<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>GrapheneOS &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/grapheneos/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Sat, 28 Jun 2025 20:36:24 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>GrapheneOS &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[Contactless Payments with GrapheneOS]]></title>
		<link>https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/</link>
					<comments>https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sun, 29 Jun 2025 11:34:57 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[GrapheneOS]]></category>
		<category><![CDATA[nfc]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=61636</guid>

					<description><![CDATA[Google&#039;s monopolistic stranglehold on Android results in poor experience for power-users, and artificially restricts choice for those who have older phones.  For example, Google Wallet is the de facto way to use NFC payments on Android. There&#039;s one problem though - it only works with Google&#039;s Android.  If you have the temerity to install a 3rd party Android OS - like the hyper-secure GrapheneOS - …]]></description>
										<content:encoded><![CDATA[<p>Google's monopolistic stranglehold on Android results in poor experience for power-users, and artificially restricts choice for those who have older phones.  For example, Google Wallet is the <i lang="la">de facto</i> way to use NFC payments on Android. There's one problem though - it only works with <em>Google's</em> Android.  If you have the temerity to install a 3rd party Android OS - like the hyper-secure <a href="https://grapheneos.org/">GrapheneOS</a> - you'll be locked out of it.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2025/06/GPay-fs8.png" alt="This device can't be set up to pay contactless. Your device doesn't meet pay contactless security standards. It may be rooted or running uncertified software." width="504" class="aligncenter size-full wp-image-61637">

<p>First of all, Google is lying. It <em>does</em> meet security standards and it is <em>not</em> rooted.  I get that <a href="https://shkspr.mobi/blog/2023/05/the-limits-of-general-purpose-computation/">I have no right to run someone else's software in an environment they don't like</a>, but this is just misinformation.  3rd party OSes are often <em>more</em> secure that a stock OS which has been left to rot by an unresponsive manufacturer.</p>

<p>Anyway, here's how you can use contactless payments on Graphene.</p>

<h2 id="prerequisites"><a href="https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#prerequisites">Prerequisites</a></h2>

<p>I'm going to tell you what I did. If you found another way, leave a comment or write your own blog post.</p>

<p>I'm using the latest version of Graphene (2025062000) with Play Services installed. The app is running in my main profile. None of the advanced app protection has been toggled for the app. NFC is on.</p>

<p>You will have to agree to <a href="https://www.curve.com/legal/privacy/">Curve's privacy policy</a>. And the privacy policy of your credit card. Look, if you're using Graphene, you're probably overly privacy sensitive. If you're concerned about The Man™ knowing that you used your card to buy a breakfast beer and then sharing that with 958 trusted partners, just use cash instead.</p>

<h2 id="install-curve"><a href="https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#install-curve">Install Curve</a></h2>

<p><a href="https://www.curve.com/join#D4MK9ZKN">Here's a referral link to install Curve</a> - join and you get £10.  Or, you can <a href="https://play.google.com/store/apps/details?id=com.imaginecurve.curve.prd">install directly from the Play Store</a>.</p>

<p>You'll need to create an account and pass KYC / AML checks. <a href="https://www.fca.org.uk/consumers/fca-firm-checker/firm-10456-925447">Curve are regulated by the FCA</a> so you should feel safe giving your details to them.</p>

<h2 id="add-a-card"><a href="https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#add-a-card">Add a card</a></h2>

<p>Curve is a <em>virtual</em> card provider. So add your existing Visa or MasterCard to the app (no Amex). When you spend on Curve, you're actually spending on the underlying card you've added. Curve promise cheaper foreign exchange fees and a few other perks. But what we're really interested in is NFC payments.</p>

<h2 id="set-up-curve-pay"><a href="https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#set-up-curve-pay">Set up Curve Pay</a></h2>

<p>On your app's dashboard, you should see a banner saying "Curve Pay is good to go!". If not, head into your account and set it up there.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2025/06/Good-to-go-fs8.png" alt="Curve dashboard." width="504" class="aligncenter size-full wp-image-61638">

