I've used GrapheneOS, but not PrivacyPros setup. The site is interesting. It is almost like a to do list of things for my phone. Most of the things they've done feels like a topic to look into and consider implementing.
It's absolutely insane that phones have online accounts deeply integrated into the OS. You need to give Apple your phone number to download any apps on iOS.
For example:
Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier.
And that's not even mentioning the other problem that nobody can download IceBlock anymore[1].
It's so refreshing for my phone not to ask for any identifying information when I set it up. GrapheneOS is a better software experience than iOS anyway[2].
Phones have great potential to be the most private and secure computers, cell services not withdrawing. And iPhones are one of the most private and secure devices. But, Apple uses that to restrict its users freedom and it makes Apple's users can easily be controlled by any government.
[2] once you install good apps. This is coming from a lifelong iOS user. Not prejudiced against Apple, I use a Mac (without an account) and their Advanced Data Protection is great (when I had an account).
"Phones have great potential to be the most private and secure computers."
How would that be achieved
We could assume that a user could make their own computer "private and secure"
But if a third party, e.g., Apple, Inc., Google, LLC, GrapheneOS Foundation, etc., has RCE, e.g., "auto-updates", then how can the computer be "private and secure" against that third party and any party that they "work with", voluntarily or not, e.g., a business partner, a government, but also others that might target these third parties, such as an attacker who isn't interested in their bug bounty programs, etc.
To achieve "private and secure", would the user need to remove the RCE capability of the third party (parties)
What about data collection and surveillance by the third party (the user would have to review the source code and compile the OS themselves to be sure about data collection and surveillance)
If there is data collection and surveillance, then how could the user be sure that the data collected and surveillance capability held by the third party is "private and secure" from that third party (e.g., Apple, Google, etc.), any third parties that work with them, and others who might target these third parties
Assuming the user even knows the identities of all these third parties, what if their operations are secretive and non-transparent
What if they have a history of dishonesty
What if they make no promises to the user that could be enforced and instead they just assume "trust"
Perhaps each user might have a different concept of "private and secure"
Can someone explain this? I've used custom ROMs back in the day (Cyanogen!) but I'm not familiar with GrapheneOS.
I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS.
So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at least give you the option of installing all that crap but that would seem to defeat the purpose in this case.)
But more broadly I'm not sure I understand the relevance in this particular context. The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario? (Ok I suppose half the stuff on the Play store is spyware so maybe it's more realistic than I'm thinking...)
On this subject since it's an Australian seller and marketed as "DV safe".
Australia has a national test of it's phone alert system in 10 days at 27/07/26, 2PM AEST. (People in North America would know it as Cell Alerts/Presidential Alerts etc.)
There have been warnings that hidden phones will almost certainly sound, and their recommendation is to ether power off the phone or put it into airplane mode at least an hour before the test...
This post is literally just SEO copy designed to sell degoogled phones to (justifiably) anxious DV victims?
Their phones are more than twice as expensive as equivalent models at JF HiFi too (and 5-10x the price of an older, but still perfectly useful degoogled phone from Marketplace).
Here we're discussing a domestic abuse situation, where people are forcing victims to hand over their phone, and have apps installed to keep track of them. Against their will.
And the solution is to... what? Mysteriously have control of your own phone, and install an OS which prevents this? Seriously? I can just imagine it, when the unfamiliar OS is discovered, or the app not working. This is a domestic abuse situation, it's not about hidden sneakiness.
It's about in-your-face control. It's about forced compliance, or else. It's about the abuser becoming exceptionally upset about their tracking not working, or about a new, mysterious OS.
Installing GrapheneOS would not be tolerated. It would be an act which comes with reprisals. I can just imagine the reaction when the abuser can't get the phone to do as they wish, for the person to disclose what the OS is, or just to hand over their unlocked phone, and discover it's GrapheneOS, and Google it and see what it's for.
It's actually horrible advice to advocate the someone in this situation installs GrapheneOS. How could it possibly help?
GrapheneOS is great to protect from secret, unknown spying. Not some domestic abuse situation where spying isn't via secretness.
29 comments
[ 0.20 ms ] story [ 23.9 ms ] threadI wouldn’t recommend domestic violence victims to install graphene os on their phone by themselves
For example:
Say anyone that downloaded IceBlock commited crime, Apple could give the govt everyone who downloaded its phone number, the govt could get the realtime location of everyone based on their phone number from the carrier.
