<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Apps on Side Of Burritos</title>
  <link rel="alternate" href="https://staging.sideofburritos.com/tags/apps/" />
  <link rel="self" href="https://staging.sideofburritos.com/tags/apps/index.xml" />
  <subtitle>Recent content in Apps on Side Of Burritos</subtitle>
  <id>https://staging.sideofburritos.com/tags/apps/</id>
  <generator uri="http://gohugo.io" version="0.165.0">Hugo</generator>
  <language>en-us</language>
  <updated>2024-09-16T10:00:00Z</updated>
  <author>
    <name>Josh</name>
    
  </author>
  
      <entry>
        <title>GrapheneOS: After 3 Years, This Is How I Install Apps on My “De-Googled” Phone</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-how-i-install-apps/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-how-i-install-apps/</id>
        <published>2024-09-16T10:00:00Z</published>
        <updated>2024-09-19T10:00:00Z</updated>
        <summary type="html">I walk you through how I install apps on my Google Pixel running GrapheneOS after 3 years of testing and refining my setup. I demonstrate how to use multiple app sources, including the GrapheneOS App Store, Accrescent, Obtainium, and the Google Play Store, while maintaining privacy and security.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode64s0hbhb">🎥 


<a href="https://youtu.be/IAoCfrqxIEg" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS</li>
<li>


<a href="https://github.com/guardianproject/orbot/releases" target="_blank" rel="noopener" class="text-break">https://github.com/guardianproject/orbot/releases</a> - Orbot GitHub</li>
<li>


<a href="https://www.fakenamegenerator.com/" target="_blank" rel="noopener" class="text-break">https://www.fakenamegenerator.com/</a> - FakeNameGenerator.com</li>
<li>


<a href="https://www.smspool.net/" target="_blank" rel="noopener" class="text-break">https://www.smspool.net/</a> - SMSPool (Service I use to rent a number for Google Account SMS verification)</li>
</ul>
<p><a href="smspool_response.png">Response from SMSPool on what they do with used phone numbers</a></p>
<ul>
<li>


<a href="https://youtu.be/JiN37bn0OE8" target="_blank" rel="noopener" class="text-break">https://youtu.be/JiN37bn0OE8</a> - My video on Obtainium</li>
<li>


<a href="https://youtu.be/E3erRhXPPNY" target="_blank" rel="noopener" class="text-break">https://youtu.be/E3erRhXPPNY</a> - My video on how Apps work between User Profiles</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Before we begin, I want to make a quick disclaimer. If you&rsquo;re just starting out using GrapheneOS, I highly recommend not using the setup I&rsquo;m about to discuss in this video. This setup will create friction, and friction is the enemy of adapting to something new, especially if you&rsquo;re hesitant to begin with. When you install GrapheneOS, just install the Play Store, sign in, download apps as you normally would, and get used to things. You can always switch to a different setup later. For everyone else, here&rsquo;s how I install apps on my Google Pixel running GrapheneOS.</p>
<p>So, this idea was suggested to me around two years ago, but I finally set it up about one year ago. This isn’t something that was just shared with me recently and now I&rsquo;m sharing it—I’ve tested it, and it’s been working well for me. This also won’t be a step-by-step guide. I’ll demonstrate installing three different apps from three different sources and give you details of my setup. When I upgrade my device in the future (still TBD), I plan to make a step-by-step video.</p>
<p>Before we begin, I want to mention that I just published the second episode of my podcast, which is called In the Hell. If you want to find out how you can listen to it, head over to inthehellpodcast.com, which I’ll link below. It&rsquo;s also worth noting that it&rsquo;s hosted on Yellowball, the no-BS podcast hosting platform I recently launched, in case you’re looking to start your own podcast.</p>
<p>When you first install GrapheneOS, you have one user profile, the owner profile, which is there by default, and you cannot delete it. From there, you can create additional user profiles depending on how you want to separate your apps. In my setup, all apps are installed from the owner profile, and I use the &ldquo;Install Available Apps&rdquo; feature to push those apps to my daily user profile. I like this setup because it lets me install apps from the Google Play Store without actually having the Play Store installed on my daily user profile. It’s kind of like having a command center for app installations.</p>
<p>The recording on the screen right now is my owner profile. The first thing I did when I set this up was install Orbot, which is a free proxy that lets you send all your device traffic over the Tor network. That means that all of our traffic when accessing the Play Store will go over the Tor network, along with any downloads of system updates from GrapheneOS, since those are all done from the owner profile. You can install Orbot by downloading the APK from GitHub, which I’ll also link down below.</p>
<p>Once we open Orbot, we can click &ldquo;Start VPN&rdquo; and give it a minute to connect. Now we have a full-device VPN, which means all of our owner profile traffic is going over the Tor network. It’s important to note that VPNs are profile-specific, so while our owner profile traffic is using Orbot, any secondary user profiles (which we’ll discuss later) will not use Orbot by default—it’s only for the profile that it&rsquo;s installed on.</p>
<p>You might notice where it says &ldquo;Change Exit.&rdquo; I currently have it set to the United States, and the reason for that is that sometimes when you go into Google Play, it might say &ldquo;App not available&rdquo; if the exit node is in a different country. This is common with banking apps or social media apps. If you run into that issue, you can change the exit node to match your country and see if you can access the app.</p>
<p>One other quick tip about Orbot: if you switch networks (for example, from Wi-Fi to cellular) or the Wi-Fi disconnects, Orbot might say it’s connected, but it’s really not. You’ll notice that because your browser won’t be able to load anything. What I found helpful is to long-press on the Orbot app, select &ldquo;App Info,&rdquo; force stop it, then clear the cache (but don’t clear the storage). After that, restart Orbot, click &ldquo;Start VPN,&rdquo; and nine times out of ten, it fixes the issue.</p>
<p>Now, let’s talk about the first app store I use. The first store I search for apps is the default GrapheneOS app store. In this case, I installed Accrescent from here, which is actually the second app store I use. If an app isn’t available in the first store, I move on to the second. The GrapheneOS app store mostly has system apps, but Accrescent is available there, so I installed it from there.</p>
<p>The second app store I use is Accrescent. There aren’t a ton of apps here, but it’s actively developed, and they’re constantly adding new apps and working with developers to get more. I plan to make a video just about Accrescent in the future because they’re doing great work, especially from a security perspective. For this demonstration, I’ll be installing Xf Eraser. I just click &ldquo;Install,&rdquo; and it’s done.</p>
<p>The third app store I use is Obtainium. If you’ve never used it before, it can be confusing, but I have a video dedicated to it, which I’ll link below. I use Obtainium for all my open-source apps or any apps that publish APKs directly on their site or on GitHub. For this example, I’ll install NewPipe. I’ll copy the GitHub link, add the app to Obtainium, and let it download. Then I’ll install it.</p>
<p>With this owner profile setup, I always make sure to uncheck &ldquo;Allow Network Permission&rdquo; when installing apps because I don’t use these apps in the owner profile. If you forget to uncheck it, you can always change it later. Now we can see that NewPipe is installed.</p>
<p>So far, we’ve seen the GrapheneOS app store, Accrescent, and Obtainium. The last store I use is the Google Play Store, which I installed using the GrapheneOS app store. You’ll notice that there’s no &ldquo;Install&rdquo; button for Google Play Services because I already have it installed. The issue with the Play Store is that you need an account to access it, which sucks. Unlike Aurora Store, which lets you use anonymous accounts, I’m not a fan of shared anonymous accounts, so I prefer this setup.</p>
<p>Creating an anonymous Google account without getting it blocked or locked is somewhat difficult but not impossible. If you try to create it over a VPN or Tor, you’ll likely run into issues. What I do is drive to a parking lot with free Wi-Fi—like at a grocery store or coffee shop—connect with my laptop, and create the account using a fake name generator for the required information.</p>
<p>The tricky part is when they ask for a phone number for SMS verification. You don’t want to use your real number here because it would ruin the anonymity. Instead, you can temporarily rent a phone number just for receiving the SMS code. There are free services, but I wouldn’t recommend them because they’re public and often blocked. You’ll have to pay, but it’s usually 50 cents to a dollar. I’ll link the site I use in the blog post for this video, but I won’t mention it here on YouTube. Once you receive the SMS code, you can validate your account.</p>
<p>I’ve done this for about ten different Google accounts without any issues. The key is to practice compartmentalization—don’t use this account for anything else. Just use it for the Play Store. If you get a new device, create a new account rather than using the same one. It sounds like a hassle, but it’s how you keep things separate and private. And since Orbot is running, all of your Play Store traffic is going over the Tor network, which helps maintain your anonymity.</p>
<p>Some people might critique using a shared phone number for account validation. While there’s a small risk someone else could gain control of that number, from what I can tell, it’s only used for initial validation, and Google doesn’t tie it to your account. If you’re concerned, you could use a prepaid SIM instead, but personally, I think the risk is low.</p>
<p>At this point, you can now sign into the Play Store with an anonymous Google account and start installing apps. For this demo, I’ll install WhatsApp. You might notice slower downloads when using Tor, but that’s normal. After installation, I’ll uncheck &ldquo;Allow Network Permission&rdquo; like I did with NewPipe.</p>
<p>Now, to avoid accidentally using the apps in the owner profile, I’ll disable them. Long-press on the app, go to &ldquo;App Info,&rdquo; and click &ldquo;Disable.&rdquo; I’ll do this for NewPipe, WhatsApp, and Xf Eraser.</p>
<p>The next step is to use the &ldquo;Install Available Apps&rdquo; feature to push these apps to my secondary user profile. In the demo, I created a profile called &ldquo;YouTube Demo,&rdquo; but you can call it whatever you like. This is the profile you’ll use daily instead of the owner profile. Once you select the secondary user profile, you can go to &ldquo;Install Available Apps,&rdquo; check the apps you want to install, and they’ll be available in the secondary user.</p>
<p>To switch profiles, swipe down from the top of the screen, tap the user icon, and select the profile. Screen recordings don’t work across profiles, so I’ll be back in a moment.</p>
<p>Now we’re in the secondary user profile. If I swipe up, you’ll see the apps we installed—Xf Eraser, NewPipe, and WhatsApp—all from different sources.</p>
<p>So this is how I install apps on my device running GrapheneOS. If you have apps that require Play Store Services, you can install them in the secondary profile. In my setup, I only have Play Store Services running in a specific profile for calls, not in my daily profile.</p>
<p>The benefit of separating profiles like this is that you can end a session for a profile where Play Store Services are running. This essentially puts that profile to rest, so Play Store Services are no longer running in the background. You can’t do this with the owner profile unless you power off the device. This method allows you to shut down Play Store Services without turning off your device.</p>
<p>One more thing to note: there’s only one instance of an app installed on the device at a time, so when you update an app in the owner profile, it’s updated across all profiles. You don’t need to worry about updating it in each profile.</p>
<p>After recording this, I realized it’s a lot of information, and it might seem overwhelming. But once you set it up, it’s pretty much &ldquo;set it and forget it.&rdquo; When you need to install a new app, install it in the owner profile, disable it, use &ldquo;Install Available Apps&rdquo; for the secondary user, and you’re good to go.</p>
<p>If you have any questions or comments, feel free to leave them down below, and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS Tablet: 1 Year Update and All the Apps I Use</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-tablet-1-year-update/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-tablet-1-year-update/</id>
        <published>2024-09-02T10:00:00Z</published>
        <updated>2024-09-02T10:00:00Z</updated>
        <summary type="html">I&amp;#39;ve really enjoyed using the Google Pixel Tablet with GrapheneOS installed over the past year. In this video, I cover what I primarily use it for and all the apps I have installed on it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode69s0hbhb">🎥 


