<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Android on Side Of Burritos</title>
  <link rel="alternate" href="https://staging.sideofburritos.com/tags/android/" />
  <link rel="self" href="https://staging.sideofburritos.com/tags/android/index.xml" />
  <subtitle>Recent content in Android on Side Of Burritos</subtitle>
  <id>https://staging.sideofburritos.com/tags/android/</id>
  <generator uri="http://gohugo.io" version="0.165.0">Hugo</generator>
  <language>en-us</language>
  <updated>2026-05-11T13:45:00Z</updated>
  <author>
    <name>Josh</name>
    
  </author>
  
      <entry>
        <title>How to Flash Stock Android on Google Pixel</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-flash-stock-android-on-pixel/" />
        <id>https://staging.sideofburritos.com/blog/how-to-flash-stock-android-on-pixel/</id>
        <published>2026-05-11T13:45:00Z</published>
        <updated>2026-05-11T13:45:00Z</updated>
        <summary type="html">Installing Stock Android on Google Pixel is easier than ever.  In this example we&amp;#39;re going to be using the official Android Flash Tool.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode76s0hbhb">🎥 


<a href="https://youtu.be/zHq8Nx-6fQ0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://flash.android.com" target="_blank" rel="noopener" class="text-break">https://flash.android.com</a> - Android Flash Tool</li>
<li>


<a href="https://grapheneos.org/install/web" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/install/web</a> - GrapheneOS Web Install (Used to remove non-stock key)</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">📝 Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>So today I&rsquo;ll be covering how to install stock Android OS on a Google Pixel currently running GrapheneOS. This process should still work if you&rsquo;re running a different operating system than GrapheneOS looking to install the stock OS on your device, but for the purpose of this demo, it&rsquo;ll be a Google Pixel 7 running GrapheneOS. So to get started, we&rsquo;re going to head on over to <a href="https://grapheneos.org">grapheneos.org</a>. Select install GrapheneOS. Select web USB-based installer. Scroll down in the table of contents to replacing GrapheneOS with the stock OS. This is the one part that&rsquo;s specific to GrapheneOS, and that is GrapheneOS factory images. Flash a non-stock Android verified boot key, which needs to be erased to fully revert back to the stock device state. Before flashing the stock factory images, you should boot the device into fast boot mode and make sure the boot loader is unlocked. Then erase the custom Android verified boot key to untrust it. And then regardless of which OS you&rsquo;re using, we&rsquo;ll be using the <a href="https://flash.android.com">Google web flashing tool</a>. So we&rsquo;ll get to that shortly. But the first step in this process is to enable OEM unlocking and USB debugging. So to do that, swipe up on your device, go to settings, scroll down to about phone, tap on that, scroll down to the bottom, tap on build number, I think four or five times. You&rsquo;ll be prompted for your PIN code. Enter that.</p>
<p>We can now swipe back. Go to system right above about phone. You should now see developer options. Tap on that. We&rsquo;re going to scroll down. The first one is OEM unlocking. Toggle that on. Enter your device PIN again. Allow OEM unlocking. Enable. Scroll down some more till you get to USB debugging. Enable that. Allow USB debugging. Okay. So now the next step is to boot into fast boot mode and make sure the boot loader is unlocked. So for that, we need to connect a USB cable to our device. This USB cable should be plugged into whatever device you&rsquo;re using to perform the installation. I&rsquo;m using my laptop with Brave Browser. Now that we have that plugged in, we need to boot into fast boot mode. And to do that, we&rsquo;re going to press the power button. And as soon as we press restart, hold the volume down button down. So, press restart, hold volume down while it&rsquo;s rebooting.</p>
<p>If that worked correctly, you should be presented with the fast boot mode. And if we look here, we see device state locked, but it is unlockable since OEM unlocking is enabled. And on the GrapheneOS page, we&rsquo;re going to scroll up to unlock bootloader. It should be the first step at the top. Press unlock bootloader. Your screen should change to this if everything&rsquo;s working successfully. But before we unlock the bootloader, I do want to say this process will erase all data on your device. So if there&rsquo;s something you want to save, stop now. Transfer that data off. Otherwise, it&rsquo;ll be gone, and you cannot recover it. So now on this screen, we have do not unlock the bootloader. To change that, press the volume up or down. And when it says unlock the bootloader, press the power button to execute it.</p>
<p>And if that was successful, you should see device state unlocked. Now at this point, we can proceed with the GrapheneOS-specific step, which again, scroll back down to the bottom, press the remove non-stock key. Key erased. We are good to proceed. Once that&rsquo;s completed, you can then right-click on the <a href="https://flash.android.com">Google web flashing tool</a>, open link in new tab. Let&rsquo;s go to the new tab. You can click get started. You&rsquo;ll see a popup like this. Grant access to ADB keys. Allow ADB access. Press the button. Now at this point, if everything was successful, you should see one available device that you can select. So click on that now because we used the GrapheneOS page to remove the stock key. You might see an error like this: connection error. Just try reconnecting your device cable and plug it back in again.</p>
<p>So once I did that, I now see that my device is available to connect to. It says connected slow because I&rsquo;m using a crappy cable, but that doesn&rsquo;t make a difference. It just makes the process take longer. So once you see this, you can then go ahead and select your device. We&rsquo;re going back to default. Once you do that, press the install build button again. Here&rsquo;s another warning. Factory reset will result in all data on the Android device being erased. It&rsquo;s already erased because we unlocked the bootloader. Do not unplug your device. Do not interact with your device unless instructed. Once you give that a quick read, select continue or confirm. You must agree to the license. I accept. Preparing your device in progress. Now, this step will take different amounts of time depending on your internet connection. So, I&rsquo;m going to give this a minute to download, and I&rsquo;ll be back in a moment.</p>
<p>So this is about done. So we should see our device flash in a moment once this finishes.</p>
<p>Now that that has finished, the next step is to lock the device. Your bootloader must be locked to complete the process. So select start. And now on our phone, we see do not lock the bootloader. We want to lock the bootloader. So, press volume up or volume down. Lock the bootloader. Press the power button to execute that.</p>
<p>Once that finishes, we saw device state locked. Your device will now reboot. You can press done on the page. We are finished here.</p>
<p>Give our device a minute to start up.</p>
<p>So, at this point, we are back on stock Android OS. The device is ready to be sold, traded in, use it, whatever. The web user interface makes the process pretty straightforward, but if you have any questions or comments, feel free to leave those down below, and I&rsquo;ll see you next time.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>GrapheneOS/Android App Permissions Explained</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-android-app-permissions-explained/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-android-app-permissions-explained/</id>
        <published>2026-04-21T13:50:00Z</published>
        <updated>2026-04-21T13:50:00Z</updated>
        <summary type="html">GrapheneOS/Android app permissions and some basic troubleshooting techniques.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode58s0hbhb">🎥 


<a href="https://youtu.be/CqF0wtucBag" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://developer.android.com/guide/topics/manifest/manifest-intro" target="_blank" rel="noopener" class="text-break">https://developer.android.com/guide/topics/manifest/manifest-intro</a> - Android Developer docs on manifest</li>
<li>


<a href="https://github.com/FossifyOrg/Calendar/blob/8c6c8b704d4211e46ee87a09f7aa2ff7ed4340c6/app/src/main/AndroidManifest.xml#L2-L13" target="_blank" rel="noopener" class="text-break">https://github.com/FossifyOrg/Calendar/blob/8c6c8b704d4211e46ee87a09f7aa2ff7ed4340c6/app/src/main/AndroidManifest.xml#L2-L13</a> - Calendar app manifest</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">📝 Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>So today I want to talk about Android app permissions and the reason for that is recently I was on a consultation call with a client. I was helping them figure out some issues they were having with an app. Turns out they had some permissions disabled. They don&rsquo;t know when it happened but I showed them how to access them, how to work through the issue and they were extremely happy knowing that information.</p>
<p>To me that information seemed basic but after thinking about it I&rsquo;ve been using Android, specifically Graphene OS, for about five years now. So something that might be basic to me could be extremely helpful to someone just getting started so that&rsquo;s why I&rsquo;m going to be going through this today.</p>
<p>I also think the art of troubleshooting and problem solving and just learning in general seems to be disappearing for some reason. If you&rsquo;re looking to get into tech anytime soon, especially in this AI era or whatever you want to call it, there&rsquo;s only so much you can memorize and so many things you can read about. But if you know how to troubleshoot and problem solve, you will be a much more valuable candidate.</p>
<p>So to get started, this is my test device I use with clients, so don&rsquo;t trust as a recommendation any of the apps you see listed here. I was just helping people troubleshoot stuff. But what we&rsquo;re going to be using today as an example is WhatsApp. I don&rsquo;t use WhatsApp personally, but WhatsApp requests a lot of permissions, so it&rsquo;s a great example to use.</p>
<p>So to get started, long press on the app. Go to App Info. Once you come to this screen, the second option down is Permissions, and this is what we&rsquo;ll be talking about today.</p>
<p>The first one you&rsquo;re going to see, at least on Graphene OS, is the Sensors Permission. This is allowed by default for all apps, which is why you might see it listed as allowed and wonder why it&rsquo;s there. One side note, you can disable sensors from being allowed by default. If you go into Settings, Security and Privacy, More Security and Privacy, and then disable the third one down, allow sensors permission to apps by default.</p>
<p>Now when that&rsquo;s disabled and you install any new apps, this will not apply to existing app installations. The sensor permission or sensors permission will not be granted. Sensors are things like your GPS module or the gyroscope module inside your phone. So if you then have an app that has sensors disabled, then that app cannot access those things.</p>
<p>So the reason this is allowed by default is that on GrapheneOS, this permission is exposed to users. Typical Android, it&rsquo;s not. So if you do have it disabled, just remember you&rsquo;ll need to enable it if you have an app that needs to use sensors. Otherwise it won&rsquo;t work.</p>
<p>So getting back to the permissions, if we take a look, the second one, we have call logs. Call logs is just the log of calls on your device. Some of these permissions are self-explanatory based on the name. Some of them are not. Call logs is one that is.</p>
<p>Some of these permissions, I haven&rsquo;t actually launched the app and gone through the setup yet, but you will be prompted to allow these when you initially launch the app to sign in. I have not yet, so everything is denied.</p>
<p>The second one down is camera. There&rsquo;s a couple settings when it comes to camera and microphone as you&rsquo;ll see. There&rsquo;s allow while using the app and ask me every time or don&rsquo;t allow. When it comes to something where you&rsquo;re going to be video chatting regularly, like in Signal, I&rsquo;ll leave that set to allow only while using the app instead of ask every time. So that&rsquo;s the camera permission.</p>
<p>Closely tied to this, I&rsquo;m just going to show you microphone for now. Again, same options for this.</p>
<p>Now this is where we&rsquo;re going to get into some troubleshooting. Let&rsquo;s say that you denied the microphone permission and a couple days later you go inside of WhatsApp to make a phone call. You launch the app. You start making a phone call. The person on the other side cannot hear you.</p>
<p>First thing you should check is the global microphone toggle enabled or disabled or global permission. In this case, in the swipe down menu, it&rsquo;s disabled. So I would enable that. You also get a prompt on Android if it&rsquo;s disabled. But again, just going through some troubleshooting steps.</p>
<p>So the person can&rsquo;t hear you. You enable this. They still can&rsquo;t hear you at that point. The overall phone permission is allowed. Next, you would check the actual app permission for microphone. You would go in there, permission, microphone, set to don&rsquo;t allow, set it to whichever one you want. The person can now hear you. There you go.</p>
<p>So next we have contacts and accounts, and some of the options you&rsquo;ll see here are a little different compared to stock Android OS, although I believe Android 17 will be adding this option, but the current Android version does not have this.</p>
<p>So for contacts, you have don&rsquo;t allow and allow. WhatsApp, I believe, requires you to allow access to your contacts. If I was to use WhatsApp, I wouldn&rsquo;t want to give it my entire address book. That&rsquo;s where contact scopes come in.</p>
<p>Now what contact scopes do is they make the app think that it has full access to your contacts, but really you&rsquo;re giving them a scoped version, thus the name. And in this case, you can do it by label, contact, number, email.</p>
<p>For the example, I&rsquo;ll just do it by contact. So in these fake contacts, let&rsquo;s assume that my friends Alex and Alex Wells both have WhatsApp and I want to talk with them. I would only select those contacts. Tap select. We could see the contacts that are allowed. Now when WhatsApp goes to read my contacts, it can only see those two contacts versus my entire contacts list.</p>
<p>Contact scopes are a great way to minimize the amount of data that an app can get, especially if it&rsquo;s not privacy friendly. I&rsquo;m a realist when it comes to privacy and security. I understand people have friends and family on WhatsApp or maybe they need to use it for work. If that&rsquo;s you, don&rsquo;t be afraid to use WhatsApp on Graphene OS. Just be aware of the added privacy features that are available and make sure to use them.</p>
<p>It&rsquo;s also worth mentioning that with contact scopes, let&rsquo;s say you met someone and you added them to your phone contacts and you now want to message them on WhatsApp, you will have to manually add them to the scoped contacts.</p>
<p>So again, you&rsquo;d go into the app settings, contacts and accounts, contact scopes. Let&rsquo;s say you met Cameron and you want to add them. Check the box, select. Now that contact will be accessible to WhatsApp.</p>
<p>So that&rsquo;s contact scopes. That&rsquo;s the contact permission.</p>
<p>The next one we have location. Location is GPS, things like that. There&rsquo;s a couple options. I like to use ask every time. I don&rsquo;t want to give an app permission to use it right when I open it. But again, it&rsquo;s up to you.</p>
<p>Music and audio. I believe by default, if you do allow, that gives it access to the music folder on Android. But music and audio is similar to contacts where you have storage scopes. Different from contact scopes. This is in regards to storage. So you can enable that. You can give it access to nothing by default. Or you can add a folder, file, things like that.</p>
<p>The next one is nearby devices. This one I usually leave off. Unless you&rsquo;re pairing some headphones or a speaker or a smart camera something like that then you likely need to turn this on. Nearby Devices uses Bluetooth Low Energy and I think there&rsquo;s some other things it uses but can&rsquo;t recall right now. So if you allow that that gives the app access to that but typically you don&rsquo;t need this.</p>
<p>The next one is Network. This is another permission that Graphene OS exposes. This is a popular one where people have issues so let&rsquo;s get back to the troubleshooting.</p>
<p>So let&rsquo;s say you just installed an app you likely saw this box pop up where you could uncheck the allow network permission. If you uncheck it you&rsquo;ll see something like this where allowed no network under not allowed is network. I found that some people think that just disabling network makes the app more secure but what that means is if you don&rsquo;t allow network then the app has no network access so it can&rsquo;t connect to the internet can&rsquo;t sign into accounts.</p>
<p>Now what that looks like is let&rsquo;s open WhatsApp. Agree and continue. We now have an alert. A cellular data network is required to activate WhatsApp Messenger.</p>
<p>If I was now troubleshooting this, I&rsquo;m wondering what was going on. First thing I would check is my network connection working. So what does that look like? Open your browser, pick a website to go to. If the page loads, that means your internet is working on your device and you can access external resources.</p>
<p>So next thing to me is, okay, good network connection. Let&rsquo;s see what the app permissions look like. Again, long press, app info, permissions. If we look here, as we expected, network is disabled. Change that to allow. Let&rsquo;s go open WhatsApp again. Agree and continue. And now the app proceeds to load because it can now access the network.</p>
<p>So again, these might seem like basic things, but understanding what&rsquo;s going on underneath is extremely helpful, especially if you encounter issues. If you&rsquo;re on iOS, you don&rsquo;t have any control over a lot of this, which is. things just work. You also don&rsquo;t have a private device, but that&rsquo;s another story.</p>
<p>So back to permissions. The next one is the phone permission. And from what I recall, this allows the app to see your phone number. It allows to see if you have a cellular connection, the SIM installed, I think, as well. That&rsquo;s what the phone permission requires or allows.</p>
<p>Once you sign into WhatsApp or other apps that request this or require it, they will prompt for that permission. But this is, again, just going through it before the initial signup.</p>
<p>We have photos and videos. This is photos and videos on your device. If you change it to always allow all, that&rsquo;ll allow all access to photos and videos on your device. There&rsquo;s allow limited access. And with that, you can select the exact photos that you want to allow or the select the exact albums you want. Or there&rsquo;s also the don&rsquo;t allow plus storage scopes. And again, that gives you access to add a folder, file, images.</p>
<p>And the last one is SMS. Again this one&rsquo;s pretty straightforward this gives the app access to your sms messages on your phone and the main reason whatsapp requests this permission is that when you sign up for an account they send you a text message this allows whatsapp to directly read your messages and verify that the verification code is correct it also means they can read all your messages so take that with a grain of salt.</p>
<p>That&rsquo;s the main permissions. These only show up because the app it&rsquo;s bundled and i believe the manifest for the app where it&rsquo;s going to request these permissions. If there&rsquo;s an app that&rsquo;s a little more privacy friendly let&rsquo;s pick the calendar app if you look for the permissions that one has or can request you can see it&rsquo;s much smaller.</p>
<p>We have calendar access for obvious reasons notification sensors again that&rsquo;s just one by default and not allowed as contacts and accounts besides that we don&rsquo;t see any other ones so if you don&rsquo;t see a bunch of permissions listed for an app that&rsquo;s because that app did not require those or did not list those in the app&rsquo;s manifest.</p>
<p>I know we&rsquo;re getting into the weeds a little bit at this point, but just pointing that out. And if you really want to get into the weeds for the permissions an app has, you can click on the three dots, select all permissions, and you can see the exact things it&rsquo;s getting when you allowed certain things.</p>
<p>So in this case with contacts and accounts, it can modify your contacts. It can find accounts on the device and read your contacts. You can also tap things in here to get more information. I&rsquo;d say go here if you&rsquo;re curious, but you likely don&rsquo;t need to come here regularly or at all.</p>
<p>That&rsquo;s all I got for today. I just want to say don&rsquo;t be afraid to tinker, experiment, learn more, troubleshoot. Even if things go horribly wrong, you can always uninstall the app and start over again. And regardless, you&rsquo;ll still learn something.</p>
<p>On this channel, I don&rsquo;t take any sort of sponsorship, but I do have a paid membership that comes with a monthly Q&amp;A along with bonus videos and early access to YouTube videos. So if you want to support me and what I create, you can find out more at membership.com. members.sideofburritos.com.</p>
<p>Thanks again for being here, and I&rsquo;ll see you next time.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>How Android Is Becoming More Restricted</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-android-is-becoming-more-restricted/" />
        <id>https://staging.sideofburritos.com/blog/how-android-is-becoming-more-restricted/</id>
        <published>2026-03-26T13:55:00Z</published>
        <updated>2026-03-26T13:55:00Z</updated>
        <summary type="html">The GrapheneOS foundation has officially announced its partnership with Motorola.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode73s0hbhb">🎥 


<a href="https://youtu.be/fSUW3y4v_w4" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://arstechnica.com/gadgets/2026/03/google-details-new-24-hour-process-to-sideload-unverified-android-apps/" target="_blank" rel="noopener" class="text-break">https://arstechnica.com/gadgets/2026/03/google-details-new-24-hour-process-to-sideload-unverified-android-apps/</a> - Ars Technica Article</li>
<li>


<a href="https://android-developers.googleblog.com/2026/03/android-developer-verification.html" target="_blank" rel="noopener" class="text-break">https://android-developers.googleblog.com/2026/03/android-developer-verification.html</a> - Android Developers Blog Post</li>
<li>


<a href="https://grapheneos.social/@GrapheneOS/116261301913660830" target="_blank" rel="noopener" class="text-break">https://grapheneos.social/@GrapheneOS/116261301913660830</a> - GrapheneOS Mastodon Post</li>
<li>


<a href="https://blog.knowbe4.com/ftc-states-that-scams-cost-u.s.-consumers-158.3b-in-one-year" target="_blank" rel="noopener" class="text-break">https://blog.knowbe4.com/ftc-states-that-scams-cost-u.s.-consumers-158.3b-in-one-year</a> - FTC Article</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">📝 Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Google has been working with the community to make your device security more robust while still being respectful of platform freedom.</p>
<p>That is not my opinion. I am loosely paraphrasing a post on the Android Developers Blog about Android developer verification. But instead of referencing a post clearly written by a marketing team, let’s look at an Ars Technica article talking about this.</p>
<p>Google details a new 24-hour process to sideload unverified Android apps.</p>
<p>Now, I really don’t like this word. I understand why it came about a couple of decades ago, but “sideloading” is just installing an app on your device. Big tech has been using it to demonize installing applications outside official app stores.</p>
<p>If you install an app outside of the Google Play Store on Android, that is called sideloading. If you install an EXE downloaded from the internet on a Windows machine outside of the Microsoft Store, that is also sideloading.</p>
<p>I could keep ranting about this, but I won’t. Just know this: if you sideload an app, you installed an app. Stop using the word “sideload.” It is doing more harm than good.</p>
<p>But Google uses that term, so we will use it here.</p>
<p>With these new limits, Android phones will only install apps from verified developers. To become verified, developers releasing apps outside Google Play will need to provide identification such as a passport or driver’s license, upload signing keys, and pay a 25 dollar fee.</p>
<p>Apps from unverified developers will not be installable unless you go through a new advanced workflow buried in developer settings.</p>
<p>Right now, Android phones alert users about enabling unknown sources and guide them through it. The new process is different and will not be obvious. You have to know where it is and enable it yourself, and it is not quick.</p>
<p>Here is how it works.</p>
<p>First, you must confirm that no one is instructing you. This is meant to prevent scammers from coaching victims.</p>
<p>Next, you must restart your phone and re-authenticate. This is supposed to cut off remote access or active scam calls.</p>
<p>Then you have to wait 24 hours. This delay is intended to break the sense of urgency scammers rely on.</p>
<p>After the wait, you return and verify again.</p>
<p>Finally, you can enable installation of unverified apps. You can choose to allow it temporarily for seven days or indefinitely, although the indefinite option is marked as not recommended.</p>
<p>Once you complete all of this, you can install apps again.</p>
<p>This entire process is difficult to describe without using harsh language. There are several dark patterns here. It is buried in settings, requires a long delay, and discourages enabling it permanently.</p>
<p>It is easy to imagine a future where the indefinite option is removed and the wait time increases.</p>
<p>Yes, users need protection. In 2023, Americans lost over 150 billion dollars to online scams, according to the FTC.</p>
<p>But a 25 dollar fee and ID verification will not stop scammers. If that much money is involved, they will find ways around it. They can buy verified accounts, purchase existing apps, or publish under someone else’s identity.</p>
<p>This is not about protecting users. This is about control. It is about deciding what you can install on your own device and where it can come from.</p>
<p>GrapheneOS recently stated that their system will remain available worldwide without requiring personal identification or accounts. They also said that if their devices cannot be sold in certain regions due to regulations, so be it.</p>
<p>This relates to upcoming rules like operating system age restrictions in places like California.</p>
<p>Some people asked for my thoughts. I do not have much to add. It is terrible.</p>
<p>This will affect what users can install and may also hurt independent developers. If you are building apps for the community, are you going to pay a fee and identify yourself, or stop developing entirely?</p>
<p>That is all for today. The future looks bleak with these changes, but there are still alternatives. You just have to be willing to accept a little discomfort.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>How GrapheneOS Releases Work - Everything You Need to Know</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-grapheneos-releases-work/" />
        <id>https://staging.sideofburritos.com/blog/how-grapheneos-releases-work/</id>
        <published>2024-12-09T10:00:00Z</published>
        <updated>2024-12-09T10:00:00Z</updated>
        <summary type="html">Have you ever wondered why your device doesn’t immediately get the latest GrapheneOS update after it’s announced? In this video, I break down how GrapheneOS releases work, including the Alpha, Beta, and Stable channels, and why updates are rolled out in stages. I’ll show you where to find the release details on GrapheneOS.org, explain how version numbers are structured, and talk about why you might want to use the Beta or Alpha channel to help with testing.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode74s0hbhb">🎥 


<a href="https://youtu.be/u0UDuNlrofU" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://discuss.grapheneos.org/d/17450-grapheneos-version-2024111700-released/5" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/17450-grapheneos-version-2024111700-released/5
</a> - GrapheneOS forum post</li>
<li>


<a href="https://grapheneos.org/releases" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/releases
</a> - GrapheneOS Releases page</li>
<li>


<a href="https://grapheneos.org/contact#community" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/contact#community
</a> - GrapheneOS Matrix Rooms</li>
<li>


