GrapheneOS recommended for domestic abuse victims
privacypros.com.au
privacypros.com.au
For example:
Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier.
And that's not even mentioning the other problem that nobody can download IceBlock anymore[1].
It's so refreshing for my phone not to ask for any identifying information when I set it up. GrapheneOS is a better software experience than iOS anyway[2].
Phones have great potential to be the most private and secure computers, cell services not withdrawing. And iPhones are one of the most private and secure devices. But, Apple uses that to restrict its users freedom and it makes Apple's users can easily be controlled by any government.
GrapheneOS delivers that dream.
[2] once you install good apps. This is coming from a lifelong iOS user. Not prejudiced against Apple, I use a Mac (without an account) and their Advanced Data Protection is great (when I had an account).
[1] https://grapheneos.org/articles/attestation-compatibility-gu...
For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run).
Another example of this is the Australian eTA - (Everyone has to have a visa to visit Australia.. but the real only way to get a visa* is you have to get an electronic travel authorization which only works via an App)
https://grapheneos.org/articles/attestation-compatibility-gu...
Apps that ban graphene-os being used:
myGov (Australian government app)
gov.br (Brazilian government app)
Ticketcorner
Authy
Chyrpe Dating
TextNow
mada Pay (Saudi NFC payment app)
McDonald's (International app used for many but not all countries not including the US)
Dott
My SEAT (Connectivity for SEAT cars)
SwissID
Volkswagen
BKK Faber-Castell & Partner
TK-Doc
TK-Ident
TK-App (Blocks access to TK-Safe, TK-GesundheitsMessenger, fingerprint login)
IO (Italian government app which uses it to gate access to the digital wallet feature)
PosteID (Italian postal service’s app used to access the national digital identity system "SPID")
SingpassThat's untrue.
There was a strong push towards the digital ID from the current administration, but it was abandoned 6 months ago.
What you likely mixed up with digital ID is the old digital visa scheme, mandatory for all non-UK citizens to prove right to work.
Re: your app list: looks a little bit eclectic, so it's worth mentioning most of the apps don't ban GoS specifically, but enforce Google play strong or device integrity pass, which GoS doesn't pass.
Some trip on some exploit protections, like secure app spawning, but these can be turned off per app in the latest releases based on Android 17.
Weren't they accepting refugees without documentation?
I don't know, probably? That always was an offence[1] anyway.
New scheme, mandatory digital ID, would simply stop Britons from being able to use their physical passport to prove they can work. For everyone else that would swap existing electronic-only scheme with another electronic-only scheme.
I don't think anyone half awake would mistake a refugee with a Brit. At least it's not a problem that would explain introducing a whole huge PITA -- like with mandatory IDs for voting: if I'm not mistaken TWO people total were sentenced for voting-related offences, yet we spend double digits of millions of pounds only to (knowingly) disenfranchise voters traditionally voting against the Conservative government.
Look, I'm a citizen of the EU country and my country's physical ID holds electronic layer containing private keys I can use to remotely sign stuff or authenticate myself. It also allows me to using a digital only ID, and the app ecosystem around that is truly amazing. And I'm a picky one.
Basically it's everything, along with basically every single one European physical ID with electronic layer built-in.
British digital ID was *nothing' of that. If it was a physical smartcard first, optional and not mandatory, I'd probably support it, but the government messaging about that was full of lies and handwaving, especially when people were bringing up the failures of digital only systems like Settled Status for Europeans. Nothing mattered, steamrolling over arguments with soundbites.
No, long story short: no, digital IDs are NOT mandatory and no, employment fraud is not that widespread, and the new system won't fix the employers skirting the law.
[1] https://www.gov.uk/government/publications/illegal-working-p...
False
In fact I can't think of a single Government service or legal requirement that requires a smartphone in the UK.
In the past year I have applied for a passport, applied for benefits, opened a bank account, passed through border control, filed a company tax return, closed down a business, helped someone else claim for benefits, made police reports, filed a case with the small claims court, paid my council tax, received an incone tax refund, travelled on public transport extensively, hired a car.
All had alternatives as far as I can recall.
