this post was submitted on 08 Sep 2024
226 points (98.3% liked)

Privacy

31799 readers
329 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Edit: Before you read, I made some mistakes here that I mention in my part 2

My mobile operating system of choice is GrapheneOS. I run it on a used Google Pixel 8, as I didn't have enough money for any of the phones in the Google Pixel 9 lineup, which offer a more secure ultrasonic fingerprint scanner. I used to use iOS, but I finally managed to switch. I wanted to share my thoughts on GrapheneOS, problems I had, and the apps that I use.

To install apps, I first check if it is available on GrapheneOS's built in app store. If not, it is installed via Accrescent. Because Accrescent is still very small in support, most of my apps are installed via Obtainium. One app however, ProtonVPN, is installed via Aurora Store, because that is the only installation medium that allows me to sign in as a guest.

I do have a Proton account, so signing in isn't an issue, but since I plan to use ProtonVPN until I can pay for Mullvad VPN, I might as well get as much anonymity as I can. I don't use the actual Google Play Store, despite claims of it being more secure, mainly due to me required to create a Google account. I only use Aurora Store for ProtonVPN. For apps that are not available for Obtainium but are available on F-Droid, I simply use the F-Droid repo inside of Obtainium. All apps are verified with AppVerifier.

For games I have a very small selection. Simon Tatham's Portable Puzzle Collection is a game collection I have been using since before I even knew it was open source. Antimine is a Mines client, which is a classic. I also play a game called Zoysii, which is only available on F-Droid. It passes the time. Code Word is a nicely made Wordle app, with some extra features. Open Sudoku is a nice Sudoku app, however I found that almost all of the available puzzles to install are very easily solvable. 2048 by SecUSo is a decent app to play 2048 that is still maintained, however it currently does not have a dark mode theme. blichess is a fork of lichess that simply adds the option to play over Bluetooth, which I really like.

My mobile 2FA app is Aegis, which is really everything you would expect. Audire is an open source frontend for Shazam, which I use for music recognition. I'm sure there are some better apps with different APIs, but Shazam works really really well, and that is what I am looking for in the app. Aves is my photo manager, as it allows for proper photo hiding. It is available through Accrescent, which is nice. It is one of few apps that required me to sign terms and conditions, but it doesn't matter since it doesn't have internet access anyways. It allows me to view extensive details about photos, and even remove metadata in the app.

I use AndBible for Bible study, but the project seems to be abandoned and needs lots of improvements. I sincerely hope a good alternative is developed eventually. I would be willing to help out any way I can.

For messaging I use SimpleX Chat for my most personal chats, but for mostly everyone I contact them via Molly, which is a hardened version of Signal available on Accrescent. When I am offline, I contact nearby people through Briar over Bluetooth, which is awesome while camping. I don't have any cellular provider, so I occasionally have to make sacrifices in terms of contact.

The default GrapheneOS calculator has no dark mode, so I opt for OpenCalc as my default calculator. I tried both Etar and Fossify Calendar as a calendar, and have been much happier with Fossify Calendar. A lot of Fossify projects have been abandoned, sadly, so I may have to switch.

I use the default GrapheneOS camera for most of my pictures, but when I need high quality shots I will use Open Camera. It supports HDR and some post processing. The GrapheneOS camera has incredible support for code scanning, such as QR codes and bar codes. I don't plan to use the Pixel Camera, since those apps work just fine for me. To edit photos I use the GrapheneOS gallery, but it is somewhat lacking. I plan to stick with it as they add new features.

I have a ClearClipboard app that, simply, clears the clipboard when you open it. It's a small tool but I get very paranoid about clipboard access. I've found that my password manager doesn't reliably autoclear, which I will discuss later.

The default GrapheneOS clock app is fine. I wish there was an OLED theme, but it's worked for what I need. DeepL is what I use for translations, because I cannot seem to find an offline translator app. It's very upsetting. For my keyboard I use HeliBoard with the proprietary swipe to type module, and it's great. There are a few weird autocorrect suggestions, such as not recognizing the word "A", but it's honestly not been a huge issue.

I use Joplin to take notes. I had issues with Standard Notes when I was on iOS, and had switched to Joplin there. I now can't even imagine why anyone would even try to use Standard Notes, Joplin makes Standard Notes look like a joke. It has all (or at least all I care about) of the paid features of Standard Notes, for completely free.

