<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Security on Side Of Burritos</title>
  <link rel="alternate" href="https://staging.sideofburritos.com/tags/security/" />
  <link rel="self" href="https://staging.sideofburritos.com/tags/security/index.xml" />
  <subtitle>Recent content in Security on Side Of Burritos</subtitle>
  <id>https://staging.sideofburritos.com/tags/security/</id>
  <generator uri="http://gohugo.io" version="0.165.0">Hugo</generator>
  <language>en-us</language>
  <updated>2026-08-30T13:45:00Z</updated>
  <author>
    <name>Josh</name>
    
  </author>
  
      <entry>
        <title>Why I left Proton Mail and Tuta for Stalwart</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/why-i-left-proton-mail-and-tuta-for-stalwart/" />
        <id>https://staging.sideofburritos.com/blog/why-i-left-proton-mail-and-tuta-for-stalwart/</id>
        <published>2026-08-30T13:45:00Z</published>
        <updated>2026-08-30T13:45:00Z</updated>
        <summary type="html">I&amp;#39;ve been paying for Proton Mail for nearly a decade. Recently, I switched to Tuta to test that out as well. But I always wanted to get back to self-hosting my own email server. Around 6 months ago, I came across Stalwart, and I knew I wanted to eventually switch to it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode125s0hbhb">🎥 


<a href="https://youtu.be/UGQVQaR6HhA" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://proton.me/" target="_blank" rel="noopener" class="text-break">https://proton.me/</a></li>
<li>


<a href="https://tuta.com/" target="_blank" rel="noopener" class="text-break">https://tuta.com/</a></li>
<li>


<a href="https://stalw.art/" target="_blank" rel="noopener" class="text-break">https://stalw.art/</a></li>
<li>


<a href="https://stalw.art/docs/email/management/masked-email/" target="_blank" rel="noopener" class="text-break">https://stalw.art/docs/email/management/masked-email/</a></li>
<li>


<a href="https://stalw.art/docs/install/upgrade/" target="_blank" rel="noopener" class="text-break">https://stalw.art/docs/install/upgrade/</a></li>
<li>


<a href="https://stalw.art/pricing/" target="_blank" rel="noopener" class="text-break">https://stalw.art/pricing/</a></li>
<li>


<a href="https://www.smtp2go.com/" target="_blank" rel="noopener" class="text-break">https://www.smtp2go.com/</a></li>
<li>


<a href="https://docs.hetzner.com/cloud/servers/faq/" target="_blank" rel="noopener" class="text-break">https://docs.hetzner.com/cloud/servers/faq/</a></li>
<li>


<a href="https://www.tb.pro/" target="_blank" rel="noopener" class="text-break">https://www.tb.pro/</a></li>
<li>


<a href="https://blog.thunderbird.net/2025/07/state-of-the-thunder-answering-community-questions/" target="_blank" rel="noopener" class="text-break">https://blog.thunderbird.net/2025/07/state-of-the-thunder-answering-community-questions/</a></li>
</ul>
<hr>


<p><details >
  <summary markdown="span">Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>I wanted to make a video on my updated email setup. For years I was using Proton and Tuda, but at this point I have migrated all my domains to a self-hosted instance of Stalwart.</p>
<p>I want to start off by giving some background on this decision and then some of the pros and cons of it. So while I have my complaints about both Proton and Tuda, in general I think they both provide a great service. It&rsquo;s also worth understanding my outlook on email is that it&rsquo;s not private at all. You&rsquo;re using one unique identifier to contact another unique identifier.</p>
<p>Yes, you can use PGP to encrypt the body of the message and sometimes the subject. You can also use things like aliases or simple login, which can improve your privacy a bit, but that also comes with its own complications. Like now you are stuck paying for a service since you don&rsquo;t have control over those aliases, which I got to give props to Proton on purchasing simple login. It makes it much more difficult to leave their service if you use that alias feature. So if you&hellip;</p>
<p>Even with my view on the privacy of email communication, there still is a massive benefit to using an end-to-end encrypted provider like Tuda or Proton. If you use one of the big centralized providers like Gmail or Yahoo, all your emails are stored in the clear on their servers. They can scrape those emails for information and at this point use them to train their AI models. So while that does help protect your emails that are stored in your inbox, it doesn&rsquo;t help for the emails you send to anyone using Gmail or one of those other providers, but that&rsquo;s a whole separate topic.</p>
<p>Typically when you self-host, it&rsquo;s for a privacy benefit, but with something like Stalwart, if I&rsquo;m being honest, I think it&rsquo;s actually less private to self-host my mail server. If you look at my sideofburritos.com domain right now, you&rsquo;ll see the MX record points to mail.sideofburritos.com. And if you look at that, you&rsquo;ll see it&rsquo;s tied to a Hetzner IP address, so you know the IP of the VPS that I&rsquo;m using.</p>
<p>I&rsquo;m the only one using this mail server, so all the activities&hellip; originates to me. If I&rsquo;m using something like Proton or Tuda, my activity can blend into the masses, but that&rsquo;s not happening in this case. But for me, it&rsquo;s more about control and having visibility into my email versus that small, in my opinion, privacy benefit.</p>
<p>One example of this that kind of pushed me over the edge to finally set this up. I was having some issues on Tuda receiving emails. Randomly, I had an email that was getting rejected that was previously working. I checked the rejected tab in the Tuda app, and I didn&rsquo;t see anything listed there.</p>
<p>I asked their support about it, and they said, not all rejections are visible there as it depends on some criteria. It can make a difference, for example, whether the email was rejected due to an issue with the email itself that caused the rejection, or if the sending server is blacklisted. We can always reach out to the service if there is a general issue with email communications with our server.</p>
<p>So the email that was getting dropped was an email from my membership site. I have mailgun configured as the smtp sending relay on there, so I checked the logs on there. Everything looked like it should have been delivered. Malgun showed no issues with the sending of the email, so tuta was just dropping it for some reason.</p>
<p>I never really got an answer on why those were getting silently dropped, but like I mentioned earlier, that for me that was kind of the breaking point for wanting more visibility into my email instead of this sort of black box set up. And I&rsquo;m not specifically blaming them. I can only imagine the amount of phishing and spam emails they need to filter out, especially offering free accounts. Who knows what kind of traffic they&rsquo;re getting?</p>
<p>But what I really wanted was more visibility, so if something was happening I could dig into it and figure out why. So with stalwart I finished migrating all my domains about two months ago, which I think is a decent amount of time to test it out, and in that time I haven&rsquo;t had any issues with it sending or receiving emails. I&rsquo;ve updated it a few times and all the updates have gone successfully. No issues. Let me put this in dark mode quick.</p>
<p>So some of the pros with Stalwart, since you are self-hosting it yourself, you can host as many domains as you want on there. With Proton, I think the plan I had, I was limited to three, so I needed to use aliases for some domains and shared domains for emails. I couldn&rsquo;t give every domain its own email, so that was kind of an inconvenience.</p>
<p>Stalwart also supports server-side encryption using OpenPGP. So the cool thing about this, Proton actually uses PGP for their encryption, some rendition of it. But if you use a client like Thunderbird, which is what I use because it&rsquo;s the only one I found so far that supports using PGP for opening your emails on desktop and mobile, you can actually discover the published Proton PGP keys for the emails. They publish those by default when you sign up.</p>
<p>So if I&rsquo;m emailing someone at Proton.me, I click discover in Thunderbird, it finds their published public PGP key, and now those emails are intent-encrypted. So I don&rsquo;t actually need a Proton account to email someone using Proton encrypted. So that&rsquo;s pretty great.</p>
<p>And on the topic of security, Stalwart reminds me of Graphene OS in the sense that out of the box, the default setup is pretty secure. You don&rsquo;t have to worry about being an open relay just because you set it up.</p>
<p>In the past, when I used to self-host my own email server, this was about a decade ago at this point, most of those services available at the time were configured to be open by default. So you had to make sure you locked them down, didn&rsquo;t miss anything. Otherwise, you could be an open relay and now you&rsquo;re sending spam mail because someone found your server when they were scanning the internet.</p>
<p>With Stalwart, it handles MTA-STS, TLS provisioning, DKIM key generation, rotation, and DNS publication. All of that is handled automatically if you use their DNS integration. I&rsquo;m currently using it with Cloudflare and Bunny.net. Both have been working flawlessly.</p>
<p>It also has&hellip; automatic IP banning, rate limiting, ACLs. So if someone&rsquo;s scanning your server and they trigger that rate limit, that IP is automatically blocked.</p>
<p>So this next part is going to get a bit into the weeds on how email works. But if you&rsquo;re at all curious about this, it&rsquo;s going to be worth watching. Otherwise, you can just skip ahead to the cons section of this video.</p>
<p>So I currently host my stalwart server on Hetzner. And by default, they block ports 25 and 465. This is common on VPS providers. Spammers will sign up quick and start spamming from their IP addresses using a VPS, which can cause a bunch of IPs to get block listed. So by default, they block that.</p>
<p>If you&rsquo;ve been paying for a month or a few months with a VPS using Hetzner, you can request those ports to be unblocked. I did it and it was unblocked within seconds. I think it was automated.</p>
<p>But as far as sending goes, I actually use a SMTP relay. In this case, SMTP to go. The reason for that is is while I do plan to have that Hetzner VPS long term, I don&rsquo;t want to be responsible for the IP reputation of that. If an IP gets marked as spam or block listed, now people will stop receiving your emails because of the IP reputation. It&rsquo;s not something I want to worry about.</p>
<p>If I had my own AS and my own IP range assigned to me, which would be way more long term that setup than I would send from my IP range. But in this case, I don&rsquo;t. But that would be a fun future project.</p>
<p>SMTP2Go, their free plan offers 1000 emails per month. That doesn&rsquo;t count against receiving emails. That&rsquo;s just sending. I can&rsquo;t imagine more people, at least an individual, send more than 1000 emails per month. So the free plan should work for you. That&rsquo;s what I use. So far, it&rsquo;s been great. I haven&rsquo;t encountered any sending reliability issues.</p>
<p>There&rsquo;s also a bunch of other free relays out there you can use. I think Postmark has 100 emails per month. Mail gun has a thousand they allow, so there&rsquo;s definitely options, but that&rsquo;s what I use for sending. Again, I don&rsquo;t want to worry about the IP reputation of my vps, so I use a third party for the sending.</p>
<p>But getting back to some of the other things that stalwart offers, they do have a masked email option. You&rsquo;ll notice this is marked as an enterprise feature, which I&rsquo;ll talk about in a few minutes. So I believe this is similar to something like simple login. Each mask is bound to one account and can be disabled or destroyed independently, so end users can hand out different addresses to every external service and cut them off without affecting the others.</p>
<p>I really do like simple login as a service. It&rsquo;s easy to use, provides a nice privacy benefit, but it&rsquo;s kind of like the mafia. It&rsquo;s really easy to get into it, but good luck migrating away from it. So I&rsquo;m hoping to move to something like this using a separate domain specifically for aliases, but we&rsquo;ll see how that goes.</p>
<p>One other pro regarding stalwart is mozilla who offers thunderbird. They&rsquo;re going to be offering thunder mail in the future, which is a paid hosted version for email. You can join their waitlist if you want, but they have a blog post where they mention that the only project we&rsquo;re using to help build thunderbird pro is stalwart, but we absolutely want to make sure the project gets its financial support from us to support its sustainability and well-being.</p>
<p>To me, that&rsquo;s a huge benefit to using stalwart. There&rsquo;s going to be a large company behind it supporting it financially, and I think that speaks a lot to the longevity of the project.</p>
<p>Now getting to some of the cons of stalwart. As we saw on the masked email wiki page, it&rsquo;s marked as an enterprise feature. So if we go to stalwart pricing, the minimum you can pay for is 25 mailboxes, which comes out to 60 usd per year. I actually think that&rsquo;s cheaper than my proton plan currently that I have. I pay for it. To me, that&rsquo;s more than worth it to support the open source project and get some of the other features that are behind that payment.</p>
<p>And then regarding the privacy and pgp keys, so proton and tuta, well actually I don&rsquo;t know what tuta uses exactly, but with proton they automate that entire pgp key setup. With stalwart you&rsquo;ll have to generate those keys yourself, configure them. It&rsquo;s not difficult, but it does take some time to set up.</p>
<p>And like I mentioned earlier, the only clients I found so far that support that encrypted mailbox are thunderbird. I couldn&rsquo;t find any web clients that supported it, which is unfortunate. I think I saw something that stalwart might offer a first party webmail client and hopefully it&rsquo;s supported in there. I would like to have webmail accessible. So you are limited on the clients you can use. You&rsquo;ll have to use the app thunderbird desktop and mobile if you want that.</p>
<p>Stalwart does have built-in spam spam filtering, but it&rsquo;s overly aggressive. You&hellip; there is a feature where you can submit the mail and say this is not spam to kind of teach the filter. I don&rsquo;t know if I just don&rsquo;t receive enough mail or I haven&rsquo;t done that enough, but it hasn&rsquo;t really seemed to help.</p>
<p>But I do guess it&rsquo;s better that it&rsquo;s overly aggressive versus not being good enough, so I just make it a habit to check the spam folder every so often. I have also configured a few sieve rules to allow list domains and senders to make sure those don&rsquo;t get marked as spam. So again, kind of goes back to that self-hosting setup. There might be some things you need to tune yourself.</p>
<p>It&rsquo;s also worth mentioning that stalwart is currently pre-version one. They expect the version one released in the first half of 2026. It&rsquo;s currently the second half, so I&rsquo;m assuming it&rsquo;ll be next year in 2027 because at this point there&rsquo;s not, there is no stable or finalized database schema and configuration system. So when you are doing upgrades, there might be some breaking changes you&rsquo;ll have to handle yourself since you are self-hosting.</p>
<p>If that doesn&rsquo;t sound like something you want to do, then you might want to put this off till version one. Like I said, though, I started doing this about three months ago or two months ago. All the upgrades so far, there&rsquo;s a new version every week, have been straightforward and simple. Docker pull and Docker up, and the new version was deployed.</p>
<p>So those are the cons that I found so far regarding stalwart directly. These next cons are more self-hosting in general related.</p>
<p>If something happens with your email setup, there&rsquo;s no status page to check. There&rsquo;s no email support to contact. It&rsquo;s on you to resolve. If you&rsquo;re not receiving emails, you&rsquo;re wondering what&rsquo;s going on. Again, that&rsquo;s on you. You need to check the logs, see what&rsquo;s going on. Did you hit your limit in your SMTP relay? Did your ports somehow get blocked? Did Docker stop running? Did the process crash?</p>
<p>In my experience self-hosting, these things aren&rsquo;t common, but when they do happen, they can take some time to figure out. I really do think that self-hosting is easy, especially with docker. A couple commands, you can have a service running setup and you can start using it.</p>
<p>The part that&rsquo;s not easy, which I think a lot of people don&rsquo;t think about when they&rsquo;re paying for a cloud service, is consistent reliable backups. It&rsquo;s easy to set a service up, but if that hard drive dies, you know, even if you&rsquo;re using a shared hosting provider, they do have hardware issues. If that server dies and they just give you a new one with a fresh installation of your operating system, can you restore your backups? Do your backups run reliably every day? Do you monitor those backups? Do you check them for freshness? Do you document your restore procedure?</p>
<p>Different things like that that people don&rsquo;t talk about enough because they&rsquo;re not that interesting to share because you only need them in a worst case scenario. But if you are self-hosting, you really need to think about those and take that into consideration before you decide to dive in head first.</p>
<p>So is the juice worth the squeeze? I don&rsquo;t know. That&rsquo;s up to you. To me it is. I also just enjoy doing this kind of stuff.</p>
<p>If you&rsquo;re going to be annoyed when you get an alert on the weekend in the middle of the day when you&rsquo;re hanging out with some friends and you&rsquo;re now no longer receiving email, then doing something like this probably isn&rsquo;t for you. Stick to a managed provider.</p>
<p>But if you&rsquo;re at all interested in self-hosting email, I definitely recommend checking out stalwart. I&rsquo;m also thinking about doing a full setup video with another domain that I have that I don&rsquo;t currently have set up to receive email. If you think that&rsquo;d be useful, let me know down in the comments or in the comments on my blog, and if there&rsquo;s enough of those I&rsquo;ll try to make that video happen.</p>
<p>But that&rsquo;s all I got for this video. I hope you have a great rest of your day and I&rsquo;ll see you next time.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>Arrested After Using GrapheneOS’s Duress PIN</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/arrested-for-using-duress-pin-grapheneos/" />
        <id>https://staging.sideofburritos.com/blog/arrested-for-using-duress-pin-grapheneos/</id>
        <published>2026-07-30T13:45:00Z</published>
        <updated>2026-07-30T13:45:00Z</updated>
        <summary type="html">The U.S. government has charged Samuel Tunick, alleging that he gave CBP officers a passcode that erased his phone when they entered it, preventing them from searching its contents.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode29s0hbhb">🎥 


<a href="https://youtu.be/vz6OwDYDIaI" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.courtlistener.com/docket/71998357/united-states-v-tunick/" target="_blank" rel="noopener" class="text-break">https://www.courtlistener.com/docket/71998357/united-states-v-tunick/</a></li>
<li>


<a href="https://arstechnica.com/gadgets/2026/07/activist-charged-with-felony-after-giving-border-agent-duress-code-that-wiped-his-phone/" target="_blank" rel="noopener" class="text-break">https://arstechnica.com/gadgets/2026/07/activist-charged-with-felony-after-giving-border-agent-duress-code-that-wiped-his-phone/</a></li>
<li>


<a href="https://www.404media.co/the-government-hopes-to-set-a-precedent-an-interview-with-the-man-charged-for-allegedly-wiping-his-grapheneos-phone/" target="_blank" rel="noopener" class="text-break">https://www.404media.co/the-government-hopes-to-set-a-precedent-an-interview-with-the-man-charged-for-allegedly-wiping-his-grapheneos-phone/</a></li>
<li>


<a href="https://en.wikipedia.org/wiki/Stop_Cop_City" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Stop_Cop_City</a></li>
<li>


<a href="https://en.wikipedia.org/wiki/January_6_United_States_Capitol_attack" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/January_6_United_States_Capitol_attack</a></li>
<li>


<a href="https://www.youtube.com/watch?v=JTurSi0LhJs" target="_blank" rel="noopener" class="text-break">https://www.youtube.com/watch?v=JTurSi0LhJs</a></li>
</ul>
<hr>


<p><details >
  <summary markdown="span">Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>So today what I want to talk about is the case of United States versus Tunick. This is regarding the use of the duress pin on Graphene OS. I thought we could start off by just reading the official indictment against Tunick before covering some other nuances in this case.</p>
<p>So on or about January 24th, 2025, in the Northern District of Georgia, the defendant Samuel Tunick, before and during the search for and seizure of property by Customs and Border Patrol Tactical Terrorism Response Team, Supervisory Officer L.CDOT, a person authorized to make such search and seizure, did knowingly destroy, damage, waste, dispose of, and otherwise take any action to delete the digital contents of a Google Pixel cellular phone for the purpose of preventing and impairing the government&rsquo;s lawful authority to take said property into its custody and control in violation of Title 18, United States Code, Section 2232A.</p>
<p>So the first thing I want to say about this is regarding the knowingly destroy, damage, waste of, dispose, delete digital contents part. The way the duress pin works on Graphene OS is when you enter that pin, it initiates the sequence, which deletes the keys that are used to decrypt the data on the device. Those keys are used to decrypt the data on your device when you correctly enter the pin and they&rsquo;re stored on the secure element.</p>
<p>So it&rsquo;s the keys that were deleted on the device, not the actual data. For all intents and purposes, that data is now permanently inaccessible, but the data was not actually deleted. Again, like I said, this is a very nuanced point, but the law loves nuances.</p>
<p>I was trying to think of a good analogy for this. So imagine the lock you have on your house. You insert the key, you open the lock, you can access your home&rsquo;s contents. Entering the duress pin is equivalent to changing the pins on the tumbler inside the lock on the door. So now when you insert the key into the lock, the key no longer works because the pins have changed. At that point you can&rsquo;t access your home, but everything inside is just as you left it. It&rsquo;s just the key no longer works.</p>
<p>I&rsquo;m not a lawyer, but that doesn&rsquo;t sound like it was destroyed. I guess we&rsquo;ll see how that plays out. So that&rsquo;s the initial indictment. I&rsquo;ll link this down below if you want to keep up with the court case. The latest item was released on July 20th, 2026.</p>
<p>But at this point there&rsquo;s been a bunch of articles published on this topic, and the first one I want to talk about is one from Ars Technica. So in early 2025, like we saw in the initial indictment, Atlanta resident Samuel Tunick was on his way home following a trip abroad. After landing in the U.S., customs agents demanded access to his Pixel phone, which was running an alternative version of Android called Graphene OS.</p>
<p>And rather than handing over his data, Tunick used a clever feature of the software to delete everything, which again is the duress pin. He actually told the border patrol agents his duress pin, they entered it, and the data was erased.</p>
<p>During their interrogation, CBP agents told Tunick they wanted to search his phone for evidence of child sexual abuse, and if he didn&rsquo;t unlock the device, it would be confiscated. Unless you are the Catholic priest from the town where I grew up who was charged and convicted of possession of CSAM—you know what they say, it&rsquo;s always the ones you most suspect—then these types of searches for everyday individuals are usually just fishing expeditions.</p>
<p>It&rsquo;s an excuse to protect the children, like we&rsquo;ve heard dozens of times, and the thing that kind of backs that up is this is what CBP told him, but it turns out it&rsquo;s because he was part of a group called Defend the Atlanta Forest, which opposed the construction of an enormous law enforcement training facility in the area, often known as Cop City. So this is what actually landed him on a list and got him detained at the airport.</p>
<p>But it just kind of makes me laugh that they followed the typical procedure of accusing someone of possessing CSAM, and that&rsquo;s why they&rsquo;re doing the search, and in order to protect the children, please unlock your device.</p>
<p>Tunick also claims he was never read his rights and requested legal counsel several times, but the requests were denied. He was at a border area. He was re-entering the U.S., and a lot of rights are sort of in a legal gray zone at that point, which is why they can conduct these warrantless search and seizures.</p>
<p>The other article which has some great points is one from 404 Media. If you haven&rsquo;t heard of them before, check them out. They put out some really good content.</p>
<p>The agents tried to rig this game by making this all come to a head at the airport, he added. Ordinarily, authorities would need a warrant to search the contents of someone&rsquo;s phone, but at an airport, those protections often do not apply. They could have asked a judge for a search warrant for Sam&rsquo;s phone if they thought they had evidence for a crime. They didn&rsquo;t do that.</p>
<p>CBP said all travelers are subject to inspection and ensure compliance with the U.S. laws. These inspections, including questioning and rare search of electronic devices, are conducted on a case-by-case basis, taking into account factors such as travel history and law enforcement alerts.</p>
<p>And speaking of those alerts, Department of Homeland Security, also known as DHS, called the airport ahead, said Tunick was coming through, and asked officers to stop him. “We want you to get his phone and search his phone,” the officers said.</p>
<p>So a lot of this keeps going back to Graphene OS, the use of the duress pin, which I think is great. It&rsquo;s a fantastic feature. I think it&rsquo;s also worth remembering that the reason Tunick is in this situation is because he legally participated in a protest, which happened to land him on a list that got him stopped at the airport.</p>
<p>So while some protests will get you on a list that gets you detained, other protests, at least I think it was a protest, will get you a presidential pardon.</p>
<p>Regardless, if you&rsquo;re in the United States, I think this video from the Pot Brothers at Law has some really good advice if you are detained.</p>
<p>And they ask more questions? Am I being detained or am I free to go? And if detained, what do you say? I invoke the fifth. And then what do you do? You shut the fuck up.</p>
<p>Now, whether or not you should enter the duress pin if you are detained, I guess we&rsquo;ll see how this case goes and see if it is a legal thing to do. Again, if you want to keep up with the case, I will link this down below so you can check for updates.</p>
<p>I do think this is one of the most important cases when it comes to privacy in recent years. So I&rsquo;m extremely curious to see how this goes. When there are updates, I will make some future videos on it. But until then, hope you have a great rest of your day, and I&rsquo;ll see you next time.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>Live conversation with GrapheneOS team member - spring-onion</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/live-conversation-with-grapheneos-team-member-spring-onion/" />
        <id>https://staging.sideofburritos.com/blog/live-conversation-with-grapheneos-team-member-spring-onion/</id>
        <published>2026-07-20T13:45:00Z</published>
        <updated>2026-07-20T13:45:00Z</updated>
        <summary type="html">Join me live for a conversation and Q&amp;amp;A with spring-onion, a member of the GrapheneOS team.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode98s0hbhb">🎥 


<a href="https://youtube.com/live/56-DCAHU29Y" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.reddit.com/r/LinusTechTips/comments/1ospoca/im_the_grapheneos_project_member_who_accompanied/" target="_blank" rel="noopener" class="text-break">https://www.reddit.com/r/LinusTechTips/comments/1ospoca/im_the_grapheneos_project_member_who_accompanied/</a></li>
<li>


<a href="https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/</a></li>
<li>


<a href="https://en.help.roblox.com/hc/en-us/articles/49648939984916-Android-Remote-Attestation" target="_blank" rel="noopener" class="text-break">https://en.help.roblox.com/hc/en-us/articles/49648939984916-Android-Remote-Attestation</a></li>
<li>


<a href="https://privsec.dev/posts/knowledge/badness-enumeration/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/knowledge/badness-enumeration/</a></li>
<li>


<a href="https://www.wired.com/story/they-built-privacy-tool-grapheneos-now-sworn-enemies/" target="_blank" rel="noopener" class="text-break">https://www.wired.com/story/they-built-privacy-tool-grapheneos-now-sworn-enemies/</a></li>
<li>


<a href="https://developer.android.com/develop" target="_blank" rel="noopener" class="text-break">https://developer.android.com/develop</a></li>
<li>


<a href="https://discuss.grapheneos.org/d/34369-original-grapheneos-responses-to-wired-fact-checker" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/34369-original-grapheneos-responses-to-wired-fact-checker</a></li>
</ul>
<hr>