Quite a few were done online just with a computer and optionally a phone number
And based on prior discussions here I have to point out that "require" doesn't mean "ok but the alternative is kind of inconvenient"
Sucks... At least brazilian banks don't ban it. At least not yet.
A new building is being built in my city, and the trash containers which were installed outside have instructions printed on them, indicating that you need to use a smartphone app to take out your trash.
I found this deeply offensive in a way that I cannot explain.
What good is free software if using it marks our devices as untrusted and gets us banned from every service out there? Gets us ostracized from digital society? Because we "tampered" with the device?
We should be able to run whatever software we want and they should be none the wiser. Instead, we are part of the threat model now. Our devices are now cryptographically attesting that they are corporate owned and that we are under corporate control. It's so disgusting. The future we're heading towards is terrifying. Everything the word hacker ever stood for will be destroyed if this keeps up.
[1] attestation.app
And even if our own keys could be used, who's going to trust those attestations? Nobody. They will trust Google's keys, Microsoft's keys, Apple's keys. Not ours.
but no one uses blind signatures for attestation so it can be used to fingerprint your device's serial. they do try to make it hard. but generally you should assume that if whoever you are attesting to colludes with google they will obtain your HWID - and if it's google you are attesting to you should assume they have your HWID.
GOS uses a proxy for attestation, but it does absolutely nothing for this threat model.
PS: DRM is even worse, there is no intermediary and the APIs are open to all apps. you probably need to be a well resourced intel agency to make use of it as you need to source a valid DRM license server certificate. technically, actual license servers are in violation of their agreements with google, apple, etc if they use the license request for fingerprinting. but they do retain the ability to blacklist silicon (invalidate pirate devices from pirated media watermarks).
That is not what remote attestation is for. The operating system maintains isolation between apps, so a free software app being installed doesn't mean an app that needs high security is compromised.
In a world of deeply untrustworthy Big Tech, and trend of governments, banks and other basic services needed to exist in society relying on apps and in the future, websites that use remote attestation, that is very troubling.
There are better ways of dealing with the bad actors problem, but Big Tech has chosen violence.
Case in point: GrapheneOS (or any other custom Android distro) is unlikely to be able to ever pass remote attestation, even a signed, secure boot build with the bootloader relocked, because it's not the original OS for the hardware.
Same goes for any desktop Linux.
I still think destroying the playing field is better, but less likely to succeed.
This isn't about you attesting anything though. It's about corporations attesting that your device is 100% corporate owned. Can't have you running software that impacts their bottom line after all.
GrapheneOS could be the most secure operating system to ever exist, it doesn't matter to the corporation because it's still under your control. When they say "security", they mean "the corporation's security against the user", not "the user's security against the hostile world out there".
The hypervisor maintains isolation between operating systems, so a free operating system being installed doesn't mean an app that needs a high security operating system is compromised.
And who maintains and "runs" that hypervisor?
There is no such a thing as "just buy a different device" when this "different device" is actively discriminated against to the point it's a paper weight. I wouldn't be surprised if remote attestation becomes necessary to even get an internet connection in the future.
Even worse, GOVERNMENTS do that. EU Governments basically forcing you to give Google (via the Google Mobile Services rootkit) or Apple (and via the cloud act also the Trump Admin) access to your entire phone (including all of your saved personal data) to use the govt eID system...
If it were only that and we actually had “free market capitalism” and “competition” you could simply choose, but leering and steering these “organizations” is the treasonous and inherently illegitimate government, which is increasingly indistinguishable from private corporations, mostly because it’s the same pool of people, which are reflexively moving us all towards a common focal point of a form of tyranny similar to hereditary oligarchy and/or serfdom.
But there is ONE feature I love on iOS and it’s the Live Photos. I feel like it’s an amazing way to keep family memories. Do you know if it exists on GrapheneOS?
I run pixelos and the amount of stuff I miss from iphone is staggering, the difference between pixelos/grapheneos isn't as big as the difference between iphone/pixel.
No back button on iOS is madness and also the Android rotate screen integration is way better than iOS.
Tap to scroll might be possible to get also. Haven't felt need for it when it takes a few regular scrolls anyway.
Even safari... On Android, you get chromium that doesn't have any extension or Firefox that has incredibly frustrating UI and doesn't work well on some website.