<a href="https://youtu.be/eJdSM60zFJQ" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, no BS podcast hosting</li>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So after a year, I figured it was finally time to put out an update on my Pixel Tablet experience running GrapheneOS. Spoiler alert: my original video had some high ambitions of replacing my laptop and taking this with me when I travel, along with a keyboard and things like that. None of that happened—it didn&rsquo;t work out. But if you&rsquo;re curious as to why, keep watching. If all you wanted was that quick answer, there you go, and I&rsquo;ll see you next time.</p>
<p>Before I get into the apps that I&rsquo;m using and things like that, I first want to talk about the physical aspects of the tablet that I really like. To begin, let&rsquo;s start with the case. This is the official case from Google, and if you end up buying the tablet after watching this video, or have bought the tablet, I highly suggest you buy this case. It&rsquo;s probably one of the best-designed cases I&rsquo;ve ever used—not that I&rsquo;ve used many cases, but to start off, it&rsquo;s a nice rubbery, grippy texture that helps with holding onto it. Besides that, you have this circle thing on the back—or oval, I should say—and that&rsquo;s great for a kickstand, holding it up in the landscape position. It also works in the portrait position, so it can lean back like that. When you&rsquo;re just kind of walking around or laying on your couch, it works great for holding it just like this.</p>
<p>You might be wondering why it&rsquo;s that shape. You see those four pins on the bottom? Those correspond to the dock. When this goes on the dock, the handhold—or whatever that metal thing is—helps align the dock so that it locks into those pins, giving you a good connection. It&rsquo;s all magnetic, so the dock just snaps on. This is the only way I charge it—I&rsquo;ve never actually plugged a USB cable into this, except for during installation. So, the case—I highly recommend it.</p>
<p>Now, back to the dock. The dock is included in the box. I&rsquo;m not going to say that the dock is free because, of course, I&rsquo;m sure that&rsquo;s baked into the price somewhere, but the dock has exceeded my expectations, mostly from an audio standpoint. When you set the tablet on the dock, this then turns into the main speaker; the internal speakers on the tablet are disabled, and the audio comes out of this. For listening to music or podcasts, things like that, you&rsquo;re not getting room-filling booming audio, but it is pretty impressive for the form factor. I like using this when I&rsquo;m listening to podcasts or audiobooks on the tablet. It just works really great for that.</p>
<p>Speaking of podcasts, I wanted to let you know that I just published the first episode of my podcast, which is called In the Shell. You can check that out at intheshellpodcast.com to find out where you can listen to it, and I will also leave a link down below in the description if you want to check it out.</p>
<p>So now, let&rsquo;s get back to the reason why you clicked on this video. One more thing to mention about the physical appearance: I don&rsquo;t use a screen protector on the tablet. They do make them for it; I just never found a need for one. It&rsquo;s not like a cell phone where I&rsquo;m carrying it around, constantly taking it out of my pocket—this wouldn&rsquo;t fit in my pocket. So, I didn&rsquo;t really see a need to have a screen protector. So far, after a year, it looks good—no chips, cracks, or scrapes. Hope I didn&rsquo;t jinx myself, but so far, so good.</p>
<p>On the actual tablet, I have two user profiles set up. I have my main owner/admin user profile that you can see here, and I have my daily &ldquo;Josh&rdquo; user profile. On my main owner profile, I have the Google Play Store installed along with Obum. On that profile, I do all the installation of apps, and then I use the &ldquo;install available apps&rdquo; feature from the main owner profile to push the apps to my daily profile. It was suggested to me a while ago to test out that method, and I&rsquo;ve been using it ever since on my phone and tablet. I&rsquo;m not going to cover it in this video, but I will make a dedicated video specifically for that topic because I think it&rsquo;s a really useful way to configure your GrapheneOS device.</p>
<p>As I mentioned, I have two user profiles set up. We&rsquo;re currently in my daily profile that I use, named &ldquo;Josh.&rdquo; You can see that in the top right-hand corner up there. On the main home screen, I have two Progressive Web Apps (PWAs) installed: one is for Miniflux, a self-hosted RSS reader that I use, and the other is Wallabag, which is kind of a bookmarking tool—another self-hosted app that I use.</p>
<p>So let&rsquo;s now swipe up and get to the app drawer. I&rsquo;m not going to explain the default apps installed, like the camera, gallery, etc. If you have GrapheneOS, you&rsquo;re already familiar with those.</p>
<p>To start off, I have AntennaPod, which I use for listening to podcasts. Like I said, that goes really well with the dock—you get really good audio quality, and it works well for listening to those. The next app is Audiobookshelf, a self-hosted app I use to listen to my audiobooks. Then there&rsquo;s Bitwarden, a password manager. I also have a calendar app and EteSync, which is a contacts, calendar, and task sync app—another self-hosted app that I use. They also offer a cloud service, so if you&rsquo;re looking for an encrypted way to store your calendar, contacts, and tasks, I would suggest checking out EteSync. You don&rsquo;t have to self-host it; you can just sign up and use their service.</p>
<p>Following that, I have Jellyfin. I run a Jellyfin server at my house for my movies and TV shows that I want to watch. The Jellyfin app lets me access and watch those on the tablet, which, with the 11-inch screen, works perfectly—much nicer than trying to watch on my phone. Material Files is a third-party file explorer I use to connect to some network shares I have in my house. I don&rsquo;t have it installed on my phone because I don&rsquo;t access my network shares on my phone, but on the tablet with a larger screen, it works great for that.</p>
<p>Mullvad is my VPN of choice—it&rsquo;s running on here all the time. NewPipe is the next app, which is a third-party client for YouTube that helps you avoid the ads, which is nice. Notify is an app that provides push notifications to my device when it receives a webhook notification from the uptime services that monitor my site and different services. It works without Google Play Services, which is why I have it installed on here, since I don&rsquo;t have Google Play installed on this user profile.</p>
<p>ProtonMail is my email provider. I have their paid plan, so I use it for my sideofburritos.com domain. If you&rsquo;re looking for a decent email provider that&rsquo;s privacy- and security-focused, I would recommend them. The next app is Standard Notes, which I use for all my note-taking. I have a couple of files stored in there, but primarily just text files. I self-host the Standard Notes server at my house, so it syncs locally to a Raspberry Pi where I have that running. They do have a cloud offering, so if you&rsquo;re looking for an encrypted notes service, I would suggest checking them out.</p>
<p>Next is Tasks, which syncs with EteSync, as I mentioned earlier, for contacts, calendar, and tasks. Tutanota is another privacy-focused email provider that supports end-to-end encryption, just like Proton does, which means they have no access to your emails or the content of them. I&rsquo;ve always wanted to test them out, so when I set up the email for  (<a href="https://yellowball.fm">https://yellowball.fm</a>), the podcast hosting provider that I recently launched, I decided to go with them. So far, so good—I like their product and interface. As a company, I kind of prefer them over Proton. Proton&rsquo;s kind of turning into a commodity; it seems like they&rsquo;re just launching more products and everyone’s using them. While I appreciate that because it means they&rsquo;re more accessible to the masses, at the same time, it&rsquo;s kind of nice to support companies that are more niche in privacy and security, and Tutanota seems to be that.</p>
<p>The last app is VLC, which I use to play any files that the default gallery app can&rsquo;t play. VLC basically plays any file you throw at it—sometimes I think it&rsquo;ll even play a text file. It&rsquo;s just one of those solid apps to have.</p>
<p>As I mentioned in the intro, I had high ambitions for this—plugging it into an external monitor, plugging it into a keyboard, possibly using it as my full-time device. But it&rsquo;s just not going to replace a laptop, especially for someone like me doing programming, editing, recording videos, and things like that. The interface just isn&rsquo;t meant—at least at this point—for a mouse and keyboard to be as productive, or even close to it, as a laptop, at least from my perspective. Again, your results may vary.</p>
<p>But that being said, would I recommend this to someone? If you want to use it like me, where 99% of the time I use it as an entertainment device—watching YouTube videos, watching Jellyfin, checking my email, or browsing the web—then absolutely, I think this is a great device to purchase. But other than that, I don&rsquo;t really use it for much else.</p>
<p>So I hope I didn&rsquo;t disappoint you too much, and if you have any questions about the tablet, feel free to leave those down below, and I will see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>Obtainium overview | My favorite way to track Open Source apps</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/obtainium-overview/" />
        <id>https://staging.sideofburritos.com/blog/obtainium-overview/</id>
        <published>2023-03-20T10:00:00Z</published>
        <updated>2023-03-20T10:00:00Z</updated>
        <summary type="html">Using an RSS reader is a popular way to tack OSS apps directly from their source. Obtainium automates this process and simplifies it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode105s0hbhb">🎥 