<p><details >
  <summary markdown="span">Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>Okay, looks like we&rsquo;re good to go. Again, welcome, everyone. Today I&rsquo;m joined by spring-onion from the GrapheneOS team, and we&rsquo;ll be taking your questions, kind of going through things. We don&rsquo;t really have much of a format for the chat, but let&rsquo;s see how it goes.</p>
<p>Um, yeah. Hello, everyone. Here I am. My name is spring-onion. I am the community manager for the GrapheneOS project, and if you have been following the project close-ish, chances are you will have seen my name around. I&rsquo;ve done some things in the past. Either that, or maybe you also know me from my pseudonym, Dave Wilson. So, hello, everyone. Excited to meet you on a more personal note, perhaps.</p>
<p>Yeah, definitely appreciate you coming on, and I&rsquo;m excited to see how this goes. If anyone has questions, post them in any of the chats, and we&rsquo;ll try to get to them and see how it goes.</p>
<p>Let&rsquo;s see. Just taking care of the self-hosted stream quickly and changing some settings.</p>
<p>Okay, let&rsquo;s stop this one quickly. Okay, now we&rsquo;re good.</p>
<p>Reading some pretty, pretty nice comments.</p>
<p>Ready? Okay, I think we should be good. One question I saw, I guess I&rsquo;ll throw this one out quickly. Someone else actually asked me this too: Any further news on the Motorola phone, or any updates on that?</p>
<p>It&rsquo;s funny because it&rsquo;s something I thought about before the livestream. I was wondering when that question was going to show up. Apparently, it&rsquo;s the very first one, so that&rsquo;s pretty funny.</p>
<p>Not much I can say in that regard. It&rsquo;s going well. That&rsquo;s what I can say. Things are going as planned, as per plan. So, yeah, all good on that front, but not much more I can really share beyond what&rsquo;s been shared so far by the press release and what you can find on our socials and whatnot.</p>
<p>Yeah, I figured it was kind of hush-hush at this point.</p>
<p>There are many things that are not really set in stone yet, many things that might change over time, et cetera. But rest assured, everything is going great. So, yeah, we&rsquo;re on track.</p>
<p>Good to hear.</p>
<p>Okay, yeah, it&rsquo;s something that we didn&rsquo;t actually touch on initially. The plan is that, Josh, you look over the stream chats, and I check our community chats. Remember, you can ask your question on the stream as well as in the chats on our Discord and Matrix.</p>
<p>If you use the chats, please do so in the media channel. Because these are the only ones I&rsquo;m watching. All right, let&rsquo;s see. There&rsquo;s a question here, how long have I been the community manager? Not that long. I honestly, I cannot really give you a definite date because it kind of just came along. Yeah, it kind of just came along over time. So I can&rsquo;t really give you a definite date. But for a couple of months now. Yeah. Maybe about September last year, but you know, you didn&rsquo;t hear too much about me until rather recently. Oh, sorry.</p>
<p>About that I need to I forgot to to mute my phone there rookie mistake here&rsquo;s a question I got is there a way for the apps not to see tun0 interface when they are excluded from the VPN tunnel um interesting question I&rsquo;ll be honest that is about my pay grade um I suggest you ask in our general chats um.</p>
<p>That is above my pay grade I&rsquo;m sure just in general we have a lovely community and someone&rsquo;s always around to hopefully hopefully answer that question yeah the forum&rsquo;s a great spot for that stuff yeah that too let&rsquo;s see is everything oh here&rsquo;s a good one this is kind of a hot topic is everything we&rsquo;re hearing about Google locking down installing apps outside of Google Play Store going to affect GrapheneOS in any way?</p>
<p>And what are your thoughts on this for the Android community in general?</p>
<p>Great question, because that is actually one of those topics I&rsquo;ve wanted to touch on a little deeper. So there is a site, it&rsquo;s called keepandroidopen.org, right? Pretty catchy name, I like it. We did sign the petition, okay? We did sign it because we like the general idea on what keepandroidopen is trying to achieve, right? What it&rsquo;s trying to achieve is to bring attention to Google, bring attention to AOSP, bring attention to what is happening with AOSP, what Google is doing. And as of right now, keepandroidopen is solely focused on the upcoming developer, like Android developer verification.</p>
<p>But it&rsquo;s settled. To rule out rollout relatively soon I think it was september originally I&rsquo;m not sure the date has changed um the problem is just um you see it&rsquo;s it&rsquo;s complicated because um Keep Android Open is a little alarmist sounding okay if you go open the web page right now uh it&rsquo;s gonna tell you hey Android is being locked down in x amount of days um and Google is gonna like block side loading and it all sounds very alarmist um and maybe not entirely accurate because you see what&rsquo;s happening is that yes Google is restricting side loading um in the future however they&rsquo;re not blocking it entirely okay um the biggest hurdle they put in place is that you as the end user have to wait 24 hours to install an app by a developer that didn&rsquo;t verify themselves to Google. That is a one-time process. And well, okay, you do also have to click through a bunch of warnings, but the 24-hour wait, that is like the biggest hurdle you need to overcome. And that&rsquo;s really it, right? But Keep Android Open. I mean, it does say that like further down in the line, further down the website, sorry. It tells you what Google has planned and how to, I suppose, reactivate normal side-loading behavior. But we, as a project, like as a whole, we have seen a lot of people on the internet who seemingly don&rsquo;t quite like fully understand the implications and like what is actually happening with with this program and that is a problem right because people might feel inclined to.</p>
<p>Drop Android they might feel inclined to switch to Apple um and that is a big problem so um we we are currently talking with the Keep Android Open folks and uh suggesting them they should perhaps um update the site a little to um better better accommodate the the reader in a sense. I guess along those same lines the age verification that some states or places are looking to put into effect will that come into play on GrapheneOS at all or no no no No, we will just not implement any of that. It doesn&rsquo;t really affect us in a sense.</p>
<p>Though we will just not, as far as I&rsquo;m aware, not much can really happen to us. So we should be covered there. But to go back to Keep Android Open, you see, from my perspective, if the reader or the customer in that sense reads your website and comes to a conclusion, a conclusion they shouldn&rsquo;t come, then I would argue it&rsquo;s kind of your responsibility to make sure to kind of rephrase your wording so people do get the overall gist right. So hopefully that is something we can work together on to maybe&hellip; Fix in a way because it is a real problem um people are very scared about this Android developer verification and like yes you you should definitely talk about it you should educate people um but we need to educate people right okay so people know what&rsquo;s coming so they can react appropriately um and most importantly not decide wrongly right we don&rsquo;t want people to jump ship to to Apple okay when that&rsquo;s really not necessary um so yeah because another another thing what at least I personally kind of envision for Keep Android Open is that it becomes sort of a hub of like central location um central like information that you can inquire about like the current state of Android or AOSP.</p>
<p>So it can perhaps talk about some of the other issues that have been, you know, plaguing AOSP as a whole, like the Play Integrity API, right? Play Integrity API is a topic that is significantly worse than the current Android developer verification. So hopefully, we can work together to essentially add to the, to the website and improve on things. But I have a good feeling, as I said, we are, we are talking with them and, um, yeah, hopefully we can, we can figure it out.</p>
<p>Do you want to grab a question from the Discord, if there&rsquo;s any over there? Cool. So, let&rsquo;s go. All right, let&rsquo;s see.</p>
<p>Where are you from, Mr. Onion? I live in Germany. And I also speak German fluently.</p>
<p>That was a short one, so maybe I&rsquo;ll grab another one. What are the current plans regarding localization? Translation of the OS apps and language support for future keyboard rework slash replacement. So localization is something that we have been looking into. This is also another topic where people often come in the chat rooms and suggest, hey, why do you not just accept translations from other people, right? Like a crowd-sourced&hellip; Crowdsourced&hellip;</p>
<p>Translation and it it sounds good on paper on first glance um the problem is just that if we add a language okay then we need to support that language moving forward okay what does supporting language mean if text gets changed with the next update that text needs to be updated as well like immediately okay and so this whole procedure cannot really um stop the update from coming out so every needs to be in sync in a way and done very quickly so that is always something to consider and the the approach of this crowdsource approach of translations carries a risk um I suggest you look into what happened with Ubuntu uh you couple of years back when I believe it was their installer who the like their installer featured hate speech temporarily so that is obviously not good and something we absolutely want to avoid as for what like languages would be supported first.</p>
<p>I would assume that German is pretty high up there but yeah it is it is definitely something we want to do but with with everything we do really we want to do that with a lot of care.</p>
<p>So in a sense it is on the to-do list.</p>
<p>So next one my whole family and friends use WhatsApp what would you use on GrapheneOS would you just install it or use another device and I think there&rsquo;s also been some issues lately registering for new one WhatsApp accounts. So I guess any thoughts on that? Yeah. To kind of answer the first part of the question, I mean, the de facto standard is Signal, I guess, among the privacy community. If you&rsquo;re talking with your family primarily, I think you&rsquo;re going to have a better time having them switch to Signal, right, if possible. But don&rsquo;t fret. Don&rsquo;t fret to install WhatsApp on GrapheneOS if it comes to that. That is something that a lot of people get wrong. They think, hey, there&rsquo;s this awesome OS and it&rsquo;s super privacy focused. And that means I&rsquo;m not allowed or I do something wrong if I install an app like WhatsApp or even Facebook, like Instagram, all these apps that are not exactly perceived as privacy. Respecting. But you couldn&rsquo;t be more wrong in that regard. Because like we have, you know, Gryphoner has many features to deal with these kind of apps that are somewhat harmful to your privacy, right? Like contact scopes, for example, in regards to WhatsApp. I believe that WhatsApp will ask for your contacts, you can use contact scopes to limit the access of your contacts to WhatsApp, you can either give it no contacts, or maybe some select, some select contacts if you want. So yeah, if you know, if you&rsquo;re gonna run privacy harmful apps, do it on GrapheneOS. Because that is the very best place to run them. Yeah, as for the WhatsApp problem.</p>
<p>That is something I have noticed in the community I believe that WhatsApp might be looking for like basic play integrity you can achieve that on graph in os but you need to so you need to install WhatsApp from the Google Play Store and you need to be logged in the Play Store if you fulfill these two requirements WhatsApp should work I would assume but that is also another another case where perhaps you should consider inquiring the the chat rooms in the forum um maybe maybe somebody else has another tip they can share yeah I think things are just a little bit tougher in that regard even creating new Google accounts has been more than a hassle in the recent months so I don&rsquo;t know if that&rsquo;s part of it got a bunch of questions here but if you want to grab one now there&rsquo;s so many questions yeah I&rsquo;m just trying to I feel like I&rsquo;m kind of you know sorry I&rsquo;m kind of maybe rambling a little too long I&rsquo;m still kind of easing my way uh into this into the stream uh let&rsquo;s see I&rsquo;m going to try to grab one from Matrix um let&rsquo;s have a look um satire question for downtime do you eat spring onions absolutely spring onions are an amazing garnish and I always have some at home and I would definitely recommend you to also have some so um yep definitely thumbs up from me um okay next up those graffinos have any potential plans for services to run alongside GrapheneOS to enhance out of the flash usability and also get an.</p>
<p>Additional steady stream of revenue maybe an Android app privacy audit service encrypt encrypted backup service etc um so to answer the out of box experience we are currently reworking like the default apps um to kind of you know modernize them because you know admittedly you know the the aosb apps that come pre-installed are not exactly super modern so we&rsquo;re currently uh modernizing those I believe that the messaging app so the SMS app is about to be released um so for the SMS app I believe there is still some work to be done um kind of in the background on a technical side of things but the ui modernization is pretty much done and I think you can expect that to be released this month in july I would believe that the gallery app is the next in the list um as far as I know a lot of progress has been done on that front hmm but that is not so confirmed just yet but yeah we are working with it as for um your main question uh any other kind of service to run it depends really I mean we are a non-profit you know we run entirely by donations um Android app privacy audit service no I don&rsquo;t think we&rsquo;d really be interested in that too much um because you know some people might consider WhatsApp to be fine to use other people will not install that no matter what encrypted backup service I mean there&rsquo;s a backup solution already in place it is local admittedly I mean if if we were to run like these kind of services will be paid I mean we&rsquo;d most likely develop them ourselves and.</p>
<p>Uh that is again something that needs to be done with with great care.</p>
<p>I I wouldn&rsquo;t I wouldn&rsquo;t completely rule it out but uh not at the moment no this one&rsquo;s regarding GrapheneOS development are llms used in development of GrapheneOS in any way whether it be for code generation code review etc. Um I know that some of our developers have been using like ai effectively you You know, obviously, they use it in specific circumstances, and they don&rsquo;t just bytecode the OS. But like, that&rsquo;s, that&rsquo;s the difference, right, AI can be a tool. But you need to know how to use the tool. And I&rsquo;m sure that our developers know how to, how to use LLMs and AI in a broader term, to maybe accelerate development or even research, while, you know, not really compromising the security of GrapheneOS, essentially, you know, of course, we make sure that the quality of GrapheneOS isn&rsquo;t, isn&rsquo;t going down the drain.</p>
<p>Yeah, there&rsquo;s definitely a lot of a spectrum of AI use when it comes to code. Mm hmm. There&rsquo;s some pretty bad stuff. And then there&rsquo;s. Some you know there&rsquo;s always the defense like oh ai hallucinates which for sure it does but also developers make mistakes there&rsquo;s yeah yeah it&rsquo;s a big answer I think it&rsquo;s it&rsquo;s really difficult for me to to like give a solid opinion about that because you know I&rsquo;m not a developer myself and it also just ai on its own kind of keeps progressing it&rsquo;s also worth noting that the devs also review each other&rsquo;s work right so that happens all the time and of course we also note when when something has been made by ai but every everything&rsquo;s being reviewed by an actual human so there is no actual like vibe coding happening here we don&rsquo;t do that here.</p>
<p>Okay you Um, any plans to change the default search engine to start page or quant or even karma search? Um, I, I, I&rsquo;m not aware of any such plans, you know, it&rsquo;s something we might revisit in the future, but at the moment, I think, uh, we&rsquo;re, we&rsquo;re pretty okay with DuckDuckGo. So on the topic of browsers, um, question, when will Vanadium be available for other Android phones? Is there any plans for that or in the works? Um, well, the thing is we develop Vanadium for GrapheneOS, right? So a lot of the work goes to support GrapheneOS exclusively.</p>
<p>Um, I believe you can already run Vanadium on a non GrapheneOS Android. So, um, yeah. But it&rsquo;s not something we&rsquo;re going to test I cannot give you a timeline for that it is something we might release in the future but I I wouldn&rsquo;t bet on it anytime like soon like very soon like very near near future I wouldn&rsquo;t I wouldn&rsquo;t bet on it yes there&rsquo;s also a lot of a lot of things we we want to do for Vanadium no features so all right let&rsquo;s see. Someone commented this month new SMS app awesome um I mean yes like that is my current status um but yeah don&rsquo;t please don&rsquo;t quote me on that if it doesn&rsquo;t happen okay I I&rsquo;m pretty I&rsquo;m pretty confident um that it will but at the end of the day um things can change very quickly right like um the devs might be working on it on a specific feature you uh on a specific part of the os but then something might come in some kind of bug and then everything needs to be dropped and we need to handle handle a bug or whatever so um but yeah it&rsquo;s it&rsquo;s looking good on that front for sure um I want to get another question because I really just commented on a on a comment there I&rsquo;ve heard that graphene needs more developers is graphene a good project to get started in phone software development and if so how to get started with little knowledge about general development um interesting question um I I would say that graphene was isn&rsquo;t exactly a junior dev kind of project So I suggest you should definitely brush up on your development skills first.</p>
<p>But for sure, it is a great place for inspiration. And just maybe you can get a good idea or a good overview on how we run things that might give you some inspiration, especially on the security side of things. I mean, everything is open source, right? So you can poke around. You can also ask the devs themselves if you want. They&rsquo;re also around often.</p>
<p>A quick note, maybe, Josh, before you read out the next question. I&rsquo;m sure we&rsquo;ll be missing a lot of questions. Guys, feel free to repose your questions every now and then. Just don&rsquo;t overdo it, okay? But I think repose are okay. Yeah. That&rsquo;s that&rsquo;s all from from my side are there any here&rsquo;s one are there any huge security functionalities coming down in the future similar to something like hardened malloc. I am not aware that there&rsquo;s any like groundbreaking features in that regard coming um I believe like harden the hardened memory allocator is just something that you also kind of maintain over time I mean in most recent times there was memory tagging right which we kind of set up um as the first like kind of production ready state um so we&rsquo;re pretty proud of that memory tagging incredible feature um also one of the primary reasons we recommend the Pixel 8 and above and I&rsquo;m assuming that&rsquo;s probably going to be some of the requirements for the Motorola device yeah yeah exactly you see that is also why um the upcoming Motorola phones are premium models because um you know Tensor has had MT for a few generations now but Snapdragon has not so for like on the Snapdragon side of things it&rsquo;s a very new development in a way and it&rsquo;s one of those cases where it needs to kind of trickle down first that&rsquo;s why it&rsquo;s it&rsquo;s really only available in like the latest and greatest Snapdragon chip which is good on the one hand because it&rsquo;s also very um performant right especially in comparison to the Tensor chip but the downside is that it&rsquo;s obviously a premium model which means it&rsquo;s gonna be expensive.</p>
<p>Okay, let&rsquo;s see. Will the GrapheneOS team members use Motorola devices as their main phone or still use Pixels? That is a good question. I think that is a very kind of personal matter.</p>
<p>I&rsquo;m not really sure, to be honest. It really depends on what people prefer. But also, at the end of the day, these upcoming Motorola phones will be flagships, right? So I don&rsquo;t think there will be much to hate on, in a way, if you understand where I&rsquo;m coming from.</p>
<p>I think this one, I always see this come up from time to time in the forums. But what about IPC scopes? Is there any progress on that or any complications that have come up? Mm-hmm. Yes, so IPC scopes, definitely something that a lot of people are looking forward to. And it&rsquo;s also something that we said we&rsquo;re going to do in the past. But the truth is, it&rsquo;s a very, very difficult feature to implement, right? Because the fun of this feature would be to stop any kind of side channel communication, any kind of leaks from happening.</p>
<p>And making sure that nothing is leaking, making sure it&rsquo;s actually bulletproof is very difficult. So it remains to be seen if we will move forward with this feature. Because at the same time, you also have the private space, which is essentially a secondary profile. That is just kind of a little, just a little bit more convenient to use. And so&hellip; Yeah. You can also make the argument hey maybe we should focus our work on private space make sure you know you can use multiple maybe in the same profile.</p>
<p>So yeah it it remains to be seen but is it is very difficult to to implement right because you see we we don&rsquo;t we don&rsquo;t do like half baked features okay like if we release something it&rsquo;s because we are we&rsquo;re confident that it it works and it works well and it also has a point right because um we get a lot of like feature requests um of people who who have ideas but then if you actually look into it and really like sit down think about think about the feature think about uh you know what what is the purpose of this feature um what could defeat the feature in a way and then you you kind of come to the conclusion that maybe you So many features out there aren&rsquo;t actually as great as they sound like at first.</p>
<p>And I think when you look into a feature, it might seem simple at first, but there&rsquo;s a lot that goes into it. And if something&rsquo;s released and it seems like it was simple, I feel like that means it was just more work. Because there&rsquo;s some things I see in apps where they just bolt on functionality that anyone asks for. And before you know it, you just have a bunch of complex options and something that don&rsquo;t really make sense and aren&rsquo;t really maintainable. Yeah, we are very selective in what kind of features we add to GrapheneOS.</p>
<p>Because A, you have the initial workload of actually implementing the feature. Well, the workload doesn&rsquo;t only consist of implementing a feature. Because as I said before, you need to design the feature. You need to think it through, what is it for, how could it be defeated? Passes that stage then you know I suppose we give it a priority um how how big of an impact would this feature bring um and then decide from there but it doesn&rsquo;t end there right like just because you you add a feature like for example duress PIN password okay that is something that a lot of people ask for it&rsquo;s it&rsquo;s it&rsquo;s out there right pretty proud of that feature but anytime a new version of Android comes out we need to port the rest PIN and in fact we need to port everything right so every feature that you add comes with this kind of hidden maintenance cost that you need to consider and so over time as like feature set of GrapheneOS grows the the actual burden of work also increases and that is something you need to be very very wary of um so yeah.</p>
<p>Here&rsquo;s an interesting one GrapheneOS has been disappointed in the changes to the Android release cycle and security patches approach from Google do they talk about this with Motorola are they on the same page and might they help you lobby for changes maybe in cooperation with other OEMs that might agree with your criticism um.</p>
<p>I can say to that that um we are very happy to have Motorola as a as a partner right I mean it&rsquo;s a it&rsquo;s a pretty strong player in the field um so that&rsquo;s that&rsquo;s always nice to have but I&rsquo;m afraid I cannot give you any detailed information so So it&rsquo;s all about that, but I cannot answer that sufficiently, I&rsquo;m afraid. While we&rsquo;re on the topic of Motorola, for the new device coming out, is the goal kind of regarding security, is it kind of parity with the current option available or is there work to make it better than what&rsquo;s currently available? Great question. Great question and also difficult to answer definitely. Because, of course, these Motorola phones will meet the requirements that are listed on our website, okay?</p>
<p>But it is difficult to predict which of the available options, Motorola or Pixel or, for example, Pixel 11, will be outright better. They could be like trading blows in one regard or another. Remember, for example&hellip; I would just assume that for example with the secure element that the Pixels have a titan m2 and I believe starting with a Pixel 11 I believe uh that will even be upgraded to the titan m3 that is a very good secure element okay like that is a very good element so that&rsquo;s that&rsquo;s just going to be difficult to beat but at the same time because we are working so closely with Motorola on these phones um I would say there&rsquo;s a lot of potential right like there&rsquo;s a lot of potential because we&rsquo;re working together with them so closely and we can kind of suggest changes as they come in so remains to be seen but I would I would assume that that both options will remain a good pick so so Who are public figures, for example, Edward Snowden, that GrapheneOS supports?</p>
<p>I&rsquo;m not sure if I understand that question fully. Do you mean people that support us, like GrapheneOS, like famous people of the kinds of Edward Snowden? Maybe you can paraphrase that.</p>
<p>What&rsquo;s another question here? Is there any way to use multiple VPNs at once for a user profile? I use Tailscale to access other devices, but I can&rsquo;t seem to be able to use a separate VPN simultaneously, so I&rsquo;m stuck making an exit node on one of my devices, but that introduces difficulties like not being able to easily change the VPN country and latency for multiple hops, phone, Tailscale, exit node, VPN through WireGuard. It&rsquo;s kind of intended that way. I mean, sorry, it&rsquo;s intended that each profile has its own VPN slot.</p>
<p>I&rsquo;m not aware that there is a way to use multiple VPNs at once in one profile. I&rsquo;m not aware of that. I&rsquo;m not exactly an expert on VPNs, but that would be news to me.</p>
<p>And I would say there are no direct plans to change that behavior. We are already kind of busy. You know, fixing all kinds of VPN leaks on Android, which we&rsquo;ve been squashing one by one. On the topic of VPNs, what apps and services on GrapheneOS are known to possibly bypass the VPN entirely? For example, Wi-Fi calling, connectivity checks, etc. Yes, I know connectivity checks do that. But, yeah, Wi-Fi calling might be another one. I&rsquo;m not aware of any other ones. But, well, you see the wave of VPN leaks, etc., Have kind of shown that there is clearly a lot of work to be done on that side, on the front of VPNs.</p>
<p>And it&rsquo;s important work, of course, just by the nature of a VPN, right?</p>
<p>Thank you. Thank you.</p>
<p>Okay I got a clarification of that previous question people with views that graphene was is in favor of oh.</p>
<p>Um.</p>
<p>I I mean graphene was in general is very anti-authoritarian so I would say that whoever you know shares that kind of sentiment is probably up there but you know people have vastly different beliefs um so I&rsquo;m afraid I cannot tell you any any specific names.</p>
<p>Are there any estimates on GrapheneOS user counts I think last time I saw a post about it it was maybe 300 000 you Funnily enough, every time this question shows up somewhere on the internet, people link to this one forum post that I actually responded to. So I believe it&rsquo;s pretty high up in the search results. I should edit the post. So last time I heard it&rsquo;s over 400,000 users. It&rsquo;s really difficult to give a precise number. In fact, it&rsquo;s impossible to give a precise number because there&rsquo;s no telemetry, right?</p>
<p>There&rsquo;s no statistics of that kind. We can only really look at the quote unquote statistics of the download server, of the update server that tells us how many updates get pushed through and make assumptions on that metric.</p>
<p>I guess on to that question. This is my own personal curiosity. I think you guys have your own AS now. So you can any cast. The ip ranges that does that mean that updates then are routed to the nearest update servers wherever the user is geographically at this point um that is probably right I will admit um that kind of question goes over my head but yes we do have our own space um and it sounded like it was amazing but I will admit I I don&rsquo;t know the specifics uh but I&rsquo;m sure that you know one of our our devs would be happy to uh to further respond to that to the question of viewers maybe maybe drop it in the on the Discord or the Matrix yeah I always I&rsquo;m fascinated by networking stuff I know it&rsquo;s not the most popular topic these days because everyone likes to outsource to big tech but yeah.</p>
<p>Oh let&rsquo;s see Next-gen Motorola handsets are said to be officially supported, presumably this means the GrapheneOS public keys are hardwired, no warning messages on boot up. Will there be stock Android versions of the same phones? If so, does this mean those phones will pass the problematic Play Integrity API checks when installed with GrapheneOS? That&rsquo;s a lot of ifs and questions. I can tell you that if a phone, like if the future Motorola phones do run, like, okay, sorry, let&rsquo;s assume you buy a phone, it could be pre-installed with GrapheneOS, you could flash it yourself, that remains to be seen, the point is, so you&rsquo;ve got that future Motorola phone in your hands and it runs unmodified GrapheneOS that will not pass Play Integrity.</p>
<p>Like beyond beyond the most basic um verdict that will not that will not pass.</p>
<p>Uh going back to I got um got a little message here uh going back to the to the question about the the dns and the our own ip space um I I&rsquo;m pretty sure that is accurate what what you what you said there before yeah I believe that is accurate yeah it&rsquo;s a pretty solid setup at that point then compared to I guess the previous setup where you didn&rsquo;t really have that option yeah yeah it&rsquo;s it&rsquo;s it&rsquo;s pretty pretty crazy yeah um.</p>
<p>It&rsquo;s nice right because um graphite always kind of carries a name uh so for example when we go on twitter or or maston or or wherever and and and we&rsquo;re like hey can we get some can we get some servers we&rsquo;re kind of running out of capacity we always get like so many so many providers kind of texting us and be like hey we can we can sponsor this we&rsquo;ll sponsor that um so that&rsquo;s um that&rsquo;s pretty cool yeah cuts down and costs considerably right like that is pretty awesome and of course we do also have a sponsor page on our website so uh there&rsquo;s that oh this question kind of goes with the updates tangentially why is there no option to turn off updates completely I want to decide when to update there should be an option and there is you can turn off updates fully you can do that um it is not like just like a toggle uh but that is by design because we don&rsquo;t like just just don&rsquo;t okay I mean like you can do it you can do it by disabling the the updater like you there&rsquo;s an app on a graph in his phone I believe it&rsquo;s just called updater or like update client if you disable that there will be no more updates um we we know you know we don&rsquo;t we have not implemented toggle for this because it&rsquo;s just a pretty bad idea to do in general I have personally seen way too many people that disable the updater then they forget and then like a year or so down the line they come into the chat rooms and they have some super obscure issue that nobody else seems to be having and then.</p>
<p>It turns out you know you ask them for the big number and they&rsquo;re just running a release from a very long time ago so uh the option is there but don&rsquo;t don&rsquo;t do it unless you have a good reason to right you Unless you know what you&rsquo;re doing, just don&rsquo;t. There you go. That would be my recommendation. Let&rsquo;s see.</p>
<p>I think for those of us who want to keep Play services in a separate profile or rather a private space, we lose the ability to use RCS messaging. Ideally, I would love to get everyone to use Signal, but I&rsquo;m also a realist. Most people don&rsquo;t want to install a separate app just to message one person. Does GrapheneOS have any plans in the future to implement RCS functionality into their own messaging app as an alternative to Google Messages? I would say yes. It&rsquo;s one of those things that would be lovely to have.</p>
<p>And it&rsquo;s also one of those things that will be difficult to implement. And practice. But, yeah, that is, I mean, for sure something we would love to have.</p>
<p>This one&rsquo;s regarding Android 17. What does the GrapheneOS team think of Android 17 so far? And have there been any major issues observed? Some people have mentioned battery life in the chat.</p>
<p>Well, the thing is with battery life, people, like, after every, like, update, there will always be somebody that, you know, brings up battery life and how it has gone downhill for them. But the truth is that most of the updates don&rsquo;t even, like, change anything battery-wise. I mean, yes, major Android versions do that. But on the other hand, I&rsquo;ve also seen plenty of people who reported an increase in battery life. So, it goes both ways um really depends on people&rsquo;s setups uh etc. I I can say for myself that with Android 17 I don&rsquo;t think I noticed like I mean you can&rsquo;t really expect massive improvements uh I don&rsquo;t really think I noticed uh like a significant improvement but it definitely didn&rsquo;t get worse so that&rsquo;s probably some some smaller optimizations.</p>
<p>Here and there um oh yeah by the way josh I don&rsquo;t know maybe you also feel up to the task to just see if you can answer some of those questions yourself uh oh yeah uh let&rsquo;s see we can we can try that so you&rsquo;re also a bit more interactive in that regard kind of forgot to mention that also another thing I forgot to mention maybe you know what I mean we&rsquo;re just winging it right there&rsquo;s no plans um but something I forgot to do at the start of the stream but how many people watching the stream right now are GrapheneOS users maybe type one in the chat if you are and type two if you are not kind of curious to know what kind of what kind of audience we have here.</p>
<p>I&rsquo;m just going to start a poll on YouTube quick see what shows up oh yeah you can do that yeah okay seeing a lot of ones in okay lots of other troll too in in the chats all right that makes sense I would assume that like on your end of things like in the in the streams you that um there will be a couple of twos as well yeah there&rsquo;s definitely more more twos there all right but definitely a bunch of already existing users nice nice to see self-hosted chat or self-hosted stream shows the same seems like most people at this point okay yeah I see my comment in the YouTube chat just only yesterday from Android welcome welcome to the club here&rsquo;s one question that I think comes up quite a bit and I&rsquo;ll have my answer on it if you have anything to add how unsafe is it to use a Pixel 6 after the update support ends in october my go-to answer is using an end of end of life device is never safe I think people sometimes have this impression that if they aren&rsquo;t a target then you don&rsquo;t have to worry about it but at this point with you know mass exploitation things like that it doesn&rsquo;t matter if you&rsquo;re a target just matters if your phone is connected to a network Yeah, pretty much.</p>
<p>You could be done for. Yeah. I mean, you know, just because you&rsquo;re running an end of life device and you&rsquo;ve not been hacked yet doesn&rsquo;t mean it&rsquo;s actually safe to use. Uh, I mean, yeah, like from a project opinion, you know, you need to switch to a newer Pixel immediately, but I would assume that perhaps this question is related to the Motorola phones. Perhaps they are, that user is looking to kind of bridge the gap and then buy the Motorola phone instead.</p>
<p>But we don&rsquo;t know when exactly these phones are coming out, right? And, uh, I think the, the Pixel six series, uh, yeah, in October of this year, they&rsquo;re going to end of life. So not, not very safe to use, unfortunately. No. Okay. I mean, my personal opinion is if it was just a month or two, maybe it&rsquo;d be like okay-ish.</p>
<p>But yeah, it also remains to be seen what we do with the Pixel 6 series and also Pixel 7s. Because you see in the past, we used to offer extended support to the phones that launched with just three years of support. And we said we weren&rsquo;t really going to do that for the Pixel 6 and above because they came with five years of support, which is decent enough. I&rsquo;m not entirely sure if that plan has changed or not. I suggest maybe ask again when the time has come. But right now, we don&rsquo;t. Don&rsquo;t really have it planned but it could change right uh we could decide to do some extended support uh but the problem with these extended support releases is that um people often uh people often would keep using these devices as if they are still considered safe right and they&rsquo;re not um they just they just aren&rsquo;t of course you can do your best to to kind of secure them uh to get you on a new phone um but yeah remains to be seen.</p>
<p>And the answers are well overdue yeah so on this one are there any plans for GrapheneOS to host a unified push server for those that can&rsquo;t do it themselves.</p>
<p>Um kind of basing off memory here but I believe that is something we could do? Yes. I think so. It&rsquo;s a bit risky to just say that out now, but I believe that is something we could do. Yes. Potentially. Yeah. Yeah. Yeah. I would definitely put that in the realm of, yes, we could do that. What is your favorite feature? That GrapheneOS provides. My personal opinion, and Josh, maybe you can also give yours after that. It&rsquo;s kind of the whole package. I love how in control you are of the OS. I like how you boot the phone for the first time after you flash it and it&rsquo;s very empty. There&rsquo;s no blow where there is no terms of condition in terms of service there&rsquo;s a privacy policy you have to accept um it&rsquo;s just the the like immediate relief and like this feeling um that the phone you&rsquo;re holding in your hands is truly yours you know.</p>
<p>Um so that&rsquo;s that&rsquo;s mine that&rsquo;s my favorite yeah mine I&rsquo;d say are the toggles under security and privacy they&rsquo;re kind of the boring features the ones that can prevent an app from opening that you know might have a memory leak or something like that or the auto off Wi-Fi auto off Bluetooth just kind of small things like that yeah yeah it was a pretty good the I mean like a lot of the like security toggles like hard memory allocator yeah but not exactly um very um how should I best put it like in your face in a way right like the probably like the the scopes feature with the context scopes exactly sandbox Google Play that is like all of these things are are things you you kind of see in front of you um whereas hard and memory allocator like memory tagging all of these cool features they&rsquo;re awesome but uh you don&rsquo;t really you don&rsquo;t interact with them too much right but they&rsquo;re they&rsquo;re kind of the unsung heroes um that are super important yeah it&rsquo;s it&rsquo;s tough when making YouTube videos on these features because I think they&rsquo;re incredibly exciting but to show someone like hey look at this cool feature and you just toggle something and you&rsquo;re like it&rsquo;s there it&rsquo;s working it&rsquo;s it&rsquo;s not big and flashy like some yeah exactly Google ad editing and image live or yeah yeah and also how do you sorry I just want to say how do you kind of present it to be or like presented or kind of in a way that is also entertaining right at the same time I mean very I mean for sure very.</p>
<p>Content out there that um takes a deep dive into like hardened or hardened memory allocator for example there was a paper written about that some time ago which as far as I&rsquo;m aware was pretty high quality as well but that is very on the educational sort of things right um it&rsquo;s maybe doesn&rsquo;t does not necessarily scratch the entertainment itch so on the topic of security could you give a quick overview of the security updates I forget the exact name of them but the uh security preview release I think it is there&rsquo;s a couple questions about that that came up uh depends on the specific questions um but yeah with the security preview releases it is worth noting that these are technically not open source right like we cannot release them like that we cannot release the source code for these patches until Google kind of does themselves or like give gives their okay but we can distribute them as a binary so we can implement them into GrapheneOS via the security preview releases it&rsquo;s just that you yourself cannot technically take a look at the at the source code but in practice if if you&rsquo;re running GrapheneOS then you kind of trust us the the maintainers so there&rsquo;s no reason not to enable it um there&rsquo;s so many patches in there for so many months in advance um.</p>
<p>Yeah it&rsquo;s not a good change by Google um because it just gives bad actors so much more time to potentially. Abuse visa security holds um but you know it is what it is and we&rsquo;ve kind of worked around it that way and it&rsquo;s worth noting though that these patches that we&rsquo;ve applied they are like they should be relatively easy to reverse engineer so someone could do that post in the internet and then it&rsquo;d be fine it&rsquo;s it&rsquo;s a very silly system overall um very silly system doesn&rsquo;t really protect it restrictions no no it&rsquo;s it&rsquo;s it&rsquo;s pretty ridiculous but you know it is it is what it is seeing the Discord chat right now someone&rsquo;s mentioning that everything is open source and there&rsquo;s an answer security preview patches of an embargo that prevents source code publishing until the embargo ends yep that is pretty accurate.</p>
<p>You can like we can say you spin We just cannot show them to you.</p>
<p>So that&rsquo;s why we have these like two release channels in a way where you got the normal graphite noise that is truly fully open source and then one with your security liquid previous security patches applied.</p>
<p>If Vanadium has all the hardening stuff within it, is there any reason to use browsers other than Vanadium? Well it is worth noting that the Brave browser for example is doing pretty good on the anti fingerprinting front, as far as I know, they are doing pretty good work on that front. But I suppose Vanadium&hellip; Needs to improve on um but I mean yeah I would definitely recommend using Vanadium it&rsquo;s a tough cat and mouse game when it comes to that yeah yeah and a lot of people kind of have the wrong idea on how to how to combat it um. There&rsquo;s there&rsquo;s a lot of kind of advice out there on the internet um where people tell you oh you know install this extension install that extension edit these settings do this and that uh but the problem is every time you install an extension or try to like fake something um specific like specific values you kind of just make yourself stand out more and not less yeah there&rsquo;s great projects like piehole but at a certain point you know those help with third-party domains but when someone moves to using first-party domains to start serving their ads from Now you get into traffic inspection and it just gets infinitely more difficult at that point.</p>
<p>Yeah, on a more direct privacy level, yeah, for sure. DNS blocking is something you can do, go for it. But the problem is just that the moment, for example, Facebook, okay, starts to route its analytics through facebook.com instead of analytics.facebook.com, you have two options. Either you don&rsquo;t use Facebook or you accept that the analytics are going to pass through anyway. And I feel that is something that&rsquo;s already happening pretty widespread. So I feel like this whole DNS blocking shenanigans, as I said, it&rsquo;s something you can do, go ahead, but don&rsquo;t feel too safe doing that. Um yeah don&rsquo;t don&rsquo;t feel too safe because I I feel like these kind of um features uh they they make you feel very safe even though you you may not be.</p>
<p>What do you feel is the greatest usability issue bearing play integrity in graphene was at this time oh that&rsquo;s a good question the greatest usability issue. Um you know what let&rsquo;s ask the community go ahead um what is your greatest usability problem with with GrapheneOS or like what what bothers you the most can I ask the community community because I&rsquo;ll be honest nothing came to mind immediately you So I&rsquo;m just using this to get some time for me to draft a response myself. On that topic, while they&rsquo;re putting some answers in there, I do think the on-device speech to text was a huge increase in usability versus someone having to go download it and figure that out, you know? Yeah, yeah, for sure. Especially in terms of accessibility, right?</p>
<p>Like super, super important, for sure. That is also something that will be improved continuously over time. But yeah, that is a big win. We try to make it a great experience for everyone, right? So no matter what, no matter your personal circumstances or like your knowledge.</p>
<p>A couple that I see in the chat over here is notifications without Google Play services. No matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what, no matter what backup handling yeah backup solution carrier things like voicemail.</p>
<p>Yeah um backup solution I mean it&rsquo;s I I think we included backup solution it&rsquo;s called seed vault I don&rsquo;t think it&rsquo;s as bad as some people will uh want you to believe it&rsquo;s it&rsquo;s gotten better over time it&rsquo;s definitely something that we&rsquo;re looking to either drastically rewrite or just replace entirely um but uh I believe it&rsquo;s it&rsquo;s doing okay but for sure it&rsquo;s it&rsquo;s not good enough I I do agree um what was the the other the other one they mentioned uh kind of slipped my mind oh notifications without play services yeah well that is something you kind of need to ask the the absent question right like to kind of ping bro devs for example proto mail right doesn&rsquo;t really doesn&rsquo;t really give you notifications unless you have Google Play um perhaps something they should uh they should get on tap the pay is another one that I see commonly come up yep yep that is a good point yeah uh the thing is like energy payments they do work on GrapheneOS the problem is that many banks kind of rely on Google wallet or Google pay to kind of handle it in the background and it&rsquo;s it&rsquo;s you know Google pay that doesn&rsquo;t work because of play integrity um so that is uh rather unfortunate if all the banks start using Google pay in the background for its functionality and Google pay doesn&rsquo;t work um but if you if you if you have a bank that kind of features its own NFC implementation then uh you might be fine you might be okay I I do admit I believe in the us.</p>
<p>At the very least um there pretty much is no no bank that kind of has its own system in place anymore there are some in the like eu space but not so much in na however um if you have a smart watch you can do you know contactless payments for that um and for for the people in the eu you can also use something like curve pay um or more or to be more detailed in the european um economic area yeah I&rsquo;ve heard people having good luck with garmin smart watches I think is what it was yeah yeah that works yeah yeah for sure oh here&rsquo;s a question I&rsquo;m actually curious about too uh does GrapheneOS us have any opinions on services like cape that offer imz rotation is that kind of a gimmick or is it something that&rsquo;s actually useful in terms of privacy.</p>
<p>Um I don&rsquo;t believe we have um talked about that specifically and I&rsquo;m afraid I don&rsquo;t really have much of an opinion about that myself so I can really answer that um I can tell you that cape definitely is gaining a lot of popularity in the privacy space or at least it does in my in my kind of field of view but we&rsquo;re not partnered with them they they do send us um what is it I believe like the first I think if you are like a new user I think like the first month of payment goes to us if I&rsquo;m not mistaken something along those lines but they do like donate to us um but yeah it&rsquo;s it&rsquo;s not really a partnership in that regard. Our only partnership is with Motorola but Motorola there&rsquo;s no money changing hands.</p>
<p>Um so yeah on the topic of Motorola I&rsquo;ve kind of seen some theories on the benefits that they get you know having an offering of a secure device they could offer to enterprises is there anything else that&rsquo;s kind of hasn&rsquo;t been really talked about in terms of what benefit they get having a partnership like this is I mean GrapheneOS is widely recognized as the pinnacle of mobile privacy and security you and I I would say that having that name in your portfolio in in a way is a pretty big win on its own and is something you can definitely market market with like your your products or like Motorola&rsquo;s products whatever they they have cooking in the background let&rsquo;s see.</p>
<p>Where is the stream yep it&rsquo;s happening right here.</p>
<p>On the topic of usability issue default apps especially gallery yeah I don&rsquo;t know if you if you heard it before but gallery is in the process of being replaced and there&rsquo;s some good work done on that front as I said uh but it&rsquo;s not done yet but yeah progress is being made um like my my personal opinion is that yeah default apps uh pretty crucial to to rework um for sure for sure it&rsquo;s just um it does a lot for like the initial impression as well right maybe makes it a bit more welcoming in a way.</p>
<p>Oh speaking of first impression had a question from earlier it&rsquo;s two parts so why are there no images on the website the person said they think it would help when someone&rsquo;s trying to decide if they want to use GrapheneOS or not and why the pure black theme for everything.</p>
<p>Um yeah good question um I I don&rsquo;t necessarily disagree but some questions could be nice that would kind of be part of like a bigger website refresh that we might do in the future. Yeah, I mean, there&rsquo;s definitely a lot of things you could do for sure. Yeah, maybe compartmentalize some of the wall of text because my personal thing is that maybe that is sometimes a little bit makes people maybe a little bit scared. I also think that some people think that there&rsquo;s this massive document full of documentation and the feature page and everything. But in reality, you don&rsquo;t actually need to read the whole thing or much of anything because in practice, most of the user facing features are somewhat self-explanatory, and if they&rsquo;re not, you can always consult the docs, the docs, the documentation. Later on or you know ask in our chat all right let&rsquo;s see.</p>
<p>It&rsquo;s going to your gallery was already unacceptable an Android kitkat what even is that user experience fair enough yeah fair enough um fair enough.</p>
<p>Oh here&rsquo;s one will we ever be able to get an in-depth interview with the GrapheneOS founder. Uh so daniel mckay um never say never I would say.</p>
<p>But so that I can confirm or or deny anything yeah kind of tough to answer that um someone also you have yeah pretty much pretty much do you have any insight to the process of getting in partnership with Motorola like was it a quick thing was it multi-year was it um yeah that&rsquo;s definitely something I I can I can say to that um it&rsquo;s pretty funny because um when we did this announcement that we&rsquo;re working with a top 10 Android OEM right um it was so funny to see the like conspiracy theories and the investigations done done by people but the thing is in reality if you were paying really close attention to, I believe it was the Discord chat, we had a Motorola employee. Yeah, so saying it here, Moto devs just kind of showed up in the dev chat one day. Yeah, that is exactly what happened. They just showed up on the Discord and were like, hey, let&rsquo;s see if we can like work together essentially. It was just like a couple of messages. I think it didn&rsquo;t really get widespread attention. But people who like saw those chats, you know, they pretty much already knew it was Motorola. So that was pretty funny.</p>
<p>Do you think GrapheneOS would ever be willing to provide new notification sounds, ringtones, background images, etc. I believe that the ringtones and and whatnot are just the ones that come default with AOSP, right? I mean, maybe? Perhaps we could include the ones that come with stock, for example.</p>
<p>We just heard at the start of the screen that the onion is rocking the default application sound. I do, yeah. Honestly, I kind of like it.</p>
<p>It&rsquo;s nostalgic. Yeah. I don&rsquo;t know. I&rsquo;ve kind of been rocking it since the very beginning, since I started using Garfin was in, what was it, May 2023?</p>
<p>Oh, somebody says, I&rsquo;ve seen a Qualcomm employee here before. Missed the Motorola one. Yep. Yeah. The Qualcomm employee? Yeah. That could also be. Next question. Yeah. Yeah, it&rsquo;s pretty interesting, right? If you just pay close attention. In a way, this Discord is a bit of a spoiler sometimes. But yeah, we got widespread support for the Motorola partnership in general. There was some controversy. Maybe it&rsquo;s worthwhile to point it out. But that there are essentially, I mean, you see, there is Motorola Mobility, and then there&rsquo;s Motorola Solutions.</p>
<p>And they share the name Motorola, but they are very distinct companies that are doing their own thing. And we are part of Motorola Mobility, the smartphone maker.</p>
<p>Any questions on your end, Josh? Yeah, actually, this one&rsquo;s from me. Or I guess&hellip; Guys could just make a statement on it so a lot of people like to use the term rom and os interchangeably even though they&rsquo;re not could you uh kind of give a quick summary on that just why GrapheneOS is not a rom and why it&rsquo;s an os um yes so the term rom stands for read only memory and so that kind of already implies that GrapheneOS is not a rom and it&rsquo;s also implied because GrapheneOS has the two letters os which you know stand for operating system and uh so yeah I mean it is a full-fledged operating system um just like lineage os is a full-fledged operating system and the reason we don&rsquo;t really like people calling graphene was it wrong is that okay a it&rsquo;s just straight up wrong but b it um it kind of gives off the impression that it&rsquo;s some kind of like hobby you project right uh and we we don&rsquo;t really want that impression um because it&rsquo;s it&rsquo;s not right um it&rsquo;s a production ready system and people should uh view it as such.</p>
<p>Yeah I think that&rsquo;s a good distinction to make because it does come up every so often but we&rsquo;re far from the rom days on Android os um so to kind of circle back to the Motorola question when I mentioned that you know they were kind of showed up in the Discord I believe I didn&rsquo;t actually answer that question fully kind of getting mixed up here a little bit um because we&rsquo;re juggling multiple chats I just want to mention uh yeah so you know they they reached it out to us uh which was pretty cool and um yeah as I said there is no money changing hands um you You know, mutual benefit is that we get the support from Motorola, which includes, you know, the developers, the engineers, which is super, super helpful. And, well, they also get our expertise, of course.</p>
<p>And, in a way, the GrapheneOS brand, in a sense that they can then advertise how they&rsquo;re the ones that brought GrapheneOS to a non-Pixel. Because that is something I&rsquo;m sure a lot of people have thought about. Like, you know, why did we, like, why? Sorry.</p>
<p>Why did, why do we. Have not released a graphic device phone until now right like why why why so late right like why why are you with Motorola um and the truth is like a lot of OEMs have reached out to us in the past and you know a lot of these OEMs um were also very motivated to work with us and you know that&rsquo;s great because I in my opinion motivation is like half a deal right you need to want to to to work with us to actually realize this um the problem is just when you are a small OEM you don&rsquo;t necessarily have the manpower um and everything else that kind of goes into a project like this okay like of course we we could have already released some average phone with for example a mediatek chip Like just kind of average hardware with, at best, average security, but that&rsquo;s not what we&rsquo;re doing here, right? If we&rsquo;re going to release a phone or if we&rsquo;ll help to release a phone that should carry the GrapheneOS branding at the end of the day, it needs to meet our requirements.</p>
<p>Because, you know, GrapheneOS is also a brand, right? People hear GrapheneOS, they trust GrapheneOS, they know if they use GrapheneOS, they get the best of the best. You know, some people&rsquo;s lives depend on GrapheneOS. So we will only release something that we are absolutely certain of ourselves that we believe in. That&rsquo;s something I wanted to mention.</p>
<p>Has GrapheneOS received any user data requests from any law enforcement agencies in any country? That&rsquo;s something I want to mention. Like, IP address logs of users who downloaded the OS from the site?</p>
<p>I don&rsquo;t believe so. My first hunch says no. But there is also simply no data to share. Like, you know, like, for example, like, kind of a little off topic, but people always hate on, like, support, like, privacy companies, like, for example, you know, Proton, like ProtonMail, et cetera. People would hate on them for complying with, like, a valid warrant of having to give out user data. And, like, you know, if you want your service and company to continue existing, you kind of have to comply with the law.</p>
<p>But at the same time, if you just don&rsquo;t collect this information in the first place, there is nothing to share. You know um and that&rsquo;s just how all our services work um there&rsquo;s no telemetry there&rsquo;s no real identifiers there is nothing of that kind um yeah like there&rsquo;s no real risk of of of getting that that kind of warrant um but yeah I&rsquo;m not I&rsquo;m not uh I&rsquo;m not aware of any any such requests since you guys don&rsquo;t keep logs has it been difficult to prevent abuse at all you know if you get ddos and you don&rsquo;t keep many logs you really can&rsquo;t filter or block the traffic so it&rsquo;s kind of the the idea like just have enough hardware to take it sort of thing yeah um not really in terms of like ddos I mean ddosing yeah it did like does affect us as well of course but um recently we&rsquo;ve had to deal with just a little spam. Also, no forum. I mean, we discussed with Josh, there was a lot of spam and forum. And that is problematic because we don&rsquo;t really collect any info. There&rsquo;s no there&rsquo;s no capture system, right? Because that&rsquo;s not exactly privacy respecting most of the time. And I don&rsquo;t think many people would exactly appreciate that. So yeah, that is kind of a problem sometimes. Yeah.</p>
<p>But we do end up coming up with with solutions at the end of the day, to to handle that, that sort of, that sort of trouble coming our way.</p>
<p>Circling back to the topic about ROMs and why we, you know, Graphic Noise is an operating system as well, got a comment that we also work on the yeah, we do indeed also like work on the on the kernel, right? We do kernel adjustments as well. So it is indeed a production ready system, but isn&rsquo;t just like surface level kind of changes. That is why it should also be regarded that way.</p>
<p>And back to Motorola, since that&rsquo;s still a popular topic. Yeah. Understandable. Yeah. Is it confirmed that GrapheneOS will come pre-installed or will it be similar to a Pixel where the user has to handle it themselves? That is not confirmed yet. Dot. Fortunately, I cannot give you a more precise answer. It is definitely something that a lot of people will want. And I mean, we want it too, but yeah, nothing really confirmed yet. But hey, if we have something to share, and we will, we will let you know.</p>
<p>Are there any other open source apps or projects that GrapheneOS endorses formally or informally or that you personally like? Another great question. We, like, in general, don&rsquo;t endorse many things at all. Because we also think that, you know, people should just kind of do their own research and decide. Based on that research, I mean, we do often talk about different kinds of services and kind of give our opinion on a technical level, but we barely endorse anything. Honestly, the only thing that comes to mind is the Accrescent App Store that you can actually find in the GrapheneOS App Store on your phone.</p>
<p>If you, for everyone running GrapheneOS isn&rsquo;t ready.</p>
<p>Yeah it&rsquo;s it&rsquo;s one of those few things that are in the app store because it also has a security benefit it there&rsquo;s just a nice chain of trust already established because you see if you install graph in os you verify that your install of graph in os is genuine then so is our app store which means that the crescent installer is also genuine and then you know a crescent itself also does a bunch of verifications and so you know it goes from GrapheneOS installed verified that means a crescent is verified that means the apps that you get from a crescent are also verified so that is that&rsquo;s nice but yeah a crescent is definitely one of those uh projects that I would say we we do that indoors yeah so let&rsquo;s mention signal and body yeah I I guess yeah I mean I don&rsquo;t think we need to endorse that too much um just because it&rsquo;s pretty known in the privacy community like signal and like it&rsquo;s fork molly pretty much the staple.</p>
<p>Speaking of verifying like with what comes pre-installed I have a tough time explaining this to people but could you maybe give some insight as to the benefits of the auditor app and maybe how that works at a high level and why it&rsquo;s beneficial to use uh yeah so the auditor app kind of uses hardware based features to crypto graphically verify the integrity of your os and you know you can do so over a period of time as well you set it to like I don&rsquo;t know any any number like every week it&rsquo;s gonna uh it&rsquo;s gonna do a routine check uh through the remote service you for example and it&rsquo;s gonna like print you the data that it gets from that it&rsquo;s gonna tell you hey your phone is in the dispatch level you know your bootloader is locked.</p>
<p>Essentially everything&rsquo;s gonna be fine and yeah it&rsquo;s very good doesn&rsquo;t cost you anything so just leave it running.</p>
<p>Is it just set up remote at a station is like a hash of what the os is currently at or what&rsquo;s going on or is it more than that or like what specifically maybe is it verifying and how yes it does also like verify the verify boot keys and whatnot.</p>
<p>So oh this might be a good clarification on the crescent question so if you endorse a crescent is that a secondary endorsement of the apps inside of a crescent um no because like you know the GrapheneOS team doesn&rsquo;t really decide what what apps get into the crescent store um I mean the main developer of the crescent store is also a a bot um like in the in the team so you know they&rsquo;re no stranger um but they likewise don&rsquo;t really I mean they do of course decide what apps go on their store also because um it&rsquo;s currently in alpha state right and uh so there&rsquo;s not too many apps on there but the point is that you know the store could also um somebody could also like upload a proprietary app on it and it would also be welcome you know at some point in the future um um so no we don&rsquo;t exactly endorse any of the apps inside and along those same lines someone also mentioned that inside the GrapheneOS app store if you go to the messaging app it used to say that to use a secure message app such as molly signal and simple x but it seems like I guess that was removed I never realized it before has the recommendation on simple x changed at all um what up so the SMS app right yeah inside there the description oh the description um um I believe that just has to do with uh I um let me let me think about that for a second trying to recall what happened there Okay, luckily, I have some of my colleagues kind of help me out here and there.</p>
<p>So shout out to those.</p>
<p>I believe it was just because like Signal and an extension Molly are just kind of easier to use, kind of more mainstream.</p>
<p>They&rsquo;re just easier to use than SimpleX. So I believe that&rsquo;s kind of where it comes from. Yeah, that is a good point. Yeah, you&rsquo;re right. That was mentioned in the past.</p>
<p>Also, hello, shout out to Akason, one of the fellow mods.</p>
<p>I got another one here unless you want to throw in a question um this one I&rsquo;ve seen come up in the forum time and time again so I don&rsquo;t know what the answer is going to be but what devices are used for building apps and os releases for security what is recommended because it has to be a desktop pc um terribly sorry can you repeat that like that question again I I I admit I kind of zoned out there for a bit on that first part I&rsquo;m not gonna please repeat yeah I&rsquo;ll reword it to so the question basically is what os is being used to build GrapheneOS and what desktop os is recommended um great question uh a question is very difficult to answer because we don&rsquo;t really give too many recommendations on that in that regard, because I mean, we do talk about which one is technically better.</p>
<p>As for our own like infrastructure, I believe with pretty certainty that it is Arch Linux. So there&rsquo;s that. But as for what desktop OS were a comment, I mean, the truth is they&rsquo;re all really far behind like Android or iOS. So there isn&rsquo;t like the perfect recommendation to make. I guess there&rsquo;s just a recommendation to make that is a little less bad. Yeah. I mean, I&rsquo;m not an expert on these things, but I believe that on the Linux side of things, Arch Linux is one of the better options just because of how fast updates come out.</p>
<p>Right.</p>
<p>And you know they don&rsquo;t do any kinds of weird like um configuration uh messing around with that um they just release the updates everything&rsquo;s good the follow-up stream and uh yeah so I yeah I guess on the desk on the desktop the next side of things um arch is most likely one of the one of the better options but you know that doesn&rsquo;t mean that desktop index is a good option as a whole right um oh someone asked what os do you use personally uh yeah that actually um contains what I just want to say um you know that doesn&rsquo;t mean I mean it&rsquo;s a bit of a philosophical matter because it doesn&rsquo;t mean okay decilinx isn&rsquo;t as good um it&rsquo;s just using an Android phone but not everyone can move all their computing needs to a phone right even with um desktop mode coming coming to Android and and Pixels right like that&rsquo;s that&rsquo;s kind of out there and it&rsquo;s continuously improved um it&rsquo;s not necessarily a full-on replacement as for my own needs I do also use arch and I also use windows for some for some use cases.</p>
<p>Yeah I mean ideally you use your graph in osfer that is the the ideal um the problem with um desktop operating systems is uh you know they have a a large history to them um They&rsquo;re pretty old, by all accounts. So they just come with a lot of kind of legacy craft, a lot of kind of bad design choices that on the mobile end of things were luckily mostly avoided because mobile phones kind of just came later. So that is really the primary reason why. Yeah, desktop operating systems are pretty far behind. I had this dream one day that I just come home and I plug in my GrapheneOS device to a monitor in like a docking station.</p>
<p>And I use that for the desktop. I take it with me when I go, but hopefully someday. I mean, you can do that, right? Like you can do that for DisplayForward, I believe. I think, no, HDMI should also work. But the point is that DisplayForward is like. Officially it&rsquo;s it&rsquo;s fully there the support is fully available for the Pixel eight and later so unfortunately if if anyone listening right now has a Pixel seven or older I&rsquo;m afraid you are lucky in that regard but it is what it is the hardware support is only in the of the newer Pixels.</p>
<p>Um how much you can do there but yeah I mean desktop mode is a thing for Android and it&rsquo;s it&rsquo;s really usable I&rsquo;ve not tried it myself but supposed to be usable. So there&rsquo;s one question here why not secure blue for the GrapheneOS team um good question I I mean this is just my uneducated assumption but I think a lot of it also has to do with the fact that the infrastructure is kind of already set up and it&rsquo;s it&rsquo;s working well because of course we also apply our own hardening um I I would assume that the answer is don&rsquo;t change your running system there you go.</p>
<p>Kind of on that topic of desktop um how are the keys secured for builds. Are the machines air gapped at all the machines are air gapped yes um kind of really tell you much more beyond that because you know I suppose sharing the exact configuration is a security risk on its own but you can bet that these machines are highly highly secured so which they should be you know if they contain the the keys or if they&rsquo;re used to to sign the bills for sure very very important.</p>
<p>Would any features found in Motorola OS be shared to GrapheneOS should they want it or sharing code to fix an issue like the old prominent Bluetooth pairing to a car issue.</p>
<p>Potentially yeah I mean there is just a lot of kind of teamwork so if the topic kind of comes up I&rsquo;m sure they can help us and you know we can help them.</p>
<p>As I said I mean Motorola is a very very strong partner for sure.</p>
<p>All right I think that&rsquo;s about it on my end josh I don&rsquo;t know if you have anything anything new on your end on the stream chat a couple here uh do you guys have any policies in place like incident response sort of things like what if signing keys get leaked is there like a plan of action to do or is it more if that happens we&rsquo;ll handle it then um there probably is some internal pan um but I&rsquo;m sure the the plan a is that this never happens and everything is done to stop that from from ever happening.</p>
<p>But yeah I I can&rsquo;t really give you the details on that because uh naturally I don&rsquo;t uh deal with it with a sign case.</p>
<p>Let&rsquo;s see oh someone asked me why I have the name side of burritos uh oh thank you I forgot to to ask you this I was curious go ahead yeah so basically so I do like burritos I think they&rsquo;re superior to tacos and when I was looking to begin a couple criterias I had for naming were nothing that gated me into a specific topic because funny enough the actual like first videos I had or ideas for this channel were personal finance videos they&rsquo;re all hidden at this point so you can&rsquo;t see them anymore and I also really wanted a dot com and that&rsquo;s pretty tough to find at this point so side of burritos it kind of landed on that and here we are yeah I mean it&rsquo;s it&rsquo;s catchy right why why have a generic sounding name if you can be called a set of burritos or or a spring-onion yeah exactly yeah you understand Yeah, exactly. You know, people will remember because it&rsquo;s just extraordinary.</p>
<p>Two questions here that are related. What are the responsibilities of a community manager and do I love my job as the community manager? Responsibilities can range.</p>
<p>To a lot of things, really. I mean, in practice, it boils down to talking to people, really. That&rsquo;s the most, I guess, primitive action there is if you boil it down. Talking to different people, communicating with different people, making sure that people understand what you&rsquo;re saying. Someone says, I shall be using spring owners in my- burritos next time I have them to celebrate this live stream it&rsquo;s a great idea yeah man I mean I I believe you can put spring on it uh spring onions on on anything so pretty much but yeah I mean yeah just just talking to people um and you know maybe um. Maybe this is a great time to talk about another topic that I have seen somebody uh drop in the chat here uh the I don&rsquo;t I don&rsquo;t remember the exact question but they asked um how to best phrase this they they kind of asked um how will we handle um like social media backlash um I believe it was in that kind of spirit um maybe it&rsquo;s something along the lines of or how do we how do we look to to kind of improve on that front and um I I have a a lot of things to say about that uh so maybe maybe stock up on your on your popcorn um so I mean from from from my perspective it&rsquo;s like um you know there are some people out there that will you know they want you to believe that this is like a massive problem and you know that like we hate everyone and we hate every project and uh all kinds of you know other other claims like that um and uh I mean what what should I say I mean it&rsquo;s it&rsquo;s just not true I mean yes I I&rsquo;m of course biased um however.</p>
<p>The kind of inherent nature of the internet and and social media is that people kind of they&rsquo;re they&rsquo;re quick to believe what they read like first um not many people actually go through the effort to like investigate what they read um and in a way like negative news or like negative press um also achieves a lot of engagement uh which kind of worsens the the quote-unquote problem um but what what a lot of people or what these people right I guess that are maybe um I don&rsquo;t want to use the word hostile but maybe the the kind of people that are not maybe not the most friendly to us um what they like to kind of exclude and and not mention you Is that there are plenty of people we don&rsquo;t hate and we don&rsquo;t have problems with. Um, I mean, like, for example, on the side of like content creators, we have you, Josh, you know, we have, I don&rsquo;t know, uh, Naomi, shoot, what was her last name?</p>
<p>Was it? Oh, Brockwell. Well, yeah, or, or that, yeah, I keep mixing up. We have, you know, we have you, we have Naomi, we have David Bombay, uh, where that interview with Metroplex is, is, is that, uh, definitely watch that if you&rsquo;re interested, um, we have, you know, the hated one, uh, who also made an interview with, uh, Gabe, AKA Floodwald, one of the, one of the devs, um, you know, very, very blinders tech tips. Um, so we, we are, you know, very good, um, quote unquote relationship with, with all of these content creators, for example.</p>
<p>Um and also what a lot of people are like what yeah what kind of most people don&rsquo;t see because it happens mostly behind closed doors is when you know people reach out to us okay um maybe they they got banned um but that can be for many reasons they reach out to us and the truth is oh wait someone says in terms of content creators pewdiepie as well yep that is also technically true he also made content um like if you know it&rsquo;s related content uh the point is what what many people don&rsquo;t see is that people pretty often they reach out to us and they say hey I&rsquo;ve been banned or hey you know whatever happened in the past let&rsquo;s let&rsquo;s talk it out and that also happens from our side you know we do also reach out to people from from our side as I said that is something that is kind of hidden from from the public but but it does happen and and you know people who um may have for example spammed the the chat rooms for a long time or trolled in in other ways um you know these people you know some of them are in fact in like the Discord chat for example and being very like you know they&rsquo;re productive members of the community or well you don&rsquo;t need to be productive but you know they&rsquo;re very welcome in the in the chat rooms um so so there&rsquo;s that um um the the point I&rsquo;m really trying to kind of get across is that there is always two sides to a coin and the problem with the internet that people often only see one side of the coin and not both of them right and that leads to issues.</p>
<p>Sometimes so um you know that that doesn&rsquo;t mean that we are like infallible and that you know we never make mistakes ourselves you know that&rsquo;s not true um but the point is that we are definitely a lot more approachable than some people will will want you to believe so there you go I think I think that pretty much uh summarizes what I what I want to mention I do want to add too um it&rsquo;s tough being online my community is much smaller than obviously GrapheneOS but it&rsquo;s a lot of work it might sound simple like I just reply here reply there but when you have you know thousands of people something goes viral it can be very difficult to kind of yeah not control the message but get a uniform message out there that sounds good especially when you&rsquo;re trying to combat something that is misinformation the way I look at it too is there&rsquo;s some people out there who like to use the the strategy of two truths and a lie so they&rsquo;ll say something of yeah Google spies on you this happens now let me throw in my thing that I&rsquo;m not going to prove but since you believe the first two truths now yeah yeah those sound better and to disprove that it just takes so much more work and they don&rsquo;t want to justify it usually there&rsquo;s yeah there&rsquo;s just a lot that goes into it that is an amazing point you know it is it is unfortunately significantly easier to spread a lie than it is to refute that lie often right um especially when it.</p>
<p>It gets messy and it&rsquo;s difficult for people to kind of collect all the information that is, yeah, it gets very messy for sure. Yeah. Especially when you&rsquo;re looking to hear something that you want to hear like, okay, Google is listening to me through my phone. Oh, great. I wanted to hear that. I don&rsquo;t care what information about it against it comes out. You know, not saying one way or another, but it&rsquo;s just a lot that goes into it. So I think you guys do a really good job at moderating that for what it is. And the community is very picky on a lot of stuff. And so, it could be tough. I mean, there&rsquo;s a lot you could say to that. I don&rsquo;t really want to blame the people only. The point is like, you know what, let&rsquo;s take Linus Tech Tips as an example. Probably a little&hellip;</p>
<p>Surprising because you know his video is is pretty good um the point is what happened when the video was released um but you know the videos is great okay um it&rsquo;s it&rsquo;s very good you know it has one or two mistakes but um it&rsquo;s it&rsquo;s still a very very good video the problem is when it was released it had a maybe um more questionable title and and thumbnail you know it was it was essentially clickbait okay um it was it it kind of uh portrayed graph in a way as something for criminals you know it was it was just a joke okay it was it was more clickbait um it wasn&rsquo;t really meant serious um the problem is when when I when I saw that and then you know I I checked out Reddit it and people were complaining about you know linus detectives doing this thumbnail in this title um and then I you look on the like att subreddit and I I see the same thing but like kind of vice versa where you know the the att folks are kind of complaining about the graffiti community um and how you know like we don&rsquo;t understand a joke right and suddenly we had these like two camps of people um that were both kind of right and wrong at the same time um and so what what I did then is um I I drafted a a post okay on the addt subreddit and I kind of just tried to uh bridge the gap between these two communities uh and uh fine enough the the post is still up um that post it took me what was it I think um yeah I think I spent.</p>
<p>Um four hours on that post like just drafting it and selecting the right words it worked great like it got tons of upvotes like over 1k upvotes which is honestly a lot I would argue people pretty much agreed across the board and I like to believe that that kind of helped to to bridge that the gap between these two communities um I think if you just talk to people um most of the time that that helps a lot um yeah I mean points also people often kind of run around with half-baked knowledge uh superficial knowledge and you know that just happens because not everyone can be an expert at everything right and that&rsquo;s okay the problem is just when you inadvertently spread that half baked knowledge um it can it can become very difficult to rectify that to to fix those those kind of misunderstandings because um many times the people involved um like it becomes a very kind of emotional topic and it&rsquo;s it&rsquo;s very very very difficult to to navigate at times um.</p>
<p>So yeah maybe that is that&rsquo;s going to help to give perspective on that I think you guys had a good point about when it comes to like misinformation being spread on why you don&rsquo;t block ai bots to the forum because at first I was thinking yeah block them why let them have the information but if they get it directly from you at least they can hopefully provide more accurate answers if someone does go that route for information yeah yeah exactly like ai is just whatever is on the internet right so it makes sense to to try to feed the ai yeah the more accurate information so but uh also on that note I think it&rsquo;s also worth adding that uh like we are looking into ways to um do better in the sense of like informing people in a yeah in just a better way um for example moving to maybe kind of longer winded blog posts where you can explain everything piece by piece uh kind of give like a timeline of things um and and yeah try to Try to figure out things that way.</p>
<p>There&rsquo;s a question here, will GrapheneOS support Motorola tablets in the future? I mean, the plan is to continue supporting future Motorola devices. You know, I don&rsquo;t know if they have a tablet planned. But, you know, if they do and they meet our requirements, why not? Yeah, I mean, we also support the Pixel tablet, right?</p>
<p>What programming language is GrapheneOS trying to avoid and why specifically C++? The question I got. Are we specifically avoiding C++? I&rsquo;m not sure.</p>
<p>That is a question. I cannot answer I&rsquo;m afraid I&rsquo;m not aware of any like specific language that we outright avoid at all costs as far as I understand you know some some some languages are just better at at certain at certain things oh wait a second.</p>
<p>Oh yeah that is a good point as I said sometimes I get some DMS here here and there but that kind of helped me out it&rsquo;s memory safety which makes sense you know like memory corruption bugs are like a great source of like overall vulnerabilities in general as a whole you know that is why we have hard and memory allocator that is why we we love memory tagging and that is also why we like rust because rust is doing a lot better in that regard to um reduce or you know not introduce memory bugs in the first place it can help just eliminate it all together at that point then instead of trying to patchwork another language that because it&rsquo;s yeah it&rsquo;s it&rsquo;s like super easy to kind of make these kind of like memory corruption bugs like mistakes in a way when like programming in like c or c plus plus and whereas it&rsquo;s as far as my understanding goes it&rsquo;s rust for example is a lot a lot safer or like java kotlin how it&rsquo;s considered memory memory safe as far as I&rsquo;m aware or at least they do much much better much better job so oh here&rsquo;s one are you paid for this job or is it purely a voluntary thing um.</p>
<p>Would say I mean first I&rsquo;m kind of talking like in general I would say that most people. Start as volunteers um at least the the non-devs um but but even I I think even like a lot of the devs probably started like volunteering first and then you know it became apparent that they they have a necessary uh skill set and the time to actually go full-time uh but yes I I do I do get paid yes but yeah I mean initially I was a volunteer for a long time so and then kind of speaking to contributing uh what would you recommend someone learns in order to contribute to GrapheneOS or to contribute to the Android ecosystem if they are a complete beginner do you have any places on where they could start or suggestions um in terms of like how to like get the basics down in terms of like just general programming knowledge yeah I think that&rsquo;s what they&rsquo;re asking about kind of just in or just in general for Android specifically like how to get involved in or get started with app development or just like the base os yeah honestly that is also one of those questions I I don&rsquo;t think I can I can answer I&rsquo;m afraid um it&rsquo;s I think it&rsquo;s best if you yeah bring bring up that question in like the dev chat perhaps um maybe hey maybe someone watching right now has a has a better understanding someone says it&rsquo;s commendable but you&rsquo;re comfortable saying I don&rsquo;t know instead of attempting to dodge the question or make up an answer if that&rsquo;s a big sign of trust in my opinion no thank you yeah I mean yeah I mean like you know not everyone has to be the best at everything.</p>
<p>So that&rsquo;s that&rsquo;s all right um I&rsquo;ve been told that uh Google themselves have Android development videos like videos on their side so maybe search for those that that they may probably give a they&rsquo;re probably gonna give you a rough idea on how you can start get going yeah I think developer.android.com has some really good stuff to kind of get you started most likely that some good reading too on there and uh something maybe another topic you know I I really like the the mix uh today because uh yeah sometimes I&rsquo;m talking sometimes you&rsquo;re talking uh sometimes we like take questions from the community sometimes I just talk on my own and I think this is one of those uh scenarios uh because as if it&rsquo;s something I wanted to kind of talk about um like how you can contribute to project like in general okay like of course you know the first thing that comes to mind is development work yeah totally makes sense absolutely correct um I mean GrapheneOS has a software project right um well for now um so totally makes sense that development and programming uh comes to mind first but there is many other ways you can contribute okay you know the second thing that comes to mind is donating money yeah also very helpful for sure no no doubt um but you can do a lot of things even without money or without you know development skills you can answer questions in the community right like there are always people looking for help with.</p>
<p>Like installing the os for example um I I don&rsquo;t know how many people I I help you with that probably um like hundreds at this point yeah just like answering questions you can for example also help with our little banking project that you can find on the privsec website or alternatively just search for GrapheneOS banking list with the search engine of your choosing you know you can file a report there or update the report or just you know let us know that hey this app is working totally fine because that&rsquo;s also very useful and another way you can you can really contribute and really help and this is my favorite part because this way to contribute does not require any like special like knowledge or skills or anything really it&rsquo;s to just voice your support for the project like online on the internet you know whenever you see it mentioned just voice the support for it like that alone is very very helpful so if you if you can do just that that&rsquo;s already just brilliant honestly and you know it&rsquo;s it&rsquo;s very it&rsquo;s very low barrier of entry in that regard so if you can if you can do just that that&rsquo;d be that&rsquo;d be awesome yeah.</p>
<p>Yeah I think that helps a ton because you know someone might see something bad about the project once you start digging into it then you see all these messages and positives about it I think that makes a really a really big difference when people are just beginning to start with it so it definitely helps yeah it kind of also just circuits back to how the internet works for most of the time people go online to like when you know when when something doesn&rsquo;t work they go online to complain about it right but people rarely go online and say oh you know today july 20th this app or this service or you know whatever has worked perfectly fine lovely you know and then moves on with the day you know that doesn&rsquo;t happen people people go go there to complain right which which makes sense why would you say anything if everything works but that can also kind of distort the view in a way because like in general right like you can maybe be interested in like a certain service a certain app and then you I don&rsquo;t know you go to like a subreddit and you see people complain all the time but what you don&rsquo;t see is the amount of people that don&rsquo;t complain because everything is working fine so um and also you So because of the inherent nature of the project and the fact that, you know, it, of course, caters to people that are interested in their privacy, that means that a lot of people, a lot of these, like, Graffino&rsquo;s fans are not necessarily very active on social media, right?</p>
<p>I guess the more common social media, you know, I know that there will be a big slice of users, like on the Fettiverse, for example. But the Fettiverse, I&rsquo;m afraid, is not social media, I would call, like, the most common one, okay? Like, most common would be, like, something like Twitter. So that&rsquo;s a thing. So, you know, if you happen to be active on social media, then&hellip; And, you know, your support is greatly, greatly appreciated. Yeah, it&rsquo;s a tough industry to be in because the goal is to be private.</p>
<p>So you&rsquo;re not going to talk about it. Or in general, you&rsquo;re not going to. Pretty much. Yeah, but people should talk about it. People should talk about GrapheneOS. They should normalize also running GrapheneOS. I see that every now and then in our chats, how people, for one reason or another, want to, like, for example, hide the, like, you know, when you start your phone, you get, like, the Google logo and then it switches to the GrapheneOS logo. And people ask, how can I hide the GrapheneOS logo?</p>
<p>For many reasons. Most of the time, they think that this is some kind of security feature to make someone or to make it harder for someone to identify that, you know, your Pixels are running Graphene. OS, even though that doesn&rsquo;t work because like verified boot will kick in. It always kicks in, right? Like when you start your phone, it tells you, hey, this phone is running a different operating system and then it displays this hash and this verified boot key and you just compare it to one on our website.</p>
<p>And then there you go. That&rsquo;s how you know Caffeine OS is running on it. So, um, hiding the, the logo doesn&rsquo;t actually achieve anything, like nothing, which is why this is not a feature because it doesn&rsquo;t do anything like generally. Um, there&rsquo;s a lot of talk over things I see proposed like security through obscurity, which in my opinion, isn&rsquo;t really security at that point. Yeah. It can help a little bit, but some of that stuff is more for show. Yeah. I mean, there is honestly, there is just like a lot of security theater like out there.</p>
<p>Yeah. Um, let&rsquo;s take, let&rsquo;s say. Banking apps for example okay so we&rsquo;ve been like the past few updates to graphic us have been focused on like re-implementing our secure app spawning okay it&rsquo;s a very very important security feature um so before it used to be like global so if you disable it it&rsquo;s disabled for every single app which is not great for security point is we rework it to be app specific like all the other security features so you can kind of just disable it one by one that&rsquo;s great because that allows for greater app compatibility for example with banking apps um most people will know that best I mean yeah majority of banking apps do work on griffin os uh some don&rsquo;t um in part because of plain integrity However, there&rsquo;s also some apps that rely on some really stupid, like anti-tampering libraries, okay? And these libraries do all sorts of weird checks and weird, like, they have all sorts of weird detections in place, and they&rsquo;re terrible.</p>
<p>You know, banking apps love to kind of pat themselves on their shoulder and, you know, talk about how great their security is, okay? But then you have these apps that have these anti-tampering libraries, as I mentioned, and they&rsquo;re just horrible. Like, they don&rsquo;t actually do anything. They just make it harder to debug for us. So that is something we&rsquo;ve been working on lately. We&rsquo;ve just been trying to reverse engineer these libraries that are figuring out what the heck are you guys doing, you know?</p>
<p>What are you doing? And trying to work around these issues um so so yeah that that is a a big um a big problem in a way where apps just have weird libraries included weird sdks that in the name of security but you know in in reality okay they they don&rsquo;t improve security they just decrease security um I think part of the issue too is I used to work for a company that some of our customers were banks and we kind of protected their websites and services and I I know for a fact all of them talk with each other so I&rsquo;m sure one is like hey I found this cool library put it in your app the other security team does it now they all do it and it&rsquo;s just down that that does happen that does happen yep unfortunately it does happen but I mean hey luckily it can also go the other way around yeah you know we we have a guide um for like app devs to implement like the hardware at the station API or like to to whitelist graphite os through this hardware attestation API and this is in simple terms essentially and like a much better alternative to plain integrity okay like if you want to verify the os just use the hardware uh maybe hardware at the station API because that is neutral and that you know actually gives you useful information and hey we we have had apps actually implement this hardware station API to mind com uh the swiss uh banking apps they&rsquo;re called you and swiss quote that both implement hardware station API so that&rsquo;s great there is another app um it&rsquo;s some kind of like.</p>
<p>Government app or something along those lines or some kind of like identity verification app also in switzerland um that has kind of announced hey we&rsquo;re going to look into graphic os support which is great or like another kind of example is like the twitter app like the x app um that in the past you know that it wouldn&rsquo;t let you log in unless you had a passkey um I believe that should be fixed now maybe somebody can confirm that I believe that should be fixed because I saw like a twitter engineer post about it they said hey we&rsquo;re going to look into graphic you know support and then somebody mentioned hey yes this works um so it would be nice if somebody could confirm but you if it if it doesn&rsquo;t work yet I&rsquo;m sure that is in the pipeline.</p>
