Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

tranquil_cassowary

@tranquil_cassowary@infosec.exchange
  • Open on infosec.exchange

Interested in software privacy and security.
PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

30 Followers
24 Following
50 Posts
Joined August 20, 2025
Mobile OS:
GrapheneOS
Desktop OS:
MacOS + ChromeOS

Posts

Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 05, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @starlight@lgbtqia.space
@starlight@lgbtqia.space It is, a lot of this is due to misguided anti-tampering, anti-reverse engineering and obscuring efforts by the app devs. Banks often use code libraries for that which are also used by other banks causing them to share the same kind of issues. It is misguided just like the usage of Play Integrity API to increase security. Part of this is app devs' fault, part of it is on Google and code libraries for mismarketing their APIs.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 04, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @lepapierblanc@mamutovo.cz
@lepapierblanc@mamutovo.cz Maybe this will work again in the future, BTW, always worth trying to enable it again down the line. FYI Having it disabled for just that one app isnt a very big issue. Once you have it for more apps its more problematic because then memory address layouts will be shared amongst them. Secure app spawning randomizes the layout which is good for security, but if you disable it for one app its not that problematic because there will still be no sharing of memory layout in practice.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 04, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @samurro@fosstodon.org
@samurro@fosstodon.org Yes but its not 2027 yet, so not yet on that list. The FAQ also says what the requirements are for future devices and Motorola is working together with GrapheneOS in order to meet those.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 04, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @lepapierblanc@mamutovo.cz
@lepapierblanc@mamutovo.cz Secure app spawning is a setting you can access via Settings > security and privacy > exploit protections > secure app spawning. Go to enabled, find the company portal app and then put that on disabled
1
1
1
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 04, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @samurro@fosstodon.org
@samurro@fosstodon.org 2027 on some Motorola flagship(s)
2
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Logical_Error@fosstodon.org
@Logical_Error@fosstodon.org @GrapheneOS@grapheneos.social parterned with Motorola Mobility, not Motorola Solutions, both are completely separate companies since 2011, they aren't sister companies.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @pft@infosec.exchange
@pft@infosec.exchange @zak@infosec.exchange Normally it should come to the hardware meeting the requirements, which for 2027 will be the phones with a flagship Qualcomm SoC. The chances are high we are talking about Signature and the two Razrs here, although these specific models haven't yet been confirmed, these ship with the flagship SoCs.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @AwetTesfaiesus@mastodon.social
@AwetTesfaiesus@mastodon.social @Torx@social.tchncs.de Please see https://discuss.grapheneos.org/d/24134-devices-lacking-standard-privacysecurity-patches-and-protections-arent-private for some insights on why a partnership is unlikely to happen. Firstly, they'll need to care about security. Secondly, they would need to actually care about sustainability, instead of just marketing with it, by providing proper long time software support. Lastly, they would need to stop their partnership with /e/OS, given their attacks on the GrapheneOS project and their userbase, and their dishonest stance on privacy and security.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to on mamutovo.cz
@lepapierblanc@mamutovo.cz Can you try disabling secure app spawning for the Company Portal app (InTune)?
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to on social.0x520.eu
@finn@social.0x520.eu Can you disclose which apps? Maybe we can help.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @six_grandfathers_mountain@mastodon.social
@six_grandfathers_mountain@mastodon.social @pierre_pebble@mastodon.ie @404mediaco@mastodon.social See further down this thread for accurate info about how durress works. I stilk have a question about this post specifically, if you don't mind. Based on whay source did you conclude that this is how it works? Its interesting to know if there is a source with inaccurate info or if you just misinterpreted something which was accurately explained.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @pierre_pebble@mastodon.ie
@pierre_pebble@mastodon.ie @six_grandfathers_mountain@mastodon.social @404mediaco@mastodon.social To summarize, it wipes 3 types of data needed to derive the encryption key. Wiping 1 of those is enough, they wipe all 3 for redundancy because this goes insanely quickly anyway. Then it reboots the device to clear RAM. At this point when the OS tries to boot, it fails because it can't decrypt the data. It will try a few times to reboot and will them prompt you on a recovery screen to factory reset the device. Then it will do the factory procedure that puts your device in a state where it will show you the device set up screen if you boot up. The data was already unrecoverable before you do that, to be very clear, but the device would just bring you to the set up wizard before you go through the recovery menu.
1
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Aug 03, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @six_grandfathers_mountain@mastodon.social
@six_grandfathers_mountain@mastodon.social @pierre_pebble@mastodon.ie @404mediaco@mastodon.social It doesn't do any "bricking". Idk if you mean something else with that term, but normally bricking means the device becomes unusable permanently.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 30, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Prometheus@infosec.exchange
@Prometheus@infosec.exchange That wouldn't work. Device needs to reboot to clear RAM which is noticeable and, without wiping the whole device, forensic evidence of other profiles having existed remains.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 30, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @paepke@chaos.social
@paepke@chaos.social No problem. Might be worth in the future to try enabling those setting again, the issues might get resolved later.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 30, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @paepke@chaos.social
@paepke@chaos.social Is it MS Company Portal ? If so disable the hardened exec bases spawning for that.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 30, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @AdansiX@metalhead.club
@AdansiX@metalhead.club No problem, happens to the best of us and the reporting about it in media and from some other projects has admittedly not really been great which leads to misunderstandings.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 30, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Okuna@social.tchncs.de