And that's not even mentioning the other problem that nobody can download IceBlock anymore[1].
It's so refreshing for my phone not to ask for any identifying information when I set it up. GrapheneOS is a better software experience than iOS anyway[2].
Phones have great potential to be the most private and secure computers, cell services not withdrawing. And iPhones are one of the most private and secure devices. But, Apple uses that to restrict its users freedom and it makes Apple's users can easily be controlled by any government.
GrapheneOS delivers that dream.
[1] https://www.iceblock.app/
[2] once you install good apps. This is coming from a lifelong iOS user. Not prejudiced against Apple, I use a Mac (without an account) and their Advanced Data Protection is great (when I had an account).
How would that be achieved
We could assume that a user could make their own computer "private and secure"
But if a third party, e.g., Apple, Inc., Google, LLC, GrapheneOS Foundation, etc., has RCE, e.g., "auto-updates", then how can the computer be "private and secure" against that third party and any party that they "work with", voluntarily or not, e.g., a business partner, a government, but also others that might target these third parties, such as an attacker who isn't interested in their bug bounty programs, etc.
To achieve "private and secure", would the user need to remove the RCE capability of the third party (parties)
What about data collection and surveillance by the third party (the user would have to review the source code and compile the OS themselves to be sure about data collection and surveillance)
If there is data collection and surveillance, then how could the user be sure that the data collected and surveillance capability held by the third party is "private and secure" from that third party (e.g., Apple, Google, etc.), any third parties that work with them, and others who might target these third parties
Assuming the user even knows the identities of all these third parties, what if their operations are secretive and non-transparent
What if they have a history of dishonesty
What if they make no promises to the user that could be enforced and instead they just assume "trust"
Perhaps each user might have a different concept of "private and secure"
I remember Cyanogen ships without Google Play etc., right? (Because if you install Google Services and a bunch of crap from their store (theirs and otherwise) that spies on you, it defeats the purpose of a privacy preserving OS.
So I'm assuming Graphene is at least as strict as that? (Well Cyanogen at least give you the option of installing all that crap but that would seem to defeat the purpose in this case.)
But more broadly I'm not sure I understand the relevance in this particular context. The article mentions that an abuser could put spyware on your phone? Is that a realistic scenario? (Ok I suppose half the stuff on the Play store is spyware so maybe it's more realistic than I'm thinking...)
They also recommend at least 12 GB RAM. What about domestic abuse survivors requires that?
It's not like Google is going to sell your tracking data to abuser.
There are many reasons to get rid of Google altogether, I just don't understand this one.
Australia has a national test of it's phone alert system in 10 days at 27/07/26, 2PM AEST. (People in North America would know it as Cell Alerts/Presidential Alerts etc.)
There have been warnings that hidden phones will almost certainly sound, and their recommendation is to ether power off the phone or put it into airplane mode at least an hour before the test...
How did we get there?
Let's not normalize this kind of profiteering out of OSS.
Their phones are more than twice as expensive as equivalent models at JF HiFi too (and 5-10x the price of an older, but still perfectly useful degoogled phone from Marketplace).
Why is it on the front page of HN?
Why?
Here we're discussing a domestic abuse situation, where people are forcing victims to hand over their phone, and have apps installed to keep track of them. Against their will.
And the solution is to... what? Mysteriously have control of your own phone, and install an OS which prevents this? Seriously? I can just imagine it, when the unfamiliar OS is discovered, or the app not working. This is a domestic abuse situation, it's not about hidden sneakiness.
It's about in-your-face control. It's about forced compliance, or else. It's about the abuser becoming exceptionally upset about their tracking not working, or about a new, mysterious OS.
Installing GrapheneOS would not be tolerated. It would be an act which comes with reprisals. I can just imagine the reaction when the abuser can't get the phone to do as they wish, for the person to disclose what the OS is, or just to hand over their unlocked phone, and discover it's GrapheneOS, and Google it and see what it's for.
It's actually horrible advice to advocate the someone in this situation installs GrapheneOS. How could it possibly help?
GrapheneOS is great to protect from secret, unknown spying. Not some domestic abuse situation where spying isn't via secretness.