<p>If it has all set up, you should see a welcome tutorial explaining how contactless works.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2025/06/Good-To-Go-fs8.png" alt="Animation showing how to hold your phone to an NFC payment terminal." width="504" class="aligncenter size-full wp-image-61639">

<h2 id="set-your-default-wallet"><a href="https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#set-your-default-wallet">Set your default wallet</a></h2>

<p>On your phone, go to Settings → Connected devices → Connection Preferences → NFC → Contactless Payments.</p>

<p>Or, search your settings for Pay.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2025/06/Pay-Location-fs8.png" alt="Settings search page." width="504" class="aligncenter size-full wp-image-61640">

<p>Select your default wallet app - in this case, Curve.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2025/06/Default-Wallet-App-fs8.png" alt="List of available wallet apps." width="504" class="aligncenter size-full wp-image-61641">

<h2 id="pay-for-something"><a href="https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#pay-for-something">Pay for something</a></h2>

<p>You need to make sure NFC is turned on before you can use NFC payments. I know that sounds obvious, but I forgot to do it the first time and got very confused.</p>

<p>Go to a local shop, pick up something, hand it to the merchant, wave your phone over the payment terminal like you are a technowizard from the future.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2025/06/Notification-fs8.png" alt="Notification showing I paid £3.95 for a sticky bun." width="504" class="aligncenter size-full wp-image-61642">

<p>Enjoy eating whatever you paid for!</p>

<h2 id="thats-it"><a href="https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/#thats-it">That's it!</a></h2>

<p>Once you're done, you can turn of NFC if you're paranoid.</p>

<p>Apparently, <a href="https://justfollow.me.uk/@sborrill/114761774161342879">Curve also works with Garmin Smart Watches</a> - but I don't have one to test out.</p>

<p>If you've found this blog post useful, I'd be grateful if you signed up with <a href="https://www.curve.com/join#D4MK9ZKN">my referral link for Curve</a>.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=61636&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2025/06/contactless-payments-with-grapheneos/feed/</wfw:commentRss>
			<slash:comments>23</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[What's the best way to protect banking apps on Android?]]></title>
		<link>https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/</link>
					<comments>https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sun, 29 Dec 2024 12:34:26 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[GrapheneOS]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=55137</guid>

					<description><![CDATA[Lots of people using banking apps on their Android phones.  They&#039;re a convenient way to check your balance, transfer money to people, and get alerts about fraudulent transactions. But, like anything related to money, they can be abused.  Nowadays, thieves are not only snatching phones, but forcing their owners to transfer money to the thieves. This is not an isolated incident.  How can you…]]></description>
										<content:encoded><![CDATA[<p>Lots of people using banking apps on their Android phones<sup id="fnref:smug"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fn:smug" class="footnote-ref" title="&quot;Not me,&quot; you say smugly. &quot;I am far superior to the sheeple. If I want to connect to my bank, I just SSH in to a bespoke firewalled box that runs a disposable Docker image which connect to TOR.&quot; You…" role="doc-noteref">0</a></sup>.  They're a convenient way to check your balance, transfer money to people, and get alerts about fraudulent transactions. But, like anything related to money, they can be abused.</p>

<p>Nowadays, thieves are not only snatching phones, but <a href="https://www.reddit.com/r/UKPersonalFinance/comments/12bl2rf/forced_to_transfer_money_to_muggers/">forcing their owners to transfer money to the thieves</a>. This is not an isolated incident<sup id="fnref:see"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fn:see" class="footnote-ref" title="See also Bank and phone lessons learned after a robbery and I was robbed and forced to transfer money from my banking app." role="doc-noteref">1</a></sup>.</p>

<p>How can you protect yourself from such a situation<sup id="fnref:state"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fn:state" class="footnote-ref" title="Here we're mostly concerned with street theft. If you are the target of state-sponsored violence, or the police are searching your phone, then you may have a different threat model. If you think that…" role="doc-noteref">2</a></sup>?</p>

<p>Broadly speaking, there are four ways to protect your sensitive apps.  Relying on the regular lockscreen, hiding the apps, using a Private Space, or placing the apps in different profile.  Let's look at the advantages and disadvantages of each approach.</p>