<a href="https://youtu.be/JiN37bn0OE8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://github.com/ImranR98/Obtainium/issues/25" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium/issues/25</a> - Obtainium Issue 25 | <strong>Help wanted</strong></li>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">https://youtu.be/IzpVI4zaso0</a> - You should uninstall F-Droid - Part 1</li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">https://youtu.be/lAbgeJau3eE</a> - You should uninstall F-Droid - Part 2</li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">https://youtu.be/FFz57zNR_M0</a> - You should use this instead of F-Droid | How to use app RSS feed</li>
<li>


<a href="https://github.com/ImranR98/Obtainium" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium</a> - Obtainium GitHub</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe</a> - NewPipe GitHub</li>
<li>


<a href="https://github.com/bitfireAT/davx5-ose" target="_blank" rel="noopener" class="text-break">https://github.com/bitfireAT/davx5-ose</a> - DAVx⁵ GitHub</li>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/</a> - F-Droid homepage</li>
<li>


<a href="https://github.com/adrcotfas/Goodtime" target="_blank" rel="noopener" class="text-break">https://github.com/adrcotfas/Goodtime</a> - Goodtime Productivity GitHub</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>Six months ago, I made a few videos on F-Droid and why you should stop using it. Shortly after the release of those videos, someone sent me a project on GitHub that says in the readme it was motivated by one of those videos. I didn&rsquo;t start using it then, but I kept an eye on the project.</p>
<p>Now, just over six months later, the project has over 900 stars on GitHub, and it has come a long way, to say the least.</p>
<p>In my original video, I covered how you could manually add the source for APKs you wanted to track and download to an RSS reader. While this method did work, it was cumbersome.</p>
<p>The app I&rsquo;m talking about today is Obtainium, and it aims to automate the process of tracking and updating apps. While it doesn&rsquo;t solve the inherent problem with F-Droid and third-party app repositories, I do think it provides some viable alternatives to help reduce or even eliminate some of those concerns. As always, you should use my advice and experience as a starting point for your own research. Make sure to test and validate everything you hear, especially if you are considering using it.</p>
<p>I&rsquo;m going to cover a few use cases and then talk about my experience the last two weeks using Obtainium on my main device, a Pixel 7. The demo you see today will be from my testing device, which is a Pixel 6A.</p>
<p>So, to obtain Obtainium, we&rsquo;re going to head on over to the official GitHub page. All links will be down below in the description box.</p>
<p>So, we&rsquo;re going to open up our browser and search for Obtainium GitHub. And this first one here is the one we want. And if you scroll down, we&rsquo;re going to select the &ldquo;Get it on GitHub&rdquo; under installation. We&rsquo;re going to expand the assets, and the one we want to select for the Google Pixel is the &ldquo;app-arm64-v8a.&rdquo;</p>
<p>Select that, download anyway. Once that finishes, select &ldquo;Open.&rdquo; If you&rsquo;ve never used your browser to install an app before, you&rsquo;ll have to allow this permission. Once you see the install window pop up, select &ldquo;Install.&rdquo;</p>
<p>Done, and we have now obtained Obtainium. You should now see it on your home screen, or if you swipe up, it should be in your app drawer. Ignore the X Recorder; I&rsquo;ve had some issues with the built-in Android screen recorder, so I&rsquo;m trying a different one.</p>
<p>You can now open the app, allow notifications. Notifications are done locally, so there&rsquo;s no need for Google Play services for notifications to work.</p>
<p>And I first want to start off by saying how refreshing it is to use an open source app that took design into consideration. I&rsquo;ve noticed a lot of times that aesthetics is an afterthought, which is fine, but I think it hurts long-term adoption. I personally have motivation from a security and privacy perspective to use an app, even if the interface is less than ideal. Others who might not have as strong of a motivation to use an app could get quickly turned off by its looks.</p>
<p>So when I first opened Obtainium, I was pleasantly surprised by the design. The developer is very active on this project, so what you see on my screen right now might not be what you see if you&rsquo;re watching this video in the future, but the general overall concept should be the same.</p>
<p>Going through the interface, the first option is the apps. This is our apps list that we&rsquo;re tracking. Obtainium is added here by default so it can track and update itself, so that&rsquo;s pretty handy. We have add app, which we&rsquo;ll come back to shortly. Then we have import/export. If you&rsquo;re currently using an RSS reader like I talked about in my previous videos, there&rsquo;s an option here to import from URLs and file like OPML. The Repla app, the main export type that I had was OPML for its backups, so you could perform an export from that and import it to Obtainium. I didn&rsquo;t test this functionality; I just manually added the apps that I wanted. You can also perform an Obtainium export, so once you get everything set up, that&rsquo;s handy. You can export it, save it, and then if you switch devices or your phone gets lost or stolen, you can always import that backup so you don&rsquo;t need to set it up all over again.</p>
<p>The last option on the bottom is settings. I just left this set to the default, but feel free to change anything you might want.</p>
<p>Now let&rsquo;s add our first app. So select add app. We can see down here listed are the supported sources, and if we look next to GitHub and Codeberg, those are labeled as searchable. So in the second box here, we can search for an app. In this case, I&rsquo;m going to search for NewPipe because that&rsquo;s on GitHub. Search, so you&rsquo;re going to be presented with a lot of results, especially for a project that&rsquo;s popular. But this first one here is the official one, Team NewPipe. Just to be safe, I always suggest that you check first to validate that it is the correct one. So let&rsquo;s go to that repo. We can see here, this is the correct one, the official NewPipe. So once you validate that, we&rsquo;re going to go back, select the first one, and then press pick.</p>
<p>There&rsquo;s a separate section for additional options for GitHub. The first one is to include pre-releases. By default, you should leave this unchecked.</p>
<p>Prereleases technically aren&rsquo;t releases that you should be using, so that&rsquo;s why it&rsquo;s left unchecked by default. The next option is fallback to older releases, and that is enabled by default. This option is for when developers on GitHub do not do the releases correctly, and they might have one release for iPhone and one for Android. If they are listed in different releases, when Obtainium goes to check what the latest version is, if the iPhone one was released latest, it will see that there&rsquo;s no Android APK available to install. Therefore, this option lets it fall back to an older release, which would be the Android version, and you can then update that.</p>
<p>Probably sounds confusing, so just leave that enabled like it is. There&rsquo;s another option here for filter release titles by regular expression. Again, this is for edge cases. I haven&rsquo;t needed this yet for any of the apps I&rsquo;m tracking on my main device. The last option down here is for track only, and what this will do is it will just track it and will not actually try to download the updates and let you install them. I leave this disabled because I want Obtainium to download the APKs for me so I can install them, and then standard version detection, I just leave that set to the default. So those are the options that are listed.</p>
<p>We can now select Add. Obtainium needs permission to install unknown apps, a lot from this source. Let&rsquo;s go back. You&rsquo;ll see this screen next. We can see latest version 0.25.0 installed, a version none. I want to install it. Install done. And now if we go back to our apps list, we can see New Pipe is now here and being tracked. Latest version 0.25 installed version 0.25. Nice clean interface, and as expected, New Pipe is installed.</p>
