7 ms·
I just installed Graphene on a new pixel. I've only used it for two days, but I got that same feeling of "finding buried treasure in your backyard" I got when I
by jrexilius 1y ago
I just installed Graphene on a new pixel. I've only used it for two days, but I got that same feeling of "finding buried treasure in your backyard" I got when I first installed Linux in 1999. I can't believe this amazing software is free in all senses of the word. It is a TON of work and they got so much right. The security and usability settings give all the grainular control I've known was possible and wanted for a long time.
I see some core team on this thread, so just wanted to say THANK YOU! Awesome job! Keep fighting for the users!
I'm totally the wrong person to offer recommendations on mobile, but so far it works very well for me, but then, I use almost no third party apps, and none of them are Play store only. My only complaint is the hardware (outside of their control).
- 1024core 1y agoWhere do you get the apps from? Google's App Store?
- robmusial 1y agoF-Droid app store. https://f-droid.org https://f-droid.org
- morserer 1y agoAurora Store on F-Droid is a FOSS frontend for the Google Play Store that is a seamless drop-in. Requires no Play Services, nor an account.
- bboygravity 1y agoBut than the apps you download (your banking app) require play services right? So then what's the point of having a Play Store without Google Play services?
- ThePowerOfFuet 1y agoMany apps claim to require Play Services, but all my (several) bank apps work perfectly on GrapheneOS. No notifications because they rely on Google, but that is more feature than bug in my books. Signal brings its own notifications, so they work perfectly. The only app which was broken to the point of unusability was Too Good To Go, which demands that you pick locations on a map which relies on Play Services; the manual city entry is broken. I use Google Maps only in Firefox Focus, but I've heard that builds of Google Maps up to about a year or so ago didn't rely on Play Services, and with Aurora Store you can manually enter a build number to install. tl;dr: 10/10, fabulous experience.
- anthk 1y agoUh GF uses TooGoodToGo, I might try if it works with MicroG and the companion app which appears at FDroid (can't recall now the name, but it appeared with Droidify and some repos). It must be a Play Services API placeholder out there too. Install Droidify, enable the repos, and install "microG Services" and "microG Companion".
- ThePowerOfFuet 1y ago>Install Droidify, enable the repos, and install "microG Services" and "microG Companion". No thanks; I choose to forego Too Good To Go instead of that. They are the only truly broken app I have found.
- easyKL 1y agoNeed the Maps data, the satellite picture, or StreetView? All these past years this WebView wrapper have been working like a charm https://f-droid.org/packages/us.spotco.maps https://f-droid.org/packages/us.spotco.maps
- gf000 1y agoGrapheneOS managed to make Google play services into normal android services, without higher privileges that they have on other android systems. I am personally more than okay with using the official, proprietary GP services from time to time if they abide by the same rules, especially that I can make these rules as strict as I want.
- unethical_ban 1y agoNot all apps on play store require play services. And even if you install Google play on your graphene phone, it is still more isolated by default. Add that to the concept of storage scopes and more permissions control (apps have to ask for access to the network) and you have a more secure platform.
- homebrewer 1y agoIt doesn't work for everything; one of the banks I'm forced to use checks for how it was installed, and Android for some incomprehensible reason is happy to report that to any application that asks (along with lots of other information like bootloader status and developer mode — you really have fewer rights to 'your' device than random applications). After opening the application, it complains about being installed through an "insecure method", and bails. Reinstalling through Google Play magically fixes that. These "security checks" are spreading like measles, so expect to see this sooner or later.
- mschuster91 1y ago> one of the banks I'm forced to use checks for how it was installed, and Android for some incomprehensible reason is happy to report that to any application that asks That's because apps that aren't published just on the Play Store but also on other stores or for direct sideloads (for users running Huawei for example which doesn't have Play Store) need to be able to detect the installation method to do updates on their own if there is no backing store.
- const_cast 1y agoThe use case makes some amount of sense, but I think once an API becomes predominantly used for fingerprinting and the real use case becomes a side effect you should just nuke the API. It's the responsible thing to do. Apple has done it a few times.