<h2 id="regular-lockscreen"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#regular-lockscreen">Regular Lockscreen</a></h2>

<p>Android's lockscreen controls are pretty good - <em>if</em> you turn them on.</p>

<p>Perhaps you have a super-long and complicated password. Maybe a 10 digit PIN that only you know. Biometrics like facial recognition and fingerprints are reasonably strong and fairly convenient.</p>

<p>But that relies on your phone being locked when it is snatched. If you're using your phone when it is taken from you, <a href="https://www.theverge.com/2024/5/15/24157068/android-15-ai-theft-detection-lock-privacy-security">the lockscreen <em>might</em> detect it and lock automatically</a>, but you need a modern device and to have specifically enabled the setting.</p>

<p>If a thief has shoulder-surfed your 4 digit PIN, that will be enough to let them enter your phone.</p>

<p>But here we are concerned with someone threatening you. Basically, if someone has a knife pointed at you, you're probably going to unlock the phone for them<sup id="fnref:palm"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fn:palm" class="footnote-ref" title="Yes, I know that your self-defence training is impressive, but handing over your unlocked phone is a lot preferable to getting punctured." role="doc-noteref">3</a></sup>. So, let's assume we want to protect our banking apps from someone who has access to your <em>unlocked</em> device.</p>

<h2 id="launcher-hiding"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#launcher-hiding">Launcher Hiding</a></h2>

<p>Some Android phones <a href="https://www.geeksforgeeks.org/how-to-hide-apps-on-an-android-phone/">let you hide apps</a>. When an attacker is scrolling through the list of installed apps, they won't be able to see any apps which are hidden.</p>

<p>This, I think, is a reasonable way to hide your banking apps. You can show the thug that there aren't any installed. That may or may not be enough to mollify them.  They might still nick your device, but you won't be forced to transfer your savings elsewhere.</p>

<p>This, of course, presents a problem for the regular user. How do <em>you</em> launch your apps if you can't find them?  Most launchers will let you type in the name of the app to find it - the app is merely hidden from the default list.</p>

<p>So an attacker would have to try typing "HSBC" or "Barclays" or "Chase" or a dozen different names until they find your app.  Will they be angry if you've lied to them?  Is that a risk you want to take?</p>

<p>Some launchers will let you change the name and icon of your sensitive apps. You can rename "Midland Bank" to "Calculator" and change its icon.  Not every launcher supports this sort of hiding though. It also places a cognitive load on you that you need to remember what you've hidden your apps as. Will you remember than Bank 1 is calendar and Bank 2 is Bumble?</p>

<h2 id="private-space"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#private-space">Private Space</a></h2>

<p>Android 15 has introduced the concept of a <a href="https://support.google.com/android/answer/15341885?hl=en">Private Space</a>. It is like a digital lock-box for your apps. If someone has your unlocked phone, they need to pass through authentication in order to use apps which are locked.</p>

<p>There are two main drawbacks with this approach.</p>

<p>Firstly, locked apps don't run in the background. That means you won't get alerts from them. If you rely on push notifications to tell you if someone is using your card fraudulently, this could be a problem.</p>

<p>Secondly, the Private Space shows up at the bottom of your app list like this:</p>

<p></p><div style="width: 230px;" class="wp-video"><video class="wp-video-shortcode" id="video-55137-2" width="230" height="512" preload="metadata" controls="controls"><source type="video/mp4" src="https://shkspr.mobi/blog/wp-content/uploads/2024/12/private-space.mp4?_=2"><a href="https://shkspr.mobi/blog/wp-content/uploads/2024/12/private-space.mp4">https://shkspr.mobi/blog/wp-content/uploads/2024/12/private-space.mp4</a></video></div><p></p>

<p>So an attacker can easily see it and demand that you open it up.  You can set the Private Space to be hidden. But then you're in the same position as above - typing in "private space" will show it in your launcher.</p>

<h2 id="work-profile"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#work-profile">Work Profile</a></h2>

<p>Android has the concept of "<a href="https://support.google.com/work/android/answer/6191949?hl=en">Work Profiles</a>". They're designed to segregate your work apps and your personal apps. Your work admin can wipe your work profile without touching your personal stuff, and you can't copy confidential emails to your personal area. Nifty!</p>