<p>So, I know that took a few minutes to go through and talk about, but in reality, it only takes 30 seconds to add an app, and now in the future, Obtainium will check for updates in the background and notify you when they are available. As always, you should be skeptical of anything open source or any app for that matter, especially something that will be installing apps on your behalf or for you. So one extra precaution that you can take is to install the app manually first from the source, and then add it to Obtainium. When you install an app, Android pins the certificate and enforces signature checks for app updates, so even if something malicious was happening with Obtainium, it wouldn&rsquo;t be able to install a malicious app update because the signature check would fail.</p>
<p>So as an example, let&rsquo;s go ahead and install Dev X5. I know their source code is on GitHub, so I&rsquo;m going to search for that. I know this is the official repo for it. I&rsquo;m going to go to the releases and download the latest one. Let&rsquo;s open and install that.</p>
<p>So now at this point, Dev X5 has been installed. We downloaded it from the trusted source that we know; therefore, the certificate has been pinned by the OS. So any updates that are installed either manually by us or using Obtainium must pass the signature check, which means that the APK is signed by the developers. We can see Dev X5 was installed. Let&rsquo;s now add it to Obtainium. We just copy this URL, go back to Obtainium, add app, paste in the URL, select add. We can see that it found that Dev X5 is installed, latest version 4.3, installed version 4.3.</p>
<p>There&rsquo;s no updates to install. So now, if we go back, then go back to the apps list, we can now see that DAV X5 is listed there. We installed it from a trusted source, and now we&rsquo;re going to let Obtainium handle any future updates.</p>
<p>There are a few other caveats or features that I want to go over. So, going back to the &ldquo;add app&rdquo; option, we can see here that Malvad and Signal are both listed as sources. If we select one of those, Malvad publishes their APK on their website, so we can just copy this, and Obtainium on our behalf will find the APK for us and download it.</p>
<p>Select &ldquo;add,&rdquo; and we can see in the background downloading Malvadvpn. So it&rsquo;s pretty handy that the developer went ahead and built in this functionality for us already. Even though we&rsquo;re not actually adding the exact page the APK is on for the apps listed there. In this case, Malvad and Signal, the app automatically knows where to look. It&rsquo;s a good minute to finish.</p>
<p>Once it finishes, we&rsquo;re prompted to install. Now, if we go back to the apps list and refresh, we can now see Malvad is shown here and being tracked.</p>
<p>Just to show an example of what updates look like, I went ahead and installed an older version of New Pipe. You&rsquo;ll receive a notification, and then when you go inside the app, you&rsquo;ll see a notification next to the app that needs to be updated. In this case, New Pipe. Select the purple download icon, and you can see the download. So Obtainium went ahead and downloaded the APK for us. We now select &ldquo;update,&rdquo; and now New Pipe was successfully updated.</p>
<p>One of the easiest ways to find where the source code for an open-source app is hosted is to use the F-Droid website. So if we go to f-droid.org in our browser and then scroll down and let&rsquo;s search for New Pipe as an example, the second one is the one we want.</p>
<p>To access the source code for the application, we need to scroll down to the section above the donate button and click on the link to the source code. By examining the URL, we can see that the source code is hosted on GitHub. If we scroll down further to the releases section, we can see that NewPipe publishes their APK on GitHub, which means Obtainium can download it from there.</p>
<p>Returning to fdroid.org, we can find that some developers only publish the APK on F-Droid, even if they have already published the source code on GitHub. As an example, let&rsquo;s search for a productivity app that starts with &ldquo;Good Time,&rdquo; which is the fifth one down. Looking at the source code, we can see that it is also hosted on GitHub. However, when we scroll down to the releases section, we notice that they do not publish the APK on GitHub; only the source code is available. In this scenario, our only option is to return to F-Droid, copy the F-Droid link, and paste it inside Obtainium.</p>
<p>After adding the app and pasting the F-Droid URL, we can see that Obtainium found the app and we can proceed to install it. Upon returning to our list of apps, we can see that Productivity is now installed, and it shows that it is signed by F-Droid.</p>
<p>Using Obtainium is still a better option than the official F-Droid app because it avoids some of the shortcomings mentioned in the previous video, such as targeting out-of-date SDKs. Although the process might seem complicated, it is relatively simple once you go through the steps yourself. It has made the process of downloading, installing, and updating apps much more accessible for the past two weeks, and the update functionality and tracking have worked flawlessly. The experience so far has been enjoyable, and the plan is to continue using it.</p>
<p>However, there are a few limitations to be aware of that are listed on the GitHub readme. The first one is that app installs occur asynchronously, and the success or failure of an install cannot be determined directly. This results in install statuses and versions sometimes being out of sync with the OS until the next launch or until the problem is manually corrected. If you notice any unusual behavior, close the app and relaunch it.</p>
<p>The second limitation, which will be revisited later, is that auto unattended updates are unsupported due to the lack of a capable Flutter plugin. Also, for some sources, data is gathered using web scraping, which can easily break due to changes in website design. In such cases, more reliable methods may be unavailable, and scraping is an unreliable method to gather data. If you have ever used NewPipe and noticed that it broke randomly because YouTube changed its layout one day, that is a similar situation to what the developer is describing here. It is not the app developer&rsquo;s fault, but rather the nature of web scraping.</p>
<p>Regarding the second limitation mentioned above, before making this video, the app developer was contacted to see if there was anything specific they wanted to mention. They requested that any Android developers watching the video take a look at issue number 25, linked below, to help complete the auto-update feature before releasing version one of Obtainium. Contributions to help with that would be greatly appreciated.</p>
<p>Overall, using Obtainium has been a great improvement and has made the manual tracking process much more efficient. Although it is not a solution to the underlying problems that still exist, it is a step in the right direction. The plan is to continue using it, and there are no plans to go back to the RSS reader method.</p>
<p>And while it&rsquo;s not a solution to the underlying problems that still exist, which I covered in my previous videos, it is a great improvement and makes the manual tracking process much more efficient. So, I hope you enjoyed this video. If you did, check out this top one here, and the bottom one has been automatically selected for you.</p>
]]></content>
      </entry>
      <entry>
        <title>F-Droid - App not installed as package appears to be invalid</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/fdroid-app-not-installed/" />
        <id>https://staging.sideofburritos.com/blog/fdroid-app-not-installed/</id>
        <published>2023-02-06T10:00:00Z</published>
        <updated>2023-02-06T10:00:00Z</updated>
        <summary type="html">The F-Droid website hosts an outdated version of the APK which causes issues for users who try to install it in multiple user profiles.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode56s0hbhb">🎥 