- mikae1 1y agoObtanium[1], F-Droid[2], Aurora Store[3] and FFUpdater[4] are some options. Signal self updates from the APK download[6]. I recommend putting proprietary Play Store apps grabbed with Aurora Store in the work profile with Shelter[5]. [1] https://obtainium.imranr.dev/ https://obtainium.imranr.dev/ [2] https://f-droid.org/ https://f-droid.org/ [3] https://f-droid.org/packages/com.aurora.store/ https://f-droid.org/packages/com.aurora.store/ [4] https://f-droid.org/packages/de.marmaro.krt.ffupdater/ https://f-droid.org/packages/de.marmaro.krt.ffupdater/ [5] https://f-droid.org/packages/net.typeblog.shelter/ https://f-droid.org/packages/net.typeblog.shelter/ [6] https://signal.org/android/apk/ https://signal.org/android/apk/
- tkel 1y agoWork profiles are inferior to separate user profiles, which are built-in to GrapheneOS. Also "private space" is now available with Android 15 and can provide the same separation within a single user profile.
- Unroasted6154 1y agoDon't you have user profiles in Pixels? I can create another user an switch. Just not super convient. Work profiles are actually pretty good good... For work.
- piaste 1y ago> Work profiles are inferior to separate user profiles, which are built-in to GrapheneOS. Different use cases. User profiles are only active when you manually switch to them, while work profiles are active _alongside_ your main profile. So for untrusted apps that you only use occasionally and on-demand (like the myriads of travel / shopping / random services apps), user profiles are great. For apps that you want to keep in the background, such as the proprietary messaging apps that all your friends use, a work profile is much nicer.
- strcat 1y agoPrivate Space is very similar to a user profile but nested inside of another user. GrapheneOS adds shared clipboard control for Private Space which was the main disadvantage compared to a secondary user. GrapheneOS supports having a Private Space in secondary users instead of only a single one in Owner. Supporting multiple Private Spaces per user is a planned feature at which point work profiles will be fully obsolete. The remaining use case for work profiles is to have both a Private Space and work profile in the Owner user.
- nicman23 1y agohave you used something like lineageOS before?
- sierra1011 1y agoGrapheneOS? On a Pixel? You must be one of those criminals /s
- haloboy777 1y agoArrest this individual
- dgan 1y agodo you need to access your mobile for bank accounts ? does that work ?
- eraviloi 1y ago[dead]
- gf000 1y agoAs a single datapoint, revolut does not work unfortunately, so I moved back to the default pixel OS.
- cyanwave 1y agoI can’t recall the switch, I believe it’s mem exploit protection. When disabled it typically fixes banking apps. You tried that?
- senorqa 1y agoRevolut does work for me. They added support for GrapheneOS long time ago
- backscratches 1y agoDid you have to turn off mem exploitation? And have google play services? Revolut did not work for me recently.
- gf000 1y agoThanks, then I might have another go at graphene! That was the only reason I went back to vanilla "pixel OS".
- lollobomb 1y agoCan you please clarify the Revolut part? Just to understand, you are saying that you are able to perform NFC payments via the Revolut app which you installed on your Graphene OS through the official Play Store? Where are you based? (asking because I start having the doubt that it might be geo-dependent)
- AndyMcConachie 1y agoI agree. I love using Graphene OS. Came for the security, stayed for the lack of bullshit.
- lrvick 1y ago> I can't believe this amazing software is free in all senses of the word. I wish that were true, but if you delete the 100s of binary blobs (many with effectively root access) copied from a stock donor vendor partition the phone won't function at all. There is no such thing as a fully open source and user controlled Android device today.
- rtpg 1y agoWas there ever? And is the situation improving or worsening? I am alright with things that allow for improvement, at least in theory
- couscouspie 1y agoAnyways, we as informed consumers are hopefully all agreeing on striving for an open mobile OS and open hardware. For those of us, who consider themselves democratic, that is even an imperative.
