Hacker News new | ask | show | jobs
by matltc 11 days ago
Curious to hear: how much effort did it take to migrate to GrapheneOS? I own a pixel, grabbed it in anticipation of unlocking, but the effort it seems it would take from reading GrapheneOS docs has stopped me from committing to it on my daily driver. Would you please provide a quick time estimate and any snags you hit?
3 comments

It took me about an hour. I sat down, read the docs, installed it via the web installer, then spent the next 45 min deciding how I wanted to segment separate profiles for play services.

Nowadays it seems a lot easier because there seems to be a separate profile isolater you can run in the main profile, which I would choose if I was installing today.

The only hiccup I've had is that sometimes group messages don't send correctly and send individual messages to everyone, but I think that's because I'm on a secondary profile, and it only happens when the phone is receiving a bunch of messages all at once while I try to send to the same group. But I deny network access to my installed swype keyboard, so it may have something to do with that too.

I've been running this for years, since the Pixel 7 came out, which I'm still using.

I love it. I can confidently go through customs knowing that if they yank my phone during some weird checkpoint and try to celbrite it, I'm as secure as can be.

Thanks for the info! Might take the dive.
Time estimate depends heavily on the apps you use (data migration in them) and maybe some features that don't easily work out-of-the-box in GOS like Google's find my device, where you'd ideally migrate to use foss alternatives like FMD[1]. For the easiest setup by far just install the sandboxed Google Play Store and get your apps from there. In general the more additional security features you enable, the more issues you may face, so I'd recommend leaving everything to GOS default, like leaving Sensors permission ON by default. There are a few gotchas that may not be mentioned in GOS official documentation or elsewhere such as BT tracker devices not being supported for the most part, requiring workarounds. There are also few apps that don't currently support GOS [2][3], so be sure to check them out beforehand.

1: https://gitlab.com/fmd-foss/fmd-android

2: https://grapheneos.org/articles/attestation-compatibility-gu...

3: https://privsec.dev/posts/android/banking-applications-compa...

Thanks for the references, especially FMD tip; have the Google version disabled due to lack of trust.
It takes around 10 minutes to install it. Most of the time people spend on it is deciding how they want to set things up. It's very easy to set it up in a similar way that you would use the stock OS. You can use a single profile with sandboxed Google Play installed.

Many people want to segment things more than that by having a dedicated profile for apps depending on sandboxed Google Play. A work profile, Private Space or secondary user can be used for it. A work profile or Private Space is a lot more convenient. Using a work profile avoids wasting the Owner user's Private Space if you want to use it for sensitive data. We want to add support for multiple Private Spaces per user in the future instead of only 1 per user to fully obsolete work profiles for local usage.

Wow, straight from the source! Heartfelt thanks for maintaining this project; it becomes more pertinent by the day as we slide ever deeper into living into this dystopian surveillance state.