who has publicly stated that they're mining the metadata, and does not by default notify you when one end's keys change (say if the phone were compromised).
Note that with cell phone spoofing, someone could impersonate you to OWS. All your contacts would get messages stating that your key ('secret numbers,' I think is the term they use) has changed, and all messages would then go to the imposter.
I'm inclined to say there's no reliably secure mobile platform, though idlewords (Maciej Ceglowski) and tptacek (Thomas Ptacek) are presently recommending iPhone or iPad.
(I'm writing this on an Android device I fear, dread, and detest.)
Looking at the price for 0-day exploits for phones one would also conclude that iPhones are the more secure option. Right now an Android 0-day root exploit fetches up to $200.000 while one for the iPhone goes for $1.500.000.
I believe Android is ok, IF you flash LineageOS (previously CyanogenMod) on it or buy a new phone every two years. The biggest problem with Android is that they stop giving you updates after two years and are too slow within those two years.
Use of Google as a third-party authentication service authorises transfer of all my contacts to the site to which I'm authenticating.
Or, alternatively: Any fuckwit I've shared contact information with might share my contact information with a third-party site by opting into the same type of auth mode.
How the holy hell did this ever seem like a good idea?