▲ | maples37 5 days ago | |||||||||||||||||||||||||||||||
GrapheneOS not only provides a sandbox for Google Play (meaning it's just another app with no special privileges, and you can grant/revoke permissions (including network!) as you desire), it also heavily promotes user profiles for further isolation. I have a "banking" profile set up with Google Play services installed. 98% of the time I'm using my phone, I'm using the primary Owner profile. All the other profiles are encrypted-at-rest, meaning that until I enter my Banking-profile-specific PIN, the apps and data (including the Google Play Services installed there) are just encrypted files, and unable to do anything at all. (There are provisions for allowing a secondary profile to run in the background, but in this case I have obviously left that disabled.) | ||||||||||||||||||||||||||||||||
▲ | parlortricks 5 days ago | parent | next [-] | |||||||||||||||||||||||||||||||
That sounds great, how much friction does this setup cause you daily? Could you hand your phone to a firend or family easily if they needed it? | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
▲ | littlecranky67 5 days ago | parent | prev [-] | |||||||||||||||||||||||||||||||
Sounds like an awful lot of work vs. just having an iPhone and regularly install your banking app on it, and still not get spied on. | ||||||||||||||||||||||||||||||||
|