There are 3rd party camera apps that support it, but you'd have to download them separately. GrapheneOS camera app is fine but nothing outstanding. It will give you decent pictures but don't expect any fancy upscaling or editing features.
Yes there are still identifiers when using cellular data service, but they aren't connected to your phone number that you give out. Phone number gets a determined threat actor real time location, which is what I explained. Threat actor gets location from any carrier identifier. Cellular was built in a terrible way for privacy and security.
Android doesn't let apps see hardware identifiers if that's related.
Yes you're correct about having to trust Apple, but my point is that the way Apple is collecting all this extra info allows them to be compelled to hand it over. It's not about trusting Apple, it's about them following the law, which they will do.
Yes, you need to use F-Droid & Co. to get apps (just like on Graphene), but otherwise they're functional and many people are actually using them like that.
Nowadays it seems a lot easier because there seems to be a separate profile isolater you can run in the main profile, which I would choose if I was installing today.
The only hiccup I've had is that sometimes group messages don't send correctly and send individual messages to everyone, but I think that's because I'm on a secondary profile, and it only happens when the phone is receiving a bunch of messages all at once while I try to send to the same group. But I deny network access to my installed swype keyboard, so it may have something to do with that too.
I've been running this for years, since the Pixel 7 came out, which I'm still using.
I love it. I can confidently go through customs knowing that if they yank my phone during some weird checkpoint and try to celbrite it, I'm as secure as can be.
1: https://gitlab.com/fmd-foss/fmd-android
2: https://grapheneos.org/articles/attestation-compatibility-gu...
3: https://privsec.dev/posts/android/banking-applications-compa...
Many people want to segment things more than that by having a dedicated profile for apps depending on sandboxed Google Play. A work profile, Private Space or secondary user can be used for it. A work profile or Private Space is a lot more convenient. Using a work profile avoids wasting the Owner user's Private Space if you want to use it for sensitive data. We want to add support for multiple Private Spaces per user in the future instead of only 1 per user to fully obsolete work profiles for local usage.
How would that be achieved
We could assume that a user could make their own computer "private and secure"
But if a third party, e.g., Apple, Inc., Google, LLC, GrapheneOS Foundation, etc., has RCE, e.g., "auto-updates", then how can the computer be "private and secure" against that third party and any party that they "work with", voluntarily or not, e.g., a business partner, a government, but also others that might target these third parties, such as an attacker who isn't interested in their bug bounty programs, etc.
To achieve "private and secure", would the user need to remove the RCE capability of the third party (parties)
What about data collection and surveillance by the third party (the user would have to review the source code and compile the OS themselves to be sure about data collection and surveillance)
If there is data collection and surveillance, then how could the user be sure that the data collected and surveillance capability held by the third party is "private and secure" from that third party (e.g., Apple, Google, etc.), any third parties that work with them, and others who might target these third parties
Assuming the user even knows the identities of all these third parties, what if their operations are secretive and non-transparent
What if they have a history of dishonesty
What if they make no promises to the user that could be enforced and instead they just assume "trust"
Perhaps each user might have a different concept of "private and secure"
Australia has a national test of it's phone alert system in 10 days at 27/07/26, 2PM AEST. (People in North America would know it as Cell Alerts/Presidential Alerts etc.)
There have been warnings that hidden phones will almost certainly sound, and their recommendation is to ether power off the phone or put it into airplane mode at least an hour before the test...
Yes, GrapheneOS of course allows this.
Edit: re followup comment.
No, adb cannot be used in all cases to disable the packages involved. At all. Some phones refuse to lets users disable some packages, no matter what.
Yes, I know what I'm talking about.
As someone with decades of Linux and Android experience, who often works nights, having Quebec police use presidental alerts... CRTC regardless, to warn of a child abducted by a parent 2000km away from me, is an exceptionally strong motivator.
The sheer stupid of an alert you cannot control the volume, sound, and length of in any way, is absurd. Try going back to sleep after something screams at you, at your equiv of 2am is madness.
By god I hate those alerts.
So yes, I know. If you don't have root, and the phone won't let you disable some packages, you're done.