<p>If you don't have work apps on your phone, you can use an app like <a href="https://f-droid.org/packages/net.typeblog.shelter/">Shelter</a> to make your own Work Profile.</p>

<p>You can stick your banking apps in the Work Profile and have them locked away from prying eyes.</p>

<p>The Work Profile button is more subtle than the Private Space.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/12/workprofile-fs8.png" alt="Work Profile in the quick settings bar." width="485" height="524" class="aligncenter size-full wp-image-55141">

<p>But it still has the disadvantage that, once locked, the apps are suspended and won't receive any alerts.</p>

<h2 id="secondary-profile"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#secondary-profile">Secondary Profile</a></h2>

<p>Finally, modern versions of Android support <a href="https://support.google.com/android/answer/2865483?hl=en">multiple profiles</a>. They're generally designed so that multiple people can use your device - but there's nothing stopping you from putting your banking apps in there.</p>

<p>The immediate advantages of multi-user profiles are:</p>

<ul>
<li>The profile can be protected by a separate password.</li>
<li>The profile switcher is generally more subtle than the Work Profile switcher or Private Space toggle.</li>
<li>Apps can run in the background while in a separate profile.</li>
</ul>

<p>The disadvantage is that, because it is a completely separate profile, you'll need to sign in again using your Google account in order to install apps from the Play store. If you use a password manager and MFA app, you may need to install them in both your main and secondary profile.</p>

<p>Because the apps can run in the background, there may be some (minor) impact on battery life - you're effectively running Google's Notifications Service twice.</p>

<p>If you are being held at knifepoint and a notification from your bank comes through - you may find it socially awkward to explain.</p>

<h2 id="which-is-right-for-me"><a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#which-is-right-for-me">Which is right for me?</a></h2>

<p>It is complicated. I think I can distil it down to the following:</p>

<ul>
<li>If you need alerts from your banking apps - put them in a secondary profile.</li>
<li>There are <a href="https://www.reddit.com/r/GooglePixel/comments/1g5v3b8/private_space_is_kinda_useless_what_do_you_use_it/lsmhz34/">some reports of banking apps not working in secondary profiles</a> - if yours don't work in a profile then hiding apps is your best defence.</li>
<li>If you're not using Work Mode and don't need alerts - put them in Work Mode.</li>
<li>If you're using Work Mode and don't need alerts - put them in a Private Space and set the space to be hidden.</li>
</ul>

<p>Remember, you can't fling <a href="https://utcc.utoronto.ca/~cks/space/blog/tech/SocialProblemsAndTechnicalDecisions">technical solutions at social problems</a> and expect them to solve everything.  In general, <a href="https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingjune2024">crime in England and Wales is at its lowest level</a> but certain crimes, like phone theft, are on the rise. Despite all the technology thrown at the problem, people are still walking around holding machines worth hundreds of pounds. Each of those machines is a gateway to potentially thousands of pounds. Phones and banking apps are incredibly lucrative targets.</p>

<p>The aim of this exercise isn't to solve the problem of crime. It isn't even to make you a less attractive target. It is to allow you to hand over your phone safe in the knowledge that your banking apps are <em>somewhat</em> protected from miscreants while still being useful to you.</p>

<p>If you have any tips on how to keep banking apps hidden, please leave a comment.</p>