@Okuna@social.tchncs.de @GrapheneOS@grapheneos.social Okay then I honestly wouldn't know. But is everything functional?
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 30, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Okuna@social.tchncs.de
@Okuna@social.tchncs.de @GrapheneOS@grapheneos.social It won't delete any of your data, if you changed settings yourself that are located under Settings > Network > Your SIM card, then those would be put on the default again. For example if you enabled voice over LTE, disabled roaming, etc. So if you did that just go through those settings again after you did that reset.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 30, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Okuna@social.tchncs.de
@Okuna@social.tchncs.de @GrapheneOS@grapheneos.social Can you try Settings > System > Reset > Mobile network settings?
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 29, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @AdansiX@metalhead.club
@AdansiX@metalhead.club I'm referring to that. Let me clarify. Apps from developers that don't complete the developer verification by Google will still install like before in non-certified OSes like GrapheneOS. The warning that you install unverified apps, which is bypassable after a one-time 24 hour wait period on certified OSes, won't be there on non-certifies OSes. There is no limitation.
1
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 29, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @tranquil_cassowary@infosec.exchange
@Dima812@mastodon.de @GrapheneOS@grapheneos.social See https://grapheneos.social/@GrapheneOS/117003886684404622
Quoting
GrapheneOS @GrapheneOS@grapheneos.social
@Dima812@mastodon.de It's possible to reliably delete specific profiles due to each having per-profile encryption keys with their own Weaver slots in the secure element. However, a lot of data about the profiles is stored globally and cannot be reliably deleted without wiping the device as a whole. It will be easily detectable by standard forensic software if there were any previously deleted profiles and the timestamps those were deleted. Bear in mind data can't be reliably deleted at a fine granularity.
Open quoted post
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 29, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Dima812@mastodon.de
@Dima812@mastodon.de @GrapheneOS@grapheneos.social Even though a profile can be reliably deleted, there is globally stored data on Android out of which forensic tools can easily conclude other profiles existed. Only way to properly wipe evidence of the other profiles is by wiping the entire device.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 29, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @AdansiX@metalhead.club
@AdansiX@metalhead.club The ID verification doesn't affect GrapheneOS. It doesn't apply to it. It only applies to OSes certified by Google.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 29, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to on babka.social
@kolev@babka.social Yes works well if installed via Sandboxes Google Play Store
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 29, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @xoagray@tiggi.es
@xoagray@tiggi.es @TheMNWolf@furry.engineer Some extra context to this: Almost all apps work and most banking apps also work. Its just a small minority that doesn't, which is more common in the banking category. The reason for this is almost solely the Play Integrity API. Other compatibility issues, that GrapheneOS can fix by changes on their side, get fixed swiftly. Play Integrity is an API made by Google which they market towards app developers as benefiting the security of their app. However the API doesn't use objective criteria related to security. The API blocks GrapheneOS because it isn't certified by Google. A certification they can only obtain by licensing and bundling Google Mobile Services, which they don't do and don't want to do. GrapheneOS however is a very secure OS that keeps up with updates to Android. While blocking this secure OS, the API allows OSes which are severely behind on security updates, running on devices which are end of life, just because they are certified. So we can conclude that it's false communication from Google to devs that this API is focused on security. The API is deemed anti-competitive by GrapheneOS and pressure is applied on app developers to either ditch Play Integrity or explicitly allow GrapheneOS via a different API. Some developers have done that, which is nice. Ideally, regulators would taken action in the context of anti-trust.
1
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 29, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @jonny@neuromatch.social
@jonny@neuromatch.social There is no reason for the technical problems to disappear because of this case. Those problems remain.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @log@mastodon.sdf.org
@log@mastodon.sdf.org @yoasif@mastodon.social @malicious_n@mastodon.social @iju@mastodon.social @GrapheneOS@grapheneos.social Yes if it was expected in this case he could have wiped the device before hand or at least just turned it off.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @yoasif@mastodon.social
@yoasif@mastodon.social @log@mastodon.sdf.org @malicious_n@mastodon.social @iju@mastodon.social @GrapheneOS@grapheneos.social Idk if protecting yourself against a warrantless privacy invasive search of your device after not being read your Miranda rights, should be classified as "freedom fighter working against the state" compared to "human being not cooperating when his rights are being violated by specific law enforcement officers".
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @yoasif@mastodon.social
@yoasif@mastodon.social @log@mastodon.sdf.org @malicious_n@mastodon.social @iju@mastodon.social @GrapheneOS@grapheneos.social Of course, the GrapheneOS devs don't have control over when people use their features. And they have admitted themselves that in the US, where you cant be forced to give your password, relying on auto-reboot would've made more sense. There are circumstances to think of though that someone carries data for a good reason or that a person would be asked to hand over their phone in circumstances where it isn't expected (e.g. you aren't passing border control). Why would someone carry an empty device in those cases? And in those cases, as I said before in another post in this thread, there are different considerations at play to decide whether it makes sense to apply duress or not. I feel like you approach the usefulness of the duress password with a very narrow view on possible situations people can find themselves in. The situation of Atlanta isn't like other situations.
0
2
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @thoralf@gruene.social
@thoralf@gruene.social @sinchens_@mastodon.social @glsbank@ruhr.social Ow, that's annoying. Might be worth contacting the developers about and leaving a 1-star Play Store review with a polite comment about this not working?
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Netzblockierer@tech.lgbt