<a href="https://newsletter.sideofburritos.com/archive/dea0e525-67ea-400b-a0c4-f140b51410e6" target="_blank" rel="noopener" class="text-break">https://newsletter.sideofburritos.com/archive/dea0e525-67ea-400b-a0c4-f140b51410e6
</a> - My RSS Newsletter post</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So whenever there&rsquo;s a new forum post about a new GrapheneOS version, there always seems to be some confusion as to why someone&rsquo;s device has not received the new update yet. When they run a manual update check, it says their system is up to date, even though there should be a new version available. So today, I want to talk about how releases work and why you do not receive them as soon as they are announced.</p>
<p>If we check out the section about the releases on GrapheneOS.org, which I will link down below, we can see here in the last paragraph: releases are tested by the developers and are then pushed out via the Alpha channel. The release is then pushed out via the Beta channel shortly afterwards. Finally, the release is pushed out via the Stable channel after being tested by some of the users in the Beta channel. In some cases, problems are caught in the Beta channel testing, and a new release is made via the Beta channel to replace the aborted one.</p>
<p>So now let&rsquo;s talk about what this actually means. First thing, I want to take a look at my device here. If we go into Settings, System, and we go to System Updates, and if we take a look at Release Channel under Settings, we can see here this corresponds to exactly what I just read: there&rsquo;s the Stable, Beta, and Alpha. So when there&rsquo;s a new forum post, like I showed earlier, that means that a new release was pushed to the Alpha channel, which is why, if you&rsquo;re on the Stable channel, you don&rsquo;t get it. If you&rsquo;re on Beta, again, you won&rsquo;t get it because it&rsquo;s still in the Alpha channel. But then, as stated here, after the testing is done in Alpha and Beta, it then goes to Stable, and your phone now gets it.</p>
<p>So then, if we scroll down to the Devices section, we can see some more details on what I was talking about. I don&rsquo;t think many people look at this often, but I think it&rsquo;s useful to know where the information is, so if you need to do some troubleshooting or you need to find the answer for yourself. So if we take a look here at the Pixel 9 Fold, we can see again the three channels. We can see the version that&rsquo;s in each channel, and then we just have some ways to download it over here. But back to the version—so again, let&rsquo;s say there was a new version, you&rsquo;d first see it in Alpha, Beta, and Stable.</p>
<p>So speaking of versions, I just wanted to quickly cover how version numbers are created. So, as an example, if we go down to this version number, it&rsquo;s the four-digit year followed by a two-digit month, then a two-digit day. Then, for the first release of that single day, it&rsquo;ll be 00. We can see that on October 17th, 2024, there was another release done on that day, which is why it ends in 01. Under each individual release, you can also see what changes were made. So I like to read this whenever a new release comes out to see what changes I can expect. It&rsquo;s helpful if there was a bug you were experiencing, and you can now see that it was fixed or something like that, or a new security feature.</p>
<p>So you might be asking yourself: why would you want to use the Beta or Alpha channel? Maybe you want to help out with testing, which I know the team could always use more people to help test. So if you switch to Beta or Alpha, it&rsquo;d be helpful to go on the forum, and then, once these releases are posted, if you experience any issues, post them there. You can also join the Matrix rooms, where they have dedicated channels for that testing. Again, you can post there. It&rsquo;s usually most needed when there&rsquo;s a new major Android release version. So from Android 14 to Android 15, there&rsquo;s always a lot of changes, always a lot of things that need to be tested.</p>
<p>So there&rsquo;s a couple more things I want to mention about channels. Typically, with a product, either software or something in the physical world, you might say, &ldquo;This is the Alpha release&rdquo; or &ldquo;the Beta release,&rdquo; and typically, what that means is it&rsquo;s not production-ready yet. That is not the case with these releases. So when a build makes it to the Alpha channel, if there&rsquo;s no problems found, that same exact build goes to the Beta channel. And again, if there&rsquo;s no issues found, that same exact build goes to the Stable channel. There&rsquo;s no separate build that is built. Everything is technically production-ready, and that exact same build goes through all three steps. So if you are using the Beta channel, don&rsquo;t think you&rsquo;re using a Beta version of GrapheneOS. Yes, the build is in the Beta channel, but if there&rsquo;s no issues found, again, that&rsquo;ll get pushed to Stable, and it&rsquo;ll be the exact same version that you&rsquo;re using in Beta.</p>
<p>I know that was a lot of information, so if you ever need a break, you can check out my new podcast, which is called In the Shell. It&rsquo;s stories of malware, hackers, and the people who shape tech. And if you want to find out where you can listen, you can head on over to intheshellpodcast.com.</p>
<p>So the last thing I want to mention is that it can be kind of a pain to have to come here and read the release announcements. It can be annoying to have to come check this web page. Thankfully, they offer an Atom feed. So if you use an RSS reader, you can subscribe to this URL in there, and you can easily track the feeds. If you&rsquo;ve never used an RSS reader before, I talked about how I use one and the brief history of them in my latest email newsletter, which you can sign up for at sideofburritos.com.</p>
]]></content>
      </entry>
      <entry>
        <title>I Tried to Brick My GrapheneOS Installation (So You Don’t Have To)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/bricked-grapheneos-install/" />
        <id>https://staging.sideofburritos.com/blog/bricked-grapheneos-install/</id>
        <published>2024-11-25T10:00:00Z</published>
        <updated>2024-11-25T10:00:00Z</updated>
        <summary type="html">Are you afraid of bricking your device while installing GrapheneOS? In this video, I put the installation process to the test—unplugging cables, refreshing the page, turning off the internet, and more—to see just how resilient the process is. Spoiler alert: it&amp;#39;s nearly impossible to brick your device.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode41s0hbhb">🎥 


<a href="https://youtu.be/ik0AiO0WtuU" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://grapheneos.org/install/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/install/</a> - GrapheneOS web installer</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So, without fail, every couple of weeks I either see an email, a forum post, or a comment on a YouTube video where someone says they want to try GrapheneOS but they&rsquo;re afraid they&rsquo;re going to brick their device. The general consensus is that with the web installer, it&rsquo;s nearly impossible to brick your device. But instead of just saying that, I wanted to make a video showing that things can go terribly wrong—and you still will not brick your device.</p>
<p>Here we have a Pixel 7 running stock Android OS. This isn&rsquo;t going to be an instructional video, so I&rsquo;m going to fast-forward through a lot of parts. The first step to install GrapheneOS is to put the phone into Fastboot mode. So, let&rsquo;s restart it. Just ignore the pop-up on the screen—I&rsquo;m running macOS, and that&rsquo;s part of the OS.</p>
<p>Step 1: Unlock the Bootloader</p>
<p>Even if you unplug your device right now, everything is still happening on the device. The actual unlocking of the bootloader doesn&rsquo;t require the computer to stay connected. So, let&rsquo;s unlock the bootloader. Again, these are things you should not be doing—I’m just showing you that they still work.</p>
<p>Once the bootloader is unlocked, it&rsquo;s worth mentioning that all existing data on your device will be erased. This happens regardless of how the rest of the installation goes. Once you unlock the bootloader, all your data is gone. Now, let’s move on to the second step.</p>
<p>Step 2: Download the Release</p>
<p>I’ve already downloaded the release earlier, so it&rsquo;s cached in my browser. Again, this step happens in the browser, not on the device yet. Now, we’re at the part where we flash the release to the device.</p>
<p>Let’s flash it. And just for demonstration, let’s unplug the device during this process. Why not? The device is restarting, the computer has lost connection with it, and we’re back to the Fastboot interface. I’ll plug the device back in, and our browser picks it up again, resuming the process. Now it’s writing some files to the device.</p>
<p>Let’s unplug it again. We see an error in the browser—no big deal. Let’s restart the phone and see where we’re at. It’s just a warning that our bootloader is unlocked.</p>
<p>Testing the Worst-Case Scenario</p>
<p>While that’s loading, let me quickly mention my new podcast, In the Shell. I launched it two months ago, and it’s about hackers, malware, and the people shaping tech. If you’d like to check it out, head over to InTheShellPodcast.com.</p>
<p>Now back to the phone. At this point, it’s not booting—it’s stuck on the Google splash screen. This is likely the worst-case scenario you’ll encounter, but it’s easily fixed with a forced reboot. Hold the power button and the volume-up button for about 15 seconds, and then hold the volume-down button to boot into Fastboot mode. Now we’re back in Fastboot mode. Let’s plug the phone back in and continue the installation.</p>
<p>Back on the screen, I’ll click Flash Release again. The phone is still connected, so it’s continuing the process. So far, our phone is not bricked.</p>
<p>What Happens if You Lose Internet?</p>
<p>Another concern people have is losing internet during installation. Let me turn off my laptop’s Wi-Fi. As we can see, the internet is gone, but the installation is still continuing. This is because the installation doesn’t require an active internet connection once you’ve downloaded the factory image. You’re fine to proceed without the internet.</p>
<p>Now, let’s unplug the device again. There’s an error, so let’s restart the device and see where we’re at. At this point, we have a different screen. It says, “Your device is corrupt. It can’t be trusted and may not work properly.” Again, this is another worst-case scenario.</p>
<p>To fix this, press the power button to continue past the bootloader warning. As we saw before, it’s stuck on the Google splash screen. Let’s do another forced reboot—power button and volume-up button—and hold the volume-down button to go back into Fastboot mode. Here we are, back in Fastboot mode. Let’s plug in the USB cable again and click Flash Release. The phone is detected again, and the process starts over.</p>
<p>Refreshing the Page During Installation</p>
<p>Now let’s test what happens if you refresh the page during installation. I’ll refresh, and as expected, it seems like everything is messed up. But this could happen to you, so let’s fix it. Press Flash Release again. It doesn’t seem to find the phone, so let’s unplug it and plug it back in. That reset the connection, and now it’s continuing the process.</p>
<p>Finishing the Installation</p>
<p>This time, I let the flash complete. Let’s move to the next step: locking the bootloader. That’s done. The bootloader is locked, so let’s restart the device.</p>
<p>We now have the GrapheneOS welcome screen. The installation was successful—even after unplugging the USB cable, doing hard reboots, refreshing the web page, and turning off the internet. We were still able to install GrapheneOS without bricking the device.</p>
<p>Conclusion</p>
<p>As long as you can do some basic troubleshooting—like unplugging and plugging back in the USB cable if the connection doesn’t work or doing a forced reboot with the power and volume-up buttons—you’ll have no problem installing GrapheneOS using the web installer. You will not brick your device.</p>
<p>If you have any questions or comments, feel free to leave them below. See you next time!</p>
]]></content>
      </entry>
      <entry>
        <title>How to use AppVerifier</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-use-appverifier/" />
        <id>https://staging.sideofburritos.com/blog/how-to-use-appverifier/</id>
        <published>2024-11-11T10:00:00Z</published>
        <updated>2024-11-11T10:00:00Z</updated>
        <summary type="html">We’re diving into a tool for Android users who download APKs from outside traditional app stores: App Verifier. This app adds an extra layer of security by verifying APKs you download from other sources, whether it’s from repositories, Obtainium, or direct from the developer’s website.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode92s0hbhb">🎥 


<a href="https://youtu.be/IkrujqcM-9Y" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://github.com/soupslurpr/AppVerifier?tab=readme-ov-file" target="_blank" rel="noopener" class="text-break">https://github.com/soupslurpr/AppVerifier?tab=readme-ov-file</a> - AppVerifier GitHub Repository</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So the app we&rsquo;re going to be talking about today is called App Verifier. It&rsquo;s useful if you download APKs without an app store and install them on your device, or if you use something like Obtainium to obtain apps directly from repositories or different sources. App Verifier adds one more layer of verification to the APKs that you download.</p>
<p>This is the official repository for App Verifier. If we check the description here, we can see that App Verifier takes the app&rsquo;s package name and the signing certificate&rsquo;s hashes and compares them to the ones you provided or the ones in the internal database to verify that your apps are genuine.</p>
<p>While that description might be a little confusing, let&rsquo;s walk through a demonstration of how to use it. The first step in order to use it is to install it. We can see here on the GitHub repository that the recommended way to download it is to get it on Apt if you&rsquo;re on Graphene OS. If you don&rsquo;t have Apt installed yet, you can swipe up, go to the app store, and install Apt from there.</p>
<p>Once you do install Apt, open the app, scroll down to App Verifier, and install it. Now, once that&rsquo;s installed, we can go into the app. The first thing you’ll see is the privacy policy; give it a read over and then accept it. It basically states that there&rsquo;s no warranty and that it’s provided as is.</p>
<p>On the main screen, the first thing we have is an app list. This shows all the current apps you have installed under your user profile. In my case, I have Obtainium and Apt installed. We can see here that there are two green check marks next to the app. If you select the app, we can see that the Apt hash was verified using the internal database. You can select &ldquo;Success&rdquo; if you want to see details on how it was matched. This is a great way to verify the apps you currently have installed on your device.</p>
<p>The next option is to verify an APK file. If you have some APKs you downloaded, you can manually verify them there. The last option is settings, so feel free to give those a read over if you want.</p>
<p>The main way I think most people will use App Verifier is in conjunction with Obtainium. For this example, I’m going to install LocalSend. I’ll paste the repository here and select the APK. Once it’s ready, I’ll select install. It’s automatically shared with App Verifier, which is convenient.</p>
<p>We can see here that LocalSend was verified using the internal database. Success! You can then swipe back and go ahead and install your app as you normally would.</p>
<p>Another way you can use App Verifier is to manually verify APKs. For example, let’s say you want to download the Signal APK. I’ll download it from their site. Once it’s downloaded, we can go into the App Verifier app, select &ldquo;Verify APK,&rdquo; and find our download. When we select it again, you can see it was successfully verified using the internal database.</p>
<p>One more feature I want to show you is down here: you can verify from clipboard. In the case of Signal, they publish the hash for the APK on their site, which we can see here. We’ll just copy it, and if we go back to App Verifier and select &ldquo;Verify from Clipboard,&rdquo; paste it in there. We can see the verification status as success.</p>
<p>The reason that verifying from clipboard is useful is that not all apps are inside the internal database. For another example, let’s download the Standard Notes APK from their repository. Once that finishes, we’ll go to App Verifier, select &ldquo;Verify APK,&rdquo; and choose the new APK we downloaded. We can see that the internal database status is not found.</p>
<p>This highlights the crux of App Verifier: if the certificate hash for an app is not in the internal database, then you need to go around and find it. Unfortunately, most developers don’t publish it anywhere, so you really do need to look for it and hope you can find it.</p>
<p>In the best-case scenario, using App Verifier as an example, we can see here in the README that the developer does post the certificate hash. Additionally, they also post it in a third-party location, which is great. We can see that it can be found in a Blue Sky post. If we open that, we have the matching certificate hash.</p>
<p>The reason having it in a third-party location is beneficial is that, let’s say someone compromises the GitHub account for this app and uploads a new APK; they would also need to update the certificate hash. If they upload a malicious one, anyone trying to verify it would use the incorrect hash. Posting it in a third-party location means that two different accounts need to be compromised, which is much less likely than just compromising one account.</p>
<p>Getting back to the main reason for discussing this: unfortunately, there’s not much more you can do. You could ask the developer to publish it on the repository or on one of their social media accounts for verification. Another option is to download it from a trusted source. For example, I could download Standard Notes from Google Play in a separate user profile, install App Verifier, check the certificate hash here, and then compare it on my other user profile with the app downloaded from GitHub.</p>
<p>Honestly, that’s a lot to do. Personally, I don’t do that; I just trust the APK I download from GitHub. It’s not the best practice, but it’s not perfect.</p>
<p>If we check the contribution guide, we see that contributions of new apps to the internal verification info database won’t be accepted at this time. Hopefully, that changes in the future, and maybe the developer builds some system for submissions or some way to verify better. But until then, if it’s not found in the internal database, you just need to hope the developer of App Verifier adds it.</p>
<p>With all that being said, I still think this is a great app and it has a lot of potential. So check it out and see if it fits into your workflow. If you have any other questions or comments, feel free to leave those down below, and I will see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>5 New-ish Things on Android 15 (GrapheneOS)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/android15-whats-new/" />
        <id>https://staging.sideofburritos.com/blog/android15-whats-new/</id>
        <published>2024-10-28T10:00:00Z</published>
        <updated>2024-10-28T10:00:00Z</updated>
        <summary type="html">Android 15 has just rolled out on GrapheneOS, bringing a few visual updates and some subtle new features. In this video, I’ll cover some of the changes you’ll notice, like the redesigned password authentication popup, adjustments to the volume slider, and Bluetooth scheduling options.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode18s0hbhb">🎥 


<a href="https://youtu.be/Ehf3ql8wW-o" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://discuss.grapheneos.org/d/16670-private-space-on-android-15-grapheneos" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/16670-private-space-on-android-15-grapheneos</a> - GrapheneOS Private Space forum post</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Android 15 has recently reached the stable release channel on GrapheneOS, so if you’re watching this video, you likely have it installed on your device. In this video, I want to cover a few visual changes I noticed along with a couple of new features. If you’ve found something new, feel free to share it in the comments below!</p>
<p>The first change is the password authentication popup. When opening an incognito tab in Vanadium, you won’t see it due to screen recording limitations, but the old popup was shorter and boxier, while the new one is taller with curved edges. Not a huge change, but personally, I preferred the shorter style. Now, let’s switch back to the regular tab.</p>
<p>Next up is a convenient product placement! My new podcast, In the Shell, launched a few months ago. It’s all about hackers, malware, and the tech shaping our world. Season 1 dives into the infamous worms that have flooded the internet over the past decades. You can check it out at intheshellpodcast.com.</p>
<p>Another visual change is in the volume slider. Hitting the three dots at the bottom reveals more rounded visuals, giving your phone a more “curvaceous” look. Functionally, not much has changed; you can still select the audio output device, but everything else remains the same.</p>
<p>Now, let’s talk about tiles at the top. If you go to Bluetooth, there’s a new option to automatically turn it on tomorrow. This feature might be geared toward the “Find My Device” functionality. It’s handy if you want to disable Bluetooth today but don’t want to forget to turn it on tomorrow. I think this mirrors a similar feature in iOS, though I personally don’t use it.</p>
<p>A feature I recently discovered is split-screen functionality on phones, which also works on Android 14 and Android 15. To use it, open the first app, swipe up, tap the app icon, and choose “Split screen.” Then, select the second app—let’s use Vanadium—and adjust the screen space each app takes. In Android 15, if you swipe up and tap both icons, you’ll now see a ‘Save app pair’ option, letting you create a shortcut to open both apps together. I’ve used split-screen for copying passwords from my password manager to a browser.</p>
<p>Next is app archiving. If you long-press on an app and go to “App Info,” there’s an archive option. If you don’t have the Play Store in the user profile, the option is grayed out. This feature replaces the app APK with a smaller archived version while preserving user data, freeing up space without deleting your data. Personally, I don’t see a need for it, as my storage usage is low.</p>
<p>Lastly, there’s the Private Space feature, which many are excited about. However, it’s only available in the owner profile. Here’s a quick overview—I’ll do a full video on it soon. To set it up, go to Settings &gt; Security and Privacy &gt; Private Space, enter your PIN, and set up a separate lock if you like. Private Space creates an isolated workspace for apps and data with its own VPN settings and encryption. This can be useful if you want separate environments, like using Orbot in the owner profile and Mullvad in Private Space. I recommend using Private Space over work profiles for better integration and isolation.</p>
<p>That wraps up this overview. I’ll be back with a more in-depth look at Private Space soon, but if you have questions or comments, feel free to leave them below. Thanks for watching!</p>
]]></content>
      </entry>
      <entry>
        <title>Best Way to Transfer Files Between Devices (Mobile, Laptop, Tablet) - Linux, Windows, macOS, iOS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/best-way-to-transfer-files-between-devices/" />
        <id>https://staging.sideofburritos.com/blog/best-way-to-transfer-files-between-devices/</id>
        <published>2024-09-30T10:00:00Z</published>
        <updated>2024-09-30T10:00:00Z</updated>
        <summary type="html">We’ll explore an open-source app called LocalSend, which allows file transfers over a local Wi-Fi network without needing the internet. Whether you’re moving files between an Android, iPhone, or different operating systems like macOS or Windows, this app simplifies the process. No need for USB cables, sketchy third-party sites, or the cloud. LocalSend makes it easy to share files, folders, or even apps securely.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode35s0hbhb">🎥 


<a href="https://youtu.be/dxRXiL3oI6Q" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://localsend.org" target="_blank" rel="noopener" class="text-break">https://localsend.org</a> - LocalSend Website</li>
<li>


<a href="https://github.com/localsend/protocol" target="_blank" rel="noopener" class="text-break">https://github.com/localsend/protocol</a> - LocalSend Protocol</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>We you ever sitting there, wondering: how do I get these files from my phone to my computer, and vice versa? You could use a USB drive or cable to plug it directly into your computer, or you could use some sketchy third-party website to temporarily upload the file—but that’s all pretty inconvenient. What if you want to transfer something between an iPhone and an Android phone or between two Android devices? What do you do then?</p>
<p>If you have an iPhone and the other person has an iPhone, you can use something like AirDrop to transfer files. But if you want to transfer files to a computer, you need to make sure it&rsquo;s a Mac; otherwise, AirDrop doesn&rsquo;t work. That’s pretty inconvenient too. And you know what? Sometimes, there are just some files you don’t want to put in the cloud. That’s where LocalSend comes in.</p>
<p>LocalSend is an open-source, cross-platform local network transfer app. No internet connection is required, except to download the app. For this demo, I’ll be using my desktop computer along with my Android device running GrapheneOS.</p>
<p>Step 1: Download and Install
On the desktop computer, head over to LocalSend.org, click download, and select the appropriate installer for your platform. I’m on macOS, so I downloaded the DMG. Once installed, you can open the app. The interface is super clean—I&rsquo;m a big fan of nice interfaces!</p>
<p>On the other device, which in my case is my Android phone, go to LocalSend.org again. For Android, you can get it from Google Play, F-Droid, or download the APK directly. Use whatever method you prefer to install apps. For iOS, it’s on the App Store. LocalSend is available on Linux, Windows, macOS, and Android—pretty much all platforms.</p>
<p>Step 2: Setup and Transfer
Once installed, open LocalSend on both devices. On my phone, the default screen shows a friendly, randomly generated device name. In my case, my phone is named &ldquo;Patient Coconut,&rdquo; and my desktop is &ldquo;Fantastic Tomato.&rdquo; It&rsquo;s fun how they name the devices like that.</p>
<p>For transferring files, on my Android device, I&rsquo;m going to be receiving files, so I&rsquo;m on the &ldquo;Receive&rdquo; tab. From the desktop, I&rsquo;m going to be sending files. I go to the &ldquo;Send&rdquo; tab, where &ldquo;Patient Coconut&rdquo; appears, matching my Android device.</p>
<p>I have some test files here. The first one is an image, which is the cover art for my new podcast. If you want to check that out, head over to InTheHellPodcast.com. Dragging the file to the &ldquo;Send&rdquo; section, it shows a preview: one image, file size 2.5 MB. I select the receiving device (Patient Coconut), and now on my phone, it shows that &ldquo;Fantastic Tomato&rdquo; wants to send a file. I can either accept or decline. I accept, and boom—the file is transferred!</p>
<p>If we check the gallery, we can see the file is there. It’s really that simple.</p>
<p>Other Features
LocalSend also allows you to easily send folders. If you’ve ever used Signal to send files to yourself, you’ll know you can’t send folders unless you zip them. With LocalSend, it&rsquo;s as simple as dragging the folder. I tested this with a folder containing four images. Just drag, select the receiving device, and accept. The transfer is done, and when I check my files, there’s the folder with all four images inside.</p>
<p>Another cool feature is the ability to send text to yourself. There have been times when I needed to send a URL to my phone while setting up a new device. Instead of emailing it to myself, you can just copy the text, go to the &ldquo;Text&rdquo; option in LocalSend, paste it, select the device, and send it. You’ll get a notification saying &ldquo;Fantastic Tomato sent you a link,&rdquo; and you can copy or open it. It’s as easy as that.</p>
<p>For Android users, there’s also an app option where you can send APKs of your installed apps. This is super useful if you have another Android device without internet access and want to transfer apps.</p>
<p>Comparison to AirDrop
One feature I missed from my iPhone days was the ability to send multiple photos to someone using AirDrop. With LocalSend, it’s very similar. You can select photos, select the receiving device, and send them over. It’s seamless and well-integrated into the system.</p>
<p>One Caveat
The main caveat with LocalSend is that both devices need to be on the same Wi-Fi network to find each other and transfer files. If there’s no Wi-Fi around, a workaround is to create a hotspot on your device and let the other person connect to it. Once connected, you can launch LocalSend and start transferring files. It’s not as convenient as AirDrop, which uses Bluetooth and Wi-Fi, but it works.</p>
<p>How It Works
If you&rsquo;re curious about the technical side of LocalSend, the receiving device sets up a web server, and the sending device sends files to it. The files are transferred over HTTPS, so they’re encrypted during transit. It’s a really elegant and simple solution, especially when dealing with different platforms and devices.</p>
<p>If you have any questions or comments, feel free to leave them down below. I&rsquo;ll see you next time!</p>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS: After 3 Years, This Is How I Install Apps on My “De-Googled” Phone</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-how-i-install-apps/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-how-i-install-apps/</id>
        <published>2024-09-16T10:00:00Z</published>
        <updated>2024-09-19T10:00:00Z</updated>
        <summary type="html">I walk you through how I install apps on my Google Pixel running GrapheneOS after 3 years of testing and refining my setup. I demonstrate how to use multiple app sources, including the GrapheneOS App Store, Accrescent, Obtainium, and the Google Play Store, while maintaining privacy and security.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode64s0hbhb">🎥 


<a href="https://youtu.be/IAoCfrqxIEg" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS</li>
<li>


<a href="https://github.com/guardianproject/orbot/releases" target="_blank" rel="noopener" class="text-break">https://github.com/guardianproject/orbot/releases</a> - Orbot GitHub</li>
<li>


<a href="https://www.fakenamegenerator.com/" target="_blank" rel="noopener" class="text-break">https://www.fakenamegenerator.com/</a> - FakeNameGenerator.com</li>
<li>


<a href="https://www.smspool.net/" target="_blank" rel="noopener" class="text-break">https://www.smspool.net/</a> - SMSPool (Service I use to rent a number for Google Account SMS verification)</li>
</ul>
<p><a href="smspool_response.png">Response from SMSPool on what they do with used phone numbers</a></p>
<ul>
<li>


<a href="https://youtu.be/JiN37bn0OE8" target="_blank" rel="noopener" class="text-break">https://youtu.be/JiN37bn0OE8</a> - My video on Obtainium</li>
<li>