My password manager is KeePassDX, which is honestly exactly what I would want from a password manager. The only issue I've had is that it sometimes disables biometric unlock and makes you unlock it yourself, which is super weird. Besides that, I will be using it until either it dies or I do.

For eBook reading I use Librera, but the UI is honestly atrocious. The best eBook reader I have ever used is Apple's stock Books app, and I honestly wish something of that polish existed on Android. Librera will work but it's not nice to use.

I have LibreTorrent in case I ever need to torrent something on the go. It's fine, I wish torrent software would include a hard toggle to disable seeding, but it's worked as intended. In a similar category I use LocalSend to transfer between any of my devices. I haven't tried KDE Connect because LocalSend has never caused me problems. The only issues I have encountered were because of strict VPN settings.

I eventually plan to use Mullvad VPN, but until I can afford it I am using ProtonVPN as I mentioned. I have no real comments because I have only used ProtonVPN. IVPN is on my radar, but Mullvad VPN is still at the top of my list. IVPN is available via Accrescent. I also have Orbot in case Proton or Mullvad are blocked.

Music players have been a struggle for me. All of them have their own various issues. All I really need is a nice way to play mp3 files offline and sort them into playlists. A night timer is nice. Vinyl Music Player is what I use for now, since Fossify Music Player seems to be abandoned. I'm open to some open source alternatives here, since the ones I have tried all have issues. Ideally these should be available by Obtainium.

I use Organic Maps for navigation. Support is alright in my city. OsmAnd has a pretty bad UI but it's gotten better. Organic Maps I've heard has a few issues, and OsmAnd has a premium tier, but I don't really care. I am just sticking with Organic Maps. I'm happy with it, so it's fine.

I have RadioDroid installed to try it out. It lets you listen to radio stations over WiFi. I'm jealous of Motorola users for their built in AM/FM radio receiver antenna. I might not keep this app, since it's fairly useless when you think about it. Either way, maybe a GrapheneOS phone will come along with a built in antenna.

I have Tor Browser installed just in case I ever need to visit an Onion site or use a Gecko based browser. My main browser is Vanadium, and I did try Mull but it doesn't block advertising redirects even with uBlock Origin. Vanadium is fine for now.

I have Trail Sense as a compass and emergency survival app. I hope I never have to use it for survival, but at the same time, I hope this app saves my life. It's cool to see how many sensors it utilizes to help you out.

Tubular is a fork of NewPipe that has SponsorBlock support. I like it, it's not as polished as I would want but it's plenty usable. I wish it had DeArrow as well, but I'm sure it won't be long until it's added.

I use the Fossify Voice Recorder for voice recordings. It's what you would expect, not much to say here. For weather, I use Breezy Weather. For some reason some features were unavailable on the F-Droid version, but after installing with Obtainium I now have plenty of features at my disposal. It's almost as good as the iOS weather app, and has plenty more features. The accuracy where I am is slightly iffy, but it's good enough that I can rely on it.

I use a passphrase to lock my phone, and use biometric unlocking to ensure no one can shouldersurf passcodes. GrapheneOS only lets you add up to 4 fingerprints, which is a good enough limit, but I do wish it was higher. If I wanted only 4 fingerprints, I would choose that myself. I backup GrapheneOS using my own USB stick and the built in backup option. Some apps such as SimpleX refuse to be backed up automatically, but I can simply manually export the database and backup that file.

Even without any Google frameworks installed, GrapheneOS has been a really seamless and polished experience. The issues I would raise are actually with Android itself, such as weird management of app signing, but overall GrapheneOS has been incredible. GrapheneOS is honestly the minimum every person should expect in terms of privacy and security on their phones, because nothing else even comes close to GrapheneOS in those categories. The gap between iOS and GrapheneOS is absolutely massive, given that so many of the apps I use are Android specific.

top 50 comments
sorted by: hot top controversial new old
[–] c0smokram3r@midwest.social 32 points 1 month ago (1 children)

This is seriously much appreciated! Been hesitant to stick from iOS to Graphene but this piqued my interest! 🀳

[–] Charger8232@lemmy.ml 10 points 1 month ago* (last edited 1 month ago) (1 children)

I will say this: I have used iOS my entire life up until now. Before I used GrapheneOS I made sure to make a list of every app I would be using (although my list did change after trying, which is ok). I also learned as much as I could about the Android and GrapheneOS ecosystem as I could before switching, since there are a few quirks. I was lucky to be able to try out a few cheap Android devices to familiarize myself.