<p>Yeah hopefully those kind of recommendations can spread because it&rsquo;d be nice instead of everyone doing their own thing and then blocking it from being able to be used and things like that yep yep it&rsquo;s it&rsquo;s and another really um funny example okay is Roblox okay um somebody found out that if you go to the like faq page of Roblox there is like an entire section hey what about custom operating systems does like the Roblox Android apps support those and versus this section that you know we investigated on a case-by-case basis and graphene was is actually listed there and they actually support graphene works yeah there&rsquo;s a full like technical rundown and everything which I didn&rsquo;t really expect, but, you know, that&rsquo;s lovely, right?</p>
<p>I feel like that&rsquo;s the last app I would expect. Like, oh yeah, Roblox. Yeah, it&rsquo;s funny, but hey, I mean, the more apps, the merrier, right? Yeah. Here&rsquo;s an interesting comment. GrapheneOS always operates under the assumption that an attacker has encyclopedic knowledge of GrapheneOS at all times. GrapheneOS is open source, publicly accessible, and transparent. So that&rsquo;s not a far-fetched idea. I&rsquo;m not really sure what the far-fetched idea refers to anymore. But yes, that is true. That is indeed very much true.</p>
<p>I guess, speaking of open source, have you guys gotten a lot of reports since kind of the bigger AI models started releasing their security scanning? Like, hey, I found a vulnerability, like whether it&rsquo;s accurate or not. Or have you guys personally scanned the source code for? Vulnerabilities, you just&hellip; Anthropic or opening um as for the first part of the question I I know of at least one kind of report uh I&rsquo;m actually I believe it wasn&rsquo;t necessarily a report about security but I believe it was a feature paid uh feature patch that was just entirely vibe coded and that just waste our time right um I I would assume that for sure we we have gotten reports about apparent security vulnerabilities and then you know just ended up being sloped um as for the second part um yeah I&rsquo;m sure I&rsquo;m sure some of the devs have done that at least in parts um hey you know it&rsquo;s it&rsquo;s worthwhile to just keep up with the times I guess um and and see see what it outputs and hey Maybe some kind of LLM or AI, whatever you want to call it, does output something useful and you can work on that.</p>
<p>Here&rsquo;s a good question I got too. What is the project&rsquo;s stance on anonymity? Is it a goal or is it only privacy and security the goal? The main goal is privacy and security for sure.</p>
<p>Like we, yeah, I mean, some like usability patches and features, sure, why not, right? Put them in the mix. But it circles back to what I said earlier on in the stream, when I mentioned how anytime you add any kind of feature, you need to see, okay, how do we maintain this going forward? And that is just a very delicate balance you need to keep in mind.</p>
<p>Like someone from a community could write a patch for any kind of feature. You know, actually, let&rsquo;s take as an example, a patch to hide the white pill, right, that tells you that you&rsquo;re using gesture navigation. I&rsquo;m sure, I mean, I would also like to hide it, admittedly, but somebody could write a patch for it. And that&rsquo;s all nice and fair. But you seem to make sure that it continues working in the future. So that&rsquo;s pretty much always what it boils down to. But yeah, I mean, security, privacy, definitely the cornerstones of what GrapheneOS OS is about.</p>
<p>And I think too, when it comes to anonymity, you know, it&rsquo;s a great goal, but I think a lot of people who say they want to be anonymous underestimate the amount of effort it actually takes a constant effort. Oh, yeah. To make sure you are anonymous I&rsquo;m not going to say it&rsquo;s impossible but to function in daily life I think it is impossible like if you plan to have a job or live somewhere you know it&rsquo;s also expensive to be anonymous if you want to get a house to see or it&rsquo;s yeah yeah for sure that um yeah I mean it&rsquo;s not something I&rsquo;ve ever personally attempted um because I mean my my personal friend model doesn&rsquo;t really require it but that&rsquo;s that&rsquo;s actually a good topic as well like um unlike the topic of maybe also privacy fatigue where people overdo their setup um let that be on GrapheneOS or just like in general they go through like all these lengths to do this and that and improve their privacy just a little bit like negligible amounts but like at what cost right like what is the price we pay and you know at some point you need to ask yourself is this worth it you know in the context of GrapheneOS uh I&rsquo;m glad that we can talk this talk about this I feel like like profiles right um that is something that people discuss all the time in our chat rooms on Reddit in our forum there&rsquo;s like pretty much a thread about like someone&rsquo;s like set up like every day there&rsquo;s a new friend and I I don&rsquo;t know I&rsquo;m getting the impression that a lot of people over complicate their setup right they have like like a million profiles okay and they&rsquo;re just like compartmentalizing uh like 10 different apps but then they they don&rsquo;t necessarily like have a foot picture or necessarily understand.</p>
<p>What benefits this brings you and so I feel like they&rsquo;re kind of just making it harder for themselves when I feel especially in the beginning okay I feel like my recommendation at the beginning like if you just start out on graphic os and you don&rsquo;t really know what you want for like immediately just run one profile like the owner profile so whatever you want there and just relax with it don&rsquo;t try to overburden yourself with all these elaborate like profile setups okay like um profiles can be useful but I don&rsquo;t know the my impression is that people maybe focus too much of them and they they make it harder on themselves and I&rsquo;ve very little action benefit yeah yeah and I&rsquo;ve heard from quite a few people who are not even using GrapheneOS they&rsquo;re just for months still planning out how they&rsquo;re going to set it up with users and private space oh god yeah I&rsquo;m like just get started see how it is don&rsquo;t do that man don&rsquo;t try and be perfect no yeah like like it&rsquo;s and again like to the topic of you should like if you&rsquo;re gonna run price invasive services or apps do it on GrapheneOS than anywhere else um just yeah just don&rsquo;t do that right like just go ahead buy your Pixel already flash caffeine or just use it already like it&rsquo;s it&rsquo;s it&rsquo;s that simple um because um there is no right or wrong in that sense like you know for us um like the the team you you can be someone who does not rely on Google Play for example and.</p>
<p>That&rsquo;s cool okay awesome you can also be someone that does rely on Google Play you know what that is also cool like great you know there&rsquo;s no real difference in a way you you can definitely make the point that it&rsquo;s probably a good idea to try to or like try to not depend as much on for example Google Play if you can and if you want to then yeah go for it absolutely it&rsquo;s a good idea but if you rely on on on like the Google suit of apps like I mean just take linus from ltt like he&rsquo;s just not the kind of individual that can get away with a you know de-googled setup and that&rsquo;s okay that&rsquo;s why we have sandbox Google Play that&rsquo;s where we have all the solutions for you to use Google Play in its sandbox state and you get like all the benefits and with very little of the disadvantages of Google Play right can I just mention how brilliant the idea is to sandbox Google Play like I found that I did brilliant when I first found out about it yeah the benefits you get just from because I know people like oh if you&rsquo;re gonna install Google Play then you know you failed but the fact it is just a normal app when you install it it&rsquo;s wild how much of a privacy benefit you get just from that even if you use it the exact same as a stock Pixel device yeah it&rsquo;s helps a ton yeah but also my impression is um I would assume that um you know people generally also like instead of YouTube maybe they use new pipe for example right like YouTube.</p>
<p>Replacement sure cool um but you know maybe that sort of type of of um user does still rely um you play one way or another so you know what if you install Google Play for example in the owner profile. But still use new pipe instead of YouTube and instead of Google maps you run I don&rsquo;t know organic maps or any of the other many alternatives okay um and so you get still so much so much of of like Google Play like the benefits of Google Play but like what do you like really lose okay like you get push notifications I mean okay admittedly with push notifications uh you know you know you need to see how these apps handle push notifications um but in in general you get so much improvement on the privacy front without losing much and that&rsquo;s just kind of a balance you need to to look you need to look at your setup and see is this privacy benefit worth it to me in relation to how much usability do you lose right so someone says I assume q and a will resume soon okay maybe maybe we should take some some questions again I don&rsquo;t want to feel like people this is just rambling all the time.</p>
<p>There&rsquo;s a comment here it says took me a long while to get GrapheneOS and the whole time I was planning things out I was very ignorant back then oh yeah you just didn&rsquo;t know and you were probably um swayed by all the people who have like extensive setups and like to be to be fair or to be clear it&rsquo;s not illegal okay for you to have like an extensive setup like a complicated setup you can you can do that totally fine you can run GrapheneOS without Google Play Store or only open source apps or like whatever you want like it&rsquo;s all okay but like that&rsquo;s the point it&rsquo;s it is okay to not always do the perfect decision when it comes to your privacy um it shouldn&rsquo;t be a zero or nothing approach.</p>
<p>I see a question here um hold on where was it I keep getting mixed up here a little bit between the the Discord chat and Matrix I I saw a question that asked how many full-time like devs we have um I can tell you that the number keeps changing you Because we are like actively hiring, but it seems like a lot of people.</p>
<p>It&rsquo;s at least 10, but in practice, it&rsquo;s more than bad. But honestly, I cannot give you the exact number.</p>
<p>Oh, someone here asked, how many user profiles do you both use on GrapheneOS? For me, I use a total of three users. But when I set up my new device, eventually, I plan to use two users with a private space in the second user. So that&rsquo;s what I&rsquo;m going for. Yeah, I think I have like three, maybe. Yeah, I have currently three. I don&rsquo;t really use the other two too much. Like, for example, I have a profile, because I&rsquo;m one of the maintainers for this banking list, right? And so I opened this profile.</p>
<p>Bye-bye. Where I have Google Play installed and then I&rsquo;ll just go ahead and download install random banking apps from like random countries to see if they run or not so that is one of my one of my profiles where I just install banking app quote unquote junk for example.</p>
<p>Like profiles can could be good if for example you intend to run a profile that is mostly like devoid of like Google like for example maybe you want your main profile to be without Google Play but you do rely on some specific apps like one or two that do need Google Play it can make sense to uh yeah to have a secondary profile where you run Google Play in that profile.</p>
<p>But yeah don&rsquo;t uh don&rsquo;t over complicated okay I got a question here is the project actively looking for other phone companies to collab with still or is the Motorola one taking up enough resources as it is um yes that that&rsquo;s pretty pretty accurate in that I mean other OEMs and other other companies are of course free to reach out uh and we we see what we can do but for for sure our resources are spread thin in a sense that of course we are heavily focused on Motorola.</p>
<p>Going back to profiles so I know one reason for using separate profiles is that any app in a specific user can list the other apps in that user is there any plans to kind of have a toggle for that like don&rsquo;t allow apps to request the list of installed apps? Yeah, it would be nice to have. I&rsquo;m afraid there is many ways that an app can find out what other apps you have installed. So I guess this is probably perhaps something for the IPC scopes. The IPC scopes is a very complicated feature, as I said.</p>
<p>Yeah, I mean, it would be nice to have, and I&rsquo;m sure that this is something that would be nice to have for sure. But it&rsquo;s difficult because you need to make sure that nothing leaks. Because if a feature doesn&rsquo;t really work, then you can block three out of four pathways, but if there&rsquo;s a leak on the fourth, then the feature isn&rsquo;t very useful. Unfortunately yeah so got another one here about Motorola how to make sure Motorola isn&rsquo;t occupying or infiltrating GrapheneOS Motorola has a Chinese mother company and Motorola stays under the FCC Motorola isn&rsquo;t fully owned by the Chinese state however and you know Motorola isn&rsquo;t infiltrating GrapheneOS in any way like we remain separate entities like entirely we we just kind of help each other out and that&rsquo;s pretty much the extent of the partnership it sounds rather simple of course it&rsquo;s bit more complicated than that but yeah in practice um in practice you know we of course also want an alternative to the Pixel lineup like pretty much the whole community does uh Motorola can provide this alternative and Motorola can also benefit from our expertise um and there you go you know perfect matchup essentially.</p>
<p>Yeah and I guess going back to private space and users so someone asked how do private space differ from users security and privacy wise a private space is essentially a secondary profile.</p>
<p>Um Josh help me out here uh I believe. I believe there was something about clipboard sharing. Could you share the clipboard to the private space user? Yeah, I think by default that&rsquo;s enabled. You can disable it, but that is one big benefit. That&rsquo;s kind of nice. Okay, yeah. I believe that is pretty much the only difference from a usability perspective. Well, I mean, from a usability perspective, yeah, it&rsquo;s just more convenient to access, right? Well, I guess technically you could install apps from a user to a private space.</p>
<p>You can&rsquo;t install apps from a secondary user to another user. I guess that&rsquo;s another usability. Yeah, that&rsquo;s true. Yeah, so there are these kind of smaller differences.</p>
<p>Add a feature to disable clipboard access or make it one way or another. Number yeah exactly yep yep yep yeah lovely thank you I remember something about the clipboard.</p>
<p>Yeah I think we touched just more convenient and secondary I think we touched on this earlier but another person asked what&rsquo;s the recommended backup solution for a tech illiterate family member using GrapheneOS is seed vault kind of the recommended route currently.</p>
<p>Um difficult question because seed vault might work great for one person and for the next it could um not do its job fully um I yeah I&rsquo;m afraid that I mean I I do also agree that backup solution we need a much more robust solution but I would say you But they should absolutely still use it, especially if they&rsquo;re not that tech-savvy, for sure. Yeah, it&rsquo;s one of those things that&rsquo;s tough, too, to recommend because you want backups to be reliable. So if it doesn&rsquo;t work when you really need it, then&hellip; That&rsquo;s not great, right? That&rsquo;s not a good backup.</p>
<p>A backup is only a backup when it actually works. Exactly. No, but I mean, as I said, I don&rsquo;t want to downplay Seatball too much because, as I said, as far as I&rsquo;m aware, it&rsquo;s been doing much, much better.</p>
<p>So, yeah.</p>
<p>Is there anything indicating that the Motorola partnership might bring some more features to GrapheneOS, like Google Wallet, where it might be easier to get approval at a higher level, or I guess allow listed for&hellip; Whatever is currently being blocked? Well, NFC payments for like Google Pay or is it called Google Wallet now? That is tied to Play Integrity API, right? And like even with Motorola support,. Like GrapheneOS is not going to pass through these higher verdicts of Play Integrity because we would need to license the Google Mobile Services, for example, the Google Play Store.</p>
<p>And GrapheneOS also doesn&rsquo;t qualify as Android, right? Like you cannot legally name GrapheneOS Android because it also isn&rsquo;t. It is an OS that is based on AOSP with Android app compatibility, but it is technically and legally not Android. For example, we would not be allowed to have the sensors and network permission.</p>
<p>Oh, if it was vanilla Android? Yeah, exactly. If we wanted this to be called Android, we would need to drop these features as an example. And I&rsquo;m sure many, many, many more. The answer to play integrity is asking regulators from the EU, for example, to look into the issue. And until then, we need to convince app developers who do use play integrity and inadvertently ban GrapheneOS users to&hellip;To&hellip; Yeah, whitelist graph in OS for the hardware installation API. That&rsquo;s the best of both worlds in a sense, because the devs can continue to use Play Integrity if they insist, but they can also whitelist graph in OS.</p>
<p>So what happens is, you know, app ask, hey, Play Integrity, okay, it fails, are you graph in OS? Yes. Okay, you&rsquo;re still allowed to pass. There are some funny occasions also with banking apps. For example, there is like a French banking app, okay? It doesn&rsquo;t work because of Play Integrity, okay? Except it does, like, you can make it work. And it&rsquo;s very simple. You go to the app info settings, and then you toggle to, like, block the usage of Play Integrity. And then the app works. And, like, this is not, like, the intended outcome for the app.</p>
<p>Because, okay. You get it. Thank you. So imagine you&rsquo;re at the airport okay and you&rsquo;re like boarding your flight and you go to like the the like the final like check-in counter whatever where um the the employees probably like scan your your ticket one one more time okay so you go there um let&rsquo;s say you are a a normal Android device okay you go there and you scan like they scan your phone and we&rsquo;re like oh yes this is a normal Android phone you can pass this is fine uh option b you go there with a Pixel that has kfn os flash on it and you go there and you know your phone is essentially like the ticket you go there you show the scan via the code and it says oh no this is not a valid ticket and you denied from boarding the plane and uh but there&rsquo;s actually option c okay you go to the to the counter to the checking counter and what you do is you don&rsquo;t show a ticket at all okay there&rsquo;s no ticket and the the employees are confused and they just let you in like they let you board the ticket the plane about the ticket that&rsquo;s essentially what happens with that bank where you know if you if you block plane ticket usage like that shouldn&rsquo;t make you pass through the app but that&rsquo;s what&rsquo;s happening so that&rsquo;s uh that&rsquo;s pretty funny how that&rsquo;s wild just fails open yeah that just means like they just messed up implementation like straight up that should never happen but it does happen um so that&rsquo;s of course very good um for those affected.</p>
<p>Users um but I&rsquo;m afraid that if the devs actually fix this problem then they will no longer work right so but yeah sometimes they are these kind of these kind of workarounds um funny short way to put it is that the banking apps need to learn from Roblox I mean you&rsquo;re not wrong yeah because the faq entry I I read it it says oh you know if it meets the requirements if it gets your consistent security updates like just a whole like technical paragraph which is just so I don&rsquo;t know out of out of place I suppose for Roblox of all places but hey um yeah so that&rsquo;s that&rsquo;s that&rsquo;s funny that is that is pretty pretty wild um.</p>
<p>Do you have any recommendations on password managers someone asked if they should just use Vanadium for passwords or something like bit warden um I mean I personally use bitwarden just very convenient right because you can access it from any device um as long as it has an internet connection of course um and as far as I know there is nothing really to um criticize like overly um I believe it is a a good option yeah for sure there&rsquo;s plenty of other alternatives but um I would argue that you know bitwarden being like your your passwords being stored in the cloud is is very convenient um so yeah I would I would just use bitwarden but definitely use a password manager at the very least.</p>
<p>Someone else recently oh yeah go um here&rsquo;s a message is there a graph in those road map.</p>
<p>I mean, not really. There&rsquo;s like longer-term plans, like Motorola, for example, like moving away from the Linux kernel entirely. But I don&rsquo;t think that&rsquo;s the kind of roadmap that you asked for. So no, priorities can change. I touched on that briefly earlier in the stream. Priorities can change drastically. It&rsquo;s just the kind of environment where you need to always be ready to react to something, right?</p>
<p>So it&rsquo;s not easy to juggle everything at once. But I think we&rsquo;re doing a pretty fine job. Okay, so what&rsquo;s the question someone on the stream got? Someone asked a dilemma they have. Is using a phone with friends and family, but without Palantir and other companies stealing or hacking your data and information. So me personally on this one, at least for when it comes to being more private in the physical world, I think the auto off toggles for Wi-Fi and Bluetooth are almost like a needed thing at this point.</p>
<p>Those are two main things they&rsquo;re looking for. Airplane mode&rsquo;s ideal, but that&rsquo;s also not functional for everyone. When they go out, they kind of need constant connection. Yeah, yeah. So definitely check those settings on your devices. Yeah, yeah, for sure, for sure. I mean, the best protection in a way is attack surface reduction, right? If there&rsquo;s no way to attack, then there&rsquo;s no vulnerabilities. So if you just disable like your Wi-Fi, when you go out and about, that is attack surface reduction.</p>
<p>So yeah, for sure. That is, that is a good idea. Thank you. These settings you know if you want you can also enable the respin password um and the the two factor fingerprint authentication I just realized we haven&rsquo;t even talked that much about like specific grapheneurs features um there&rsquo;s a bunch yeah like which one should we talk about I mean honestly for the respin password if you&rsquo;re going to use the feature look I mean listen I&rsquo;m guessing that most people that are watching this stream right now and the people that will be watching this when it&rsquo;s on YouTube they don&rsquo;t exactly I guess have the threat model of the respin slash password but it can still be useful um you could like carry like a piece of paper in like your your phone case that you know apparently tells a thief like your your PIN or password and then they enter it and it turns out to be duress and it just nukes your phone uh like that is the kind of um little things you can do um but please please for the love of god make backups if you have I mean make backups anyway but like in particular if you have this feature enabled because um I have seen and I have read you know way too many people who have this enabled and then they you know they enable this feature because I I don&rsquo;t know either you know their setup is a complicated they have like 15 profiles with like 15 different PINs um or I don&rsquo;t know they get drunk or something and they accidentally input the respin password it nukes their whole phone then they come into the chat rooms to ask for help.</p>
<p>And we cannot help you nobody can help you so please please be be careful yeah or if you have a child who likes to press on the PIN numbers don&rsquo;t make it something where they can just type it maybe don&rsquo;t make it one one one one yeah yeah actually worth noting maybe um some people have missed that Google has very recently updated um like the the like throttling from the secure element so now like it used to go up to like two weeks it&rsquo;s a lot more aggressive now um I think yeah it it starts pretty you know relaxed but it actually goes up to like nine years of wait. And the the attempt after the nine years is just a permanent you know soft break so like I think like 20 attempts what was it you cannot attempt it again ever so yeah uh be careful out there um yeah I don&rsquo;t know where the article is but I remember seeing that recently and it was almost extreme the limits they put in are very aggressive yeah it was yeah we we have an updated table on the on the website um in one of our categories there yeah it&rsquo;s it&rsquo;s like max 20 attempts so it&rsquo;s it&rsquo;s a lot more aggressive now it goes to like one year then like three years and then nine years and it&rsquo;s like okay um sure sure buddy I&rsquo;m gonna I&rsquo;m gonna remember my password in nine years I&rsquo;m sure if I just sleep a night or two I&rsquo;m gonna I&rsquo;m gonna remember it um so yeah that&rsquo;s uh and that&rsquo;s also why even a four digit long PIN is considered secure now you know if you So if you trust the secure element to do its throttling, even a four digit PIN is secure now. So before it was six digits. But now that, yeah, the throttling has been strengthened even more. It&rsquo;s like, okay. So good on the one hand, and I guess maybe bad on the other, if you forget your password.</p>
<p>Yeah. Speaking of forgetting passwords, I guess this was a trend I saw every so often, but it seems like there&rsquo;s a block of forum posts that come up about my PIN used to work. It doesn&rsquo;t work after this update. Have you guys found anything specific on what could be causing that? Or is it just? I know which, which threads you mean. Yeah. Most of the time, it&rsquo;s someone like reviving a dead thread. And they, you know, they mentioned the same issue where they, yeah, they, you know, they type in their PIN, but one day, just doesn&rsquo;t work seemingly apparently after an os update um I don&rsquo;t think we know the cause um I I do know in in the sense that there is no indication that it is a GrapheneOS specific issue it could be a super rare upstream bug um it could I mean it could also be that half these people did indeed forget their pain I&rsquo;m not saying that that&rsquo;s what happened to everyone I&rsquo;m sure some people you know did face this legitimately I think I read somewhere that um if you maybe keep the you know device turned off for a bit and then turn it back on it might work um but it could yeah it could just be some kind of hardware issue right where someone rightfully mentioned in the chat where a secure element could be on his way out one thing I do when changing a PIN code or when I set a password is I&rsquo;ll record myself I&rsquo;ll make sure I delete it afterwards just in case I incorrectly enter it twice all right yeah I like different device I like it yeah just to be safe because it can happen okay apparently there are reports of that same thing happening on the stock operating system so that&rsquo;s what I meant that it&rsquo;s it&rsquo;s not really graphene ois specific issue so don&rsquo;t really know what exactly.</p>
<p>It is but I mean very small sample size right but I mean it has never happened to me and I&rsquo;ve been using graphene ois for over three years at this point um and you know it hasn&rsquo;t happened to anyone I I know more personally I guess but yeah you know it&rsquo;s it&rsquo;s it&rsquo;s a computer at the end of the day and the computers are are weird like that sometimes um.</p>
<p>But it&rsquo;s definitely not a widespread issue so yeah are there any major differences between a physical SIM or an e-SIM and is one better than the other um I don&rsquo;t think there are any inherent benefits I mean I guess for the I mean the benefit from e-SIM may be that um they&rsquo;re like it&rsquo;s not the physical like little chip that you put in your phone so it cannot get lost or or broken but um I I don&rsquo;t believe there&rsquo;s any like inherent like privacy benefits from one to to another it is worth noting that you&rsquo;re like if you do you have like an e-SIM for example on your phone and you flash graphite os or you flash back to stock os your e-SIM does remain on the device and it should remain no matter what you flash on it one exception is the duras PIN slash password feature if you activate that that will also wipe the e-SIM but yeah under like normal flashing the e-SIM does remain I think there&rsquo;s also a toggle in the os when you want to install an e-SIM isn&rsquo;t there some Google code or something it requires to install it on the device because you need a Play Store maybe but you don&rsquo;t anymore yeah that&rsquo;s that&rsquo;s that&rsquo;s no longer um like applicable I mean I believe no I believe we are like we&rsquo;re still using like a proprietary Google app but it doesn&rsquo;t send like data to to anything I believe we have yeah we&rsquo;ve definitely stopped it from sending like any kind of data like that to like Google Play for example so it is it is isolated um oh nice yeah.</p>
<p>We also done something I mean not similar but it kind of just popped up in my mind how you can use you know Google camera like the Pixel camera app on GrapheneOS without the Google Play Store um it broke at one point but we fixed it and we just kind of stubbed it out and uh so that&rsquo;s that&rsquo;s useful for people who do prefer the output of the of a Pixel camera.</p>
<p>Um here&rsquo;s a question what goes into asking organizations to support GrapheneOS via device attestation many apps including banking apps have explicit support for GrapheneOS as an alternative to using plain tagger and GrapheneOS has remarked on social media that they have been successful on this front.</p>
<p>We need the actual customers of the banks like to complain essentially right and to ask the app devs and whoever is responsible for it to add support and like on first glance it might seem kind of hopeless because like okay yes we have over 400,000 users but that&rsquo;s like drop in the bucket in comparison to how many Android users are out there but it&rsquo;s really not that impossible of a challenge to pull off as you know we have done it before and like the two swiss ones I I mentioned earlier in the stream is that the like confirmed cases there are also some banking apps that I don&rsquo;t know if they have like implemented or like whitelisted GrapheneOS for that API directly uh you know some some banks um they they don&rsquo;t necessarily say they support GrapheneOS but in practice if there&rsquo;s an issue they they will fix it so take that as you will have any banks implemented device at the station for GrapheneOS of their own accord on or on their own accord without customers complaining um I think that is difficult to tell because um chances are the you know in that case the app just continues to work And, you know, if the app continues to work, there is something to complain about, right?</p>
<p>One question here someone asked is, is it possible to set up a VPN and an ad blocker at the same time? I&rsquo;m confused about the two working together. So from my understanding for that one, it depends on what type of ad blocker you&rsquo;re referring to. Some do it by having a local, I guess, a VPN and a loopback address on the device. Yeah. So that does take up the VPN slot. So you can&rsquo;t. Exactly. But if you have something that supports ad blocking in it, like a VPN provider in their app, then you can just toggle that on.</p>
<p>Otherwise, you can&rsquo;t. Yeah. It&rsquo;s really just considering this requirement that you can only use one VPN app. So if your ad blocking solution takes up that slot, then you&rsquo;re in a bit of a pickle.</p>
<p>Does GrapheneOS ever take known spyware samples and run them on air-gapped GrapheneOS devices to see how they work in real time to be able to block them, e.G. Pegasus, Celebrite, Palantir, Graphite, etc. If there&rsquo;s any documented attempt these adversaries spyware tried to exploit GrapheneOS. We do have a thread on the forum that has some, like, Celebrite slides that kind of show that, or, like, that at least, yeah, I mean, they do show that GrapheneOS is effectively immune in simple terms. They are a little bit older, but&hellip; But we do, like, get the updated slides, like, regularly.</p>
<p>So we do kind of keep track of that. And yeah, I mean, nothing has really changed in that regard.</p>
<p>Yeah, I mean, I just want to add, like, by all accords, GrapheneOS does appear to be very, very resistant to these kind of, you know, forensics software and this kind of advanced malware. Because the defense is layered, right? Like, you have many, many protections kind of working together. So even if one protection has a vulnerability somewhere, chances are the next line of defense stops the attack.</p>
<p>Yeah it was great seeing that slide because it was like iphone stock Pixel something else and it was all like check mark check mark check mark GrapheneOS just x x x x exploits don&rsquo;t work exactly yeah sometimes like we do see um people that like dig up like weird like super old like even the court documents or like weird um old slides or whatever that apparently show um that GrapheneOS is um or has been compromised but in practice every time it turns out that um the the owner of that of that phone ended up you know revealing their PIN slash password one way or another and it&rsquo;s like yes if you give your PIN password voluntary or involuntary then I mean yes you are cooked you know um yeah how do you approach ad blocking on Vanadium I don&rsquo;t see ads almost anywhere now except for Reddit and x aka twitter uh yeah we did implement ad blocking on Vanadium some time ago uh it&rsquo;s based on like a filter list um forgot the exact name I&rsquo;m sure somebody can tell me but yeah it&rsquo;s based on like two lists I believe.</p>
<p>So it&rsquo;s not like overly complex but it does the job pretty well I would say.</p>
<p>Um a little off topic but for Reddit for example you can uh use I mean Reddit and and twitter also have uh like open source front ends you can use uh instead of visiting the sites directly you easy block yeah yeah that&rsquo;s that&rsquo;s that&rsquo;s one of them I forgot there&rsquo;s a second one but yeah that is that is correct thank you oh no yeah it&rsquo;s quite easy list yeah good point thank you yeah another question I got which I&rsquo;m actually curious about this one because I think it used to be a feature for like a short period of time currently you can only use install available apps from owner is there what&rsquo;s the reason why you can&rsquo;t do that from a secondary user to another secondary user because I think it was enabled for a time but then it got removed for I think security reasons yes I I yes I do recall there was some kind of security issue with that approach for sure I don&rsquo;t recall the exact reasoning however maybe somebody can look that up for me uh but yeah I&rsquo;m a I&rsquo;m afraid I don&rsquo;t know the exact reasoning but there was indeed I do vaguely remember there being an issue and with that are you aware of any countries that support GrapheneOS through policies someone said that they know there was a politician in the czech republic who spoke about GrapheneOS on tv and debian.</p>
<p>Interesting I did not know of that um I I do yeah I do see you know people that work in politics talk about GrapheneOS every now and then well they&rsquo;re also on mastodon for example um it it does it does happen yeah yeah for sure uh I mean there might be a lot of these kind of people using it but maybe we&rsquo;re not exactly, they were not exactly outspoken about it.</p>
<p>Oh, I&rsquo;m getting some explanations for why you cannot push apps from one secondary user to another. Let&rsquo;s see.</p>
<p>It basically could be an issue with malicious users. The old feature didn&rsquo;t say the profile that had the app installed. Oh, okay.</p>
<p>Okay. So yeah, it is. Yeah. A potential vector then. Oh, so since Android, I guess, is made to be a multi-user device, someone could then have a user push an app and then. Okay.</p>
<p>Anyone can push whatever app to other users. Yeah. Oh yeah. Good point. Yeah. Of course. Yeah.</p>
<p>Yeah. That&rsquo;s true. I mean. I didn&rsquo;t think about that one. Yeah. That&rsquo;d be pretty bad, right? Yeah. I see. Yeah. Thanks for that. Thanks for everyone helping out here a little bit.</p>
<p>Oh, here&rsquo;s one if you can answer it. Where does GrapheneOS source the Google apps like Play Store and Markup that are in the App Store? Good question. Um, I&rsquo;m afraid I cannot give you a good answer to that. I don&rsquo;t know how exactly it works. I&rsquo;m guessing they are maybe ripped from the stock OS, perhaps.</p>
<p>That is my admittedly not so educated guess. Not so educated guess. You can do it. I know unless you&rsquo;re a good sign. But, you know what you&rsquo;re doing is like a good sign.</p>
<p>Yeah, I got a note that they are probably indeed taken off a device that is running the stock operating system. That makes sense. Yeah. Yeah, markup is weird because it&rsquo;s, for some reason, it&rsquo;s not offered in the Play Store, so we have to host our site, which is kind of strange. But it is what it is.</p>
<p>Also, go ahead. I&rsquo;ll try to remember it. Do you have any opinions on pass keys in the OS? I&rsquo;ll just quickly give my opinion on pass keys. I don&rsquo;t like pass keys since they&rsquo;re tied to a device and I can lose my device. I prefer hardware keys, like a YubiKey or something, but I know that pass keys are being pushed for convenience. Convenience and so the person&rsquo;s questions are like is there a plan to incorporate them more into the os natively or just use an app I guess that can hold them for you okay um yeah I mean I definitely agree with your sentiment joshua um yeah if you just kind of cruciform they have to be a bit unfortunate um not aware of any specific goals for that no.</p>
<p>I I don&rsquo;t I don&rsquo;t believe so you mm-hmm um yes I mean yes it it it does sound good on paper um. And I mean the oral store has made some improvements in like their like security wise to like make sure that the apps you download from the oral store are actually the apps you want to download um I believe it is still not quite on the same level as the Play Store however and uh problem is with the aurora store is um it doesn&rsquo;t like you always need an account to use the Play Store and it doesn&rsquo;t change with the aurora store just on the aurora store you&rsquo;re given a dummy account and you know that is a violation of the terms of service And it often is overloaded with users and then you log back in, try a different account, try a different dummy account. And so I believe you get rate limited relatively often.</p>
<p>So yeah, it&rsquo;s, it&rsquo;s not quite on the, on the cellular, the, the, the Google Play Store, I&rsquo;m afraid, but there are some like really strange, um, edge cases where, um, with your oral store, you can actually download an app that, um, is kind of set to, um, because you can, you can use the play integrity to, to stop an app from showing up on the Play Store on apps or sorry, on phones. That don&rsquo;t pass play integrity right um and aurora store kind of just ignores that restriction so you get to install that kind of app and sometimes it&rsquo;s again kind of a weird setup with play integrity so you know they might enforce play integrity on the app store listing but then when you download and install the app try to run it it actually works because there is no plan to go to check inside the app um so that is one of those really weird edge cases um where aurora is I guess in a way superior but yeah most of the time uh you&rsquo;re probably better off using the the Play Store if you want like the best security security and it&rsquo;s also worth noting that um all these like dummy accounts let&rsquo;s just get banned by Google right it&rsquo;s just not a very um.</p>
<p>Like reliable way of accessing the Play Store I&rsquo;m afraid yeah it works well until it doesn&rsquo;t unfortunately yeah and it&rsquo;s also like the fact that um the oral store will also not have the same app compatibility right because some apps also check where they were installed from um for example um it doesn&rsquo;t really have like play asset delivery so like overall compatibility will generally be worse than the Play Store but well uh it is admittedly also pretty difficult to compete with the original Play Store right in that sense like the original place that will always have the best compatibility I mean that is why you can install it and it&rsquo;s in a sandbox state if you want.</p>
<p>I heard the goal is to come away from the linux kernel to a microkernel is this a goal in Motorola devices for long term two that is very far in the future. I&rsquo;m afraid like that is just too far in the future to to really comment on that but yeah the first sentence does does check out.</p>
<p>Good question here which stock apps will be replaced or modernized? Pretty much all of the AUSB ones. So let me just quickly check here. I&rsquo;m on the phone here. So it would include the clock app, contacts, I&rsquo;m guessing files as well, gallery, absolutely. Yeah, the messaging aka SMS app.</p>
<p>And I&rsquo;m not sure about the phone app. I mean, that appears to be working decently well, but maybe, I&rsquo;m guessing there&rsquo;s going to be some updates across the board.</p>
<p>Also, have you guys played around with the updated PDF viewer? You can finally, like if you want to change pages, you can just kind of swipe, so that is very nice. It&rsquo;s very hype when that update when we push that out yeah it&rsquo;s it&rsquo;s a huge uh usability improvement that was a pain before yeah yeah for sure I I do have to agree unfortunately what about calculator um I mean probably yeah I I didn&rsquo;t I didn&rsquo;t really get told what happens to calculator uh it&rsquo;s relatively far down in the list right um for for many reasons uh but yeah I mean as I said I&rsquo;m guessing all of his apps will get a facelift one way or another.</p>
<p>So someone asked I guess going back to the aurora question so is installing play services and using Play Store the official recommended route you um if you need something from Google Play yes yes we we do like this official recommendation where you you better just use the Play Store.</p>
<p>What&rsquo;s the biggest security weakness in GrapheneOS that the devs want to improve on currently. Oh that is an interesting question very thought-provoking definitely biggest current security weakness um so from what I&rsquo;ve gathered the biggest security weakness really is the linux kernel um I&rsquo;m afraid so but that is difficult to um fully fix right I mean there&rsquo;s there&rsquo;s some things you can do there&rsquo;s some there&rsquo;s some tweaks you can do to the kernel um there&rsquo;s features you can sort of disable and remove to remove a bunch of attack surface but the kernel does remain a relatively big attack vector.</p>
<p>Oh and going back to the install available apps question the person that asked that clarified they&rsquo;re wondering if let&rsquo;s say you install an app in a secondary user if it would be possible to make it so that owner could install from that secondary user because otherwise you can&rsquo;t really unless you directly installed an owner you you can&rsquo;t get that app across if that makes sense no I&rsquo;m not sure sure I follow so they&rsquo;re installing an app yeah they&rsquo;re installing an app in a secondary user and then if you go to owner you&rsquo;ll see that it says this app is installed for another user would it be possible to make a toggle to let you install that app in owner since if you&rsquo;re owner then you should have permission necessary because currently you can&rsquo;t you have to manually install it in owner um I thought about that yeah indeed same here maybe um it&rsquo;s a little strange because apps are installed like phone wide right okay like they&rsquo;re not necessarily available in every every um profile but they&rsquo;re installed everywhere at the same time which is also why if you update the app in one profile it should be updated in the other as well um that is yeah that is also a very thoughtful question um perhaps I I suggest maybe look through the GitHub tracker like the issue tracker on GitHub um see if maybe somebody has yeah come up with this idea before and if not maybe consider uh yeah filing an issue there.</p>
<p>Any future thoughts on making graphene was its own desktop operating system I know desktop is not a it&rsquo;s not as secure overall but it would still be nice.</p>
<p>Um well you see there&rsquo;s there&rsquo;s many things that we would love to have um that pretty much sums it up unfortunately um well I mean there is the Android desktop mode right um but hey I mean who knows if there is suitable hardware.</p>
<p>Why not I mean there was also talk about a sort of like a Pixel book or like a kind of laptop by Google and I was I believe supposed to run Android at the end of the day um you know if that ever gets released then it does meet our requirements when chances are we can support that but yeah that doesn&rsquo;t really quite answer the question um let&rsquo;s say we have our hands full with the current um the yeah the current circumstances you with this one going back to the kernel so you mentioned the biggest security weakness is the security of the kernel and I do see that it is frequently exploited what about the closed sourced boot chain they asked um in detail what do you mean with closed boot uh the closed boot chain like do you mean the closed source like proprietary like firmware for example they said when rebooting the device you will see the hash of the os image which will betray the state of the device uh yes but that&rsquo;s just verified uh boot doing its its its work right.</p>
<p>Yeah I&rsquo;m a bit confused by that question yeah maybe we can you worded I think I also didn&rsquo;t quite yeah I see the message you have now I&rsquo;m talking about the proprietary initial bootloader when talking about the boot chain.</p>
<p>Propriety okay I mean well yeah I mean you know that is all kind of in the firmware and we can&rsquo;t really change the firmware in that regard but there&rsquo;s also one of the requirements that the firmware is updated regularly yeah can&rsquo;t do much about that on the Pixels. But as far as I understand for more you security on the Pixels is pretty good and I mean Google has like we cannot really like change the firmware on our own but Google has changed the firmware for for us in a way based on our suggestions in in the past so so there&rsquo;s that I remember a while ago uh mentioning there might be plans to implement an anti-feft feature that lock the device if sense being snatched out of someone&rsquo;s hands like there is an Android but it would be it would be a graphic or a specific implementation it&rsquo;s just in the pipeline.</p>
<p>Um yeah someone mentions there is an issue on tracker mission that is max priority okay yeah I mean yeah I would say you know if if the issue is open if it&rsquo;s got a decent priority then it&rsquo;s on the radar then at the very least it&rsquo;s something that you know the devs consider to be a useful feature and on the topic of the issue tracker and kind of um jumping back to a previous talk we had here on the stream uh something I noticed that um like also on the on the internet people say we uh we&rsquo;ll just like delete uh issues randomly or comments on on our issue tracker and the answer to that is just like you know if if you&rsquo;re being rude or like super entitled then we simply don&rsquo;t have to put up with that like there you go and so in that case yeah we will delete comments or maybe even entire issues if you are uh not being nice there you go to put in the most um nice terms myself um you know if if you&rsquo;re like respectful then we will also be respectful.</p>
<p>Yeah sometimes there&rsquo;s this impression that an open source project is the equivalent of someone being angry at an Apple support employee but it&rsquo;s much different yeah like a lot of open source projects I&rsquo;ve seen some where you&rsquo;ll have a open source project a corporation is dependent on and the corporation will open an issue and start complaining asking for stuff and it&rsquo;s like well you know you&rsquo;re getting this for free there&rsquo;s only so much And it&rsquo;s, it&rsquo;s kind of odd and funny and also good in a sense, because, um, and actually this is something I&rsquo;m like happy about is that, um, like we will absolutely, um, like we, like we, we support like everyone in the sense of that, um, even if it&rsquo;s like just one seemingly random user who needs help or need something like specific explained, like we will indeed like take care of that user, um, and even like, like given in-depth, like technical explanation, for example, um, like we, we will do that, but it&rsquo;s like, we&rsquo;re happy to do that. Um, you know, that&rsquo;s, that&rsquo;s our passion is a project driven by, by passion.</p>
<p>Um, but it&rsquo;s sad, like if, if you&rsquo;re just being rude or, or, or anything like that. Then we, we just don&rsquo;t need to, yeah, just, you know, we, we don&rsquo;t need to do that. So, and like, we just want, um, yeah, yeah, it&rsquo;s, it&rsquo;s an interesting, um, setup, right? Because it&rsquo;s like, um, this whole, like, I guess the graph, you know, ecosystem in a, in a sense is, is, is unique in a, in a sense that like you have, I don&rsquo;t know, like a typical, uh, Android phone and like the, the support from any of these like super large companies or, or Apple. And like, uh, in practice, like getting help from like a real human is, um, like closely impossible.</p>
<p>And you&rsquo;re just being shoved around in like FAQs and, uh, probably AI chatbots and probably AI chatbots like on your phone. And you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re just, you&rsquo;re well um whereas here you can just join the chat rooms or the forum or our Reddit or wherever and get help pretty much around the clock so that&rsquo;s nice and that&rsquo;s all for free there you go yeah it&rsquo;s pretty unheard of isn&rsquo;t that lovely.</p>
<p>Now here&rsquo;s a nice uh not a question but uh something someone wrote not so much a question but I love how informed whoever runs the twitter slash Reddit accounts is on other projects like the other linux phones and eos I always enjoy the twitter smackdowns they do okay yeah I mean yeah yeah indeed um you know some of our uh devs I mean some I&rsquo;ll give it all of devs definitely know what they&rsquo;re doing uh but yeah there&rsquo;s um um people in there they are clearly very very very good at their craft um so yeah yeah twitter account is like the general graph, you know, as I kind of shared, but most of the time I can kind of tell who is saying what, because it depends on like the time of the day. I can kind of guess who is saying what. But yeah, it&rsquo;s pretty, pretty cool. Yeah, I mean, that&rsquo;s the thing. Not everyone appreciates that. But the truth is like, we don&rsquo;t, we don&rsquo;t sugarcoat things. Okay. Like, because like educating people about, I mean, I don&rsquo;t want to say like real privacy insecurity, because real privacy security depends on who you ask. But like the privacy insecurity that we think is real. Like educating people.</p>
<p>About that um is it&rsquo;s a it&rsquo;s a major role of of of what we do plays a major role um so we we don&rsquo;t really sugarcoat things and I guess sometimes that does um upset people occasionally um so yeah but you know there are um ways you can vegetate that yeah part of the issue too is the more popular that privacy and security get as a trend the more you get people coming in who want to make a buck off what&rsquo;s been done and so they kind of launch their own products that is such a great topic I&rsquo;m I I love I&rsquo;m really happy that you touched on this like the amount of like probably like almost every day okay I I I check like graphing or socials I&rsquo;ll check like our chats and then I I I come across some random like os that is based on GrapheneOS and that is clearly just trying to piggy bank of our success okay some random os and turns out all they do is just bundle some some apps and then yeah they they bundle some apps they bundle some um some some kind of services some like gimmicky features call it an os slap a price tag on it most of the time it&rsquo;s even a subscription and then sell that that happens so often and like people can do that like the permissive license does allow people to take GrapheneOS do their own thing and and sell it or sell straight up GrapheneOS like people do that people can&rsquo;t do it um yeah it happens so frequently and like the truth is like there is simply nobody else that um does the work we do and especially not these like very shady looking forks of graphene.</p>
<p>OS okay yeah just don&rsquo;t yeah just don&rsquo;t don&rsquo;t even no just just don&rsquo;t there you go that&rsquo;s that&rsquo;s my response um yeah like GrapheneOS kind of plays on its in its own league um in in practice I mean okay I guess like stock Android and like stock Pixel OS and like iOS also like admittedly are pretty like in that league I suppose or at least the closest um but um yeah and uh it&rsquo;s what yeah what also happens is because like um we are so good at what we do um it&rsquo;s happened that um you know sometimes we call out these kind of fishy products that are just out to like startup scam you okay and you know of course we&rsquo;re not going to make friends with these people but we also don&rsquo;t want to be friends with these kind of like entities um and there&rsquo;s many examples I could I could bring here um but like just straight up scam products um.</p>
<p>I&rsquo;ve seen some replies that are like oh well why don&rsquo;t you just help them instead and make them better and that&rsquo;s such a big request to tell or to make it&rsquo;s be like I&rsquo;ll just help improve their product that&rsquo;s like it&rsquo;s tough enough maintaining one os let alone helping improve a project to bring them up to the same standards I don&rsquo;t know it&rsquo;s just some of the comments I see on those those threads that pop up um yeah but you need to differentiate between like you like a literal just scam product that, you know, the creators clearly don&rsquo;t actually care about. They&rsquo;re only after your money, okay? Like, always follow the money, essentially. Like, that&rsquo;s not going to do anything. It&rsquo;s just a waste of time.</p>
<p>And we also don&rsquo;t want to, like, be put in any kind of connection with these kind of companies. Just don&rsquo;t. They always advertise, like, military-grade encryption and all kinds of, like, just ridiculous amount of, like, buzzwords. But I don&rsquo;t know, like, what do they even mean? Yep. Yeah. There&rsquo;s been somewhere then they go and do, like, an interview, and it&rsquo;s like, what are you even talking about? Yeah. Or they just have, like, paid sponsorships on, like, various YouTube channels and content creators.</p>
<p>And then&hellip; You like watch the video and and they&rsquo;re like uh they&rsquo;re advertising like uh like a dns block list as like the holy feature and they they show how look how many trackers we&rsquo;ve blocked and it&rsquo;s like bro like this is just very simple dns blocking that you can set up literally in two minutes like you don&rsquo;t need any specific knowledge and that is really not a crazy feature but um yeah I mean unfortunately some people who are just not very tech savvy um get sucked in that and and believe these claims um and you know most of the time we just leave them alone uh but yeah sometimes we will kind of go ham on them when they just spread lies about us and the project if they say oh look oh you know graphene is actually a good project but look at how good our project is like and then yeah that like good luck because we will absolutely obliterate you on a technical level completely and you will not survive that encounter um yeah and like I I do find that is totally fine like as harsh as that may have sounded just now yeah like I I don&rsquo;t know why we should give space to just outright scammers I&rsquo;ve been seeing some posts where they&rsquo;ll use like a block test site and they just reverse the domains that are blocked why isn&rsquo;t GrapheneOS blocking them actually here&rsquo;s the full story you know it&rsquo;s just kind of debunking those yep those those facts yep yep yep yep it is really sad to see um I I hate those so much yeah.</p>
<p>So I mean honestly like if you like don&rsquo;t have a Pixel or or you know like we we also have to keep in mind people who live in countries where Pixels are not sold okay and importing Pixels are super expensive um in that case well you can&rsquo;t really use graffiti OS but in that case we would just recommend you to either stay on the the stock OS or I guess go and switch to the natural ways if if a device supports it um because I guess on an like end-of-life phone um you know that doesn&rsquo;t receive further updates um I suppose lineage OS would still bring some like user space updates um you know it&rsquo;s not saying that is that it&rsquo;s a very good idea to use bad but uh sometimes you kind of have to work with what you have um.</p>
<p>But uh yeah I guess on that line of thought question about what does GrapheneOS think about the pal moon browser so I guess that could be a general question isn&rsquo;t that just a Firefox like yeah it&rsquo;s a hard fork from Firefox so I guess maybe just a general question about Firefox forks in general kind of what&rsquo;s the opinion on those kinds of browsers um so first of all Firefox not exactly a very secure option especially not on Android uh it&rsquo;s it&rsquo;s really far behind on on Chromium uh like behind Chromium um so it&rsquo;s just not a good option in in general um I I recommend you to search for like Firefox uh like keywords on our socials and maybe even on on our Discord for example uh it it doesn&rsquo;t do very well in terms of like site isolation as uh you of similar things of similar nature and I mean this pale pale moon browser I mean it&rsquo;s probably very niche and so um it may also lag behind on on updates um which is not good uh you know if you&rsquo;re gonna fork a browser then you also need to stay up to date with a fork.</p>
<p>Uh I I don&rsquo;t I I I mean I&rsquo;ve not looked into it right but a is Firefox b it&rsquo;s probably pretty niche um so probably not not the best option from a purely objective standpoint.</p>
<p>So it says my phone died and I just went for a walk while it was charging please don&rsquo;t say I missed some kind of cursed desktop os discussion um I mean we did have some desktop discussion before it wasn&rsquo;t particularly long.</p>
<p>All right here&rsquo;s one that I&rsquo;ve seen come up a few times as well what is GrapheneOS doing or going to do when Google makes AOSP closed Google cannot be trusted would GrapheneOS move to a model similar to what pure os did with their phone. Um I don&rsquo;t know what model this pure os is going for but there is no indication that you know Google is closing off AOSP in that regard you And we do have a Motorola on our side now, which should help with that or any other kinds of weird shenanigans that Google might be doing. Because I feel like on the Hakuka side of things, things change very quickly recently.</p>
<p>Yeah, it would be interesting to know what this other OS has in store or what it&rsquo;s doing. I think people also forget too that Android has run on more than just phones. So for them to close off Android, it&rsquo;s not just against GrapheneOS or some other projects. It would be like every device, car, TV. Yep, yep. That is indeed also true. I think people vastly underestimate what it would take for Google. To be like yep yeah we&rsquo;re closing this off here&rsquo;s an interesting question what is a common recommendation people give to GrapheneOS users that is very wrong um let me think about this for a moment a common recommendation okay so people that are non-graphine os users that recommend things to actually graphine os users that is very wrong that&rsquo;s how I understand it um.</p>
<p>Interesting josh do you have any thoughts on that like yourself.</p>
<p>I think uh I guess this also touches on another topic but the fact to avoid Google at all costs and if you use open source then you&rsquo;re safe I think is yeah yeah that is a good point too that&rsquo;s a very blanket statement that has a lot of nuance to it like just because you don&rsquo;t install play services because someone recommended it doesn&rsquo;t mean an app is not bundled with Google code inside of it yeah function yeah that happens all the time it happens all the time like apps are bundled with the Google libraries all the time yeah for sure I mean I would also say like like rooting your phone using like shizuku I hope I pronounced that right um like tinkering with developer options um you know changing system apps permissions or like disable mentality like just don&rsquo;t do that in general do not touch on like do not touch like system apps you know go ham on like any apps you install yourself you can just do whatever you want for those but just leave the system apps alone they&rsquo;re trusted um just leave them alone.</p>
<p>Uh probably in a also more philosophical aspect that is a good point uh they say that grapheneurs is security first and you know essentially privacy second and that&rsquo;s just not true from from our perspective um because our perspective is um to achieve privacy you need good security because if you know if your phone is not very secure then you you can argue well the privacy aspect is kind of falling apart then so that is why also a lot of the work we do is also security but at the same time there&rsquo;s plenty of actually like straight up face-to-face privacy features use context scopes for example sandbox Google Play so there&rsquo;s there&rsquo;s plenty of that someone else mentioned that using F-Droid for everything is another uh yeah getting spread.</p>
<p>Um yeah I mean yes I mean sort of like yeah because you see I mean f4 sounds great on paper um great open source apps but then probably start with like they&rsquo;re building infrastructure like suddenly running on like an end of life uh like devian server for example uh like they&rsquo;ve been released I mean they&rsquo;re weird like inclusion policy um the like the the the as slow app release like updates update schedule there is a lot you can mention for F-Droid which kind of need to be approved upon ideally.</p>
<p>I saw some people saying GrapheneOS is the most secure os but they don&rsquo;t use it because they don&rsquo;t need that high level of security.</p>
<p>Yes but I mean.</p>
<p>Like everyone you know needs one&rsquo;s security whether they know it or not um I think these people. Don&rsquo;t necessarily like know that you know whatever phone or whatever setup they&rsquo;re currently have running is probably pretty awful to be honest you I think it&rsquo;s also tough to explain because if I lock my door in my house if someone breaks in or if I leave it open I know that happened saying you don&rsquo;t need security and kind of the cyberspace you don&rsquo;t really know something&rsquo;s wrong until it&rsquo;s really wrong yeah so to say you don&rsquo;t need it&rsquo;s kind of difficult I guess to say yeah yeah for sure as we have a we have the official graphic news account posting right now I say many people greatly underestimate the importance of the privacy and security improvements it makes yeah pretty much so it goes back to people who don&rsquo;t yeah who don&rsquo;t really have or understand the the whole picture.</p>
<p>Because it&rsquo;s also not something that um you touch on often right like there&rsquo;s not there&rsquo;s there&rsquo;s just simply not many projects that that take security seriously oh here&rsquo;s a question going back to the secure element could an attacker wait for a vulnerability in the secure element to access the device in before first unlock since the phone wouldn&rsquo;t be receiving updates if so would GrapheneOS consider an optional setting to purge the decryption key from the secure element after an amount of time similar to auto reboot.</p>
<p>Yes so I mean yeah that is true um in theory you you could wait or try to develop a secure element exploit um you know as far as we are aware that has not happened so far but yeah in theory yes if you if you hold a phone your possession for for enough time which is not updated eventually you may come across a vulnerability and you know if if you feel like that is in your threat model if that is something you want to be safe from um there are some features that are already in the os that kind of help like the recipe and password um that you know will nuke hot civil encryption keys and other like critical data um and the you know the mere presence of this feature existing um kind of just scares away you from like entering random PINs right because you might you might you might hit the duress one and then your all hope is lost on on recovering but the data but also we like this is what our um like the two factor uh fingerprint unlock is is used for where um so you can kind of use you can kind of rely on the secure element to do is throttling um or no sorry I I completely messed it up um where you do not do that in fact where you use like a master password for example so you know you reboot your phone uh your phone will always ask with initial password uh so that is like your primary unlock and that can be pretty much anything you want that can be just a regular PIN so you fully rely on the secure element but if you don&rsquo;t want to rely on just the secure element if you&rsquo;re afraid.</p>
<p>Where you could get breached in the future that is a new threat model then you will just use a sufficiently long for example passphrase or a password that is like 20 digits long um and that will protect the contents of your like phone even against a brute force attempt right like at least so far um it is not really possible to to brute force that um so even in the event that the secure element like throttling gets bypassed somehow in that case like your password would still kind of protect your your data and then you can use it to to factor fingerprint unlock to still have like a like in terms of usability a massive improvement um because you can still for like your secondary unlock you can then use your fingerprint and then additionally a PIN um because you know if you only have a fingerprint then that is a little risky because well your finger you somebody can just hold your finger against the phone and unlock it. Whereas with the two-factor fingerprint unlock, they would need your fingerprint as well as your PIN. And then you couple that with the auto reboot feature, right?</p>
<p>Which puts your phone back to the BFU state, which is the most secure state your phone can be. And then it would ask you for a master password again. So you can see there&rsquo;s a bunch of kind of features that work together to make this kind of cohesive structure. And yeah, try to cover all tracks in a way. But yeah, it really depends on your use case, your threat model, what you&rsquo;re afraid of. Like in practice, most people don&rsquo;t need to be afraid of the secure elements. Meant being breached like right um but hey if if if you are afraid of that if that&rsquo;s in your threat model or even if you&rsquo;re just interested in in in like securing your set from bed you know the features are there um play around the settings see see how they they all kind of interconnect.</p>
<p>I think talking about the encryption as well you know correct me if I&rsquo;m wrong but the PIN code or password used to set on the device is then used to derive the encryption key so it&rsquo;s not like a four-digit PIN means you have a four-digit encryption key no no no it&rsquo;s it&rsquo;s part of the like process yeah like someone tries to force the encryption it&rsquo;s it&rsquo;s much more protected it&rsquo;s not just a five-digit yeah yeah yeah there&rsquo;s there&rsquo;s a bunch of um things that go into that so for example also when like if um before if encryption keys are destroyed like you use duras PIN everything gets nuked even if like if that happens and even if the attacker for some reason knows your PIN slash password it doesn&rsquo;t matter anymore they still cannot decrypt it oh because you can&rsquo;t re-derive those encryption keys at that point in time anymore so the data is destroyed because yeah yeah there&rsquo;s just a bunch of factors that go into it duras PIN just nukes everything and then yeah duras PIN is very I mean it&rsquo;s it&rsquo;s not like it&rsquo;s I mean it is a simple feature in in a sense of what it does um and it is kept simple on purpose right because it obviously always needs to work so any complexity um could work against that so that&rsquo;s why we don&rsquo;t really have much of a like you know option menu for the duras PIN slash password.</p>
<p>Would having unfettered access to the data and the secure element give you the decryption key or would you still need the PIN slash password to get the full key someone asked um yes I am I&rsquo;m pretty sure that is accurate in the sense that like you do still need your your PIN slash password how to access it the decryption key yeah.</p>
<p>I I would recommend to read the there&rsquo;s a section of that on our website that talks about like the encryption in particular how long should the device pass you phrase B minimum I mean if you don&rsquo;t want to rely on the secure element faultling I believe there would be like six to eight words like if you&rsquo;re using a passphrase I believe that is still up to date and if it&rsquo;s like truly just a you know random jarbled mess of letters and numbers for example it would be about 20 characters I believe that it that like that makes it so you have enough entropy to resist even brute force attacks yeah.</p>
<p>And like doing that will provide like encryption on every any any kind of like phone or like or like regular drive right if you encrypt it with a sufficiently long PINs password passphrase But it&rsquo;s not necessarily very convenient to type in, especially on a phone, right? So that&rsquo;s why we use Pixels that have the good, that have the fortly included. That&rsquo;s why we have two-factor fingerprint unlock. I use like a 10-word passphrase and I kind of dread reboots now, but it&rsquo;s a nice peace of mind. Yeah, yeah.</p>
<p>Yeah, like that first reboot is going to be a little painful, I suppose. Although, I mean, I guess you could maybe use like a keyboard to type it in, but yeah, it&rsquo;s not the most like perfect condition usability-wise, but that&rsquo;s just the kind of trade-offs you have to make sometimes. Yeah. In general, like we strive to have like the best combination of like privacy, security, and usability, and like the out-of-the-box settings. Because there are ways to&hellip;</p>
<p>Where do you think that&rsquo;s okay? Where are we going from? I&rsquo;m going to show you what I&rsquo;m going to do. Like harden in a way the os fervor with like with the included toggles um.</p>
<p>But yeah a lot of them are not set by default or some of them some of them aren&rsquo;t I was actually curious about that when you guys so I think memory tagging is off by default if I remember correctly for user installed apps yeah do you guys do that is it kind of like how many users will this cause issues for versus the benefit or is there a time where it&rsquo;s like it&rsquo;s worth turning on by default is there like an analysis that goes into that at all um yeah it&rsquo;s just it&rsquo;s just sort of like an assumption or like a like knowing how many apps out there that have some kind of memory corruption bug that will be detected and thus terminated by memory tagging and then seeing well okay that&rsquo;s that&rsquo;s not great if people cannot use your apps because like okay in an ideal world you wouldn&rsquo;t need to use the app but in practice maybe you do need to use a buggy app um so yeah that that does also play a role right um you can for example also with our like the usbc settings um you can even turn off the usbc port entirely um or use it for charging only but that is not the default because it&rsquo;s just not um what I guess most people would use it for because a lot of people will connect the phone for something that isn&rsquo;t just charging like to a car for example or whatever um so so the default is uh pretty useful there somebody made a good point that the encryption keys are derived but not stored when a BFU state there is no key to obtain yeah I believe I believe you&rsquo;re right.</p>
<p>Yeah yeah.</p>
<p>No I&rsquo;m still looking for Discord I&rsquo;m sorry sometimes I go on these on these ramblings um all right let&rsquo;s see uh what else is here.</p>
<p>What are your thoughts on badness enumeration is it completely useless not as a convenience feature but as a tool for your price and security.</p>
<p>It&rsquo;s I would say not the end goal you Because I&rsquo;m sure there&rsquo;s plenty of papers and written sites that kind of go into detail about badness enumeration and why it doesn&rsquo;t actually work in practice or is not very reliable or you should be reliant on.</p>
<p>Is there a plan to support face unlock in GrapheneOS or is it considered less secure than other options? It can be fine if the Pixels still had the appropriate hardware for it. I believe, what was it, the Pixel 4 XL, I don&rsquo;t remember, but one of the Pixel 4s had like special like camera uh hardware that allowed an actually secure face unlock and that is since missing from like modern Pixels and that is also something and that is also why face unlock is not a thing in GrapheneOS.</p>
<p>Yeah I think then with the older device it could do like a 3d image almost I think they&rsquo;re like stereoscopic or something I forget the name now it&rsquo;s just a camera which is not ideal for that yeah it&rsquo;s it&rsquo;s just not yeah it&rsquo;s it&rsquo;s simply not secure you know it can be most definitely tricked and you don&rsquo;t want that um so yeah not even mentioning like pattern unlock right like that it&rsquo;s just horrible so it&rsquo;s also out removed.</p>
<p>What if you rely on the secure element how long then I mean if you rely on the secure element with the updated changes even the four digit long PIN um is secure right um and so like if you do rely on the secure element like adding much more beyond that isn&rsquo;t very useful I would argue.</p>
<p>Because if you see if you do something kind of in between where it&rsquo;s not really enough to withstand prolonged periods of brute forcing in an event that the secure element does fail you you might as well have just used a four-digit long pinband, for example.</p>
<p>Here&rsquo;s an interesting one. Will the Motorola&hellip; Go ahead. Is there any preference by the project on either a hardware or software solution being preferred? So like Lux encryption versus a secure element? Like is one better than the other?</p>
<p>Yes, I mean, the secure element has been tested under various conditions of trying to like break it and break the throttling et cetera. So yeah, yeah. I mean, I think it&rsquo;s maybe a little bit difficult to to come to come. Hair I don&rsquo;t really think they both fit the same use case if I understood the question correctly yeah I think it&rsquo;s more just which one&rsquo;s maybe more reliable if there is one hardware versus a software security sort of thing I mean having actual hardware to to back it up is definitely better especially for some like a secure element like frottling unlock attempts for for sure.</p>
<p>Uh will the Motorola devices support face unlock and eventually with a PIN so face unlock and a PIN that is written with stars.</p>
<p>Someone said three factor unlock. Like yeah let&rsquo;s go.</p>
<p>I mean yeah in theory right like but again only if the actual hardware is there to support a secure face unlock I believe that Apple does that much better I believe Apple does have actual hardware don&rsquo;t quote me on that but I&rsquo;m pretty sure Apple does would you use an Android laptop or tablet if Motorola offered one that met GrapheneOS requirements sure why not I I don&rsquo;t see why I couldn&rsquo;t replace my current laptop with an Android laptop to build this because I don&rsquo;t like I personally don&rsquo;t run anything like super intensive on my laptop which means um you know it kind of means I don&rsquo;t run any you any like programs or apps that wouldn&rsquo;t really work on Android at all, or not very well. So yeah, I can see that happen.</p>
<p>Are there any recommendations on secure firmware for old Thinkpads or old devices, like LibreBoot, CoreBoot, things like that?</p>
<p>I&hellip; I think these are kind of random questions, but just&hellip; Yeah, I mean, I think there isn&rsquo;t really a good way to fix this device at this point. We&rsquo;re just too old. The problem with, like, most of the time&hellip; Upgrading the firmware is like, the firmware is signed by keys that you do not have access to, okay? So like most firmware, at least on like modern devices, you cannot just update the firmware yourself, even if you wanted to. That is kind of just excluded as a possibility. I suppose, you know, some old devices, you can do that, which also kind of raises questions.</p>
<p>You know, if you can upgrade the firmware, it means anyone can also upgrade the firmware in a nefarious way. Also, the problem with these old, like the old hardware is not necessarily just missing firmware updates, but also just security issues in the hardware that you cannot necessarily fix. Software. I mean, there&rsquo;s all kinds of like, CPU side channel attacks, etc. But most of the time can be digitated by software, but it&rsquo;s not exactly a great fix. And at the end of the day, I mean, you see, just just look at the Pixel eight. And and later that comes with memory tagging, that is such a crazy good feature. And then it&rsquo;s just not it&rsquo;s just not a thing on older Pixels, right? So naturally, over time, old hardware just becomes so much more, or like so much worse in terms of protecting you. Because the newer hardware just has all the bells and whistles, like memory tagging, for example, crazy good feature.</p>
<p>Yeah, and it&rsquo;s tough because I definitely get the critique that e-waste is a problem for sure. So it&rsquo;s unfortunate that we&rsquo;re kind of end up with end up with the option of just discarding it. Which kind of sucks yeah yeah it does suck from an environmental perspective absolutely but it&rsquo;s just how it is I&rsquo;m afraid just the current state it&rsquo;s just not something that we can we can fix I would I would love to but I mean hey if if you have a um a plan I&rsquo;m all ears right.</p>
<p>Um yeah like it yeah you know for like the Pixels um if you have Pixels six and seven series it&rsquo;s not like they&rsquo;re bad um Pixel eight and later are just so much better but that&rsquo;s how you should maybe look at that so if you don&rsquo;t have a Pixel yet you should definitely consider eight or above because a the support time for the older Pixels is kind of running out slowly but But surely New Pixels have seven years of support from launch. So you would have just more support time one way or another.</p>
<p>Someone asked, going back to passphrase versus password. Is there much difference between a password of 40 random characters or a passphrase like a diceware? I think you get more entropy with random characters. That can also be a pain to remember to type in. Yeah, that is essentially why people use passphrases, right? Like, yeah. Yeah, it&rsquo;s not a huge difference. Yeah, it&rsquo;s an improvement, but it&rsquo;s just horrible to type and memorize. Yeah. If you can do it, you know, go for it. Good for you. But I think the longer the password will always kind of win out versus a complex short password.</p>
<p>At least at this point in time.</p>
<p>Oh, this is an interesting one. Have you had any memorable experiences working for GrapheneOS? Yeah, many. Where do I start?</p>
<p>You know, the ATT video, for example. I was kind of, in a way, responsible for that video. In a sense that I happened to talk to Linus himself. It was just like a DM.</p>
<p>Which was, of course, a little nerve-wracking because I&rsquo;m, of course, aware how. Thank you. How big the channel is so it makes sense to try to get the the best video uh out of this exp out of his um like test run as as possible but yeah I mean pretty happy with the end result and then another very very memorable experience something we didn&rsquo;t even touch on so far was um the like the article that uh wired published about GrapheneOS um that was definitely very memorable experience um because I I was the one who got interviewed by the the writer from from wired and um. Um yeah what do you even say about that like it&rsquo;s a it&rsquo;s a pretty complex topic because um you so what what happened is that um the article was really supposed to be about you know GrapheneOS uh it was supposed to be okay like yes it was also supposed to kind of cover the history of GrapheneOS it was supposed to cover uh the features of GrapheneOS um like we we talked about the like the philosophical aspect of GrapheneOS like who is it for um is it just for like security professionals and other super tech savvy people the answer was of course no um how does it compare to ios like the writer even bought herself I believe it was a Pixel 6a um because she she messaged me that she like was about to or or maybe like bought accidentally like a verizon model and I told her hey that&rsquo;s not gonna work and so you know the the plan was probably also for her to kind of share her her experience with GrapheneOS like her own like personal experience like someone that isn&rsquo;t like super tech savvy um which I think is like was a great idea um because it would probably um match better with the average reader of wired um and so that was what um was the plan okay like we talked about so many things right we talked about what happened in france uh we we we talked I I don&rsquo;t know what like we talk about everything pretty much okay and the end result is that we got an article that focuses like pretty much exclusively on like what happened like the very beginning with.</p>
<p>With copperhead um and it&rsquo;s like why um it kind of came out of nowhere um um they they just kind of you know send us like a questionnaire with a bunch of questions and it was clearly very very much linked to um what happened with with Copperhead back in the day like directly and it was pretty much only about Copperhead and that kind of um came as a surprise because that that is just not what the article was supposed to be about but I guess like maybe the editorial team over at Wired wanted some kind of um yeah some kind of like I I guess a bit of a clickbait even uh some kind of engagement bait um but like talk about what happened in France or or like talk about our partnership with with Motorola talk about the like the infinite palette of content that you know I offered the writer and you they they just discarded all of it and just did this whole article only about copperhead and that was just really disappointing because um you know I spent a lot of time talking to that writer and I I yeah I put in a lot of effort um and you know also bothered a lot of people trying to get all the details together and the end result is just this one article that focuses so lately on copperhead and it&rsquo;s not like a terrible article um it like it does paint GrapheneOS in a good light and which you know it should like especially in regards to copperhead um but it&rsquo;s just not what was discussed all this time right like like yes of.</p>
<p>Course go over the history of the project go over copperhead sure makes sense it&rsquo;s part of the history that is totally legitimate okay but why why did why did we make this whole article about copperheads suddenly um so yeah that was um very very bad yeah it&rsquo;s an interesting direction they chose especially with yeah like all the france stuff and all that going on at the time as well and then you focus on like talk about france like there is so much like clickbait potential there there is like I could give her a whole book about content that they can write about okay but why are you focusing on just this one single part of like the the history when there&rsquo;s so much to talk about there is so much content and we&rsquo;re like yep we&rsquo;ll do freaking copperhead and copper only uh yeah this uh has upset me to be honest a little frustrating a lot um but yeah it is what it is we we did share like we did publicly post like the questionnaire um that they sent to us and we also shared our answers to that questionnaire so we kind of did everything in our power um but yeah not exactly my favorite experience in that regard because like the the whole point and really this kind of circles back to the stream here the whole point is that um you know all of our communication thus far has been through written means okay it has always been it&rsquo;s pretty much only been text okay and text is great on the one hand.</p>
<p>Okay it takes us awesome because it&rsquo;s it&rsquo;s concise you can it&rsquo;s it&rsquo;s easily searchable but with tech next um I feel like you are you sometimes lose that that human element and um that is really something I&rsquo;m trying to introduce or reintroduce so people have a better understanding of the people behind you know GrapheneOS like our values uh what what bothers us um like what what what concerns us like what what what problems are we looking at um yeah that is that is really what what I want to achieve and that&rsquo;s also one of the reasons I did this word article right and then yeah you can tell it really bothers me because I spent so much time and it was all discovered it was all for nothing essentially you But yeah, go ahead.</p>
<p>What did you want to say? I mean, there&rsquo;s some benefit to a live stream where you kind of tell it your way versus the Wired article. You got to wait for the edit. What actually got included? What did you say? You know, it&rsquo;s, yeah. I think it humanizes it a little bit more. Kind of hearing someone talk directly. Yeah, yeah. I mean, yeah, like, you know, we&rsquo;re of course not like, I&rsquo;m not like sitting next to a whole bunch of, you know, GrapheneOS users or fans of the project. But I think it&rsquo;s definitely a lot closer than just the text, right?</p>
<p>Yeah. So yeah, you should. Everyone is listening. Everyone will listen. I mean, we&rsquo;re like four hours in. Oh God. I don&rsquo;t know if anyone that is like going to be listening to this on YouTube will even make it this far. But hey, if you did, post about it in the comments. Yo, говоря, church. No, no, no. Oh God. They never say it. And let me know if you appreciate this stream and if we should do this more often, because that&rsquo;s the whole idea. Yeah, kind of humanize the project a little bit and just show that the whole project is just driven by passion.</p>
<p>Yeah.</p>
<p>Yeah, if you want, we can probably wrap it up soon. I&rsquo;m getting a little fatigued at this point, four and a half hours in. Yeah, that&rsquo;s fair. I think, yeah, it is probably time. Yeah. Being on camera that long kind of throws me off. Yeah, understandable. I mean, I don&rsquo;t have my camera on, right? So I&rsquo;m in a bit of a more favorite position in that regard. Definitely would love to see more. That&rsquo;s nice to hear. Yeah. I mean I really appreciate you guys kind of speaking out in this manner I&rsquo;ve always watched all the interviews I see come out because it&rsquo;s just a a different medium to hear from yeah yeah exactly the project definitely enjoy it yeah the interview is uh they&rsquo;re both great I mean there&rsquo;s one with with gabe like flawed world right on the hated one channel thought I should repeat that if somebody wants to watch those and there&rsquo;s one with metroplex uh on david bombay channel and yeah I guess now there&rsquo;s this one too yeah nice little four hour one.</p>
<p>I guess I got a couple more questions and maybe we&rsquo;ll take like one or two more and then kind of okay end it there sure do you have a recommended time for auto reboot for me at least what I do is as short of a time as I can have without rebooting when I sleep it&rsquo;s kind of how I do it yeah that checks out things with auto reboot it really depends on what kind of apps and potential services you rely on you see the like stock clock app it supports direct boot what is direct boot direct boot is essentially a feature so the app continues to run and you know offers or like some of its services after you reboot your phone when your phone is in the BFU state before you unlock it for first time after reboot so that&rsquo;s what direct boot does so yes the clock app supports direct boot so even if auto reboots strikes when when you&rsquo;re sleeping your phone should still ring the alarm yeah I&rsquo;ve tested that one and it does work yep confirmed yeah I I have I mean I do every now then very rarely I do see reports if it&rsquo;s not working but it should If it doesn&rsquo;t, then I&rsquo;m not sure.</p>
<p>Maybe you just misconfigured something effectively. But yeah, then there&rsquo;s something to fix. But yeah, it should work. Other apps, maybe not so much. I&rsquo;m not actually sure about Signal, for example. How well does it work in a BFU state? I&rsquo;m not entirely sure. Is there an easy way to check if an app supports that? I guess you&rsquo;ve got to inspect the APK directly. You can&rsquo;t just do like app info. Yeah, I don&rsquo;t know. No, it&rsquo;s not going to be in the app info page. But that is just something you need to keep in mind.</p>
<p>But I mean, the default is set to, it should be 18 hours. I mean, realistically, almost everyone will unlock their phone at least once with one of those 18 hours. I don&rsquo;t know. Someone says their molly database looks for me after reboot yeah but that could be surgery depends on the apps do you do your own research in a way and yeah I mean the default is already pretty good like 18 hours yeah you can you can put it put it down all the way to 10 minutes if you you want to but I think.</p>
<p>Almost nobody watching will have that sort of requirement.</p>
<p>I&rsquo;ve got a got a message here that signal does not support direct boot okay calls Doesn&rsquo;t text work BFU, but contacts do not see, you wouldn&rsquo;t see contact names. I mean, okay, it&rsquo;s a decent though. Yeah, good to know. But yeah, the direct boot support is something you need to keep in mind. If that is something you rely on, I don&rsquo;t know what kind of apps are there. So there could be some constellations. Do you know of anything that is a major security issue, but cannot be fixed, for example, because it&rsquo;s a hardware flaw?</p>
<p>And the devices?</p>
<p>I&rsquo;m not aware of any specific incidents like that. It is not for any of the ones that are currently supported, no. I don&rsquo;t believe so. There is anything like critical or like that crucial, let me put it that way. No I I think yeah like any any of the ones we currently support are suitable but still get eight or later because uh you don&rsquo;t you don&rsquo;t want to run a phone that is end of life right and we will also just drop support for those phones.</p>
<p>Um so yeah. I don&rsquo;t know if you have any more questions about or questions on your side if you want to cover any more uh someone does yeah okay this is I guess yeah this this does kind of count they say fix the firmware sometimes has issues that require a full power cycle including discharging the device when shut so down. There shouldn&rsquo;t be a security issue, but it is semi, semi-common.</p>
<p>Yeah. Um, I mean, some, some of those people like, uh, discharge their phone all the way down to 0%. Um, and then like they plug it in and it&rsquo;s, it&rsquo;s, it&rsquo;s kind of strange because like the phone starts to like boot the OS, but oftentimes that requires more power than is bill is being delivered to the phone. Uh, so the phone ends up kind of like boot looping. Um, in a way it starts to tries to start the OS crashes, you know, phone shuts down, uh, on repeat. Uh, but you can, you can fix that by just like pausing the boot process at the like verified boot key screen when, you know, when it tells you that you&rsquo;re running a different operating system, just hit the power button to, to pause the screen there. Uh, let it sit for a few minutes and then resume.</p>
<p>Uh, does Graphene always have any plans for an enterprise device management app or any other features geared towards enterprise appeal?</p>
<p>I,.</p>
<p>I&rsquo;m not aware of any immediate plans.</p>
<p>But it is, of course, useful to try to make these apps work if, if they don&rsquo;t, or at least, you know, try our best and see, see what&rsquo;s fixable. Right.</p>
<p>As I&rsquo;m also mentioning that Pixel 6a cannot be used for flashing, like, uh, That&rsquo;s not really fine. You, you know what year? Another Pixel like to install graphite noise on that is something I&rsquo;ve also read cannot verify myself but that is yeah one of those a real quick that might affect you okay one you know what one one last question. They say they ask how was the live stream and interaction with the community for you both. I mean it was good from my side. Yeah I think the questions and amount of them was overwhelming a little bit I never had that many come in in a stream before yeah I think it was a pretty good mix of like over discussions maybe a little fatiguing for Josh in particular because he&rsquo;s always a part of the camera right so that&rsquo;s maybe something we need to um do better next time potentially um I thought it was great though yeah I don&rsquo;t yeah lots of lots of interesting questions yeah yeah what&rsquo;s it was a good mix for sure I I think I I think yeah I think I talked about pretty much everything I want to touch on so um that was good yeah um not for sure and someone did ask where can people go to read more about GrapheneOS and where can they donate if you want to point them in the the right direction for that to see them off um yeah there is a on the website there is a like subsection donate so it&rsquo;s just like grapheneos.org slash donate and then you can get to the donation page and it kind of tells you all the all the donation options GitHub sponsors bitcoin monero zcash ethereum uh cardano litecoin wise local bank transfer papal and interact e-transfer so you have all the options you have all the options um and I believe those are pretty much also sorted by like the least amount of fees you have to you have to pay uh from top to bottom uh I know GitHub sponsor is pretty good in that regard but yeah you can I mean we get a lot of donations through like crypto as well.</p>
<p>So yeah of course donations always welcome but as I said before you know if if you want to participate in in the project beyond like just using it there&rsquo;s plenty plenty of ways right plenty plenty of ways advocating online for it kind of posting your experience with it definitely helps yeah yeah for sure that is definitely one of the most important things you can do with the the biggest impact and definitely do not under underestimate how how much of an impact you can have so yeah it&rsquo;s my favorite part because it&rsquo;s it&rsquo;s so easy or like you know like the barrier to entry is so low in that regard um you don&rsquo;t need any any specific knowledge or or like hardware or whatever uh you just need yourself and an internet connection I suppose.</p>
<p>Um yeah so that&rsquo;s uh that&rsquo;s awesome yeah I think that about sums it up pretty well then yeah okay yeah thank you everyone for joining yeah thanks everyone for sticking around I I&rsquo;m really curious yeah I&rsquo;m really curious how like the aftermath when when you upload this massive chunk of the video how people react it might be a little too long for some people but all right yeah but I mean you you said you were gonna um kind of put some put us in timestamps and like what we generally talk about um I think I think that&rsquo;s gonna help a lot yeah so if you can maybe see kick through yeah on the on the topics that you know they might be interested in the most yeah um okay yeah lovely yeah thanks again for being here appreciate it and thanks again everyone yeah as well yeah thank you thank you I I hope the beginning of the stream was fine I was definitely a little uh shaky but uh it&rsquo;s fine from shaky to comfortable to tired pretty much yeah but that about sums it up awesome sounds good everyone have a good one yeah.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>How to Set Up IVPN on OpenWrt with WireGuard | Router VPN Guide</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-setup-ivpn-on-openwrt-wireguard/" />
        <id>https://staging.sideofburritos.com/blog/how-to-setup-ivpn-on-openwrt-wireguard/</id>
        <published>2026-07-19T13:45:00Z</published>
        <updated>2026-07-19T13:45:00Z</updated>
        <summary type="html">I&amp;#39;ve been using a router VPN for over five years. It provides blanket protection for your network, and it&amp;#39;s a great way to protect devices that don&amp;#39;t natively support a VPN client.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode91s0hbhb">🎥 