<a href="https://youtu.be/E3erRhXPPNY" target="_blank" rel="noopener" class="text-break">https://youtu.be/E3erRhXPPNY</a> - My video on how Apps work between User Profiles</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Before we begin, I want to make a quick disclaimer. If you&rsquo;re just starting out using GrapheneOS, I highly recommend not using the setup I&rsquo;m about to discuss in this video. This setup will create friction, and friction is the enemy of adapting to something new, especially if you&rsquo;re hesitant to begin with. When you install GrapheneOS, just install the Play Store, sign in, download apps as you normally would, and get used to things. You can always switch to a different setup later. For everyone else, here&rsquo;s how I install apps on my Google Pixel running GrapheneOS.</p>
<p>So, this idea was suggested to me around two years ago, but I finally set it up about one year ago. This isn’t something that was just shared with me recently and now I&rsquo;m sharing it—I’ve tested it, and it’s been working well for me. This also won’t be a step-by-step guide. I’ll demonstrate installing three different apps from three different sources and give you details of my setup. When I upgrade my device in the future (still TBD), I plan to make a step-by-step video.</p>
<p>Before we begin, I want to mention that I just published the second episode of my podcast, which is called In the Hell. If you want to find out how you can listen to it, head over to inthehellpodcast.com, which I’ll link below. It&rsquo;s also worth noting that it&rsquo;s hosted on Yellowball, the no-BS podcast hosting platform I recently launched, in case you’re looking to start your own podcast.</p>
<p>When you first install GrapheneOS, you have one user profile, the owner profile, which is there by default, and you cannot delete it. From there, you can create additional user profiles depending on how you want to separate your apps. In my setup, all apps are installed from the owner profile, and I use the &ldquo;Install Available Apps&rdquo; feature to push those apps to my daily user profile. I like this setup because it lets me install apps from the Google Play Store without actually having the Play Store installed on my daily user profile. It’s kind of like having a command center for app installations.</p>
<p>The recording on the screen right now is my owner profile. The first thing I did when I set this up was install Orbot, which is a free proxy that lets you send all your device traffic over the Tor network. That means that all of our traffic when accessing the Play Store will go over the Tor network, along with any downloads of system updates from GrapheneOS, since those are all done from the owner profile. You can install Orbot by downloading the APK from GitHub, which I’ll also link down below.</p>
<p>Once we open Orbot, we can click &ldquo;Start VPN&rdquo; and give it a minute to connect. Now we have a full-device VPN, which means all of our owner profile traffic is going over the Tor network. It’s important to note that VPNs are profile-specific, so while our owner profile traffic is using Orbot, any secondary user profiles (which we’ll discuss later) will not use Orbot by default—it’s only for the profile that it&rsquo;s installed on.</p>
<p>You might notice where it says &ldquo;Change Exit.&rdquo; I currently have it set to the United States, and the reason for that is that sometimes when you go into Google Play, it might say &ldquo;App not available&rdquo; if the exit node is in a different country. This is common with banking apps or social media apps. If you run into that issue, you can change the exit node to match your country and see if you can access the app.</p>
<p>One other quick tip about Orbot: if you switch networks (for example, from Wi-Fi to cellular) or the Wi-Fi disconnects, Orbot might say it’s connected, but it’s really not. You’ll notice that because your browser won’t be able to load anything. What I found helpful is to long-press on the Orbot app, select &ldquo;App Info,&rdquo; force stop it, then clear the cache (but don’t clear the storage). After that, restart Orbot, click &ldquo;Start VPN,&rdquo; and nine times out of ten, it fixes the issue.</p>
<p>Now, let’s talk about the first app store I use. The first store I search for apps is the default GrapheneOS app store. In this case, I installed Accrescent from here, which is actually the second app store I use. If an app isn’t available in the first store, I move on to the second. The GrapheneOS app store mostly has system apps, but Accrescent is available there, so I installed it from there.</p>
<p>The second app store I use is Accrescent. There aren’t a ton of apps here, but it’s actively developed, and they’re constantly adding new apps and working with developers to get more. I plan to make a video just about Accrescent in the future because they’re doing great work, especially from a security perspective. For this demonstration, I’ll be installing Xf Eraser. I just click &ldquo;Install,&rdquo; and it’s done.</p>
<p>The third app store I use is Obtainium. If you’ve never used it before, it can be confusing, but I have a video dedicated to it, which I’ll link below. I use Obtainium for all my open-source apps or any apps that publish APKs directly on their site or on GitHub. For this example, I’ll install NewPipe. I’ll copy the GitHub link, add the app to Obtainium, and let it download. Then I’ll install it.</p>
<p>With this owner profile setup, I always make sure to uncheck &ldquo;Allow Network Permission&rdquo; when installing apps because I don’t use these apps in the owner profile. If you forget to uncheck it, you can always change it later. Now we can see that NewPipe is installed.</p>
<p>So far, we’ve seen the GrapheneOS app store, Accrescent, and Obtainium. The last store I use is the Google Play Store, which I installed using the GrapheneOS app store. You’ll notice that there’s no &ldquo;Install&rdquo; button for Google Play Services because I already have it installed. The issue with the Play Store is that you need an account to access it, which sucks. Unlike Aurora Store, which lets you use anonymous accounts, I’m not a fan of shared anonymous accounts, so I prefer this setup.</p>
<p>Creating an anonymous Google account without getting it blocked or locked is somewhat difficult but not impossible. If you try to create it over a VPN or Tor, you’ll likely run into issues. What I do is drive to a parking lot with free Wi-Fi—like at a grocery store or coffee shop—connect with my laptop, and create the account using a fake name generator for the required information.</p>
<p>The tricky part is when they ask for a phone number for SMS verification. You don’t want to use your real number here because it would ruin the anonymity. Instead, you can temporarily rent a phone number just for receiving the SMS code. There are free services, but I wouldn’t recommend them because they’re public and often blocked. You’ll have to pay, but it’s usually 50 cents to a dollar. I’ll link the site I use in the blog post for this video, but I won’t mention it here on YouTube. Once you receive the SMS code, you can validate your account.</p>
<p>I’ve done this for about ten different Google accounts without any issues. The key is to practice compartmentalization—don’t use this account for anything else. Just use it for the Play Store. If you get a new device, create a new account rather than using the same one. It sounds like a hassle, but it’s how you keep things separate and private. And since Orbot is running, all of your Play Store traffic is going over the Tor network, which helps maintain your anonymity.</p>
<p>Some people might critique using a shared phone number for account validation. While there’s a small risk someone else could gain control of that number, from what I can tell, it’s only used for initial validation, and Google doesn’t tie it to your account. If you’re concerned, you could use a prepaid SIM instead, but personally, I think the risk is low.</p>
<p>At this point, you can now sign into the Play Store with an anonymous Google account and start installing apps. For this demo, I’ll install WhatsApp. You might notice slower downloads when using Tor, but that’s normal. After installation, I’ll uncheck &ldquo;Allow Network Permission&rdquo; like I did with NewPipe.</p>
<p>Now, to avoid accidentally using the apps in the owner profile, I’ll disable them. Long-press on the app, go to &ldquo;App Info,&rdquo; and click &ldquo;Disable.&rdquo; I’ll do this for NewPipe, WhatsApp, and Xf Eraser.</p>
<p>The next step is to use the &ldquo;Install Available Apps&rdquo; feature to push these apps to my secondary user profile. In the demo, I created a profile called &ldquo;YouTube Demo,&rdquo; but you can call it whatever you like. This is the profile you’ll use daily instead of the owner profile. Once you select the secondary user profile, you can go to &ldquo;Install Available Apps,&rdquo; check the apps you want to install, and they’ll be available in the secondary user.</p>
<p>To switch profiles, swipe down from the top of the screen, tap the user icon, and select the profile. Screen recordings don’t work across profiles, so I’ll be back in a moment.</p>
<p>Now we’re in the secondary user profile. If I swipe up, you’ll see the apps we installed—Xf Eraser, NewPipe, and WhatsApp—all from different sources.</p>
<p>So this is how I install apps on my device running GrapheneOS. If you have apps that require Play Store Services, you can install them in the secondary profile. In my setup, I only have Play Store Services running in a specific profile for calls, not in my daily profile.</p>
<p>The benefit of separating profiles like this is that you can end a session for a profile where Play Store Services are running. This essentially puts that profile to rest, so Play Store Services are no longer running in the background. You can’t do this with the owner profile unless you power off the device. This method allows you to shut down Play Store Services without turning off your device.</p>
<p>One more thing to note: there’s only one instance of an app installed on the device at a time, so when you update an app in the owner profile, it’s updated across all profiles. You don’t need to worry about updating it in each profile.</p>
<p>After recording this, I realized it’s a lot of information, and it might seem overwhelming. But once you set it up, it’s pretty much &ldquo;set it and forget it.&rdquo; When you need to install a new app, install it in the owner profile, disable it, use &ldquo;Install Available Apps&rdquo; for the secondary user, and you’re good to go.</p>
<p>If you have any questions or comments, feel free to leave them down below, and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS Tablet: 1 Year Update and All the Apps I Use</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-tablet-1-year-update/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-tablet-1-year-update/</id>
        <published>2024-09-02T10:00:00Z</published>
        <updated>2024-09-02T10:00:00Z</updated>
        <summary type="html">I&amp;#39;ve really enjoyed using the Google Pixel Tablet with GrapheneOS installed over the past year. In this video, I cover what I primarily use it for and all the apps I have installed on it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode69s0hbhb">🎥 


<a href="https://youtu.be/eJdSM60zFJQ" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So after a year, I figured it was finally time to put out an update on my Pixel Tablet experience running GrapheneOS. Spoiler alert: my original video had some high ambitions of replacing my laptop and taking this with me when I travel, along with a keyboard and things like that. None of that happened—it didn&rsquo;t work out. But if you&rsquo;re curious as to why, keep watching. If all you wanted was that quick answer, there you go, and I&rsquo;ll see you next time.</p>
<p>Before I get into the apps that I&rsquo;m using and things like that, I first want to talk about the physical aspects of the tablet that I really like. To begin, let&rsquo;s start with the case. This is the official case from Google, and if you end up buying the tablet after watching this video, or have bought the tablet, I highly suggest you buy this case. It&rsquo;s probably one of the best-designed cases I&rsquo;ve ever used—not that I&rsquo;ve used many cases, but to start off, it&rsquo;s a nice rubbery, grippy texture that helps with holding onto it. Besides that, you have this circle thing on the back—or oval, I should say—and that&rsquo;s great for a kickstand, holding it up in the landscape position. It also works in the portrait position, so it can lean back like that. When you&rsquo;re just kind of walking around or laying on your couch, it works great for holding it just like this.</p>
<p>You might be wondering why it&rsquo;s that shape. You see those four pins on the bottom? Those correspond to the dock. When this goes on the dock, the handhold—or whatever that metal thing is—helps align the dock so that it locks into those pins, giving you a good connection. It&rsquo;s all magnetic, so the dock just snaps on. This is the only way I charge it—I&rsquo;ve never actually plugged a USB cable into this, except for during installation. So, the case—I highly recommend it.</p>
<p>Now, back to the dock. The dock is included in the box. I&rsquo;m not going to say that the dock is free because, of course, I&rsquo;m sure that&rsquo;s baked into the price somewhere, but the dock has exceeded my expectations, mostly from an audio standpoint. When you set the tablet on the dock, this then turns into the main speaker; the internal speakers on the tablet are disabled, and the audio comes out of this. For listening to music or podcasts, things like that, you&rsquo;re not getting room-filling booming audio, but it is pretty impressive for the form factor. I like using this when I&rsquo;m listening to podcasts or audiobooks on the tablet. It just works really great for that.</p>
<p>Speaking of podcasts, I wanted to let you know that I just published the first episode of my podcast, which is called In the Shell. You can check that out at intheshellpodcast.com to find out where you can listen to it, and I will also leave a link down below in the description if you want to check it out.</p>
<p>So now, let&rsquo;s get back to the reason why you clicked on this video. One more thing to mention about the physical appearance: I don&rsquo;t use a screen protector on the tablet. They do make them for it; I just never found a need for one. It&rsquo;s not like a cell phone where I&rsquo;m carrying it around, constantly taking it out of my pocket—this wouldn&rsquo;t fit in my pocket. So, I didn&rsquo;t really see a need to have a screen protector. So far, after a year, it looks good—no chips, cracks, or scrapes. Hope I didn&rsquo;t jinx myself, but so far, so good.</p>
<p>On the actual tablet, I have two user profiles set up. I have my main owner/admin user profile that you can see here, and I have my daily &ldquo;Josh&rdquo; user profile. On my main owner profile, I have the Google Play Store installed along with Obum. On that profile, I do all the installation of apps, and then I use the &ldquo;install available apps&rdquo; feature from the main owner profile to push the apps to my daily profile. It was suggested to me a while ago to test out that method, and I&rsquo;ve been using it ever since on my phone and tablet. I&rsquo;m not going to cover it in this video, but I will make a dedicated video specifically for that topic because I think it&rsquo;s a really useful way to configure your GrapheneOS device.</p>
<p>As I mentioned, I have two user profiles set up. We&rsquo;re currently in my daily profile that I use, named &ldquo;Josh.&rdquo; You can see that in the top right-hand corner up there. On the main home screen, I have two Progressive Web Apps (PWAs) installed: one is for Miniflux, a self-hosted RSS reader that I use, and the other is Wallabag, which is kind of a bookmarking tool—another self-hosted app that I use.</p>
<p>So let&rsquo;s now swipe up and get to the app drawer. I&rsquo;m not going to explain the default apps installed, like the camera, gallery, etc. If you have GrapheneOS, you&rsquo;re already familiar with those.</p>
<p>To start off, I have AntennaPod, which I use for listening to podcasts. Like I said, that goes really well with the dock—you get really good audio quality, and it works well for listening to those. The next app is Audiobookshelf, a self-hosted app I use to listen to my audiobooks. Then there&rsquo;s Bitwarden, a password manager. I also have a calendar app and EteSync, which is a contacts, calendar, and task sync app—another self-hosted app that I use. They also offer a cloud service, so if you&rsquo;re looking for an encrypted way to store your calendar, contacts, and tasks, I would suggest checking out EteSync. You don&rsquo;t have to self-host it; you can just sign up and use their service.</p>
<p>Following that, I have Jellyfin. I run a Jellyfin server at my house for my movies and TV shows that I want to watch. The Jellyfin app lets me access and watch those on the tablet, which, with the 11-inch screen, works perfectly—much nicer than trying to watch on my phone. Material Files is a third-party file explorer I use to connect to some network shares I have in my house. I don&rsquo;t have it installed on my phone because I don&rsquo;t access my network shares on my phone, but on the tablet with a larger screen, it works great for that.</p>
<p>Mullvad is my VPN of choice—it&rsquo;s running on here all the time. NewPipe is the next app, which is a third-party client for YouTube that helps you avoid the ads, which is nice. Notify is an app that provides push notifications to my device when it receives a webhook notification from the uptime services that monitor my site and different services. It works without Google Play Services, which is why I have it installed on here, since I don&rsquo;t have Google Play installed on this user profile.</p>
<p>ProtonMail is my email provider. I have their paid plan, so I use it for my sideofburritos.com domain. If you&rsquo;re looking for a decent email provider that&rsquo;s privacy- and security-focused, I would recommend them. The next app is Standard Notes, which I use for all my note-taking. I have a couple of files stored in there, but primarily just text files. I self-host the Standard Notes server at my house, so it syncs locally to a Raspberry Pi where I have that running. They do have a cloud offering, so if you&rsquo;re looking for an encrypted notes service, I would suggest checking them out.</p>
<p>Next is Tasks, which syncs with EteSync, as I mentioned earlier, for contacts, calendar, and tasks. Tutanota is another privacy-focused email provider that supports end-to-end encryption, just like Proton does, which means they have no access to your emails or the content of them. I&rsquo;ve always wanted to test them out, so when I set up the email for  (<a href="https://yellowball.fm">https://yellowball.fm</a>), the podcast hosting provider that I recently launched, I decided to go with them. So far, so good—I like their product and interface. As a company, I kind of prefer them over Proton. Proton&rsquo;s kind of turning into a commodity; it seems like they&rsquo;re just launching more products and everyone’s using them. While I appreciate that because it means they&rsquo;re more accessible to the masses, at the same time, it&rsquo;s kind of nice to support companies that are more niche in privacy and security, and Tutanota seems to be that.</p>
<p>The last app is VLC, which I use to play any files that the default gallery app can&rsquo;t play. VLC basically plays any file you throw at it—sometimes I think it&rsquo;ll even play a text file. It&rsquo;s just one of those solid apps to have.</p>
<p>As I mentioned in the intro, I had high ambitions for this—plugging it into an external monitor, plugging it into a keyboard, possibly using it as my full-time device. But it&rsquo;s just not going to replace a laptop, especially for someone like me doing programming, editing, recording videos, and things like that. The interface just isn&rsquo;t meant—at least at this point—for a mouse and keyboard to be as productive, or even close to it, as a laptop, at least from my perspective. Again, your results may vary.</p>
<p>But that being said, would I recommend this to someone? If you want to use it like me, where 99% of the time I use it as an entertainment device—watching YouTube videos, watching Jellyfin, checking my email, or browsing the web—then absolutely, I think this is a great device to purchase. But other than that, I don&rsquo;t really use it for much else.</p>
<p>So I hope I didn&rsquo;t disappoint you too much, and if you have any questions about the tablet, feel free to leave those down below, and I will see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>How to set up Duress PIN/Password on GrapheneOS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-duress-pin-password/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-duress-pin-password/</id>
        <published>2024-08-19T10:00:00Z</published>
        <updated>2024-08-19T10:00:00Z</updated>
        <summary type="html">A few months ago, GrapheneOS released the Duress PIN/Password feature. In this video, I&amp;#39;ll describe some caveats about the feature, walk you through the setup, and show you what it looks like when you enter it to wipe the device.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode60s0hbhb">🎥 


<a href="https://youtu.be/Q7oM0IB-IiM" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/features#duress" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#duress</a> - GrapheneOS Duress PIN/Password documentation</li>
<li>


<a href="https://monogr.ph/665ae7b0571fecfdc8c3bdb0/" target="_blank" rel="noopener" class="text-break">https://monogr.ph/665ae7b0571fecfdc8c3bdb0/</a> - QA of GrapheneOS Duress PIN/Password feature</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>I finally found my battery, so I can start recording videos again. The feature I want to talk about today is the duress PIN/password feature that GrapheneOS released a few months ago. First, we&rsquo;ll start by looking at the documentation, and then I&rsquo;ll show you how to set it up on a device and what the actual wipe process looks like once you enter the duress PIN/password.</p>
<p>Looking at the official documentation, which is always the best place to go first, I will link that down below. GrapheneOS provides users with the ability to set a duress PIN/password that will irreversibly wipe the device along with any installed eSIMs. Once entered, anywhere the device credentials are requested, such as the lock screen or any other prompt that the OS shows you asking for your PIN or password, the wipe does not require a reboot and cannot be interrupted. So once it&rsquo;s entered, all data on your device is completely inaccessible, and you will never have access to it again. Take that as a warning—be careful with this. Once you set it, do not enter it just to test for any reason whatsoever, because all your data will be gone.</p>
<p>Both a duress PIN and password are needed to account for the different unlock methods that user profiles may use. You might have one user profile with a PIN and another with a password, which is why you need to set both. It&rsquo;s important to note that if your duress PIN is the same as your actual unlock PIN, the actual unlock PIN will take precedence. So, let&rsquo;s say your duress PIN is 1234 and your unlock PIN is also 1234—once you enter 1234 into your device, it will be unlocked, and you will not wipe the device.</p>
<p>One more thing I want to mention before I get into the live demo: make sure you check into any local laws or regulations regarding this feature. If you&rsquo;re at the airport and they ask you for your PIN, and instead, you enter this and your device is wiped, who knows what could happen. Destruction of evidence could be one of many legal implications. So, make sure you understand the ramifications of using this feature, wherever you are in the world, before actually using it.</p>
<p>With that out of the way, let&rsquo;s check out what this actually looks like. Here, I have a Google Pixel with GrapheneOS installed. The only thing I&rsquo;ve done is set a PIN code, which is 12345. In order to set a duress PIN/password according to the documentation, we go into Settings, scroll down to Security, and then we go to Duress Password. We need to enter our device PIN to authenticate that it&rsquo;s us. Once you finish reading the text on the page, you can select the duress PIN. I&rsquo;m going to set the PIN to 1111 and the password to qqqq. Once we select &ldquo;Add,&rdquo; again, you&rsquo;ll see a warning about what will happen if you enter this. Select &ldquo;Proceed,&rdquo; and now on this screen, you can either update your duress PIN or password or delete it.</p>
<p>So now, let&rsquo;s see what the actual wipe looks like. We&rsquo;re all pretty familiar with the lock screen—if you enter it there, the phone will be erased. To show you a little more non-standard scenario, if we go into Settings and back to Security, in order to set a fingerprint, you have to enter your device PIN. We&rsquo;re going to select the fingerprint unlock, and now this is an example of the OS prompting us for our PIN. Instead of entering my actual PIN, I&rsquo;m going to enter my duress PIN. You&rsquo;ll see it says &ldquo;Wrong PIN,&rdquo; the device powers off, and the irreversible wipe has occurred along with wiping all installed eSIMs. At this point, you can power the device back on. Just give it a minute to power up. This is the screen you&rsquo;ll see after the wipe occurs. You can go down to the factory reset. It&rsquo;s important to note that this feature does not brick the device in any way; it just makes the data completely inaccessible. So, we select the option for factory reset, confirm that, and now we have a fresh installation of GrapheneOS.</p>
<p>Whether or not this feature is applicable to you and your threat model is a personal decision and something you need to decide. I would caution against setting it to something simple like 1234. If someone has your device and, as a joke, they enter that PIN, now your device is wiped, and that would not be good. I do want to point out one other site that I think someone posted on the GrapheneOS forum. Someone did some duress password QA testing—they just went through a bunch of different scenarios to test it out. I thought it was something cool to check out, so I&rsquo;ll link that down below. One other use I saw someone mention for this feature is: you take a piece of paper, write your duress PIN code on it, and put it in your phone case. If someone finds your phone and they think you just left your PIN code in there because you&rsquo;re forgetful, they&rsquo;ll enter it, and your device is wiped. That&rsquo;s one option I like—that&rsquo;s something to consider.</p>
<p>So, for the last year, I wanted to start a podcast, and when I started looking at where I could host it, I couldn&rsquo;t really find an option that had everything I was looking for from a privacy perspective. So instead, I decided to build that, and it&rsquo;s called Yellowball. You can check it out at yellowball.fm. I would appreciate it if you could sign up and test it out. Let me know if you find any bugs—all you need to sign up is a username and a password. I know many of you are not looking to start a podcast, but if you&rsquo;re like me, then in your friends and family, you&rsquo;re likely the go-to person when someone has a tech question. So, if someone comes to you and asks about starting a podcast, if you could suggest they check out Yellowball, I would really appreciate it. Keep an eye out because in the next one to two weeks, I&rsquo;ll be publishing the first episode of my podcast, which is going to be called In the Shell. It&rsquo;s going to feature different stories from tech, different events that have happened in the past, and things I find interesting. So, if you&rsquo;re watching this video a week or two after it&rsquo;s been published, check down below—I&rsquo;ll link it in the description. If you have any questions or comments, feel free to leave those down below, and I&rsquo;ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>How to install GrapheneOS on Google Pixel Tablet GPT &#43; Setup for new users</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel-tablet/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel-tablet/</id>
        <published>2023-07-24T10:00:00Z</published>
        <updated>2023-07-24T10:00:00Z</updated>
        <summary type="html">The Google Pixel Tablet is finally here! Unfortunately, the stock Android OS is lacking when it comes to privacy. GrapehenOS is a private and secure mobile operating system with Android app compatibility.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode80s0hbhb">🎥 


<a href="https://youtu.be/zcHhzf-agSk" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/install/web" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/install/web</a> - GrapheneOS Web installer</li>
<li>


<a href="https://grapheneos.org/donate" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/donate</a> - GrapheneOS donation page</li>
<li>


<a href="https://grapheneos.org/features#sandboxed-google-play" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#sandboxed-google-play</a> - Sandboxed Google Play details</li>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a> - Mobile Privacy &amp; Security Guide</li>
<li>


