Graphene-Os

[!toc] Table of Contents

GrapheneOS is a mobile operating system based on Android. It is often recommended as an alternative to pre-installed (OEM) operating systems, as it can be used entirely without Google services. In addition to this feature, which protects user privacy, GrapheneOS, in combination with supported devices, offers state-of-the-art security features, which is why we strongly recommend its use here.

GrapheneOS comes as a very blank operating systems, with just the very necessary tools installed. Because app installations are crucial to security, we would like to give a recommendation on how to install apps from which sources/app stores.

We consider the following apps as part of most activists standard installations. The following list, as far as necessary, contains links to our instructions on how to install those apps securely, on a fresh GrapheneOS installation. We:

[!technical] What about Organic Maps?

CoMaps is a community fork of the well known

Organic Maps, which unfortunately upset their own community, by making private profit from community contributions

Confidential profile

For many, data-hungry apps such as WhatsApp and the like are still a must-have in their digital repertoire. As a result, separate work profiles are often set up to use these apps. The “private space” feature can be a welcome alternative here:

[!quote] Quote {static}

Android 15 introduces the ability to install apps in a completely isolated area, separate from the rest of the system. [...] Unlike the previous work profile, which required a separate user login, Private Space is integrated directly into the system, making it much easier to use and more accessible.

The GrapheneOS team has written this feature announcement, which gives further details on how the private space feature can be used.

It is important to note that the confidential profile has its own network settings. This means that if you use TOR or VPNs, you have to set this up again in the confidential profile, as the settings from the normal owner profile do not apply here. This can also be seen a privacy feature, since exit IPs can be separate.

Data protection & security

Exploit protection

In the settings under Security and Privacy > Exploit protection:

[!technical] WiFi privacy risks

When your WiFi is activated, your phone constantly checks for any known previous WiFi connections nearby. It thereby reveals information on your saved WiFi networks, which can be a significant privacy risk. Combined with other resources, it may be used by advanced adversaries to identify you or to track your location. As an example, the WIGLE map can be potentially used by anyone to track certain devices 2.

More Security and Privacy

In the settings under Security and Privacy > More security and privacy:

Duress Password

It is best to choose a Duress Password that:

WiFi

For all WiFis that you do not have full control over:

2FA for fingerprint

It has recently become possible to use a second factor for unlocking your phone via fingerprint. This represents a huge step forward in the conflict between usability and security!

What was the problem before?

Normally, biometric unlocking methods should be used with extreme caution for the simple reason that they can be forced by others. In case of doubt, the police can force your finger onto your phone and unlock it This means that, until now, the use of biometric unlocking has always been accompanied by the risk of being taken by surprise and forced to unlock your phone before it can be turned off.

What is the solution?

The 2FA option offers the possibility of setting up a minimum 4-digit (6 digits are recommended) PIN number, which must be entered each time after the fingerprint to unlock the phone.

You still have to type something, but a 6-digit PIN on the large number pad is much easier and faster to type than a 7-word passphrase on the small keyboard. In addition, the PIN can be changed much more easily when necessary, as you don't have to worry about learning a new long password.

Your password should still follow the recommended passphrase guidelines, but using this feature means that the cell phone can be encrypted with a very strong password without having to type it several times a day, since the long password is only required when the phone is first unlocked.

Can the PIN be brute-forced?

Only to a very limited extent:

PIN scrambling

PIN scrambling is pretty nerdy, but it does have its use cases:

Depending on whether you already have enabled the 2. factor pin for fingerprints, the locations are different from each other. See here in our instructions.

Instead of the digits always being displayed in numerical order on the screen, the digits are displayed in random positions on the screen when the PIN is entered. This means that if an attacker has been watching you entering your PIN from a short distance and has only been able to see the direction of your thumb on the screen, for example, they will not be able to reconstruct your PIN. The same applies to CCTV / surveillance cameras.

PIN scrambling is also available for the fingerprint 2FA.

Apps

In the settings under Apps > Special app access:

[!tip] Tip {static}

Also allow Signal to install apps! Although this seems counter intuitive, this enables signal to update it self!


Version #2
Erstellt: 2026-02-15 16:16:40 UTC von ESC-IT Migration Bot
Zuletzt aktualisiert: 2026-03-18 13:28:28 UTC von ESC-IT Migration Bot