I'm not saying any of this is required, you really will see that it's just an OS and the usability is pretty much the same, but I did my preparation for about a year and was on my feet in a few days (keep in mind I am a niche user). For a normal iOS user who has never used Android, I'm certain they'll be able to use it just fine as long as they have some basic privacy knowledge.

Part of why I made this post is to ease the worries of any iOS users who are hesitant. It really is a smooth transition, but it can be hard if you make it hard. I am a tinkerer and power user with a higher threat model, so of course I had lots more bumps than an average user. Try it out and see what you think!

P.S. If you do ever decide to switch, DM me if you want some help :)

[–] c0smokram3r@midwest.social 3 points 1 month ago (1 children)

Thanks! Might take you up on that offer when I have some time to track down a used pixel!

[–] Charger8232@lemmy.ml 7 points 1 month ago* (last edited 1 month ago)

It took me months, I got mine from ebay. The only advice I have is MAKE SURE the listing EXPLICITLY says it is OEM Unlocked. I found many listings that claimed to be factory unlocked that were not, and network (carrier) unlocked devices rarely allow OEM Unlocking. I made a post about my hassles with T-Mobile. Listings that say OEM Unlocked are not uncommon, and some of them bury it somewhere in the footnotes. The Pixel 8 series provides MTE support compared to the 7 series and lower, and the 9 series provides better biometrics than the 8. A used 8 will run you about $350 or more. Most go for $400+ now, but occasionally the prices dip down. Good luck!

Edit: Here is an ebay link with useful filters: https://www.ebay.com/b/Cell-Phones-Smartphones/9355?LH_BIN=1&LH_ItemCondition=3000%7C2030%7C2020%7C2010%7C1500%7C1000&Lock%2520Status=Factory%2520Unlocked&Model=Google%2520Pixel%25208%2520Pro%7CGoogle%2520Pixel%25208&mag=1&rt=nc&_fsrp=0&_sacat=9355&_sop=15

[–] z3rOR0ne@lemmy.ml 16 points 1 month ago

Nice writeup. One note: I don't think the Fossify projects are abandoned. The creator has commits on the project as recent as 21 hours ago at the time of this writing. They just haven't pushed updates to FDroid for a couple months.

[–] thayerw@lemmy.ca 11 points 1 month ago (1 children)

Nice writeup, thanks for sharing. For your music woes, have you tried plain old VLC? It's what I use for music (and Mpv for video) and it's been fine. I like that I can keep my mp3 folder structure the way I like it and still be able to browse and queue albums without relying on metadata.

[–] Charger8232@lemmy.ml 4 points 1 month ago (2 children)

People have recommended me VLC in the past. If it's anything like the usability of the desktop version, I'm going to say it's a hard pass. The nice thing about playlists compared to folders is the same song can be in multiple playlists without duplication. My files have all the necessary metadata for albums and whatnot, but it's really playlists that are the issue.

[–] Corngood@lemmy.ml 4 points 1 month ago (1 children)

I can't vouch for it as a music player, but it's what I use for videos when I can't get on a bigger screen. It's nothing like the desktop app, so you might want to give it a try.

[–] Charger8232@lemmy.ml 6 points 1 month ago (4 children)

I am quick to admit when I am wrong, VLC is actually exactly what I am looking for. It has support for playlists, sleep timers, and everything else. I may make a writeup about this. I genuinely thank you.

[–] thayerw@lemmy.ca 2 points 1 month ago

Glad you found something that'll work!

load more comments (3 replies)
load more comments (1 replies)

koreader is my goto reader, on my tablet and phone. The interface is a bit unintuitive, but once you get it set up to your liking, it's a great reader.

[–] GustavoFring@lemmy.world 8 points 1 month ago (1 children)

You can install Proton VPN via F-Droid.

[–] Charger8232@lemmy.ml 3 points 1 month ago (1 children)

As I mentioned, other installation methods don't support signing in as a guest. Only the Play Store version, for some reason.

[–] jet@hackertalks.com 1 points 1 month ago (1 children)

fdroid does not require you to sign in

[–] Charger8232@lemmy.ml 4 points 1 month ago

The ProtonVPN app itself does unless you install via the Play Store.

[–] JustMarkov@lemmy.ml 6 points 1 month ago (3 children)

I'm so bummed that Accrescent is now part of the built-in App Store on GrapheneOS and is gaining popularity because of it.

[–] vikingtons@lemmy.world 5 points 1 month ago (2 children)

I've heard very little about it. Is there some controversy around it?

