graphene os - practical talk

Good in theory, in practice many apps don’t work. It takes more than just an os to make a phone secure. See here: Secure communication devices
after almost two years I can say it works surprisingly well, except google pay and curve I don't recall anything that wouldn't work for me

I don't see any better yet practically usable alternative - however it doesn't fully meet my requirements when it comes to "resilience" and app isolation...
 
GrapheneOS user here. Happy to share experience and talk through how to set things up.

I’ve run almost every flavour of secure comms/OS imaginable, including some of the commercial ones, but ended up sticking with GrapheneOS plus an iPhone/iPad for other business use.

I used to travel with multiple Pixels, but nothing draws more unwarranted attention from government parasites than walking around with a stack of post-crypto phones. On top of that, iOS/iPadOS remains far better supported for the banking apps that now strictly enforce Play Integrity.

I run about 10 profiles on the Pixel and use those as the isolation boundary. For each profile I have Seedvault set up to back up to a WebDAV location of my choosing.

On the resilience side I completely feel you. It happened to me recently that some freshly installed profiles weren’t configured properly for backups. If you don’t explicitly specify certain files/directories, Seedvault simply won’t back them up. That wiped quite a bit of history and made recovery impossible.

Where possible I try to avoid Wi-Fi and run a couple of layers of active/passive network protection (think something along the lines of SASE, but working across multiple layers).

What are you trying to achieve specifically? Happy to go into more detail on profiles, Seedvault config, network hardening or whatever.
 
I run a very similar setup - two pixel phones, two laptops, many server-side components, decent wireguard network with disposable exit nodes registered and paid anonymously or hijacked network components (private Tor network in essence šŸ™‚)

anyways... graphane does the job - 95% user experience satisfaction, including dozens of banking apps
however I'm focused a lot on disaster recovery and backup - basically I want each of my toys to be completely useless for anyone who steals or finds it if lost and I want to be able to immediately switch to my server system or backup device

when it comes to graphene the seedvault backup is pretty useless - it saves some time to recover a profile from backup but most of the apps need activation not only on a different hw but also when recovered on the same phone - this sucks and I'm not happy with current state of things

also native profiles are incredibly clumsy and slow to use, same with work profiles (island, etc.) - I fancy very different solution when it comes to app isolation and there doesn't seem to be anything acceptable to meet my requirements as I consider every app installed a potential threat and malicious code running on my device and it needs to get sandboxed
 
  • Like
Reactions: prime

JohnnyDoe.is is an uncensored discussion forum
focused on free speech,
independent thinking, and controversial ideas.
Everyone is responsible for their own words.

Quick Navigation

User Menu