<div id="footnotes" role="doc-endnotes">
<hr>
<ol start="0">

<li id="fn:smug">
<p>"Not me," you say smugly. "I am far superior to the sheeple. If I want to connect to my bank, I just SSH in to a bespoke firewalled box that runs a disposable Docker image which connect to TOR."  You continue, indifferent to the exasperated sighs of the waitress  "Of course, I only use GNU/Linux on my phones, have you heard of it? I don't even trust password managers! I have my own algorithm for generating passwords using dice. I have some nifty D20s if you wanna see them? Sure beats having a <strong>CR</strong>app on my phone! If I want to transfer someone money I generate a new seed phrase for my Bitcoin wallet and then… say, do you take crypto here?"  The waitress contemplates stabbing you with a fish-knife but, instead, politely replies "If you don't want to leave a tip, sir, that's OK." She makes the mistake of smiling, which you misinterpret as a flirtatious gesture. You torrented a whole bunch of books about social interactions with girls and yet, somehow, failed to understand any of them. You try negging her. That's bound to work. "Of course, you're probably the sort of girl who uses an iPhone or as I call them…" before you can chuckle about normies running iDrones the waitress has turned and walked away. Bitch. Still, at least you don't have any banking apps on your phone. That makes you better than most people.&nbsp;<a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fnref:smug" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:see">
<p>See also <a href="https://www.reddit.com/r/UKPersonalFinance/comments/11nmyyz/bank_and_phone_lessons_learned_after_a_robbery/">Bank and phone lessons learned after a robbery</a> and <a href="https://www.reddit.com/r/UKPersonalFinance/comments/1clqlxd/i_was_robbed_and_forced_to_transfer_money_from_my/">I was robbed and forced to transfer money from my banking app</a>.&nbsp;<a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fnref:see" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:state">
<p>Here we're mostly concerned with street theft. If you are the target of state-sponsored violence, or the police are searching your phone, then you may have a different threat model. If you think that your snarky posts on your three-subscriber Substack about "lamestream media" and "Micro$oft" make you a target for the CIA, please go outside and run around in the fresh air for a bit.&nbsp;<a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fnref:state" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

<li id="fn:palm">
<p>Yes, I know that <a href="https://forums.somethingawful.com/showthread.php?threadid=3742916">your self-defence training is impressive</a>, but handing over your unlocked phone is a lot preferable to getting punctured.&nbsp;<a href="https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/#fnref:palm" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>

</ol>
</div>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=55137&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2024/12/whats-the-best-way-to-protect-banking-apps-on-android/feed/</wfw:commentRss>
			<slash:comments>10</slash:comments>
		
		<enclosure url="https://shkspr.mobi/blog/wp-content/uploads/2024/12/private-space.mp4" length="169206" type="video/mp4" />

			</item>
		<item>
		<title><![CDATA[Notes on installing GrapheneOS on a Pixel 8 Pro - some bugs & oddities]]></title>
		<link>https://shkspr.mobi/blog/2024/03/notes-on-installing-grapheneos-on-a-pixel-8-pro-some-bugs-oddities/</link>
					<comments>https://shkspr.mobi/blog/2024/03/notes-on-installing-grapheneos-on-a-pixel-8-pro-some-bugs-oddities/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 13 Mar 2024 12:34:36 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[GrapheneOS]]></category>
		<category><![CDATA[LineageOS]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=49860</guid>

					<description><![CDATA[These are notes to myself - and anyone else who finds them useful.  Before starting, I booted the Google OS to install the latest firmware and an eSIM. After a few days of enduring Google&#039;s naggy software, I was ready to commit to installing something better.  I tried using the Web Installer. It managed to flash some of the partitions and then failed with:  Failed to execute &#039;claimInterface&#039; on…]]></description>
										<content:encoded><![CDATA[<p>These are notes to myself - and anyone else who finds them useful.</p>

<p>Before starting, I booted the Google OS to install the latest firmware and an eSIM. After a few days of enduring Google's naggy software, I was ready to commit to installing something better.</p>

<p>I tried using <a href="https://grapheneos.org/install/web">the Web Installer</a>. It managed to flash <em>some</em> of the partitions and then failed with:</p>

<p><code>Failed to execute 'claimInterface' on 'USBDevice'</code></p>

<p>So I used the <a href="https://grapheneos.org/install/cli">CLI instructions</a> which were comprehensive. Worth re-reading them a few times to make sure you understand what needs doing. I (foolishly) assumed my fastboot didn't need updating. Tsk!</p>

<p>And then... it just worked!</p>

<p>Well, almost. The device saw the previously installed eSIM, but wouldn't connect to its network. I manually removed it, reloaded it. Still nothing.  So I manually chose the network and that seemed to fix it. No idea if that's a problem with the network, the eSIM, or something else.</p>