<a href="https://youtu.be/pLCCr3NhwdY" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.ivpn.net/setup/router/openwrt-wireguard/" target="_blank" rel="noopener" class="text-break">https://www.ivpn.net/setup/router/openwrt-wireguard/</a> - IVPN setup guide</li>
<li>


<a href="https://www.ivpn.net/status/" target="_blank" rel="noopener" class="text-break">https://www.ivpn.net/status/</a> - IVPN server list</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>Today I want to talk about how to set up a whole-home VPN on OpenWrt.</p>
<p>If you already know why you want to do this, feel free to skip ahead to the instructions. The timestamps are listed below the video. But if you’re curious about why you might want a whole-home VPN, let’s start with a demonstration.</p>
<p>Imagine your normal home network. You have a router, a laptop, and a phone. In a typical setup, your devices connect to the router over Wi-Fi or through a LAN or Ethernet cable.</p>
<p>Your router is assigned an external IP address by your internet service provider, usually through a modem or another device depending on the type of internet connection you have. For this example, we’ll call that IP address <strong>1.2.3.4</strong>.</p>
<p>When you request a website such as example.com, your device sends the request through your router. The request leaves your network using the IP address assigned by your ISP. When example.com checks who is visiting, it sees <strong>1.2.3.4</strong>.</p>
<p>Many people use a VPN to mask that ISP-assigned address. In my case, I use IVPN. The usual way to use a VPN provider is to install its app on each device. You install the IVPN client, choose a server location, and establish a connection through your router and ISP to the VPN provider.</p>
<p>After that connection is established, a request to example.com uses the VPN provider’s IP address instead. For this example, we’ll call that address <strong>5.6.7.8</strong>. The website now sees the VPN address rather than the IP address assigned by your ISP.</p>
<p>The drawback is that the VPN client must be installed and connected on every device. IVPN’s standard plan, for example, has a device limit. If the client is installed on both your phone and laptop, those count as two separate devices.</p>
<p>You may also have devices that do not support a VPN client. A Roku is one example. I’m not endorsing Roku; I’m only using it because it is popular in the United States. Because the Roku cannot run the VPN app, it continues accessing the internet through your ISP-assigned IP address even while your other devices use the VPN.</p>
<p>Instead of installing the VPN client directly on every device, you can configure the VPN connection on your router.</p>
<p>In that setup, the router establishes the connection to IVPN. Any outbound traffic routed through it uses the VPN address. Your laptop, phone, streaming box, and other devices do not need their own VPN clients. A firewall rule on the router directs outbound traffic through the VPN tunnel, so every connected device receives the same protection.</p>
<p>That is why this is often called a whole-home VPN.</p>
<p>Another benefit is that all of the devices behind the router share a single VPN tunnel. You might have three devices connected, or you might have ten, but the VPN provider generally sees the router’s tunnel as one connected device.</p>
<p>Guests also receive the same protection. When a friend connects a phone or laptop to your Wi-Fi, that traffic is routed through the VPN automatically. You do not need to install individual clients, confirm that every client is connected, or worry about exceeding the VPN account’s device limit.</p>
<p>The main reason I’m configuring this on my travel router is for hotel Wi-Fi.</p>
<p>The travel router connects to the hotel’s wireless network and then broadcasts a separate wireless network for my devices. Everyone traveling with me connects to the network broadcast by the travel router, and all of those devices are protected by the VPN connection.</p>
<p>This is also convenient when a hotel uses a captive portal. The travel router becomes the authorized device on the hotel network. Once the router has completed the hotel’s sign-in or registration process, the devices behind it can usually connect without each one going through the captive portal separately.</p>
<p>The network diagram may look a little confusing, but I hope it answers more questions than it creates. They say a picture is worth a thousand words. This was a diagram, so hopefully it was worth ten thousand.</p>
<p>For this setup, I’m following the official documentation on IVPN’s website, which is linked below the video.</p>
<p>Always check the provider’s current documentation before following a YouTube tutorial, because the video may eventually become outdated.</p>
<p>I have not configured this particular setup on OpenWrt before. I’m starting with a mostly default OpenWrt installation. I set an administrator password and enabled HTTPS, but I have not changed much else.</p>
<p>For the demonstration, the travel router is using my home Wi-Fi as its wireless uplink so that it has an internet connection.</p>
<p>In the router’s web interface, navigate to:</p>
<p><strong>System → Software</strong></p>
<p>Click <strong>Update Lists</strong> and allow the package list to finish refreshing. After it completes, dismiss the status window.</p>
<p>Use the filter field to search for <strong>WireGuard</strong>. Locate and install the following packages:</p>
<ul>
<li>WireGuard Tools</li>
<li>Kmod WireGuard</li>
<li>LuCI Proto WireGuard</li>
</ul>
<p>IVPN also provides OpenVPN instructions, but I’m using WireGuard for this guide. In my opinion, there is no benefit to using OpenVPN for this setup at this point. Follow IVPN’s OpenVPN guide instead if that is the protocol you prefer.</p>
<p>Install <strong>WireGuard Tools</strong> first. Leave the “Allow overwriting files from other packages” option unchecked, then confirm the installation.</p>
<p>Kmod WireGuard may be installed automatically as a dependency. Finally, install <strong>LuCI Proto WireGuard</strong>, again leaving the overwrite option unchecked.</p>
<p>After the packages are installed, restart the router:</p>
<p><strong>System → Reboot → Perform Reboot</strong></p>
<p>My router took about 45 seconds to restart. When the login screen returns, sign in again.</p>
<p>The next step is to create the WireGuard interface.</p>
<p>First, generate a WireGuard configuration file using your preferred server and parameters. IVPN notes that its configuration-file generator is available only for accounts created after November 2020, so older accounts may require a different process.</p>
<p>Sign in to your IVPN account, scroll to the WireGuard setup section, and open the <strong>Configuration File Generator</strong>.</p>
<p>The key comment is optional. I entered <strong>OpenWrt</strong>.</p>
<p>Click <strong>Generate Key</strong>. The page will display a public key. I blurred mine in the video for privacy.</p>
<p>For this example, I’m creating a single-hop connection. Select the country, city, and server you want to use. I selected Reykjavik, Iceland, and one of the available servers.</p>
<p>I left the connection on the default port, selected IPv4 only to keep the demonstration simple, and left the DNS setting on Standard.</p>
<p>Click <strong>Download ZIP Archive</strong>. Extract the archive, open the configuration file in a text editor, and copy its entire contents. The file contains sensitive configuration information, so do not share it publicly.</p>
<p>In OpenWrt, navigate to:</p>
<p><strong>Network → Interfaces</strong></p>
<p>Click <strong>Add New Interface</strong>.</p>
<p>Give the interface any descriptive name. I used <strong>IVPN Iceland</strong>.</p>
<p>Set the protocol to <strong>WireGuard VPN</strong>, then click <strong>Create Interface</strong>.</p>
<p>On the <strong>General Settings</strong> tab, click <strong>Load Configuration</strong>. Paste the contents of the WireGuard configuration file and click <strong>Import Settings</strong>.</p>
<p>OpenWrt should parse the file and populate the configuration fields automatically. If it does not, the file contents may not have been copied correctly.</p>
<p>Next, open the <strong>Advanced Settings</strong> tab and set the MTU to:</p>
<p><strong>1412</strong></p>
<p>Make sure this value is set correctly. An incorrect MTU can cause poor performance or prevent some connections from working. MTU stands for maximum transmission unit. If it is too high, packets may be fragmented and the connection may behave unpredictably.</p>
<p>Open the <strong>Peers</strong> tab and click <strong>Edit</strong> next to the imported peer configuration.</p>
<p>Enable <strong>Route Allowed IPs</strong>.</p>
<p>Set <strong>Persistent Keep Alive</strong> to:</p>
<p><strong>25</strong></p>
<p>Click <strong>Save</strong>, then save the interface configuration and click <strong>Save &amp; Apply</strong>.</p>
<p>Before continuing, I checked my current external IP information. At that point, my traffic was still appearing through a Chicago location. This gives us a baseline so we can confirm later that the route changes to the Iceland VPN server.</p>
<p>Navigate to:</p>
<p><strong>Network → Firewall</strong></p>
<p>Click <strong>Add</strong> and enter the following settings:</p>
<ul>
<li><strong>Name:</strong> <code>ivpn_firewall</code></li>
<li><strong>Input:</strong> Reject</li>
<li><strong>Output:</strong> Accept</li>
<li><strong>Intra-zone forward:</strong> Reject</li>
<li><strong>Masquerading:</strong> Enabled</li>
<li><strong>MSS clamping:</strong> Enabled</li>
</ul>
<p>Under <strong>Covered Networks</strong>, select the VPN tunnel interface you created earlier. In my case, that is <strong>IVPN Iceland</strong>.</p>
<p>Under <strong>Allow Forward From Source Zones</strong>, select <strong>LAN</strong>.</p>
<p>This allows traffic from devices connected to the router’s LAN or wireless network to be forwarded through the IVPN interface.</p>
<p>Click <strong>Save</strong>, then click <strong>Save &amp; Apply</strong>.</p>
<p>The next step is optional, but I recommend it.</p>
<p>A kill switch ensures that traffic from your LAN devices travels only through the VPN tunnel. It also prevents leaks if the router loses its connection to the VPN server.</p>
<p>Edit the existing <strong>LAN</strong> firewall zone and remove <strong>WAN</strong> from the allowed destination zones. This blocks outbound traffic if the IVPN connection goes down instead of allowing the connection to fail over to the normal WAN interface and expose your ISP-assigned IP address.</p>
<p>In the firewall page, click <strong>Edit</strong> on the LAN zone. Uncheck <strong>WAN</strong> under the allowed destination zones, then click <strong>Save</strong> and <strong>Save &amp; Apply</strong>.</p>
<p>After this change, the LAN zone should forward only to the IVPN firewall zone.</p>
<p>Next, configure DNS.</p>
<p>Navigate to:</p>
<p><strong>Network → Interfaces</strong></p>
<p>Click <strong>Edit</strong> next to the WAN interface. On the <strong>Advanced Settings</strong> tab, uncheck <strong>Use DNS Servers Advertised by Peer</strong>.</p>
<p>Enter IVPN’s standard WireGuard DNS server address:</p>
<p><strong>172.16.0.1</strong></p>
<p>You may use IVPN’s AntiTracker DNS address instead if you prefer that option.</p>
<p>Click <strong>Save</strong>.</p>
<p>In my setup, the internet uplink is wireless, so I also needed to apply the same setting to the <strong>WWAN</strong> interface. If your router uses its physical WAN port, edit the WAN interface. If it uses a wireless uplink, edit the corresponding WWAN interface instead.</p>
<p>Uncheck the advertised-DNS option, enter the VPN DNS server address, and save the interface.</p>
<p>If your ISP also provides IPv6 connectivity, repeat the applicable steps for <strong>WAN6</strong>. My ISP does not provide IPv6, so I skipped that part.</p>
<p>Click <strong>Save &amp; Apply</strong>.</p>
<p>A reboot is not strictly required, but it can help confirm that everything behaves correctly after a restart. When in doubt, reboot.</p>
<p>Navigate to:</p>
<p><strong>System → Reboot</strong></p>
<p>After the router restarts, sign in again.</p>
<p>With the configuration complete, run several tests from a device connected to the OpenWrt router.</p>
<p>First, use a service such as dnsleaktest.com. In my test, the connection showed Reykjavik, Iceland.</p>
<p>I also refreshed an IP-information service. The first site appeared to block the Icelandic VPN address, so I tested the address using MaxMind instead. That service showed Reykjavik and identified the hosting network.</p>
<p>This confirms that internet traffic is using the new VPN connection.</p>
<p>The DNS leak test also showed an Icelandic DNS server, confirming that DNS requests were using the server configured in the previous step.</p>
<p>The final test is the kill switch.</p>
<p>I started a continuous ping to:</p>
<p><strong>1.1.1.1</strong></p>
<p>The ping worked while the VPN interface was active.</p>
<p>I then returned to:</p>
<p><strong>Network → Interfaces</strong></p>
<p>I stopped the WireGuard interface. As soon as the VPN connection shut down, the ping requests began timing out. Restarting the ping did not restore internet access while the VPN interface remained disabled.</p>
<p>That confirms the kill switch is working. When I restarted the WireGuard interface, the internet connection returned.</p>
<p>At this point, the router is connected to the VPN, the kill switch is functioning, and any device connected through the router’s wireless network or LAN port is routed through the VPN connection.</p>
<p>There are some inconveniences with this setup.</p>
<p>For example, the VPN server may have an outage. If the selected server goes down, you may need to connect to a different server manually.</p>
<p>You can check IVPN’s server status page, select another server, and update the IVPN configuration in OpenWrt. In the interface settings, open the <strong>Peers</strong> section and update the endpoint host and public key as required.</p>
<p><em>[The original VTT transcript cuts off part of the sentence at this point.]</em></p>
<p>That about sums it up. I hope this helped address any concerns or doubts about setting up a whole-home VPN.</p>
<p>The setup is fairly straightforward once you become familiar with it. Test everything and make sure it behaves as expected. Do not wait until something breaks to learn how the configuration works.</p>
<p>If you have any questions or comments, leave them below, and I’ll see you next time.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>How Android Is Becoming More Restricted</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-android-is-becoming-more-restricted/" />
        <id>https://staging.sideofburritos.com/blog/how-android-is-becoming-more-restricted/</id>
        <published>2026-03-26T13:55:00Z</published>
        <updated>2026-03-26T13:55:00Z</updated>
        <summary type="html">The GrapheneOS foundation has officially announced its partnership with Motorola.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode73s0hbhb">🎥 