@Netzblockierer@tech.lgbt @nakal@mastodon.social @shadowwwind@mastodon.social @gdmalan@infosec.exchange @maddad@mastodon.world @ZoidbergForPresident@kolektiva.social @arstechnica@mastodon.social @tails@fosstodon.org @torproject@mastodon.social

I've seen enough of that drama from afar…

The video you link is very disingenuous and bad faith. It leaks a private conversation, leaving out the necessary context to properly understand that private conversation and then makes false claims about how system updates work.

Rossman has had interactions with the GrapheneOS project and that specific developer before those private messages. He has also multiple times been very toxic towards them and has voiced support for another video on YouTube that is full of false claims and unfounded claims about the health of that GrapheneOS develper. In that private conversation, the developer asked Rossman once again to remove his support for that video. Because the video was cited as a motivation by the people that had repeatedly swatted the developer leading up to that conversation with Rossman. The developer was distressed due to his life being endangered by the swatting attacks which is the explanation for the suboptimal approach he used in that conversation. His request, however, "please don't publicly support a video full of lies that's a motivation for people to try to get me killed", seems very reasonable. Please also note that Rossman is a KiwiFarmer that has an identity verified KiwiFarms account named "larossman". He is just a bully who loves hanging out on the internet with other bullies.

He lied in the video about stopping with using GrapheneOS, he kept using it afterwards. That could be seen when he was using his phone in videos after that. He also made a wrong claim about him possibly being targeted with a malicious update while that isn't possible because GrapheneOS doesn't collect any telemetry.

I've ditched phones long ago and only use @tails / @tails_live / #Tails & @torproject / #TorBrowser, with maybe a VPN.

That's your decision but it isn't a good one for your privacy and security. Tails is based on typical desktop Linux software that doesn't have proper sandboxing with a proper permission model and mandatory access control. It also heavily uses memory unsafe languages compared to Android and has a lot of unnecessary extra attack surface.