<h2 id="bugs"><a href="https://shkspr.mobi/blog/2024/03/notes-on-installing-grapheneos-on-a-pixel-8-pro-some-bugs-oddities/#bugs">Bugs</a></h2>

<p>As soon as I booted, my network provider sent me a text. I opened up the default messaging app and saw this error:
<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/messaging-fs8.png" alt="This app was built for an older version of Android. It might not work properly and doesn't include the latest security and privacy protections. Check for an update or contact the app's developer." width="1008" height="588" class="aligncenter size-full wp-image-49880"></p>

<p>This is <a href="https://discuss.grapheneos.org/d/8249-why-does-the-default-sms-app-warn-it-was-built-for-an-older-version-of-android/4">a known problem</a> but it makes for a crappy user-experience. There's no way to update the app in Graphene - you need to manually install your preferred SMS app.</p>

<p>In similar UX fails, I tried to add the clock widget to my home screen. This is what I saw.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/Clock-fs8.png" alt="Hard to see graphics." width="1008" height="1851" class="aligncenter size-full wp-image-49881"></p>

<p>If you peer carefully, you'll see an analogue <em>and</em> digital clock. I hadn't switched to dark mode or anything like that - this is the default experience.</p>

<p>I wanted to see how long I could go before installing Google Play Services. The answer was... five minutes. I tried to log in to my password manager using a WebAuthN token and it wouldn't work. The default Vanadium browser can't handle them.  Again, this is a known problem - but it does slightly undermine the attraction of Graphene. I'm privacy conscious and want as little Google in my life as possible. I'm security conscious and want to use MFA everywhere. Pick one.</p>

<p>Partway through the day, I got this internal error:</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2024/03/Unable-fs8.png" alt="Pop up saying it was unable to fetch a list of apps." width="1008" height="840" class="aligncenter size-full wp-image-49882">

<p>I was happily browsing the web with no connectivity issues. So I'm not sure what caused that.</p>

<p>It's annoying that Graphene doesn't support LineageOS's bottom-button changes. I have a decade of muscle-memory saying back is on the right. There's no way to change it, so I've swapped to gesture navigation.</p>

<p>The icon size on the stock launcher are far too small. On a massive screen like the 8 Pro they are tiny. So I've installed <a href="https://github.com/NeoApplications/Neo-Launcher">NeoLauncher</a> which is a lot more customisable.</p>

<p>The only other (non-essential) thing missing is the ability to use Cast to screen share a device. There's a button in the UI, but it does nothing.</p>

<p>Setting up a work-profile required a little bit of a work-around, but seems to have worked. Hurrah for forum threads detailing the various tricks you need.</p>

<p>A software update <a href="https://grapheneos.org/releases#2024031100">allowed DisplayPort via USB-C</a>.  I plugged the 8 Pro into my USB-C hub, it detected the ethernet, keyboard, mouse, and display - graphics came through fine. Although there's <a href="https://mastodon.social/@Edent/112084893031982717">no way to rotate an external screen</a> - so you're stuck with landscape orientation.  My HDMI adapters showed as detected via a little icon - but no video came out.</p>

<p>The Graphene camera's interface isn't as good as GCam and it is missing a bunch of options. Installing the stock Pixel camera worked - and there are lots of hacky derivatives.</p>

<p>Other than that, it has been pretty good so far. My banking apps work, call recording works, 5G and Bluetooth works, eSIM and regular SIM works. There have been a few odd things where apps have complained that they can't work and then suddenly sprang to life - but that might just be Android.</p>

<p>The only big thing Graphene is missing is Google Pay / Wallet. It is <em>so</em> convenient using tap to pay - but getting rid of the rest of the incessant Google bloat is worth the sacrifice.</p>

<p>Overall, I'm happy with the decision to nuke the original Google software. I know they say they'll support the device for 7 years - but I literally have no reason to trust them. Maybe I'm being naïve trusting a group of random hackers to produce a more secure OS - but I'd rather that than further entanglement with an organisation which has repeatedly shown contempt for its customers and users.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=49860&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2024/03/notes-on-installing-grapheneos-on-a-pixel-8-pro-some-bugs-oddities/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