<a href="https://youtu.be/SZ0PKtiXTSs" target="_blank" rel="noopener" class="text-break">https://youtu.be/SZ0PKtiXTSs</a> - How to install Sandboxed Google Play in a separate User Profile</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>In today&rsquo;s video, I&rsquo;m going to cover step by step how to install Graphene OS on the newly released Google Pixel tablet. I&rsquo;m going to be using the web installer, which makes it nearly impossible to break your device. There are some hiccups you might run into during the installation, and I&rsquo;ll cover those at the relevant points in the video.</p>
<p>So, to begin the installation, we&rsquo;re going to head on over to grapheneos.org. Once you get there, select &ldquo;Install Graphene OS.&rdquo; Like I said, I&rsquo;ll be using the web installer, so go ahead and click the &ldquo;Web USB-based installer.&rdquo;</p>
<p>Once we get here, go ahead and read through the prerequisites. You must be using a supported OS, which they do list here. I&rsquo;ll be using macOS for the installation today. It&rsquo;s also worth noting that if you have an existing Graphene OS device, you can use that for the installation, along with another Android device running stock Pixel OS or another certified Android variant. Make sure your operating system is up to date before proceeding, and then lastly, you must make sure you&rsquo;re using a supported browser. In this video, I&rsquo;ll be using Brave, but make sure that you are using one of the browsers listed above.</p>
<p>There are a couple of other notes below that I want to mention. If you are using Linux, avoid flat pack and snap versions of the browser as they&rsquo;re known to cause issues during the installation process. Do not use incognito mode or other private browsing modes. The reasons why are listed here. There&rsquo;s also an important note here; I don&rsquo;t really think this applies to the tablet, but to make sure that the device can be unlocked to install Graphene OS, avoid carrier variants of the devices. So with the phones, they&rsquo;ll have a Sprint or Verizon version, and those will usually have issues and you can&rsquo;t unlock them. So if you do buy a device, make sure it&rsquo;s OEM unlockable. I also suggest reading the rest of the information here, but I&rsquo;m not going to read that to you.</p>
<p>The first step in the process is to enable OEM unlocking. One thing I want to mention is always go to the source for documentation and guides. Be hesitant to follow some random YouTuber or blog post that claims they have their own method or knows the process better. That&rsquo;s why I&rsquo;m following the official guide in this video. You&rsquo;ll always get the most up-to-date instructions and information.</p>
<p>So, I just took this tablet out of the box and turned it on, which means we&rsquo;re going to have to walk through the initial setup before we can actually enable OEM unlocking. If you&rsquo;ve already gone through the setup on your device, feel free to skip this part in the video.</p>
<p>So, I&rsquo;m going to select &ldquo;Get started.&rdquo; I&rsquo;m going to set up offline, continue. I&rsquo;m going to leave that set to the default. I&rsquo;m going to uncheck these options, accept the limited warranty. Next, you should always set a secure PIN on your device, but since I&rsquo;m going to be erasing the OS in five minutes, I&rsquo;m just going to set &ldquo;12345&rdquo; for mine. I&rsquo;m going to skip fingerprint unlock because we&rsquo;re erasing the OS, so select &ldquo;No thanks.&rdquo; Swipe navigation, skip. That&rsquo;s just a guide on how to use it, so if you need to follow that, otherwise skip it. We&rsquo;ll swipe up to go home.</p>
<p>So, we are now at the home screen. Let&rsquo;s go back to the instructions. Enable the developer options menu by going to Settings &gt; About phone and pressing the &ldquo;Build number&rdquo; menu entry until developer mode is enabled. So, to do that, we&rsquo;re going to swipe up, we&rsquo;re going to scroll down and go to Settings, scroll down again, go to About tablet. Scroll down to the bottom, and you&rsquo;ll see this labeled &ldquo;Build number.&rdquo; That&rsquo;s what you want to tap until you see &ldquo;Developer options&rdquo; show up. You&rsquo;re going to have to enter your PIN code to enable this. And then you&rsquo;ll see the pop-up that says, &ldquo;You are now a developer&rdquo; on the bottom.</p>
<p>So, the next step is to go to Settings &gt; System &gt; Developer options and toggle the OEM unlock settings. So, we&rsquo;ll go to System, we can see Developer options, select that, scroll down to OEM unlocking, which we can see is grayed out here. So, I did purchase this device brand new from Google, and it is unlocked. But, in order to enable OEM unlocking, you need to connect the device to the internet for the first time. If you bought your device used and someone has previously enabled OEM unlocking, you don&rsquo;t need to worry about this step. But if you did buy this brand new, like me, you&rsquo;re going to have to connect to the internet for this to be available. So, go ahead and connect to Wi-Fi. So, you can scroll up, tap &ldquo;Network and internet,&rdquo; select &ldquo;Internet,&rdquo; to your Wi-Fi network.</p>
<p>So, once your device is successfully connected to the internet, let&rsquo;s go back to the Developer options, System &gt; Developer options, and we can now see OEM unlocking is no longer grayed out, and we can now enable it. So, we&rsquo;ll go ahead and tap the toggle. You&rsquo;ll have to enter your PIN code again. You&rsquo;ll see a pop-up for &ldquo;Allow OEM unlocking,&rdquo; select &ldquo;Enable,&rdquo; and OEM unlocking is now enabled.</p>
<p>So now, back to the instructions. The next step is flashing is non-root (this is for Linux, so if you&rsquo;re on Linux, follow these instructions; if you&rsquo;re not, skip ahead). The next step is booting into the bootloader interface. You need to boot your phone into the bootloader interface. To do this, you need to hold the volume down button while the phone boots (or, in this case, a tablet). It&rsquo;s also worth mentioning that I&rsquo;m making this video about 12 hours after the initial release of Graphene OS for the Pixel tablet, so some things on some wording may change in the future, but the overall general process will be the same.</p>
<p>So, to boot into the bootloader interface, if you&rsquo;ve never done this before, it can take you a few tries. But what you need to do is swipe down, swipe down again, tap the power icon in the bottom right-hand corner, and then select &ldquo;Restart.&rdquo; And now, immediately hold the volume down, which is on the left side of the device on the bottom, then keep holding that. And if you are successful in booting into the bootloader interface, you&rsquo;ll reach a screen that looks like this. This is going to be a little bit difficult for the camera since this is so tiny (that&rsquo;s what she said). So here, you&rsquo;ll see this output, it&rsquo;ll have some information about your device, and also say &ldquo;Device state is locked,&rdquo; we&rsquo;ll be changing that shortly. And for now, I&rsquo;m going to set this down, and we&rsquo;ll proceed onto the next step.</p>
<p>So, the next step is connecting the phone, or in this case, our tablet. Again, the Pixel tablet was just released, so they haven&rsquo;t updated the wording yet, but this is referring to your tablet. So in the note here, if you are on Windows, you need to install a driver for Fastboot if you don&rsquo;t already have it. No driver is needed on other operating systems. There&rsquo;s a couple of ways you can install the Fastboot driver on Windows. The first and easiest way, you can obtain the driver from Windows update, which will detect it as an optional update when the device is booted into the bootloader interface, which is what we see on the screen now and connected to the computer. So that&rsquo;s the easiest way. So if you are on Windows, just follow the instructions here. The second way is you can manually install it with Device Manager. So if you feel up to that, you can also go ahead and do that, but I would recommend the first method as that&rsquo;s easier and more straightforward.</p>
<p>At this point, we can now connect our tablet to our computer. The typical recommendation is to use the USB cable that came with the device. The tablet does not come with one, so you&rsquo;re going to need to use one that you have lying around or purchase one. Your best option will be to use the stock cable that came with a Pixel phone if you purchased one in the past, or you can just use whatever cable you have lying around that you know is in good working condition. That&rsquo;s what I&rsquo;m using. I just have a third-party cable here. As I mentioned in the beginning, there are a few things that could go wrong with the installation, and the USB cable is a big one that a lot of people have issues with. If you have any strange behavior during the installation, it&rsquo;s likely due to a faulty USB cable. It might work for powering a device, but data and power use different pins on a USB cable, so it&rsquo;s possible that the data pins are damaged, and it&rsquo;s not working so good. First troubleshooting step is to try a different cable, purchase a new one, and again, use that if you have any strange issues during the installation process.</p>
<p>So I&rsquo;m going to go ahead and connect this to my tablet on the bottom. There&rsquo;s a USB-C port, plug in the cable there. So once you plug it in, we&rsquo;re going to move on to the next step, which is &ldquo;Unlock Bootloader.&rdquo; So, one warning before unlocking the bootloader. This step will completely erase the device, so if you have any photos you took or maybe you have some contacts you saved, make sure you save those somewhere else first before moving on to this step. Again, this will completely erase the device and anything on there. So, we&rsquo;re going to select &ldquo;Unlock Bootloader.&rdquo; We can see up here, &ldquo;Pixel tablet&rdquo; shows up on the screen, select that, press &ldquo;Connect.&rdquo; We&rsquo;re going to see our screen change. We have a warning here, &ldquo;If you unlock the bootloader, you will be able to install custom operating system software on this phone.&rdquo; That&rsquo;s why we&rsquo;re here. So in order to do this, we can see up at the top right, it says the current option is &ldquo;Do not unlock the bootloader.&rdquo; We&rsquo;re going to press either volume up or down to change the selection. So when I press that, it now says &ldquo;Unlock the bootloader,&rdquo; and then to select that, we need to press the power button. So I&rsquo;m going to press the power button. Now that it says &ldquo;Unlock the bootloader,&rdquo; the screen goes blank for a minute, and as I mentioned earlier, down here, we had &ldquo;Device state,&rdquo; and it was green, and it said &ldquo;Locked.&rdquo; At this point, since we unlocked the bootloader, our device is now unlocked, and it&rsquo;s red. You will also see the output on the screen that says &ldquo;Bootloader unlocked.&rdquo;</p>
<p>So the next step is obtaining factory images. In order to do that, press &ldquo;Download release.&rdquo; So depending on your internet speed, this can take a few minutes, but at this point, it&rsquo;s just downloading the factory image. It&rsquo;s not actually flashing it to our device yet. And while that&rsquo;s downloading, I want to mention that if you get any value from Graphene OS or after you install it, you really like it and use it on a regular basis, consider donating to the project. And like I said earlier, they had this tablet release initial release out within 12 hours of me actually receiving the device in the mail, so they do incredible work. They&rsquo;re a great resource for the privacy and security community. So any monetary contribution you can offer, I&rsquo;m sure the project would appreciate.</p>
<p>So once the download has finished, you&rsquo;ll see this has changed to &ldquo;Downloaded,&rdquo; doesn&rsquo;t say &ldquo;Download&rdquo; anymore. So the next step is flashing factory images. The initial install will be performed by flashing the factory images. This will replace the existing OS installation and wipe all the existing data. I do suggest you give this paragraph a read before clicking the button above. The most important part down here is avoid interacting with the device until the flashing script is finished and the device is back at the bootloader interface. So once you&rsquo;re ready, select &ldquo;Flash release.&rdquo; You&rsquo;re going to see your screen flash and change. So just give it a few minutes for this process to complete.</p>
<p>So once the flashing has completed, the text on the screen will change to &ldquo;Flashed,&rdquo; and we can now proceed onto the next step, which is &ldquo;Locking the bootloader.&rdquo; Locking the bootloader is important as it enables full verified boot. It also prevents using fastboot to flash, format, or erase partitions. There&rsquo;s also some other interesting information here, so I suggest you give that a read, but similar to how we unlocked the bootloader, in order to lock it, we&rsquo;re going to select &ldquo;Lock bootloader&rdquo; in the corner. We now see &ldquo;Do not unlock the bootloader.&rdquo; We&rsquo;re going to press the volume rocker either up or down, and it now has changed to &ldquo;Lock the bootloader,&rdquo; and then to select that option, we&rsquo;re going to press the power button.</p>
<p>So I&rsquo;m going to press the power button. Give it a second. And we can confirm the bootloader is locked as &ldquo;Device state&rdquo; is now green and &ldquo;Locked.&rdquo; So at this point, we are ready to boot up the OS. There&rsquo;s a couple more steps we need to complete underneath the &ldquo;Post-installation.&rdquo; You&rsquo;ve now successfully installed Graphene OS and can boot it. Nice job! Pressing the power button with the default start option selected in the bootloader interface will boot the OS. We can see the default option right now is &ldquo;Start,&rdquo; so select the power button, and our device will now start up.</p>
<p>So, this is the first screen you&rsquo;re going to see. I&rsquo;m going to press the power button quick to pause the display or to pause the boot process. So, this is normal to see if you have a different operating system other than stock Android OS installed on your device. We can see here, &ldquo;Your device is loading a different operating system.&rdquo; And on these post-installation instructions, there&rsquo;s one step you can do here, which is &ldquo;Verified Boot Key Hash.&rdquo; So, we pause the screen by pressing the power button, and we can now see the hash listed out down there below. And what you want to do is look at that hash that&rsquo;s listed next to &ldquo;ID&rdquo; and make sure that matches the, in this case, Pixel tablet. I&rsquo;m going to read that quick, and it does match. So it&rsquo;s just one other way to verify the integrity of the installation we just performed. If that matches, we can proceed. You don&rsquo;t need to do this every time; this is just after the initial installation. I think it&rsquo;s good practice. So once you&rsquo;ve verified that, we can now press the power button to resume. So I&rsquo;m going to select that. The next screen you&rsquo;re going to see is the Google splash screen. That&rsquo;s normal. Don&rsquo;t be worried. And then we will see the Graphene OS screen. I&rsquo;m going to let this complete the first boot, but we are now successfully booting Graphene OS. Once that finishes, we&rsquo;re going to walk through the initial setup. I&rsquo;m going to press &ldquo;Start&rdquo; next.</p>
<p>Change to your time zone.</p>
<p>Enable Wi-Fi if you want. I&rsquo;m going to skip that for now.</p>
<p>I&rsquo;m going to uncheck location services.</p>
<p>I&rsquo;m going to skip the fingerprint setup.</p>
<p>I&rsquo;m going to set up a PIN code, though. Don&rsquo;t make your PIN code &ldquo;12345.&rdquo; I&rsquo;m going to be wiping this device shortly.</p>
<p>Once you confirm that, I&rsquo;m going to skip restore apps and data, and then we can press &ldquo;Start.&rdquo;</p>
<p>So I&rsquo;m pretty excited. This is the first time I&rsquo;ve ever booted Graphene OS on a tablet. I&rsquo;ve been waiting for the larger display for a long time, so this is pretty awesome.</p>
<p>So if we go back to the post-installation instructions, we can see &ldquo;Disabling OEM unlocking.&rdquo; So we want to complete that step, so we&rsquo;re going to go into Settings, scroll down to &ldquo;About phone,&rdquo; we&rsquo;re going to tap &ldquo;Build number.&rdquo; Once we see this screen, enter your PIN code.</p>
<p>We are now developers. We can see on the bottom. Go to System, and then back to Developer options, and then disable OEM unlocking. Please restart the device to enable the device protection feature. So I&rsquo;m going to hold down the power button and then select &ldquo;Restart.&rdquo;</p>
<p>So my camera is saying it&rsquo;s going to overheat. Let&rsquo;s hope it doesn&rsquo;t overheat.</p>
<p>There&rsquo;s more information under &ldquo;Verifying installation&rdquo; and some other details down below regarding hardware-based attestation. I would suggest you give that a read-through. I&rsquo;m not going to cover that in this tutorial.</p>
<p>And so once your device boots up, we can swipe up, enter our PIN code.</p>
<p>And you are now ready to start using Graphene OS on your Pixel tablet. So if you&rsquo;re looking for an easy way to get started and to start downloading apps, Graphene OS offers sandbox Google Play services. They are very easy to install. I&rsquo;m going to run through that quick. First step is we need to connect to Wi-Fi, so I&rsquo;m going to go into Settings &gt; Network and internet, select my Wi-Fi network.</p>
<p>So once you&rsquo;re connected to Wi-Fi, we can swipe up again, go back into the app drawer. We&rsquo;re going to go into the Apps app. You can then go to Google Play services, tap &ldquo;Install.&rdquo; This will take a few minutes depending on your internet connection. You&rsquo;ll see a few pop-ups. Tap &ldquo;Install.&rdquo;</p>
<p>So once that finishes, you can swipe up to go to your home screen. Going to swipe up again, we can now see Play Store is installed. If you&rsquo;ve ever used Android OS before, this is going to be very similar to the Google Play Store. There&rsquo;s a lot more information on the sandboxed Google Play services on grapheneos.org, which I&rsquo;ll link down below. But I&rsquo;m not going to cover that in this video.</p>
<p>So again, this is just a basic setup if you&rsquo;re just getting started, want to experiment, and mess around. You can make a fake Google account and sign in with that just on your tablet to use. And if you don&rsquo;t like having Google Play services on your device, you can always erase your device and set it up however you prefer.</p>
<p>So, if you made it this far and are not tired of hearing me talk yet, I do have a monthly newsletter that I send out. You can sign up for that at sideofburritos.com. I send out random text stuff and non-text stuff. You might like it or you might not, but you can always unsubscribe.</p>
<p>So, my camera just shut off that was recording the tablet, but we&rsquo;ve reached the end of the installation process. If you&rsquo;re looking for a good resource on Graphene OS-related information, check out the forum that they host. You can go to that at discuss.grapheneos.org. And if you enjoyed this video, I think you might like the top one listed here, and the YouTube algorithm thinks you might like the bottom one.</p>
]]></content>
      </entry>
      <entry>
        <title>Pixel Tablet Unboxing and Initial Impressions | GrapheneOS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-pixel-tablet-initial-impressions/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-pixel-tablet-initial-impressions/</id>
        <published>2023-06-26T10:00:00Z</published>
        <updated>2023-06-26T10:00:00Z</updated>
        <summary type="html">The Google Pixel Tablet was just released! 12 hours after I received it in the mail, the initial build of GrapheneOS was ready for it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode65s0hbhb">🎥 


<a href="https://youtu.be/jfbz1RzSJh4" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://store.google.com/product/pixel_tablet" target="_blank" rel="noopener" class="text-break">https://store.google.com/product/pixel_tablet</a> - Google Store - Pixel Tablet</li>
<li>


<a href="https://youtu.be/aTf7AMVOoDY" target="_blank" rel="noopener" class="text-break">https://youtu.be/aTf7AMVOoDY</a> - MKBHD Pixel Tablet Overview</li>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS</li>
<li>


<a href="https://nitter.net/GrapheneOS/status/1671432517285552128" target="_blank" rel="noopener" class="text-break">https://nitter.net/GrapheneOS/status/1671432517285552128</a> - GrapheneOS tweet about initial release for tablet</li>
<li>


<a href="https://hhkeyboard.us/hhkb/Pro-HYBRID-Type-S" target="_blank" rel="noopener" class="text-break">https://hhkeyboard.us/hhkb/Pro-HYBRID-Type-S</a> - HHKB Professional Hybrid Type-S (Mechanical keyboard)</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>I have been waiting a while for this product to be released. This is the Google Pixel tablet. I was initially going to make this an unboxing video, along with a few first impressions. But 12 hours after receiving this tablet in the mail, I saw this tweet from the Graphene OS team that they had an initial build ready. So, I thought I would test it out. This is not going to be an installation guide video; that will be coming out shortly after this one, and I will link it down below once it&rsquo;s ready.</p>
<p>So, as we can see in the box, this is the Pixel tablet with charging speaker dock. So, that&rsquo;s kind of cool to include that for free. I went with the 128-gigabyte version; that&rsquo;s what I normally get whenever I buy a Pixel device.</p>
<p>So, we have two strips on the bottom. First, we have the tablet. Let&rsquo;s get that out of the way. I&rsquo;m going to set that aside for now. And then underneath the tablet, we have some instruction pamphlets. It tells you how to use the dock, tells you how to get started—press the power button, follow the instructions. Thank you, Google.</p>
<p>Here we have the dock that comes with it, and then we have a charging cable just for the dock. This wall adapter is just meant to be plugged into the dock directly; it doesn&rsquo;t have a USB-C connection, so you can&rsquo;t use it with a tablet. But the dock does charge the tablet, so you can always charge it that way. So, let&rsquo;s get this box out of the way.</p>
<p>So, this is the dock for the tablet. I believe it&rsquo;s also a speaker, has a nice fabric finish to it.</p>
<p>So, this is everything in the box: you have the tablet, the dock, and the power adapter. Pretty simple, nothing much. So, let&rsquo;s take a look at the tablet.</p>
<p>On the back, it&rsquo;s plain, kind of has a soft finish to it. I believe it&rsquo;s metal, but there&rsquo;s some kind of coding on here which feels kind of nice. We have the reflective Google logo in the center, along with the four pins that correspond to the four magnetic pins on the dock as well.</p>
<p>So, the actual tablet is a 10.95-inch screen. The resolution is 1600 by 2560. It has an 8-megapixel camera, and it also has the Google Tensor G2, which is the same as the Google Pixel 7. So, just for a quick size comparison, my camera can focus on the front screen. Here is a Google Pixel 6A laying on top of the tablet. So, as you can see, it is much larger, as is to be expected from a tablet.</p>
<p>On the bottom, we have a couple speaker holes along with the USB-C port. On this side, there are some rubber bumpers here, and on the other side, we have what looks pretty similar to a Pixel phone. We have a power button, which is recessed into the actual body of the device, and then we have a rocker, which I&rsquo;m assuming is for volume.</p>
<p>On the front, it might be tough to see, but we do have a circle there, and that is where the front web camera is. And on the back is the rear camera. So, let&rsquo;s go ahead and turn this on. Hold down the power button.</p>
<p>So, usually these devices come charged, but it looks like this one is&hellip; up there it goes. I&rsquo;ll give this a minute to start up. This currently just has stock Android OS on it. I&rsquo;ve never turned this on before, so this is the first boot. We have the standard walkthrough screens.</p>
<p>I&rsquo;m going to set up offline. I&rsquo;m just going to walk through this quick.</p>
<p>So, here we are at the home screen. Let&rsquo;s go find the one part that actually matters, which is OEM unlocking.</p>
<p>So, this looks like it&rsquo;s similar to mobile devices where you need to connect to the internet to enable OEM unlocking. But for now, I&rsquo;m going to take a break from this video. I&rsquo;m going to go ahead and make the installation video, and I will be back here shortly.</p>
<p>So, after I finished filming the installation video, I ran out of time. So, here we are, the next day after I completed the installation. I just powered off the tablet. So, let&rsquo;s turn this on and take a look.</p>
<p>We have our standard screens you expect to see with Graphene OS and an alternate operating system installed.</p>
<p>One of the most shocking things, I think, so far is just how large this screen is. After using Graphene OS on a handheld device for the past two years, it&rsquo;s very odd to see it in such a large form factor.</p>
<p>I didn&rsquo;t realize yesterday, but the buttons are actually on the left side of the device, unlike the mobile devices where the buttons are on the right side.</p>
<p>Don&rsquo;t make your passcode one, two, three, four, five. So, here we are, Graphene OS on the Google Pixel tablet. If you&rsquo;ve ever installed and used Graphene OS before, then you might be familiar with the bare screen that you are presented with, which is a reminder of just how minimal this operating system is. We just have the default apps you expect to see.</p>
<p>Like I mentioned in the intro, there&rsquo;s not going to be much to go into in this video. I just kind of wanted to show that it works, what it looks like, my initial first impressions, which there&rsquo;s not much going on, so not much really to tell. I will have a much more in-depth video in the coming weeks, so stay tuned for that one.</p>
<p>But if we just poke around again, it&rsquo;s great having such a larger display.</p>
<p>Now, since I don&rsquo;t have much to actually talk about the user experience in this video, I did want to talk about why I bought this tablet and what use case I think it can offer. For me, at least, this is much easier to travel around with, the larger display. It&rsquo;s not annoying to use. If I need to do something technical with terminal, it&rsquo;s easy on this display, especially with landscape mode.</p>
<p>You get the full experience. It&rsquo;s like a full-screen computer, and at a 10-inch screen versus the smaller mobile device. And one of the things I recently purchased to use with this, I was actually looking at upgrading the mechanical keyboard I had to something that&rsquo;s a little bit easier to travel with. So, thank you to my friend who recommended this, the HHKB. So, this is a Bluetooth keyboard. It does not have a dongle. That&rsquo;s important to note. So, I wanted to make sure that this would actually work with it. So, I&rsquo;m going to test that out now and see if I can pair it with the device, because to me, if you can get this on a stand and have a keyboard paired with it, at that point you have a nearly fully functional computer, at least for my use cases. That can work, and it&rsquo;s compact, easy to travel with. So, let me pair this quick.</p>
<p>There&rsquo;s the keyboard. Looks like it has paired successfully. So, let&rsquo;s just test out this text box up here.</p>
<p>That looks abysmal on camera. Let&rsquo;s try something else.</p>
<p>So, the keyboard does work. That&rsquo;s pretty awesome. I did order the case for this that comes with a kickstand for it. So, at that point, you kind of have a computer display that you can use.</p>
<p>The other reason I was very excited for this device is that this retails for $499 in the US, and I&rsquo;m not aware of anything else you can get that is as secure and private as the default installation of Graphene OS for that price point. Yes, you can throw Linux on a laptop and have a high level of privacy, but there&rsquo;s nothing at this price point, especially in this form factor, that offers this level of security and privacy combined. So, at this point, I think this is one of the most secure and private devices you could purchase. And with a larger screen, it&rsquo;s extremely usable.</p>
<p>The other thing I really like about this device is it&rsquo;s Wi-Fi only. I&rsquo;ve been in the tech industry for over 10 years, and from everything I&rsquo;ve seen about cellular technologies, I still don&rsquo;t think there&rsquo;s a great way to use them in a secure and private manner. You&rsquo;re always triangulated when you&rsquo;re connected. And yes, some services exist to help anonymize you or to spoof some of the data that&rsquo;s used when you are connecting to those services. But at the end of the day, I think it&rsquo;s a broken technology.</p>
<p>So, now when it comes to Wi-Fi and Ethernet, those technologies I understand, and there are good ways to remain private and secure while using them. So, there&rsquo;s no need to disable cellular connectivity because it does not exist on the tablet.</p>
<p>So, one last thing I want to cover is I did read there might be some initial issues with the dock if you didn&rsquo;t first set up the dock using stock Android OS. So, I just want to test that quick. From what I understand, the smart features of the dock don&rsquo;t work on Graphene OS because those require system-level Play services, and on Graphene OS, sandboxed Play services are installed as normal apps. Therefore, it will not function. But again, it&rsquo;s still too early to tell, but that&rsquo;s what the initial feedback was I saw from the developers on Twitter.</p>
<p>So, the audio works on the tablet, as to be expected.</p>
<p>Here&rsquo;s a YouTube ad, of course.</p>
<p>So, the dock should also function as a speaker when you plug it in. So, I want to test that out quick. Let me plug in the dock.</p>
<p>So, there&rsquo;s nothing indicating the dock is plugged in once you do plug it in. So, I guess it&rsquo;s just on. So, there&rsquo;s a sound that does come out of the dock when you plug it in. So, I guess it&rsquo;s booting up or turning on. And now we can dock the tablet with the four corresponding magnets.</p>
<p>Those are extremely strong magnets. So, if we look here, we can see the tablet is charging. So, the charging functionality works. Let&rsquo;s see if the audio works.</p>
<p>And so, I can confirm that just by doing that, the audio on the speaker is working on the dock. So, it seems like that does work. There&rsquo;s no initial setup needed on the stock Android OS.</p>
<p>As to the other smart features of the dock, like I said, those probably or likely will not work in the future. At least they don&rsquo;t work at this time.</p>
<p>So, to sum up my five minutes of usage with this tablet, I&rsquo;m extremely impressed that within 12 hours after its release, the Graphene OS team had the initial build out there. So far, from my basic usage, it works well. It&rsquo;s also worth noting this is technically a first-generation device. So, if you&rsquo;re looking for something that&rsquo;s perfect from a hardware perspective, this is not that. But at the end of the day, I think the software is more important. And with Graphene OS, we know that it&rsquo;s going to be a secure and private device. And I think, in that regard, it&rsquo;s going to be a really good device for people who are looking for something at this price point.</p>
<p>So, if you&rsquo;re interested in more videos about this tablet, let me know down below. I think in the future I will be making a video about that custom stand I got, as well as any other use cases I find for this device. So, let me know if you&rsquo;re interested in that. I&rsquo;ll have a lot more coming out shortly, so stay tuned.</p>
]]></content>
      </entry>
      <entry>
        <title>Obtainium overview | My favorite way to track Open Source apps</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/obtainium-overview/" />
        <id>https://staging.sideofburritos.com/blog/obtainium-overview/</id>
        <published>2023-03-20T10:00:00Z</published>
        <updated>2023-03-20T10:00:00Z</updated>
        <summary type="html">Using an RSS reader is a popular way to tack OSS apps directly from their source. Obtainium automates this process and simplifies it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode105s0hbhb">🎥 


<a href="https://youtu.be/JiN37bn0OE8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://github.com/ImranR98/Obtainium/issues/25" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium/issues/25</a> - Obtainium Issue 25 | <strong>Help wanted</strong></li>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">https://youtu.be/IzpVI4zaso0</a> - You should uninstall F-Droid - Part 1</li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">https://youtu.be/lAbgeJau3eE</a> - You should uninstall F-Droid - Part 2</li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">https://youtu.be/FFz57zNR_M0</a> - You should use this instead of F-Droid | How to use app RSS feed</li>
<li>


<a href="https://github.com/ImranR98/Obtainium" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium</a> - Obtainium GitHub</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe</a> - NewPipe GitHub</li>
<li>


<a href="https://github.com/bitfireAT/davx5-ose" target="_blank" rel="noopener" class="text-break">https://github.com/bitfireAT/davx5-ose</a> - DAVx⁵ GitHub</li>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/</a> - F-Droid homepage</li>
<li>