<a href="https://youtu.be/fSUW3y4v_w4" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://arstechnica.com/gadgets/2026/03/google-details-new-24-hour-process-to-sideload-unverified-android-apps/" target="_blank" rel="noopener" class="text-break">https://arstechnica.com/gadgets/2026/03/google-details-new-24-hour-process-to-sideload-unverified-android-apps/</a> - Ars Technica Article</li>
<li>


<a href="https://android-developers.googleblog.com/2026/03/android-developer-verification.html" target="_blank" rel="noopener" class="text-break">https://android-developers.googleblog.com/2026/03/android-developer-verification.html</a> - Android Developers Blog Post</li>
<li>


<a href="https://grapheneos.social/@GrapheneOS/116261301913660830" target="_blank" rel="noopener" class="text-break">https://grapheneos.social/@GrapheneOS/116261301913660830</a> - GrapheneOS Mastodon Post</li>
<li>


<a href="https://blog.knowbe4.com/ftc-states-that-scams-cost-u.s.-consumers-158.3b-in-one-year" target="_blank" rel="noopener" class="text-break">https://blog.knowbe4.com/ftc-states-that-scams-cost-u.s.-consumers-158.3b-in-one-year</a> - FTC Article</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">📝 Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Google has been working with the community to make your device security more robust while still being respectful of platform freedom.</p>
<p>That is not my opinion. I am loosely paraphrasing a post on the Android Developers Blog about Android developer verification. But instead of referencing a post clearly written by a marketing team, let’s look at an Ars Technica article talking about this.</p>
<p>Google details a new 24-hour process to sideload unverified Android apps.</p>
<p>Now, I really don’t like this word. I understand why it came about a couple of decades ago, but “sideloading” is just installing an app on your device. Big tech has been using it to demonize installing applications outside official app stores.</p>
<p>If you install an app outside of the Google Play Store on Android, that is called sideloading. If you install an EXE downloaded from the internet on a Windows machine outside of the Microsoft Store, that is also sideloading.</p>
<p>I could keep ranting about this, but I won’t. Just know this: if you sideload an app, you installed an app. Stop using the word “sideload.” It is doing more harm than good.</p>
<p>But Google uses that term, so we will use it here.</p>
<p>With these new limits, Android phones will only install apps from verified developers. To become verified, developers releasing apps outside Google Play will need to provide identification such as a passport or driver’s license, upload signing keys, and pay a 25 dollar fee.</p>
<p>Apps from unverified developers will not be installable unless you go through a new advanced workflow buried in developer settings.</p>
<p>Right now, Android phones alert users about enabling unknown sources and guide them through it. The new process is different and will not be obvious. You have to know where it is and enable it yourself, and it is not quick.</p>
<p>Here is how it works.</p>
<p>First, you must confirm that no one is instructing you. This is meant to prevent scammers from coaching victims.</p>
<p>Next, you must restart your phone and re-authenticate. This is supposed to cut off remote access or active scam calls.</p>
<p>Then you have to wait 24 hours. This delay is intended to break the sense of urgency scammers rely on.</p>
<p>After the wait, you return and verify again.</p>
<p>Finally, you can enable installation of unverified apps. You can choose to allow it temporarily for seven days or indefinitely, although the indefinite option is marked as not recommended.</p>
<p>Once you complete all of this, you can install apps again.</p>
<p>This entire process is difficult to describe without using harsh language. There are several dark patterns here. It is buried in settings, requires a long delay, and discourages enabling it permanently.</p>
<p>It is easy to imagine a future where the indefinite option is removed and the wait time increases.</p>
<p>Yes, users need protection. In 2023, Americans lost over 150 billion dollars to online scams, according to the FTC.</p>
<p>But a 25 dollar fee and ID verification will not stop scammers. If that much money is involved, they will find ways around it. They can buy verified accounts, purchase existing apps, or publish under someone else’s identity.</p>
<p>This is not about protecting users. This is about control. It is about deciding what you can install on your own device and where it can come from.</p>
<p>GrapheneOS recently stated that their system will remain available worldwide without requiring personal identification or accounts. They also said that if their devices cannot be sold in certain regions due to regulations, so be it.</p>
<p>This relates to upcoming rules like operating system age restrictions in places like California.</p>
<p>Some people asked for my thoughts. I do not have much to add. It is terrible.</p>
<p>This will affect what users can install and may also hurt independent developers. If you are building apps for the community, are you going to pay a fee and identify yourself, or stop developing entirely?</p>
<p>That is all for today. The future looks bleak with these changes, but there are still alternatives. You just have to be willing to accept a little discomfort.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>GrapheneOS goes Motorola</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-goes-motorola/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-goes-motorola/</id>
        <published>2026-03-04T14:55:00Z</published>
        <updated>2026-03-04T14:55:00Z</updated>
        <summary type="html">The GrapheneOS foundation has officially announced its partnership with Motorola.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode61s0hbhb">🎥 


<a href="https://youtu.be/26zdGTQRxDY" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://discuss.grapheneos.org/d/32656-motorola-partnership-announcement" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/32656-motorola-partnership-announcement</a> - GrapheneOS forum Motorola partnership announcement</li>
<li>


<a href="https://discuss.grapheneos.org/d/25099-pixel-10-support-for-grapheneos-is-now-available" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/25099-pixel-10-support-for-grapheneos-is-now-available</a> - GrapheneOS forum Pixel 10 support announcement</li>
<li>


<a href="https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/" target="_blank" rel="noopener" class="text-break">https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/</a> - Motorola announcement of GrapheneOS partnership</li>
<li>


<a href="https://grapheneos.social/@GrapheneOS/116159602850585685" target="_blank" rel="noopener" class="text-break">https://grapheneos.social/@GrapheneOS/116159602850585685</a> - GrapheneOS Mastodon partnership announcement</li>
<li>


<a href="https://news.ycombinator.com/item?id=47214645" target="_blank" rel="noopener" class="text-break">https://news.ycombinator.com/item?id=47214645</a> - Hacker News: Motorola announces a partnership with GrapheneOS</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">📝 Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So it&rsquo;s been a long time coming, but here we are.</p>
<p>The Graphene OS team has officially announced their partnership with Motorola to collaborate on future devices that will officially support Graphene OS.</p>
<p>I recently added self-hosted comments to my blog. So if you want to leave a comment without leaving one on YouTube and having to log in there, that is an option.</p>
<p>So check the description box below for the link to this blog post for this video. This is obviously not the blog post for this video, but that will be linked down below. So if you want to leave comments there, it is an option.</p>
<p>I don&rsquo;t speak for the Graphene OS project. I&rsquo;m going to be simply sharing some things that I&rsquo;ve read and some thoughts that I have in the announcement. So take it with a grain of salt. And as with anything online, do your own research.</p>
<p>I think a big motivating factor behind partnering with an OEM, I think it was always in the cards. They announced it years ago. But one of the things that I think pushed it forward was QPR one with Android 16.</p>
<p>What originally happened was the source code was published to the Android open source project for Android 16 QPR1, but the issue was the device-specific code for the Google Pixels was not published. So what this led to happening is the Pixel 10 was released, the device-specific code was not released.</p>
<p>So the Graphene OS team was forced to work from an older release that was available, and they were not able to release it for production usage. They still needed Android 16 QPR1 to be pushed to AOSP before they could do that properly. Unfortunately, that was delayed for quite a bit of time. There wasn&rsquo;t really a great reason given by Google for why that happened. There were some theories behind it.</p>
<p>Long story short, I think that was a big motivating factor behind it, at least accelerating that timeline. So instead of being supported days after the phone came out when the code is normally published, it took much longer, which caused that delay for the Pixel 10. At this time, it is now supported, so that&rsquo;s great.</p>
<p>Going back to the official announcement, if you want to read it, Graphene OS did do a post on their forum about it, where they linked to the Motorola news article.</p>
<p>Which that leads me into one of my theories or thoughts on this, which I guess is kind of announced here, or maybe not, they&rsquo;re talking about these other two features. But essentially, Motorola&rsquo;s B2B or business-to-business ecosystem.</p>
<p>It&rsquo;s possible that bringing Graphene OS to a Motorola device could give Motorola access to offering a private and secure mobile operating system to businesses and corporations. That gives them some new business options, especially when competing with Apple.</p>
<p>I think getting Graphene OS in the hands of corporations would be fantastic, rolling it out. I never had the option of an Android device at any company I worked at, or any tech company I worked at. So if Graphene OS ended up being an option for that, I would love to see that.</p>
<p>I also wanted to go through a few of the comments on the Hacker News article which this actually made it to the front page the first spot actually yesterday which is pretty cool to see. On Hacker News strcat is Daniel McKay so I kind of wanted to go through some of the comments he left on there.</p>
<p>I think it provides some interesting insight. Might as well go directly to the source when you&rsquo;re getting information so this is one way that I do it.</p>
<p>As far as when this device will be released we can see here it&rsquo;s going to be a subset of Motorola&rsquo;s future devices in 2027 and later which are going to support Graphene OS since the current ones in 2026 didn&rsquo;t quite meet all their security requirements yet so we will be waiting till 2027 for this device.</p>
<p>In another post it&rsquo;s also mentioned aside from that we&rsquo;ll have a lot more access to the code for firmware etc and the ability to do hardening below the OS layer through the partnership with Motorola and their partnership with Qualcomm. That&rsquo;s something they did not have access to before.</p>
<p>As far as support goes for devices our official requirement is five years of support meeting our standards but it will be raised to seven at some point. Motorola&rsquo;s signature 2026 already has seven years of support but it&rsquo;s future devices which are going to meet all the requirements.</p>
<p>So if you&rsquo;re curious how long these devices will be supported for it looks like it&rsquo;ll be standard five years but hopefully raised to seven at some point so that&rsquo;s great if you&rsquo;re like me and like to keep your device as long as possible.</p>
<p>If you end up reading through the forum at all or their post on mastodon there is some people talking about the chinese-owned company Lenovo who owns Motorola. I don&rsquo;t really care to get into that discussion much. My opinion I&rsquo;ll be buying this phone when it comes out kind of sums up what I think.</p>
<p>I think this is another one that&rsquo;s important to note. I hope they make this partnership work probably a 50 50 partnership. Graphene OS is a nonprofit, and it&rsquo;s not that kind of business partnership.</p>
<p>We are getting a device with official GrapheneOS support out of it, and they&rsquo;re getting an increased device sales from having more secure devices with better updates and official GrapheneOS support.</p>
<p>It&rsquo;s not an exclusive partnership, but we aren&rsquo;t currently working with any other OEM and don&rsquo;t have the resources to handle multiple for quite a while anyway.</p>
<p>So this isn&rsquo;t your standard partnership you might see out there. It&rsquo;s not some exclusive partnership. They can&rsquo;t work with anyone else. It is not that. So I think that&rsquo;s important to mention.</p>
<p>And again, going back to what I originally mentioned about the Pixel releases that were delayed. With this, GrapheneOS won&rsquo;t have to use their stock OS, talking about Motorola, to get firmware and etc. as we do with the Pixels.</p>
<p>So that&rsquo;s a huge improvement, not dependent on Google for releasing that device-specific code.</p>
<p>And that leads me to one other thing I want to mention. I&rsquo;ve seen a lot of people post on the forum about a wish list with hardware kill switches and removable battery, and whatever else.</p>
<p>Currently this device is not being designed, and again I don&rsquo;t speak for the Graphene OS team just from what I&rsquo;ve read, currently this device is not being designed by them from the ground up.</p>
<p>They are working with Motorola to meet their security requirements. That does not mean they&rsquo;re making feature requests to build the whatever other people might see as a optimal device.</p>
<p>This is going to be a Motorola flagship device designed with the Graphene OS Foundation&rsquo;s input so that the device meets their security requirements for running Graphene OS.</p>
<p>So to sum it up, this is great news in the privacy and security space where in general, just not the privacy security space, good news is limited these days. So this is exciting, it&rsquo;s a great development, and good progress.</p>
<p>So just to give my input on a question that might come up, should you upgrade or should you wait till next year?</p>
<p>If you&rsquo;re in my situation where the Pixel 6a will be done? Okay? Now, okay. Now, going end-of-life next July.</p>
<p>I don&rsquo;t know if the Graphene OS-supported Motorola device will be out by then.</p>
<p>In addition, the Pixel 8 and newer supports memory tagging, which is a fantastic security feature that I really want, and I&rsquo;m considering upgrading to a Pixel 8 or newer just because of that.</p>
<p>So if you&rsquo;re on a 6a, or 7 for that matter, I could make the case for upgrading to a Pixel 8 or newer.</p>
<p>If you&rsquo;re on a Pixel 8 or newer, just wait it out. It&rsquo;ll be next year before you know it. See what the Motorola offering is, and then decide then if you want to upgrade.</p>
<p>So that&rsquo;s all I got on this. Again, congratulations to the Graphene OS Foundation.</p>
<p>This is an amazing accomplishment, and I&rsquo;m excited to see where this goes.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>Qubes OS First Boot – Wi-Fi, Updates, TOR, &amp; Videos</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/qubes-os-first-boot/" />
        <id>https://staging.sideofburritos.com/blog/qubes-os-first-boot/</id>
        <published>2026-01-27T14:55:00Z</published>
        <updated>2026-01-27T14:55:00Z</updated>
        <summary type="html">A first-time, unprepared boot of Qubes OS to see what it’s really like to use.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode111s0hbhb">🎥 


<a href="https://youtu.be/qarVS4fkXOU" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.qubes-os.org/" target="_blank" rel="noopener" class="text-break">https://www.qubes-os.org/</a> - Qubes OS</li>
<li>


<a href="https://isso-comments.de/" target="_blank" rel="noopener" class="text-break">https://isso-comments.de/</a> - Isso</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">📝 Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So, here we are back again to dive into Qubes OS. In my first video, I did say that I wouldn&rsquo;t be using Qubes OS without recording it. So, a couple things to clarify on that.</p>
<p>I did record the installation. I installed the—I think it was—4.3 release candidate, thanks to someone&rsquo;s suggestion in the comments last video. And speaking of that, if you have any suggestions on Qubes OS, I&rsquo;m brand new to it, so feel free to drop those down below.</p>
<p>Josh, the video editor here. There&rsquo;s a couple things I wanted to mention about this video. The times in it are not perfectly accurate. If you hear me making comparisons that something opened slower or faster than something else, don&rsquo;t trust the time you see on the screen. This video already isn&rsquo;t the most exciting thing to watch, let alone if I left a bunch of silence in there as an application is loading.</p>
<p>Second is that I added comments to my blog, or at least on this video and new ones going forward. I&rsquo;m using a self-hosted instance of Isso—I think that&rsquo;s how you say it. I realize that most people watching my videos are into privacy and security and likely do not want to log into YouTube using a Google account to leave a comment. I don&rsquo;t blame you.</p>
<p>I also didn&rsquo;t want to post my videos in a duplicate place on another platform and have comments there. So, this is what I came up with. If you go to the description box for this video, you&rsquo;ll see a blog post on my website related to this. This is not that blog post. Ignore the title. But if you go there, scroll down to the bottom, you will then see a comment box where you can now leave comments. Name, email, and website—they&rsquo;re optional, so you can leave anonymous comments if you&rsquo;d like.</p>
<p>We&rsquo;ll see how that goes. This is something I&rsquo;m just testing. So, if you go to the blog post and you no longer see comments are available, then likely the experiment went poorly.</p>
<p>So, with that out of the way, I&rsquo;m going to get back to editing this video, which is my least favorite part of this process. But, I did record the installation. I recorded it by pointing a camera at the laptop screen and walking through the setup process. As I was watching it back, it looked terrible. It was also pretty boring. If that video came across my feed, I would not watch it.</p>
<p>Therefore, I&rsquo;m not going to subject you to that. So, the installation process—you won&rsquo;t be seeing that.</p>
<p>That being said, the documentation is very, very good. The only reason you will mess up the installation is if you don&rsquo;t read the instructions. At least that&rsquo;s what happened in my case. Once I did read through all the details, made the necessary changes in the BIOS, the setup was simple. Took around 40 minutes on the—what is this—the T480 ThinkPad. So, pretty simple.</p>
<p>Regarding that initial installation, I did actually wipe it from this laptop. I had to put Windows back on here for a video I released earlier this week. So, I did just install Qubes OS again yesterday. I did install version 4.3.0 because it&rsquo;s out of the release candidate phase.</p>
<p>Regarding the options that show up in the initial setup, I left them set to the default, but the only one I did change was this: enable system and template updates over the Tor anonymity network using Whonix. Besides that, left everything set to the default.</p>
<p>This is what shows up after the first boot after installation. This took around an hour to complete. And then after that, we are now at the screen you see now.</p>
<p>So, regarding screen recording, I actually found out you can purchase HDMI input dongles. So, I have that connected to my MacBook. The output HDMI on the ThinkPad is connected to that. So, you get a nice screen recording where you&rsquo;ll see me using Qubes OS without having to point a camera at the screen, which looks terrible.</p>
<p>And the last thing I want to mention about using Qubes is I did have to use it because I made some poor networking changes at my house. Long story short, I use VLANs. I made some configuration changes that essentially locked me out of all my equipment over the Wi-Fi network I have. So, I needed a computer that had an Ethernet port.</p>
<p>Funny enough, the only computer that had an Ethernet port was my ThinkPad. So, I did have to log into Qubes, connect an Ethernet cable, and then open the browser, connect to some web interfaces to fix my changes. But besides that, haven&rsquo;t used it anymore. But I did want to mention both of those scenarios.</p>
<p>So, with that out of the way, let&rsquo;s continue.</p>
<p>I didn&rsquo;t really know how to structure these videos. So what I came up with was putting together a few goals I want to accomplish in this video. Once we accomplish those, we&rsquo;ll see what else we find. If that&rsquo;s all we accomplish today, that&rsquo;ll be the end of the video. And the next video, I&rsquo;ll come up with some more goals.</p>
<p>Essentially, I&rsquo;m trying to migrate all my use cases from macOS to Qubes OS. So that&rsquo;s what these are based on.</p>
<p>So, one other thing I wanted to mention before we get into it is that I&rsquo;ve seen people call Qubes OS a Linux distribution. It is not a Linux distribution. Qubes OS is built on the Xen hypervisor, which then runs Linux templates or virtual machines on top of that. So, you could call it a Xen distribution, but it is incorrect to call it a Linux distribution.</p>
<p>I understand I&rsquo;m getting pedantic with that, but if you make comments online or things like that, people will dismiss what you say because you say one thing incorrectly. So, just thought it&rsquo;s worth mentioning if you&rsquo;re out there talking about Qubes. It is a Xen distribution, not a Linux distribution.</p>
<p>So, with that out of the way, let&rsquo;s get into it and continue.</p>
<p>So, one cool thing I noticed on the login screen we have here: the top left default, or the first option, is hide password bullets. Second, which is the default, show password as bullets. And the third, show password as text.</p>
<p>So let me just type something in the password box. If you&rsquo;re out in public, you can hide the password field. It&rsquo;s kind of cool. The second function, F2, again shows the password as bullets. Function F8 shows the text in the box. For someone recording a video, this is handy. I can hide that. Don&rsquo;t need to edit that in post and hide it.</p>
<p>So, let me type in my password. Hopefully I typed it right.</p>
<p>So, here we are at the user login screen. That previous screen was the disk decryption password.</p>
<p>So, let&rsquo;s see. On the top left, we have dom0. Oh, I remember reading about that when I was researching this. Let me just look up an explanation quick.</p>
<p>So, dom0, or domain zero, is the first domain started by the Xen hypervisor on boot. It has special privileges like being able to cause new domains to start and being able to access the hardware directly.</p>
<p>So, in the future, I&rsquo;ll talk about that more. It might even warrant its own video, because from what I understand, it&rsquo;s a pretty important concept to understand when it comes to Qubes OS. But for now, let&rsquo;s log in.</p>
<p>Be nice if this screen had the same hide password characters. Don&rsquo;t believe it does.</p>
<p>Top right we have—okay, I realized I&rsquo;m trying to click with the screen recording mouse. Okay, so I&rsquo;ll fix this after I log in because right now it&rsquo;s extending the display, which is a little complicated, but okay.</p>
<p>We have the power options, language. It&rsquo;s using XFCE accessibility options. dom0. Can&rsquo;t click on that. But there&rsquo;s my password. It&rsquo;s the only user that I created during the initial setup. Log in.</p>
<p>So, like I said, this is extending the current display. So, let me fix it. So, it&rsquo;s recording the desktop. Since you can&rsquo;t see what&rsquo;s going on right now, I&rsquo;m just looking for the display settings. I will show you after what I did.</p>
<p>Change this to mirror. Apply.</p>
<p>Looks good.</p>
<p>So, I came in. There&rsquo;s the Qubes menu in the top left.</p>
<p>I just searched for display. As you can see here, recent applications. Came in here, set this to mirror displays, and here we are.</p>
<p>So, here&rsquo;s the desktop.</p>
<p>So, on our list, we had the first is to connect to Wi-Fi, because these days you can&rsquo;t do anything without internet access.</p>
<p>Network connection, available networks. Let me find my network. And these will all be blurred out so you can&rsquo;t see them.</p>
<p>So, I think this is part of the domains, or maybe what they&rsquo;re called. Hopefully I&rsquo;m not using too many words incorrectly in this first video. I&rsquo;ll try to make sure of them in the next video.</p>
<p>But this is red. It&rsquo;s sys-net. So I believe that&rsquo;s a specific virtual machine just for networking. Again, don&rsquo;t take my word on all these explanations.</p>
<p>But this window is red and belongs to sys-net. So it&rsquo;s just something we&rsquo;ll keep an eye on.</p>
<p>And get my Wi-Fi password. Let&rsquo;s see if that&rsquo;s right. Connect.</p>
<p>See it connecting in the top right. I&rsquo;m guessing I typed it wrong because it&rsquo;s taking so long. Disconnected.</p>
<p>Let&rsquo;s try this again.</p>
<p>Actually, looks like it&rsquo;s connected. So, I don&rsquo;t know why it&rsquo;s showing that spinning—whether or not that&rsquo;s connected.</p>
<p>Let&rsquo;s open a terminal and do some network tests quick.</p>
<p>Okay, sys-net disconnected. Well, it&rsquo;s open terminal anyways, just to check terminal.</p>
<p>So, the search is definitely handy.</p>
<p>I guess over here, these are our different—so we have our work qube. This one&rsquo;s untrusted, vault, personal. I&rsquo;m assuming all these come by default. Not assuming—they come by default because I didn&rsquo;t configure them.</p>
<p>So, where do we want to open one? Let&rsquo;s just pick personal.</p>
<p>So, qube personal is starting.</p>
<p>I guess this little menu here is for qubes. So here we have some status on the qubes.</p>
<p>dom0 using 4 gigs of RAM. Personal that&rsquo;s running is using 3 gigs. sys-firewall, 2.5 gigs. sys-whonix, 3 gigs by itself.</p>
<p>So, I guess that&rsquo;s why they say Qubes OS requires quite a bit of RAM, since every qube is going to use more memory.</p>
<p>I think this laptop came with 16 gigs of RAM. It supports up to 64 unofficially. Unfortunately, with the prices of RAM right now, because of the massive corporations ruining it for the everyday person, I probably won&rsquo;t be buying any RAM anytime soon for this. So, 16 gigs is what it is.</p>
<p>So now that terminal&rsquo;s open in our personal qube, you can see here: personal, yellow. So that matches what was in the menu here. So anything yellow is going to be personal.</p>
<p>So let&rsquo;s just see if we&rsquo;re connected quick.</p>
<p>Unreachable.</p>
<p>Okay, so we are not connected, which I guess is kind of confirmed by the red network icon.</p>
<p>Let me try and type in my password again.</p>
<p>So, I&rsquo;m pretty sure the password I typed is wrong, but I don&rsquo;t see a way to edit it right now.</p>
<p>Let me see if there&rsquo;s any network settings that we can go into. It might look like I&rsquo;m pretty uncoordinated while doing this, but I&rsquo;m looking at the screen recording while trying to move the mouse around. So it&rsquo;s a little off as I&rsquo;m trying to do this.</p>
<p>So, there was no network connections in the Qubes menu, but I right-clicked on the network icon. We can go edit connections. I&rsquo;m assuming it&rsquo;s going to be in here.</p>
<p>There it is.</p>
<p>Okay. If we go in here—Wi-Fi security. Here&rsquo;s the password that I&rsquo;ll be blurring out. So, I did type the password correctly. Don&rsquo;t understand why it&rsquo;s not working.</p>
<p>IPv4 DHCP. That should just work.</p>
<p>Oh, I know why. Because I picked the wrong Wi-Fi network.</p>
<p>What do you know? If you pick the wrong Wi-Fi network and you type in the wrong password, things will not work. Surprise, surprise.</p>
<p>Okay, with that out of the way, I guess we learned how to edit network connections. So, at least we learned something.</p>
<p>So, we are connected.</p>
<p>I will say that is kind of inconvenient that it doesn&rsquo;t give you another chance to edit the password or show a box and say “could not authenticate.” I don&rsquo;t know if that&rsquo;s a feature or not, but it&rsquo;s kind of inconvenient, and you have to go and actually edit the connection instead of just retyping the password.</p>
<p>So it does say we are connected.</p>
<p>Okay, ping works.</p>
<p>That works too. So network connection and DNS resolution is working.</p>
<p>I don&rsquo;t know if you saw that, but there was a notification that said there was an update available for Fedora.</p>
<p>So, looking back to our notes of what we&rsquo;re trying to accomplish, next step is to check for updates.</p>
<p>So, whatever update was checking, obviously something&rsquo;s available.</p>
<p>I thought I hovered over this and saw what the battery stat was. So, fully charged.</p>
<p>Okay, let me see what else is up here quick while we&rsquo;re here.</p>
<p>So, click on the username. We have user options. Right next to that, we have some disk stats. This one is updates—Qubes updates.</p>
<p>Updates are available.</p>
<p>So, updates are our next goal.</p>
<p>Updates for one qube. Launch updater.</p>
<p>So, I&rsquo;ll just let you read that section. I started reading it to you, but you can read it if you want to.</p>
<p>Here it is.</p>
<p>So, it looks like Debian 13, maybe Fedora, I guess, since it&rsquo;s running because that&rsquo;s what this qube is.</p>
<p>It can tell there&rsquo;s an update available since it did check today.</p>
<p>So, yes, it knows the Whonix gateway.</p>
<p>Maybe.</p>
<p>So, yeah, Qubes OS checks for updates for running and networked qubes and their templates. So since this is running, it confirmed yes, an update is available.</p>
<p>Let&rsquo;s check what&rsquo;s behind the settings.</p>
<p>Attempt update qubes after 7 days without checking for updates. Qubes that are based on—restart all service qubes after update by default. Restart other qubes.</p>
<p>Okay, I&rsquo;m just going to leave it the default.</p>
<p>Let&rsquo;s update the qubes.</p>
<p>So personal still running as we expect. Select a qube to see details.</p>
<p>Nothing really going on yet.</p>
<p>If you recall back to the first screen that I showed, I did check enable system and template updates over the Tor anonymity network using Whonix. So these updates might be pretty slow since they&rsquo;re going to be going over Tor.</p>
<p>Looks like the first one being done is the Whonix gateway, where that Tor connection&rsquo;s running. So that&rsquo;ll probably take a few.</p>
<p>So, while that&rsquo;s going, not going to make you watch this, but I&rsquo;m going to check that as completed.</p>
<p>The check for updates—connect to Wi-Fi, done.</p>
<p>Next is open browser.</p>
<p>So, like I said, I&rsquo;m trying to replace the functionality of macOS. I use the browser all the time. Therefore, I want to use the browser on Qubes OS and see how that is on here.</p>
<p>One thing to note: this laptop is really chugging away right now. The fan&rsquo;s heating up. It&rsquo;s getting pretty warm. So, it seems like this is pretty intensive for it.</p>
<p>So, let&rsquo;s go into the applications.</p>
<p>And I guess while we&rsquo;re here, we can look through what applications are available.</p>
<p>So, we have apps.</p>
<p>Okay. So, here&rsquo;s all the qubes or templates, and here are the apps inside each one.</p>
<p>Anon-Whonix—makes sense. Tor Browser is there. Tor Browser Downloader, system check.</p>
<p>Default DVM—I don&rsquo;t know what that is.</p>
<p>Personal—we have Firefox, settings, file manager, and terminal.</p>
<p>Untrusted—same.</p>
<p>Vault—same.</p>
<p>Workstation 18—I don&rsquo;t know what that is.</p>
<p>Work—same.</p>
<p>So it seems the default are these four apps for most of these.</p>
<p>Let&rsquo;s see what the settings is.</p>
<p>I&rsquo;m just going to keep it in personal since that&rsquo;s where we already are.</p>
<p>So the qube is currently—I’m assuming since it&rsquo;s already running that if I launch Firefox, it should be quick because the qube&rsquo;s already started. It doesn&rsquo;t have to start it up.</p>
<p>I&rsquo;m saying quick relative here. I&rsquo;m not expecting lightning, just quicker than if it&rsquo;s not running.</p>
<p>Initial Firefox setup. We&rsquo;re going to skip all this for now. We&rsquo;ll just start browsing.</p>
<p>Okay. So, browsing works. It&rsquo;s a default Firefox installation.</p>
<p>So, as we can see here, we have a yellow box on this one. So, all personal qubes or all personal apps inside that qube will have the yellow outline.</p>
<p>And then therefore, every other qube or template—I’ll look up the terminology so I can say it correctly next video.</p>
<p>So, if we go to—let&rsquo;s just say work—we&rsquo;re going to open up a work terminal.</p>
<p>So now that qube is starting. It should take longer, because that qube needs to start.</p>
<p>Here&rsquo;s our other terminal.</p>
<p>Like we saw, personal was yellow, work is blue.</p>
<p>I do like how clear it is which profile, which qube you&rsquo;re in.</p>
<p>I think they&rsquo;re called qubes, based on the notifications.</p>
<p>So, it is nice how the color coding is for different qubes. Work is blue, personal is yellow. Matches up with the windows we see.</p>
<p>So, that&rsquo;s still updating. I&rsquo;m going to minimize that because it&rsquo;s kind of distracting.</p>
<p>So, we have—okay—personal Firefox.</p>
<p>If we search for Firefox here, so we get any qube that has Firefox in it, which is pretty much all of them at the top.</p>
<p>Any qube.</p>
<p>So, we can launch Firefox for any one of these qubes.</p>
<p>Like I said, the work one is started, so this should launch relatively quickly, and the internet should just work.</p>
<p>There&rsquo;s no history in here.</p>
<p>So, these are separate qubes. So, even though I typed cyberios.com, which is now in the history here, it does not exist in the work one because that is a separate qube, separate browser instance.</p>
<p>So, we don&rsquo;t need this one for now. So, we&rsquo;ll close it.</p>
<p>But I think this little icon is this eject or shut down the qube. Doesn&rsquo;t seem like the helper text is popping up, or the tool tip. So, I&rsquo;ll click it.</p>
<p>Okay, that just pushes the window up. This is just XFCE.</p>
<p>That&rsquo;s about it.</p>
<p>This one—what does it do? Just all the options. Move to another workspace.</p>
<p>Okay.</p>
<p>So, if I close this, I don&rsquo;t know if it&rsquo;ll shut down the work qube.</p>
<p>So, if we go here to our running qubes, work is still running.</p>
<p>So, we no longer need work.</p>
<p>So, I guess we can shut it down from here.</p>
<p>Let&rsquo;s see.</p>
<p>Open qube manager.</p>
<p>Let&rsquo;s take a look at this.</p>
<p>So, this is interesting. It looks like a process manager except for qubes.</p>
<p>So, we don&rsquo;t need work anymore. Here it is at the bottom. Emergency pause, shutdown, restart, settings, edit firewall.</p>
<p>Let&rsquo;s just shut it down for now.</p>
<p>Work has shut down. So, no longer running, no longer using resources.</p>
<p>Now, we can finish with Firefox here.</p>
<p>Well, actually, let&rsquo;s try this quick.</p>
<p>So, I have Mullvad running on my router at my home. So, this should be routed over Mullvad.</p>
<p>Yes, as you can see, using Mullvad VPN.</p>
<p>Just to understand how the Whonix qube works, let&rsquo;s open up Tor Browser. I believe that qube is already running since the updates are using it. So, it should start up relatively quickly.</p>
<p>Or maybe not.</p>
<p>Here is Tor Browser Whonix welcome page. We&rsquo;ll give that a minute.</p>
<p>So, let&rsquo;s go to Mullvad in this browser.</p>
<p>I believe this should be over Tor. So we should not be using Mullvad.</p>
<p>Not using Mullvad. Location: the Netherlands.</p>
<p>If you didn&rsquo;t guess, I&rsquo;m not from the Netherlands. So this is correct. It&rsquo;s using Tor.</p>
<p>So, update available for Firefox.</p>
<p>I guess one thing I don&rsquo;t know yet, which I guess we&rsquo;ll see—I don&rsquo;t know if these are similar to Docker containers or if they&rsquo;re ephemeral, essentially.</p>
<p>So, if I update Firefox here, will it actually update in the Whonix qube and be persistent, or will it just get overwritten?</p>
<p>Don&rsquo;t really know, but I guess let&rsquo;s try it quick.</p>
<p>So, updating Firefox there.</p>
<p>If you haven&rsquo;t guessed yet from me walking through this like a bumbling fool, I&rsquo;m not exactly sure how storage works yet on Qubes OS. So, I&rsquo;m not totally confident where data is stored or how that works.</p>
<p>So that&rsquo;s why I&rsquo;m currently experimenting, if anyone&rsquo;s still watching the video at this time.</p>
<p>Whonix Workstation is attempting to shut down.</p>
<p>Is that part of the update?</p>
<p>Oh, so that&rsquo;s part of the update. Whonix Workstation. Okay.</p>
<p>Not related to our Firefox update.</p>
<p>Let me get rid of these or move this over.</p>
<p>So Firefox has been updated.</p>
<p>Let&rsquo;s shut down this qube and see if that update sticks.</p>
<p>sys-whonix—that&rsquo;s using that to update these qubes.</p>
<p>Yeah, whatever.</p>
<p>Okay, we&rsquo;ll shut it down anyways and restart it.</p>
<p>I&rsquo;m assuming these updates will either fail or pause.</p>
<p>Just says Whonix has shut down. It&rsquo;s now starting.</p>
<p>You know, so far, based off my expectations for this—I forget now—8- or 10-year-old laptop, this is actually running pretty well.</p>
<p>I know I&rsquo;m not doing much, right? I&rsquo;m just kind of browsing the web and updating some qubes. But so far, so good. So that&rsquo;s good news.</p>
<p>So I think that qube—we restarted it.</p>
<p>Let&rsquo;s go back in there.</p>
<p>Anon-Whonix Tor Browser.</p>
<p>You know, looking back, I don&rsquo;t know if that was the right qube that we restarted, but whatever.</p>
<p>At this point, looks like it was shut down when we closed it. So now it is restarting.</p>
<p>Okay, so that has started up.</p>
<p>I don&rsquo;t see any updates for Firefox. Let&rsquo;s go check quick.</p>
<p>Was it Help → About?</p>
<p>I think—for Tor Browser, not Firefox.</p>
<p>It&rsquo;s up to date.</p>
<p>So, I guess that update did stick even after restarting that qube.</p>
<p>So, that was Anon-Whonix.</p>
<p>Oh, here it is.</p>
<p>So, yeah, we restarted the wrong one last time. So, let&rsquo;s restart this one.</p>
<p>It is kind of nice that out of the box you get a qube that you can use to browse in. No additional software was needed. Just kind of came that way.</p>
<p>And it&rsquo;s also nice that system updates can use it. So that&rsquo;s really convenient.</p>
<p>Okay.</p>
<p>So let&rsquo;s open browser and check if it has stayed updated.</p>
<p>Help → About Tor Browser.</p>
<p>It is up to date.</p>
<p>So that storage was persistent.</p>
<p>As to where that&rsquo;s stored and how, don&rsquo;t really know, but I guess that&rsquo;ll be something to learn in the future.</p>
<p>Wonder if there&rsquo;s a way to reset this qube or the settings.</p>
<p>Let&rsquo;s see.</p>
<p>Settings.</p>
<p>What do we have here?</p>
<p>Advanced, PCI devices, applications.</p>
<p>So, it looks like in the settings for the qube, there are more applications you can add. I don&rsquo;t know where these come from.</p>
<p>I really need to look up how qubes actually work.</p>
<p>So is each of these a separate repository that someone built into these qubes?</p>
<p>Notes, services, devices, net qube.</p>
<p>Oh, so since this one is Tor Browser, it&rsquo;s using sys-whonix, which makes sense why we&rsquo;re also going over the Tor network. It&rsquo;s also Tor Browser.</p>
<p>So, let&rsquo;s see.</p>
<p>If I take personal, I&rsquo;m assuming that&rsquo;s not using Whonix.</p>
<p>Let&rsquo;s check this out.</p>
<p>Settings.</p>
<p>sys-firewall default current.</p>
<p>Let&rsquo;s change this to sys-whonix.</p>
<p>Now, I&rsquo;m assuming—what&rsquo;s this little thing for? Just because defaults were changed.</p>
<p>The default disposable template.</p>
<p>So, I guess there&rsquo;s something similar to how qubes work in Docker containers. I&rsquo;m not too sure.</p>
<p>These should be a lot of good settings to go through.</p>
<p>But if we now go back here and refresh this, this should say not using Mullvad.</p>
<p>Not using Mullvad. The Netherlands.</p>
<p>So, now it&rsquo;s using the sys-whonix qube for networking.</p>
<p>So, that&rsquo;s pretty cool.</p>
<p>I&rsquo;m assuming then how we set up—or I&rsquo;m assuming that at least—you can create a sys-Mullvad qube and then route any qubes that I want through that net qube, and they&rsquo;ll then use Mullvad.</p>
<p>So there&rsquo;s no really installing Mullvad as an app, I&rsquo;m assuming—again, something I&rsquo;ll look into.</p>
<p>Let me put this back to the default.</p>
<p>So that&rsquo;s kind of cool.</p>
<p>This definitely reminds me of Docker in a way, how this works—where you alter the Docker Compose file and the changes are reflected then in the container.</p>
<p>I think I just need to get used to the different terminology here with this.</p>
<p>So, back to using Mullvad on my router or my VPN on my router.</p>
<p>The browser changes seem to be persistent. So there&rsquo;s some sort of storage I&rsquo;ll need to look into another time.</p>
<p>As far as our list goes, I did want to try and play a video.</p>
<p>So, let&rsquo;s go to youtube.com.</p>
<p>This computer—I don&rsquo;t think it has a GPU inside of it, so I don&rsquo;t know how these videos are going to play.</p>
<p>Let&rsquo;s pick a 4K video.</p>
<p>Now that I think about it, I believe this laptop also has a 1080p screen, so I guess 4K is not that relevant either.</p>
<p>There are some—of course there&rsquo;s an ad.</p>
<p>There are some mods I believe you can do to this where you can replace the 1080p screen with a 4K screen. If this ends up working out, that is absolutely something I&rsquo;ll be doing.</p>
<p>The older I get, the more I learn that resolution matters a lot.</p>
<p>So, skip.</p>
<p>Let&rsquo;s see how the 4K looks or how it plays.</p>
<p>I&rsquo;m assuming on this screen recording it&rsquo;s going to be a bit laggy going over this adapter, but I&rsquo;ll let you know how it is on the actual screen.</p>
<p>Let&rsquo;s go full screen.</p>
<p>Okay, not going full screen. It&rsquo;s also not playing.</p>
<p>No, it is playing.</p>
<p>Okay, maybe 4K was a bit ambitious.</p>
<p>I don&rsquo;t really know if it&rsquo;s my internet right now or this computer that&rsquo;s really struggling.</p>
<p>Looks like this qube is using—what—52%.</p>
<p>Okay, so it is feeling the video playback.</p>
<p>Maybe I shouldn&rsquo;t be doing this while updating the qubes.</p>
<p>Let me go cancel these for now. Let&rsquo;s run them after this video is done.</p>
<p>Or let&rsquo;s just change it down. Scale it down a bit.</p>
<p>HD.</p>
<p>What if we throw it on 240?</p>
<p>Okay. It&rsquo;s like watching a potato.</p>
<p>Still slamming the CPU, but not lagging as much.</p>
<p>Wonder if audio works well.</p>
<p>Audio works.</p>
<p>Okay, so that was the test.</p>
<p>Real time, that took about an hour. I don&rsquo;t know what it&rsquo;s going to come down to in the edit—how long this is going to be or what parts I&rsquo;m going to fast forward through, because I don&rsquo;t want to subject you to them.</p>
<p>So, first thoughts after using it: pretty decent experience, I would say.</p>
<p>The video experience—not great. I didn&rsquo;t really have extremely high expectations for that. There&rsquo;s no GPU from what I can recall inside this laptop, so it&rsquo;s going to struggle with video playback doing everything on the CPU.</p>
<p>As far as updates go, that was easy. I was notified that there were updates available. They ran, went through Tor by default, which was pretty awesome.</p>
<p>I do like the coloring a lot. This was very easy to keep track of which windows were in which qube.</p>
<p>So, like I said, don&rsquo;t trust the terminology that I used in this video. You&rsquo;re going to want to double-check it.</p>
<p>This is more of just a “here&rsquo;s my experience for the first time using Qubes OS accomplishing a couple tasks.”</p>
<p>Haven&rsquo;t done much research into it, which was on purpose. I didn&rsquo;t want to skew my perspective much as far as how it is for beginners.</p>
<p>I don&rsquo;t know if I could give this to my mom and say, “Here you go, mom. Go browse the web. See how it goes.”</p>
<p>I think the menus and everything like that makes sense so far. This is straightforward.</p>
<p>The coloring—once you go into settings—I&rsquo;ll be honest, this got somewhat overwhelming pretty quick. There&rsquo;s a lot of options in here and a lot of things you can change.</p>
<p>When I say overwhelming for me, not in a bad way. For beginners, it definitely could be. For me, it&rsquo;s exciting. This is cool. I&rsquo;m excited to see how this goes.</p>
<p>Also, so far, I haven&rsquo;t really understood how to install more apps. I think that&rsquo;s just something I need to research and do some reading on.</p>
<p>Reading on qubes, tools, backup—there&rsquo;s just a lot to go through in here.</p>
<p>Let&rsquo;s see. Is there a store by chance? I wouldn&rsquo;t expect there to be.</p>
<p>Restore backup down there.</p>
<p>Now, so that&rsquo;ll be interesting. Maybe you just add more qubes for the apps you want, or in the settings. We saw different apps in there.</p>
<p>Long story short, I don&rsquo;t know if this video was useful, but this was my experience so far.</p>
<p>But so far, I really like the security and privacy benefits I&rsquo;m getting just out of the box. It&rsquo;s also nice having something that&rsquo;s not automatically phoning home the second I boot it up.</p>
<p>So, let&rsquo;s see how this goes.</p>
<p>And again, any comments or tips are welcome. And feel free to leave those down below.</p>
<p>And I&rsquo;ll see you next time.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>How to Detect IMSI Catchers (EFF Rayhunter Setup Guide)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/imsi-catcher-detector-how-to-setup-rayhunter/" />
        <id>https://staging.sideofburritos.com/blog/imsi-catcher-detector-how-to-setup-rayhunter/</id>
        <published>2026-01-19T14:55:00Z</published>
        <updated>2026-01-19T14:55:00Z</updated>
        <summary type="html">We may not be able to stop IMSI catchers, but we can detect signs of them using tools like the EFF Rayhunter.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode95s0hbhb">🎥 