And it's another reason I like GrapheneOS.
She ended up disabling the alerts entirely, which seemed a shame to me, but the ear splitting siren every 5minutes wasn't really conducive to our sanity or our dog's or our ability to actually hear the weather radio.
Moreover, it's a huge pain to get to the history of emergency alerts, which seems like a design flaw. Surprising how poorly a critical life system can be designed.
Their phones are more than twice as expensive as equivalent models at JF HiFi too (and 5-10x the price of an older, but still perfectly useful degoogled phone from Marketplace).
Why is it on the front page of HN?
> and 5-10x the price of an older, but still perfectly useful degoogled phone from Marketplace
Devices with drastically worse privacy and security than the Android Open Source Project including lack of bare minimum updates aren't in the same space as GrapheneOS.
It's generally better for people to install GrapheneOS themselves since it's very easy and saves a lot of money. It takes 10 minutes to install GrapheneOS with the web installer. It also avoids needing to trust a company to do it, although it's possible to verify an install done by someone else is genuine with the verified boot key fingerprint and/or Auditor. An existing install by someone else should be factory reset it to avoid any sketchy configuration.
The linked post is a mess which was probably generated with an LLM. GrapheneOS does have useful properties for this even though it isn't the focus. Someone could write a proper article making a case for it even though this isn't one.
GrapheneOS is free and we recommend people install it themselves with the web installer. People can also save a lot of money getting a used device, but we strongly recommend against an older device than a Pixel 8 due to support time. A used Pixel 8a tends to be the cheapest option. An important thing to watch out for with used devices is avoiding ones which were originally sold by carriers locking their devices. Some phone sellers wrongly label locked devices as being fully unlocked.
If people buy a device with GrapheneOS instead of doing it themselves as we recommend, we a guide to follow to make sure it's genuine GrapheneOS and get rid of any strange software or configuration it ships with:
I mean in the long run, it should be a good thing to separate out the hardware phone market from the OS it comes with IMO. And for large scale adoption, it's extremely useful to have the most non-technical people using your OS, because they will complain and bugs will get reported (maybe not through the preferred channels, though).
No notes on the markup though. Infuriating there's no negotiating ability to say "you can't sell this OS on a cheap phone for 600% margins".
I have notifications turned ON for WhatsApp, Signal and Telegram. I never receive notifications from Telegram. I have to open that app to see if anyone said anything. WhatsApp and Signal notifications seem to vary between late or never? This is despite a constant notification reminder that Signal has Background connection enabled.
Also I can only send messages to some whatsapp contacts. My messages appear as pending for a while and eventually turn into 'could not send'.
All of those apps support using google services FCM for push notification delivery. I dont think Telegram has a fallback, and Signal and Whatsapp have power-intensive fallbacks. You may also need to reinstall these apps for them to detect google services (apps generally dont check for google services more than once on initial launch).
I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS.
So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at least give you the option of installing all that crap but that would seem to defeat the purpose in this case.)
But more broadly I'm not sure I understand the relevance in this particular context. The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario? (Ok I suppose half the stuff on the Play store is spyware so maybe it's more realistic than I'm thinking...)
Their docs are really good, not only for their phone but for learning about privacy and security: https://grapheneos.org
You could still install an app that spies on you on grapheneos because it has 99.99% android app compatibility, so if you gave an app designed for spying the relevant permissions, it would still be able to spy. No way it could hide location indicator or anything like that, but I doubt it could do that on other OSes (don't quote me on other OSes).
- App isolation and hidden profiles (up to 32 separate profiles)
- Verified Boot (tamper detection on every startup)
So you can do stuff on there that's not going to tip off someone who's controlling enough to demand to see your phone, and so you'll at least be tipped off if someone compromises it.
I am a happy user of GrapheneOS, I don't know about "hidden" profiles. I am not sure what they are talking about.
> App isolation
That's an Android thing, not specific to GrapheneOS.
> Verified Boot (tamper detection on every startup)
That's an Android thing, not specific to GrapheneOS.
Stock Android runs the tamper detection just the same; they just don't warn about the custom keys because the keys are not custom, they are the ones expected by the manufacturer :-).
