3 ms·
That's totally fair and valid. I don't need root a lot of the time, but the one use I do depend on is network blocking via hosts like AdAway allows. If I unders
by 4oo4 4y ago
That's totally fair and valid. I don't need root a lot of the time, but the one use I do depend on is network blocking via hosts like AdAway allows. If I understand correctly the GrapheneOS alternative is running a local VPN to accomplish this?
That doesn't suffice for me since then I'm limited by Android only allowing one VPN at a time and would then have to choose between having adblocking or hiding my public IP. Yes, I can (and do) use a custom DoH like NextDNS for blocking as well, but I also like having a static hosts file so I have a baseline blocklist on my phone itself. However that's just my personal preference, any of those approaches are valid.
Having the ability for logcat would be nice too, since I depend on that to audit apps and track down strange bugs occasionally.
My main defense in limiting my attack surface is just not installing very many apps in general, and preferring apps from F-Droid that are as simple as possible and offline only, or that are connecting to a self-hosted service that I control. Which I'm sure helps but is obviously not as thorough as Graphene's hardening.
Verified boot is an awesome feature though, I think the ideal for me would be using my own custom keys to have verified boot, so I can include and sign whatever I want in my ROM. Though, I know there are the hardware backed keys you can't change and at that point I'd essentially just have my own custom ROM. I might just be spoiled from what I get with the Pureboot firmware on my Librem laptop and being able to verify firmware with my own GPG key.
I also think it's awesome that we have enough privacy-focused ROM choices on Android to be having this discussion :)