard, or real markings that are irrelevant (CE/FCC attest radio/electrical compliance, NOT security or privacy).
“Custom secure OS” = re-skinned stock Android
Often a stock Android/Linux with a launcher and wallpaper. No verified boot under your keys, no reproducible builds, nothing auditable. The “hardening” is cosmetic settings.
Closed code, “just trust us”
No way to verify what actually runs. No sources, no reproducible build hash, no hardware attestation. Trust is verified, not declared.
A phone that “calls home”
“Private” devices that actually exfiltrate data to the vendor — or worse, entire platforms operated by third parties (reminder: several “encrypted” networks turned out to be controlled end to end).
Over-charging for free, open software
Charging a premium for GrapheneOS, Tails or OpenWRT — which are free and open-source — without saying they are free or explaining the real added value (assembly, hardening, support).
Scarcity, urgency, no-recourse payment
Countdowns, “limited stock”, crypto framed as a way to escape any dispute. (We accept Monero by privacy choice — and we explain it, with legal warranty and right of withdrawal.)
Checklist: verify it yourself
- Does the seller name the exact OS and link its upstream source (grapheneos.org, tails.net, openwrt.org…)?
- Does it state the product’s LIMITS (baseband, theft, physical extraction) in the same place as the claims?
- Is verified boot active under keys you control? Is there verifiable hardware attestation?
- Are builds reproducible / sources public? Can you recompute a hash?
- Does the price match the real hardware + explicit work, or are you mostly paying for a logo and jargon?
- Does it use absolutes (“unhackable”, “untraceable”)? If so, it is false — and that itself is a signal.
Get your device verified
Bought (or considering) a “secure” device? Send us the model, screenshots of the seller’s claims, and the device if possible. We will tell you whether it does what it claims — with evidence.
- Real identification of the hardware and OS (teardown / photos, firmware fingerprints).
- Verified-boot and hardware-attestation checks where they exist.
- Claims ↔ reality: each promise tested or refuted.
- Reproducibility / source verification where applicable.
- Honest verdict: legitimate / partial / security theater — with the supporting evidence.
Contact us
Encrypted channels (preferred for sensitive requests) — see the contact page for up-to-date details:
Contact page (PGP / SimpleX / Signal)Verified & debunked products
Our evidence-based verifications are published here (with the requester’s consent). On principle, we only call a product a scam on the basis of verifiable material evidence — never rumor.
First verifications in progress. Submit a product through the channels above to start an analysis.