- bornfreddy 1y agoNot sure what the situation is with Librem, Pine and Joola/SailfishOS, maybe those qualify?
- A4ET8a8uTh0_v2 1y agoI tried librem and pine a year or so ago. As long as it is basic phone use ( phone, text ), it is ok for daily use. That said, the experience is nowhere near ok experience in terms of speed or responsiveness, when compared to most basic android phones. I do not know if that changed since, but librem left a bad taste in my mouth based on how they seem to operate. Pine, by comparison, was a lot more honest about its limitations.
- strcat 1y agoThe Librem 5 and Pinephone are closed source hardware with closed source firmware. It's a misconception that they're open source. They have open source drivers, not hardware and firmware. SailfishOS is not open source itself. It's far less open source than Android which has the Android Open Source Project with the whole base OS.
- csmattryder 1y agoI got it installed last weekend, really powerful mobile OS. I did do about three weeks of research, as I worried that maybe a number of apps wouldn't run on it or needed some form of deep attestation. Didn't find much, OpsGenie and other work apps are happy with the GOS level of attestation provided. Great to have Google kicked off the phone. So nice to shut off the network permission for any apps that only require an internet connection to serve ads. One tip from me, if you came from stock Pixel: You can download the default Pixel sounds and set them up like it was. Have a look for "Your New Adventure" online, the message sound is "Eureka".
- exe34 1y ago> So nice to shut off the network permission for any apps that only require an internet connection to serve ads. For those of us who aren't ready to cut the umbilical cord to the mothership, you can also root/firewall on normal android to stop this. In fact I choose to not be able to use banking apps in order to cut out the crappy ads.
- morserer 1y agoRoot, while more efficient, isn't strictly necessary. AdAway (FOSS, F-Droid) can run without root using the stock Android VPN backend.
- exe34 1y agoI use both adaway and AFWall+, as I don't like random apps making random connections, even if it's not for adverts. Once google play store ate my monthly data allowance, and it will never happen to me again.
- strcat 1y agoRethinkDNS is implemented as a VPN service but it has support for local filtering combined with optionally using a WireGuard VPN or multiple chained WireGuard VPNs. You can have both via the VPN service API rather than choosing one or the other. No need for app accessible root access.
- 1y ago
- throwaway-0001 1y agoI think they don’t even have basic location mocking. They have disable or enable. But some apps won’t work.
- eks391 1y agoNot by default, but there are several apps on F-Droid that do this
- johnisgood 1y agoCan you give me one that works on a stock Android? I used to use one but it no longer works on newer Androids.
- strcat 1y agoIt's a standard Android feature with various apps available for different use cases. Some are for setting a specific location, others are for using an external device. It's a very generic feature. GrapheneOS plans to add a different feature called Location Scopes similar to our Contact Scopes and Storage Scopes features for setting a per-app location. Android's Mock Location is global.
- skim 1y agoI believe this is in the works: https://bsky.app/profile/grapheneos.org/post/3lqbhoqwrjs2y https://bsky.app/profile/grapheneos.org/post/3lqbhoqwrjs2y
- strcat 1y agoMock Location is a standard Android feature available in GrapheneOS. Our upcoming Location Scopes feature is being added for per-app control rather than global. It's fairly pointless for apps to check for Mock Location being active without also verifying the OS via the Play Integrity API or hardware attestation API. Most apps checking for it are using or in the process of adopting the Play Integrity API. Apps enforcing the Play Integrity API basic/strong integrity level won't work on GrapheneOS unless they explicitly allow it. A growing number of apps doing this are explicitly allowing GrapheneOS. It would be counterproductive if our Location Scopes API didn't provide a way for apps to check if since those apps simply wouldn't permit GrapheneOS. However, it doesn't need to be the existing Mock Location API. It can be our own API which would only be used by apps explicitly choosing to permit GrapheneOS. This would allow apps like Pokemon Go and Ingress to permit GrapheneOS even if they insist on not allowing directly spoofing location.
- squigz 1y agohttps://grapheneos.org/donate https://grapheneos.org/donate If you want it to stay free