Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

tranquil_cassowary

@tranquil_cassowary@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Interested in software privacy and security.
PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

41 Followers
27 Following
50 Posts
Joined August 20, 2025
Mobile OS:
GrapheneOS
Desktop OS:
MacOS + ChromeOS
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2w ago
Replying to

@jonquass@mstdn.social

GrapheneOS has Google Play installed on the phone, but it's in its own sandbox. That means it sends real telemetry to google, but is limited to what it can see from within the sandbox

Its important to note that it isn't bundled and installed by default though. And that if you use privacy friendly apps, they are unlikely to talk to Google Play via IPC. And you can also restrict such communication by putting them in separate profiles.

CalyxOS doesn't support Google Play at all. It has Aurora Store and you can install migroG to get access to apps from Google Play. The only interaction with Google is push notifications, which are also optional.

You might find this explanation of the downsides of the approach useful https://discuss.grapheneos.org/d/4290-sandboxed-microg/11

So problem is that it runs privileged, doesn't have the most secure reimplementation, and for some functionality (not only push notifications like you mentioned) still talks to Google, but in this case does via a component that, as mentioned, runs privileged, thus increasing privacy and security issues. Google Play dependent apps also often bundle Google Play libraries, the explanation about just cutting out the middle man is quite interesting. Especially noting that middle man is more secure. Same holds for the store. Play Store does better verification of app installs, including verifying their metadata, compared to Aurora. And Play has better and more reliable auto updating of apps, which is important to get security patches.

This means some apps won't work. Sound like it's mostly banking apps that break.

That's true. Compatibility with apps will be higher with sandboxed Google Play due to it using the real unalerted Google Play but just forced in the app sandbox. GrapheneOS also has more exploit mitigations and if those give compatibility issues they can turned off on an app by app basis. Banking apps more often implement misguided or mismarketed libraries for "security" and anti-tampering. One of those libraries is Play Integrity API, which is sometimes impossible to work around, and will give issues on both OSes given that they are uncertified.