<a href="https://youtu.be/E3erRhXPPNY" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/</a> - F-Droid homepaage</li>
<li>


<a href="https://f-droid.org/en/packages/org.fdroid.fdroid/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/en/packages/org.fdroid.fdroid/</a> - F-Droid package</li>
<li>


<a href="https://www.sisik.eu/apk-tool" target="_blank" rel="noopener" class="text-break">https://www.sisik.eu/apk-tool</a> - Browser APK analyzer</li>
<li>


<a href="https://forum.f-droid.org/t/cannot-install-f-droid-invalid-package-using-profiles/16122" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/cannot-install-f-droid-invalid-package-using-profiles/16122</a> - F-Droid forum post 1</li>
<li>


<a href="https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234</a> - F-Droid forum post 2</li>
<li>


<a href="https://hub.libranet.de/wiki/and-priv-sec/wiki/apps" target="_blank" rel="noopener" class="text-break">https://hub.libranet.de/wiki/and-priv-sec/wiki/apps</a> - Android apps</li>
<li>


<a href="https://grapheneos.org/features#install-available-apps" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#install-available-appss</a> - GrapheneOS install available apps feature</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>It&rsquo;s good practice to document answers to frequently asked questions, as it allows other users to reference them. For example, I&rsquo;ve been asked multiple times through email and video comments why a user is unable to install F-Droid in another user profile. To avoid answering these questions individually, I decided to make a video explaining the reason behind this issue. To demonstrate the process, a user can go to f-droid.org on their Android device and click the &ldquo;Download&rdquo; button on the home page to download F-Droid. Once the download is complete, they can install the APK.</p>
<p>Open the app, ignore the warning, allow it a minute to update the repositories. Now, if you go to updates because of the notification, the first thing the app wants you to do is update F-Droid to the newest version. The user now has the latest version of it installed. They go through and download whatever apps they want, install them, and then shortly after this, the user finds out about user profiles and wants to start separating their apps to different user profiles to separate user data.</p>
<p>So, they create a new user profile and we&rsquo;re on that new user profile. And again, the first thing they want to do is install F-Droid so they can download apps. They go to fdroid.org again, same process as before, click the download button, download once the download finishes, open, and install again. And they are presented with an error. This is the error I get asked about and that I see different posts about online.</p>
<p>So now that we see what is happening, let&rsquo;s talk about why this is happening. This diagram is overly simplified, but I think it&rsquo;ll help paint the picture of what&rsquo;s going on. At the bottom here, we have the system and part of the system is the Android Package Manager, which we can see here. And above the system level is the user profiles, as we saw in the example. We had our initial owner user profile that we were on and then switched to our user profile, which was that second user profile where the F-Droid install failed.</p>
<p>A common misconception is that when you install an app on a user profile, it&rsquo;s installed in that user profile and then when you switch to the other user profile, it&rsquo;s installed there as well. But that is not correct. What happens when you install an app on Android is that it is handled by the Android Package Manager. That app is installed and then linked, for lack of a better term, to the profile that you are presently in.</p>
<p>In this example, we installed F-Droid from our owner profile. We downloaded it and installed it, which was version one. And as we saw in the example, once we installed F-Droid, we were immediately prompted to update the app, so we went from version one to version two. These are not the actual version numbers. I&rsquo;m just doing this for the sake of simplicity. So at this point, we now had version 2 of it installed and being managed by the Android Package Manager.</p>
<p>We went to our second user profile, downloaded and installed F-Droid, or tried to install it, but the issue that was occurring was that when we downloaded F-Droid from the website, the version we downloaded was actually version one. Since Android packages are managed by the system, there&rsquo;s a protection in place that prevents an app from being downgraded. So in this case, we were trying to install version one of F-Droid, but the Package Manager saw that we had version 2 installed, therefore it blocked the install on that second user profile, and we were unable to install F-Droid on it.</p>
<p>Just to reiterate, because it was a misconception that I had as well, user profiles are meant to separate user data. The actual installation of apps is handled at the system level by the Android Package Manager. And if you try to install an app on a separate user profile that is an older version than the one currently being tracked by the Android Package Manager, the install will fail.</p>
<p>You may have noticed that when you update an app in one user profile, the same update is reflected in all other user profiles. This is because the package installation is handled at the system level, not at the user profile level. When the app is updated in one profile, the actual package is upgraded across the system, making all user profiles use the same updated version.</p>
<p>This is why the issue of updating F Droid continually occurs. F Droid hosts an outdated version of their app on their website, so every time a new user visits the site, they end up downloading an older version of the app, which then prompts them for an update. To avoid this, you can download the latest version of the app from the home page and save it in a folder titled &ldquo;F Droid&rdquo;. From there, you can search for &ldquo;F-Droid&rdquo; on the right side.</p>
<p>We can scroll down to the latest version labeled &ldquo;Suggested Download&rdquo;. Again, placing that in the &ldquo;F Droid&rdquo; folder. Now, for the sake of simplicity, I&rsquo;m going to use this online APK analyzer. Here we have our &ldquo;F Droid&rdquo; folder with the &ldquo;F Droid.apk&rdquo; that was downloaded from the home page and the &ldquo;org.fdroid&rdquo; that was the most recent suggested version we downloaded.</p>
<p>If we look at these, we can see that the one from the home page is version 1.15.4, and the version from the actual page in the search was 1.15.6. The 1.15.4 was published on December 2nd, 2022, and the most recent suggested version on January 14th, 2023.</p>
<p>That&rsquo;s why if you go to a separate user profile and try to download F Droid from the main home page, you receive an older version that&rsquo;s out of date and the install fails because Android&rsquo;s downgrade protection kicks in and blocks the install.</p>
<p>Now that we know what is happening and why, there are a couple of things you can do to get around this issue:</p>
<p>Instead of going to the F Droid home page, you can scroll down, search for &ldquo;Appdroid&rdquo;, select F Droid, and download the latest version with the tag &ldquo;Suggested&rdquo;. When you open this one and select &ldquo;install&rdquo;, it&rsquo;s not blocked by Android because you&rsquo;re not trying to install an older version of the app. This is probably the easiest for most people.</p>
<p>If you are running Graphene OS, you can go into &ldquo;Settings&rdquo;, &ldquo;System&rdquo;, &ldquo;Multiple Users&rdquo;, select the second user profile, and use the option &ldquo;Install Available Apps&rdquo;. Change the toggle next to F Droid, and it will be accessible from your second user profile. The reason the &ldquo;Install Available Apps&rdquo; feature works is that APK installation is handled by the package manager at the system level, so when you are in the owner profile, you can give additional profiles access to installed apps.</p>
<p>For the F Droid team, you could update the version on your home page to the latest stable version. It&rsquo;s not good security practice to intentionally host an outdated version of your app in the most popular place to download it. This one change of hosting the most recent version on your home page would save everyone time and make for a better overall user experience.</p>
<p>If you enjoyed this video, I think you&rsquo;ll like the top one listed here, and the engineers at Google think you will like the bottom one.</p>
]]></content>
      </entry>
      <entry>
        <title>FULL reveal of what apps I use on my personal phone | GrapheneOS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/app-i-use-on-my-personal-phone/" />
        <id>https://staging.sideofburritos.com/blog/app-i-use-on-my-personal-phone/</id>
        <published>2022-07-31T12:57:39Z</published>
        <updated>2022-08-10T12:57:39Z</updated>
        <summary type="html">If you&amp;#39;re curious what apps I use on my personal device, here they are.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode21s0hbhb">🎥 