Yes, stalkerware is an entire genre of software and it is designed for exactly this purpose.
How “stalkerware” apps are letting abusive partners spy on their victims https://www.technologyreview.com/2019/07/10/134249/stalkerwa...
The Abuser in Your Pocket: How Stalkerware Threatens Women’s Privacy https://safeescape.org/stalkerware-threatens-womens-privacy/
'I thought I'd been microchipped': How abusers spy on partners with 'parental control' apps https://news.sky.com/story/i-thought-id-been-microchipped-ho...
A web search for the term will turn up many more results. Graphene OS's hardening against exploits, compared to the abysmal record of Android vendors, gives much better odds against any of these apps being able to run with elevated privileges, which means Android's sandboxing is effective.
(Happy Graphene OS user of many years here.)
I am having a hard time believing your first link, which says:
> In Anna’s case, stalkerware was disguised as a picture message, sent to her by the man she was dating (let’s call him David), just a few weeks after they met. She was then under constant surveillance for about two years
That sounds like an NSO-level attack, right? I doubt abusers routinely pull that out?!
I totally get the problem that "the abuser knows the iCloud password and can use the FindMyPhone feature to track the victim", or "the abuser convinced the victim to install an app that would track the victim without their consent". But I am genuinely wondering how much GrapheneOS protects against that.
Not really, these are available to any script kiddy as long as unpatched phones and software exists. It takes some initial effort to find them out, but that is it.
And I remember similar attacks floating around few years ago even outside domestic violence situation.
There are many tiers of far easier remote attacks far easier than exploiting an up-to-date iPhone through iMessage of WhatsApp. It doesn't mean that's what happened but it's often not something that's extremely difficult. Many people use phones with years of missing security patches. It's getting increasingly easy to exploit those in the age of LLMs.
Regardless, it sounds more like a social engineering attack tricking someone into installing an invasive app and granting invasive permissions to it.
> I doubt abusers routinely pull that out?!
They do regularly use social engineering to trick their partners into setting up stalkerware or permitting it to be installed. Getting a new phone and accounts is a very helpful for people who are victims of it. They've often given access to their accounts and devices without knowing how to fully get rid of it. Reclaiming the existing devices and accounts is far easier if they have a clean one to start from where they can get technical help. It doesn't specifically need to be a GrapheneOS device, but it's a good choice in general and doesn't require being technically savvy to use or even install it.
Right, yeah that's actually a good reason to use GrapheneOS.
> It doesn't specifically need to be a GrapheneOS device, but it's a good choice in general and doesn't require being technically savvy to use or even install it.
I totally agree here. Very good choice, and I would argue that a "normal" person wouldn't make the difference between GrapheneOS with sandbox Play Services and stock Android. Installing may be intimidating, even though the GrapheneOS installer is extremely impressive (it just works and doesn't require any knowledge). Still normies tend to get intimidated just from the idea of reinstalling their system :-).
GrapheneOS is a privacy and security hardened OS. LineageOS and CyanogenMod aren't in that space. GrapheneOS preserves the standard privacy and security features and updates of the Android Open Source Project as a baseline. It greatly improves privacy and security with major privacy and security features along with much better privacy/security updates. It keeps up with the major OS updates including having a release based on Android 17 since the day it was released (2026-06-16).
> Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS.
GrapheneOS is a production quality OS with around 15 people paid to work on it. It's not a hobbyist project. We've never used the term custom ROM since it isn't accurate and propagates misconceptions. It's best to avoid it.
> The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario?
Yes, stalkerware is very common and there are a bunch of apps marketed for this purpose. It's helpful to get a new phone set up from scratch without the same accounts or automatically restoring any data on it. This can be a GrapheneOS phone but it doesn't particularly need to be. It's not GrapheneOS recommending itself for this purpose. There are an assortment of privacy and security features relevant to this in standard Android 17 and in the features added by GrapheneOS but nothing essential to this. GrapheneOS makes sense as a general choice for a new phone for many people due to being a highly usable, compatible, private and secure device but we're not specifically recommending it for being who are victims of stalkerware ourselves.
It's a ROM (in the phone sense), and it's not stock (so installing it is a customization). In what way is it not a custom ROM?