<a href="https://youtu.be/UXp77zJkLN4" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://efforg.github.io/rayhunter/installing-from-release.html" target="_blank" rel="noopener" class="text-break">https://efforg.github.io/rayhunter/installing-from-release.html</a> - EFF Rayhunter Installation Guide</li>
<li>


<a href="https://bja.ojp.gov/program/it/privacy-civil-liberties/authorities/statutes/1285" target="_blank" rel="noopener" class="text-break">https://bja.ojp.gov/program/it/privacy-civil-liberties/authorities/statutes/1285</a> - Electronic Communications Privacy Act of 1986 (ECPA)</li>
<li>


<a href="https://www.fpds.gov/ezsearch/fpdsportal?q=TECHOPS&#43;SPECIALTY&#43;VEHICLES%2C&#43;LLC&#43;&#43;AGENCY_NAME%3A%22Immigration&#43;and&#43;Customs&#43;Enforcement%22&#43;PIID%3A%2270CMSD24FR0000115%22&amp;s=FPDS.GOV&amp;templateName=1.5.3&amp;indexName=awardfull&amp;sortBy=SIGNED_DATE&amp;desc=Y" target="_blank" rel="noopener" class="text-break">https://www.fpds.gov/ezsearch/fpdsportal</a> - ICE Cell Site Simulator Public Record</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>


<p><details >
  <summary markdown="span">📝 Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Two weeks ago, Ben Jordan released a video covering a bunch of really cool tech, including the EFF’s Ray Hunter project. I will give a quick summary here, but I also wanted to make a step by step video showing how to install this on Windows, macOS, and Linux, mostly just to show how easy it is.</p>
<p>At the time of recording this, you can build one of these for between $25 and $40. But before we set anything up, let’s talk about why this thing exists.</p>
<p>Every phone has something called an IMSI, an International Mobile Subscriber Identity. It is basically a unique ID tied to your cellular connection. Normally, when your phone connects to a network, that ID gets shared as part of the authentication process. That information is supposed to be gated behind warrants, probable cause, and the Fourth Amendment.</p>
<p>But that is inconvenient if your job involves detaining people who have not actually committed crimes. So instead, the highest funded federal law enforcement agency in the United States, ICE, spends taxpayer money on fake cell towers.</p>
<p>These devices, also known as IMSI catchers, impersonate legitimate cellular networks. Your phone automatically connects because that is how cellular standards work. Once that happens, ICE is not just collecting identifiers and location data from their so called target. They are collecting it from everyone nearby.</p>
<p>To make this kind of surveillance easier, these devices often force phones onto weaker, older protocols like 4G, 3G, or even 2G, where protections are worse or basically non existent. If you ever notice your phone suddenly dropping to an older network in a dense urban area where 5G is normally available, that can be a red flag.</p>
<p>If you or I tried this, we would be committing multiple felonies. When ICE does it, they call it enforcement. And because oversight is optional and accountability is rare, the burden shifts to the public to notice when it is happening.</p>
<p>That is where this device comes in.</p>
<p>Using cheap, discarded cellular hotspots and open source firmware from the EFF, we can turn throwaway hardware into portable IMSI catcher detectors. Before we begin, there is a legal disclaimer, so make sure you read that before continuing.</p>
<p>To be clear about what this device actually does, it is essentially performing a packet capture with a set of rules that look for specific patterns. When one of those patterns is detected, it generates an alert and logs it for later analysis.</p>
<p>I want to be very clear that just because an alert is generated does not mean an IMSI catcher was present. It simply means something unusual happened and it is worth taking a closer look. Likewise, just because you do not get any alerts does not mean everything is perfectly normal.</p>
<p>One more thing to note is that this device needs a SIM card inserted to work, but it does not have to be active. I am using a two dollar Mint Mobile SIM I picked up at Best Buy a couple of years ago. You can also find them at places like CVS or Walgreens. Any SIM card should work.</p>
<p>Because this device uses a SIM, it does transmit an IMSI of its own, so it is not completely invisible. That IMSI could be logged by a carrier or by an IMSI catcher if you happen to encounter one. That said, this SIM is not meaningfully tied to you. There is no active plan, no billing information, and no name attached to it.</p>
<p>Realistically, if you are carrying this device around, your phone is probably nearby or sitting right next to you, and that is by far the bigger privacy risk.</p>
<p>For this video, I will be using the Verizon Orbit RC400L. If you do not live in the United States, there are other supported devices that work in other countries.</p>
<p>If you are not here for the installation, you can skip to the last part of the video to see a demonstration of the interface. If you are here for the installation, the first few steps are the same regardless of which operating system you are using, so we will start there.</p>
<p>Device Setup</p>
<p>Here is my device. The first step is to insert the SIM card. One of the corners has a notch cut out. You can usually slip a fingernail in there, but if it is your first time removing the cover, it can be a little difficult. You may want to use something plastic, like a butter knife, to pry it off.</p>
<p>Once you get it started, just pull and the cover will come off.</p>
<p>On the back, you will see the battery. I miss the days of removable batteries. Pry it up and take it out. I am blocking part of this so you cannot see the details of my device.</p>
<p>The SIM card goes in the bottom right. There is a small diagram showing open, slide to the right, and lock, slide to the left. Slide the little tray to the right until you hear a click. Lift up the silver tray, place the SIM card inside, following the diagram. The cut corner should be in the bottom left.</p>
<p>It does not really lock in place. It just sits there. Once it is positioned correctly, close the tray, press it down, and slide it to the left until it clicks.</p>
<p>Now replace the battery. Match the three contact points on the battery with the three metal contacts in the bottom right of the device and slide it in.</p>
<p>For the back cover, there is a plastic tab that lines up with a notch in the bottom left corner. If the cover is not oriented correctly, it will not go on, so make sure that lines up. Then snap it back into place all the way around.</p>
<p>We can now power on the device. Hold the power button until you see the welcome screen. If you do not see it, the battery is probably dead and you will need to charge it.</p>
<p>Installation Overview</p>
<p>For the next step, go to the Ray Hunter installation page. Open your browser and search for “EFF Ray Hunter GitHub.” It should be the first result. Make sure the URL is github.com/efforg/rayhunter.</p>
<p>Scroll down and click on “Installation Guide,” then select “Install from a release (recommended).” From here, the process becomes operating system specific. Use the timestamps in the video to jump to your OS, then come back to the final section afterward.</p>
<p>After Installation</p>
<p>Once installation is complete, you will notice a thin green line at the top of the device’s screen. That means Ray Hunter is running and nothing has been detected.</p>
<p>To access the web interface, connect your computer to the Wi Fi network broadcast by the device. Then open your browser and go to the IP address shown during installation, typically 192.168.1.180.</p>
<p>You should now see the Ray Hunter web interface.</p>
<p>Final Notes</p>
<p>Updating Ray Hunter is the same process as installation. Download the new version and run the installer again.</p>
<p>The interface is simple. You can see details about the current recording, view historical recordings, and review any alerts. There is also a test heuristic option you can enable to verify that detection is working. This mode is noisy, so remember to disable it afterward and reboot the device.</p>
<p>If you receive a legitimate alert, the FAQ in the installation guide explains where and how to submit that data if you want to help with further analysis.</p>
<p>If I get any alerts myself, I will make a follow up video analyzing the packet capture. While this device does not fix the problem, it does give us visibility. And honestly, it is just cool, which is more than enough reason to do something like this.</p>
<p>If you want, I can also:</p>
<p>Convert this into Markdown</p>
<p>Break it into sections with anchors for a blog post</p>
<p>Produce a shortened summary version</p>
<p>Create speaker notes or chapters for YouTube or a podcast</p>
<p>Just tell me.</p>
<p>I don&rsquo;t think you did the entire thing, you cut a bunch out</p>
<p>You’re right. I did cut a bunch out (mostly the OS-specific walkthrough parts and some repeated lines). Below is a full-length, cleaned transcript that keeps essentially everything, just with punctuation, capitalization, and obvious caption errors fixed. No em dashes. I also kept the structure readable for a website with headings.</p>
<p>Full Cleaned Transcript (Web-Ready)</p>
<p>Two weeks ago, Ben Jordan released a video covering a bunch of really cool tech, including the EFF’s Ray Hunter project. I’ll give a quick summary here, but I also wanted to make a step by step video showing how to install this on Windows, macOS, and Linux, mostly just to show how easy it is.</p>
<p>At the time of recording this, you can build one of these for between $25 and $40. But before we set anything up, let’s talk about why this thing exists.</p>
<p>Every phone has something called an IMSI, an International Mobile Subscriber Identity. It’s basically a unique ID tied to your cellular connection. Normally, when your phone connects to a network, that ID gets shared as part of the authentication process. That information is supposed to be gated behind warrants, probable cause, and the Fourth Amendment.</p>
<p>But that’s inconvenient if your job involves detaining people who haven’t actually committed crimes. So instead, the highest funded federal law enforcement agency in the United States, ICE, spends taxpayer money on fake cell towers. These devices, which are also known as IMSI catchers, impersonate legitimate cellular networks, and your phone automatically connects because that’s just how cellular standards work.</p>
<p>Once that happens, ICE isn’t just collecting identifiers and location data from their so called target. They’re collecting it from everyone nearby. And to make this kind of surveillance easier, these devices often force phones onto weaker, older protocols like 4G, 3G, or even 2G, where protections are worse or basically non existent.</p>
<p>So if you ever notice your phone suddenly dropping to an older network in a dense urban area where 5G is normally available, that can be a red flag.</p>
<p>If you or I tried this, we’d be committing multiple felonies. But when ICE does it, they call it enforcement. And because oversight is optional and accountability is rare, the burden ends up shifting to the public to notice when it’s happening.</p>
<p>And that’s where this device comes in.</p>
<p>Using cheap, discarded cellular hotspots and open source firmware from the EFF, we can turn throwaway hardware into portable IMSI catcher detectors. But before we begin, there is a legal disclaimer, so give that a read before you continue.</p>
<p>To be clear about what this actually is, this device is essentially doing a packet capture with a set of rules that look for specific patterns. Once one of those patterns is detected, it generates an alert and gets logged for later analysis.</p>
<p>I do want to be clear that just because an alert was generated does not mean an IMSI catcher was present. It just means something unusual happened, and it’s worth taking a closer look. And just because you don’t get any alerts does not mean everything is perfectly normal.</p>
<p>One more thing to note is that this device does need a SIM card inserted to work, but it does not have to be active. I’m using a $2 Mint Mobile SIM I picked up at Best Buy a couple years ago. You can also find them at places like CVS or Walgreens, but any SIM card should work.</p>
<p>Because this device uses a SIM, it does transmit an IMSI of its own, so it isn’t completely invisible. That IMSI could be logged by a carrier or by an IMSI catcher if you happen to encounter one.</p>
<p>This SIM isn’t meaningfully tied to you. There’s no active plan, no billing information, no name attached to it. Realistically, if you’re carrying this around, your phone is probably nearby or sitting right next to you. And that is by far the bigger privacy risk.</p>
<p>For this, I’ll be using the Verizon Orbit RC400L. If you don’t live in the United States, there are some other supported devices that will work in other countries.</p>
<p>If you aren’t here for the installation, you can skip to the last part of this video to see a demonstration of the interface. If you are here for the installation, the first couple steps are the same regardless of which OS you’re using. So let’s do that first.</p>
<p>Device Setup: Insert the SIM Card</p>
<p>So here’s my device. The first step is to insert the SIM card. One of the corners will have a notch taken out of it. You can either slip your fingernail in there, or if it’s the first time you’re taking the cover off, it is kind of difficult. So maybe use a butter knife or something else plastic you can pry it off with.</p>
<p>Once you get something in there, you basically just pull and it comes un-snapped.</p>
<p>On the back, we now see the battery. I miss the days of removable batteries. You can pry that up and take it out. I’m going to be blocking this out so you can’t see the details of my device.</p>
<p>Our SIM card goes in the bottom right. You’ll see a little diagram down here. It says open, slide to the right, lock, slide to the left. The little tray in the right hand corner, slide that to the right. You might hear a little click. You can then pick up the little silver part.</p>
<p>Grab your SIM card. Like I said, I’m just using a prepaid Mint Mobile SIM card that is not activated. Follow the little diagram. The cut off corner should be in the bottom left. Set that in the tray. It doesn’t really lock in. It kind of just sits there.</p>
<p>Once you have it in position, take the little silver thing, close it, press it down, and slide to the left. Again, you should hear a little click when it locks into place.</p>
<p>We can now replace our battery. Match up these three contact points with the three metal contact points in the bottom right. Slide in the battery.</p>
<p>For the back cover, you’ll notice this plastic tab on it that matches up to this notch in the bottom left hand corner. Place the cover on. If you don’t do it the right direction, the cover won’t go on. That’s why. Then just snap it back in place all around.</p>
<p>We can now power up our device for the next step. Hold the power button down until you see the welcome screen. If you don’t see that, your battery is likely dead, so go charge it for a few minutes.</p>
<p>Go to the Ray Hunter Installation Page</p>
<p>For the next step, we need to go to the Ray Hunter installation page. Regardless of which operating system you’re on, open your browser and type in: “EFF Ray Hunter GitHub.” It should be the first result.</p>
<p>“GitHub efforg/rayhunter, Rust tool to detect cell site simulators.” Click on that. Now double check the URL of the page you’re on to make sure you’re on the right page. It should be github.com/efforg/rayhunter.</p>
<p>Scroll down and click “Check out the installation guide.” Click “Installation Guide.” Once you’re on this page, we’re going to use “Install from a release (recommended).” Select that.</p>
<p>At this point, the video is going to be a choose your own adventure style. Either check the timestamps below, or go to the timestamps on the screen now, depending on the operating system you want to install from. Once you finish following your OS specific part, skip to the final section of the video and we’ll meet back up to discuss some final details.</p>
<p>macOS Installation</p>
<p>The first step is for TP-Link only. I’m not using TP-Link. I don’t know if you are, but I’m not. So we’ll go on to the second step.</p>
<p>Download the latest RayHunter.zip from the Ray Hunter releases page. Right below that, we’re on macOS. Depending on whether you’re on Intel, which is older MacBooks, or the new ARM-based ones like M1 or M2, you need to look for the correct name in the file.</p>
<p>In my case, I’m on an M processor, so I’ll be looking for “macOS ARM.” If you’re on Intel, look for “macOS Intel.”</p>
<p>Select the Ray Hunter releases page. The current version is 0.9.0. This might be different depending on when you’re watching this video. Scroll down to the Assets section. Click “Show all” assets, whatever number it is.</p>
<p>Here’s the ARM version. Here’s the Intel. Again, I’m on ARM, so I’m going to select this one. Make sure you’re selecting the one ending in .zip. The SHA-256 is just a file hash. You don’t want that. That’s not the actual files we need.</p>
<p>Select the .zip. Once that finishes, hit the back button in your browser.</p>
<p>Step three is to decompress the RayHunter.zip archive. Open Terminal and navigate to the folder. Be sure to replace x.x.x with the correct version number.</p>
<p>If you’ve never opened Terminal on your Mac, the easiest way is to open Finder, go to your Applications folder, scroll down to Utilities, and then toward the bottom you’ll see Terminal. Double click it. You can also use Spotlight. Press Command plus Spacebar, type Terminal, then press Enter.</p>
<p>Now that we have Terminal open, we need to cd, change directory, to our Downloads folder. That’s where Ray Hunter was downloaded.</p>
<p>Type:
cd ~/Downloads</p>
<p>Then type:
ls</p>
<p>You should see RayHunter.zip. You might have more files if you don’t clean out your Downloads folder.</p>
<p>The instructions show:
unzip RayHunter.zip</p>
<p>Type unzip, then start typing RayHunter and hit Tab to autocomplete, then press Enter. You’ll see output.</p>
<p>Type ls again. You should now see the RayHunter folder.</p>
<p>You can type clear to make it easier to read.</p>
<p>Now change directory into the extracted folder:
cd RayHunter</p>
<p>Type ls. If you see installer and other files, you’re in the right place.</p>
<p>Back on the instructions page, the next step is to connect to our device. If your device is already powered on, press the power button to see the output.</p>
<p>Press the Menu button on the top right. It’s a little hard to see on the camera. Cycle through the options. You’ll see 2.4 GHz Wi-Fi and 5 GHz Wi-Fi. I’m going to use 5 GHz Wi-Fi to connect. This is the Wi-Fi that the device is broadcasting for us to connect to.</p>
<p>Once you’re on 5 GHz, press the power button to select it. At the top you can see the name of the wireless network it’s broadcasting. In my case, Verizon RC400L-2. The password is on the bottom. I changed mine just for this video. You’ll likely see a random string of letters and numbers.</p>
<p>On your Mac, click the Wi-Fi icon, look for the network name, select it, and enter the password shown on the device. Once you connect, you’ll see a number one next to the Wi-Fi icon on the device, meaning one device is connected.</p>
<p>You can verify the connection by going back to your browser, opening a new tab, and going to 192.168.1.1 for Orbit. Type that in. It takes a minute to load.</p>
<p>If you’re correctly connected, you’ll see the Verizon Orbit page. We’re not going to log in here, but the default credentials are admin, and the password is your Wi-Fi password. If you want to log in later to check options or change anything, that’s where you can do it.</p>
<p>Now that we confirmed we’re connected, go back to the instructions.</p>
<p>On macOS only, you have to run a command to un-quarantine the installer. Copy that command, go back to Terminal, and paste it in. Right click and paste, then press Enter. There will be no output.</p>
<p>Now run the installer command for Orbit.</p>
<p>I’m only going to copy up to the first single quote because “my password” is just an example. Paste the command into Terminal. If you haven’t changed the admin password on your device, it defaults to the Wi-Fi network password.</p>
<p>Type the password, then close it with a single quote, and press Enter.</p>
<p>You’ll see output showing it sending the file to the device. Once it finishes, you should see: “Installation complete. Rebooting device.”</p>
<p>The device will reboot. The screen will go black. You should see the welcome logo again. Give it a minute to start up.</p>
<p>Once it starts up, you’ll notice a thin green line at the top. That means Ray Hunter is running and nothing is detected. That’s why it’s green.</p>
<p>To view the web interface, connect to the device’s Wi-Fi network again. If you forgot the network name, press the Menu button and cycle through until you get to Wi-Fi information.</p>
<p>Once connected, go to:
192.168.1.180</p>
<p>If you go there in your browser, you’ll see the Ray Hunter web interface.</p>
<p>That’s it for installation on macOS. You can now skip to the final part of the video.</p>
<p>Windows Installation</p>
<p>The first step is for TP-Link only. We’re not using TP-Link.</p>
<p>Second step: download the latest RayHunter.zip from the Ray Hunter releases page for your platform. For Windows, it’s Windows-x86_64.</p>
<p>Click the Ray Hunter releases page link. Current version is 0.9.0. Scroll down to Assets. Click “Show all” assets. Look for Windows x86_64. Make sure you’re downloading the one that ends in .zip. The SHA-256 file is not what we need.</p>
<p>Select the .zip file. Once it finishes, hit the back arrow.</p>
<p>Next, decompress the RayHunter.zip archive. On Windows, you can decompress using File Explorer.</p>
<p>Go to Downloads. You should see the RayHunter zipped file. Right click, choose “Extract All,” then click Extract. Once that finishes, it will open the extracted folder.</p>
<p>Select the folder. Hold Shift, then right click inside the folder. Choose “Open PowerShell window here.”</p>
<p>Now the next step is to connect to your device. If your device is powered on, tap the power button. Press the Menu button on the top right to cycle through options. Choose 5 GHz or 2.4 GHz Wi-Fi.</p>
<p>Press the power button to see details. It shows the Wi-Fi network name, for example Verizon RC400L-2, and the password. I set mine manually for this video. Yours is likely a random string.</p>
<p>On your computer, connect to that Wi-Fi network. Select it and connect. You’ll be prompted for the password. If you have connected before, it may be saved.</p>
<p>You might see a page pop up asking to activate the SIM. This is because the Mint SIM inside the device wants activation. We won’t be doing that.</p>
<p>Once connected, you can verify by visiting 192.168.1.1 in your browser. You should see the Verizon Orbit login page. We’re not going to log in, but the default credentials are admin and the Wi-Fi password shown on the device. This confirms you’re connected.</p>
<p>Close that tab.</p>
<p>Back to the instructions, the next step is to run the installer. Copy the command up to the first single quote. Paste it into PowerShell. Right click will paste.</p>
<p>Then type the password. By default, it’s the Wi-Fi password shown on the device. Close it with a single quote. Press Enter.</p>
<p>I got a weird error for some reason. I ran it again and everything worked.</p>
<p>You should see output like: sending file, device is rebooting. The device will reboot and show the welcome screen again. Give it a minute.</p>
<p>If everything worked, you’ll see a green line on the top of the device screen. That means Ray Hunter is running and nothing was detected.</p>
<p>Back on your computer, connect again to the Wi-Fi network broadcast by the device. Once connected, open a new tab and go to:
192.168.1.180</p>
<p>If everything was successful, you should see the Ray Hunter interface.</p>
<p>That’s it for installation on Windows. You can now skip to the final part of the video.</p>
<p>Linux Installation</p>
<p>For context, I’m performing this installation from a live boot of Ubuntu running off a USB stick.</p>
<p>The first step is for TP-Link only. I’m using the Verizon Orbit, so this is not applicable.</p>
<p>Second step: download the latest RayHunter.zip from the Ray Hunter releases page. On Linux, if you’re using x86_64, look for Linux-x86_64. If you’re on ARM, look for Linux-aarch64.</p>
<p>Select the Ray Hunter releases page. Current version is 0.9.0. It might be different depending on when you’re watching this. Scroll down to Assets. Click “Show all” assets.</p>
<p>In my case, I’m on x86_64, so I want Linux-x86_64. Make sure you select the one ending in .zip. The SHA-256 is the file hash. We want the .zip.</p>
<p>Download it, then hit the back button.</p>
<p>Next, decompress the RayHunter.zip archive. Open Terminal. How you open Terminal varies depending on your Linux setup. Usually you can search for Terminal and press Enter.</p>
<p>Change directory to Downloads:
cd ~/Downloads</p>
<p>Type ls. Then unzip the file:
unzip RayHunter.zip</p>
<p>Start typing RayHunter and hit Tab to autocomplete, then press Enter. Once it finishes, run ls. You’ll see the extracted folder.</p>
<p>Change directory into that folder:
cd RayHunter</p>
<p>Type ls. If you see the installer in there, you’re in the right spot.</p>
<p>Next step is to connect to your device. Press the power button to turn on the screen if it’s off. Press the Menu button on the top right and cycle through the options.</p>
<p>I’m going to use 5 GHz Wi-Fi. Once you’re on that screen, press the power button. You’ll see the Wi-Fi name, for example Verizon RC400L-2, and the Wi-Fi password. I changed mine for this video. Yours will likely be random numbers and letters.</p>
<p>Connect your computer to the Wi-Fi network the device is broadcasting. Select it and type the password shown on the device.</p>
<p>You may get a prompt to sign into the network because the SIM is unactivated, but we don’t care.</p>
<p>You can confirm you’re on the right network by visiting:
192.168.1.1</p>
<p>If you’re in the right place, you’ll see the Verizon Orbit login page. We’re not logging in, but the default credentials are admin and the default Wi-Fi password shown on your device. You can log in later if you want to check options.</p>
<p>Close that tab and proceed.</p>
<p>Now run the installer. Copy the command up to the first single quote, because “my password” is just filler text. Paste it into Terminal. Then type the admin password, which by default is the Wi-Fi password shown on the device. Close with a single quote and press Enter.</p>
<p>You’ll see output: sending file, logged in, installation complete, rebooting device. The device will reboot.</p>
<p>You’ll see the welcome screen. Give it a minute to start up.</p>
<p>Back in Terminal, it will show the web interface address:
192.168.1.180</p>
<p>You can click it if it’s a link in your Terminal, or copy and paste it into your browser.</p>
<p>Once your device starts up, you’ll notice a green line at the top. That means Ray Hunter is running and has not detected anything.</p>
<p>Connect back to the hotspot Wi-Fi network. If you don’t see it right away, give the device more time. It can take a couple minutes for the Wi-Fi network to show up. Once connected, visit that IP address in your browser.</p>
<p>If everything worked, you should see the Ray Hunter web interface.</p>
<p>At this point, installation is complete on Linux. You can now skip to the final part of the video.</p>
<p>Final Section: Interface and Next Steps</p>
<p>So that was the installation process. Hopefully you were able to complete that successfully.</p>
<p>Updating is the same process as installation. Download the new version, run the installer command, and you’ll have the new version.</p>
<p>The interface is pretty simple. You get details on the current recording. There’s also a History section that shows past recordings and any that triggered alerts.</p>
<p>There’s also a way to test the heuristic detection if you have any doubt that it’s working. You can open the configuration, enable “test heuristic,” which is noisy, then select Apply and Restart. Give it a minute, then refresh your browser.</p>
<p>One note on that test configuration. You might need to reboot the device. Hold down the power button, turn it back on, and then you should start seeing the test warnings.</p>
<p>You can expand the entries and see the test analyzer output. Just remember afterward to disable that test mode, and to be safe, reboot the device again.</p>
<p>If you do receive a legitimate alert, their FAQ page in the installation guide has details on what and where to send that data if you want to help them out. They can look into it further.</p>
<p>If I get any alerts, I’ll make a video analyzing the PCAP. I’m not too familiar with this exact type of traffic, but I did spend years analyzing packets. Either way, it should be interesting to look at.</p>
<p>While this isn’t necessarily fixing any problems, it is giving us visibility. It’s also just cool, and that’s more than enough reason to do anything.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>How to Install Home Assistant on Raspberry Pi (Connect ZBT-2 Tutorial)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-home-assistant-on-raspberry-pi/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-home-assistant-on-raspberry-pi/</id>
        <published>2026-01-09T15:00:00Z</published>
        <updated>2026-01-09T15:00:00Z</updated>
        <summary type="html">I’ve avoided anything “smart home” related for a while. But eventually, my research led me to Home Assistant, so here we are.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode84s0hbhb">🎥 


<a href="https://youtu.be/N8n3VwpyFbk" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.home-assistant.io/" target="_blank" rel="noopener" class="text-break">https://www.home-assistant.io/</a> - Home Assistant Website</li>
<li>


<a href="https://www.home-assistant.io/connect/zwa-2/" target="_blank" rel="noopener" class="text-break">https://www.home-assistant.io/connect/zwa-2/</a> - Home Assistant Connect ZWA-2</li>
<li>


<a href="https://www.home-assistant.io/green/" target="_blank" rel="noopener" class="text-break">https://www.home-assistant.io/green/</a> - Home Assistant Green</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So, last month I bought a lamp. It has a switch on it. Turns on and off. I did put a dimmable bulb in it, but the switch does not support dimming. So, unfortunately, it&rsquo;s either off or full brightness. I did start looking into some options on how to make it dimmable without actually changing the switch on the lamp. I found some plugs that you can manually adjust that essentially limit the current going to the actual bulb or to the outlet, which then makes the lamp dimmer. If you turn it up, it makes it brighter. But fiddling around with something like that and then having it statically set did not seem ideal.</p>
<p>Up until this point, I don&rsquo;t have any home automation. I don&rsquo;t have any smart bulbs. I don&rsquo;t have any smart thermostats. But after I started looking into my options with this lamp, it started leading me towards home automation options. Given all the other content on my channel, I obviously don&rsquo;t want to use something that&rsquo;s cloud-controlled by someone else. I wanted something I could self-host, control on my own, yet could still have full automation.</p>
<p>And then the more I looked into it, the more I thought it&rsquo;d be nice to have something where the lights could start turning on at dusk. They could then ramp up in brightness as the night went on. Once it started getting towards the time I wanted to go to sleep, the lights would start to dim down until they turned off. I also thought it&rsquo;d be nice to have something where it could turn on and off on a schedule when I am not home or on vacation. Whether or not this actually would deter a potential robber into thinking someone&rsquo;s home, I don&rsquo;t know, but it seemed like a nice feature to have.</p>
<p>And so what I settled on was using Home Assistant with Z-Wave. Z-Wave is a wireless protocol that lets you control different smart devices if they support Z-Wave. There&rsquo;s alternatives like Zigbee, which I also looked into. But what I found is that Z-Wave has been around for a while, and they seem to have better security, which was extremely important to me. Regardless of the security, though, I&rsquo;ll be placing it on a separate VLAN on my switch. This will let me keep an eye just on the Home Assistant traffic and the Z-Wave traffic, along with keeping it separate from my actual LAN traffic.</p>
<p>But what this boils down to is I purchased a lamp, and that gave me an excuse to now look at some more self-hosting home automation that I can explore. And this is where we&rsquo;re at. But before we get into it, I do want to mention that I truly believe that, given enough time, anyone can pretty much figure out anything. But if you are someone that prefers to spend money in order to save time, I do offer paid consultations. You can head on over to sideburritos.com and then click on the Schedule Consultation button. Whether that&rsquo;s GrapheneOS, or you&rsquo;re looking to get into self-hosting, or maybe you&rsquo;re a business looking to improve your overall security and privacy, I&rsquo;m happy to help. So again, sideburritos.com, and then click on the Schedule Consultation button.</p>
<p>So, I don&rsquo;t have an actual top-down camera setup, but I did find out I could clip a tripod to my monitor stand, and it looks pretty good. So, let&rsquo;s see how this goes.</p>
<p>So, here&rsquo;s the hardware I mentioned. It&rsquo;s the Home Assistant Connect ZWA-2. Thank you, Jeff Geerling, for posting a video on this. It kind of led me down that path instead of going with a third-party option.</p>
<p>So, inside the box, it&rsquo;s pretty straightforward. We have the base. On the back, there&rsquo;s a single USB-C port along with a reset button. We then have the rather large antenna, a small instruction booklet, and then lastly, a USB-A to USB-C cable, which is cloth braided. Pretty nice, and that&rsquo;s convenient since Raspberry Pis all have USB-A on them, and that&rsquo;s what I&rsquo;ll be using.</p>
<p>And then, speaking of Raspberry Pis, I have this one here. This is just a standard, I think it&rsquo;s a 4B. It has a janky heatsink on the bottom, along with a PoE hat on it. If you&rsquo;ve never heard of the PoE hat before for the Raspberry Pi, basically what this allows is you install this on the top of the board, and now that turns this Ethernet port into a port that accepts PoE. So that means you no longer need to use a wall adapter to power the Raspberry Pi. As long as you have a PoE switch, you plug in the Ethernet cable that provides network connectivity along with power, and you can save yourself a cable.</p>
<p>For the actual operating system, I have a microSD card here. I&rsquo;d prefer to use one of the hard drives I have lying around, but I don&rsquo;t have an external hard drive enclosure. So, SD card it is.</p>
<p>As far as the smart home devices that I&rsquo;ll be using with this, I have two smart plugs I purchased. This is a Zooz smart plug, and this is a Minoston smart plug. The reason I got two different ones is the Zooz comes highly recommended. Thanks again, Jeff Geerling, for that one. But this only supports on-and-off functionality, which is not what I&rsquo;m looking for with my lamp. But this one, the Minoston, does support dimming, so I&rsquo;ll be using this for my lamp. This one I&rsquo;ll be using with my Christmas tree for testing. But long-term, I do have a device that I want to be able to turn on and off remotely, and that&rsquo;s what I&rsquo;ll be using this for.</p>
<p>On a side note, in case you&rsquo;re wondering where the Qubes OS video is, that&rsquo;ll be coming shortly. I had to purchase an adapter so I could record the Qubes OS screen from my current laptop. I tried to film it with a camera. It looked terrible. I wouldn&rsquo;t want to watch a video like that, so I&rsquo;m not going to make you watch one like that either. But that one will be out shortly.</p>
<p>So, with the SD card installed, let&rsquo;s go back to Home Assistant&rsquo;s website. Get started. Home Assistant does have official hardware, which is pretty cool. I did not purchase one of these. I&rsquo;m going to be using the Raspberry Pi, but if you don&rsquo;t feel comfortable using a Raspberry Pi, they do have some plug-and-play options.</p>
<p>Let&rsquo;s get started with the Raspberry Pi. This is a Pi 4, so it should work. MicroSD card. You do need an Ethernet cable required for installation. After that, it can work with Wi-Fi. I will be keeping this on Ethernet, though, plugged into my PoE switch.</p>
<p>First step: download and install Raspberry Pi Imager. Just had to update Raspberry Pi Imager. Quick, let&rsquo;s go back to the guide. So, I have a Raspberry Pi 4. Next. What OS do I want to use? Looks like other specific-purpose OS. Looks like they actually have Home Assistant in here according to the guide. Home automation. There&rsquo;s Home Assistant. We&rsquo;re going with Home Assistant OS. This one. This is the actual kit that you can buy from Home Assistant, but we&rsquo;re using the Raspberry Pi, so it&rsquo;s going to be this one.</p>
<p>Storage. That&rsquo;s the one I plugged into my computer. Next. Writing. Right. You&rsquo;re about to erase. I understand.</p>
<p>While that finishes up, let&rsquo;s check on the next step. Eject the SD card and then start up your Raspberry Pi. I think this is almost done verifying. Currently testing out OBS to record these videos, so it seems a little bit easier to see the windows. Looks good. Finish.</p>
<p>So now, for this setup, since my switch is not over here, I&rsquo;ll show you what I&rsquo;ll be doing. I&rsquo;m going to insert the SD card into the Raspberry Pi. That&rsquo;s good.</p>
<p>Next, we have the antenna. Get the base out of here. Grab the actual antenna. Get the USB cable.</p>
<p>So what I&rsquo;ll be doing is plugging an Ethernet cable into here. This USB cable goes into one of the ports. The base gets the antenna screwed into it like so. Pretty straightforward. And then the USB-C cable gets plugged into the back of the antenna. So that&rsquo;s it. I&rsquo;m going to plug this into my switch now, and I&rsquo;ll be back.</p>
<p>So, I just plugged that into my switch. Let&rsquo;s hope it&rsquo;s booting up and getting an IP address from DHCP. I&rsquo;ll log into my switch to see what IP address it got. So, it&rsquo;s been a couple of minutes, and it looks like the Raspberry Pi did get an IP address. So, I guess it&rsquo;s started up correctly.</p>
<p>Next is to go to the IP address, port 8123, in your browser. So let&rsquo;s go there. Continue to site. Cool. Preparing Home Assistant. This may take 20 minutes or more. Interesting. So I&rsquo;m going to make you watch every minute of this. Just kidding. I&rsquo;ll see you shortly.</p>
<p>So, we are back. That took about five minutes, I&rsquo;d say. Are you ready to awaken your home, reclaim your privacy, and join a worldwide community of tinkerers? Absolutely, I am.</p>
<p>Looks like you can upload a backup or restore from their cloud. I&rsquo;m guessing they offer that as a service. So, I&rsquo;ll create my smart home. Time to create a user. I&rsquo;m going to blur out this screen because you don&rsquo;t need to see me doing this.</p>
<p>Looks like you can select your home location. I&rsquo;m going to skip this one for now. The country you&rsquo;re in. Share anonymized information from your installation. No, no, no, no. It&rsquo;s nice that it&rsquo;s opt-in, not opt-out, so I&rsquo;ll give them credit on that one.</p>
<p>Found compatible devices on your local network. Z-Wave. Cool. Bluetooth. I&rsquo;m assuming Z-Wave uses that to pair with.</p>
<p>Finish.</p>
<p>My user, Josh. Let&rsquo;s see. Settings. Devices and Services. Home Assistant. Connect ZWA-2. That&rsquo;s it. Looks like it&rsquo;s discovered. I do want to add it. In a few steps, we&rsquo;re going to set up your home adapter. Home Assistant can automatically install and configure the recommended Z-Wave setup. Let&rsquo;s customize it, because why not.</p>
<p>Is your network new, or does it already exist? It is new. Created configuration for Z-Wave JS. Finish.</p>
<p>Failed setup. Failed to connect. Cannot connect to blah blah blah. Okay. Don&rsquo;t know why that is.</p>
<p>I just reloaded it, and it did find it. So I guess it did work. Or maybe it took a little bit too long to start up, so it couldn&rsquo;t see it.</p>
<p>LED. If I toggle it, it does turn off. Okay. I will say the device does look pretty cool. I&rsquo;ll try and include a picture here in the video. It kind of looks like a small airplane tower.</p>
<p>Firmware update available. Okay, let&rsquo;s just update it because we&rsquo;re here. I&rsquo;m always a big fan of a changelog, so it&rsquo;s nice they include that.</p>
<p>So, I didn&rsquo;t see the actual antenna flash at all, but I just noticed that the installed version and latest version now match. So I&rsquo;m assuming it&rsquo;s good now. Refresh the page. Up to date. Z-Wave info. Okay.</p>
<p>I&rsquo;m going to look more into this after. I&rsquo;m not going to do it right now, but I do want to try and connect one of the outlets that I purchased.</p>
<p>So, overview map. Not in Amsterdam, but that&rsquo;s the default location. Energy. Okay. Has to-do list overview. Media. Guessing what it can save from devices, or if you have cameras hooked up, which I might try and pair some home security cameras I have to this.</p>
<p>Okay, so just looking so far, I will say it&rsquo;s a little confusing at first. Okay, here&rsquo;s the plus button. Want to add a device. Add a Z-Wave device.</p>
<p>Only use your camera to scan QR codes when using a secure connection with the app or over HTTPS. Okay. Well, I&rsquo;m not going to scan with my camera, so I guess I&rsquo;ll use the QR code manually.</p>
<p>Let&rsquo;s get back to the top-down view quick. Every smart device does have a QR code on it. Let me not show these on camera since that would be a security issue. Actually, this one, yeah, on the side here, we do have a QR code, which I&rsquo;m not going to show you.</p>
<p>But here&rsquo;s the plug. I think this is a physical power switch. So it&rsquo;s nice that even though it&rsquo;s a smart device, you can still use it as a dumb device, which is nice in case my home hosting setup goes down and I can still turn a lamp on and off.</p>
<p>Okay, looks like I need to scan it with my phone so I can get the QR code, since the QR code does not list it. Okay, so I scanned it with my phone. I think this is about 100 characters. I&rsquo;m just going to send it to myself on Signal quick so I can copy and paste it, because I&rsquo;m not typing that in.</p>
<p>So I guess long-term, it would be good to put an HTTPS proxy in front of this or use the app so that you don&rsquo;t need to do this manually every time you want to add a new device. Either way, it&rsquo;s always a good idea to use HTTPS. So I will be adding that later. I run Nginx Proxy Manager on my home hosting or self-hosting setup, so I&rsquo;ll just add it to that.</p>
<p>So here&rsquo;s the code. It&rsquo;s going to be blurred out on the screen, but it is massive. Next. Indoor smart plug. I guess it detects that from the code. Let me plug this in, though, so it can be on.</p>
<p>So I just plugged in the smart plug. I heard a relay click inside of it. This is a long-range device area. I don&rsquo;t have any yet. I guess there&rsquo;s some default ones. Just put living room. Add device.</p>
<p>If your device is already turned on, you might need to turn it off and on again. Okay, it&rsquo;s searching for the device. I guess I&rsquo;ll try turning it on and off.</p>
<p>Just turned it on and off. It should be scanning for it. Looks like it did find it. This device is currently being interviewed. It may not be fully operational. Okay, definitely got some stuff to learn about Z-Wave and Home Assistant. This is cool.</p>
<p>The plug looks like it gives some sensor details about it. Let me plug in my phone to this. So, I wish I had something better to visibly show that the outlet is on or off based on the dashboard here, but here&rsquo;s a phone. I have a power brick plugged into the outlet and then plugged into a USB-C cable. So let&rsquo;s plug it into the phone. Looks correct. It should be off.</p>
<p>And I&rsquo;m guessing controls. If I toggle this, then the phone should turn on.</p>
<p>Heard the relay click, and the phone is now booting up. So that did work. We can see some stats here. Electrical consumption: 0.4 amps, 2 watts. The phone is currently charging at 9 watts. Okay, looks like it is working.</p>
<p>And if I turn this off—let me just—okay, there it is. Heard the relay click again in the outlet, and it&rsquo;s no longer charging.</p>
<p>So one thing I was worried about is the latency from when I toggle something to when the actual device reacts to that action. It seems almost instant. If I click it, I feel like I&rsquo;m hearing, in real time, the outlet going on and off. So it does seem near instant that this is working.</p>
<p>I&rsquo;ve seen some complaints—maybe it&rsquo;s some other protocols or other devices—where there is some latency, which can be kind of annoying because you&rsquo;re wondering, did the actual action work? Is your setup not working? Is the device not working? But with this being instant, you can tell pretty quickly.</p>
<p>So overall, I think that setup was pretty straightforward. It&rsquo;s always pretty iffy when you&rsquo;re dealing with hardware and software how things are going to work, but it seems like the Home Assistant antenna worked very well with Home Assistant, as I would hope.</p>
<p>So I&rsquo;m going to go and play with this some more, work on some configurations, and I&rsquo;ll come back in the future with another video on what I have set up and some good things and maybe bad things I find out about it.</p>
<p>So if you do want to set this up yourself, I do think it was pretty straightforward. Again, Home Assistant does have some first-party hardware that you can use. So if you&rsquo;re looking for something that might be a little bit better than a Raspberry Pi or a little more straightforward, then that is an option.</p>
<p>So if you have any questions or comments, or any tips on using Home Assistant or some cool things that you set up, feel free to leave those down below, and I&rsquo;ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>Why I&#39;m finally ready to leave macOS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/leaving-macos-for-qubes-os/" />
        <id>https://staging.sideofburritos.com/blog/leaving-macos-for-qubes-os/</id>
        <published>2025-11-08T16:00:00Z</published>
        <updated>2025-11-08T16:00:00Z</updated>
        <summary type="html">A presentation at DEF CON 33 finally gave me the motivation to leave macOS.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode97s0hbhb">🎥 


<a href="https://youtu.be/A-a3d7Hb_6E" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://youtu.be/BNmJ3qBP9GE" target="_blank" rel="noopener" class="text-break">https://youtu.be/BNmJ3qBP9GE</a> - DEF CON 33 - AppleStorm - Unmasking the Privacy Risks of Apple Intelligence - Yoav Magid - YouTube Video</li>
<li>


<a href="https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Yoav%20Magid%20-%20AppleStorm%20-%20Unmasking%20the%20Privacy%20Risks%20of%20Apple%20Intelligence.pdf" target="_blank" rel="noopener" class="text-break">https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Yoav%20Magid%20-%20AppleStorm%20-%20Unmasking%20the%20Privacy%20Risks%20of%20Apple%20Intelligence.pdf</a> - DEF CON Presentation Slides</li>
<li>


<a href="https://www.theverge.com/news/737757/apple-president-donald-trump-ceo-tim-cook-glass-corning" target="_blank" rel="noopener" class="text-break">https://www.theverge.com/news/737757/apple-president-donald-trump-ceo-tim-cook-glass-corning</a> - Tim Cook gift to Trump</li>
<li>


<a href="https://fortune.com/2025/09/05/trump-tech-dinner-full-attendee-list/" target="_blank" rel="noopener" class="text-break">https://fortune.com/2025/09/05/trump-tech-dinner-full-attendee-list/</a> - Silicon Valley Tech Dinner</li>
<li>


<a href="https://www.bbc.com/news/articles/c708y1egzlko" target="_blank" rel="noopener" class="text-break">https://www.bbc.com/news/articles/c708y1egzlko</a> - Apple removing apps from App Store</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>I attended Defcon 33 a few months ago, in August of 2025, in Las Vegas, Nevada. It&rsquo;s always an enlightening experience. So, if you ever have the chance to go, I highly recommend it. To those that saw me there and came up to me and thanked me for my content that I publish, thank you for that. Your words truly meant a lot to me.</p>
<p>But before we get into it, I want to mention that I offer paid consulting. I truly believe that anyone can figure out anything given enough time, but there are some people that prefer to save time by spending money. And if that&rsquo;s you, I am happy to help. You can find out more at sidabritos.com by clicking the &ldquo;Schedule Consultation&rdquo; button.</p>
<p>This year, I saw a presentation by Yoav McGidd. I hope I pronounced that correctly. That gave me the same gross feeling I had when I made my initial video in August 2021 about switching to GrapheneOS. Here&rsquo;s the TL;DDR of what that presentation talked about. It covered how Apple&rsquo;s AI ecosystem is sending WhatsApp, iMessage, and other app data of Apple users when they are using the &ldquo;Hey Siri&rdquo; feature, and the user has no control over this.</p>
<p>Besides sending the message data that was being used to transcribe what the user had said, it was also sending what media the user was currently listening to in their browser. I guess they need that for context. It was also sending a list of apps installed on the user&rsquo;s machine, including a list of apps from a virtual machine the user had on the host. The presentation has way more details on this, so I suggest you look at that. I also saw that Defcon published the talk yesterday on YouTube, so if you want to watch that, I will link it down below.</p>
<p>But after seeing this presentation, I was just grossed out, for lack of a better term. I don&rsquo;t use Siri on my MacBook, but I know there&rsquo;s other privacy invasive stuff running, even though I filter my network traffic with Little Snitch and have most of the Apple features and apps disabled. And before you start typing that comment, yes, I know I talk about GrapheneOS and that&rsquo;s what I use, so using macOS makes me a hypocrite, a sellout, trying to think of the other names that I&rsquo;ve been called, but it&rsquo;s fine. I get it. No hard feelings. It&rsquo;s what worked best for me at the time.</p>
<p>But times are changing. And add in that Tim Cook is selling out to Donald Trump, giving him a gold bar trophy, because that&rsquo;s what I do with my friends. We have a bunch of Silicon Valley nerds brown-nosing the current administration and going to fancy dinners. We also have Apple doing whatever they can to appease the current people in power. And regardless of which side you fall on, tech companies being in bed with the government is not normal, at least in the U.S., at least not this blatantly.</p>
<p>So, what I&rsquo;m going to be doing is trying to migrate to Qubes OS, which is a reasonably secure operating system. I mean, if this guy likes it, then it&rsquo;s got to be kind of good. Where Qubes OS is different from a regular operating system is that they leverage Xen-based virtualization to allow for the creation and management of isolated compartments called cubes. Basically, what that means is that every app or compartment is a virtual machine which keeps it separate from others.</p>
<p>I&rsquo;ve read and heard that the learning curve can be pretty steep for Qubes OS. And in the past, I&rsquo;ve tried other desktop OSes like Fedora, Pop!_OS, Ubuntu, Debian, but none of them did it for me. This time, I have the motivation behind me, so I figured I would try and use the best available option that I knew of. So, I went out and purchased a 2018 T480 ThinkPad for $25 shipped off eBay. I wanted to use something that was listed as compatible with Qubes but not spend a ton of money. I&rsquo;m not recommending you go out and buy this laptop. I just wanted to find the cheapest option available. If Qubes OS ends up working for me, then I&rsquo;ll switch out to something else in the future.</p>
<p>There are a few things I want to mention about this laptop. First off, it was one of the first laptops I used at my first job that we would roll out to employees. And like I said, this is a 2018 laptop, but somehow it came with some amazing features like an integrated, I don&rsquo;t know if you can see it, slide for the webcam to cover it. So that&rsquo;s pretty awesome. I don&rsquo;t know why that&rsquo;s not a feature anymore.</p>
<p>The keyboard&rsquo;s also pretty decent and has some nice tactile feedback. The touchpad is decent as well. It also has the little nub in the center that you can use for the mouse. The red nub is actually missing from this one, but I could replace it if I wanted to. In addition, it has a removable battery, so that&rsquo;s pretty handy as well. And the ports on here also impressed me. So again, 2018 laptop, almost eight years old at this point, it has two USB-C ports along with a dock connection port. And on the other side, it has an Ethernet port, a full-size SD card slot, two USB-A ports, an HDMI port, and a headphone jack. So, it was pretty refreshing to see all those ports again on a laptop. I miss those days, along with an integrated webcam cover.</p>
<p>So, I&rsquo;m going to be recording my experience from the start with this process. It&rsquo;s not going to be like my current videos where I test everything out and make a polished guide demonstrating how to do things. I&rsquo;m going to share my experience from the perspective of someone who has never used Qubes OS before and document that process. So, a little bit different format, but I think it&rsquo;ll be interesting.</p>
<p>I know it&rsquo;s not realistic to expect I&rsquo;ll get everything migrated over to a five-year-old laptop. I&rsquo;ll probably continue my video editing on macOS, but everything else is fair game. So, if you have any suggestions or feedback on getting started with Qubes OS, feel free to share that down below, and I&rsquo;ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS - Private Space Feature</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-private-space/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-private-space/</id>
        <published>2025-10-23T14:00:00Z</published>
        <updated>2025-10-23T14:00:00Z</updated>
        <summary type="html">Separate user profiles a bit much? Using a Private Space might be the answer for you.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode66s0hbhb">🎥 