<a href="https://youtu.be/FEN_NvKsVBc" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<h2 id="my-other-videos-i-referenced">My other videos I referenced</h2>
<ul>
<li>


<a href="https://youtu.be/NJzA9yRGgeM" target="_blank" rel="noopener" class="text-break">🎥 Storing your contacts in the cloud</a></li>
<li>


<a href="https://youtu.be/ocwznyrMVwE/" target="_blank" rel="noopener" class="text-break">🎥 Storing your calendar events in the cloud</a></li>
<li>


<a href="https://youtu.be/9R6M4NuBTi4" target="_blank" rel="noopener" class="text-break">🎥 Calling a scammer</a></li>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">🎥 You should uninstall F-Droid - Part 1</a></li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">🎥 You should uninstall F-Droid - Part 2</a></li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">🎥 You should use this instead of F-Droid | How to use app RSS feed</a></li>
</ul>
<h2 id="full-list-of-apps-i-have-installed-as-of-2022-07-31">Full list of apps I have installed (as of 2022-07-31)</h2>
<ul>
<li>1Password</li>
<li>Aegis</li>
<li>AntennaPod</li>
<li>Aurora Store</li>
<li>Briar</li>
<li>Burner</li>
<li>Cube ACR</li>
<li>DAVx⁵</li>
<li>Geometric Weather</li>
<li>Google Camera</li>
<li>Magic Earth</li>
<li>Mullvad VPN</li>
<li>NewPipe</li>
<li>Nextcloud</li>
<li>OpenVPN</li>
<li>Play Store</li>
<li>Plex</li>
<li>Read You</li>
<li>Signal</li>
<li>Simple Calendar Pro</li>
<li>Sonos</li>
<li>Spotify</li>
<li>Syncthing</li>
<li>Todoist</li>
<li>Twidere</li>
<li>UniFi Network</li>
<li>UniFi Protect</li>
<li>UptimeRobot</li>
<li>Vanadium</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>F-Droid, Droid-ify, Aurora Droid, Neo Store, Google Play, Aurora Store - What should you use?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/app-stores-explained/" />
        <id>https://staging.sideofburritos.com/blog/app-stores-explained/</id>
        <published>2022-07-17T12:57:39Z</published>
        <updated>2022-08-10T12:57:39Z</updated>
        <summary type="html">There are multiple apps stores available on Android which can make it a bit confusing to know what each one might be used for.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode22s0hbhb">🎥 


<a href="https://youtu.be/JMSiTFLpUP8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<p>


<a href="Diagram%20from%20video.png" target="_blank" rel="noopener" class="text-break">Full Size Diagram from video</a> -
To download a full-size copy of the image, <code>Right-Click</code> the <code>Full Size Image</code> link and select <code>Save Link As</code> (or just click it to view)</p>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<h2 id="my-previous-f-droid-videos">My previous F-Droid videos</h2>
<ul>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">You should uninstall F-Droid - Part 1</a></li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">You should uninstall F-Droid - Part 2</a></li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">You should use this instead of F-Droid | How to use app RSS feed0</a></li>
</ul>
<h2 id="app-store-links">App Store Links</h2>
<ul>
<li>


<a href="https://github.com/NeoApplications/Neo-Store" target="_blank" rel="noopener" class="text-break">Droid-ify (Now Neo Store)</a></li>
<li>


<a href="https://auroraoss.com/" target="_blank" rel="noopener" class="text-break">Aurora Store</a></li>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">F-Droid</a></li>
<li>


<a href="https://gitlab.com/AuroraOSS/auroradroid" target="_blank" rel="noopener" class="text-break">Aurora Droid</a></li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://wonderfall.dev/fdroid-issues/" target="_blank" rel="noopener" class="text-break">Blog post on F-Droid Security (Great read)</a></li>
<li>


<a href="https://f-droid.org/en/docs/Inclusion_Policy/" target="_blank" rel="noopener" class="text-break">F-Droid Inclusion Policy</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should use this instead of F-Droid</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/use-this-instead-of-f-droid/" />
        <id>https://staging.sideofburritos.com/blog/use-this-instead-of-f-droid/</id>
        <published>2022-07-10T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">F-Droid has issues. Using this method is a way to completely bypass using F-Droid to install open source apps.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode122s0hbhb">🎥 


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<h2 id="my-previous-two-f-droid-videos">My previous two F-Droid videos</h2>
<ul>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">https://youtu.be/IzpVI4zaso0</a> - You should uninstall F-Droid - Part 1</li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">https://youtu.be/lAbgeJau3eE</a> - You should uninstall F-Droid - Part 2</li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://en.wikipedia.org/wiki/RSS" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/RSS</a> - RSS Feeds</li>
<li>


<a href="https://github.com/Ashinch/ReadYou" target="_blank" rel="noopener" class="text-break">https://github.com/Ashinch/ReadYou</a> - Read You Github page</li>
<li>