<a href="https://github.com/adrcotfas/Goodtime" target="_blank" rel="noopener" class="text-break">https://github.com/adrcotfas/Goodtime</a> - Goodtime Productivity GitHub</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>Six months ago, I made a few videos on F-Droid and why you should stop using it. Shortly after the release of those videos, someone sent me a project on GitHub that says in the readme it was motivated by one of those videos. I didn&rsquo;t start using it then, but I kept an eye on the project.</p>
<p>Now, just over six months later, the project has over 900 stars on GitHub, and it has come a long way, to say the least.</p>
<p>In my original video, I covered how you could manually add the source for APKs you wanted to track and download to an RSS reader. While this method did work, it was cumbersome.</p>
<p>The app I&rsquo;m talking about today is Obtainium, and it aims to automate the process of tracking and updating apps. While it doesn&rsquo;t solve the inherent problem with F-Droid and third-party app repositories, I do think it provides some viable alternatives to help reduce or even eliminate some of those concerns. As always, you should use my advice and experience as a starting point for your own research. Make sure to test and validate everything you hear, especially if you are considering using it.</p>
<p>I&rsquo;m going to cover a few use cases and then talk about my experience the last two weeks using Obtainium on my main device, a Pixel 7. The demo you see today will be from my testing device, which is a Pixel 6A.</p>
<p>So, to obtain Obtainium, we&rsquo;re going to head on over to the official GitHub page. All links will be down below in the description box.</p>
<p>So, we&rsquo;re going to open up our browser and search for Obtainium GitHub. And this first one here is the one we want. And if you scroll down, we&rsquo;re going to select the &ldquo;Get it on GitHub&rdquo; under installation. We&rsquo;re going to expand the assets, and the one we want to select for the Google Pixel is the &ldquo;app-arm64-v8a.&rdquo;</p>
<p>Select that, download anyway. Once that finishes, select &ldquo;Open.&rdquo; If you&rsquo;ve never used your browser to install an app before, you&rsquo;ll have to allow this permission. Once you see the install window pop up, select &ldquo;Install.&rdquo;</p>
<p>Done, and we have now obtained Obtainium. You should now see it on your home screen, or if you swipe up, it should be in your app drawer. Ignore the X Recorder; I&rsquo;ve had some issues with the built-in Android screen recorder, so I&rsquo;m trying a different one.</p>
<p>You can now open the app, allow notifications. Notifications are done locally, so there&rsquo;s no need for Google Play services for notifications to work.</p>
<p>And I first want to start off by saying how refreshing it is to use an open source app that took design into consideration. I&rsquo;ve noticed a lot of times that aesthetics is an afterthought, which is fine, but I think it hurts long-term adoption. I personally have motivation from a security and privacy perspective to use an app, even if the interface is less than ideal. Others who might not have as strong of a motivation to use an app could get quickly turned off by its looks.</p>
<p>So when I first opened Obtainium, I was pleasantly surprised by the design. The developer is very active on this project, so what you see on my screen right now might not be what you see if you&rsquo;re watching this video in the future, but the general overall concept should be the same.</p>
<p>Going through the interface, the first option is the apps. This is our apps list that we&rsquo;re tracking. Obtainium is added here by default so it can track and update itself, so that&rsquo;s pretty handy. We have add app, which we&rsquo;ll come back to shortly. Then we have import/export. If you&rsquo;re currently using an RSS reader like I talked about in my previous videos, there&rsquo;s an option here to import from URLs and file like OPML. The Repla app, the main export type that I had was OPML for its backups, so you could perform an export from that and import it to Obtainium. I didn&rsquo;t test this functionality; I just manually added the apps that I wanted. You can also perform an Obtainium export, so once you get everything set up, that&rsquo;s handy. You can export it, save it, and then if you switch devices or your phone gets lost or stolen, you can always import that backup so you don&rsquo;t need to set it up all over again.</p>
<p>The last option on the bottom is settings. I just left this set to the default, but feel free to change anything you might want.</p>
<p>Now let&rsquo;s add our first app. So select add app. We can see down here listed are the supported sources, and if we look next to GitHub and Codeberg, those are labeled as searchable. So in the second box here, we can search for an app. In this case, I&rsquo;m going to search for NewPipe because that&rsquo;s on GitHub. Search, so you&rsquo;re going to be presented with a lot of results, especially for a project that&rsquo;s popular. But this first one here is the official one, Team NewPipe. Just to be safe, I always suggest that you check first to validate that it is the correct one. So let&rsquo;s go to that repo. We can see here, this is the correct one, the official NewPipe. So once you validate that, we&rsquo;re going to go back, select the first one, and then press pick.</p>
<p>There&rsquo;s a separate section for additional options for GitHub. The first one is to include pre-releases. By default, you should leave this unchecked.</p>
<p>Prereleases technically aren&rsquo;t releases that you should be using, so that&rsquo;s why it&rsquo;s left unchecked by default. The next option is fallback to older releases, and that is enabled by default. This option is for when developers on GitHub do not do the releases correctly, and they might have one release for iPhone and one for Android. If they are listed in different releases, when Obtainium goes to check what the latest version is, if the iPhone one was released latest, it will see that there&rsquo;s no Android APK available to install. Therefore, this option lets it fall back to an older release, which would be the Android version, and you can then update that.</p>
<p>Probably sounds confusing, so just leave that enabled like it is. There&rsquo;s another option here for filter release titles by regular expression. Again, this is for edge cases. I haven&rsquo;t needed this yet for any of the apps I&rsquo;m tracking on my main device. The last option down here is for track only, and what this will do is it will just track it and will not actually try to download the updates and let you install them. I leave this disabled because I want Obtainium to download the APKs for me so I can install them, and then standard version detection, I just leave that set to the default. So those are the options that are listed.</p>
<p>We can now select Add. Obtainium needs permission to install unknown apps, a lot from this source. Let&rsquo;s go back. You&rsquo;ll see this screen next. We can see latest version 0.25.0 installed, a version none. I want to install it. Install done. And now if we go back to our apps list, we can see New Pipe is now here and being tracked. Latest version 0.25 installed version 0.25. Nice clean interface, and as expected, New Pipe is installed.</p>
<p>So, I know that took a few minutes to go through and talk about, but in reality, it only takes 30 seconds to add an app, and now in the future, Obtainium will check for updates in the background and notify you when they are available. As always, you should be skeptical of anything open source or any app for that matter, especially something that will be installing apps on your behalf or for you. So one extra precaution that you can take is to install the app manually first from the source, and then add it to Obtainium. When you install an app, Android pins the certificate and enforces signature checks for app updates, so even if something malicious was happening with Obtainium, it wouldn&rsquo;t be able to install a malicious app update because the signature check would fail.</p>
<p>So as an example, let&rsquo;s go ahead and install Dev X5. I know their source code is on GitHub, so I&rsquo;m going to search for that. I know this is the official repo for it. I&rsquo;m going to go to the releases and download the latest one. Let&rsquo;s open and install that.</p>
<p>So now at this point, Dev X5 has been installed. We downloaded it from the trusted source that we know; therefore, the certificate has been pinned by the OS. So any updates that are installed either manually by us or using Obtainium must pass the signature check, which means that the APK is signed by the developers. We can see Dev X5 was installed. Let&rsquo;s now add it to Obtainium. We just copy this URL, go back to Obtainium, add app, paste in the URL, select add. We can see that it found that Dev X5 is installed, latest version 4.3, installed version 4.3.</p>
<p>There&rsquo;s no updates to install. So now, if we go back, then go back to the apps list, we can now see that DAV X5 is listed there. We installed it from a trusted source, and now we&rsquo;re going to let Obtainium handle any future updates.</p>
<p>There are a few other caveats or features that I want to go over. So, going back to the &ldquo;add app&rdquo; option, we can see here that Malvad and Signal are both listed as sources. If we select one of those, Malvad publishes their APK on their website, so we can just copy this, and Obtainium on our behalf will find the APK for us and download it.</p>
<p>Select &ldquo;add,&rdquo; and we can see in the background downloading Malvadvpn. So it&rsquo;s pretty handy that the developer went ahead and built in this functionality for us already. Even though we&rsquo;re not actually adding the exact page the APK is on for the apps listed there. In this case, Malvad and Signal, the app automatically knows where to look. It&rsquo;s a good minute to finish.</p>
<p>Once it finishes, we&rsquo;re prompted to install. Now, if we go back to the apps list and refresh, we can now see Malvad is shown here and being tracked.</p>
<p>Just to show an example of what updates look like, I went ahead and installed an older version of New Pipe. You&rsquo;ll receive a notification, and then when you go inside the app, you&rsquo;ll see a notification next to the app that needs to be updated. In this case, New Pipe. Select the purple download icon, and you can see the download. So Obtainium went ahead and downloaded the APK for us. We now select &ldquo;update,&rdquo; and now New Pipe was successfully updated.</p>
<p>One of the easiest ways to find where the source code for an open-source app is hosted is to use the F-Droid website. So if we go to f-droid.org in our browser and then scroll down and let&rsquo;s search for New Pipe as an example, the second one is the one we want.</p>
<p>To access the source code for the application, we need to scroll down to the section above the donate button and click on the link to the source code. By examining the URL, we can see that the source code is hosted on GitHub. If we scroll down further to the releases section, we can see that NewPipe publishes their APK on GitHub, which means Obtainium can download it from there.</p>
<p>Returning to fdroid.org, we can find that some developers only publish the APK on F-Droid, even if they have already published the source code on GitHub. As an example, let&rsquo;s search for a productivity app that starts with &ldquo;Good Time,&rdquo; which is the fifth one down. Looking at the source code, we can see that it is also hosted on GitHub. However, when we scroll down to the releases section, we notice that they do not publish the APK on GitHub; only the source code is available. In this scenario, our only option is to return to F-Droid, copy the F-Droid link, and paste it inside Obtainium.</p>
<p>After adding the app and pasting the F-Droid URL, we can see that Obtainium found the app and we can proceed to install it. Upon returning to our list of apps, we can see that Productivity is now installed, and it shows that it is signed by F-Droid.</p>
<p>Using Obtainium is still a better option than the official F-Droid app because it avoids some of the shortcomings mentioned in the previous video, such as targeting out-of-date SDKs. Although the process might seem complicated, it is relatively simple once you go through the steps yourself. It has made the process of downloading, installing, and updating apps much more accessible for the past two weeks, and the update functionality and tracking have worked flawlessly. The experience so far has been enjoyable, and the plan is to continue using it.</p>
<p>However, there are a few limitations to be aware of that are listed on the GitHub readme. The first one is that app installs occur asynchronously, and the success or failure of an install cannot be determined directly. This results in install statuses and versions sometimes being out of sync with the OS until the next launch or until the problem is manually corrected. If you notice any unusual behavior, close the app and relaunch it.</p>
<p>The second limitation, which will be revisited later, is that auto unattended updates are unsupported due to the lack of a capable Flutter plugin. Also, for some sources, data is gathered using web scraping, which can easily break due to changes in website design. In such cases, more reliable methods may be unavailable, and scraping is an unreliable method to gather data. If you have ever used NewPipe and noticed that it broke randomly because YouTube changed its layout one day, that is a similar situation to what the developer is describing here. It is not the app developer&rsquo;s fault, but rather the nature of web scraping.</p>
<p>Regarding the second limitation mentioned above, before making this video, the app developer was contacted to see if there was anything specific they wanted to mention. They requested that any Android developers watching the video take a look at issue number 25, linked below, to help complete the auto-update feature before releasing version one of Obtainium. Contributions to help with that would be greatly appreciated.</p>
<p>Overall, using Obtainium has been a great improvement and has made the manual tracking process much more efficient. Although it is not a solution to the underlying problems that still exist, it is a step in the right direction. The plan is to continue using it, and there are no plans to go back to the RSS reader method.</p>
<p>And while it&rsquo;s not a solution to the underlying problems that still exist, which I covered in my previous videos, it is a great improvement and makes the manual tracking process much more efficient. So, I hope you enjoyed this video. If you did, check out this top one here, and the bottom one has been automatically selected for you.</p>
]]></content>
      </entry>
      <entry>
        <title>F-Droid - App not installed as package appears to be invalid</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/fdroid-app-not-installed/" />
        <id>https://staging.sideofburritos.com/blog/fdroid-app-not-installed/</id>
        <published>2023-02-06T10:00:00Z</published>
        <updated>2023-02-06T10:00:00Z</updated>
        <summary type="html">The F-Droid website hosts an outdated version of the APK which causes issues for users who try to install it in multiple user profiles.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode56s0hbhb">🎥 


<a href="https://youtu.be/E3erRhXPPNY" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/</a> - F-Droid homepaage</li>
<li>


<a href="https://f-droid.org/en/packages/org.fdroid.fdroid/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/en/packages/org.fdroid.fdroid/</a> - F-Droid package</li>
<li>


<a href="https://www.sisik.eu/apk-tool" target="_blank" rel="noopener" class="text-break">https://www.sisik.eu/apk-tool</a> - Browser APK analyzer</li>
<li>


<a href="https://forum.f-droid.org/t/cannot-install-f-droid-invalid-package-using-profiles/16122" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/cannot-install-f-droid-invalid-package-using-profiles/16122</a> - F-Droid forum post 1</li>
<li>


<a href="https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234</a> - F-Droid forum post 2</li>
<li>


<a href="https://hub.libranet.de/wiki/and-priv-sec/wiki/apps" target="_blank" rel="noopener" class="text-break">https://hub.libranet.de/wiki/and-priv-sec/wiki/apps</a> - Android apps</li>
<li>


<a href="https://grapheneos.org/features#install-available-apps" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#install-available-appss</a> - GrapheneOS install available apps feature</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>It&rsquo;s good practice to document answers to frequently asked questions, as it allows other users to reference them. For example, I&rsquo;ve been asked multiple times through email and video comments why a user is unable to install F-Droid in another user profile. To avoid answering these questions individually, I decided to make a video explaining the reason behind this issue. To demonstrate the process, a user can go to f-droid.org on their Android device and click the &ldquo;Download&rdquo; button on the home page to download F-Droid. Once the download is complete, they can install the APK.</p>
<p>Open the app, ignore the warning, allow it a minute to update the repositories. Now, if you go to updates because of the notification, the first thing the app wants you to do is update F-Droid to the newest version. The user now has the latest version of it installed. They go through and download whatever apps they want, install them, and then shortly after this, the user finds out about user profiles and wants to start separating their apps to different user profiles to separate user data.</p>
<p>So, they create a new user profile and we&rsquo;re on that new user profile. And again, the first thing they want to do is install F-Droid so they can download apps. They go to fdroid.org again, same process as before, click the download button, download once the download finishes, open, and install again. And they are presented with an error. This is the error I get asked about and that I see different posts about online.</p>
<p>So now that we see what is happening, let&rsquo;s talk about why this is happening. This diagram is overly simplified, but I think it&rsquo;ll help paint the picture of what&rsquo;s going on. At the bottom here, we have the system and part of the system is the Android Package Manager, which we can see here. And above the system level is the user profiles, as we saw in the example. We had our initial owner user profile that we were on and then switched to our user profile, which was that second user profile where the F-Droid install failed.</p>
<p>A common misconception is that when you install an app on a user profile, it&rsquo;s installed in that user profile and then when you switch to the other user profile, it&rsquo;s installed there as well. But that is not correct. What happens when you install an app on Android is that it is handled by the Android Package Manager. That app is installed and then linked, for lack of a better term, to the profile that you are presently in.</p>
<p>In this example, we installed F-Droid from our owner profile. We downloaded it and installed it, which was version one. And as we saw in the example, once we installed F-Droid, we were immediately prompted to update the app, so we went from version one to version two. These are not the actual version numbers. I&rsquo;m just doing this for the sake of simplicity. So at this point, we now had version 2 of it installed and being managed by the Android Package Manager.</p>
<p>We went to our second user profile, downloaded and installed F-Droid, or tried to install it, but the issue that was occurring was that when we downloaded F-Droid from the website, the version we downloaded was actually version one. Since Android packages are managed by the system, there&rsquo;s a protection in place that prevents an app from being downgraded. So in this case, we were trying to install version one of F-Droid, but the Package Manager saw that we had version 2 installed, therefore it blocked the install on that second user profile, and we were unable to install F-Droid on it.</p>
<p>Just to reiterate, because it was a misconception that I had as well, user profiles are meant to separate user data. The actual installation of apps is handled at the system level by the Android Package Manager. And if you try to install an app on a separate user profile that is an older version than the one currently being tracked by the Android Package Manager, the install will fail.</p>
<p>You may have noticed that when you update an app in one user profile, the same update is reflected in all other user profiles. This is because the package installation is handled at the system level, not at the user profile level. When the app is updated in one profile, the actual package is upgraded across the system, making all user profiles use the same updated version.</p>
<p>This is why the issue of updating F Droid continually occurs. F Droid hosts an outdated version of their app on their website, so every time a new user visits the site, they end up downloading an older version of the app, which then prompts them for an update. To avoid this, you can download the latest version of the app from the home page and save it in a folder titled &ldquo;F Droid&rdquo;. From there, you can search for &ldquo;F-Droid&rdquo; on the right side.</p>
<p>We can scroll down to the latest version labeled &ldquo;Suggested Download&rdquo;. Again, placing that in the &ldquo;F Droid&rdquo; folder. Now, for the sake of simplicity, I&rsquo;m going to use this online APK analyzer. Here we have our &ldquo;F Droid&rdquo; folder with the &ldquo;F Droid.apk&rdquo; that was downloaded from the home page and the &ldquo;org.fdroid&rdquo; that was the most recent suggested version we downloaded.</p>
<p>If we look at these, we can see that the one from the home page is version 1.15.4, and the version from the actual page in the search was 1.15.6. The 1.15.4 was published on December 2nd, 2022, and the most recent suggested version on January 14th, 2023.</p>
<p>That&rsquo;s why if you go to a separate user profile and try to download F Droid from the main home page, you receive an older version that&rsquo;s out of date and the install fails because Android&rsquo;s downgrade protection kicks in and blocks the install.</p>
<p>Now that we know what is happening and why, there are a couple of things you can do to get around this issue:</p>
<p>Instead of going to the F Droid home page, you can scroll down, search for &ldquo;Appdroid&rdquo;, select F Droid, and download the latest version with the tag &ldquo;Suggested&rdquo;. When you open this one and select &ldquo;install&rdquo;, it&rsquo;s not blocked by Android because you&rsquo;re not trying to install an older version of the app. This is probably the easiest for most people.</p>
<p>If you are running Graphene OS, you can go into &ldquo;Settings&rdquo;, &ldquo;System&rdquo;, &ldquo;Multiple Users&rdquo;, select the second user profile, and use the option &ldquo;Install Available Apps&rdquo;. Change the toggle next to F Droid, and it will be accessible from your second user profile. The reason the &ldquo;Install Available Apps&rdquo; feature works is that APK installation is handled by the package manager at the system level, so when you are in the owner profile, you can give additional profiles access to installed apps.</p>
<p>For the F Droid team, you could update the version on your home page to the latest stable version. It&rsquo;s not good security practice to intentionally host an outdated version of your app in the most popular place to download it. This one change of hosting the most recent version on your home page would save everyone time and make for a better overall user experience.</p>
<p>If you enjoyed this video, I think you&rsquo;ll like the top one listed here, and the engineers at Google think you will like the bottom one.</p>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS vs Android OS on the Pixel 7 Review</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-vs-android-pixel7/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-vs-android-pixel7/</id>
        <published>2023-01-22T10:00:00Z</published>
        <updated>2023-01-22T10:00:00Z</updated>
        <summary type="html">I finally decided to switch to my Pixel 7. Before installing GrapheneOS on it, I wanted to use stock Android OS for a few weeks, so I could make a fair comparison video.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode71s0hbhb">🎥 


<a href="https://youtu.be/nuy76Iapmn8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/features#sandboxed-google-play" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#sandboxed-google-play</a> - Sandboxed Google Play Documentation</li>
<li>


<a href="https://youtu.be/hx2eiPTe7Zg" target="_blank" rel="noopener" class="text-break">https://youtu.be/hx2eiPTe7Zg</a> - Sensor &amp; Network Permissions</li>
<li>


<a href="https://youtu.be/WjrANjvrSzw" target="_blank" rel="noopener" class="text-break">https://youtu.be/WjrANjvrSzw</a> - Storage Scopes</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>I am upgrading to the Pixel 7 and after nearly two years of using Graphene OS, I have decided to leave the stock Android OS installed on it. Let me be clear, I did not want to do this, but I figured in order to offer a fair comparison between stock Android OS and Graphene OS, I should probably test out the stock OS and see how it is. My first impression with stock Android OS is that it has a very friendly setup. It wants you to log into your accounts to sync your settings and it comes with a ton of popular apps installed, as well as the Google Play Store, installed by default. I am speaking objectively for someone new to the OS, not from a privacy or security perspective. The whole initial experience was very welcoming. To keep things equal in my testing, I am going to be using the Play Store on both OS&rsquo;s by signing in so I can download apps. I also wanted to try and embrace the stock Android OS as much as possible to see if there were any features I might miss.</p>
<p>I am a simple person and my phone habits stick to that theme, so it&rsquo;s likely I missed a bunch of features that these OS&rsquo;s offer. With my time on stock Android OS, there are a few major things I noticed. The OS wants you to sign in a lot, which I guess is no surprise. You are always reminded to log in, sync, and use your Google account. I did my best to avoid this, even though I signed into the Google Play Store. I didn&rsquo;t want to sync any of my phone data with my Google account. As far as navigation goes, I noticed that Google Maps is very helpful for traffic. As someone who lives in a busy city that I think has some of the worst drivers in the United States, Google Maps saved me time at least on three different occasions by helping me take a different route instead of the one that had multiple traffic accidents during rush hour. Now the biggest difference I noticed right off the bat, which I was not expecting, was Google Keyboard, otherwise known as Gboard. It makes the initial feeling of stock Android OS very fluid and cohesive. My typing felt more accurate while using it and I&rsquo;ve heard people in the past suggest using a different keyboard from the stock one that comes with Graphene OS. Now, I can see why they suggested it. It really makes a big difference. The phone and clock apps on stock Android OS are very well designed as compared to the AOSP versions used on Graphene OS. While I didn&rsquo;t use any of the extra features offered by the phone or clock app on stock Android OS, aesthetically, they are very nice looking.</p>
<p>In terms of functionality, the way I use them, there was no difference. There are two features on stock Android OS that are not available on Graphene OS. The first is Android Auto. The reason for that is that it requires system-level integration, and that is not something the project is willing to support, which I completely understand. The second feature that I found, which I really liked, is the now playing feature. Now playing listens to background audio in your environment and will show you the song that is now playing on the lock screen, if it can identify them. It does sound a little bit counter-intuitive from a privacy perspective, but I liked it. Now playing doesn&rsquo;t send audio or background conversations to Google, according to their documentation, and all processing takes place locally on your device. I can already hear the people typing &rsquo;lies, Google&rsquo;s collecting my audio and listening to my conversations.&rsquo; I&rsquo;m going based off of the information available and documentation, not speculation. So with all that said, at the end of the day, I still did not like being on the stock OS. You are reminded that Google is there for your convenience, ready to save your passwords, collecting telemetry in the background, and the inability to uninstall a lot of the bundled apps. All you can do is disable them. There&rsquo;s just something uncomfortable about knowing that Google services have system-level integration, and therefore do not follow the regular permission controls available for sandboxed apps. So after almost two weeks, I went and installed Graphene OS on my Pixel 7.</p>
<p>The first things I did to make it a fair comparison were to install sandboxed Google Play services, all of my apps, I installed the Google keyboard, and I set the same wallpaper. I was happy to be back. No annoying prompts to sign in, and I felt like my privacy was back under my control pretty quickly. I noticed some of the visible features that I missed that Graphene OS offers. Those features were the network permission, when you install an app, the sensor&rsquo;s permission, and storage scopes. Stock Android OS does not have these features. If you want to learn more about those, I&rsquo;ll link my video covering those down below, but overall, with the Play Store, Gboard, and a wallpaper set, the experience felt very familiar to stock Android OS. I honestly thought there would be a jarring difference when I switched back, but there wasn&rsquo;t. A popular question I see is, &lsquo;Am I getting any benefit to using Graphene OS with sandboxed Play Services installed?&rsquo; And the answer is yes. On Graphene OS, they are installed as sandboxed apps, like any other app you install. They have no access beyond what other apps can access, and you can set the permissions on the apps installed. This implementation provides a great balance of usability and privacy. Now, this was an oversimplified explanation. The official documentation goes over this in great detail and explains it very well. I&rsquo;ll link that down below, and I do suggest you give it a read if you plan on using them or want to learn more. So, at the time of this recording, I&rsquo;ve been using Graphene OS on my Pixel 7 for nearly two weeks, and I haven&rsquo;t noticed any issues or bugs for my specific use cases. As far as battery life goes, I haven&rsquo;t noticed much of a difference between the two OS&rsquo;s. I feel that they are similar for the setup that I&rsquo;m using, but I haven&rsquo;t done any official tests for battery life. Now, the setup in this video isn&rsquo;t how I&rsquo;m going to leave my Pixel 7. I&rsquo;ll be covering a new setup that I&rsquo;m going to try in a future video, but if you have any hesitations about moving from stock Android OS to graphene Os from my basic phone usage habits with sandbox to play services installed I don&rsquo;t think you&rsquo;ll have much of an issue.</p>
]]></content>
      </entry>
      <entry>
        <title>A minimalist dumb phone you should actually use</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/minimalist-dumb-phone/" />
        <id>https://staging.sideofburritos.com/blog/minimalist-dumb-phone/</id>
        <published>2022-12-05T10:00:00Z</published>
        <updated>2023-01-23T10:00:00Z</updated>
        <summary type="html">There is no discussion about the security and privacy of a dumb phone.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode100s0hbhb">🎥 


<a href="https://youtu.be/OrZacTUhH0c" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS</li>
<li>


<a href="https://jkuester.github.io/unlauncher/" target="_blank" rel="noopener" class="text-break">https://jkuester.github.io/unlauncher/</a> - Unlauncher</li>
<li>


<a href="https://github.com/jkuester/unlauncher" target="_blank" rel="noopener" class="text-break">https://github.com/jkuester/unlauncher</a> - Unlauncher GitHub</li>
<li>


<a href="https://signal.org/" target="_blank" rel="noopener" class="text-break">https://signal.org/</a> - Signal</li>
<li>


<a href="https://store.google.com/category/phones" target="_blank" rel="noopener" class="text-break">https://store.google.com/category/phones</a> - Google Pixel</li>
<li>


<a href="https://youtu.be/B0RVWU_nROk" target="_blank" rel="noopener" class="text-break">https://youtu.be/B0RVWU_nROk</a> - YouTube Video - I used a flip phone for 30 days</li>
<li>


<a href="https://youtu.be/Vl5OrbsXBI8" target="_blank" rel="noopener" class="text-break">https://youtu.be/Vl5OrbsXBI8</a> - YouTube Video - One Month with a Minimalist Dumb Phone | Light Phone II Review</li>
<li>


<a href="https://www.thelightphone.com/" target="_blank" rel="noopener" class="text-break">https://www.thelightphone.com/</a> - Light Phone</li>
<li>