<a href="https://youtu.be/G94V5I2xH1E" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases</a> - GrapheneOS forum post announcement</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So today I want to talk about the private space feature on GrapheneOS.</p>
<p>But before we get into that, I want to mention that I do offer paid consulting. I truly think anyone can figure out anything given enough time, but there are some people that prefer to save time by spending money — and if that’s you, then I’m happy to help. Whether you’re an individual just getting started with GrapheneOS, you’re looking to get into self-hosting, or maybe you’re a business looking to improve your overall security or privacy — if you want to find out more, you can head on over to sideofburritos.com and click on Schedule Consultation.</p>
<p>I want to start by going through the official announcement first by the GrapheneOS team on the discussion forum. I realize this was posted almost a year ago, and some things have changed since the initial announcement, but I still think it’s beneficial to go through.</p>
<p>GrapheneOS and the Private Space Feature</p>
<p>So, GrapheneOS fully supports the private space feature on Android 15, which is essentially a separate user nested inside of the owner user. This last part has already changed — the private space feature is now available in all users, not just the owner profile anymore.</p>
<p>The team strongly recommends it as a replacement for a work profile managed by a local profile admin app. It has better OS integration and isolation. So if you’re using something like Shelter on your phone currently to create a work profile, this is a great replacement.</p>
<p>The private space is an isolated workspace profile for apps and data, similar to both user profiles and work profiles. All three forms of profiles have entirely separate VPN configurations, which is very useful even if you are connected to the same VPN, since exit IPs can be separate. That part might sound a little confusing, but I’ll explain that better in the demo.</p>
<p>All forms of profiles have separate encryption keys. You can keep a private space at rest while the owner user is logged in, just as you can with a secondary user. This was a big reason I always liked using secondary users — you could end the session on that user profile and now it’s at rest, as compared to the owner user profile, which you need to be logged into in order to use your device.</p>
<p>Now, you can have a single profile setup. You can use the owner user profile, have a separate private space in there, and then put that private space at rest if you have something running that you don’t always want running. Before, you needed a secondary user profile for that.</p>
<p>The private space makes it easier to share data than users. The clipboard is shared, but we could add a setting for it — they have added a setting for that, which I’ll point out. All the features, including contact scopes, storage scopes, and sandboxed Play Services, have full support of private space. So if you use any of those features and you’re concerned about them not working in private space — they do work.</p>
<p>Currently, I think a lot of users use a separate user profile if they want to use sandboxed Google Play. And while this does provide great isolation, it can be cumbersome to switch to that separate user in order to use apps. Now, with private space, you get the same benefit of isolation, but it’s much more convenient to use those apps in the same user profile you always use.</p>
<p>I realize a lot of this might sound confusing in the way I’m explaining it, but hopefully that’ll be cleared up in the demo. So let’s get into that.</p>
<p>Setting Up a Private Space</p>
<p>Here I am in my owner user profile on a Pixel 7 running GrapheneOS. The first thing we’re going to do is set up a private space — and again, this works in any user profile, so if you’re in a secondary user, you can follow this same process and set one up there.</p>
<p>Go into Settings, scroll down to Security and Privacy. At the bottom, you’ll see Private Space — tap on that.</p>
<p>The screen will then prompt you for your user PIN, so type that in. Here we have some details about the private space — I suggest reading through that. At the bottom, there’s a warning:</p>
<p>“Private spaces are not suitable for apps that need to run in the background or send critical notifications, such as medical apps.”</p>
<p>This is because notifications and background activity are stopped when your space is locked. As the warning states — if the private space is locked, notifications will not work. But if it’s not locked, notifications should work. Do your own testing before depending on it for something critical to your health or well-being.</p>
<p>Once you’ve read through that, tap Set Up at the bottom right. Once that finishes, you’ll be prompted to choose the lock method for your private space. You can either use your screen lock or choose a new lock. I’ve been using my screen lock, but if you want it different, go ahead and do that.</p>
<p>Tap Use Screen Lock and it’s all set. It tells you where to find it. Click Done, and as you can see, I’m now in the app drawer. Swipe up from the home screen and you’ll now see the private space at the bottom — on the right side, you’ll see the lock icon, which means it’s currently locked.</p>
<p>Tap on that, enter your lock screen PIN or password, and once entered correctly, you are now presented with the private space.</p>
<p>Navigating the Private Space</p>
<p>A couple of things — when it’s unlocked, you can swipe up or go back, and it stays unlocked. Tap the lock button to lock it again. Remember: when the private space is locked, those apps are not running. So if you need notifications from any apps in your private space, those will not work while it’s locked.</p>
<p>You’ll notice some apps already installed — these are the same default apps that come on GrapheneOS when you install it. Each app installed in the private space has a small shield-and-key icon at the bottom right — that means it’s installed in the private space.</p>
<p>There are a couple of ways to install apps into the private space. If you tap the Install button here, it opens the GrapheneOS App Store. From there, you can install Google Play Store and Google Play Services. This is great for people currently using a separate user profile for apps that require Play Store. You get that same separation with the convenience of being able to lock or turn off the private space when not using it — something you couldn’t do with apps installed in the owner profile without powering your phone down.</p>
<p>Private Space Settings</p>
<p>Tap the gear icon next to the lock icon — these are the private space settings.</p>
<p>Private Space Lock – You can change it so it doesn’t use the device screen lock.</p>
<p>Lock Private Space Automatically – By default, it’s set to Every Time Device Locks. If you want it to run continuously in the background, change it to Only After Device Restarts.</p>
<p>Hide Private Space – By default, this is off. Turning it on hides the private space from the app drawer. To access it, go to Settings → Security and Privacy → Private Space → Unlock. I keep this off since I’m the only one who uses my device.</p>
<p>Cross-Profile Shared Clipboard – The default option allows sharing between the main user and private space. It’s up to personal preference whether to keep or restrict that.</p>
<p>End Session Immediately on Lock – Disallows delayed locking of storage. I don’t fully understand this option, but it seems safe to enable.</p>
<p>At the bottom, you’ll see the same warning from setup — again, test notifications before relying on them.</p>
<p>Installing Apps from the Main Profile</p>
<p>Going back to Install Available Apps, tapping it shows a list of all apps installed in the current user profile. Installing apps to the private space is as simple as toggling the switch next to the app. For example, if we enable Molly, we’ll now see it in our private space.</p>
<p>Default apps are separated by a horizontal rule, and anything with the small icon in the corner is in the private space. This is helpful for distinguishing which version you’re in — for example, if you have Signal installed in both, the icon tells you whether you’re in the private space or the main profile.</p>
<p>VPN and Profile Isolation</p>
<p>All three forms of profiles have entirely separate VPN configurations. For example, in my owner profile, I have ProtonVPN installed. If I connect there, that VPN only applies to the owner user. If I go to the private space and check my IP in Vanadium, it will show my home or cellular IP.</p>
<p>To apply a VPN to the private space, install and sign in to your VPN there separately. While it might sound cumbersome, it’s actually a benefit — you can have different exit IPs or countries per profile. This is the same behavior as secondary users on GrapheneOS.</p>
<p>Final Thoughts</p>
<p>I’ve been testing out the private space feature for the past few weeks, and it’s been working well. It’s much more convenient to use than a separate user profile. The only app I noticed some oddities with was MySudo — some calls and texts behaved oddly, at least notifications did.</p>
<p>I reached out to the MySudo team, and they said it should be supported in any profile type. I’m going to continue testing before fully committing and deleting my secondary user. But I think the private space is a great option for a lot of people, especially if you’re just getting started.</p>
<p>It makes the transition much easier than having a separate user, where you need to switch whenever you want to use those apps or get notifications.</p>
<p>Looking back at my notes, I covered a lot of information in this video. Hopefully it didn’t come across as too confusing, and it can serve as a good place to get you started. If you’ve been testing the private space feature, feel free to share your experience. And if you have any questions or comments, feel free to leave those down below — and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS - Security Preview Releases</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-security-preview-releases/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-security-preview-releases/</id>
        <published>2025-10-11T14:00:00Z</published>
        <updated>2025-10-11T14:00:00Z</updated>
        <summary type="html">GrapheneOS recently started publishing releases that provide early access to Android Security Bulletin patches before the official disclosure. Here’s how to enable it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode68s0hbhb">🎥 


<a href="https://youtu.be/_fNbTFCl1qw" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases</a> - GrapheneOS forum post announcement</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So today I want to talk about one of the biggest features I think Graphine OS has released in a long time.</p>
<p>But before we get into that, I do want to mention that I offer paid consulting. I truly believe that anyone can figure out anything given enough time, but there are some people that prefer to save time by spending money. And if that&rsquo;s you, then I&rsquo;m happy to help.</p>
<p>Whether you&rsquo;re someone just getting started with Graphine OS or you&rsquo;re looking to get into self-hosting or maybe you&rsquo;re a business looking to improve your security or employee privacy, you can find out more by heading on over to sidebretos.com and clicking the schedule consultation button.</p>
<p>But what this feature is is security preview releases. Security preview releases provide early access to Android Security Bulletin patches prior to the official disclosure. Their current security preview releases provide access to the November 2025 and December 2025 patches for the Android Open Source Project.</p>
<p>They recommend enabling this, as do I. The only difference between regular releases and security preview releases are the future Android Security Bulletin patches being applied with any conflicts resolved.</p>
<p>The downside of the security preview releases is that they are unable to provide the source code for the patches until the official disclosure date. The reason for this is that the OEM they are working with is allowing them to release these as binary only, which means that they are technically closed source even though the rest of the operating system is open source.</p>
<p>If we scroll down, the Graphine OS team has also posted some more details about it. The terms with their OEM partner are not really under an NDA, and neither is which OEM they are working with, but they don’t want to publish which OEM it is until an official announcement with them.</p>
<p>On a side note, that&rsquo;s pretty exciting. That means they found an official OEM partner to work with, and I&rsquo;m assuming that means they&rsquo;re going to be working on hardware with them. I haven’t heard any more details about it at this point, and this is likely the reason why.</p>
<p>Now, to cover some of the concerns that I&rsquo;ve seen about this — yes, technically these early security release preview patches are closed source even though the rest of the operating system is open source. Personally, I have no concern about this. These are typically tiny pieces of code that fix vulnerabilities or exploits.</p>
<p>I&rsquo;m sure some people will comment that this is bad and evil that the code is closed source right after they finish writing a message on WhatsApp.</p>
<p>As far as enabling this goes, once you are in your owner user profile on Graphine OS, go into Settings, scroll down to System, and then select System Updates. If you&rsquo;re on a recent or the most recent release of Graphine OS, you&rsquo;ll see a “Receive security preview releases” option. It is disabled by default.</p>
<p>If you toggle that, you can either wait a little while for the phone to check for updates by itself, or you can select “Check for updates.” You’ll now see there’s a new update installing since you enabled that option. That update will download and install the security preview release of Graphine OS.</p>
<p>If you&rsquo;re wondering how these releases work, they’re actually going through significant effort and building two variants of each release. The 2592500 build is the non-security preview, and the security preview release is 01. Once you enable it, your phone downloads the 01 version.</p>
<p>Their plan is to keep it off by default with a new page added to the setup wizard, but they’ll recommend turning it on. Once the embargo ends, they plan to publish what they used, so it will still be open source — just delayed.</p>
<p>So, if you have any questions or comments, feel free to leave those down below.</p>
]]></content>
      </entry>
      <entry>
        <title>CalyxOS Is NO Longer Safe to Use</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/calyxos-is-no-longer-safe-to-use/" />
        <id>https://staging.sideofburritos.com/blog/calyxos-is-no-longer-safe-to-use/</id>
        <published>2025-09-13T14:00:00Z</published>
        <updated>2025-09-13T14:00:00Z</updated>
        <summary type="html">After some recent news by the Calyx Institute, CalyxOS is no longer safe to use.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode50s0hbhb">🎥 


<a href="https://youtu.be/oTp8cTPH8g4" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://calyxos.org/news/2025/08/01/a-letter-to-our-community/" target="_blank" rel="noopener" class="text-break">https://calyxos.org/news/2025/08/01/a-letter-to-our-community/</a> - CalyxOS Letter with Updates</li>
<li>


<a href="https://www.radware.com/security/ddos-knowledge-center/ddospedia/mirai/" target="_blank" rel="noopener" class="text-break">https://www.radware.com/security/ddos-knowledge-center/ddospedia/mirai/</a> - Mirai Botnet Article</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So today I want to talk about CalyxOS and why it is no longer safe to use.</p>
<p>Earlier this month, on August 1st, 2025, the Calyx Institute published a letter to their community. I will link this down below, but I want to highlight a few important parts of it. I would still suggest reading the entire thing yourself for more details.</p>
<p>The first thing is that Nicholas, president and founder of the Calyx Institute, has left the organization to pursue other projects. Additionally, Sirayu, I think that’s how you say it, the CalyxOS tech lead, has also departed from the project. So basically, two high-level and important people at Calyx Institute have left recently.</p>
<p>In light of that, they have decided that they are going to define some priorities, which include upgrading the tech infrastructure, supporting CalyxOS development, stabilizing update release cycles for their 25+ supported devices, and revising and updating documentation, wikis, and other user guides. Overall that’s a good thing. It’s never a bad thing to do, but the main issue comes here.</p>
<p>After conducting a thorough inspection of the work required for successful completion of the above priorities, they determined that it may take up to four to six months for them to provide the level of security maintenance they aim to deliver. They also state they will be switching to new signing keys along with the overhaul of the signing and verification process. As a result, current CalyxOS users will not be able to receive further security software updates until this process is in place. Given the potential risk posed by the pause of maintenance and development, it is logical that they stop providing options to install CalyxOS for now, which I applaud them for. But they went back on that decision a little while later.</p>
<p>Just to go over this first: we have two high-level individuals that have left, and they have decided to pause updates for the next four to six months. That means that when the AOSP, the Android Open Source Project, puts out updates—which includes security fixes—CalyxOS will not be receiving those. As of the time of recording this, CalyxOS is stuck on the June 1st, 2025 patch level. That means there are already two remotely executable vulnerabilities present in the latest release of CalyxOS, and it may take four to six months for them to provide any updates. More and more vulnerabilities will be found in Android OS, and those will not be fixed or patched.</p>
<p>Now you might be saying, “I’m not an important individual, so I won’t be a target.” First of all, I want to say you are important, and thanks for being here. But besides that, it doesn’t matter if you are a target or not. Once these vulnerabilities are weaponized, they are launched at mass scale. Even if you aren’t a direct target, if your device is vulnerable, it could be compromised.</p>
<p>You see this all the time with routers people have in their homes. They’re compromised on a mass scale and used in DDoS attacks and things like that. So it doesn’t matter if you’re not a target—if your device is vulnerable, then you are not safe.</p>
<p>And even if CalyxOS does stick to the four-to-six-month timeline they’ve laid out, they are planning on rotating the security keys. For some reason they’re doing it in a manner that’s disruptive, which will require users to reinstall CalyxOS from scratch. That doesn’t make sense, because there are non-intrusive ways to do it, at least for most of the keys. You can read into that more or do your own research. Regardless, if they do come back, you’re still going to have to reinstall your device, which is not ideal.</p>
<p>Then, four days later on August 5th, the CalyxOS team posted another update to the article. They said, “First we want to assure you that we have no reason to believe the security of CalyxOS and its signing keys have been compromised.” They also mentioned that for the time being, current CalyxOS users will not be able to receive further software security updates until the new security protocols are in place. Good on them for being honest, but without security updates this does not guarantee the level of security they strive for—especially when global threats to privacy and human rights are at a critical moment.</p>
<p>The last thing is that, due to overwhelming feedback from the community, they decided to make the images publicly available once more. This is different from when they hid the “Get CalyxOS” button on their site originally. Now, while they do have a banner saying CalyxOS releases are paused, you can still install it on your device. It’s okay that they have a very obvious message there, but even they recommend that this is not a recommendation to migrate to CalyxOS now.</p>
<p>So to summarize: CalyxOS is no longer safe and secure to use. If you are using CalyxOS and you have a Google Pixel that is supported by GrapheneOS, then my recommendation is to install GrapheneOS and use that instead. Even when CalyxOS was being updated, that would still be my recommendation.</p>
<p>If you have a device that is not supported by GrapheneOS and you want to get one, check out the A versions of the Pixels. Those are usually more affordable, and you can find them significantly discounted when used on eBay or other sites. On my website, sideofburritos.com, I have a few options for people in the United States and also for international buyers.</p>
<p>If you want to hear more from me in the meantime, I have a podcast called In The Shell. You can find it at intheshellpodcast.com. I am planning on launching season three shortly, so stay tuned for that. I also have a monthly newsletter you can sign up for at sideofburritos.com.</p>
<p>And if you have any questions or comments, feel free to leave those down below, and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>Some thoughts on switching to KeePass</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/i-switched-to-keepass/" />
        <id>https://staging.sideofburritos.com/blog/i-switched-to-keepass/</id>
        <published>2025-05-31T10:00:00Z</published>
        <updated>2025-06-01T10:00:00Z</updated>
        <summary type="html">I switched to KeePass</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode93s0hbhb">🎥 


<a href="https://youtu.be/sRi66okPdFM" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1" target="_blank" rel="noopener" class="text-break">https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1</a> - Allow Attachments to be exported when using Export Data Feature Request</li>
<li>


<a href="https://bitwarden.com/blog/upload-store-and-now-export-attached-files-in-your-secure-bitwarden-vault/" target="_blank" rel="noopener" class="text-break">https://bitwarden.com/blog/upload-store-and-now-export-attached-files-in-your-secure-bitwarden-vault/</a> - Bitwarden blog post announcing attachments export</li>
<li>


<a href="https://grapheneos.social/@GrapheneOS/114549099206535021" target="_blank" rel="noopener" class="text-break">https://grapheneos.social/@GrapheneOS/114549099206535021</a> - GrapheneOS post mentioned in intro</li>
<li>


<a href="https://keepassxc.org/" target="_blank" rel="noopener" class="text-break">https://keepassxc.org/</a> - KeePassXC (Desktop)</li>
<li>


<a href="https://www.keepassdx.com/" target="_blank" rel="noopener" class="text-break">https://www.keepassdx.com/</a> - KeePassDC (Android)</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Just a few quick updates before we get into it.</p>
<p>I send out a monthly email newsletter — if you want to sign up for that, you can go to sidecideros.com, throw your email in the box, and hit subscribe. While you&rsquo;re there, you can also check out my podcast, which is called In the Shell. You can find out where to listen at intheshellpodcast.com.</p>
<p>Back on sidecideros.com, I added a small phone icon at the top. If you click on it, it takes you to a page with an up-to-date list of all the apps I use on my Google Pixel running GrapheneOS. So if you&rsquo;re just getting started or you&rsquo;re curious about what I use, you can check that out and use it as a reference.</p>
<p>About five months ago, I published a video called The Big Problem with Bitwarden Backups. TL;DR — I was migrating my self-hosted Bitwarden instance to a new server. I set it up, imported my backup (exported using the web interface), and everything seemed fine. But shortly after, I needed an attachment from my vault — I think it was a PDF — and realized that none of the attachments had been imported.</p>
<p>After digging into it and finding a forum post, I learned that Bitwarden backups didn’t export attachments at the time. Fast forward to now, and it looks like they’ve fixed that — they even published a blog post about it. Attachments are now included in backups, which is great!</p>
<p>That said, I still don’t use Bitwarden. As Bush once said (sort of):</p>
<p>“Fool me once… shame on — shame on you. Fool me… we can&rsquo;t get fooled again.”</p>
<p>(Yes, that was a joke.)</p>
<p>Even so, I still recommend Bitwarden for 99% of people. I think it’s the best option if you need a cloud-hosted, centralized vault — especially if you’re managing passwords for multiple people in your family and don’t want to be solely responsible for your data.</p>
<p>As for me, I’ve reached a point in my self-hosting journey where I’m trying to simplify my setup. Bitwarden running in Docker containers is fairly straightforward, but there were some backend elements I wasn’t entirely comfortable with. A few times during updates, the service wouldn&rsquo;t come back up right away. I had to troubleshoot, figure out what changed, make updates, and get it running again.</p>
<p>For something like a password manager, that kind of downtime can be stressful. That’s why I moved to KeePass.</p>
<p>One of the benefits of KeePass is that your vault is just a single file. That means you can back it up by literally copying it to a flash drive. If you ever need to restore it, you just open the file with KeePass — no need to set up a new instance, import a backup, and go through the login process. You can access your vault from any computer or phone with the app installed. That simple file structure is a big plus in my book.</p>
<p>Quick note before I continue: If you haven’t self-hosted anything before, your password manager shouldn’t be the first thing you self-host. Start with something less critical, get your backup plan in place, and then maybe consider self-hosting your password manager.</p>
<p>So back to KeePass — it’s simple. I use KeePassXC on desktop and KeePassDX on Android. One thing to keep in mind is that unlike Bitwarden (which provides a complete ecosystem from the same company), KeePass is more fragmented. But once everything is set up, you don’t really have to think about it.</p>
<p>The interface is straightforward. I really like the password generator — you can choose between passwords and passphrases, and it includes a default word list (you can add more if you want). I do wish it had a username generator, though — that’s one feature it lacks.</p>
<p>Creating new entries is simple. You can attach files, and since everything is stored in that one file, you don’t have to worry about exporting attachments separately.</p>
<p>KeePass also supports MFA. I use YubiKeys for this — specifically the 5C model. Every time you make a change, KeePass prompts you to touch the YubiKey for confirmation. I also have a Nano YubiKey that I leave plugged into my computer, which makes it more convenient. This adds a layer of protection against automated attacks since physical touch is required for authentication.</p>
<p>There’s a browser plugin for KeePass, but I found it a bit clunky and stopped using it. Instead, KeePass has a feature called Auto-Type. You select an entry, click Perform Auto-Type, and it types your credentials into the active window. I don’t personally use it — I just copy and paste.</p>
<p>On my phone, I also avoid keyboard integration — I just copy and paste there as well, and it works fine for me.</p>
<p>You might be wondering how I sync across devices now that I’m not using a centralized setup. I do 95% of my work on my laptop, so I only make changes there. Then every few days, I manually transfer the updated password database to my phone and tablet using LocalSend.</p>
<p>You could sync your KeePass database to a cloud service and install the client on each device — I actually have mine synced to Seafile, which I also self-host — but I still prefer the manual method. It keeps things simple, and I haven’t had any issues with it.</p>
<p>So while I still think Bitwarden is a fantastic choice for most people, if you&rsquo;re into self-hosting, KeePass is absolutely worth checking out.</p>
<p>If you have any questions or comments, feel free to leave them down below — and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>The Big Problem with Bitwarden Backups</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/problems-with-bitwarden-backups/" />
        <id>https://staging.sideofburritos.com/blog/problems-with-bitwarden-backups/</id>
        <published>2025-01-11T10:00:00Z</published>
        <updated>2025-01-11T10:00:00Z</updated>
        <summary type="html">Bitwarden is a great password manager, but there’s a critical issue with backups that could catch you off guard.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode109s0hbhb">🎥 


<a href="https://youtu.be/OI_mElYmQ7w" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://bitwarden.com/help/export-your-data/" target="_blank" rel="noopener" class="text-break">https://bitwarden.com/help/export-your-data/</a> - Bitwarden Export Vault Data Help Page</li>
<li>


<a href="https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1" target="_blank" rel="noopener" class="text-break">https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1</a> - Allow Attachments to be exported when using Export Data Feature Request</li>
<li>


<a href="https://news.ycombinator.com/item?id=31702594" target="_blank" rel="noopener" class="text-break">https://news.ycombinator.com/item?id=31702594</a> - Hacker News post about Bitwarden backups</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Today, I want to talk about Bitwarden. Let me start by saying that I think it&rsquo;s a great password manager and a solid option for many people. I&rsquo;ve been self-hosting it for the past two years, but there&rsquo;s one major feature missing that could potentially cause problems for users, just as it did for me.</p>
<p>For the past two years, I&rsquo;ve been hosting Bitwarden on a Raspberry Pi, along with a few other containers. Recently, I wanted to simplify and consolidate my setup, so I moved Bitwarden, along with the other containers, to an existing Mini PC I had. I got the containers up and running on the new host, and the next step was to restore the backups I had taken. Everything went smoothly—backups for the other containers restored perfectly. When I restored Bitwarden’s backup, everything seemed fine. I signed in on my other devices, ensured syncing was working, and verified all my passwords were intact. Perfect.</p>
<p>About a month later, everything still looked good. Confident in my setup, I decided to format the drive the Raspberry Pi was using and deleted the backups I had for it. Then, of course, Murphy’s Law struck. I logged into my new Bitwarden instance to check on some documents I had uploaded, and to my surprise, they were gone.</p>
<p>This leads to the major feature Bitwarden is missing: the ability to export attachments when you back up your vault.</p>
<p>Let me walk you through what happened. In my self-hosted instance, I had to use a cloud-hosted Bitwarden Vault to get a license for the self-hosted subscription. So, I decided to test this feature in the cloud-hosted vault. Here’s what I found:</p>
<p>When you try to export your vault, you have a few options—JSON, CSV, or encrypted JSON. I selected JSON, confirmed the format, typed in my master password, and exported the vault. When I looked at the exported file, it was clear something was off. The file size was only 636 bytes, even though the test entry I uploaded included a 40 MB attachment.</p>
<p>I’ll take some responsibility here—there were red flags I should have noticed. The file was too small, and JSON is unlikely to contain encoded attachments due to size limitations. There were no additional folders or files for attachments, just a single, tiny JSON file. I should have realized this, but I was working casually and didn’t double-check.</p>
<p>To make matters worse, there’s no warning in the Bitwarden interface about attachments not being included in exports. The only mention of this that I could find was in the &ldquo;Export Vault&rdquo; help document, which states: “Vault exports will not include file attachments, items in the trash, or sends.” While they do technically warn you, I think this information should be far more prominent.</p>
<p>Bitwarden has no problem including warnings in other parts of the app. For instance, the &ldquo;Security&rdquo; tab highlights warnings about changing your master password or enabling two-step login with yellow-highlighted alerts. A similar approach for export warnings could save users from losing critical data.</p>
<p>Needless to say, I lost backups of SSH keys, important documents, and even photos of identification that I had stored securely in Bitwarden. It’s a harsh lesson in the importance of keeping local backups, which is a topic I’ll cover in a future discussion.</p>
<p>After realizing this, I started searching to see if others had faced the same issue. I found a Hacker News thread discussing the exact problem: Bitwarden does not export attachments in backups. The thread linked to a community feature request for this functionality dating back to May 2018. That’s nearly six years, and the feature still hasn’t been implemented.</p>
<p>Some commenters suggested contributing to the open-source project by submitting a pull request to implement the feature. While that’s a fair point, it’s also worth noting that file attachments are a paid feature. If you’re paying for the product, you might reasonably expect such a basic feature to be included without needing to develop it yourself.</p>
<p>All this is to say: if you’re using attachments in Bitwarden or considering it, I’d recommend either avoiding them or ensuring you save local copies of any files you upload. Personally, I might use this as an opportunity to explore other options like KeePass and see if they better meet my needs.</p>
<p>I hope sharing this experience helps someone avoid losing their attachments in Bitwarden. If you have any questions or comments, feel free to leave them below, and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>Pixel Tablet Unboxing and Initial Impressions | GrapheneOS</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-pixel-tablet-initial-impressions/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-pixel-tablet-initial-impressions/</id>
        <published>2023-06-26T10:00:00Z</published>
        <updated>2023-06-26T10:00:00Z</updated>
        <summary type="html">The Google Pixel Tablet was just released! 12 hours after I received it in the mail, the initial build of GrapheneOS was ready for it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode65s0hbhb">🎥 


<a href="https://youtu.be/jfbz1RzSJh4" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://store.google.com/product/pixel_tablet" target="_blank" rel="noopener" class="text-break">https://store.google.com/product/pixel_tablet</a> - Google Store - Pixel Tablet</li>
<li>


<a href="https://youtu.be/aTf7AMVOoDY" target="_blank" rel="noopener" class="text-break">https://youtu.be/aTf7AMVOoDY</a> - MKBHD Pixel Tablet Overview</li>
<li>


<a href="https://grapheneos.org/" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/</a> - GrapheneOS</li>
<li>


<a href="https://nitter.net/GrapheneOS/status/1671432517285552128" target="_blank" rel="noopener" class="text-break">https://nitter.net/GrapheneOS/status/1671432517285552128</a> - GrapheneOS tweet about initial release for tablet</li>
<li>


<a href="https://hhkeyboard.us/hhkb/Pro-HYBRID-Type-S" target="_blank" rel="noopener" class="text-break">https://hhkeyboard.us/hhkb/Pro-HYBRID-Type-S</a> - HHKB Professional Hybrid Type-S (Mechanical keyboard)</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>I have been waiting a while for this product to be released. This is the Google Pixel tablet. I was initially going to make this an unboxing video, along with a few first impressions. But 12 hours after receiving this tablet in the mail, I saw this tweet from the Graphene OS team that they had an initial build ready. So, I thought I would test it out. This is not going to be an installation guide video; that will be coming out shortly after this one, and I will link it down below once it&rsquo;s ready.</p>
<p>So, as we can see in the box, this is the Pixel tablet with charging speaker dock. So, that&rsquo;s kind of cool to include that for free. I went with the 128-gigabyte version; that&rsquo;s what I normally get whenever I buy a Pixel device.</p>
<p>So, we have two strips on the bottom. First, we have the tablet. Let&rsquo;s get that out of the way. I&rsquo;m going to set that aside for now. And then underneath the tablet, we have some instruction pamphlets. It tells you how to use the dock, tells you how to get started—press the power button, follow the instructions. Thank you, Google.</p>
<p>Here we have the dock that comes with it, and then we have a charging cable just for the dock. This wall adapter is just meant to be plugged into the dock directly; it doesn&rsquo;t have a USB-C connection, so you can&rsquo;t use it with a tablet. But the dock does charge the tablet, so you can always charge it that way. So, let&rsquo;s get this box out of the way.</p>
<p>So, this is the dock for the tablet. I believe it&rsquo;s also a speaker, has a nice fabric finish to it.</p>
<p>So, this is everything in the box: you have the tablet, the dock, and the power adapter. Pretty simple, nothing much. So, let&rsquo;s take a look at the tablet.</p>
<p>On the back, it&rsquo;s plain, kind of has a soft finish to it. I believe it&rsquo;s metal, but there&rsquo;s some kind of coding on here which feels kind of nice. We have the reflective Google logo in the center, along with the four pins that correspond to the four magnetic pins on the dock as well.</p>
<p>So, the actual tablet is a 10.95-inch screen. The resolution is 1600 by 2560. It has an 8-megapixel camera, and it also has the Google Tensor G2, which is the same as the Google Pixel 7. So, just for a quick size comparison, my camera can focus on the front screen. Here is a Google Pixel 6A laying on top of the tablet. So, as you can see, it is much larger, as is to be expected from a tablet.</p>
<p>On the bottom, we have a couple speaker holes along with the USB-C port. On this side, there are some rubber bumpers here, and on the other side, we have what looks pretty similar to a Pixel phone. We have a power button, which is recessed into the actual body of the device, and then we have a rocker, which I&rsquo;m assuming is for volume.</p>
<p>On the front, it might be tough to see, but we do have a circle there, and that is where the front web camera is. And on the back is the rear camera. So, let&rsquo;s go ahead and turn this on. Hold down the power button.</p>
<p>So, usually these devices come charged, but it looks like this one is&hellip; up there it goes. I&rsquo;ll give this a minute to start up. This currently just has stock Android OS on it. I&rsquo;ve never turned this on before, so this is the first boot. We have the standard walkthrough screens.</p>
<p>I&rsquo;m going to set up offline. I&rsquo;m just going to walk through this quick.</p>
<p>So, here we are at the home screen. Let&rsquo;s go find the one part that actually matters, which is OEM unlocking.</p>
<p>So, this looks like it&rsquo;s similar to mobile devices where you need to connect to the internet to enable OEM unlocking. But for now, I&rsquo;m going to take a break from this video. I&rsquo;m going to go ahead and make the installation video, and I will be back here shortly.</p>
<p>So, after I finished filming the installation video, I ran out of time. So, here we are, the next day after I completed the installation. I just powered off the tablet. So, let&rsquo;s turn this on and take a look.</p>
<p>We have our standard screens you expect to see with Graphene OS and an alternate operating system installed.</p>
<p>One of the most shocking things, I think, so far is just how large this screen is. After using Graphene OS on a handheld device for the past two years, it&rsquo;s very odd to see it in such a large form factor.</p>
<p>I didn&rsquo;t realize yesterday, but the buttons are actually on the left side of the device, unlike the mobile devices where the buttons are on the right side.</p>
<p>Don&rsquo;t make your passcode one, two, three, four, five. So, here we are, Graphene OS on the Google Pixel tablet. If you&rsquo;ve ever installed and used Graphene OS before, then you might be familiar with the bare screen that you are presented with, which is a reminder of just how minimal this operating system is. We just have the default apps you expect to see.</p>
<p>Like I mentioned in the intro, there&rsquo;s not going to be much to go into in this video. I just kind of wanted to show that it works, what it looks like, my initial first impressions, which there&rsquo;s not much going on, so not much really to tell. I will have a much more in-depth video in the coming weeks, so stay tuned for that one.</p>
<p>But if we just poke around again, it&rsquo;s great having such a larger display.</p>
<p>Now, since I don&rsquo;t have much to actually talk about the user experience in this video, I did want to talk about why I bought this tablet and what use case I think it can offer. For me, at least, this is much easier to travel around with, the larger display. It&rsquo;s not annoying to use. If I need to do something technical with terminal, it&rsquo;s easy on this display, especially with landscape mode.</p>
<p>You get the full experience. It&rsquo;s like a full-screen computer, and at a 10-inch screen versus the smaller mobile device. And one of the things I recently purchased to use with this, I was actually looking at upgrading the mechanical keyboard I had to something that&rsquo;s a little bit easier to travel with. So, thank you to my friend who recommended this, the HHKB. So, this is a Bluetooth keyboard. It does not have a dongle. That&rsquo;s important to note. So, I wanted to make sure that this would actually work with it. So, I&rsquo;m going to test that out now and see if I can pair it with the device, because to me, if you can get this on a stand and have a keyboard paired with it, at that point you have a nearly fully functional computer, at least for my use cases. That can work, and it&rsquo;s compact, easy to travel with. So, let me pair this quick.</p>
<p>There&rsquo;s the keyboard. Looks like it has paired successfully. So, let&rsquo;s just test out this text box up here.</p>
<p>That looks abysmal on camera. Let&rsquo;s try something else.</p>
<p>So, the keyboard does work. That&rsquo;s pretty awesome. I did order the case for this that comes with a kickstand for it. So, at that point, you kind of have a computer display that you can use.</p>
<p>The other reason I was very excited for this device is that this retails for $499 in the US, and I&rsquo;m not aware of anything else you can get that is as secure and private as the default installation of Graphene OS for that price point. Yes, you can throw Linux on a laptop and have a high level of privacy, but there&rsquo;s nothing at this price point, especially in this form factor, that offers this level of security and privacy combined. So, at this point, I think this is one of the most secure and private devices you could purchase. And with a larger screen, it&rsquo;s extremely usable.</p>
<p>The other thing I really like about this device is it&rsquo;s Wi-Fi only. I&rsquo;ve been in the tech industry for over 10 years, and from everything I&rsquo;ve seen about cellular technologies, I still don&rsquo;t think there&rsquo;s a great way to use them in a secure and private manner. You&rsquo;re always triangulated when you&rsquo;re connected. And yes, some services exist to help anonymize you or to spoof some of the data that&rsquo;s used when you are connecting to those services. But at the end of the day, I think it&rsquo;s a broken technology.</p>
<p>So, now when it comes to Wi-Fi and Ethernet, those technologies I understand, and there are good ways to remain private and secure while using them. So, there&rsquo;s no need to disable cellular connectivity because it does not exist on the tablet.</p>
<p>So, one last thing I want to cover is I did read there might be some initial issues with the dock if you didn&rsquo;t first set up the dock using stock Android OS. So, I just want to test that quick. From what I understand, the smart features of the dock don&rsquo;t work on Graphene OS because those require system-level Play services, and on Graphene OS, sandboxed Play services are installed as normal apps. Therefore, it will not function. But again, it&rsquo;s still too early to tell, but that&rsquo;s what the initial feedback was I saw from the developers on Twitter.</p>
<p>So, the audio works on the tablet, as to be expected.</p>
<p>Here&rsquo;s a YouTube ad, of course.</p>
<p>So, the dock should also function as a speaker when you plug it in. So, I want to test that out quick. Let me plug in the dock.</p>
<p>So, there&rsquo;s nothing indicating the dock is plugged in once you do plug it in. So, I guess it&rsquo;s just on. So, there&rsquo;s a sound that does come out of the dock when you plug it in. So, I guess it&rsquo;s booting up or turning on. And now we can dock the tablet with the four corresponding magnets.</p>
<p>Those are extremely strong magnets. So, if we look here, we can see the tablet is charging. So, the charging functionality works. Let&rsquo;s see if the audio works.</p>
<p>And so, I can confirm that just by doing that, the audio on the speaker is working on the dock. So, it seems like that does work. There&rsquo;s no initial setup needed on the stock Android OS.</p>
<p>As to the other smart features of the dock, like I said, those probably or likely will not work in the future. At least they don&rsquo;t work at this time.</p>
<p>So, to sum up my five minutes of usage with this tablet, I&rsquo;m extremely impressed that within 12 hours after its release, the Graphene OS team had the initial build out there. So far, from my basic usage, it works well. It&rsquo;s also worth noting this is technically a first-generation device. So, if you&rsquo;re looking for something that&rsquo;s perfect from a hardware perspective, this is not that. But at the end of the day, I think the software is more important. And with Graphene OS, we know that it&rsquo;s going to be a secure and private device. And I think, in that regard, it&rsquo;s going to be a really good device for people who are looking for something at this price point.</p>
<p>So, if you&rsquo;re interested in more videos about this tablet, let me know down below. I think in the future I will be making a video about that custom stand I got, as well as any other use cases I find for this device. So, let me know if you&rsquo;re interested in that. I&rsquo;ll have a lot more coming out shortly, so stay tuned.</p>
]]></content>
      </entry>
      <entry>
        <title>Obtainium overview | My favorite way to track Open Source apps</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/obtainium-overview/" />
        <id>https://staging.sideofburritos.com/blog/obtainium-overview/</id>
        <published>2023-03-20T10:00:00Z</published>
        <updated>2023-03-20T10:00:00Z</updated>
        <summary type="html">Using an RSS reader is a popular way to tack OSS apps directly from their source. Obtainium automates this process and simplifies it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode105s0hbhb">🎥 


<a href="https://youtu.be/JiN37bn0OE8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://github.com/ImranR98/Obtainium/issues/25" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium/issues/25</a> - Obtainium Issue 25 | <strong>Help wanted</strong></li>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">https://youtu.be/IzpVI4zaso0</a> - You should uninstall F-Droid - Part 1</li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">https://youtu.be/lAbgeJau3eE</a> - You should uninstall F-Droid - Part 2</li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">https://youtu.be/FFz57zNR_M0</a> - You should use this instead of F-Droid | How to use app RSS feed</li>
<li>


<a href="https://github.com/ImranR98/Obtainium" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium</a> - Obtainium GitHub</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe</a> - NewPipe GitHub</li>
<li>


<a href="https://github.com/bitfireAT/davx5-ose" target="_blank" rel="noopener" class="text-break">https://github.com/bitfireAT/davx5-ose</a> - DAVx⁵ GitHub</li>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/</a> - F-Droid homepage</li>
<li>


<a href="https://github.com/adrcotfas/Goodtime" target="_blank" rel="noopener" class="text-break">https://github.com/adrcotfas/Goodtime</a> - Goodtime Productivity GitHub</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>Six months ago, I made a few videos on F-Droid and why you should stop using it. Shortly after the release of those videos, someone sent me a project on GitHub that says in the readme it was motivated by one of those videos. I didn&rsquo;t start using it then, but I kept an eye on the project.</p>
<p>Now, just over six months later, the project has over 900 stars on GitHub, and it has come a long way, to say the least.</p>
<p>In my original video, I covered how you could manually add the source for APKs you wanted to track and download to an RSS reader. While this method did work, it was cumbersome.</p>
<p>The app I&rsquo;m talking about today is Obtainium, and it aims to automate the process of tracking and updating apps. While it doesn&rsquo;t solve the inherent problem with F-Droid and third-party app repositories, I do think it provides some viable alternatives to help reduce or even eliminate some of those concerns. As always, you should use my advice and experience as a starting point for your own research. Make sure to test and validate everything you hear, especially if you are considering using it.</p>
<p>I&rsquo;m going to cover a few use cases and then talk about my experience the last two weeks using Obtainium on my main device, a Pixel 7. The demo you see today will be from my testing device, which is a Pixel 6A.</p>
<p>So, to obtain Obtainium, we&rsquo;re going to head on over to the official GitHub page. All links will be down below in the description box.</p>
<p>So, we&rsquo;re going to open up our browser and search for Obtainium GitHub. And this first one here is the one we want. And if you scroll down, we&rsquo;re going to select the &ldquo;Get it on GitHub&rdquo; under installation. We&rsquo;re going to expand the assets, and the one we want to select for the Google Pixel is the &ldquo;app-arm64-v8a.&rdquo;</p>
<p>Select that, download anyway. Once that finishes, select &ldquo;Open.&rdquo; If you&rsquo;ve never used your browser to install an app before, you&rsquo;ll have to allow this permission. Once you see the install window pop up, select &ldquo;Install.&rdquo;</p>
<p>Done, and we have now obtained Obtainium. You should now see it on your home screen, or if you swipe up, it should be in your app drawer. Ignore the X Recorder; I&rsquo;ve had some issues with the built-in Android screen recorder, so I&rsquo;m trying a different one.</p>
<p>You can now open the app, allow notifications. Notifications are done locally, so there&rsquo;s no need for Google Play services for notifications to work.</p>
<p>And I first want to start off by saying how refreshing it is to use an open source app that took design into consideration. I&rsquo;ve noticed a lot of times that aesthetics is an afterthought, which is fine, but I think it hurts long-term adoption. I personally have motivation from a security and privacy perspective to use an app, even if the interface is less than ideal. Others who might not have as strong of a motivation to use an app could get quickly turned off by its looks.</p>
<p>So when I first opened Obtainium, I was pleasantly surprised by the design. The developer is very active on this project, so what you see on my screen right now might not be what you see if you&rsquo;re watching this video in the future, but the general overall concept should be the same.</p>
<p>Going through the interface, the first option is the apps. This is our apps list that we&rsquo;re tracking. Obtainium is added here by default so it can track and update itself, so that&rsquo;s pretty handy. We have add app, which we&rsquo;ll come back to shortly. Then we have import/export. If you&rsquo;re currently using an RSS reader like I talked about in my previous videos, there&rsquo;s an option here to import from URLs and file like OPML. The Repla app, the main export type that I had was OPML for its backups, so you could perform an export from that and import it to Obtainium. I didn&rsquo;t test this functionality; I just manually added the apps that I wanted. You can also perform an Obtainium export, so once you get everything set up, that&rsquo;s handy. You can export it, save it, and then if you switch devices or your phone gets lost or stolen, you can always import that backup so you don&rsquo;t need to set it up all over again.</p>
<p>The last option on the bottom is settings. I just left this set to the default, but feel free to change anything you might want.</p>
<p>Now let&rsquo;s add our first app. So select add app. We can see down here listed are the supported sources, and if we look next to GitHub and Codeberg, those are labeled as searchable. So in the second box here, we can search for an app. In this case, I&rsquo;m going to search for NewPipe because that&rsquo;s on GitHub. Search, so you&rsquo;re going to be presented with a lot of results, especially for a project that&rsquo;s popular. But this first one here is the official one, Team NewPipe. Just to be safe, I always suggest that you check first to validate that it is the correct one. So let&rsquo;s go to that repo. We can see here, this is the correct one, the official NewPipe. So once you validate that, we&rsquo;re going to go back, select the first one, and then press pick.</p>
<p>There&rsquo;s a separate section for additional options for GitHub. The first one is to include pre-releases. By default, you should leave this unchecked.</p>
<p>Prereleases technically aren&rsquo;t releases that you should be using, so that&rsquo;s why it&rsquo;s left unchecked by default. The next option is fallback to older releases, and that is enabled by default. This option is for when developers on GitHub do not do the releases correctly, and they might have one release for iPhone and one for Android. If they are listed in different releases, when Obtainium goes to check what the latest version is, if the iPhone one was released latest, it will see that there&rsquo;s no Android APK available to install. Therefore, this option lets it fall back to an older release, which would be the Android version, and you can then update that.</p>
<p>Probably sounds confusing, so just leave that enabled like it is. There&rsquo;s another option here for filter release titles by regular expression. Again, this is for edge cases. I haven&rsquo;t needed this yet for any of the apps I&rsquo;m tracking on my main device. The last option down here is for track only, and what this will do is it will just track it and will not actually try to download the updates and let you install them. I leave this disabled because I want Obtainium to download the APKs for me so I can install them, and then standard version detection, I just leave that set to the default. So those are the options that are listed.</p>
<p>We can now select Add. Obtainium needs permission to install unknown apps, a lot from this source. Let&rsquo;s go back. You&rsquo;ll see this screen next. We can see latest version 0.25.0 installed, a version none. I want to install it. Install done. And now if we go back to our apps list, we can see New Pipe is now here and being tracked. Latest version 0.25 installed version 0.25. Nice clean interface, and as expected, New Pipe is installed.</p>
<p>So, I know that took a few minutes to go through and talk about, but in reality, it only takes 30 seconds to add an app, and now in the future, Obtainium will check for updates in the background and notify you when they are available. As always, you should be skeptical of anything open source or any app for that matter, especially something that will be installing apps on your behalf or for you. So one extra precaution that you can take is to install the app manually first from the source, and then add it to Obtainium. When you install an app, Android pins the certificate and enforces signature checks for app updates, so even if something malicious was happening with Obtainium, it wouldn&rsquo;t be able to install a malicious app update because the signature check would fail.</p>
<p>So as an example, let&rsquo;s go ahead and install Dev X5. I know their source code is on GitHub, so I&rsquo;m going to search for that. I know this is the official repo for it. I&rsquo;m going to go to the releases and download the latest one. Let&rsquo;s open and install that.</p>
<p>So now at this point, Dev X5 has been installed. We downloaded it from the trusted source that we know; therefore, the certificate has been pinned by the OS. So any updates that are installed either manually by us or using Obtainium must pass the signature check, which means that the APK is signed by the developers. We can see Dev X5 was installed. Let&rsquo;s now add it to Obtainium. We just copy this URL, go back to Obtainium, add app, paste in the URL, select add. We can see that it found that Dev X5 is installed, latest version 4.3, installed version 4.3.</p>
<p>There&rsquo;s no updates to install. So now, if we go back, then go back to the apps list, we can now see that DAV X5 is listed there. We installed it from a trusted source, and now we&rsquo;re going to let Obtainium handle any future updates.</p>
<p>There are a few other caveats or features that I want to go over. So, going back to the &ldquo;add app&rdquo; option, we can see here that Malvad and Signal are both listed as sources. If we select one of those, Malvad publishes their APK on their website, so we can just copy this, and Obtainium on our behalf will find the APK for us and download it.</p>
<p>Select &ldquo;add,&rdquo; and we can see in the background downloading Malvadvpn. So it&rsquo;s pretty handy that the developer went ahead and built in this functionality for us already. Even though we&rsquo;re not actually adding the exact page the APK is on for the apps listed there. In this case, Malvad and Signal, the app automatically knows where to look. It&rsquo;s a good minute to finish.</p>
<p>Once it finishes, we&rsquo;re prompted to install. Now, if we go back to the apps list and refresh, we can now see Malvad is shown here and being tracked.</p>
<p>Just to show an example of what updates look like, I went ahead and installed an older version of New Pipe. You&rsquo;ll receive a notification, and then when you go inside the app, you&rsquo;ll see a notification next to the app that needs to be updated. In this case, New Pipe. Select the purple download icon, and you can see the download. So Obtainium went ahead and downloaded the APK for us. We now select &ldquo;update,&rdquo; and now New Pipe was successfully updated.</p>
<p>One of the easiest ways to find where the source code for an open-source app is hosted is to use the F-Droid website. So if we go to f-droid.org in our browser and then scroll down and let&rsquo;s search for New Pipe as an example, the second one is the one we want.</p>
<p>To access the source code for the application, we need to scroll down to the section above the donate button and click on the link to the source code. By examining the URL, we can see that the source code is hosted on GitHub. If we scroll down further to the releases section, we can see that NewPipe publishes their APK on GitHub, which means Obtainium can download it from there.</p>
<p>Returning to fdroid.org, we can find that some developers only publish the APK on F-Droid, even if they have already published the source code on GitHub. As an example, let&rsquo;s search for a productivity app that starts with &ldquo;Good Time,&rdquo; which is the fifth one down. Looking at the source code, we can see that it is also hosted on GitHub. However, when we scroll down to the releases section, we notice that they do not publish the APK on GitHub; only the source code is available. In this scenario, our only option is to return to F-Droid, copy the F-Droid link, and paste it inside Obtainium.</p>
<p>After adding the app and pasting the F-Droid URL, we can see that Obtainium found the app and we can proceed to install it. Upon returning to our list of apps, we can see that Productivity is now installed, and it shows that it is signed by F-Droid.</p>
<p>Using Obtainium is still a better option than the official F-Droid app because it avoids some of the shortcomings mentioned in the previous video, such as targeting out-of-date SDKs. Although the process might seem complicated, it is relatively simple once you go through the steps yourself. It has made the process of downloading, installing, and updating apps much more accessible for the past two weeks, and the update functionality and tracking have worked flawlessly. The experience so far has been enjoyable, and the plan is to continue using it.</p>
<p>However, there are a few limitations to be aware of that are listed on the GitHub readme. The first one is that app installs occur asynchronously, and the success or failure of an install cannot be determined directly. This results in install statuses and versions sometimes being out of sync with the OS until the next launch or until the problem is manually corrected. If you notice any unusual behavior, close the app and relaunch it.</p>
<p>The second limitation, which will be revisited later, is that auto unattended updates are unsupported due to the lack of a capable Flutter plugin. Also, for some sources, data is gathered using web scraping, which can easily break due to changes in website design. In such cases, more reliable methods may be unavailable, and scraping is an unreliable method to gather data. If you have ever used NewPipe and noticed that it broke randomly because YouTube changed its layout one day, that is a similar situation to what the developer is describing here. It is not the app developer&rsquo;s fault, but rather the nature of web scraping.</p>
<p>Regarding the second limitation mentioned above, before making this video, the app developer was contacted to see if there was anything specific they wanted to mention. They requested that any Android developers watching the video take a look at issue number 25, linked below, to help complete the auto-update feature before releasing version one of Obtainium. Contributions to help with that would be greatly appreciated.</p>
<p>Overall, using Obtainium has been a great improvement and has made the manual tracking process much more efficient. Although it is not a solution to the underlying problems that still exist, it is a step in the right direction. The plan is to continue using it, and there are no plans to go back to the RSS reader method.</p>
<p>And while it&rsquo;s not a solution to the underlying problems that still exist, which I covered in my previous videos, it is a great improvement and makes the manual tracking process much more efficient. So, I hope you enjoyed this video. If you did, check out this top one here, and the bottom one has been automatically selected for you.</p>
]]></content>
      </entry>
      <entry>
        <title>Thieves are stealing iPhone pin codes | GrapheneOS settings and protections</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/pin-code-thefts/" />
        <id>https://staging.sideofburritos.com/blog/pin-code-thefts/</id>
        <published>2023-03-13T10:00:00Z</published>
        <updated>2023-03-13T10:00:00Z</updated>
        <summary type="html">The Wall Street Journal recently reported on a trend of iPhone pin codes being stolen.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode108s0hbhb">🎥 