<a href="https://discuss.grapheneos.org/d/16-f-droid-auto-updates/5" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/16-f-droid-auto-updates/5</a> - Forum post about using RSS reader</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Period tracking app Roe v Wade | Cloud vs Local Storage</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/period-tracking-app-roe-v-wade/" />
        <id>https://staging.sideofburritos.com/blog/period-tracking-app-roe-v-wade/</id>
        <published>2022-07-03T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Understanding how data is stored on your mobile device is the first step in understanding how it can affect you. Different laws and policy changes can impact how your data is used and accessed, such a Roe v Wade.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode107s0hbhb">🎥 


<a href="https://youtu.be/2wxI6GtdspI" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="app-downloads-android">App Downloads Android</h2>
<ul>
<li>


<a href="https://bloodyhealth.gitlab.io/" target="_blank" rel="noopener" class="text-break">https://bloodyhealth.gitlab.io/</a> - Drip</li>
<li>


<a href="https://play.google.com/store/apps/details?id=de.arnowelzel.android.periodical" target="_blank" rel="noopener" class="text-break">https://play.google.com/store/apps/details?id=de.arnowelzel.android.periodical</a> - Periodical</li>
<li>


<a href="https://play.google.com/store/apps/details?id=com.kollectivemobile.euki" target="_blank" rel="noopener" class="text-break">https://play.google.com/store/apps/details?id=com.kollectivemobile.euki</a> - Euki</li>
</ul>
<h2 id="app-download-ios">App Download iOS</h2>
<ul>
<li>


<a href="https://apps.apple.com/us/app/euki/id1469213846" target="_blank" rel="noopener" class="text-break">https://apps.apple.com/us/app/euki/id1469213846</a> - Euki</li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://transparencyreport.google.com/user-data/overview?hl=en" target="_blank" rel="noopener" class="text-break">https://transparencyreport.google.com/user-data/overview?hl=en</a> - Google Transparency Report</li>
<li>


<a href="https://theintercept.com/2022/06/29/crypto-coinbase-tracer-ice/" target="_blank" rel="noopener" class="text-break">https://theintercept.com/2022/06/29/crypto-coinbase-tracer-ice/</a> - Coinbase Providing “Geo Tracking Data” to ICE</li>
<li>


<a href="https://www.youtube.com/watch?v=8FDIef7tVFg" target="_blank" rel="noopener" class="text-break">https://www.youtube.com/watch?v=8FDIef7tVFg</a> - &lsquo;The Hated One - My Phone Is Anonymous Now&rsquo; Video</li>
<li>


<a href="https://lers.google.com/signup_v2/landing" target="_blank" rel="noopener" class="text-break">https://lers.google.com/signup_v2/landing</a> - Google | Law Enforcement Request System</li>
<li>


<a href="https://www.facebook.com/records/login/" target="_blank" rel="noopener" class="text-break">https://www.facebook.com/records/login/</a> - Facebook | Law Enforcement Request System</li>
<li>


<a href="https://help.twitter.com/en/forms/law-enforcement" target="_blank" rel="noopener" class="text-break">https://help.twitter.com/en/forms/law-enforcement</a> - Twitter | Law Enforcement Request System</li>
<li>


<a href="https://www.npr.org/2022/07/01/1109467942/tiktok-china-data-privacy" target="_blank" rel="noopener" class="text-break">https://www.npr.org/2022/07/01/1109467942/tiktok-china-data-privacy</a> - TikTok says it&rsquo;s putting new limits on Chinese workers&rsquo; access to U.S. user data</li>
<li>


<a href="https://www.businessinsider.com/tiktok-confirms-us-user-data-accessed-in-china-bytedance-2022-7" target="_blank" rel="noopener" class="text-break">https://www.businessinsider.com/tiktok-confirms-us-user-data-accessed-in-china-bytedance-2022-7</a> - TikTok Confirms US User Data Can Be Accessed in China</li>
<li>


<a href="https://www.theverge.com/2022/6/24/23181851/t-mobile-browsing-data-app-insights-marketing-opt-out" target="_blank" rel="noopener" class="text-break">https://www.theverge.com/2022/6/24/23181851/t-mobile-browsing-data-app-insights-marketing-opt-out</a> - T-Mobile is happily selling customers’ app habits to advertisers</li>
<li>


<a href="https://www.cio.com/article/402208/data-science-drives-big-decisions-at-kohls.html" target="_blank" rel="noopener" class="text-break">https://www.cio.com/article/402208/data-science-drives-big-decisions-at-kohls.html</a> - Data science drives big decisions at Kohl&rsquo;s</li>
<li>


<a href="https://www.theregister.com/2022/06/20/captial_one_wire_fraud/" target="_blank" rel="noopener" class="text-break">https://www.theregister.com/2022/06/20/captial_one_wire_fraud/</a> - Capital One fraudster got in via &lsquo;misconfigured&rsquo; AWS storage</li>
<li>


<a href="https://twitter.com/alexjyong/status/1542184851532423168" target="_blank" rel="noopener" class="text-break">https://twitter.com/alexjyong/status/1542184851532423168</a> - Tweet regarding Drip iOS release</li>
<li>


<a href="https://floridaphoenix.com/2020/11/25/u-s-appeals-court-oks-use-of-third-party-app-data-to-track-down-suspected-child-molester/" target="_blank" rel="noopener" class="text-break">https://floridaphoenix.com/2020/11/25/u-s-appeals-court-oks-use-of-third-party-app-data-to-track-down-suspected-child-molester/</a> - U.S. appeals court OKs use of third-party app data to track down suspected child molester</li>
<li>


<a href="https://www.nytimes.com/interactive/2019/04/13/us/google-location-tracking-police.html" target="_blank" rel="noopener" class="text-break">https://www.nytimes.com/interactive/2019/04/13/us/google-location-tracking-police.html</a> - Google is a dragnet for police</li>
<li>


<a href="https://www.ftc.gov/business-guidance/blog/2021/01/health-app-broke-its-privacy-promises-disclosing-intimate-details-about-users" target="_blank" rel="noopener" class="text-break">https://www.ftc.gov/business-guidance/blog/2021/01/health-app-broke-its-privacy-promises-disclosing-intimate-details-about-users</a> - Health app broke its privacy promises by disclosing intimate details about users</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should uninstall F-Droid - Part 1</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt1/" />
        <id>https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt1/</id>
        <published>2022-06-19T10:00:00Z</published>
        <updated>2022-12-26T10:00:00Z</updated>
        <summary type="html">If you&amp;#39;re going to use F-Droid for apps, there are a few things that you should be aware of.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode127s0hbhb">🎥 


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://privsec.dev/posts/android/f-droid-security-issues/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/android/f-droid-security-issues/</a> - Main article referenced on F-Droid</li>
<li>


<a href="https://en.wikipedia.org/wiki/Android_version_history#Android_7.0_Nougat" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Android_version_history#Android_7.0_Nougat</a> - Android version history</li>
<li>


<a href="https://developer.android.com/studio/releases/platforms" target="_blank" rel="noopener" class="text-break">https://developer.android.com/studio/releases/platforms</a> - SDK Releases</li>
<li>


<a href="https://gitlab.com/fdroid/fdroidclient/-/blob/2a8b16683a2dbee16d624a58e7dd3ea1da772fbd/app/build.gradle#L33" target="_blank" rel="noopener" class="text-break">https://gitlab.com/fdroid/fdroidclient/-/blob/2a8b16683a2dbee16d624a58e7dd3ea1da772fbd/app/build.gradle#L33</a> - F-Droid code showing legacy SDK</li>
<li>