There are multiple ROMs involved but GrapheneOS isn't one. There's an SoC boot ROM which loads SoC firmware from the SSD, verifies it and transfers control to it. The littlekernel-based firmware stage which loads GrapheneOS isn't a ROM. GrapheneOS and most of the SoC firmware are simply stored on SSD partitions. There are A/B partitions for both the SoC firmware and the OS on the SSD. Installing (flashing) GrapheneOS involves writing out images to those partitions on the SSD and erasing an existing data partition which also happens as part of unlocking or locking the device. Those partitions aren't read-only from an OS perspective. Verified boot secures what's stored on those, not any form of hardware or firmware level write protection.
There are also boot ROMs for other hardware components. Many of those are responsible for receiving firmware uploaded by the OS to the hardware component at boot, verifying it and transferring control to it. The secure element has separate persistent firmware with a separate verified boot process since the OS isn't allowed to update it until the Owner user has successfully authenticated so it needs persistent firmware. Other hardware components mostly don't need persistent firmware and it's more secure if they don't have it.
> it's not stock
GrapheneOS will be available as the stock OS on multiple Motorola Mobility devices based on our partnership. It won't necessarily be available as the stock OS when the official support for it launches since it's not one of the minimum requirements but it's planned.
> so installing it is a customization
It's a separate OS forked from the Android Open Source Project but this terminology gives many people the incorrect impression that it's a modification of the stock OS. It leads to many people asking questions about what it removes from the stock OS and believing we removed Google integration when that was never present in the baseline. There are a lot of misconceptions which are propagated by this terminology. We don't use it and think it only serves to create unnecessary confusion and misconceptions.
> In what way is it not a custom ROM?
It was just never accurate terminology for forks of the Android Open Source Project on modern devices. The terminology originates from phone modding prior to Android and there was a time it made sense. It hasn't made sense for a long time.
Why?
Here we're discussing a domestic abuse situation, where people are forcing victims to hand over their phone, and have apps installed to keep track of them. Against their will.
And the solution is to... what? Mysteriously have control of your own phone, and install an OS which prevents this? Seriously? I can just imagine it, when the unfamiliar OS is discovered, or the app not working. This is a domestic abuse situation, it's not about hidden sneakiness.
It's about in-your-face control. It's about forced compliance, or else. It's about the abuser becoming exceptionally upset about their tracking not working, or about a new, mysterious OS.
Installing GrapheneOS would not be tolerated. It would be an act which comes with reprisals. I can just imagine the reaction when the abuser can't get the phone to do as they wish, for the person to disclose what the OS is, or just to hand over their unlocked phone, and discover it's GrapheneOS, and Google it and see what it's for.
It's actually horrible advice to advocate the someone in this situation installs GrapheneOS. How could it possibly help?
GrapheneOS is great to protect from secret, unknown spying. Not some domestic abuse situation where spying isn't via secretness.
Let's not normalize this kind of profiteering out of OSS.
They also recommend at least 12 GB RAM. What about domestic abuse survivors requires that?
It has 99.99% android app compatibility. Over 90% of banking and government apps work. These apps take extra measures to ban grapheneos, apps must put in work to make their app incompatible, not the other way around.
I wouldn't say anyone can use it, if you can't sign in to a Google account by yourself then you would have trouble setting it up. But that would be similar on iOS. For the average person, definitely. There's no code or anything like that. Works just like stock Pixels.
If I was giving it to my grandma then I would install her apps and she would be fine clicking icons. But similar on iOS.
Yeah that RAM mention is very strange, not the best article.
> anyone can make something insecure
Many consumer products, including iPhones to a significant degree, are designed to prevent this, much to the frustration of hackers. 'What do you mean I can't sideload random apps?' Or other products: It takes a lot of effort to make your car insecure, or to make your stove leak gas. They are carefully designed for safety.
Two tips for beginners:
Google Play Store and Google Play Services can be installed from the App Store. They aren’t included by default because GrapheneOS works fine without them.
If a trusted app has trouble running, try enabling Exploit protection compatibility mode on the app’s Info screen (long-press the app icon → Info → Exploit protection).
