graphene os - practical talk

Good in theory, in practice many apps don’t work. It takes more than just an os to make a phone secure. See here: Secure communication devices
after almost two years I can say it works surprisingly well, except google pay and curve I don't recall anything that wouldn't work for me

I don't see any better yet practically usable alternative - however it doesn't fully meet my requirements when it comes to "resilience" and app isolation...
 
GrapheneOS user here. Happy to share experience and talk through how to set things up.

I’ve run almost every flavour of secure comms/OS imaginable, including some of the commercial ones, but ended up sticking with GrapheneOS plus an iPhone/iPad for other business use.

I used to travel with multiple Pixels, but nothing draws more unwarranted attention from government parasites than walking around with a stack of post-crypto phones. On top of that, iOS/iPadOS remains far better supported for the banking apps that now strictly enforce Play Integrity.

I run about 10 profiles on the Pixel and use those as the isolation boundary. For each profile I have Seedvault set up to back up to a WebDAV location of my choosing.

On the resilience side I completely feel you. It happened to me recently that some freshly installed profiles weren’t configured properly for backups. If you don’t explicitly specify certain files/directories, Seedvault simply won’t back them up. That wiped quite a bit of history and made recovery impossible.

Where possible I try to avoid Wi-Fi and run a couple of layers of active/passive network protection (think something along the lines of SASE, but working across multiple layers).

What are you trying to achieve specifically? Happy to go into more detail on profiles, Seedvault config, network hardening or whatever.
 
I run a very similar setup - two pixel phones, two laptops, many server-side components, decent wireguard network with disposable exit nodes registered and paid anonymously or hijacked network components (private Tor network in essence šŸ™‚)

anyways... graphane does the job - 95% user experience satisfaction, including dozens of banking apps
however I'm focused a lot on disaster recovery and backup - basically I want each of my toys to be completely useless for anyone who steals or finds it if lost and I want to be able to immediately switch to my server system or backup device

when it comes to graphene the seedvault backup is pretty useless - it saves some time to recover a profile from backup but most of the apps need activation not only on a different hw but also when recovered on the same phone - this sucks and I'm not happy with current state of things

also native profiles are incredibly clumsy and slow to use, same with work profiles (island, etc.) - I fancy very different solution when it comes to app isolation and there doesn't seem to be anything acceptable to meet my requirements as I consider every app installed a potential threat and malicious code running on my device and it needs to get sandboxed
 
that's why plausible deniability features are absolutely essential (ideally combined with steganographical storage) - in this regard it makes no sense to me that Graphene has visible profiles - the logical approach is unlock screen that opens profile based on PIN submitted instead of a silly list of available profiles

almost nobody needs NSA-proof solution - we just need to fool the airport monkeys and other collaborants by showing them what they expect to see - we just need them to make some non-negligible effort (submit some proof of work) which is almost always a big enough barrier
 
If you really care about privacy you need to stop talking about GrapheneOS and portables generally. Or do you genuinely think you can outsmart forensic science?
Do you need to have access to your data while on travel? Fine: upload what you need somewhere, travel with a burner device and download the data when you are safe. I’m sure you can survive even 24h without access to your ā€œpreciousā€ data nobody cares about unless there is a reason to use it against you - in which case no matter what the data is the prosecutor will find a way to interpret it.
 
If you really care about privacy you need to stop talking about GrapheneOS and portables generally. Or do you genuinely think you can outsmart forensic science?
Do you need to have access to your data while on travel? Fine: upload what you need somewhere, travel with a burner device and download the data when you are safe. I’m sure you can survive even 24h without access to your ā€œpreciousā€ data nobody cares about unless there is a reason to use it against you - in which case no matter what the data is the prosecutor will find a way to interpret it.
I'm no Snowden nor Tsikhanouskaya, I'm no drug cartel boss, I'm no politician, I'm no arms dealer - I'm no one - different case, you seem to mix things up
 
  • Like
Reactions: compromised
I'm no Snowden nor Tsikhanouskaya, I'm no drug cartel boss, I'm no politician, I'm no arms dealer - I'm no one - different case, you seem to mix things up
That’s why I wrote that nobody cares about your data. Unless you give them a reason to believe you are hiding something interesting and to build a case against you for absolutely nothing (but be assured that they will manage to find, or build, something against you).
So why to complicate your life and expose yourself when there is a simple and bulletproof solution to your worries?
 
Or do you genuinely think you can outsmart forensic science?
You can most definitely run circles around forensicators. Unless you’ve drawn so much attention that they’re shipping your phone off to an Israeli company, you’ll be fine on the latest software version with a password that is not 0000 or 1234.

As you mentioned, absence of evidence just means the prosecutor will put a magnifying glass on every scrap of bullshit they can pin on you. Those criminals won’t stop.
anyways... graphane does the job - 95% user experience satisfaction, including dozens of banking apps
however I'm focused a lot on disaster recovery and backup - basically I want each of my toys to be completely useless for anyone who steals or finds it if lost and I want to be able to immediately switch to my server system or backup device
I do understand the concern, but remote wiping or control simply isn’t possible without relying on a third party. In my case, I use an MDM solution on my own devices because I need to enforce certain technical controls, like deploying specific apps and configurations, that would otherwise be cumbersome to manage.

Even if a device is seized, they’ll typically place it in a Faraday bag and store it somewhere with no signal, so remote access wouldn’t work regardless.

The best solution I’ve found so far (also mentioned by @JohnnyDoe) i s keeping my phone empty when traveling, then restoring a backup using the native iOS/iPadOS tools. They work far more reliably, and I’ve had no case where all my apps and configurations did not came back intact. On my 512 GB iPhone, a full backup and restore takes less than an hour.
 
  • Like
Reactions: jafo and JohnnyDoe
I'm no Snowden nor Tsikhanouskaya, I'm no drug cartel boss, I'm no politician, I'm no arms dealer - I'm no one - different case, you seem to mix things up
What @JohnnyDoe and @compromised are trying to tell you is that they do NOT need your phone to arrest, imprison, or convict you (e.g. sentenced to time served even if they let you go and stain your record).

Source (one of thousands of similar cases that did NOT make the news): An innocent man spent a year in jail and $300,000 on legal fees - all because US authorities extradited the wrong 'Carlos'. Colombian Carlos Ortega recently lost his lawsuit against the US and a Florida prosecutor, which he had hoped would see him reimbursed for his financial losses and personal distress

1785350431061.png
 
  • Like
Reactions: Filda
but remote wiping or control simply isn’t possible without relying on a third party
I clearly didn't express myself correctly - I didn't have in mind any kind of remote wipeout - actually the exact opposite - the device should be at any moment disposable without becoming a threat for the owner - this mostly means encryption but also the owner should be able to hand it over and unlock the device for the malicious actor and provide him with a decoy system/profile that satisfies his expectation - that's where graphene os fail at this moment (by design)
 
  • Like
Reactions: jafo

JohnnyDoe.is is an uncensored discussion forum
focused on free speech,
independent thinking, and controversial ideas.
Everyone is responsible for their own words.

Quick Navigation

User Menu