<a href="https://github.com/NeoApplications/Neo-Store" target="_blank" rel="noopener" class="text-break">https://github.com/NeoApplications/Neo-Store</a> - Droidi-fy</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid homepage</li>
<li>


<a href="https://discuss.grapheneos.org/d/16-f-droid-auto-updates/4" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/16-f-droid-auto-updates/4</a> - F-Droid discussion on auto-updates</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should uninstall F-Droid - Part 2</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt2/" />
        <id>https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt2/</id>
        <published>2022-05-22T10:00:00Z</published>
        <updated>2022-08-22T10:00:00Z</updated>
        <summary type="html">The F-Droid app repository has some issues that could potentially affect your security.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode128s0hbhb">🎥 


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://privsec.dev/posts/android/f-droid-security-issues/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/android/f-droid-security-issues/</a> - Main article referenced on F-Droid</li>
<li>


<a href="https://github.com/signalapp/Signal-Android/issues/127" target="_blank" rel="noopener" class="text-break">https://github.com/signalapp/Signal-Android/issues/127</a> - GitHub issue regarding Signal/TextSecure</li>
<li>


<a href="https://en.wikipedia.org/wiki/Moxie_Marlinspike" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Moxie_Marlinspike</a> - Moxie Marlinspike</li>
<li>


<a href="https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning" target="_blank" rel="noopener" class="text-break">https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning</a> - Certificate Pinning</li>
<li>


<a href="https://f-droid.org/en/docs/Reproducible_Builds/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/en/docs/Reproducible_Builds/</a> - F-Droid build process</li>
<li>


<a href="https://arxiv.org/pdf/1904.05572.pdf" target="_blank" rel="noopener" class="text-break">https://arxiv.org/pdf/1904.05572.pdf</a> - Android Playform Security Model</li>
<li>


<a href="https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234</a> - f-droid.org hosting out of date APK</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>3 Best Open Source Android Apps</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/3-best-open-source-android-apps/" />
        <id>https://staging.sideofburritos.com/blog/3-best-open-source-android-apps/</id>
        <published>2022-03-27T12:57:39Z</published>
        <updated>2022-08-21T12:57:39Z</updated>
        <summary type="html">Android has a ton of Open Source Apps available. Some are good, some are not so good. This video cover 3 of my favorite Open Source Android Apps I use on a daily basis.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode9s0hbhb">🎥 


<a href="https://youtu.be/GucI1BgpgkU" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.bromite.org/" target="_blank" rel="noopener" class="text-break">https://www.bromite.org/</a> Bromite Homepage</li>
<li>


<a href="https://github.com/bromite/bromite" target="_blank" rel="noopener" class="text-break">https://github.com/bromite/bromite</a> - Bromite GitHub</li>
<li>


<a href="https://github.com/xarantolus/filtrite" target="_blank" rel="noopener" class="text-break">https://github.com/xarantolus/filtrite</a> - Bromite Alternate Blocklist</li>
<li>


<a href="https://newpipe.net/" target="_blank" rel="noopener" class="text-break">https://newpipe.net/</a> - NewPipe Homepage</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe/" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe/</a> - NewPipe GitHub</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe/issues/7734" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe/issues/7734</a> - NewPipe GitHub Issues Example</li>
<li>


<a href="https://trackercontrol.org/" target="_blank" rel="noopener" class="text-break">https://trackercontrol.org/</a> - TrackerControl Homepage</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe/" target="_blank" rel="noopener" class="text-break">https://github.com/TrackerControl</a> - TrackerControl GitHub</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid App Store</li>
</ul>
<hr>
<h2 id="how-to-add-bromite-f-droid-repository">How to add Bromite F-Droid Repository</h2>
<ol>
<li>Open F-Droid</li>
<li>Select <code>Settings</code> on the bottom</li>
<li>Under the <code>My Apps</code> section, select <code>Repositories</code></li>
<li>Click the <code>+</code> in the upper right corner</li>
<li>Go to the following URL in your browser and copy the <code>Address</code> listed on the page - 


<a href="https://www.bromite.org/fdroid" target="_blank" rel="noopener" class="text-break">https://www.bromite.org/fdroid</a></li>
<li>Go back to F-Droid and add the <code>Address</code> you copied in the <code>Repository address</code> box</li>
<li>Optional (but suggested) - go back to the webpage in step 5 and copy the <code>Fingerprint of the signing key</code></li>
<li>Go back to F-Droid and paste the <code>Fingerprint of the signing key</code> in the <code>Fingerprint</code> box</li>
<li>Go back to the main page on F-Droid, pull down to manually refresh the repositories</li>
<li>Once the refresh has finished, search for <code>Bromite</code> and install the app</li>
</ol>
]]></content>
      </entry>
      <entry>
        <title>Best Secure Messaging App | FBI Document Leaked</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/best-secure-messaging-app-2021/" />
        <id>https://staging.sideofburritos.com/blog/best-secure-messaging-app-2021/</id>
        <published>2021-12-13T10:00:00Z</published>
        <updated>2022-12-24T10:00:00Z</updated>
        <summary type="html">According to a recently unearthed FBI training paper, US law enforcement has limited access to the content of encrypted communication on specific platforms.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode33s0hbhb">🎥 


<a href="https://youtu.be/wj-aR96FOA0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<p>


<a href="FBIs-Ability-to-Legally-Access-Secure-Messaging-App-Content-and-Metadata.png" target="_blank" rel="noopener" class="text-break">Full Size Image</a> -
To download a full-size copy of the image, <code>Right-Click</code> the <code>Full Size Image</code> link and select <code>Save Link As</code></p>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.npr.org/2018/06/07/588068536/wikipedia-jimmy-wales" target="_blank" rel="noopener" class="text-break">https://www.npr.org/2018/06/07/588068536/wikipedia-jimmy-wales</a> - Podcast interview with Jimmy Wales (Wikipedia Founder)</li>
<li>


<a href="https://www.foia.gov/about.html" target="_blank" rel="noopener" class="text-break">https://www.foia.gov/about.html</a> - What is a FOIA request</li>
<li>


<a href="https://therecord.media/fbi-document-shows-what-data-can-be-obtained-from-encrypted-messaging-apps/" target="_blank" rel="noopener" class="text-break">https://therecord.media/fbi-document-shows-what-data-can-be-obtained-from-encrypted-messaging-apps/</a> - Transcribed FBI Document</li>
<li>


<a href="https://propertyofthepeople.org/document-detail/?doc-id=21114562" target="_blank" rel="noopener" class="text-break">https://propertyofthepeople.org/document-detail/?doc-id=21114562</a> - Original FBI Document Disclosure</li>
<li>


<a href="https://www.law.cornell.edu/uscode/text/18/2703" target="_blank" rel="noopener" class="text-break">https://www.law.cornell.edu/uscode/text/18/2703</a> - 18 U.S. Code § 2703 -  Required disclosure of customer communications or records</li>
<li>


<a href="https://faq.whatsapp.com/general/chats/about-end-to-end-encrypted-backup" target="_blank" rel="noopener" class="text-break">https://faq.whatsapp.com/general/chats/about-end-to-end-encrypted-backup</a> - WhatsApp E2EE</li>
<li>


<a href="https://faq.whatsapp.com/iphone/chats/how-to-turn-off-icloud-backup" target="_blank" rel="noopener" class="text-break">https://faq.whatsapp.com/iphone/chats/how-to-turn-off-icloud-backup</a> - WhatsApp turn off iCloud Backup</li>
<li>


<a href="https://telegram.org/faq" target="_blank" rel="noopener" class="text-break">https://telegram.org/faq</a> - Details about telegrams E2EE</li>
<li>


<a href="https://signal.org" target="_blank" rel="noopener" class="text-break">https://signal.org</a> - Signal Messaging App</li>
</ul>
]]></content>
      </entry>

</feed>