Check whether your bank is supported: https://privsec.dev/posts/android/banking-applications-compa.... If it isn’t, it likely depends on the Play Integrity API, which means it requires customers to stay under constant surveillance by the world’s largest advertising company, with no real security justification (see https://grapheneos.org/articles/attestation-compatibility-gu...). In that case, you should switch to a more trustworthy bank.
> Google Play Store and Google Play Services can be installed from the App Store.
Few will manage this on their own. What is Play Store? And what are Play Services? What does 'services' mean? Do I need both? Can I just use one or the other? When would I use them?
> They aren’t included by default because GrapheneOS works fine without them.
It doesn't, from what I understand. For normal users, 'works fine' means they can download and install any app.
> If a trusted app has trouble running, try enabling Exploit protection compatibility mode on the app’s Info screen (long-press the app icon → Info → Exploit protection).
lol - 'exploit'? 'mode'? 'app’s Info screen'? Even 'long-press' is not usuable by many, especially older people and others with less manual dexterity than 20-something software designers.
> you should switch to a more trustworthy bank
That isn't a serious solution. I love GrapheneOS, but it isn't ready for typical end-users.
How did we get there?
I wouldn’t recommend domestic violence victims to install graphene os on their phone by themselves
"Australian research shows that 99% of domestic violence cases now involve some form of technology-facilitated abuse."
Where the "Australian research" is linked to a page where the first Key Finding states:
"Over one quarter (27%) of domestic violence cases involve technology-facilitated abuse of children."
Doesn't fill me with confidence in anything they say (even if I do believe the advice is right).
Technology-facilitated abuse is becoming more and more of a key feature of domestic and family violence. A 2015 survey of 546 domestic and family violence frontline workers found that 98% of respondents had clients who had experienced technology-facilitated abuse.
The research then focuses specifically on children, finding that of all the domestic violence cases, 27% involve technology-facilitated abuse of children.Can you expand on what it is that "Doesn't fill [you] with confidence" ?
* Page 9: https://www.esafety.gov.au/sites/default/files/2020-12/Child...
98% of "frontline workers" having direct experience of "Technology-facilitated abuse" (ie. have encountered at least one case of it out of all their cases)
is very different to
98% of "all domestic violence cases" involving "Technology-facilitated abuse".
[1] attestation.app
Getting a new phone is very useful to someone that's a victim of a controlling partner but it doesn't particularly need to be a GrapheneOS device. GrapheneOS has features useful for this including Auditor and standard Android profiles but we're not specifically recommending it for this ourselves. People who are victims of this probably just need a new phone of any kind and to prioritize other things.
It's not like Google is going to sell your tracking data to abuser.
There are many reasons to get rid of Google altogether, I just don't understand this one.
The tl;dr is that you can either share this data by accident through some sort of "locate my family" app, or because your abuser gets access to your Google/Apple account (for instance because you're signed in on another device they have access to).
The threat model here can be: domestic abuse victim flees a situation at home in a hurry, stays signed in on a computer. Abuser uses the sign-in on that computer to track their phone, figures out they're staying at their aunt's place.
Yes, you can avoid this on a regular Google phone as well, but that requires correctly configuring it (and a lot, such as location and search history, can be re-enabled remotely!). If you're running Graphene you are protected by default, rather than compromised by default.
Technically you can use fdroid, Aurora store, or only use stock applications but if we are serious, not all domestic abuse victims are also geeks that know how to do all these things.
They will need their apps, for instance for social security. Also, many people use their phone to pay nowadays, can't do on grapheneos.
Domestic abuse is a serious threat and people are motivated to stay away from their abusers, but if you give them something so barebone that they can't do 90% of their stuff, a significant percentage of them will revert to their old behavior and risk compromising themselves. For instance, buying a second phone and connecting it to the old Google account just to browse tiktok.
Grapheneos has 99.99% app compatibility and over 90% of banking apps are compatible.
No, that's exactly the fear. With enough disclaimers and third parties involved, a motivated, highly intelligent and rich attacker with the right connections could get that information.
Police can obtain data from Google. Police can be abusers or friends with abusers.
I am a (very happy) GrapheneOS user, I am certain that I can install a tracking app on it. I can even easily side-load an abusive app that would be banned on the Play Store...