Sandboxed MicroG? - GrapheneOS Discussion Forum
GrapheneOS Discussion Forum

Sandboxed MicroG? - GrapheneOS Discussion Forum

GrapheneOS discussion forum

2
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2w ago
Replying to
@seanm@infosec.exchange @metr0pl3x@grapheneos.social They used poor wording. To make it more private you disable certain "non private" toggles. Those toggles are "privacy related" so you could ambiguously say you disable "privacy toggles".
1
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Netzblockierer@tech.lgbt @shadowwwind@mastodon.social @gdmalan@infosec.exchange @maddad@mastodon.world @ZoidbergForPresident@kolektiva.social @nakal@mastodon.social @arstechnica@mastodon.social @EUCommission@ec.social-network.europa.eu GrapheneOS focuses on usability besides privacy and security. They've made a web installer to simplify the installation compared to needing to use a command line interface. They've clarified the error messages this web installer gives over time in case something goes wrong. They've focused on community building to make sure free support is widely available on various platforms. They've made a compatibility layer for Google Mobile Services so people can for the most part just install Google Play and use the Play Store and its apps like people would on other Android phones. They focus on fixing regressions with regard to compatibility very swiftly. They've made some hardening options opt-in instead of opt-out to make sure the OS by default is very compatible with third-party apps. They are now also focussing on accessibility, by developing their own text to speech and speech to text engines. They are revamping the bundled apps they inherit from AOSP at the moment to make sure their UI and UX aligns with current expectations of people. Etc. What exactly do you think makes GrapheneOS difficult to use for the "average person"? This is a genuine question. Feedback is useful. #GrapheneOS
4
5
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@gdmalan@infosec.exchange @maddad@mastodon.world @ZoidbergForPresident@kolektiva.social @nakal@mastodon.social @arstechnica@mastodon.social Good replies but I have one small correction. It hasn't been confirmed yet that GrapheneOS could be installed by default as an option. At a minimum it will be yellow boot support like with Pixels now, allowing you to flash it and then compare the public verified boot key hash to the hash on GrapheneOS' website. And an in-between option could be green boot but still not preinstalled as OS. In case of green boot GraoheneOS verified boot key would be flashed onto the device in the factory, alongside the key for Motorola's OS. If you then install GrapheneOS, you dont have to verify the verified boot hash on the boot screen.
4
0
1
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@samurro@fosstodon.org 2027 on some Motorola flagship(s)
2
2
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@pierre_pebble@mastodon.ie @six_grandfathers_mountain@mastodon.social @404mediaco@mastodon.social To summarize, it wipes 3 types of data needed to derive the encryption key. Wiping 1 of those is enough, they wipe all 3 for redundancy because this goes insanely quickly anyway. Then it reboots the device to clear RAM. At this point when the OS tries to boot, it fails because it can't decrypt the data. It will try a few times to reboot and will them prompt you on a recovery screen to factory reset the device. Then it will do the factory procedure that puts your device in a state where it will show you the device set up screen if you boot up. The data was already unrecoverable before you do that, to be very clear, but the device would just bring you to the set up wizard before you go through the recovery menu.
2
4
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@AdansiX@metalhead.club No problem, happens to the best of us and the reporting about it in media and from some other projects has admittedly not really been great which leads to misunderstandings.
2
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@AdansiX@metalhead.club I'm referring to that. Let me clarify. Apps from developers that don't complete the developer verification by Google will still install like before in non-certified OSes like GrapheneOS. The warning that you install unverified apps, which is bypassable after a one-time 24 hour wait period on certified OSes, won't be there on non-certifies OSes. There is no limitation.
2
2
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@AdansiX@metalhead.club The ID verification doesn't affect GrapheneOS. It doesn't apply to it. It only applies to OSes certified by Google.
2
4
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@majorlinux@toot.majorshouse.com For text edits I like BeauTyXT For full note taking I like Notesnook and Standard Notes For navigation is use Google Maps and Organic Maps For music, I heard great things about Auxio if youre not streaming For local calendar, Fossify Calendar is an option, otherwise use something like Tuta or Proton Calendar for encryption If you don't like the bundled keyboard, FlorisBoard is nice I'm just going to assume you disline the bundled Gallery, because everyone does, in that case ReFra is nice and it's what GrapheneOS is building on as replacement for the current Gallery app For chatting Signal is nice of course as its the gold standard, there is fork called Molly that you might have interest in If you think of anything else feel free to ask.
2
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@lepapierblanc@mamutovo.cz Secure app spawning is a setting you can access via Settings > security and privacy > exploit protections > secure app spawning. Go to enabled, find the company portal app and then put that on disabled
1
1
1
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Logical_Error@fosstodon.org@GrapheneOS@grapheneos.social parterned with Motorola Mobility, not Motorola Solutions, both are completely separate companies since 2011, they aren't sister companies.
1
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@six_grandfathers_mountain@mastodon.social @pierre_pebble@mastodon.ie @404mediaco@mastodon.social See further down this thread for accurate info about how durress works. I stilk have a question about this post specifically, if you don't mind. Based on whay source did you conclude that this is how it works? Its interesting to know if there is a source with inaccurate info or if you just misinterpreted something which was accurately explained.
1
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@six_grandfathers_mountain@mastodon.social @pierre_pebble@mastodon.ie @404mediaco@mastodon.social It doesn't do any "bricking". Idk if you mean something else with that term, but normally bricking means the device becomes unusable permanently.
1
8
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Prometheus@infosec.exchange That wouldn't work. Device needs to reboot to clear RAM which is noticeable and, without wiping the whole device, forensic evidence of other profiles having existed remains.
1
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@paepke@chaos.social Is it MS Company Portal ? If so disable the hardened exec bases spawning for that.
1
3
1
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@xoagray@tiggi.es @TheMNWolf@furry.engineer Some extra context to this: Almost all apps work and most banking apps also work. Its just a small minority that doesn't, which is more common in the banking category. The reason for this is almost solely the Play Integrity API. Other compatibility issues, that GrapheneOS can fix by changes on their side, get fixed swiftly. Play Integrity is an API made by Google which they market towards app developers as benefiting the security of their app. However the API doesn't use objective criteria related to security. The API blocks GrapheneOS because it isn't certified by Google. A certification they can only obtain by licensing and bundling Google Mobile Services, which they don't do and don't want to do. GrapheneOS however is a very secure OS that keeps up with updates to Android. While blocking this secure OS, the API allows OSes which are severely behind on security updates, running on devices which are end of life, just because they are certified. So we can conclude that it's false communication from Google to devs that this API is focused on security. The API is deemed anti-competitive by GrapheneOS and pressure is applied on app developers to either ditch Play Integrity or explicitly allow GrapheneOS via a different API. Some developers have done that, which is nice. Ideally, regulators would taken action in the context of anti-trust.
1
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@yoasif@mastodon.social @log@mastodon.sdf.org @malicious_n@mastodon.social @iju@mastodon.social @GrapheneOS@grapheneos.social Of course, the GrapheneOS devs don't have control over when people use their features. And they have admitted themselves that in the US, where you cant be forced to give your password, relying on auto-reboot would've made more sense. There are circumstances to think of though that someone carries data for a good reason or that a person would be asked to hand over their phone in circumstances where it isn't expected (e.g. you aren't passing border control). Why would someone carry an empty device in those cases? And in those cases, as I said before in another post in this thread, there are different considerations at play to decide whether it makes sense to apply duress or not. I feel like you approach the usefulness of the duress password with a very narrow view on possible situations people can find themselves in. The situation of Atlanta isn't like other situations.
1
5
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@thoralf@gruene.social @sinchens_@mastodon.social @glsbank@ruhr.social Does this info help you to get it working?: https://github.com/PrivSec-dev/banking-apps-compat-report/issues/44
GitHub

