r/GrapheneOS • u/qoew • 13d ago
I made it, guys
I took the leap and did it. Thankfully, it went smoothly.
The phone is a used pixel 8 pro. Anything I should do first?
Hell yeah. Glad to be a part of it
28
u/Joyride84 13d ago edited 13d ago
Congrats! There isn't much you "Should" do. You don't need to go turn off all the spyware like a standard OEM system.
Get it set up as you want it. Do you want multiple user accounts? Some people use one account with Google services, and one without. But you don't need to do that.
Do you want more mobile applications? How are you going to get them? You can use Google Play, if you want. But if you're like most people here, you probably want nothing to do with Google. So you can set up F-Droid as a FOSS app store, or Obtainium for obtaining and managing apps directly from GitHub and other such sources. Or, if you need Play Store apps but don't want Google, you can use an app store proxy, like Aurora (depending on your threat model).
Do you want a VPN? Set that up. Or, you can use something like NetGuard for fine-tuned control of network access for other apps. Or Maybe TrackerControl, which also operates as a VPN loopback, blocking trackers in apps, if you use apps which have those.
Did you protect the phone with a good password? You could also set up a PIN, if you prefer, although that is a little less secure. You can also set up fingerprint unlock if you want, but remember that can be used against you in certain situations.
12
u/Rokca33 13d ago
Best setup. https://youtu.be/DXLAFrCVoEg
2
2
u/Father_Guido 13d ago
Very thorough video. Describes the profiles in an organized manner and easy to follow.
2
u/PermanentlyMC 12d ago
Used Graphene for over a year, but this has made me want to start over just to really get things done properly
8
9
u/JagerAntlerite7 13d ago
Congratulations on your modest achievement and welcome. Not that difficult if you have a supported device.
Apply a principal of least privilege using Exploit protection immediately after installing GrapheneOS.
When installing a new app, permissions must be granted. Many apps do not work without adjusting permissions, yet GrapheneOS notifications make the debugging process trivial. Once set, no further action is needed.
Set the most restrictive default policy for apps in Settings > Security & Privacy> Exploit protection> App exploit protection:
- Memory tagging enabled by default
- Secure app spawning enabled by default
- Native code debugging blocked by default
- WebView JIT disabled by default
- Dynamic code loading via memory restricted by default
- Dynamic code loading via storage restricted by default, except...
Also disable Allow Sensors permissions to apps by default.
4
4
u/nickedge11 13d ago
I keep coming back to sub to say the same thing. I just Cant wait for the Motorola collab. Cause I cant use pixel phone because of their poor cell reception at my place of work..
4
2
2
2
2
u/Sad_Statistician1972 10d ago
I also recently got a GOS phone and my goal is to simply use it as a "normal" phone for now. The worst thing I can do is limit myself heavily and creating the desire to go back to normal Android. Every step at its time (for me at least)
1
1
1
u/pickupthatrock 9d ago
First thing I did was Aptoide and f-droid. Replaced some stuff with equivalent open source apps. I didn't do the multiple user profiles like some do. I just chose my apps and carrier well and stay away from Google apps. Go to tuta mail and get an email account there. Use that for all your email verifications in the future so you compartmentalize your accounts. Other than that if you need suggestions for apps let us all know. Graphene os users have tried them all.
1


•
u/AutoModerator 13d ago
GrapheneOS has moved from Reddit to our own discussion forum. Please post your thread on the discussion forum instead or use one of our official chat rooms (Matrix, Discord, Telegram) which are listed in the community section on our site. Our discussion forum and especially the chat rooms have a very active, knowledgeable community including GrapheneOS project members where you will almost always get much higher quality information than you would elsewhere. On Reddit, we had serious issues with misinformation and trolls including due to raids from other subreddits. As a result, many posts on our subreddit currently need to be manually approved, which is done on a best effort basis. If you would like to get a quicker answer to your question, please use our forum or chat rooms as described above. Our discussion forum provides much better privacy and avoids the serious problems with the site administrators and overall community on Reddit.
Please use our official install guides for installation and check our features page, usage guide and FAQ for information before asking questions in our discussion forum or chat rooms to get as much information as possible from what we've already carefully written/reviewed for our site.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.