Like I would totally recommend GrapheneOS because it's great, but I don't think it solves the problem of "a domestic abuser can access your phone by making you give access to your phone".
It's not as easy as it can be (the text is aimed at people familiar with Android flashing) but in practice you need to toggle one setting, reboot holding the volume button, and then click four buttons in your browser in order, with the exact names for settings spelled out in the guide itself.
I don't think wiping an abuser's malware is such a great solution unless you've already managed to get out of the DV situation. Perhaps GrapheneOS is a good idea on a secret second phone?
The basic premise, that a secured and private phone, is useful for domestic abuse victims is of course okay. It is true that protecting your privacy from abusive family members can be useful and GrapheneOS' features, which are accurately described on their own website (contrary to the linked blog post), certainly help remove threats in that regard. See : https://grapheneos.org/features . This is dependent on the specific situation, of course, (e.g. huge difference between ex-partner stalking you and a current partner you live with abusing you), because if you are forced to give your phone password at the threat of being hurt, a secure phone won't really help you a lot.
While the licenses that GrapheneOS uses permit companies to establishes businesses using GrapheneOS software, it's not recommended by the project to buy pre-installed phones, certainly not pre-configured phones, like PrivacyPros offers. The install process of GrapheneOS is simple if you are using the WebInstaller, and there is a lot of free support available in the community chat rooms and fora if you bump into issues. This saves you a lot of money because you can buy a new, used or refurbished Pixel with the stock OS installed at a much lower price. If you install GrapheneOS itself the guide also mentions you have to verify the integrity of your installation. That also holds true for preinstalled phones, you should check the verified boot hash and set up Auditor app. Preconfigured phones should actually be completely factory reset, not only from the OS but preferably also from recovery mode and then set up again, with a check of the boot hash and a set up of Auditor app before you install any apps or start changing settings. You don't know what PrivacyPros has changed to the settings, what they loaded on the device and Auditor should be set up by yourself and straight from the beginning, before you start using the device, because pinning-based security is an important part of its security model and you would want to be pinned to a clean state from the post install.
The blog post and also the PrivacyPros website where they promote and sell their phones is riddled with unnecessary misguided advice and also falsehoods about what GrapheneOS offers and what the dangers of the stock Pixel OS and Android in general are. Pixel OS and Android in general are portrayed way too negatively. I'll just give a few examples because it will cost me way too much time too debunk and correct all of it. These ones are verified easily by yourself and I hope it just makes clear you can discard everything PrivacyPros has written and makes clear you should just consult the official GrapheneOS website. So, they pretend as if Android and Pixels themselves don't have a permission model, multiple users and verified boot. This is untrue. GrapheneOS hardens the app sandbox and permissions model more and offers stuff like storage scopes to work around to broad permissions, but the sandbox and permissions model itself exists for Android in general. Verified boot is also a standard Android feature, and also exists on iPhones and even on MacOS and ChromeOS. Multiple users are part of Android, GrapheneOS just increases the available number of users and increases their usability. Also note that users don't improve sandboxing. Sandboxing and access control exist within profiles as well, profiles are mainly meant for increased isolation via separate user data, user settings and VPN slots. They also offer separate encryption keys allowing you to selectively put data at rest etc. The whole idea of a "ghost" profile and user profiles being at the centre to security and privacy is misguided. They also call about kill switches, Pixels don't have hardware kill switches and the software kill switches are just part of Android.
Have you seen how many articles recommend not secure and not private alternative phones, that's not cool.
Edit: damn some of their phones with it preloaded are like 4x the price your can get for pixels in the state's. Can't speak to Australian prices for regular pixels tho.
So not quite a 50% markup on the bard phone, not quite as bad as 4x.
And while I'd feel like a jerk if I asked for money helping someone at risk of DV setting this up, if I was doing it as a business with the mandatory warranty and support this'd need to include in Australia, I think that's expensive but probably fair?
Interesting they don't sell the 10a, seems like a great budget phone from what I've seen.
Edit: I didn't consider taxes and initially I assumed exchange rates were more similar then they are.
Law in my profile heh (not on purpose)