<a href="https://youtu.be/LV6lqQrzqEE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://www.youtube.com/watch?v=KlQFyVF8oW0" target="_blank" rel="noopener" class="text-break">https://www.youtube.com/watch?v=KlQFyVF8oW0</a> - Wall Stree Journal YouTube video</li>
<li>


<a href="https://www.karltarvas.com/2023/02/25/protecting-your-iphone-against-shoulder-surfing-password-theft.html" target="_blank" rel="noopener" class="text-break">https://www.karltarvas.com/2023/02/25/protecting-your-iphone-against-shoulder-surfing-password-theft.html</a> - How to protect your iPhone from password theft.</li>
<li>


<a href="https://support.apple.com/en-us/HT201355" target="_blank" rel="noopener" class="text-break">https://support.apple.com/en-us/HT201355</a> - How to Change your Apple ID password</li>
<li>


<a href="https://www.intego.com/mac-security-blog/if-hackers-crack-a-six-digit-iphone-passcode-they-can-get-all-your-passwords/" target="_blank" rel="noopener" class="text-break">https://www.intego.com/mac-security-blog/if-hackers-crack-a-six-digit-iphone-passcode-they-can-get-all-your-passwords/</a> - If Hackers Crack a Six-Digit iPhone Passcode, They Can Get All Your Passwords</li>
<li>


<a href="https://grapheneos.org/features#auto-reboot" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#auto-reboot</a> - GrapheneOS Auto reboot</li>
<li>


<a href="https://grapheneos.org/features#pin-scrambling" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#pin-scrambling</a> - GrapheneOS PIN scrambling</li>
<li>


<a href="https://grapheneos.org/features#improved-user-profiles" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#improved-user-profiles</a> - GrapheneOS Improved user profiles</li>
<li>


<a href="https://grapheneos.org/features#more-secure-fingerprint-unlock" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#more-secure-fingerprint-unlock</a> - GrapheneOS fingerprint unlock</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>The other day, someone sent me this video from The Wall Street Journal. It was a good video, so if you have some time, you might enjoy watching it. The video covered a situation that&rsquo;s occurring where someone will be at a bar. An individual or a group of individuals will either observe or befriend a Target to determine what their pin code is as they enter it into their device. As it&rsquo;s normal for someone to enter their pin code multiple times while they are out for the evening, they have various chances to figure out what it is.</p>
<p>Once they figure out what the PIN code is, they either swipe the iPhone when the suspect is distracted or they forcefully take it. Now, what happens after that is quick and calculated. The thieves using the PIN code are able to change the victim&rsquo;s password associated with their Apple ID, thus locking them out of their account and rendering finding my iPhone unusable. Once that step is completed, the thieves start draining any Financial accounts on the user&rsquo;s device that uses the PIN code to authenticate. In addition, if the victim uses the iCloud keychain chain, the PIN code can also be used to gain access to that which would then allow them access to any accounts stored in there.</p>
<p>The video goes over in more detail, and if anyone you care about uses an iPhone, consider sending them the video to make them aware of the situation so they can be more cautious. I will also link a post below that has some advice for iPhone owners on steps they can take to protect themselves.</p>
<p>In today&rsquo;s video, I wanted to cover some settings and suggestions you can implement on graphene OS to help with these kinds of attacks. While it&rsquo;s not the exact same scenario, I do think these are useful options. So, the example scenario is that you have a Google pixel running graphene OS, and either you or you and your friends decided to go out and grab a bite to eat or some drinks at a local bar.</p>
<p>The first suggestion I want to make for this type of scenario is to use biometric authentication, which is a fancy way of saying to use your fingerprint. To access that setting, you can go into Settings &gt; Security &gt; Fingerprint unlock. Enter your passcode and you can then set up a new fingerprint to authenticate with. I know some people don&rsquo;t like the idea of using biometric authentication, but the main advantage that using your fingerprint has for authentication is that you can&rsquo;t shoulder surf a fingerprint. Someone can&rsquo;t observe you and gain access to your fingerprint. So in a social setting where others might see you enter a PIN code on your device, using your fingerprint can avoid this altogether.</p>
<p>Graphene OS also has a quick option to disable the fingerprint reader. So let&rsquo;s say you&rsquo;re going through TSA at the airport or a police officer pulls you over, you can press and hold down the power button and then select &ldquo;Lockdown.&rdquo; At this point, biometric authentication is disabled and you need to enter your PIN code to access your device. If you aren&rsquo;t comfortable using biometric authentication, another useful feature is pin scrambling. To access that, go into Settings &gt; Security &gt; Pin scrambling. Go ahead and enable that. What that does is, on your lock screen, the PIN code will be scrambled every time you go to enter it. This means that someone observing you can&rsquo;t determine your PIN code based on the physical location of your finger on the screen when entering your PIN code. And while it&rsquo;s not guaranteed that they can&rsquo;t determine what your PIN code is, it will make it much more difficult and hopefully deter them enough that they pick an easier target.</p>
<p>And while we are on the topic of PIN codes, the longer the PIN code, the better. It&rsquo;s going to be much more difficult to determine a 10-digit PIN code compared to a four-digit PIN code. My next suggestion is to use a separate user profile with a different PIN code from your main owner profile, specifically for situations where you&rsquo;re in a public setting with a large amount of individuals around who could watch you enter your PIN code into your device.</p>
<p>To do that, we&rsquo;re going to go into Settings &gt; System &gt; Multiple users &gt; Enable &ldquo;Allow multiple users&rdquo; &gt; Add user &gt; Set a name for your new user profile. For this example, on this restricted user profile, I&rsquo;m going to leave phone calls and SMS disabled, but as far as apps go, I do think it would be helpful to have NewPipe installed in case I need to look up a video to show someone. Other than that, I won&rsquo;t install any other apps. The &ldquo;Install available apps&rdquo; feature is a convenient feature to install apps on separate user profiles so that you don&rsquo;t need to install a separate App Store on the other user profile.</p>
<p>Separate user profiles are a great way to keep your sensitive apps like banking apps separate from a profile you&rsquo;ll be using in a public setting. So now that we have our new user profile created, you can switch to that by either tapping &ldquo;Switch to&rdquo; and your profile name or you can swipe down, pull down again, tap the user icon in the bottom right, and then select your new user profile.</p>
<p>So you won&rsquo;t be able to see it in the screen recording because it stopped recording when I switched, but all I did was go through the initial profile setup and set a different pin code for my main owner profile. So now here we are in the new user profile. If we swipe up, we can see NewPipe was installed, but Signal was not installed. So now at this point, we have a separate user profile created with a different pin code from our main owner profile that we can use in public settings so that in a worst-case scenario, if someone does get our pin code, they won&rsquo;t have access to our main owner profile with our sensitive data.</p>
<p>I also want to note that every user profile has separate settings, so you will need to enable pin scrambling on this new user profile we just created. The last setting I want to talk about is auto reboot, and this setting is only accessible from the main owner profile. So make sure you switch back to that user profile. To access that, go into Settings &gt; Security &gt; Auto reboot. I like the 12 hours option. What this setting does is it will reboot the phone if there hasn&rsquo;t been any successful unlock within the timeframe selected. This puts the device fully at rest in a pre-first unlock state, which is the most secure state for your data.</p>
<p>The reason this is useful for us is if we&rsquo;re logged into that separate user profile, worst-case scenario someone finds out our pin code, they swipe our device, they now have access to that restricted user profile. Once there is no successful authentication within 12 hours, the device will reboot itself. And now at that point, they need to enter the main owner pin code, which is required to unlock any separate user profiles. The entire device is now inaccessible to them since they don&rsquo;t know the main owner PIN code, and therefore they cannot access that separate user profile we created. For all intents and purposes, your device is a brick to them.</p>
<p>Probably the best protection, at least in the United States, is the fact that you are using an Android device. Most thieves target Apple devices because they have a great resale value and just how connected they are to everything else on the device. So an Android device being less premium is a solid defense.</p>
<p>Those are the ideas that I came up with. If you have any other suggestions, feel free to leave those down below in the comments. And if you enjoyed this video, I think you&rsquo;ll like the top one shown here, and the bottom one has been selected for you based on your viewing habits.</p>
]]></content>
      </entry>
      <entry>
        <title>How to set up Google’s Advanced Protection Program | Secure YouTube Channel</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/googles-advanced-protection-program/" />
        <id>https://staging.sideofburritos.com/blog/googles-advanced-protection-program/</id>
        <published>2022-10-31T10:00:00Z</published>
        <updated>2022-11-02T10:00:00Z</updated>
        <summary type="html">Is your YouTube channel safe? How about your Gmail? Do you have a Google account? Take the necessary steps now to secure your account and protect your future self. It&amp;#39;s much easier to secure your account now, than it is to recover it after a malicious actor has taken it over.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode57s0hbhb">🎥 


<a href="https://youtu.be/ZoUF8bWG5FU" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://landing.google.com/advancedprotection/" target="_blank" rel="noopener" class="text-break">https://landing.google.com/advancedprotection/</a> - Enrollment page</li>
<li>


<a href="https://about.fb.com/news/2022/10/protecting-people-from-malicious-account-compromise-apps/" target="_blank" rel="noopener" class="text-break">https://about.fb.com/news/2022/10/protecting-people-from-malicious-account-compromise-apps/</a> - Facebook/Meta compromised apps</li>
<li>


<a href="https://support.google.com/a/answer/9503534" target="_blank" rel="noopener" class="text-break">https://support.google.com/a/answer/9503534</a> - Advanced Protection Program FAQ</li>
<li>


<a href="https://support.google.com/accounts/answer/9289445" target="_blank" rel="noopener" class="text-break">https://support.google.com/accounts/answer/9289445</a> - Use your phone&rsquo;s built-in security key</li>
<li>


<a href="https://support.google.com/accounts/answer/7519408" target="_blank" rel="noopener" class="text-break">https://support.google.com/accounts/answer/7519408</a> - How Advanced Protection Program works</li>
<li>


<a href="https://support.google.com/accounts/answer/46526" target="_blank" rel="noopener" class="text-break">https://support.google.com/accounts/answer/46526</a> - Google Account Security Checkup</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS - Sensors, Network, Exploit Protection | Changelog 02</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/grapheneos-changelog-02/" />
        <id>https://staging.sideofburritos.com/blog/grapheneos-changelog-02/</id>
        <published>2022-10-24T10:00:00Z</published>
        <updated>2022-10-24T10:00:00Z</updated>
        <summary type="html">GrapheneOS provides access to additional permission toggles that AOSP doesn&amp;#39;t have. One of those toggles is sensors. A recently released feature now allows you to deny the sensors permission by default.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode59s0hbhb">🎥 


<a href="https://youtu.be/0ic6QK0xUMY" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://youtu.be/hx2eiPTe7Zg" target="_blank" rel="noopener" class="text-break">https://youtu.be/hx2eiPTe7Zg</a> - Sensors and Network permission toggle video</li>
<li>


<a href="https://grapheneos.org/features#sensors-permission-toggle" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#sensors-permission-toggle</a> - Sensors permission toggle</li>
<li>


<a href="https://grapheneos.org/features#network-permission-toggle" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#network-permission-toggle</a> - Network permission toggle</li>
<li>


<a href="https://discuss.grapheneos.org/d/502-mahjong-soul-game-constantly-crashing" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/502-mahjong-soul-game-constantly-crashing</a> - Thread discussing Unity memory corruption bug</li>
<li>


<a href="https://grapheneos.org/usage#exec-spawning" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/usage#exec-spawning</a> - Exec spawning</li>
<li>


<a href="https://grapheneos.org/usage#bugs-uncovered-by-security-features" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/usage#bugs-uncovered-by-security-features</a> - Bugs uncovered by security features</li>
<li>


<a href="https://grapheneos.org/features#exploit-mitigations" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#exploit-mitigations</a> - Exploit mitigations</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>YouTube Handles | The security feature we ALL needed</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/youtube-handles/" />
        <id>https://staging.sideofburritos.com/blog/youtube-handles/</id>
        <published>2022-10-17T10:00:00Z</published>
        <updated>2022-10-17T10:00:00Z</updated>
        <summary type="html">YouTube has finally released a feature to help uniquely identify users across the platform. The new YouTube handle feature will help uniquely identify users across the platform, and hopefully make it more difficult for individual to impersonate legitimate users and cut down on scams.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode129s0hbhb">🎥 


<a href="https://youtu.be/ggxSz0e7vrg" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://blog.youtube/press/" target="_blank" rel="noopener" class="text-break">https://blog.youtube/press/</a></li>
<li>


<a href="https://blog.youtube/news-and-events/introducing-handles-a-new-way-to-identify-your-youtube-channel/" target="_blank" rel="noopener" class="text-break">https://blog.youtube/news-and-events/introducing-handles-a-new-way-to-identify-your-youtube-channel/</a></li>
<li>


<a href="https://www.youtube.com/watch?v=1Cw-vODp-8Y" target="_blank" rel="noopener" class="text-break">https://www.youtube.com/watch?v=1Cw-vODp-8Y</a> - Video: YouTube Needs to Fix This</li>
<li>


<a href="https://www.youtube.com/watch?v=w3QxMFwQAfM" target="_blank" rel="noopener" class="text-break">https://www.youtube.com/watch?v=w3QxMFwQAfM</a> - Video: YouTube Comment Giveaway SCAMS ft. Pleasant Green</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Why you probably don&#39;t need a VPN | Do I need a VPN?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/why-you-probably-dont-need-a-vpn/" />
        <id>https://staging.sideofburritos.com/blog/why-you-probably-dont-need-a-vpn/</id>
        <published>2022-10-10T10:00:00Z</published>
        <updated>2022-10-10T10:00:00Z</updated>
        <summary type="html">The first task on every privacy blog is “get a VPN”. I no longer think this advice holds true. While there are scenarios where a VPN service can be beneficial, a lot of the original use cases are no longer valid.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode126s0hbhb">🎥 


<a href="https://youtu.be/BE33daPiaYQ" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://matt.traudt.xyz/posts/2019-10-17-you-want-tor-browser-not-a-vpn/" target="_blank" rel="noopener" class="text-break">https://matt.traudt.xyz/posts/2019-10-17-you-want-tor-browser-not-a-vpn/</a></li>
<li>


<a href="https://madaidans-insecurities.github.io/index.html" target="_blank" rel="noopener" class="text-break">https://madaidans-insecurities.github.io/index.html</a></li>
<li>


<a href="https://privsec.dev/knowledge/commercial-vpn-use-cases/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/knowledge/commercial-vpn-use-cases/</a></li>
<li>


<a href="https://www.cnet.com/home/internet/ftc-calls-out-internet-providers-for-amassing-user-browsing-data/" target="_blank" rel="noopener" class="text-break">https://www.cnet.com/home/internet/ftc-calls-out-internet-providers-for-amassing-user-browsing-data/</a></li>
<li>


<a href="https://blog.james.cridland.net/why-you-probably-dont-need-a-vpn-e7bb35e7d744" target="_blank" rel="noopener" class="text-break">https://blog.james.cridland.net/why-you-probably-dont-need-a-vpn-e7bb35e7d744</a></li>
<li>


<a href="https://www.tomsguide.com/news/you-may-no-longer-need-vpn" target="_blank" rel="noopener" class="text-break">https://www.tomsguide.com/news/you-may-no-longer-need-vpn</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Progressive Web Apps | How they work &#43; Security &amp; Privacy</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/progressive-web-apps-explained/" />
        <id>https://staging.sideofburritos.com/blog/progressive-web-apps-explained/</id>
        <published>2022-09-19T10:00:00Z</published>
        <updated>2022-09-19T10:00:00Z</updated>
        <summary type="html">Is there an app that makes you cringe that you have it installed because of the privacy issues with it? Progressive Web Apps might be a great alternative for you.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode110s0hbhb">🎥 


<a href="https://youtu.be/crF0c96pXhI" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://appsco.pe/" target="_blank" rel="noopener" class="text-break">https://appsco.pe/</a> - Site with list of Progressive Web Apps</li>
<li>


<a href="https://medium.com/@amberleyjohanna/seriously-though-what-is-a-progressive-web-app-56130600a093" target="_blank" rel="noopener" class="text-break">https://medium.com/@amberleyjohanna/seriously-though-what-is-a-progressive-web-app-56130600a093</a> - What is a Progressive Web App?</li>
<li>


<a href="https://developer.mozilla.org/en-US/docs/Web/Manifest" target="_blank" rel="noopener" class="text-break">https://developer.mozilla.org/en-US/docs/Web/Manifest</a> - Web app manifests</li>
<li>


<a href="https://web.dev/learn/pwa/service-workers/" target="_blank" rel="noopener" class="text-break">https://web.dev/learn/pwa/service-workers/</a> - Service Workers</li>
<li>


<a href="https://infrequently.org/2015/06/progressive-apps-escaping-tabs-without-losing-our-soul/" target="_blank" rel="noopener" class="text-break">https://infrequently.org/2015/06/progressive-apps-escaping-tabs-without-losing-our-soul/</a> - Alex Russell post about &ldquo;websites that took all the right vitamins.&rdquo;</li>
<li>


<a href="https://blog.nviso.eu/2020/01/16/deep-dive-into-the-security-of-progressive-web-apps/" target="_blank" rel="noopener" class="text-break">https://blog.nviso.eu/2020/01/16/deep-dive-into-the-security-of-progressive-web-apps/</a> - Progressive Web App security</li>
<li>


<a href="https://www.simicart.com/blog/pwa-hardware-access/" target="_blank" rel="noopener" class="text-break">https://www.simicart.com/blog/pwa-hardware-access/</a> - Progressive Web App and hardware access</li>
<li>


<a href="https://asperbrothers.com/blog/pwa-vs-native-app/" target="_blank" rel="noopener" class="text-break">https://asperbrothers.com/blog/pwa-vs-native-app/</a> - PWA vs Native App</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>GrapheneOS Sensors and Network Permission Toggle</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/sensors-network-toggle/" />
        <id>https://staging.sideofburritos.com/blog/sensors-network-toggle/</id>
        <published>2022-08-21T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">GrapheneOS provides access to two additional permission toggles that are not available on stock Android OS.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode118s0hbhb">🎥 


<a href="https://youtu.be/hx2eiPTe7Zg" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://grapheneos.org/features#network-permission-toggle" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#network-permission-toggle</a> - GrapheneOS Sensors and Network permission toggle documentation</li>
<li>


<a href="https://github.com/GrapheneOS/os-issue-tracker/issues/597" target="_blank" rel="noopener" class="text-break">https://github.com/GrapheneOS/os-issue-tracker/issues/597</a> - GitHub issue referenced regarding default sensor permission seting for system apps</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You&#39;re probably doing it wrong | Multi-Factor Authentication Explained</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/mfa-explained/" />
        <id>https://staging.sideofburritos.com/blog/mfa-explained/</id>
        <published>2022-08-15T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Your username and password is only one layer of protection, add a second layer with MFA.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode99s0hbhb">🎥 


<a href="https://youtu.be/PV39P6aeyCc" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://privsec.dev/knowledge/multi-factor-authentication/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/knowledge/multi-factor-authentication/</a> - PrivSec.dev article - great read</li>
<li>


<a href="https://www.yubico.com/product/yubikey-5c-nfc/" target="_blank" rel="noopener" class="text-break">https://www.yubico.com/product/yubikey-5c-nfc/</a> - YubiKey 5C NFC I purchased</li>
<li>


<a href="https://www.dongleauth.com/" target="_blank" rel="noopener" class="text-break">https://www.dongleauth.com/</a> - Check the services you use for MFA support</li>
<li>


<a href="https://portswigger.net/daily-swig/researchers-trick-duo-2fa-into-sending-authentication-request-to-attacker-controlled-device" target="_blank" rel="noopener" class="text-break">https://portswigger.net/daily-swig/researchers-trick-duo-2fa-into-sending-authentication-request-to-attacker-controlled-device</a> - Duo 2FA article</li>
<li>


<a href="https://fidoalliance.org/fido2/" target="_blank" rel="noopener" class="text-break">https://fidoalliance.org/fido2/</a></li>
<li>


<a href="https://blog.cloudflare.com/2022-07-sms-phishing-attacks/" target="_blank" rel="noopener" class="text-break">https://blog.cloudflare.com/2022-07-sms-phishing-attacks/</a> - Cloudflare stopping phishing scam with hardware tokens</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>How your phones&#39; wallpaper can be used to track you</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/wallpaper-privacy/" />
        <id>https://staging.sideofburritos.com/blog/wallpaper-privacy/</id>
        <published>2022-08-07T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Is that family photo a simple personalization to your wallpaper, or is that being used to track you?</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode123s0hbhb">🎥 


<a href="https://youtu.be/cwLRiadmfaQ" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://fingerprint.com/blog/how-android-wallpaper-images-threaten-privacy/" target="_blank" rel="noopener" class="text-break">https://fingerprint.com/blog/how-android-wallpaper-images-threaten-privacy/</a> - privacy.com main article referenced</li>
<li>


<a href="https://github.com/fingerprintjs/blog-android-wallpaper-id-demo" target="_blank" rel="noopener" class="text-break">https://github.com/fingerprintjs/blog-android-wallpaper-id-demo</a> - WallpaperID App used in demo</li>
<li>


<a href="https://developer.android.com/reference/android/app/WallpaperManager#getWallpaperColors%28int%29" target="_blank" rel="noopener" class="text-break">https://developer.android.com/reference/android/app/WallpaperManager#getWallpaperColors(int)</a> - Android source code - getWallpaperColors</li>
<li>


<a href="https://cs.android.com/android/platform/superproject/&#43;/master:frameworks/base/core/java/com/android/internal/graphics/palette/VariationalKMeansQuantizer.java;l=31?q=KMeansQua&amp;ss=android%2Fplatform%2Fsuperproject" target="_blank" rel="noopener" class="text-break">https://cs.android.com/android/platform/superproject/+/master:frameworks/base/core/java/com/android/internal/graphics/palette/VariationalKMeansQuantizer.java;l=31?q=KMeansQua&ss=android%2Fplatform%2Fsuperproject</a> - getWallpaperColors source code - K-means clustering</li>
<li>


<a href="https://www.clear.rice.edu/elec301/Projects02/artSpy/patmac/RGB.jpg" target="_blank" rel="noopener" class="text-break">https://www.clear.rice.edu/elec301/Projects02/artSpy/patmac/RGB.jpg</a> - 3D color cube</li>
<li>


<a href="https://clarle.github.io/yui3/yui/docs/color/rgb-slider.html" target="_blank" rel="noopener" class="text-break">https://clarle.github.io/yui3/yui/docs/color/rgb-slider.html</a> - RGB sliders</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Most Secure Phone 2022 | DeGoogle Your Phone | Google Pixel 6?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/most-secure-phone-2022/" />
        <id>https://staging.sideofburritos.com/blog/most-secure-phone-2022/</id>
        <published>2022-05-22T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Could the Google Pixel 6 be the most secure phone in 2022? With five years of security upgrades and the most layers of hardware security, the Pixel 6 and Pixel 6 Pro are the most secure Pixel phones yet.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode101s0hbhb">🎥 


<a href="https://youtu.be/1nj3vnHvn84" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://security.googleblog.com/2021/10/pixel-6-setting-new-standard-for-mobile.html" target="_blank" rel="noopener" class="text-break">https://security.googleblog.com/2021/10/pixel-6-setting-new-standard-for-mobile.html</a> - Pixel 6 New Security Features</li>
<li>


<a href="https://source.android.com/security/biometric" target="_blank" rel="noopener" class="text-break">https://source.android.com/security/biometric</a></li>
<li>


<a href="https://www.wired.com/story/google-pixel-6-tensor-chip-security/" target="_blank" rel="noopener" class="text-break">https://www.wired.com/story/google-pixel-6-tensor-chip-security/</a></li>
<li>


<a href="https://www.engadget.com/google-tensor-soc-pixel-6-chip-170059466.html" target="_blank" rel="noopener" class="text-break">https://www.engadget.com/google-tensor-soc-pixel-6-chip-170059466.html</a></li>
<li>


<a href="https://cpl.thalesgroup.com/2014/01/14/random-numbers-and-cryptography" target="_blank" rel="noopener" class="text-break">https://cpl.thalesgroup.com/2014/01/14/random-numbers-and-cryptography</a></li>
<li>


<a href="https://www.androidcentral.com/what-titan-security-module" target="_blank" rel="noopener" class="text-break">https://www.androidcentral.com/what-titan-security-module</a></li>
<li>


<a href="https://www.androidcentral.com/how-does-google-titan-m2-and-tensor-security-core-work" target="_blank" rel="noopener" class="text-break">https://www.androidcentral.com/how-does-google-titan-m2-and-tensor-security-core-work</a></li>
<li>


<a href="https://www.androidcentral.com/what-titan-security-module" target="_blank" rel="noopener" class="text-break">https://www.androidcentral.com/what-titan-security-module</a></li>
<li>


<a href="https://source.android.com/security/trusty" target="_blank" rel="noopener" class="text-break">https://source.android.com/security/trusty</a></li>
<li>


<a href="https://arstechnica.com/gadgets/2021/11/pixel-6-review-google-hardware-finally-lives-up-to-its-potential/" target="_blank" rel="noopener" class="text-break">https://arstechnica.com/gadgets/2021/11/pixel-6-review-google-hardware-finally-lives-up-to-its-potential/</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Secure Contacts Storage | Free Cloud Storage Android | Nextcloud</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/secure-contacts-app/" />
        <id>https://staging.sideofburritos.com/blog/secure-contacts-app/</id>
        <published>2022-05-22T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">If you&amp;#39;re looking to regain your privacy, it&amp;#39;s time to use Nextcloud. Storing your contacts with Google or Apple gives them all the details on whom you&amp;#39;re in contact with.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode116s0hbhb">🎥 


<a href="https://youtu.be/NJzA9yRGgeM" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://nextcloud.com" target="_blank" rel="noopener" class="text-break">https://nextcloud.com</a> Nextcloud Homepage</li>
<li>


<a href="https://nextcloud.com/signup/" target="_blank" rel="noopener" class="text-break">https://nextcloud.com/signup/</a> - Nextcloud Account Signup</li>
<li>


<a href="https://www.howtogeek.com/448829/how-to-export-apple-icloud-and-iphone-contacts-to-windows-10/" target="_blank" rel="noopener" class="text-break">https://www.howtogeek.com/448829/how-to-export-apple-icloud-and-iphone-contacts-to-windows-10/</a> - How to export iCloud contacts</li>
<li>


<a href="https://support.google.com/contacts/answer/7199294?hl=en&amp;co=GENIE.Platform=Desktop" target="_blank" rel="noopener" class="text-break">https://support.google.com/contacts/answer/7199294?hl=en&co=GENIE.Platform=Desktop</a> - How to export Google Contacts</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>So you just installed GrapheneOS, now what?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/just-installed-grapheneos/" />
        <id>https://staging.sideofburritos.com/blog/just-installed-grapheneos/</id>
        <published>2022-05-14T14:51:16Z</published>
        <updated>2022-08-10T14:51:16Z</updated>
        <summary type="html">GrapheneOS can look a little intimidating at first. I&amp;#39;ll cover the default apps that come with the OS and the app stores to install to get you started.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode96s0hbhb">🎥 


<a href="https://youtu.be/to67NVB7qo8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="other-tutorial-videos-referenced">Other tutorial videos referenced</h2>
<ul>
<li>


<a href="https://youtu.be/ocwznyrMVwE" target="_blank" rel="noopener" class="text-break">https://youtu.be/ocwznyrMVwE</a> - GrapheneOS calendar setup</li>
<li>


<a href="https://youtu.be/NJzA9yRGgeM" target="_blank" rel="noopener" class="text-break">https://youtu.be/NJzA9yRGgeM</a> - GrapheneOS contacts setup</li>
<li>


<a href="https://youtu.be/eyWmcItzisk" target="_blank" rel="noopener" class="text-break">https://youtu.be/eyWmcItzisk</a> - GrapheneOS phone backup</li>
<li>


<a href="https://youtu.be/SZ0PKtiXTSs" target="_blank" rel="noopener" class="text-break">https://youtu.be/SZ0PKtiXTSs</a> - GrapheneOS Google Play Services install</li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://attestation.app/about" target="_blank" rel="noopener" class="text-break">https://attestation.app/about</a> - Auditor App details</li>
<li>


<a href="https://github.com/GrapheneOS/Vanadium" target="_blank" rel="noopener" class="text-break">https://github.com/GrapheneOS/Vanadium</a> - Vanadium Browser details</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid Store</li>
<li>


<a href="https://auroraoss.com" target="_blank" rel="noopener" class="text-break">https://auroraoss.com</a> - Aurora Store</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>uBlock Origin - Bounce Tracking Prevention | Browser Privacy</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/ublock-origin-bounce-tracking-prevention/" />
        <id>https://staging.sideofburritos.com/blog/ublock-origin-bounce-tracking-prevention/</id>
        <published>2022-04-24T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">uBlock Origin does more than you might realize. Preventing bounce tracking is a huge feature of it, often overlooked.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode121s0hbhb">🎥 


<a href="https://youtu.be/DZQvTc-t9js" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://github.com/gorhill/uBlock/wiki/Strict-blocking" target="_blank" rel="noopener" class="text-break">https://github.com/gorhill/uBlock/wiki/Strict-blocking</a> - uBlock Origin example documented</li>
<li>


<a href="https://www.pcgamingwiki.com/wiki/Dead_Rising_2" target="_blank" rel="noopener" class="text-break">https://www.pcgamingwiki.com/wiki/Dead_Rising_2</a> - You can click the &ldquo;Green Man Gaming&rdquo; link here if you want to follow along</li>
<li>


<a href="https://www.dpbolvw.net/click-6723194-10912384?url=https://www.greenmangaming.com/games/dead-rising-2/?tap_a=1964-996bbb&amp;tap_s=341948-7fd0d2" target="_blank" rel="noopener" class="text-break">https://www.dpbolvw.net/click-6723194-10912384?url=https://www.greenmangaming.com/games/dead-rising-2/?tap_a=1964-996bbb&tap_s=341948-7fd0d2</a> - <strong>Direct link to click tracker, only click if you have uBlock Origin installed</strong></li>
<li>


<a href="https://en.wikipedia.org/wiki/Query_string" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Query_string</a></li>
<li>


<a href="https://brave.com/privacy-updates/8-grab-bag-2/" target="_blank" rel="noopener" class="text-break">https://brave.com/privacy-updates/8-grab-bag-2/</a></li>
<li>


<a href="https://arstechnica.com/information-technology/2022/03/brave-has-a-plan-to-stymie-websites-that-override-your-privacy-settings/?comments=1" target="_blank" rel="noopener" class="text-break">https://arstechnica.com/information-technology/2022/03/brave-has-a-plan-to-stymie-websites-that-override-your-privacy-settings/?comments=1</a></li>
<li>


<a href="https://brave.com/privacy-updates/16-unlinkable-bouncing/" target="_blank" rel="noopener" class="text-break">https://brave.com/privacy-updates/16-unlinkable-bouncing/</a></li>
<li>


<a href="https://brave.com/privacy-updates/8-grab-bag-2/" target="_blank" rel="noopener" class="text-break">https://brave.com/privacy-updates/8-grab-bag-2/</a></li>
<li>


<a href="https://www.pcgamingwiki.com/wiki/Dead_Rising_2" target="_blank" rel="noopener" class="text-break">https://www.pcgamingwiki.com/wiki/Dead_Rising_2</a></li>
<li>


<a href="https://forums.tomshardware.com/threads/http-www-dpbolvw-net-whenever-i-click-a-link-it-redirects-me-here.940336/" target="_blank" rel="noopener" class="text-break">https://forums.tomshardware.com/threads/http-www-dpbolvw-net-whenever-i-click-a-link-it-redirects-me-here.940336/</a></li>
</ul>
<h2 id="ublock-origin-download-links">uBlock Origin Download Links</h2>
<ul>
<li>


<a href="https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm" target="_blank" rel="noopener" class="text-break">https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm</a> - Chrome/Chromium</li>
<li>


<a href="https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/" target="_blank" rel="noopener" class="text-break">https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/</a> - Firefox</li>
<li>


<a href="https://microsoftedge.microsoft.com/addons/detail/ublock-origin/odfafepnkmbhccpbejgmiehpchacaeak?node=10232440011" target="_blank" rel="noopener" class="text-break">https://microsoftedge.microsoft.com/addons/detail/ublock-origin/odfafepnkmbhccpbejgmiehpchacaeak?node=10232440011</a> - Microsoft Edge</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Browser Privacy | Cookieless Tracking - ETag</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/browser-privacy-cookieless-tracking-etag/" />
        <id>https://staging.sideofburritos.com/blog/browser-privacy-cookieless-tracking-etag/</id>
        <published>2022-04-17T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Cookies may be on their way out, but tracking users is not. As with most thing, if one method gets restricted companies always seem to find another way.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode48s0hbhb">🎥 


<a href="https://youtu.be/rsET1-e0acc" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="firefox-users">Firefox Users</h2>
<p>For some reason, I wasn&rsquo;t able to get Firefox to send a blank header even with the <code>Empty header mode</code> enabled. Perhaps it&rsquo;s something with the browser. As a workaround, enter a <code>space</code> in the <code>Value</code> box once you get to step 5. Click the <code>Value</code> box, and hit your space bar once. After that, everything should work as expected. If you know why it&rsquo;s not working, please <a href="https://staging.sideofburritos.com/contact/">reach out</a>.</p>
<hr>
<h2 id="how-to-send-an-empty-if-none-match-http-header">How to send an empty &lsquo;If-None-Match&rsquo; HTTP header</h2>
<ol>
<li>Download and install the extension/add-on <code>ModHeader</code> for your browser (links below)</li>
<li>After the install has completed, click the icon in the menu bar.</li>
<li>Click the <code>+</code> and click <code>Request Header</code>.</li>
<li>In the <code>Name</code> box enter <code>If-None-Match</code>. Since we want to send an empty header, leave the <code>Value</code> box empty (Firefox users enter a space).</li>
</ol>
<h3 id="in-order-to-send-an-empty-header-we-much-enable-the-option-in-the-extensionadd-on">In order to send an empty header, we much enable the option in the extension/add-on.</h3>
<ol>
<li>Click the 3 vertical dots in the top right corner of the extension/add-on settings box.</li>
<li>Scroll to the bottom where you will see the heading <code>Empty header mode</code>.</li>
<li>Select the <code>Send empty header</code> option.</li>
</ol>
<p>Your configuration should look similar to <a href="Browser_Privacy_Cookieless_Tracking_ETag_ModHeader_Config.webp">this image</a></p>
<p>At this point your browser is now configured to send an empty <code>If-None-Match</code> HTTP Header. To test, visit the follow URL - 


<a href="https://hinternesch.com/page1.html" target="_blank" rel="noopener" class="text-break">https://hinternesch.com/page1.html</a>. If everything is working as expected, you should see <code>Your ID is .</code> if you see something else, then it&rsquo;s not working as expected.</p>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://levelup.gitconnected.com/no-cookies-no-problem-using-etags-for-user-tracking-3e745544176b" target="_blank" rel="noopener" class="text-break">https://levelup.gitconnected.com/no-cookies-no-problem-using-etags-for-user-tracking-3e745544176b</a> - Main article referenced</li>
<li>


<a href="https://hinternesch.com/page1.html" target="_blank" rel="noopener" class="text-break">https://hinternesch.com/page1.html</a> - ETag tracking example website from article</li>
<li>


<a href="https://www.wendys.com/cookies-and-tracking-2020" target="_blank" rel="noopener" class="text-break">https://www.wendys.com/cookies-and-tracking-2020</a> - Wendy&rsquo;s Cookies and Tracking Policy</li>
<li>


<a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Caching" target="_blank" rel="noopener" class="text-break">https://developer.mozilla.org/en-US/docs/Web/HTTP/Caching</a> - Mozillia HTTP caching wiki</li>
</ul>
<h2 id="modheader-download-links">ModHeader Download Links</h2>
<ul>
<li>


<a href="https://chrome.google.com/webstore/detail/modheader/idgpnmonknjnojddfkpgkljpfnnfcklj" target="_blank" rel="noopener" class="text-break">https://chrome.google.com/webstore/detail/modheader/idgpnmonknjnojddfkpgkljpfnnfcklj</a> - Chrome/Chromium</li>
<li>


<a href="https://addons.mozilla.org/en-US/firefox/addon/modheader-firefox/" target="_blank" rel="noopener" class="text-break">https://addons.mozilla.org/en-US/firefox/addon/modheader-firefox/</a> - Mozillia Firefox</li>
<li>


<a href="https://microsoftedge.microsoft.com/addons/detail/modheader/opgbiafapkbbnbnjcdomjaghbckfkglc" target="_blank" rel="noopener" class="text-break">https://microsoftedge.microsoft.com/addons/detail/modheader/opgbiafapkbbnbnjcdomjaghbckfkglc</a> - Microsoft Edge</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Browser Cookies and Privacy</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/browser-cookies-and-privacy/" />
        <id>https://staging.sideofburritos.com/blog/browser-cookies-and-privacy/</id>
        <published>2022-04-09T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">Cookies directly affect your privacy. Not all cookies are equal, and they all serve different purposes. Cookies perform important and sometimes necessary services on the internet.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode44s0hbhb">🎥 


<a href="https://youtu.be/qI2EDsBurQQ" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="blocking-cookies">Blocking Cookies</h2>
<h3 id="how-to-block-third-party-cookies-in-firefox">How to block Third-Party Cookies in Firefox</h3>
<ol>
<li>Click the hamburger (settings) menu in the top right → select settings.</li>
<li>Select <code>Privacy &amp; Security</code> on the left.</li>
<li>Under <code>Enhanced Tracking Protection</code> select <code>Custom</code></li>
<li>Check the <code>Cookies</code> box, click the dropdown next to it, and select <code>All third-party cookies</code></li>
<li>BONUS - Also check the boxes for <code>Tracking content</code>, <code>Cryptominers</code>, and <code>Fingerprinters</code>.</li>
</ol>
<h3 id="how-to-block-third-party-cookies-in-chromechromium">How to block Third-Party Cookies in Chrome/Chromium</h3>
<ol>
<li>Click the vertical 3 dot menu in the top right → select settings.</li>
<li>Select <code>Privacy and Security</code> on the left.</li>
<li>Click <code>Cookies and other site data</code></li>
<li>Under <code>Generatl settings</code> select the <code>Block third-party cookies</code> radio button.</li>
</ol>
<h3 id="how-to-block-third-party-cookies-in-safari">How to block Third-Party Cookies in Safari</h3>
<ol>
<li>Click <code>Safari</code> in the top menu bar and select <code>Preferences...</code>.</li>
<li>Select the <code>Privacy</code> tab.</li>
<li>Check the box next to <code>Website tracking:</code> that says <code>Prevent cross-site tracking</code></li>
</ol>
<h3 id="how-to-block-third-party-cookies-in-microsoft-edge">How to block Third-Party Cookies in Microsoft Edge</h3>
<ol>
<li>Download 


<a href="https://www.mozilla.org/en-US/firefox/new/" target="_blank" rel="noopener" class="text-break">Firefox</a>&hellip;just kidding.</li>
<li>Click the horizontal 3 dot menu in the top right → select settings.</li>
<li>Select <code>Cookies and site permissions</code> on the left.</li>
<li>Under <code>Cookies and data stored</code> click <code>Manage and delete cookies and site data</code>.</li>
<li>Click the button next to <code>Block third-party cookies</code>.</li>
</ol>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.facesofopensource.com/person/lou-montulli/" target="_blank" rel="noopener" class="text-break">https://www.facesofopensource.com/person/lou-montulli/</a> - Stunning photos of individuals who contributed to the development and advancement of Open Source Software.</li>
<li>


<a href="https://www.techopedia.com/definition/8207/magic-cookie" target="_blank" rel="noopener" class="text-break">https://www.techopedia.com/definition/8207/magic-cookie</a></li>
<li>


<a href="https://www.cnet.com/tech/services-and-software/aol-buys-netscape-for-4-2-billion/" target="_blank" rel="noopener" class="text-break">https://www.cnet.com/tech/services-and-software/aol-buys-netscape-for-4-2-billion/</a></li>
<li>


<a href="https://www.cookiepro.com/knowledge/what-is-a-session-cookie/" target="_blank" rel="noopener" class="text-break">https://www.cookiepro.com/knowledge/what-is-a-session-cookie/</a></li>
<li>


<a href="https://www.invisibly.com/learn-blog/companies-selling-your-personal-data" target="_blank" rel="noopener" class="text-break">https://www.invisibly.com/learn-blog/companies-selling-your-personal-data</a></li>
<li>


<a href="https://www.cloudflare.com/learning/privacy/what-are-cookies/" target="_blank" rel="noopener" class="text-break">https://www.cloudflare.com/learning/privacy/what-are-cookies/</a></li>
<li>


<a href="https://en.wikipedia.org/wiki/Shopping_cart_software" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Shopping_cart_software</a></li>
<li>


<a href="https://en.wikipedia.org/wiki/HTTP_cookie" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/HTTP_cookie</a></li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>Secure Calendar Storage | Free Cloud Storage | Android  Nextcloud</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/secure-calendar-app/" />
        <id>https://staging.sideofburritos.com/blog/secure-calendar-app/</id>
        <published>2022-03-20T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">If you&amp;#39;re looking to regain your privacy, it&amp;#39;s time to use Nextcloud. Storing your calendar events with Google or Apple gives them all the details on whom you&amp;#39;re in contact with.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode115s0hbhb">🎥 


<a href="https://youtu.be/ocwznyrMVwE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://nextcloud.com" target="_blank" rel="noopener" class="text-break">https://nextcloud.com</a> Nextcloud Homepage</li>
<li>


<a href="https://nextcloud.com/signup/" target="_blank" rel="noopener" class="text-break">https://nextcloud.com/signup/</a> - Nextcloud Account Signup</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid App Store</li>
<li>


<a href="https://www.akruto.com/backup-phone-contacts-calendar/export-icloud-calendar-as-ical/" target="_blank" rel="noopener" class="text-break">https://www.akruto.com/backup-phone-contacts-calendar/export-icloud-calendar-as-ical/</a> - How to export iCloud calendar</li>
<li>


<a href="https://support.google.com/calendar/answer/37111?hl=en" target="_blank" rel="noopener" class="text-break">https://support.google.com/calendar/answer/37111?hl=en</a> - How to export Google Calendar</li>
</ul>
]]></content>
      </entry>

</feed>