[–] JustMarkov@lemmy.ml 5 points 1 month ago (1 children)

It depends. If we only mention security, then there's (probably) nothing to worry about. However, if you look at it from the perspective of the FLOSS movement, Accrescent does not support any third-party repos, claiming that they are "breaking the Android security model", and also allows submitting closed-source apps to the repo.

[–] vikingtons@lemmy.world 3 points 1 month ago (1 children)

Would it almost be equivalent to snap on Android?

[–] JustMarkov@lemmy.ml 3 points 1 month ago

In a way, yes.

[–] Charger8232@lemmy.ml 2 points 1 month ago

I'd also like to know this, considering many people swear that Accrescent is more secure than any other option.

load more comments (2 replies)
[–] MagnumDovetails@lemmy.world 5 points 1 month ago (1 children)

I’ve been on iOS since the iPhone 3. I’m planning to switch soon. I’m not quite a power user and still dual booting my computer with Linux.

I was curious what you mentioned about unlocked phones not be able to be boot loaded. How could I determine this for sure? I’ve been looking at purchasing on back market dot com, but I’m open to purchasing elsewhere as long as it’s not amazon.

Thanks for that ebay link and this write up

[–] Charger8232@lemmy.ml 6 points 1 month ago

Hi! Glad you're deciding to switch. Carrier locked devices tend to disable OEM Unlocking, which is a feature that allows you to unlock the phone's bootloader and install a custom ROM such as GrapheneOS. There is no way to determine this for sure unless it is mentioned as "OEM unlocked" or "bootloader unlockable" in the listing, or by asking the seller to check in Developer Options. Good luck!

[–] bloodfart@lemmy.ml 4 points 1 month ago (1 children)

You can pay for mullvad month to month by sending them five bucks and a piece of paper with your special number written on it in an envelope.

Might make it more affordable.

There is one thing you should probably change post haste (see what I did there?): get you one of those polarized privacy screen protectors and stop using biometrics. At least in the us biometrics aren’t protected by laws against unlawful search and compelled speech.

[–] Charger8232@lemmy.ml 2 points 1 month ago (1 children)

I considered a privacy screen protector such as the one I had on my iPhone, but I found that biometrics would become an issue with having one on. I don't plan to disable biometrics, since it's easy enough to simply hold the power button and select "Power off" if I am ever compelled to unlock my phone.

load more comments (1 replies)
[–] ravhall@discuss.online 3 points 1 month ago (1 children)
[–] Charger8232@lemmy.ml 4 points 1 month ago (1 children)

No. I don't see how this is relevant. I use Linux on all my devices.

[–] ravhall@discuss.online 11 points 1 month ago (1 children)

Then it should be relatively easy to leave iOS, because you aren’t even using half of the features of the ecosystem that sucks you in.

[–] Charger8232@lemmy.ml 3 points 1 month ago (1 children)

The hardest part is the price and adapting to an Android-like system, but I agree.

[–] MigratingtoLemmy@lemmy.world 1 points 1 month ago (2 children)

How did you afford the iPhone before?

[–] ravhall@discuss.online 1 points 1 month ago

Well, they couldn’t afford a real computer.

(I’m joking, I love Linux.)

load more comments (1 replies)
[–] 9488fcea02a9@sh.itjust.works 2 points 1 month ago (3 children)

AndBible updated 2 months ago for me on f-droid

The github doesnt look dead to me

load more comments (3 replies)
[–] crash_thepose@lemmy.ml 2 points 1 month ago (1 children)

I'm hoping to switch to GrapheneOS from Iphone. Do you know if its possible to keep the same number/carrier?

load more comments (1 replies)
[–] dessalines@lemmy.ml 2 points 1 month ago

Great list of apps. The only few things I could recommend on top of yours are:

  • tasks.org for tasks (and it can easily replace your calendar). It's foss, and has good syncing / backups.
  • You could move off aegis and put all your 2fa in keepassdx. It supports 2fa already, and has smart form filling for it too.
  • Readera for ebook reading. Not FOSS, but its light and works really well.
[–] Templa@beehaw.org 2 points 1 month ago* (last edited 1 month ago) (1 children)

For music I am currently using Tempo with a Navidrome server. It allows you to download specific songs to listen to them locally or I can listen to everything if I connect through Tailscale.

Also, I highly recommend Catima if you want to carry loyalty cards and things like that.

load more comments (1 replies)
load more comments
view more: next β€Ί