0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @thoralf@gruene.social
@thoralf@gruene.social Agreed but the GrapheneOS project is aware of that themselves. They don't think the UX and reliability is good. They want to replace it but there is currently no better alternative with adequate licensing and they haven't yet have the time to make one themselves.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @thoralf@gruene.social
@thoralf@gruene.social @sinchens_@mastodon.social @glsbank@ruhr.social Does this info help you to get it working?: https://github.com/PrivSec-dev/banking-apps-compat-report/issues/44
1
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Netzblockierer@tech.lgbt
@Netzblockierer@tech.lgbt @shadowwwind@mastodon.social @gdmalan@infosec.exchange @maddad@mastodon.world @ZoidbergForPresident@kolektiva.social @nakal@mastodon.social @arstechnica@mastodon.social @EUCommission@ec.social-network.europa.eu GrapheneOS focuses on usability besides privacy and security. They've made a web installer to simplify the installation compared to needing to use a command line interface. They've clarified the error messages this web installer gives over time in case something goes wrong. They've focused on community building to make sure free support is widely available on various platforms. They've made a compatibility layer for Google Mobile Services so people can for the most part just install Google Play and use the Play Store and its apps like people would on other Android phones. They focus on fixing regressions with regard to compatibility very swiftly. They've made some hardening options opt-in instead of opt-out to make sure the OS by default is very compatible with third-party apps. They are now also focussing on accessibility, by developing their own text to speech and speech to text engines. They are revamping the bundled apps they inherit from AOSP at the moment to make sure their UI and UX aligns with current expectations of people. Etc. What exactly do you think makes GrapheneOS difficult to use for the "average person"? This is a genuine question. Feedback is useful. #GrapheneOS
4
2
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 28, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
RE: https://social.tchncs.de/@kuketzblog/116996309563886213 Interesting for people residing in Germany. (Of course always factory reset a pre-installed GrapheneOS from recovery mode after receiving it and verify the integrity by doing the post-installation steps from the install guide (checking the verified boot hash on the boot screen and setting up the Auditor app).
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @majorlinux@toot.majorshouse.com
@majorlinux@toot.majorshouse.com For text edits I like BeauTyXT For full note taking I like Notesnook and Standard Notes For navigation is use Google Maps and Organic Maps For music, I heard great things about Auxio if youre not streaming For local calendar, Fossify Calendar is an option, otherwise use something like Tuta or Proton Calendar for encryption If you don't like the bundled keyboard, FlorisBoard is nice I'm just going to assume you disline the bundled Gallery, because everyone does, in that case ReFra is nice and it's what GrapheneOS is building on as replacement for the current Gallery app For chatting Signal is nice of course as its the gold standard, there is fork called Molly that you might have interest in If you think of anything else feel free to ask.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @tyzbit@toot.now
@tyzbit@toot.now Play Integrity didn't exist yet when they started the GrapheneOS project in 2014. What alternative was and is there to basing yourself on Android that is equally secure and private? AOSP is a FOSS project and was made to be an open project and the ecosystem and Google as well benefited a lot from it being open because it made the OS attractive to OEMs. Why are you blaming @GrapheneOS@grapheneos.social for being the victim of Google increasing its anticompetitive actions? What Google does is likely illegal in the context of anti-trust laws. Also most things are compatible still and GrapheneOS and the community have been able to convince some developers to allow GrapheneOS after first blocking it. GrapheneOS hasn't sacrificed privacy for compatibility. It offers various exploit protection settings to make the trade-off between compatibility and privacy as you see fit. Your comment is also very dismissive of the privacy benefits of the compatibility for Google Mobile Services that GrapheneOS has created.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @majorlinux@toot.majorshouse.com
@majorlinux@toot.majorshouse.com What categories of apps are you looking for?
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @gdmalan@infosec.exchange
@gdmalan@infosec.exchange @maddad@mastodon.world @ZoidbergForPresident@kolektiva.social @nakal@mastodon.social @arstechnica@mastodon.social Good replies but I have one small correction. It hasn't been confirmed yet that GrapheneOS could be installed by default as an option. At a minimum it will be yellow boot support like with Pixels now, allowing you to flash it and then compare the public verified boot key hash to the hash on GrapheneOS' website. And an in-between option could be green boot but still not preinstalled as OS. In case of green boot GraoheneOS verified boot key would be flashed onto the device in the factory, alongside the key for Motorola's OS. If you then install GrapheneOS, you dont have to verify the verified boot hash on the boot screen.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @tyzbit@toot.now
@tyzbit@toot.now That is Google's fault. Google uses the anticompetitive Play Integrity API to deny non-certified OSes access to the NFC functionality of Google Wallet. Besides NFC, Google Wallet works and NFC itself also works, just not in Google Wallet. Google allows very insecure out of date OSes to use all Google Wallet functionality but doesn't certify or allow a proper secured OS like GrapheneOS.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Life_is@no-pony.farm
@Life_is@no-pony.farm @ennopark@mastodon.social I understand why people try to implement it and why people are interested in finding a solution for their non-GrapheneOS device, let me be clear about that. But it's in my opinion very bad if an individual thinks he can rely on it (especially people with high threat model) and it ends up not being waterproof at all, or when they end up not needing to every use durress but had an invasive app installed on their system which did more harm than good in that cade.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @nek@hear-me.social
@nek@hear-me.social @HaTetsu@mastodon.com.pl Should work to install it over LineageOS
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 27, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @Life_is@no-pony.farm
@Life_is@no-pony.farm @ennopark@mastodon.social A userspace app can't implement this properly and whilst trying to do so often will ask very invasive device permissions for that app.
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 26, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
RE: https://grapheneos.social/@GrapheneOS/116946765689545308 For those who weren't able to join this live, this Q&A was interesting for people who are considering GrapheneOS and current users. Quite long, that's true, but so is Dune Part 1 and that movie is way more boring than this.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 26, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @j_r@social.jugendhacker.de
@j_r@social.jugendhacker.de @dristor@masto.es They are saying this because its technically accurate, not because they think it helps people know they are the most secure option. The Linux kernel is even regarded by them as a weak point for the security. They aren't happy about the kernel's architecture and security culture. So their take is actually quite honest because they feel its technically correct, they don't do it to market themselves because they don't see it as a strong point. The other OS and phone projects trying to claim the Linux label for themselves, however, are often romanticising Linux and seeing it as a positive thing. For them it seems to be PR.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 26, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @FlashMobOfOne@mstdn.social
@FlashMobOfOne@mstdn.social The website has well documented information thats mostly in laymans terms especially the usage guide. Its quite a lot to read though and not always suiting for every type of attention span or people who retain better from visual and auditory media instead of text. You can join the community channels for instant messaging though: https://grapheneos.org/contact And for videos, the YouTuber SideOfBurritos has good YouTube content. For the rest, I recommend being careful with reading third-party sources because many are inaccurate or outdated.
0
0
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 26, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @tranquil_cassowary@infosec.exchange
@FlashMobOfOne@mstdn.social this might interest you https://grapheneos.social/@GrapheneOS/116984346634476510
Quoting
GrapheneOS @GrapheneOS@grapheneos.social
We've published an overview of how we protect against data extraction from locked devices with the recently improved secure element rate limiting, locked device auto-reboot, strong passphrases, 2nd factor fingerprint PIN, stronger exploit protections and more: https://discuss.grapheneos.org/d/40700-grapheneos-protections-against-data-extraction-from-locked-devices
Open quoted post
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 26, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @FlashMobOfOne@mstdn.social
@FlashMobOfOne@mstdn.social Feel free to ask questions if you have any
0
1
0
0
Open post
tranquil_cassowary
tranquil_cassowary @tranquil_cassowary@infosec.exchange · Jul 26, 2026
tranquil_cassowary
@tranquil_cassowary@infosec.exchange