Sparkasse Ihre mobile Filiale · Issue #44 · PrivSec-dev/banking-apps-compat-report

Is there an existing issue for this? I have searched the existing issues App name Sparkasse Ihre mobile Filiale Link to app https://play.google.com/store/apps/details?id=com.starfinanz.smob.android...

1
2
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@nek@hear-me.social @HaTetsu@mastodon.com.pl Should work to install it over LineageOS
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@AwetTesfaiesus@mastodon.social @Torx@social.tchncs.de Please see https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private for some insights on why a partnership is unlikely to happen. Firstly, they'll need to care about security. Secondly, they would need to actually care about sustainability, instead of just marketing with it, by providing proper long time software support. Lastly, they would need to stop their partnership with /e/OS, given their attacks on the GrapheneOS project and their userbase, and their dishonest stance on privacy and security.
Devices lacking standard privacy/security patches and protections aren't private - GrapheneOS Discussion Forum
GrapheneOS Discussion Forum

Devices lacking standard privacy/security patches and protections aren't private - GrapheneOS Discussion Forum

GrapheneOS discussion forum

0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Okuna@social.tchncs.de @GrapheneOS@grapheneos.social Okay then I honestly wouldn't know. But is everything functional?
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to on social.0x520.eu
@finn@social.0x520.eu Can you disclose which apps? Maybe we can help.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@samurro@fosstodon.org Yes but its not 2027 yet, so not yet on that list. The FAQ also says what the requirements are for future devices and Motorola is working together with GrapheneOS in order to meet those.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Okuna@social.tchncs.de @GrapheneOS@grapheneos.social It won't delete any of your data, if you changed settings yourself that are located under Settings > Network > Your SIM card, then those would be put on the default again. For example if you enabled voice over LTE, disabled roaming, etc. So if you did that just go through those settings again after you did that reset.
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
RE: https://grapheneos.social/@GrapheneOS/116946765689545308 For those who weren't able to join this live, this Q&A was interesting for people who are considering GrapheneOS and current users. Quite long, that's true, but so is Dune Part 1 and that movie is way more boring than this.
grapheneos.social

GrapheneOS: "Join Josh from Side Of Burritos and our Community…" - GrapheneOS Mastodon