<a href="https://palm.com/pages/product" target="_blank" rel="noopener" class="text-break">https://palm.com/pages/product</a> - Palm Phone</li>
<li>


<a href="https://mudita.com/products/phones/mudita-pure/" target="_blank" rel="noopener" class="text-break">https://mudita.com/products/phones/mudita-pure/</a> - Mudita Pure</li>
<li>


<a href="https://github.com/sduduzog/slim-launcher" target="_blank" rel="noopener" class="text-break">https://github.com/sduduzog/slim-launcher</a> - Slim launcher (Unlauncher is a fork of this project)</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>I&rsquo;ll be the first to admit, whenever I see some slick looking minimalistic dumb phone, video thumbnail or a title with &ldquo;I use the flip phone for 30 days,&rdquo; I click it. And why you may ask? Because I&rsquo;m tempted to try one. From a design aspect, the minimalist phone gets a nine out of 10. The Flip Phone usually doesn&rsquo;t look as great, but they are minimal.</p>
<p>But for both of those options, it&rsquo;s downhill pretty quick from their functionality, usability, and hardware. They are all lacking. But the biggest downside for me as someone who has a tech background is the lack of security and privacy on these phones. These devices all have some random custom OS specifically designed for aesthetics. From an OS perspective, they&rsquo;re insecure. From an app perspective, it&rsquo;s no surprise that it&rsquo;s also minimal. And usually the only form of communication you have is standard phone call and SMS, which are both unencrypted and not secure.</p>
<p>So what are you really getting for your money? Once you dig a little bit deeper and get past the good looks, you end up with a device that in all honesty, nobody should be using. So what options are you left with? Do you use an iPhone with the color turned off, so you&rsquo;re less tempted to use it, or maybe a stock android phone with all the apps uninstalled? Both of those are not great from a privacy perspective. And they both take quite a bit of customization to actually get what you&rsquo;re looking for. And so for me, neither of those are great options.</p>
<p>That brings us to something called a Graphene OS. It&rsquo;s a private and secure mobile operating system with Android app compatibility. And this is what it looks like. Minimal, clean, simplistic, and most importantly, private and secure.</p>
<p>This in and of itself as a minimal phone, you can see the apps that it comes with just the basics to get you started and have a functioning device. You can make phone calls, receive text messages, you have a browser, calculator, alarm, nothing extra unless you choose to add it. And so I&rsquo;m a fan of the default interface.</p>
<p>If you want that aesthetically pleasing, minimalistic phone looking interface, there&rsquo;s something called On Launcher. On Launcher is a free launcher you can install on your Android device. In this case, my Google Pixel six a running Graphene OS. So once you install it and set it as your default launcher, this is the interface that you are now presented with. At the bottom left, we have access to our phone. At the bottom right, we have access to the camera. In the center, we have settings. And if you swipe up, no colors or fanciness, drawing you in, just a simple list of your apps in a functional interface.</p>
<p>So now that we have our secure and private device with our simple interface configured, there is one last app we want to install. And since this is an Android device, it is compatible with Android apps. And that last step is Signal. What that&rsquo;s going to provide us with is a secure and private means of communication. If you&rsquo;ve never used it before, it has text, audio, and video chat available. I have a friend using a setup very similar to this.</p>
<p>He&rsquo;s been using it for over six months and at this point, he said there&rsquo;s no going back. So, if you&rsquo;re interested in getting a similar setup for yourself, graphene OS supports the Google Pixel. So, if you have one of those, install on launcher and signal, all of which will be linked down below. And at that point, you will then have a secure, private, and minimalistic phone that will make you not hate your life.</p>
]]></content>
      </entry>
      <entry>
        <title>How to install GrapheneOS on Google Pixel 7 (Pixel 7 Pro) &#43; Setup for new users</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel7/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel7/</id>
        <published>2022-11-28T10:00:00Z</published>
        <updated>2022-12-21T10:00:00Z</updated>
        <summary type="html">The Google Pixel 7/Pixel 7 Pro is a great mobile device. With the Google Tensor G2 chip, it&amp;#39;s one of the most secure mobile devices you can purchase.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode83s0hbhb">🎥 


<a href="https://youtu.be/ZAZlmYKrwfk" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/install/web" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/install/web</a> - GrapheneOS Web installer</li>
<li>


<a href="https://grapheneos.org/donate" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/donate</a> - GrapheneOS donation page</li>
<li>


<a href="https://grapheneos.org/features#sandboxed-google-play" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#sandboxed-google-play</a> - Sandboxed Google Play details</li>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a> - Mobile Privacy &amp; Security Guide</li>
<li>


<a href="https://youtu.be/SZ0PKtiXTSs" target="_blank" rel="noopener" class="text-break">https://youtu.be/SZ0PKtiXTSs</a> - How to install Sandboxed Google Play in a separate User Profile</li>
<li>


<a href="https://nitter.net/DanielMicay/status/1552966692749414402#m" target="_blank" rel="noopener" class="text-break">https://nitter.net/DanielMicay/status/1552966692749414402#m</a> - Twitter thread explaining OEM unlocking</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So in today&rsquo;s video, I&rsquo;ll be demonstrating how to install graphene iOS on the Google Pixel seven specifically, but if you have a different Google Pixel, this process will be relatively similar, I&rsquo;m going to be using the web installer. And if you use that, it&rsquo;s nearly impossible to mess up your phone. So don&rsquo;t be afraid to attempt this. Now with that being said, there are a few hiccups you may run into during the install process. And I&rsquo;ll cover those at the relevant points in the video. The computer I&rsquo;m demonstrating this from is running Mac OS, and I&rsquo;m using the brave browser. So to get started, we&rsquo;re going to head on over to Griffin os.org. All websites that I mentioned in the video will be linked down below in the description box. So once you get here, click on Install Griffin OS. As I mentioned, we&rsquo;re going to be using the web based installer. So once you get to this page, we&rsquo;re going to scroll down to the prerequisites, give this a read through make sure that you have all of these requirements met. Make sure you&rsquo;re using one of the supported OSS, like I said, I&rsquo;ll be installing from macOS. So besides a supported operating system, make sure you are using a supported browser. There is an important note here, if you are using chromium on Ubuntu, it&rsquo;s broken and will not work. So use a different browser, such as Google Chrome. Another important note here do not use incognito or private browsing mode. And so once you give that a read through, I&rsquo;m not going to waste your time by reading it to you, and you make sure that all the prerequisites are met, we can then proceed on to the first step, which is enabling OEM unlocking in the screen we&rsquo;re currently on is the screen that you&rsquo;ll see if you just bought it brand new and just took it out of the box. So first, I&rsquo;m going to walk through the initial setup. If you&rsquo;re already past this part, you can skip it, I&rsquo;ll leave the timestamps down below in the play bar. So we&rsquo;re going to go ahead and select to get started. I&rsquo;m not going to connect to a mobile network, I don&rsquo;t have a SIM card in my phone. Skip. I&rsquo;m going to skip connecting to Wi Fi select Setup offline, continue. Date and time, you can leave that set to default. You don&rsquo;t need to uncheck these but I like to anyways click Accept limited warranty. Next additional legal terms except we are going to be erasing the phone so you don&rsquo;t really need to set a pin but I think it&rsquo;s good practice anyways</p>
<p>confirm the pin fingerprint unlock I&rsquo;m going to skip this because like I said, we&rsquo;re just gonna be erasing the phone momentarily. No banks face on luck, no thanks. This is just a quick tutorial on swipe navigation. If you want, you can go through it. Otherwise skip. So we have finished the initial setup offline and go ahead and swipe up. And we&rsquo;re now at the home screen. So I&rsquo;m recording this part while editing the video because I forgot to mention it initially, this step is not required. But it is suggested that you update your device before installing graphene allow us to check for updates, first connect to Wi Fi, then swipe up, go into settings, scroll down, tap on system. And then tap system update. If you see your system is up to date, then you&rsquo;re good to go. Otherwise, install any pending updates and then continue with the video. So to enable OEM unlocking we first need to enable developer options, which you can do by going to settings about and repeatedly pressing the build number menu entry. And just one note before we actually start following the instructions, make sure you always go to the source when you&rsquo;re looking for information. Don&rsquo;t just follow some random YouTuber or some blog post, always go to the official documentation in this case graphene os.org get your information from the source first and then go from there. Select the instruction said we&rsquo;re going to swipe up, go into settings, scroll down to the bottom, we&rsquo;re going to tap about phone, scroll to the bottom. And down here we have build number. Go ahead and tap that until you are prompted for your PIN. If you set one, enter your PIN. And we can now see you are now a developer. So another developer options are enabled. Next go into Settings System developer options and toggle the OEM unlocking setting. So we&rsquo;re going to go back, scroll down, go to system. At the bottom, we have developer options, tap that. If we scroll down, we can see here OEM unlocking so there is one caveat about OEM unlocking that I want to mention. So if you purchased your phone brand new from Google or from a store, you will need to connect to the internet first so that your phone can check if the serial number was sold carrier locked or if you&rsquo;re able to enable OEM unlocking devices that are typically locked by the carrier or Verizon based devices, those ones even if you connect to the internet, you won&rsquo;t be able to unlock. Your only option at that point is to either return the device or sell it and buy a factory unlocked device. For me personally, I usually buy my devices directly from Google, I select the unlocked version option. And every time I&rsquo;ve had no issues, so if you&rsquo;re watching this video and haven&rsquo;t purchased a device yet, and you&rsquo;re looking to buy a used mobile phone, I suggest asking the seller to send you a screenshot or a photo showing that OEM unlocking is available. That&rsquo;s the only way to truly guarantee it. I&rsquo;ve purchased a device used in the past, and it was carrier unlocked, which means I could connect to different carriers, but it didn&rsquo;t actually support OEM unlocking so reach out to the seller to confirm that if they&rsquo;re not willing to send you a photo showing that I would suggest not buying that device. So again, if you bought a new phone, you connected the internet OEM unlocking should be available at that point. And once it is, go ahead and enable OEM unlocking, you&rsquo;ll be prompted for your pin again. Allow OEM unlocking, enable, and we can now see OEM unlocking is enabled. So on to the next step flashing as non root. This is for anyone who&rsquo;s on Linux, I&rsquo;m not on Linux. So I&rsquo;m not going to cover this. But if you are give this a read over following that is booting into the bootloader interface, you need to boot your phone into the bootloader interface. To do this, you need to hold the Volume Down button while the phone boots, the easiest way is to reboot your phone and begin holding the Volume Down button until it boots up into the bootloader interface. So this part can be a little bit tricky for some people. So we&rsquo;re going to swipe down, swipe down again, you&rsquo;ll see down here the power button, select that, and then select Restart. Once restarting disappears from the screen, hold the Volume Down button.</p>
<p>This will take a minute. And if you were successful on booting into the bootloader interface, you will see this screen. If you were not successful, your phone will just boot up as normal. At that point restarted again, hold the Volume Down button until you get into this interface. So the next step is connecting the phone. If you&rsquo;re on Linux, here&rsquo;s a note about that. If you&rsquo;re on Windows, you need to install the driver for fast boot if you don&rsquo;t already have it, there&rsquo;s a couple options for actually obtaining the drivers. So pause the video and Give this a read over if you&rsquo;re on Windows. And for everyone else, we can just go ahead and connect our USB cable to our device. So this is where a lot of people run into an issue. They plug their phone into the computer with a USB cable, and their computer doesn&rsquo;t actually see the phone and they don&rsquo;t understand what&rsquo;s going on. Typically that&rsquo;s due to a faulty USB cable. The best option in this scenario is to use the stock cable that came with your device. If you don&rsquo;t have that use a third party cable. But if you plug in your phone to the computer with a USB cable, and it doesn&rsquo;t see it, try a different cable. Typically it&rsquo;s a faulty cable causing you issues. One other thing to mention, make sure you&rsquo;re plugging your USB cable directly into your computer, don&rsquo;t plug it into a dongle first. That can also be the cause of issues. So again, use the cable that came with your device, plug it directly into your computer, and you should have the best chance of not having an issue. So plugging the cable to your device. So before we unlock the bootloader it&rsquo;s important to note that once you do, all data on your device will be wiped. So if you were using your phone and you took some photos, or maybe this was your primary device and now you want to test out graphene iOS, make sure you make a backup of everything on there, your contacts, calendar events, text messages, everything will be erased and there&rsquo;s no way to recover it. So once you confirm you have everything&rsquo;s backed up or saved that you want, you can then proceed to unlock the bootloader select unlock bootloader and if your cables not faulty and your computer sees your device, you will see a prompt like this graphene os.org wants to connect, you should see your device listed here. Select Connect, we can see the screen changed, we have a quick disclaimer down here about unlocking the bootloader. And up here we can see it do not unlock the bootloader we want to unlock the bootloader. So to change the selection, we&rsquo;re going to press the volume down or up. You&rsquo;ll now see it says unlock the bootloader once you see that to select that option, press the Power button. And if you were successful at unlocking the bootloader you&rsquo;ll see device state has now changed to red unlocked. So now that the bootloader is unlocked, we can proceed on to the next step which is obtaining factory images. We&rsquo;re going to select Download release. And the actual amount of time this takes to download will vary depending on your internet speed. It&rsquo;s gonna take a minute, two minutes or an hour. And so while that&rsquo;s downloading, I just want to mention to consider donating to the project if you&rsquo;re getting any sort of value from it, the developers putting in a lot of work to updates and Supporting new phones as they come out. My favorite way to contribute is using GitHub sponsors, it lets me schedule a monthly recurring donation to them. So again, consider donating to the project donations are used for paying developers purchasing hardware paying for infrastructure. So once the download has finished, it&rsquo;ll say downloaded and the progress bar will be full. So now that the download has completed, we can proceed on with flashing our device, the initial install will be performed by flashing the factory images. This will replace the existing OS installation and wipe all the existing data, give this paragraph or read over. But the most important part is avoid interacting with the device until the flashing script is finished. So once we click flash release, just leave your device alone, don&rsquo;t touch it, wait for it to complete. Once you&rsquo;re ready, select flash release, you&rsquo;ll see the screen changes. And again, just let the device do its thing. Don&rsquo;t interact with it at all.</p>
<p>And so while that&rsquo;s flashing I just want to mention that I have a somewhat monthly newsletter that I send out, you can sign up for that at site of burritos.com. If you&rsquo;re new to privacy and security on your mobile device, I have a page on my website that has an index of all my videos I have. It&rsquo;s a good starting point if you want to get familiar with what options are out there.</p>
<p>And then while we wait for this to complete, one of my friends came to me the other day upset about something they did, I told them some solid life advice, and that was that they needed to embrace their mistakes. So they gave me a hug</p>
<p>so once the flashing has completed, you&rsquo;ll see the text on the screen has changed to flashed, and our phone is back at the bootloader interface. The next step and this is extremely important is to actually lock the bootloader give this a read over it explains why it&rsquo;s so important. But again, to do that, we&rsquo;re going to select Lock bootloader we see the prompt on our screen again, we see it says do not lock the bootloader same as earlier we&rsquo;re going to press the volume up or down until it says lock the bootloader at that point, press the Power button</p>
<p>and if that completes successfully, we&rsquo;ll see device state now says locked and it is green. Congratulations. You&rsquo;ve now successfully installed graphene OS and can boot it. pressing the power button with the default start option selected in the bootloader interface will boot the OS. So if you have the default option selected, it should say start press the power button</p>
<p>you&rsquo;re going to see the screen here devices loading a different operating system. Since we have a nonstock operating system installed, the screen is normal so expect to see that it&rsquo;s also normal to see the Google splash screen. And at this point you&rsquo;ll now see the graphene OS boot animation we&rsquo;ll take a minute for the initial boot we can now walk through the initial setup. Select Start, select your language Next, set your timezone. Next I&rsquo;m going to skip connecting to Wi Fi for now skip I don&rsquo;t have a SIM card in my device but you can put one in if you want. Next, I&rsquo;m going to disable location services for now. Next fingerprint you can set this up if you want to.</p>
<p>I do suggest setting a PIN code at the very least then please set something else besides 12345. Once you type that in and again press confirm if you had a backup from an existing graphene OS installation, you can restore it now. Otherwise, if this is a new installation for you, press skip</p>
<p>and then start so back on the webpage disabling OEM unlocking OEM unlocking can be disabled again in the developer settings menu within the operating system after booting it up again. After disabling OEM unlocking we recommend disabling developer options for a device that&rsquo;s not being used for app or OS development. So we&rsquo;re going to follow the same steps We did it when we initially enabled OEM unlocking, we&rsquo;re going to go into settings, scroll to the bottom, select About phone, go to the bottom, tap build number to be prompted for your PIN code. You are now a developer, select back, go into System developer options. We can see here OEM unlocking is enabled, we want to disable that, please restart the device to enable device protection feature. So we&rsquo;re going to do that in a moment. And then again, we want to disable developer options. So on select that, you need to restart your device to change this setting. Tap Restart. Now on the boot screen, I&rsquo;m going to press my power button. When that initial warning shows up, tell you why in a second.</p>
<p>So pressing the power button pauses the boot. And the reason for that is down below here, we can verify the boot key hash. And so what you want to do depending on the device you have, if it&rsquo;s a pixel six or newer, you want to look at this screen. In my case, I&rsquo;m on the pixel seven. And I want to verify that this string matches what is displayed on my device. So take a minute to do that. Looking at it, I can see it does match. The reason as to why is listed here. So give that a read over. And so once you confirm that, press the Power button again to resume the boot. So at this point, you have successfully installed graphene OS and you can start using it if you like. But if you are new and looking for the simplest way to get started, I want to quickly cover that one feature of graphene OS is they offer sandbox Google Play services on stock Android OS plays services are installed in a way where they bypass the app sandbox and receive a massive amount of highly privileged access. On Griffin OS Play services can be installed as standard apps with no special access or privileges. So if you&rsquo;re new and looking for the simplest way to get started, this is what I recommend. And that&rsquo;s what I will be demonstrating. There&rsquo;s a couple other options if you want a bit more privacy, such as installing them in a separate user profile. And I cover that in a video which I will link down below. But if you&rsquo;re at all hesitant about this switch, and using graphene OS, then I suggest installing them as I&rsquo;m about to demonstrate. Once you get more comfortable, you can watch my other videos or check out different blog posts on some ways to enhance your privacy and security. But for now, take the simplest approach get comfortable and go from there. So the first thing we need to do to install sandbox Play services is connected to Wi Fi. So I&rsquo;m going to swipe down, select Internet, I&rsquo;m going to select my Wi Fi network. Once you&rsquo;ve successfully connected to your Wi Fi, we&rsquo;re going to swipe up, select the Apps app. We&rsquo;re going to go to Google Play Store, select that, as we can see here, it&rsquo;s also going to install a Google services framework and Google Play services. Select Install all it&rsquo;s going to take about five minutes to complete, I will be linking this down below, I do suggest you take the time to read it over, as well as the usage guide that&rsquo;s linked at the bottom. There&rsquo;s a lot of great information in here. It explains how it works, the actual configuration, limitations, things like that. So take the time read it over. There&rsquo;s a lot of good stuff. So once that&rsquo;s completed, you&rsquo;ll see down here and now says open instead of installing. I&rsquo;m just going to swipe up. We&rsquo;re going to swipe up again, go into our app drawer. And you&rsquo;ll now see Play Store listed here. So this will function just like Play Store on stock Android OS, you can select that sign in. If you&rsquo;re looking for a little more privacy, create a separate Google account that you just use on here to download apps and things like that. Go ahead and sign in, download your apps, get yourself started. And then like I said at that point once you&rsquo;re comfortable, check out some of my other videos or different options that are available. On my last piece of advice, privacy and security. It&rsquo;s a journey. Don&rsquo;t try and do everything at once. If you change too much, it&rsquo;ll be hard to keep the habit so take it step by step. Do what you can and every little bit helps.</p>
]]></content>
      </entry>
      <entry>
        <title>Android Full Lock Screen Bypass - Pixel | Demo &#43; Explanation | CVE-2022-20465</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/android-os-full-lock-screen-bypass/" />
        <id>https://staging.sideofburritos.com/blog/android-os-full-lock-screen-bypass/</id>
        <published>2022-11-14T10:00:00Z</published>
        <updated>2022-12-21T10:00:00Z</updated>
        <summary type="html">With all software comes vulnerabilities, and Android OS is no exception. CVE-2022-20465 is a Full Lock Screen bypass that works on various Android devices, including the Google Pixel line.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode17s0hbhb">🎥 


<a href="https://youtu.be/B6q0nJnltsk" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://feed.bugs.xdavidhu.me/bugs/0016" target="_blank" rel="noopener" class="text-break">https://feed.bugs.xdavidhu.me/bugs/0016</a> - Complete Lock Screen Bypass on Google Pixel devices post by David Schütz</li>
<li>


<a href="https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/" target="_blank" rel="noopener" class="text-break">https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/</a> - Accidental $70k Google Pixel: Lock Screen Bypass - by David Schütz</li>
<li>


<a href="https://nitter.net/xdavidhu/status/1590626467414958080" target="_blank" rel="noopener" class="text-break">https://nitter.net/xdavidhu/status/1590626467414958080</a> - Tweet by David Schütz announcing discovery of vulnerability</li>
<li>


<a href="https://source.android.com/docs/security/bulletin/2022-11-01" target="_blank" rel="noopener" class="text-break">https://source.android.com/docs/security/bulletin/2022-11-01</a> - Pixel Update Bulletin—November 2022</li>
<li>


<a href="https://android.googlesource.com/platform/frameworks/base/&#43;/ecbed81c3a331f2f0458923cc7e744c85ece96da" target="_blank" rel="noopener" class="text-break">https://android.googlesource.com/platform/frameworks/base/+/ecbed81c3a331f2f0458923cc7e744c85ece96da</a> - Technical details regarding fix</li>
<li>


<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20465" target="_blank" rel="noopener" class="text-break">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20465</a> - CVE-2022-20465</li>
<li>


<a href="https://support.google.com/pixelphone/answer/4457705" target="_blank" rel="noopener" class="text-break">https://support.google.com/pixelphone/answer/4457705</a> - Support schedule for Pixel Phones</li>
<li>


<a href="https://nitter.net/DanielMicay/status/1590941219462742018" target="_blank" rel="noopener" class="text-break">https://nitter.net/DanielMicay/status/1590941219462742018</a> - Tweet by Daniel Micay regarding scope of vulnerability</li>
<li>


