this post was submitted on 29 Jun 2024
1 points (100.0% liked)

Privacy

37039 readers
1 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

Hello, making this post to get some honest, and technical opinions about GrapheneOS. Please do not be bother by this question. No drama here pls ๐Ÿ™. I've heard that there is some of the google code into the "sandbox" feature. Say your opinion below! ๐Ÿ‘‡๐Ÿ‘‡

you are viewing a single comment's thread
view the rest of the comments
[โ€“] RubberElectrons@lemmy.world 0 points 2 years ago (3 children)

There's also CalyxOS, low drama and very reliable. https://www.calyxos.org/

[โ€“] jabjoe@feddit.uk 1 points 2 years ago

Can it run problem bank apps? I need a bank auth app for work as the bank stopped fobs and it just would not run on LineageOS. It refused to run because "the phone is insecure". I tried Magisk hiding stuff and MicroG, and a number of way of tricking methods. That's why I ended up on GrapheneOS, as a compromise without feeling too compromised. Everything seams to think it's on a normal Android phone, but I've sandboxed the Google tentacles. But it would be better if mandating OS wasn't allowed. If I want to run a "insecure" phone, that's my "problem".

[โ€“] Andromxda@lemmy.dbzer0.com 1 points 2 years ago

Calyx is unfortunately pretty slow to release security patches, uses privileged apps with root access like microG and the F-Droid privileged extension by default and doesn't really provide any unique features. All of the privacy features of Calyx are either already present or can be easily replicated in a better form on GrapheneOS. Take Datura Firewall, it's yet another privileged app with root access which adds unnecessary attack surface, and is less secure than the Graphene equivalent. GrapheneOS implements a network permission toggle, which is embedded in Android's native permission manager and uses the INTERNET permission to restrict network access. It disables both direct and indirect network access, including the local device network (localhost). GrapheneOS also has a bunch of unique security features, that can't be found on any other Android ROM, like for example a hardened memory allocator, hardened kernel, secure app spawning, improved SELInux policies, Duress PIN/Password, driver-level USB-C control, Storage Scopes, Contact Scopes and soon App Communication Scopes. GrapheneOS also includes Sandboxed Google Play services, a better GMS implementation than microG, which doesn't require root and has better app compatibility.

[โ€“] carloshr@lile.cl 0 points 2 years ago

@RubberElectrons @privacy @foremanguy92_
I've been using CalyxOS for a year now and I like it so much. I also tried GrapheneOS but I consider that sandboxed apps are harder to manage than microG in Calyx. I chose simplicity.