0
0
1
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2w ago
Replying to
@sb@metroholografix.ca It won't, you just invented that.
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to on babka.social
@kolev@babka.social Yes works well if installed via Sandboxes Google Play Store
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2w ago
Replying to
@andreS@nrw.social @mrxlix@dresden.network You are correct that a secure OS like GrapheneOS gets unfairly blocked for "security" while outdated OSes that are certified by Google do not. But just FYI, /e/OS especially and LineageOS to a lesser extent, don't get properly updated. They lag behind Android and Linux kernel updates and security patches quite a lot. /e/OS also ships outdated chromium (for LineageOS I am not sure about that aspect). Would avoid those two OSes if you use them or plan to.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@thoralf@gruene.social Agreed but the GrapheneOS project is aware of that themselves. They don't think the UX and reliability is good. They want to replace it but there is currently no better alternative with adequate licensing and they haven't yet have the time to make one themselves.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@pft@infosec.exchange @zak@infosec.exchange Normally it should come to the hardware meeting the requirements, which for 2027 will be the phones with a flagship Qualcomm SoC. The chances are high we are talking about Signature and the two Razrs here, although these specific models haven't yet been confirmed, these ship with the flagship SoCs.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Life_is@no-pony.farm @ennopark@mastodon.social A userspace app can't implement this properly and whilst trying to do so often will ask very invasive device permissions for that app.
0
2
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2w ago
Replying to
@ocelot221@mastodon.social @GrapheneOS@grapheneos.social @mhoye@cosocial.ca @mulchmaxxing@blahaj.zone Very unlikely for 2027. Maybe for future generations. EDIT: Apparently likely, just not on launch. See reply of official project account underneath this post.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@starlight@lgbtqia.space It is, a lot of this is due to misguided anti-tampering, anti-reverse engineering and obscuring efforts by the app devs. Banks often use code libraries for that which are also used by other banks causing them to share the same kind of issues. It is misguided just like the usage of Play Integrity API to increase security. Part of this is app devs' fault, part of it is on Google and code libraries for mismarketing their APIs.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@log@mastodon.sdf.org @yoasif@mastodon.social @malicious_n@mastodon.social @iju@mastodon.social @GrapheneOS@grapheneos.social Yes if it was expected in this case he could have wiped the device before hand or at least just turned it off.
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Okuna@social.tchncs.de @GrapheneOS@grapheneos.social Can you try Settings > System > Reset > Mobile network settings?
0
5
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Life_is@no-pony.farm @ennopark@mastodon.social I understand why people try to implement it and why people are interested in finding a solution for their non-GrapheneOS device, let me be clear about that. But it's in my opinion very bad if an individual thinks he can rely on it (especially people with high threat model) and it ends up not being waterproof at all, or when they end up not needing to every use durress but had an invasive app installed on their system which did more harm than good in that cade.
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@lepapierblanc@mamutovo.cz Maybe this will work again in the future, BTW, always worth trying to enable it again down the line. FYI Having it disabled for just that one app isnt a very big issue. Once you have it for more apps its more problematic because then memory address layouts will be shared amongst them. Secure app spawning randomizes the layout which is good for security, but if you disable it for one app its not that problematic because there will still be no sharing of memory layout in practice.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@tyzbit@toot.now Play Integrity didn't exist yet when they started the GrapheneOS project in 2014. What alternative was and is there to basing yourself on Android that is equally secure and private? AOSP is a FOSS project and was made to be an open project and the ecosystem and Google as well benefited a lot from it being open because it made the OS attractive to OEMs. Why are you blaming @GrapheneOS@grapheneos.social for being the victim of Google increasing its anticompetitive actions? What Google does is likely illegal in the context of anti-trust laws. Also most things are compatible still and GrapheneOS and the community have been able to convince some developers to allow GrapheneOS after first blocking it. GrapheneOS hasn't sacrificed privacy for compatibility. It offers various exploit protection settings to make the trade-off between compatibility and privacy as you see fit. Your comment is also very dismissive of the privacy benefits of the compatibility for Google Mobile Services that GrapheneOS has created.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@yoasif@mastodon.social @log@mastodon.sdf.org @malicious_n@mastodon.social @iju@mastodon.social @GrapheneOS@grapheneos.social Idk if protecting yourself against a warrantless privacy invasive search of your device after not being read your Miranda rights, should be classified as "freedom fighter working against the state" compared to "human being not cooperating when his rights are being violated by specific law enforcement officers".
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@thoralf@gruene.social @sinchens_@mastodon.social @glsbank@ruhr.social Ow, that's annoying. Might be worth contacting the developers about and leaving a 1-star Play Store review with a polite comment about this not working?
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to

@Netzblockierer@tech.lgbt @nakal@mastodon.social @shadowwwind@mastodon.social @gdmalan@infosec.exchange @maddad@mastodon.world @ZoidbergForPresident@kolektiva.social @arstechnica@mastodon.social @tails@fosstodon.org @torproject@mastodon.social

I've seen enough of that drama from afar…

The video you link is very disingenuous and bad faith. It leaks a private conversation, leaving out the necessary context to properly understand that private conversation and then makes false claims about how system updates work.