<a href="https://grapheneos.org/features#auto-reboot" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#auto-reboot</a> - GrapheneOS Auto reboot feature</li>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS home page</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>On November 10 2022, I saw a tweet circulating from someone named David shifts that he had found a vulnerability to unlock any Google Pixel. He did a great write up on his blog, including the timeline when he disclosed it to Google explanation of how he found it and decode logic exploits, as well as a demonstration video, all of which I will link down below. The vulnerability exists in the way that the SIM card is unlocked on Android OS using the PUK code, which I will explain a little bit more later, I want to be clear that I have nothing to do with actually discovering this vulnerability. I&rsquo;m just discussing what David shared publicly. And while I was debating and just talking about the video that he shared, it&rsquo;s always a lot cooler to actually show something than just to talk about it, so I decided to test it out myself. To exploit this vulnerability, you need to have a SIM card with a pin which is easy enough anyone can set that through the settings and you also need a PUK code which is either written on the packaging that your SIM card comes in, or you need to call your carrier to get that information. The PUK code is used if you have a pin set on your SIM card and you forget it. Once you enter the PIN incorrectly three times you need to enter the PUK code to unlock it and to set a new pin. The easiest way to test this would be to use the SIM card I already have for my existing cell phone service. But it turns out that my carrier does not keep the PUC codes or does not give them out to users. If you lock yourself out of your SIM card, they just send you a new one. So that was not going to be an option. My next choice was to buy a prepaid SIM card and hope that it had the PUK code printed on the actual packaging. So the first prepaid SIM card I bought from Target since I had to go there anyways, I opened the packaging and there was no PUK code written on it. That means I would need to reach out to the carrier to get the PUK code. So I message them on Messenger through their website. I told them that I set a PIN code I forgot it and locked my sim before I was able to set up service. I asked them if I could get the PUK code to unlock it. They said absolutely we can sure do that for you. So I got pretty excited because usually things do not go so smoothly on a first try. And then the next message said we can give you the PUK code as soon as you sign up for service. After I pushed a few more times the representative kindly closed down the chat and I was out of luck. So I looked up where the nearest Best Buy was and I headed over there in the hopes that they would have a few more options. Thankfully, Best Buy did have more options. So I bought three different ones so I didn&rsquo;t have to keep going back. I live in Florida, so I&rsquo;m pretty sure that the cashier thought I was a dealer buying so many prepaid cards all at the same time. But regardless, I got to my car tore up in the packaging for the three SIM cards and none of them had the PUK code printed on it.</p>
<p>So when I got home, I checked and one of the three carriers had live chat available. So that&rsquo;s the one I started with. I use the exact same story as earlier that I set a PIN code, I forgot it and I needed the PUK code so I could set up service. Thankfully, this time, the support individual was more than happy to give me the code. So we were all set the test. If you watch the recording that David released, it took him one attempt to actually get the screen to unlock on his device, which was a pixel six. For me, I was testing on a pixel six A where I intentionally flashed an out of date version of Android OS that had the October 2022 security patch, which means it was vulnerable to this exploit. And while it did end up working and unlocking my device, as you&rsquo;ll see, it did take me about 10 minutes to actually get it to work. So the first thing I&rsquo;m doing is failing the fingerprint authentication so that a PIN code is required so that I can show you that the phone is indeed locked. This is not required but make the demonstration a little more realistic. So the next step is to eject the SIM card slot on the device and then insert the SIM card that you set a PIN code on and that you know the PUK code for once you place that in the device, you&rsquo;re going to get this screen asking for the sim pin. And what you want to do next is incorrectly enter the sim pin three times as fast forwarding this part because I&rsquo;m adjusting my camera and then after you enter the sim PIN code and correctly three times you&rsquo;re presented with this screen which is asking for the PUK code. You then enter the PUK code correctly, which lets you set a new pin. Once you do that, you&rsquo;ll see the unlocking SIM card. And on the screen you might have seen it it was quick. But we saw the lock screen glitch and show us the Settings screen, which is the screen I have open currently on the pixel six A that I&rsquo;m testing this on, this is the part that I didn&rsquo;t see in David&rsquo;s video, at least on the six A it took me multiple times as you&rsquo;ll see, to actually get the lock screen to disappear. So I don&rsquo;t know exactly what&rsquo;s happening in the background that&rsquo;s making this not unlock on the first time. But at this point I&rsquo;m going to fast forward my next attempts so your eyes do not bleed from watching the same thing over and over again. And so while we wait for my unlock to be successful, let&rsquo;s talk about exactly how this works. From what I understand at this time. This works because of a race condition that&rsquo;s occurring in the sim unlock process. And don&rsquo;t worry if you don&rsquo;t completely understand my explanation the blog at LinkedIn the district Shouldn&rsquo;t goes into more details if you want to read up on it. But on Android, there&rsquo;s a concept of security screens when the fingerprint screen is displayed. That&rsquo;s a security screen. When the pin on lock is displayed, that&rsquo;s a security screen. These screens can also be layered on top of one another. So in this example, we have the PIN code security screen. And on top of that is the PUK code security screen. When the sim puck reset is successful, it issues a dismiss function, the dismiss function it calls does not specify which security screen is going to dismiss. So whichever security screen is active is the one that is dismissed. So what appears to be happening is that the puck reset is completing successfully, the puck reset is then calling the dismiss function. But something is changing in the background that&rsquo;s making the PIN code security screen the active security screen instead of the puck code security screen. So therefore, instead of the puck security screen being dismissed, the PIN code security screen is dismissed and the phone is unlocked. And so we&rsquo;re now back to normal speed because this is the attempt that unlocks my device. And there&rsquo;s a couple things I want to point out that I noticed. So right after you enter the third sin pin incorrectly, the lock screen actually flashes and you can see the time there. That doesn&rsquo;t happen on the previous attempts that were unsuccessful. The previous attempts would instantly show the PUK code the screen, and whenever that happened, the unlock was unsuccessful. So we can see here unlocking SIM card, and we now see the screen that was left open on my Pixel six A, the device is completely unlocked. We can swipe up see all the apps the device works as if we successfully unlocked it. So the main reason I made this video is to try and communicate that timely security updates matter vulnerabilities exist in all software just waiting to be discovered. And timely security updates are the only way that you can ensure that you&rsquo;re protected quick updates might seem like a boring feature to look for in a mobile OS, but you need them. The fix for this is in the November 2022 security patch from Google to check if your Android device is patched, you can go into settings, about phone, tap on Android version, you can then look at the date for the Android security update. And if your phone isn&rsquo;t up to date, update it.</p>
<p>If you&rsquo;re using an OS with delayed updates, consider switching to another OS with faster updates. And if your phone is no longer supported with security updates, I guess this is more of an FYI. So that you understand the risk of using end of life hardware, you can&rsquo;t have privacy without security. And this is just one example to show that. One example of an OS that still isn&rsquo;t patched yet is lineage OS. I just installed this last night on a pixel five A. And as we can see, it&rsquo;s still in the October 2022 security update, which means it is vulnerable. It&rsquo;s also running android 12, which in my testing works every time you try this exploit. And as of the time of this recording, which is November 12 2022. I did confirm that graphene OS calyx, OS and stock Android OS are all up to date and are no longer vulnerable to this exploiting. The last thing I want to talk about is a feature on the OS that I recommend and use, which is Griffin OS. The feature is called Auto reboot. You can access this by going to your Settings Security, and selecting auto reboot. The option you select determines how long until your phone auto reboots after the last successful unlock. So in my case, if I don&rsquo;t unlock my phone in a 12 hour time period, it reboots. Now, you might be asking yourself, Josh, how&rsquo;s this supposed to help me if the lock screen can be bypassed. So it&rsquo;s important to remember that if you just restarted your device, and you have not entered your PIN code successfully, at least once, then the user data on your device is still encrypted. And so while this exploit bypasses the lock screen, it has nothing to do with the encryption of your data. So as an example, I use this exploit after a reboot, and we can see the phone just hangs on pixels starting. The phone never gets past this point because the user data is still encrypted and safe. So let&rsquo;s say that you were out somewhere in October, you lost your phone and someone found it. A few weeks later, it&rsquo;s November, the individual that found your device came across this exploit and wants to see if they can get into your phone. So luckily, you had the auto reboot feature enabled 12 hours after the individual found your device and rebooted itself. And while they were able to get past the initial lock screen, since your device was not fully up to date, that individual was not able to actually get your data since it was still safe and encrypted. And so while this protection is imperfect, that does decrease the window of opportunity for the malicious actor.</p>
<p>So as far as the scope of this vulnerability goes, Daniel McKay covered that in a tweet. I&rsquo;m paraphrasing what he shared, but this is an Android vulnerability, not something specifically related to the Google Pixel, depending on what a vendor altered in their fork of aos P. They may not be impacted by this, but if they use close to unaltered aos P will likely be impacted. And lastly, I want to mention that while this might seem like a basic oversight by a developer vulnerabilities like this exist in all code and will continue to be discovered, so keep your software up to date and do protection so keep your software up to date to make sure that you stay protected</p>
]]></content>
      </entry>
      <entry>
        <title>How to install GrapheneOS on Google Pixel 6a (GP6a) &#43; Setup for new users</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel6a/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel6a/</id>
        <published>2022-11-06T10:00:00Z</published>
        <updated>2022-12-21T10:00:00Z</updated>
        <summary type="html">The Google Pixel 6a is a great mobile device. With the Google Tensor chip, it&amp;#39;s one of the most secure mobile devices you can purchase.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode82s0hbhb">🎥 


<a href="https://youtu.be/qruzL9IdUr8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/install/web" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/install/web</a> - GrapheneOS Web installer</li>
<li>


<a href="https://nitter.net/DanielMicay/status/1552966692749414402#m" target="_blank" rel="noopener" class="text-break">https://nitter.net/DanielMicay/status/1552966692749414402#m</a> - Twitter thread explaining OEM unlocking</li>
<li>


<a href="https://grapheneos.org/donate" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/donate</a> - GrapheneOS donation page</li>
<li>


<a href="https://grapheneos.org/features#sandboxed-google-play" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#sandboxed-google-play</a> - Sandboxed Google Play details</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So the main purpose of today&rsquo;s video is to install graphene OS on the Google Pixel six a specifically, the process will be similar regardless of which pixel you have. But the one I&rsquo;m demonstrating on today is the six A, we&rsquo;re going to be following the instructions on graphene os.org. I&rsquo;ll put the link down below in the description as well as on the screen right now. And we will be using the web installer, it&rsquo;s essentially impossible to break your phone using the web installer. So don&rsquo;t be scared to try this, I&rsquo;ve done the process probably about 50 to 100 times at this point, I&rsquo;ve never had an issue with it. Now that being said, there are some issues that come up for some individuals when they are going through the install process. And I will point those out throughout the video for any tips, you can try to overcome those. But with that out of the way, let&rsquo;s begin the installation process. So we&rsquo;re at Griffin os.org, the web installer, we&rsquo;re going to go down to the prerequisites, give this a read through the supported OS. I&rsquo;m installing this from Mac OS today using brave browser, make sure you are using a supported browser and a supported OS. Otherwise you will encounter issues. This is a very important note for those on Ubuntu. If you&rsquo;re using chromium that is broken and will not work. So make sure if you&rsquo;re on a boon to you are not using chromium. So once you know you&rsquo;re using a supported browser and OS, we can continue, make sure to give all this a read through I&rsquo;m not going to waste your time reading it to you. But there&rsquo;s some other important bits of information in here such as Do not use an incognito browser or private browser. Because again, you will encounter issues. So once you make sure all the prerequisites are met, we are on to enabling OEM unlocking. So just a note about where you get your information from always go to the source directly, in this case, Griffin os.org. That&rsquo;s why I&rsquo;m following along in their guide when showing you the developers do a great job documenting the installation process and different features. Always go to the source. First, don&rsquo;t trust some random YouTuber talking about it, or some random forum posts that you saw, you&rsquo;ll always get the best information directly from the source. So the first step for this OEM unlocking needs to be enabled from within the operating system, enable the developer options by going into settings about and pressing the build number entry until developer mode is enabled. So I&rsquo;m going to be demonstrating this, like I just took my pixel out of the box. When you turn it on for the first time, you will see this screen. If you already past the initial setup, and you want to skip ahead, I&rsquo;ll have that in the play bar below. So you can skip this section. But if you&rsquo;re here, go ahead and press Get Started. I don&rsquo;t have a SIM card in the phone yet. So go ahead and click Skip. So you could connect to Wi Fi at this point. But I like to skip this because we don&rsquo;t need a Wi Fi connection, we can set up the pixel offline first. So we&rsquo;re gonna go to Setup offline. Just a quick warning about setting up offline continue. Date and time. I uncheck these just for good practice. Except Except it&rsquo;s always good practice to set a pin. Even if you&rsquo;re just going to be erasing the OS quick. Sometimes I don&rsquo;t but you should anyways.</p>
<p>No fingerprint, no thanks. Skip, and then swipe up to go home. So at this point, we&rsquo;re on the home screen, the first step is to go into settings about so swipe up,</p>
<p>you&rsquo;ll see settings, go to Settings, scroll down to the bottom, we&rsquo;re going to go into about phone, scroll down at the bottom here you see build number. Now tap on that you will get this screen if you set a PIN number, type in the pin. And we can now see you are now a developer. So developer options are enabled. And that&rsquo;s where the setting for OEM unlocking will be located. So next, go into settings, system developer options and toggle OEM unlocking. So we&rsquo;re gonna go back word in the settings, so go to System developer options. And here&rsquo;s the option to enable OEM unlocking. So there&rsquo;s a couple things to note about OEM unlocking. So if you purchase your device brand new OEM unlocking will be grayed out and you won&rsquo;t be able to enable it. The reason for that is that you need to actually connect to Wi Fi at this point before you can enable OEM unlocking. So we can see here OEM unlocking requires Internet access so that the stock OS can check if the device was sold as locked by a carrier. And so what does that actually mean? So the founder and lead developer of graphene OS has a thread on Twitter describing how OEM unlocking actually works, which again, I&rsquo;ll link down below if you want to read through it. So essentially, how that works is that Google has a database of the pixels serial numbers and which ones were sold as an unlocked device not locked by the carrier. Your device will check with Google if the device is enabled for OEM unlocking after you connect to the internet. You will then be able to enable OEM unlocking. If your device checks with Google and your serial number is not authorized for unlocking, then that option will remain grayed out because it&rsquo;s locked by the carrier devices that are commonly locked or Verizon branded pixels. So if you have a Verizon pixel, you will not be able to enable OEM unlocking and you cannot install graphene unless your only option is to return it or sell it and buy a OEM, unlockable pixel. For me personally, I buy my devices directly from Google as unlocked, so I know that it&rsquo;s unlockable, I don&rsquo;t need to worry about it being locked. If you decide to buy used online, I would suggest asking the seller to confirm if OEM unlocking is available, had them send you a screenshot so that you know, I&rsquo;ve made the mistake in the past of buying a locked pixel, I had to return it. So don&rsquo;t make the same mistake as me. One other note on the site is so for the pixel six A, this phone in particular, if you&rsquo;re using one, unlocking won&rsquo;t work with the version of the stock OS from the factory, you need to update it to the June 2022 release or later, via and over the air update. After you&rsquo;ve updated it, you also need to factory reset the device to fix the OEM unlocking issue. So depending on when you bought your pixel, this may not be an issue for you. This pixel was purchased around a month ago, and it shipped with the newer updates. And I did not have to factory reset or follow this at all to get it to work. But if you purchased a pixel earlier, you may need to do this and follow these steps to actually get OEM unlocking to work. So I&rsquo;ve unlocked this device in the past, which is why OEM unlocking is available. So again, connect to Wi Fi, if it&rsquo;s not, if your device is able to be unlocked after a checksum with Google, you will then be able to enable it, enable OEM unlocking if you have a pin set you need to enter it. Allow OEM unlocking enable, and we can now see it&rsquo;s enabled. So on to the next step flashing as non root. This is for Linux distributions, I&rsquo;m not going to cover this part. So the next step is booting into the bootloader interface, you need to boot your phone into the bootloader interface. To do this, you need to hold the Volume Down button while the phone boots. The easiest approach is to reboot the phone and begin holding the Volume Down button until it boots up into the bootloader interface. So now what that looks like we have OEM unlocking enabled. Going to swipe down, going to pull down again, in the bottom right hand corner is the power button. And then from here, we&rsquo;re going to select Restart, hold down the volume down button on the right side of the phone. So as you saw that took about 10 seconds. And once you see this screen, we are in the bootloader interface. If the screen doesn&rsquo;t come up for you, the phone will just boot up like normal, try restarting and again, hold the Volume Down button until you get to this screen. So the next step is actually connecting the phone to our computer. And so for this step I want to mention, make sure you use the stock cable that actually came with your device. Now that being said, the most common issue that I&rsquo;ve heard others talk about is that their computer doesn&rsquo;t see the phone. And that&rsquo;s because they have a faulty USB cable. So if you plug in your USB cable to your computer with your phone, and it doesn&rsquo;t see it or you have any other strange issues when downloading the OS later in this guide, go ahead and try a different USB cable, and likely that&rsquo;ll solve your issue. Also, when connecting the USB cable to your computer connected directly to your computer, don&rsquo;t connect it through a dongle that&rsquo;s plugged into another port. While it still might work. This could lead to some other strange issues. Let&rsquo;s go ahead and connect the USB cable to our device. So just some notes here. If you&rsquo;re using Windows on Windows, you need to install the driver for fastboot. If you don&rsquo;t already have it, you can obtain the driver from Windows Update, which will detect it as an optional update when the device is booted into the bootloader interface and connected to the computer. So you should see a little pop up if you&rsquo;re on Windows. Another method is to go here and just download the driver manually. But the easiest option will likely be through Windows Update. So once you have your device connected to your computer with a USB cable, and you have all the drivers installed, if you&rsquo;re on Windows, the next step is unlocking the bootloader. It&rsquo;s important to note that unlocking the bootloader will erase the device and wipe all data. It&rsquo;s impossible to recover your data if you erase it. So make sure if you had any contacts or calendar events or photos that you need to save that you save those before proceeding because your device will be erased. So if you&rsquo;re ready to continue, we&rsquo;re going to press the unlock bootloader button, you&rsquo;ll see this prompt in your browser. If you have issues or if the drivers didn&rsquo;t install or you&rsquo;re using an unsupported browser, you&rsquo;ve likely will not see your phone here. If that&rsquo;s the case, the first and easiest step, go through again, if you&rsquo;re on Windows, make sure you install the drivers. And what I usually suggest to people is if you&rsquo;re not using Google Chrome, just go ahead and install it even if it&rsquo;s temporary google chrome Rome is supported and will work. So that&rsquo;s one easy way to rule out that your browser is the issue. But if you do see it in your browser, and you see you can select your phone, go ahead and select Connect, you&rsquo;re going to see this warning on the phone, take a second to read that through. Once you do, press the volume down or up button, so that it says unlock the bootloader. And once you see that, press the Power button to select that. And if this was successful, you will now see device state red unlocked, as compared to before where it was green and said locked. So once you see device state unlocked, we&rsquo;re ready to proceed on to the next step. Next one is obtaining the factory images. So go ahead and press download release. This will download the release in your browser. Depending on your internet connection speed. This could take a minute, a few minutes or an hour. And so while that&rsquo;s downloading it, just want to mention that once you start using graphene OS consider donating to the project. The developers put in a lot of hard work supporting current devices and new devices very quickly. The donations are used for paying developers and purchasing hardware. Me personally, I like the GitHub sponsors option. So I set that up. So I have a reoccurring monthly donation. And again, I&rsquo;ll link this down below. So you can check out the page and set up your donation. And so once that finishes, you&rsquo;ll see the progress bar is full and this will say downloaded and then the name of the release dot zip. And the next step is to actually flash the image to our device. So the initial install be performed by flashing the factory images. This will replace the existing OS installation and wipe all existing data. The main thing to note here is avoid interacting with the device until the flashing script is finished and the device is back at the bootloader interface. So once you&rsquo;re ready, select flash release, you&rsquo;ll see your screen change waiting bootloader. And your device will now flash and go through the entire process. And again, this will probably take five to 10 minutes. So while that&rsquo;s flashing and you and I are both waiting for this to finish, I just want to mention that I have a monthly newsletter that I send out, you can sign up for that at side of burritos.com. So the other day I was talking to my best friend who was a truck driver and he asked me if I knew what frogs did when their car breaks down. I said no, I do not know what frogs do when their car breaks down. And he said they get it towed. So with that great joke out of the way I&rsquo;m going to fast forward the video and I will see you shortly</p>
<p>so once that&rsquo;s completed, for me, it took about five minutes for that to complete. You will see flashed and then again the name dot zip to device. And I want to the next step which is locking the bootloader which is extremely important as it enables full verified boot. And some of the reasons why this is extremely important are in the rest of this paragraph, which I would suggest you read over. So to do that, we&rsquo;re going to select Lock bootloader again, we can see do not lock the bootloader use the volume up or down to change that. When it says lock the bootloader Press the Power button to select and once that is successful, you will see device state is now green locked. So once that&rsquo;s completed, we can go on to the next step post installation booting. You&rsquo;ve now successfully installed graphene OS congratulations and can boot it. pressing the power button with the default start option selected in the bootloader interface will boot the OS. So we can see here it says start press the power button the screen is normal. Do not be afraid if you see that we have a customer lesson installed. Seeing the Google screen is normal and then once you see the graphene OS screen, this is now the boot animation booting into graphene OS so the next step after booting is disable OEM unlocking. So for that we have to go to the initial setup. So start set your language, date and time set that we&rsquo;re going to skip Wi Fi for now. I don&rsquo;t have a SIM card if you do, you can put it in now just turn location services off by default. Next, I&rsquo;m going to skip fingerprint setup but you can set that up if you want. I&rsquo;m just going to set a PIN code quick just for the demo but again, set a secure PIN code along with fingerprint if you want. I don&rsquo;t have a backup to restore from Skip and start. So we have now reached the GrapheneOS home screen. And now to disable OEM unlocking we&rsquo;re gonna go into settings. We&rsquo;re going to scroll down again to About phone. Go to the bottom tap Build Number or type in the PIN code. We can now see your now developer, go back system developer options.</p>
<p>Disable OEM unlocking, please restart the device to enabled device protection feature. And also, I&rsquo;m going to disable developer options, you don&rsquo;t really need those enabled,</p>
<p>we can now see developer options are gone. So as the instruction said, Let&rsquo;s Reboot the device, since we disabled OEM unlocking, restart so I&rsquo;m just gonna press the power button quick, so I can pause it on the screen. So the next part, verifying installation, give this a read over some very good information. This verified boot key hash, the reason I paused it by pressing the power button on boot is that we can verify the boot key hash. And here we have the pixel six A in this example, can make sure the number matches there. Which does so we&rsquo;re good to go. So I&rsquo;m gonna press the power button to resume. So I&rsquo;m just gonna log in quick. So the next thing I want to cover quick is what I think is the best setup for anyone that&rsquo;s new to Griffin OS. If you&rsquo;ve read around, there&rsquo;s a lot of videos, including my own channel or blog post that talks about using F Droid or Aurora store or all these different things you can do to increase your privacy and security. And while some of them are valid, it can be a bit overwhelming for anyone that&rsquo;s new. So what I&rsquo;m going to do is show you a basic initial setup that I think is best for anyone that&rsquo;s new here. So for that we need to connect to Wi Fi.</p>
<p>And some other Wi Fi is connected, we can proceed on, we&rsquo;re going to swipe up, we&rsquo;re going to go into apps.</p>
<p>And the apps app support allows you to install different apps that are provided by Griffin OS. In this case, we&rsquo;re going to be installing the sandbox Google Play services. Again, like I said, this is going to be a basic setup for anyone that&rsquo;s new, I get a lot of messages from people that say they&rsquo;re new to privacy or the security community. And it&rsquo;s overwhelming at first they get a VPN, they get a new phone, they get this, they get that they want to use F droid. And I can understand how that&rsquo;s overwhelming. And that&rsquo;s why don&rsquo;t suggest trying to do everything at first, privacy and security as a journey. You can&rsquo;t do it all at once. Because if something&rsquo;s too difficult, you&rsquo;re not going to stick with it, you&rsquo;re gonna give up easily. And that&rsquo;s why I think it&rsquo;s easier to go ahead and install the sandbox Play services use Google Play, like we&rsquo;re about to do and start there. Once you get comfortable with the OS, you can make changes one by one, you can check out some other videos I have, you can see different suggestions that users might have online. But the first step is getting a solid base that you&rsquo;re comfortable with using Griffin OS. And I think sandbox Google Play services are a great place to start. So to do that, we&rsquo;re going to go down to the bottom, and we want to install Google Play Store. We can see here it&rsquo;s going to install these other two dependencies, services framework and Play services. So select Install. All right. So that took about three minutes, we can now see that it&rsquo;s finished. Because we see the Open option. You can either select open, or you can go swipe up. And you&rsquo;ll now see Play stores installed. This is the same Play Store you&rsquo;d get on Android OS except on graphene OS it&rsquo;s sandboxed and installed as a normal app instead of an app with system level access. So select the Play store. You can select Sign In. And then at this point, you can either sign in with your personal Gmail account. Or another option if you want a little bit of increased privacy, create a separate gmail account that you can use specifically for this. That&rsquo;s not tied to anything else you have. If you have paid for apps, you can sign in with that account. You can installed paid apps like anything else. And since we now have all the Google services installed in our device, notifications, and everything else will work as expected. And if you&rsquo;ve used Android in the past, this is going to feel like the standard Android experience.</p>
]]></content>
      </entry>
      <entry>
        <title>How your phones&#39; wallpaper can be used to track you</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/wallpaper-privacy/" />
        <id>https://staging.sideofburritos.com/blog/wallpaper-privacy/</id>
        <published>2022-08-07T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Is that family photo a simple personalization to your wallpaper, or is that being used to track you?</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode123s0hbhb">🎥 


<a href="https://youtu.be/cwLRiadmfaQ" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://fingerprint.com/blog/how-android-wallpaper-images-threaten-privacy/" target="_blank" rel="noopener" class="text-break">https://fingerprint.com/blog/how-android-wallpaper-images-threaten-privacy/</a> - privacy.com main article referenced</li>
<li>


<a href="https://github.com/fingerprintjs/blog-android-wallpaper-id-demo" target="_blank" rel="noopener" class="text-break">https://github.com/fingerprintjs/blog-android-wallpaper-id-demo</a> - WallpaperID App used in demo</li>
<li>


<a href="https://developer.android.com/reference/android/app/WallpaperManager#getWallpaperColors%28int%29" target="_blank" rel="noopener" class="text-break">https://developer.android.com/reference/android/app/WallpaperManager#getWallpaperColors(int)</a> - Android source code - getWallpaperColors</li>
<li>


<a href="https://cs.android.com/android/platform/superproject/&#43;/master:frameworks/base/core/java/com/android/internal/graphics/palette/VariationalKMeansQuantizer.java;l=31?q=KMeansQua&amp;ss=android%2Fplatform%2Fsuperproject" target="_blank" rel="noopener" class="text-break">https://cs.android.com/android/platform/superproject/+/master:frameworks/base/core/java/com/android/internal/graphics/palette/VariationalKMeansQuantizer.java;l=31?q=KMeansQua&ss=android%2Fplatform%2Fsuperproject</a> - getWallpaperColors source code - K-means clustering</li>
<li>


<a href="https://www.clear.rice.edu/elec301/Projects02/artSpy/patmac/RGB.jpg" target="_blank" rel="noopener" class="text-break">https://www.clear.rice.edu/elec301/Projects02/artSpy/patmac/RGB.jpg</a> - 3D color cube</li>
<li>


<a href="https://clarle.github.io/yui3/yui/docs/color/rgb-slider.html" target="_blank" rel="noopener" class="text-break">https://clarle.github.io/yui3/yui/docs/color/rgb-slider.html</a> - RGB sliders</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>FULL reveal of what apps I use on my personal phone | GrapheneOS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/app-i-use-on-my-personal-phone/" />
        <id>https://staging.sideofburritos.com/blog/app-i-use-on-my-personal-phone/</id>
        <published>2022-07-31T12:57:39Z</published>
        <updated>2022-08-10T12:57:39Z</updated>
        <summary type="html">If you&amp;#39;re curious what apps I use on my personal device, here they are.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode21s0hbhb">🎥 


<a href="https://youtu.be/FEN_NvKsVBc" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<h2 id="my-other-videos-i-referenced">My other videos I referenced</h2>
<ul>
<li>


<a href="https://youtu.be/NJzA9yRGgeM" target="_blank" rel="noopener" class="text-break">🎥 Storing your contacts in the cloud</a></li>
<li>


<a href="https://youtu.be/ocwznyrMVwE/" target="_blank" rel="noopener" class="text-break">🎥 Storing your calendar events in the cloud</a></li>
<li>


<a href="https://youtu.be/9R6M4NuBTi4" target="_blank" rel="noopener" class="text-break">🎥 Calling a scammer</a></li>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">🎥 You should uninstall F-Droid - Part 1</a></li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">🎥 You should uninstall F-Droid - Part 2</a></li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">🎥 You should use this instead of F-Droid | How to use app RSS feed</a></li>
</ul>
<h2 id="full-list-of-apps-i-have-installed-as-of-2022-07-31">Full list of apps I have installed (as of 2022-07-31)</h2>
<ul>
<li>1Password</li>
<li>Aegis</li>
<li>AntennaPod</li>
<li>Aurora Store</li>
<li>Briar</li>
<li>Burner</li>
<li>Cube ACR</li>
<li>DAVx⁵</li>
<li>Geometric Weather</li>
<li>Google Camera</li>
<li>Magic Earth</li>
<li>Mullvad VPN</li>
<li>NewPipe</li>
<li>Nextcloud</li>
<li>OpenVPN</li>
<li>Play Store</li>
<li>Plex</li>
<li>Read You</li>
<li>Signal</li>
<li>Simple Calendar Pro</li>
<li>Sonos</li>
<li>Spotify</li>
<li>Syncthing</li>
<li>Todoist</li>
<li>Twidere</li>
<li>UniFi Network</li>
<li>UniFi Protect</li>
<li>UptimeRobot</li>
<li>Vanadium</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>F-Droid, Droid-ify, Aurora Droid, Neo Store, Google Play, Aurora Store - What should you use?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/app-stores-explained/" />
        <id>https://staging.sideofburritos.com/blog/app-stores-explained/</id>
        <published>2022-07-17T12:57:39Z</published>
        <updated>2022-08-10T12:57:39Z</updated>
        <summary type="html">There are multiple apps stores available on Android which can make it a bit confusing to know what each one might be used for.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode22s0hbhb">🎥 


