4 ms·
I just bought a pixel from best buy to install gos, which was an ordeal. At checkout they looked at me like I was up to no good when I said I didn’t want to gi
by electric_muse 1y ago
I just bought a pixel from best buy to install gos, which was an ordeal.
At checkout they looked at me like I was up to no good when I said I didn’t want to give them my name, address, and phone number just to purchase the device. I didn’t set up a plan. They said it was for “restocking” or something.
Fortunately they accepted obviously fake info. These front line sales people just don’t care as long as they can say they followed the policy.
The user containers are very helpful. I have to have TikTok for work and I put it in a container all by itself with a vpn on kill switch. And for one app that needs google play services, I have it a container with that.
The duress passcode is super clever, too. You enter a different device passcode and it just wipes the device.
- codethief 1y ago> The user containers are very helpful You mean different user accounts? Those are available on stock Android, too.
- a0sud0a8s 1y agoTrue, although on GrapheneOS, apps on different profiles can remain active when you switch and notifications can be sent to the primary profile if you choose.
- ysnp 1y agoI think it depends on the Android distribution. I am not sure it is available on Samsung's One UI.
- gertop 1y agoMultiple user is available on Samsung. Both multiple profiles as well as work profile. Samsung also has "secure folder" which isolates apps and files and presumably uses multiple users to do the isolation.
- ysnp 1y agoApparently multiple user profiles is available on their tablets but not on their smartphones.
- strcat 1y agoSecure folder is an older approach to what Android provides via the standard Private Space feature since Android 15. Private Space and work profiles are based on the same infrastructure as secondary users including per-profile encryption keys, although typically work profile management apps don't take advantage of it.
- aucisson_masque 1y agolast time I tried, my samsung phone couldn't use multiple profiles. it is a setting that has been disabled in oneUI since a few years. Don't ask me why.
- subscribed 1y agoOn GrapheneOS they're profiles. Pretty much the same as with the stock aosp, but they add very extensive support - like notifications forwarding and a perfect balance between security and convenience, 2FA with shorter pin.
- codethief 1y ago> but they add very extensive support Huh, I didn't realize they had added additional functionality not present on stock Android. Thanks!
- electric_muse 1y agoIt's incredibly useful! I have one profile for the "social" apps I don't trust (TikTok, Reddit, etc.). They can commingle. And there's another profile that contains the apps that rely on Google Play Services (e.g. something relies on google maps). As far as I understand it, it's like a strong firewall between them such that they are pretty close to having multiple different phones.
- codethief 1y agoWhat about settings, though? Don't you have to set up each user profile separately? Also, what if you ever want to share a file across user profiles?
- gruez 1y agoSee: https://github.com/VentralDigital/InterProfileSharing https://github.com/VentralDigital/InterProfileSharing It also shows that profiles can't really prevent an app from correlating profiles on the same device, by listening on a local socket.
- tranq_cassowary 1y agoIf you disallow Network permission to an app (a GrapheneOS feature), local network access is also disabled.
- strcat 1y agoYes, but a small subset of the GrapheneOS features are enhancements to user profiles and Private Space. We enable more of the standard user profile functionality that's usually not available (such as ending secondary user sessions or toggling them running the background) and add extra features such as notification forwarding. For Private Space, we enable making them in secondary users instead of only Owner and provide control over clipboard sharing instead of it always being shared with the parent profile (the user it's nested in). Our more prominent 2-factor fingerprint authentication feature is also relevant when switching between users a lot.
- shaky-carrousel 1y agoThe only thing I don't like from private space is that all notifications from apps inside private space are hidden. Wish that was configurable. I use private space for containerization, not to hide things.
- dosshell 1y ago> I have to have TikTok for work I'm sorry but what? Your job demands what apps you have installed on your PRIVATE phone!?
- TranquilMarmot 1y agoI would assume for advertising/business account. There are things you can only do on the TikTok app that you can't do on the web.
- ffsm8 1y agoAll jobs I've had since the mid 2010s essentially did the same for me by requiring 2fa in certain contexts
- usr1106 1y agoWhat kind of 2FA? I run OTP on my work laptop. Yes, it's maybe not really a 2nd factor if someone had access to my laptop with LUKS open. But at least I don't expect any automated attack because it's my own piece of code using an otp library.
- carlmr 1y agoOnly my most recent job is doing this. Before the job provided a phone for 2FA that I didn't use much outside of that.
- electric_muse 1y ago
- glitchc 1y agoDid you pay cash? If not, you already gave them your real name and info.
- pabs3 1y ago... and did you get the cash from an ATM? or other source that tracks serial numbers?
- pbmonster 1y agoDo you think Best Buy assigns cash serial numbers to individual products they sold, by default, always? How would they even do that? As part of the machine that checks for counterfeit notes? They don't always use that, right?
- alt227 1y ago> Do you think Best Buy assigns cash serial numbers to individual products they sold, by default, always? No but when you took that cash out of an ATM, it logged the serial numbers on the bills it gave you. Then when Best Buy deposited that cash at the bank they again scanned that serial number and can make an assumption that you spent that money at Best Buy. What that information is used for, who knows? But the flow of cash is definitely logged somewhere, for some reason!
- pndy 1y ago> (...) my name, address, and phone number just to purchase the device That's a thing in the US? Here, clerks in various stores ask me for postal code but nothing else and I could refuse giving that info.
- drnick1 1y agoI recently bought a Pixel from a Google store and wasn't asked any personal information. I installed Graphene right away and the phone just works. I use FOSS apps obtained on F-Droid and don't bother with sandboxed Google Play and all that. For me that kind of defeats the point of a FOSS OS.
- madmads 1y agoThat was my experience too. Up and running in 30 minutes, I was quite surprised
- throitallaway 1y agoYeah, I'm just worried about the future of this with the AOSP and "sideloading" changes that Google is making to Android.
- tranq_cassowary 1y agoThe planned sideloading instructions only apply to certified OSes. GrapheneOS is not certified because it doesn't bundle privileged Google Mobile Services.
- mewse-hn 1y ago> I recently bought a Pixel from a Google store and wasn't asked any personal information. A physical pop-up? The online google store requires a google account that has your personal info already..
- tranq_cassowary 1y agoSandboxed Google Play doesn't really defeat the point of GrapheneOS. Not wanting to use Google Play or any proprietary Google services is perfectly valid, for all clarity. But, it's just important to note that for people that heavily use Google services, the advantage of using those on GrapheneOS instead of on a GMS-licensing OS is very high. The GMS-licensing OS will bundle the Google Mobile Services (Google suite off apps, Google Play, ...) in a privileged way. They won't be treated as regular apps, as is the case on GrapheneOS, but will have invasive access on your phone. In general, GrapheneOS' many hardening and privacy features allow you to have a better grasp on privacy-invasive apps.
- vid 1y agoObviously avoiding surveillance can be a bigger red flag than being surveilled. I use a google account for convenience for some purposes, and host my own email (out of principle, not exactly super interesting material). It would be nice if when I enter the 'duress' password it erased everything except the gmail related activity.