I collect old smartphones, but I follow strict rules to keep my data safe on them
by Faith Leroux · Android PoliceIf I can afford to, I love keeping old phones. They are fascinating relics to study.
But sadly, you still have to handle them with care, even if the installed software is more than capable of running your favorite apps.
Even if you have a reliable Google Pixel phone predating long-term software support, like the Pixel 5 series, you shouldn't trust it; Android 14 is still quite good, but it isn't infallible.
That's why I use soft rules when handling outdated phones to reduce the risk of my data being stolen, lost, or leaked.
Related
The surprisingly practical act of keeping your old phone
Your phone can last longer than you think
Posts 11
By Jon Gilbert
My personal 'don'ts' with old phones
What you'll never catch me doing with them
When the phones I keep stop receiving security updates, I have to be realistic about what I can do with them.
They're no longer my daily driver or a place to store personal data. As such, I try to diligently follow a few practices to avoid straying into danger.
For one, I never install certain apps, and I don't sideload on these phones because I don't want to risk downloading malware.
Second, I never do banking or log in to payment apps. If anyone stole those credentials, it could ruin my life for good.
I also avoid storing sensitive information such as my password or staying logged in to certain email accounts.
If I store anything on my phone — images — I always back them up; I never treat these phones as a local storage-only option unless I am repurposing them.
This is mainly because, depending on your phone's age, it can have a sudden hardware failure, and you don't want to lose your data.
The last practice is mostly precautionary.
I try to be mindful when browsing the web. If I am using a browser, it needs a safety option to avoid third-party trackers, especially ones that can identify the type of device I am using.
I only visit websites I have been to before, and I have done my homework to check them out.
I also avoid signing in to anything, and if I can use Google apps more sparingly and turn off permissions, I do, since that's another way to profile my habits across platforms.
Outdated security makes your phone a great target
Check the monthly Android Security Bulletin for risks
In September 2025, Samsung issued an emergency patch to address a critical security vulnerability.
The security vulnerability, referred to as CVE-2025-21043, came from a third-party image-parsing library called libimagecodec.quram.
Hackers used it to exploit a memory allocation flaw to run malicious code targeting Samsung Galaxy devices running Android 13 or newer.
You could encounter this exploit from WhatsApp, which forced both developers to fix the vulnerability.
That's only one example. More vulnerabilities were later found on Android devices in December 2025, totaling 107.
According to Cybersecurity Insiders, 40% were classified as "high-severity flaws that could potentially allow attackers to gain access to sensitive information or compromise the functionality of the device."
That's a high number, and outdated devices are not getting these patches.
My oldest device runs Android 11, and my second-oldest runs Android 12 — eventually, these add up, so I feel pressured to build better practices to safeguard my data.
On the websites I browse, I check the security status to make sure it has a certificate and my connection is secure; sometimes I turn on a VPN to encrypt my traffic if I am on a network I don't trust.
But even then, I stay overly cautious because I know my devices are a target and OEMs won't release patches for devices no longer under support.
It's a tough pill to swallow, but that's why I have strict practices about how I handle my data, and which devices I trust with it.
Flashing custom firmware can sometimes help
I don't have personal experience with LineageOS since I have made my peace with what I can and can't do with my old Android phones, but for those who feel pressed about their old software, it is (sort of) an option.
However, installing LineageOS comes with some trade-offs, particularly around security.
Basically, the trade-off is that installing LineageOS can compromise physical security (if it remains unlocked afterward), since it requires an unlocked bootloader to load the open source OS.
Another issue is that LineageOS relies on the OEM for proprietary hardware, kernel, and driver fixes, so when that goes out of date, LineageOS can only do so much to protect your device — it can't fix hardware-level security issues.
But at the very least, LineageOS can incorporate Google security bulletins into its active builds — so it's better than having nothing.
Otherwise, if you're looking for deeper security and a privacy-centric custom OS, GrapheneOS is a decent alternative for supported phones with active software.
Though it's currently only compatible with some Google Pixels, in 2027 you'll be able to load the custom OS on Motorola flagships.