Rossman has had interactions with the GrapheneOS project and that specific developer before those private messages. He has also multiple times been very toxic towards them and has voiced support for another video on YouTube that is full of false claims and unfounded claims about the health of that GrapheneOS develper. In that private conversation, the developer asked Rossman once again to remove his support for that video. Because the video was cited as a motivation by the people that had repeatedly swatted the developer leading up to that conversation with Rossman. The developer was distressed due to his life being endangered by the swatting attacks which is the explanation for the suboptimal approach he used in that conversation. His request, however, "please don't publicly support a video full of lies that's a motivation for people to try to get me killed", seems very reasonable. Please also note that Rossman is a KiwiFarmer that has an identity verified KiwiFarms account named "larossman". He is just a bully who loves hanging out on the internet with other bullies.

He lied in the video about stopping with using GrapheneOS, he kept using it afterwards. That could be seen when he was using his phone in videos after that. He also made a wrong claim about him possibly being targeted with a malicious update while that isn't possible because GrapheneOS doesn't collect any telemetry.

I've ditched phones long ago and only use @tails / @tails_live / #Tails & @torproject / #TorBrowser, with maybe a VPN.

That's your decision but it isn't a good one for your privacy and security. Tails is based on typical desktop Linux software that doesn't have proper sandboxing with a proper permission model and mandatory access control. It also heavily uses memory unsafe languages compared to Android and has a lot of unnecessary extra attack surface.

0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to on mamutovo.cz
@lepapierblanc@mamutovo.cz Can you try disabling secure app spawning for the Company Portal app (InTune)?
0
4
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Dima812@mastodon.de @GrapheneOS@grapheneos.social Even though a profile can be reliably deleted, there is globally stored data on Android out of which forensic tools can easily conclude other profiles existed. Only way to properly wipe evidence of the other profiles is by wiping the entire device.
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@jonny@neuromatch.social There is no reason for the technical problems to disappear because of this case. Those problems remain.
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@majorlinux@toot.majorshouse.com What categories of apps are you looking for?
0
2
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@tyzbit@toot.now That is Google's fault. Google uses the anticompetitive Play Integrity API to deny non-certified OSes access to the NFC functionality of Google Wallet. Besides NFC, Google Wallet works and NFC itself also works, just not in Google Wallet. Google allows very insecure out of date OSes to use all Google Wallet functionality but doesn't certify or allow a proper secured OS like GrapheneOS.
0
1
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
RE: https://social.tchncs.de/@kuketzblog/116996309563886213 Interesting for people residing in Germany. (Of course always factory reset a pre-installed GrapheneOS from recovery mode after receiving it and verify the integrity by doing the post-installation steps from the install guide (checking the verified boot hash on the boot screen and setting up the Auditor app).
social.tchncs.de

Kuketz-Blog 🛡: "Am 30. Juli 2026 läuft die Sommerferien-Verlosung…" - Mastodon

0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@paepke@chaos.social No problem. Might be worth in the future to try enabling those setting again, the issues might get resolved later.
0
0
0
0
Open post
tranquil_cassowary @tranquil_cassowary@infosec.exchange
· 2mo ago
Replying to
@Dima812@mastodon.de @GrapheneOS@grapheneos.social See https://grapheneos.social/@GrapheneOS/117003886684404622
Open quoted post
Quoting
GrapheneOS
@GrapheneOS@grapheneos.social
@Dima812@mastodon.de It's possible to reliably delete specific profiles due to each having per-profile encryption keys with their own Weaver slots in the secure element. However, a lot of data about the profiles is stored globally and cannot be reliably deleted without wiping the device as a whole. It will be easily detectable by standard forensic software if there were any previously deleted profiles and the timestamps those were deleted. Bear in mind data can't be reliably deleted at a fine granularity.
Open quoted post
grapheneos.social

GrapheneOS: "@Dima812@mastodon.de It's possible to reliably de…" - GrapheneOS Mastodon

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:53:45 UTC