• 0 Posts
  • 12 Comments
Joined 3 years ago
cake
Cake day: June 17th, 2023

help-circle
  • I came to GrapheneOS for privacy and security, but stayed for the features.

    1. Per application network toggle: I found this incredibly useful in cases where the application is fully functional without internet, yet still asks for internet permission, and I do not want it to phone home (e.g. Google Photos). It is helpful for when you are using a VPN, and do not want the slot to be taken by an application like NetGuard. Although, I believe you can replicate this functionality with (Split Tunneling) + (Block connections without VPN).

    2. Storage Scopes: This is a another highly useful feature. Say you took a bunch of pictures on a trip, and want to show the pictures to a friend. Normally, you’d fear them snooping around pictures that you don’t want to show them. However, with GrapheneOS, you can just download a separate Gallery application, only expose the photos (or the photo directory) that you want to show via Storage Scopes, pin the application, and safely hand the phone over to them.

    I found this feature very helpful when shortlisting ~10 photos from a gallery of 500 photos. I downloaded PhotoSwooper (which lets you keep/delete photos by swiping right/left) from F-Droid, exposed the 500 photos directory to it, and started swiping. I iterated this a couple of times, and got my perfect 10.

    1. Contact Scopes: This is for the cases when you don’t want to expose your contacts to the application for whatever reason (e.g. you don’t want them to graph your connections or you just want to protect the privacy of your friends). You can just selectively share contact(s) instead of handing your entire phonebook to the application.

    2. Sandboxed Google Play: Some applications require the extremely invasive Google Play Services (because it operates with elevated system-level privileges). However, with GrapheneOS, you can just install the sandboxed play services, which acts as a regular user level application. You can then revoke network access within Sandboxed Google Play Services, and use your play services dependant application as usual.

    So, basically, if you can afford it, go for GrapheneOS. I wanted privacy and security; but now that I tried GrapheneOS’s features, a lot of these are now nonnegotiable to me.


  • And why would you trust your own ISP more than reputable VPNs?

    Sure, this statement is very valid for (free) VPNs which are not reputable, and act as data mines instead of providing true privacy; but your statement reads very much like we do not need VPNs at all.

    ISPs know what sites you are visiting and when, and they are ready to comply with the government. Also, we have acts like Online Safety Act (UK), which incentivizes more data collection. Combine that with age verification on every site, and you are basically giving away your browsing history.

    I agree that a VPN alone is not going to protect you, and you need to authenticate less into websites, and clear your cookies after every browser session (basically good OpSec). However, I also think that reputable providers like Mullvad and Proton are a must.









  • I don’t use Proton Drive too much, but for my use case, it works great. I sometimes save files in there and share them via urls, and it works great for that use case.

    The last time I used Bitwarden, the base plan did not support 2FA which is a must for me. Keepass keeps it local, and supports 2FA too. These days, I use Proton Pass more because I want easier sync across my devices, but I back up everything to Keepass every once in a while.


  • Here are the ones I use:

    • YouTube:

    This is the hardest and you might need to hop a lot. But, these are the ones I have: FreeTube, Grayjay, LibreTube, NewPipe, PipePipe, and if none of these work, then YTDLnis (yt-dlp client)

    • Mail:

    ProtonMail (Tuta is heavily suggested too, but I personally have never used it)

    • Cloud Storage:

    Proton Drive (although I don’t use cloud storage much)

    • Gallery:

    Stock and AvesLibre (I heard Immich is good too, but I cannot afford self hosting atm)

    • Video Player

    VLC

    • Audio Player

    VLC

    • 2FA

    Proton Pass and KeepassXC

    • Mail App

    ProtonMail and K9Mail

    • Password Manager

    Proton Pass and KeepassXC

    • Weather app

    Breezy Weather