Interested in software privacy and security. PSA: The FOSS Accrescent App Store for Android needs your help, donations are very welcome right now!

infosec.exchange
Replying to @okias@floss.social
@okias@floss.social @GrapheneOS@grapheneos.social @FediFollows@social.growyourown.services @wariat@mastodon.social @SpaceLifeForm@infosec.exchange Seems to be in agreement with the spirit of this post https://grapheneos.social/@GrapheneOS/116975553767986938 Note that the top post was about Linux bases phones, using the penguin mascot of the Linux kernel. It wasn't about GNU phones or anything alike. The responses seem technically correct replies to a question from someone else tagging GrapheneOS and asking why it isn't listed.
Quoting
GrapheneOS @GrapheneOS@grapheneos.social
@FediFollows@social.growyourown.services @SpaceLifeForm@infosec.exchange GrapheneOS is a Linux distribution. It's incorrect to say otherwise. Linux is a kernel and doesn't mean systemd. You don't say Linux when you mean GNU hurd or FreeBSD. Bringing glibc and systemd to mobile is not bringing Linux to mobile. Based on the fact that one of the operating systems you've listed uses musl rather than glibc, the correct terminology to use would be systemd phones. Bringing systemd to mobile is not the same as bringing Linux to mobile.
Open quoted post
0
0
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 00:27:00 UTC