<a href="https://youtu.be/JMSiTFLpUP8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<p>


<a href="Diagram%20from%20video.png" target="_blank" rel="noopener" class="text-break">Full Size Diagram from video</a> -
To download a full-size copy of the image, <code>Right-Click</code> the <code>Full Size Image</code> link and select <code>Save Link As</code> (or just click it to view)</p>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<h2 id="my-previous-f-droid-videos">My previous F-Droid videos</h2>
<ul>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">You should uninstall F-Droid - Part 1</a></li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">You should uninstall F-Droid - Part 2</a></li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">You should use this instead of F-Droid | How to use app RSS feed0</a></li>
</ul>
<h2 id="app-store-links">App Store Links</h2>
<ul>
<li>


<a href="https://github.com/NeoApplications/Neo-Store" target="_blank" rel="noopener" class="text-break">Droid-ify (Now Neo Store)</a></li>
<li>


<a href="https://auroraoss.com/" target="_blank" rel="noopener" class="text-break">Aurora Store</a></li>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">F-Droid</a></li>
<li>


<a href="https://gitlab.com/AuroraOSS/auroradroid" target="_blank" rel="noopener" class="text-break">Aurora Droid</a></li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://wonderfall.dev/fdroid-issues/" target="_blank" rel="noopener" class="text-break">Blog post on F-Droid Security (Great read)</a></li>
<li>


<a href="https://f-droid.org/en/docs/Inclusion_Policy/" target="_blank" rel="noopener" class="text-break">F-Droid Inclusion Policy</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should use this instead of F-Droid</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/use-this-instead-of-f-droid/" />
        <id>https://staging.sideofburritos.com/blog/use-this-instead-of-f-droid/</id>
        <published>2022-07-10T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">F-Droid has issues. Using this method is a way to completely bypass using F-Droid to install open source apps.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode122s0hbhb">🎥 


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<h2 id="my-previous-two-f-droid-videos">My previous two F-Droid videos</h2>
<ul>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">https://youtu.be/IzpVI4zaso0</a> - You should uninstall F-Droid - Part 1</li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">https://youtu.be/lAbgeJau3eE</a> - You should uninstall F-Droid - Part 2</li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://en.wikipedia.org/wiki/RSS" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/RSS</a> - RSS Feeds</li>
<li>


<a href="https://github.com/Ashinch/ReadYou" target="_blank" rel="noopener" class="text-break">https://github.com/Ashinch/ReadYou</a> - Read You Github page</li>
<li>


<a href="https://discuss.grapheneos.org/d/16-f-droid-auto-updates/5" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/16-f-droid-auto-updates/5</a> - Forum post about using RSS reader</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should uninstall F-Droid - Part 1</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt1/" />
        <id>https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt1/</id>
        <published>2022-06-19T10:00:00Z</published>
        <updated>2022-12-26T10:00:00Z</updated>
        <summary type="html">If you&amp;#39;re going to use F-Droid for apps, there are a few things that you should be aware of.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode127s0hbhb">🎥 


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://privsec.dev/posts/android/f-droid-security-issues/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/android/f-droid-security-issues/</a> - Main article referenced on F-Droid</li>
<li>


<a href="https://en.wikipedia.org/wiki/Android_version_history#Android_7.0_Nougat" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Android_version_history#Android_7.0_Nougat</a> - Android version history</li>
<li>


<a href="https://developer.android.com/studio/releases/platforms" target="_blank" rel="noopener" class="text-break">https://developer.android.com/studio/releases/platforms</a> - SDK Releases</li>
<li>


<a href="https://gitlab.com/fdroid/fdroidclient/-/blob/2a8b16683a2dbee16d624a58e7dd3ea1da772fbd/app/build.gradle#L33" target="_blank" rel="noopener" class="text-break">https://gitlab.com/fdroid/fdroidclient/-/blob/2a8b16683a2dbee16d624a58e7dd3ea1da772fbd/app/build.gradle#L33</a> - F-Droid code showing legacy SDK</li>
<li>


<a href="https://github.com/NeoApplications/Neo-Store" target="_blank" rel="noopener" class="text-break">https://github.com/NeoApplications/Neo-Store</a> - Droidi-fy</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid homepage</li>
<li>


<a href="https://discuss.grapheneos.org/d/16-f-droid-auto-updates/4" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/16-f-droid-auto-updates/4</a> - F-Droid discussion on auto-updates</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS Profiles - Work Profiles vs User Profiles | Shelter &amp; Insular</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-profiles-work-vs-user/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-profiles-work-vs-user/</id>
        <published>2022-05-22T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">There is a massive different between User Profiles and Work Profiles. It&amp;#39;s important to understand the differences between them before choosing which one is right for you.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode67s0hbhb">🎥 


<a href="https://youtu.be/20C0FD7mGDY" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.reddit.com/r/GrapheneOS/comments/g0ly0j/islandshelter_on_grapheneos/" target="_blank" rel="noopener" class="text-break">https://www.reddit.com/r/GrapheneOS/comments/g0ly0j/islandshelter_on_grapheneos/</a></li>
<li>


<a href="https://developer.android.com/work/managed-profiles" target="_blank" rel="noopener" class="text-break">https://developer.android.com/work/managed-profiles</a> - Android Work Profile Details</li>
<li>


<a href="https://www.reddit.com/r/GrapheneOS/comments/fpc2av/apps_are_meant_to_be_able_to_enumerate_other_apps/" target="_blank" rel="noopener" class="text-break">https://www.reddit.com/r/GrapheneOS/comments/fpc2av/apps_are_meant_to_be_able_to_enumerate_other_apps/</a></li>
<li>


<a href="https://grapheneos.org/faq#encryption" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/faq#encryption</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Most Secure Phone 2022 | DeGoogle Your Phone | Google Pixel 6?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/most-secure-phone-2022/" />
        <id>https://staging.sideofburritos.com/blog/most-secure-phone-2022/</id>
        <published>2022-05-22T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Could the Google Pixel 6 be the most secure phone in 2022? With five years of security upgrades and the most layers of hardware security, the Pixel 6 and Pixel 6 Pro are the most secure Pixel phones yet.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode101s0hbhb">🎥 


<a href="https://youtu.be/1nj3vnHvn84" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://security.googleblog.com/2021/10/pixel-6-setting-new-standard-for-mobile.html" target="_blank" rel="noopener" class="text-break">https://security.googleblog.com/2021/10/pixel-6-setting-new-standard-for-mobile.html</a> - Pixel 6 New Security Features</li>
<li>


<a href="https://source.android.com/security/biometric" target="_blank" rel="noopener" class="text-break">https://source.android.com/security/biometric</a></li>
<li>


<a href="https://www.wired.com/story/google-pixel-6-tensor-chip-security/" target="_blank" rel="noopener" class="text-break">https://www.wired.com/story/google-pixel-6-tensor-chip-security/</a></li>
<li>


<a href="https://www.engadget.com/google-tensor-soc-pixel-6-chip-170059466.html" target="_blank" rel="noopener" class="text-break">https://www.engadget.com/google-tensor-soc-pixel-6-chip-170059466.html</a></li>
<li>


<a href="https://cpl.thalesgroup.com/2014/01/14/random-numbers-and-cryptography" target="_blank" rel="noopener" class="text-break">https://cpl.thalesgroup.com/2014/01/14/random-numbers-and-cryptography</a></li>
<li>


<a href="https://www.androidcentral.com/what-titan-security-module" target="_blank" rel="noopener" class="text-break">https://www.androidcentral.com/what-titan-security-module</a></li>
<li>


<a href="https://www.androidcentral.com/how-does-google-titan-m2-and-tensor-security-core-work" target="_blank" rel="noopener" class="text-break">https://www.androidcentral.com/how-does-google-titan-m2-and-tensor-security-core-work</a></li>
<li>


<a href="https://www.androidcentral.com/what-titan-security-module" target="_blank" rel="noopener" class="text-break">https://www.androidcentral.com/what-titan-security-module</a></li>
<li>


<a href="https://source.android.com/security/trusty" target="_blank" rel="noopener" class="text-break">https://source.android.com/security/trusty</a></li>
<li>


<a href="https://arstechnica.com/gadgets/2021/11/pixel-6-review-google-hardware-finally-lives-up-to-its-potential/" target="_blank" rel="noopener" class="text-break">https://arstechnica.com/gadgets/2021/11/pixel-6-review-google-hardware-finally-lives-up-to-its-potential/</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Secure Contacts Storage | Free Cloud Storage Android | Nextcloud</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/secure-contacts-app/" />
        <id>https://staging.sideofburritos.com/blog/secure-contacts-app/</id>
        <published>2022-05-22T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">If you&amp;#39;re looking to regain your privacy, it&amp;#39;s time to use Nextcloud. Storing your contacts with Google or Apple gives them all the details on whom you&amp;#39;re in contact with.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode116s0hbhb">🎥 


<a href="https://youtu.be/NJzA9yRGgeM" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://nextcloud.com" target="_blank" rel="noopener" class="text-break">https://nextcloud.com</a> Nextcloud Homepage</li>
<li>


<a href="https://nextcloud.com/signup/" target="_blank" rel="noopener" class="text-break">https://nextcloud.com/signup/</a> - Nextcloud Account Signup</li>
<li>


<a href="https://www.howtogeek.com/448829/how-to-export-apple-icloud-and-iphone-contacts-to-windows-10/" target="_blank" rel="noopener" class="text-break">https://www.howtogeek.com/448829/how-to-export-apple-icloud-and-iphone-contacts-to-windows-10/</a> - How to export iCloud contacts</li>
<li>


<a href="https://support.google.com/contacts/answer/7199294?hl=en&amp;co=GENIE.Platform=Desktop" target="_blank" rel="noopener" class="text-break">https://support.google.com/contacts/answer/7199294?hl=en&co=GENIE.Platform=Desktop</a> - How to export Google Contacts</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should uninstall F-Droid - Part 2</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt2/" />
        <id>https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt2/</id>
        <published>2022-05-22T10:00:00Z</published>
        <updated>2022-08-22T10:00:00Z</updated>
        <summary type="html">The F-Droid app repository has some issues that could potentially affect your security.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode128s0hbhb">🎥 


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://privsec.dev/posts/android/f-droid-security-issues/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/android/f-droid-security-issues/</a> - Main article referenced on F-Droid</li>
<li>


<a href="https://github.com/signalapp/Signal-Android/issues/127" target="_blank" rel="noopener" class="text-break">https://github.com/signalapp/Signal-Android/issues/127</a> - GitHub issue regarding Signal/TextSecure</li>
<li>


<a href="https://en.wikipedia.org/wiki/Moxie_Marlinspike" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Moxie_Marlinspike</a> - Moxie Marlinspike</li>
<li>


<a href="https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning" target="_blank" rel="noopener" class="text-break">https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning</a> - Certificate Pinning</li>
<li>


<a href="https://f-droid.org/en/docs/Reproducible_Builds/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/en/docs/Reproducible_Builds/</a> - F-Droid build process</li>
<li>


<a href="https://arxiv.org/pdf/1904.05572.pdf" target="_blank" rel="noopener" class="text-break">https://arxiv.org/pdf/1904.05572.pdf</a> - Android Playform Security Model</li>
<li>


<a href="https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234</a> - f-droid.org hosting out of date APK</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>UPDATED - GrapheneOS Google Services | Sandboxed Play Services | How to install</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-google-services-updated/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-google-services-updated/</id>
        <published>2022-05-08T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Do you need working notifications on GrapheneOS? The official Google Play releases can be installed and used in the regular app sandbox on GrapheneOS thanks to a compatibility layer.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode63s0hbhb">🎥 


<a href="https://youtu.be/SZ0PKtiXTSs" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/usage#sandboxed-google-play" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/usage#sandboxed-google-play</a> - GrapheneOS -  Sandboxed Play Services Instructions</li>
<li>


<a href="https://twitter.com/GrapheneOS/status/1514199657362169861" target="_blank" rel="noopener" class="text-break">https://twitter.com/GrapheneOS/status/1514199657362169861</a> - Tweet about new features</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>3 Best Open Source Android Apps</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/3-best-open-source-android-apps/" />
        <id>https://staging.sideofburritos.com/blog/3-best-open-source-android-apps/</id>
        <published>2022-03-27T12:57:39Z</published>
        <updated>2022-08-21T12:57:39Z</updated>
        <summary type="html">Android has a ton of Open Source Apps available. Some are good, some are not so good. This video cover 3 of my favorite Open Source Android Apps I use on a daily basis.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode9s0hbhb">🎥 


<a href="https://youtu.be/GucI1BgpgkU" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.bromite.org/" target="_blank" rel="noopener" class="text-break">https://www.bromite.org/</a> Bromite Homepage</li>
<li>


<a href="https://github.com/bromite/bromite" target="_blank" rel="noopener" class="text-break">https://github.com/bromite/bromite</a> - Bromite GitHub</li>
<li>


<a href="https://github.com/xarantolus/filtrite" target="_blank" rel="noopener" class="text-break">https://github.com/xarantolus/filtrite</a> - Bromite Alternate Blocklist</li>
<li>


<a href="https://newpipe.net/" target="_blank" rel="noopener" class="text-break">https://newpipe.net/</a> - NewPipe Homepage</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe/" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe/</a> - NewPipe GitHub</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe/issues/7734" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe/issues/7734</a> - NewPipe GitHub Issues Example</li>
<li>


<a href="https://trackercontrol.org/" target="_blank" rel="noopener" class="text-break">https://trackercontrol.org/</a> - TrackerControl Homepage</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe/" target="_blank" rel="noopener" class="text-break">https://github.com/TrackerControl</a> - TrackerControl GitHub</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid App Store</li>
</ul>
<hr>
<h2 id="how-to-add-bromite-f-droid-repository">How to add Bromite F-Droid Repository</h2>
<ol>
<li>Open F-Droid</li>
<li>Select <code>Settings</code> on the bottom</li>
<li>Under the <code>My Apps</code> section, select <code>Repositories</code></li>
<li>Click the <code>+</code> in the upper right corner</li>
<li>Go to the following URL in your browser and copy the <code>Address</code> listed on the page - 


<a href="https://www.bromite.org/fdroid" target="_blank" rel="noopener" class="text-break">https://www.bromite.org/fdroid</a></li>
<li>Go back to F-Droid and add the <code>Address</code> you copied in the <code>Repository address</code> box</li>
<li>Optional (but suggested) - go back to the webpage in step 5 and copy the <code>Fingerprint of the signing key</code></li>
<li>Go back to F-Droid and paste the <code>Fingerprint of the signing key</code> in the <code>Fingerprint</code> box</li>
<li>Go back to the main page on F-Droid, pull down to manually refresh the repositories</li>
<li>Once the refresh has finished, search for <code>Bromite</code> and install the app</li>
</ol>
]]></content>
      </entry>
      <entry>
        <title>Secure Calendar Storage | Free Cloud Storage | Android  Nextcloud</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/secure-calendar-app/" />
        <id>https://staging.sideofburritos.com/blog/secure-calendar-app/</id>
        <published>2022-03-20T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">If you&amp;#39;re looking to regain your privacy, it&amp;#39;s time to use Nextcloud. Storing your calendar events with Google or Apple gives them all the details on whom you&amp;#39;re in contact with.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode115s0hbhb">🎥 


<a href="https://youtu.be/ocwznyrMVwE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://nextcloud.com" target="_blank" rel="noopener" class="text-break">https://nextcloud.com</a> Nextcloud Homepage</li>
<li>


<a href="https://nextcloud.com/signup/" target="_blank" rel="noopener" class="text-break">https://nextcloud.com/signup/</a> - Nextcloud Account Signup</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid App Store</li>
<li>


<a href="https://www.akruto.com/backup-phone-contacts-calendar/export-icloud-calendar-as-ical/" target="_blank" rel="noopener" class="text-break">https://www.akruto.com/backup-phone-contacts-calendar/export-icloud-calendar-as-ical/</a> - How to export iCloud calendar</li>
<li>


<a href="https://support.google.com/calendar/answer/37111?hl=en" target="_blank" rel="noopener" class="text-break">https://support.google.com/calendar/answer/37111?hl=en</a> - How to export Google Calendar</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>OUTDATED - GrapheneOS Google Services | Sandboxed Google Play | How to install</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-google-services/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-google-services/</id>
        <published>2022-02-06T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">This guide is out of date. Please watch the updated video https://youtu.be/SZ0PKtiXTSs.</summary>
          <content type="html"><![CDATA[<hr>
<h3 id="this-guide-is-out-of-date-please-watch-the--hahahugoshortcode62s0hbhb">This guide is out of date. Please watch the 🎥 


<a href="https://youtu.be/SZ0PKtiXTSs" target="_blank" rel="noopener" class="text-break">updated video</a></h3>
]]></content>
      </entry>
      <entry>
        <title>CalyxOS Review | 3 weeks with a DeGoogled Phone | Secure &amp; Private Mobile OS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/calyxos-review/" />
        <id>https://staging.sideofburritos.com/blog/calyxos-review/</id>
        <published>2022-01-30T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">It&amp;#39;s time to DeGoogle your phone and take back some of your privacy. CalyxOS contains features and options not found in most mobile device manufacturers&amp;#39; official firmware.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode52s0hbhb">🎥 


<a href="https://youtu.be/_yyKNJrI71k" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://calyxos.org" target="_blank" rel="noopener" class="text-break">https://calyxos.org</a> - CalyxOS Homepage</li>
<li>


<a href="https://microg.org" target="_blank" rel="noopener" class="text-break">https://microg.org</a> - microG Homepage</li>
<li>


<a href="https://www.chromium.org/" target="_blank" rel="noopener" class="text-break">https://www.chromium.org</a> - Chromium Homepage</li>
<li>


<a href="https://tarnkappe.info/interviews/microg-android-almost-without-google-our-interview-with-the-developer-41258.html" target="_blank" rel="noopener" class="text-break">https://tarnkappe.info/interviews/microg-android-almost-without-google-our-interview-with-the-developer-41258.html</a> - Interview with microG developer</li>
<li>


<a href="https://www.statista.com/statistics/1224510/time-spent-per-day-on-smartphone-us/" target="_blank" rel="noopener" class="text-break">https://www.statista.com/statistics/1224510/time-spent-per-day-on-smartphone-us/</a> - Phone Usage Statistics</li>
<li>


<a href="https://forum.xda-developers.com/t/index-how-to-get-signature-spoofing-support.3557047/" target="_blank" rel="noopener" class="text-break">https://forum.xda-developers.com/t/index-how-to-get-signature-spoofing-support.3557047/</a> - Signature Spoofing</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>How to Install Stock Android on Google Pixel</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-stock-android-on-pixel/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-stock-android-on-pixel/</id>
        <published>2022-01-23T12:57:39Z</published>
        <updated>2022-08-23T12:57:39Z</updated>
        <summary type="html">Installing Stock Android on Google Pixel is easier than ever.  In this example we&amp;#39;re going to be using the official Android Flash Tool.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode86s0hbhb">🎥 


<a href="https://youtu.be/TIHG1j0yylc" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://flash.android.com" target="_blank" rel="noopener" class="text-break">https://flash.android.com</a> - Android Flash Tool</li>
<li>


<a href="https://grapheneos.org/install/web" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/install/web</a> - GrapheneOS Web Install (Used to remove non-stock key)</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>How to install GrapheneOS on Google Pixel 6 (Pixel 6 Pro) | DeGoogled Phone</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel6/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-grapheneos-on-pixel6/</id>
        <published>2022-01-16T12:57:39Z</published>
        <updated>2022-08-23T12:57:39Z</updated>
        <summary type="html">It&amp;#39;s time to DeGoogle your phone and take back some of your privacy. This guide will show you how to install GrapheneOS on a Pixel 6.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode81s0hbhb">🎥 


<a href="https://youtu.be/ro5OsVk8OfE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="commands-referenced-in-video">Commands referenced in video</h2>
<p>If you&rsquo;re on Arch Linux or Debian/Ubuntu, use the following commands to install as non-root:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">sudo pacman -S android-udev
</span></span></code></pre></div><p>Arch Linux</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">sudo apt install android-sdk-platform-tools-common
</span></span></code></pre></div><p>Debian/Ubuntu</p>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org" target="_blank" rel="noopener" class="text-break">https://grapheneos.org</a> - GrapheneOS Homepage</li>
<li>


<a href="https://grapheneos.org/install/web" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/install/web</a> - GrapheneOS Web Install</li>
<li>


<a href="https://www.chromium.org/getting-involved/download-chromium/" target="_blank" rel="noopener" class="text-break">https://www.chromium.org/getting-involved/download-chromium/</a> - Download Chromium</li>
<li>


<a href="https://developer.android.com/studio/run/win-usb" target="_blank" rel="noopener" class="text-break">https://developer.android.com/studio/run/win-usb</a> - Windows Users - Google USB Driver - Fastboot</li>
<li>


<a href="https://developer.android.com/studio/run/oem-usb#InstallingDriver" target="_blank" rel="noopener" class="text-break">https://developer.android.com/studio/run/oem-usb#InstallingDriver</a> - How to install Windows Drivers with Device Manager</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>How to install CalyxOS on Android using Microsoft Windows (Google Pixel)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-calyxos-on-android-windows/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-calyxos-on-android-windows/</id>
        <published>2021-11-29T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">It&amp;#39;s time to DeGoogle your phone and take back some of your privacy. This guide will show you how to install CalyxOS using Microsoft Windows.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode79s0hbhb">🎥 


<a href="https://youtu.be/cgpAvce1mLI" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="commands-referenced-for-video">Commands referenced for video</h2>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nb">cd</span> Downloads
</span></span></code></pre></div><p>Change to the directory of the files we downloaded earlier – 


<a href="https://youtu.be/cgpAvce1mLI?t=345" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">dir
</span></span></code></pre></div><p>Show the contents of the directory – 


<a href="https://youtu.be/cgpAvce1mLI?t=354" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">CertUtil -hashfile device-flasher.exe SHA256
</span></span></code></pre></div><p>OPTIONAL – Verify device-flasher – 


<a href="https://youtu.be/cgpAvce1mLI?t=360" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">CertUtil -hashfile redfin-factory-202112110.zip SHA256
</span></span></code></pre></div><p>OPTIONAL – Verify CalyxOS image – 


<a href="https://youtu.be/cgpAvce1mLI?t=423" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://calyxos.org" target="_blank" rel="noopener" class="text-break">https://calyxos.org</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>How to install CalyxOS on Android using Linux Ubuntu (Google Pixel) </title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-calyxos-on-android-linux/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-calyxos-on-android-linux/</id>
        <published>2021-11-22T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">It&amp;#39;s time to DeGoogle your phone and take back some of your privacy. This guide will show you how to install CalyxOS using Linux (Ubuntu).</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode77s0hbhb">🎥 


<a href="https://youtu.be/wSv_KH6pfts" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="commands-referenced-for-video">Commands referenced for video</h2>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">sudo apt update
</span></span></code></pre></div><p>Update local repositories – 


<a href="https://youtu.be/wSv_KH6pfts?t=184" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">sudo apt install android-sdk-platform-tools-common
</span></span></code></pre></div><p>Install required packages – 


<a href="https://youtu.be/wSv_KH6pfts?t=200" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">sudo apt install adb
</span></span></code></pre></div><p>Install Android Debug Bridge – 


<a href="https://youtu.be/wSv_KH6pfts?t=206" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nb">cd</span> ~/Downloads
</span></span></code></pre></div><p>Change directory to where files were downloaded – 


<a href="https://youtu.be/wSv_KH6pfts?t=264" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">sha256sum device-flasher.linux
</span></span></code></pre></div><p>OPTIONAL – Verify device-flasher – 


<a href="https://youtu.be/wSv_KH6pfts?t=254" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">sha256sum redfin-factory-202112110.zip
</span></span></code></pre></div><p>OPTIONAL – Verify CalyxOS image – 


<a href="https://youtu.be/wSv_KH6pfts?t=327" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">chmod +x device-flasher.linux
</span></span></code></pre></div><p>Make device-flash executable – 


<a href="https://youtu.be/wSv_KH6pfts?t=388" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">./device-flasher.linux
</span></span></code></pre></div><p>Execute device-flasher.linux – 


<a href="https://youtu.be/wSv_KH6pfts?t=400" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://calyxos.org" target="_blank" rel="noopener" class="text-break">https://calyxos.org</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>How to install CalyxOS on Android using a Mac (Google Pixel)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-calyxos-on-android-mac/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-calyxos-on-android-mac/</id>
        <published>2021-11-15T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">It&amp;#39;s time to DeGoogle your phone and take back some of your privacy. This guide will show you how to install CalyxOS on using a Mac.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode78s0hbhb">🎥 


<a href="https://youtu.be/OYpeRlYEmns" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="commands-referenced-for-video">Commands referenced for video</h2>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nb">cd</span> ~/Downloads/calyxos
</span></span></code></pre></div><p>Change Directory (if stored in your downloads folder). If you named the folder differently, then change “calyxos” to what you named it – 


<a href="https://youtu.be/OYpeRlYEmns?t=178" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">shasum -a <span class="m">256</span> device-flasher.darwin
</span></span></code></pre></div><p>OPTIONAL – Verify device-flasher – 


<a href="https://youtu.be/OYpeRlYEmns?t=196" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">shasum -a <span class="m">256</span> redfin-factory-number_in_file_name.zip
</span></span></code></pre></div><p>OPTIONAL – Verify CalyxOS image – 


<a href="https://youtu.be/OYpeRlYEmns?t=265" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nb">pwd</span>
</span></span></code></pre></div><p>Print Working directory – 


<a href="https://youtu.be/OYpeRlYEmns?t=331" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nb">cd</span> ~/Downloads/calyxos
</span></span></code></pre></div><p>Change to the directory of the files we downloaded earlier – 


<a href="https://youtu.be/OYpeRlYEmns?t=344" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">chmod +x device-flasher.darwin
</span></span></code></pre></div><p>Make device-flasher.darwin executable – 


<a href="https://youtu.be/OYpeRlYEmns?t=381" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">./device-flasher.darwin
</span></span></code></pre></div><p>Execute device-flasher.darwin – 


<a href="https://youtu.be/OYpeRlYEmns?t=395" target="_blank" rel="noopener" class="text-break">Link to section in video</a></p>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://calyxos.org" target="_blank" rel="noopener" class="text-break">https://calyxos.org</a></li>
</ul>
]]></content>
      </entry>

</feed>
