Free Palestine 🇵🇸

  • 1 Post
  • 36 Comments
Joined 1 year ago
cake
Cake day: August 16th, 2023

help-circle







  • Google hardware actually gives you the most freedom, no other Android phone allows you to install a custom operating system, relock the bootloader and use Android Verified Boot, which is a fundamental part of the Android security model, with a custom signing key defined by the custom OS. It also includes the Titan M2 secure element which gives you great security through features like Android StrongBox, the Weaver API and it even has Insider Attack Resistance meaning Google, even if they get a court order to do so, can’t comprise the Titan M. Firmware can only be loaded to the chip after proper user authentication. Yes, it’s a little ironic, but Google hardware gives you the most freedom over your device.












  • Unlike other ROMs like CalyxOS, GrapheneOS ships the actual Google Play services and Google Services Framework, but they’re sandboxed so they can’t spy on you. Whether your banking app works, depends on the SafetyNet requirement it has. If it requires full integrity, it unfortunately won’t work on any system that is not whitelisted by Google. If basic SafetyNet integrity is enough for the app, it will work on GrapheneOS. You can google (or duckduckgo) your banks name and “GrapheneOS”, and you may find posts by other people who tried it out.

    Edit regarding software in general: When you install Sandboxed Play Services, you also get the Play Store which you can use to install apps. You can also use the Aurora Store, an anonymous front-end for the Play Store. There is also F-Droid, which offers FOSS alternatives to most applications.

    Edit 2: I found this post over on PrivSec which has a list of apps and details on whether they work