Privacy and control. My tech setup

(toidiu.com)

65 points | by todsacerdoti 2 hours ago

15 comments

  • arionmiles 55 minutes ago
    As much as I'd love to daily drive an OS like GrapheneOS, the risk of running into apps that use Google Integrity API thereby making it impossible to run those apps on Graphene is too much of an inconvenience.

    I took a look at this curated list of bank apps[1] supported on Graphene OS and I'm glad that a large majority of them work on Graphene. However, just my luck that one of the banks I use on this list isn't supported.

    In my country, the state is enforcing a lot of essential workflows to be digital-first (and in extreme cases digital-exclusive) and I dread to think needing these services at a crticial moment and the choice of my OS making it impossible for me. This is more of a commentary on my government's choices but it's a reality for me.

    In any case, I don't think it's practical to go cold turkey and switch to a privacy focused phone without testing waters first to see which of your of workflows break and then reason about the tradeoffs/workarounds.

    I do admire folks who use GrapheneOS as a daily driver, I'd like to chat them up if I find them in the wild.

    https://privsec.dev/posts/android/banking-applications-compa...

    • delichon 49 minutes ago
      I worried about that too, but jumped in and it hasn't been an issue at all in two years. Including three bank apps. And it's usually so easy to reset to vanilla Android if you need to, that it shouldn't be your moat.
    • fylo 13 minutes ago
      I believe there is some support for the API although its not perfect.
    • ignoramous 17 minutes ago
      > As much as I'd love to daily drive an OS like GrapheneOS

      The Play Integrity shenanigans is mostly on app developers.

      That said, good thing GrapheneOS will launch its own Android phone: https://discuss.grapheneos.org/d/27687-new-manufacturer-theo... / https://piunikaweb.com/2025/10/13/grapheneos-ending-pixel-ex... / https://www.androidauthority.com/grapheneos-phone-wait-or-bu...

    • kgwxd 27 minutes ago
      Is the app the only way to access what you need? I've never once install the app of any bank I've ever used (10ish) and never found myself wishing I had.
    • bitwize 29 minutes ago
      I've seen a couple of apps try to use Play Integrity, get blocked by GrapheneOS, and keep on running. Maybe I'm being locked out of something, but it's not something I use anyway.

      Note that I don't use banking or government apps. If I bank online it's via the web.

    • closuregarden 17 minutes ago
      [dead]
  • nyx 57 minutes ago
    Agree that "control" is a much better framing, since it doesn't suggest a need for secrecy and therefore embarrassing/unacceptable/untoward behavior that needs to stay behind drawn window blinds. I'm also fond of "agency" and "digital self-sovereignty" as alternatives.

    But fine, I'll be the one to say it: Cloudflare isn't one of the good guys here and as an entity it shouldn't be trusted. It doesn't matter how pure their stated motives appear to be now, or how unmarred their track record is so far. It's a corporation that has control over an ever-increasing share of internet infrastructure, and is susceptible to the same risks as any other tech monopolist basket that we all decide to put our eggs in. Maybe more risky than the others, given how deep in the stack its influence is buried.

    What happens when a government forces it to NXDOMAIN porn or put nuisance captchas in front of dissident blogs? Is there some reason people think this one is different?

    • ccakes 35 minutes ago
      > Cloudflare isn't one of the good guys here

      Came here to say the same thing, post was interesting until I got to that point.

      > nuisance captchas

      Try using the internet outside of the western world and major hubs. Cloudflare make it so painful with captchas and browser integrity checks

  • barishnamazov 8 minutes ago
    > "I don't need to care about privacy because I have nothing to hide." is an argument that I have heard countless times. I found this argument difficult to counter in the past, yet deep-down I knew the reasoning was flawed.

    This one is pretty easy to counter. Just ask the person to hand you their phone and go through their messages and photos. There's no one that wouldn't feel restless about it.

  • jumpingpants 1 hour ago
    > Instead of "privacy" we really should be talking about "control".

    Fantastic. This is what I have been shifting towards these past couple years. Hardly anyone likes to be controlled, right?

    • kgwxd 20 minutes ago
      I don't but it seems a LOT of people do. They even seem to prefer it.
  • navigate8310 35 minutes ago
    The only thorn in the opine is Cloudflare. Everything looks reasonable but CF. I get that DNS is free, it is OP's employer and registry being offered sans margin but it doesn't make up for the fact that CF is on its way to become the biggest gatekeeper and strangle the freenet if it wishes to do so.
    • OGEnthusiast 27 minutes ago
      Them being employed by Cloudflare means you should take the article with a grain of salt IMO.
  • OGEnthusiast 59 minutes ago
    What's the story for maps and POI search on GrapheneOS? I'm assuming using Google Maps is a non-starter since that defeats the whole point of all these privacy protections in the first place.
    • nextos 57 minutes ago
      OSMAnd and others can do offline maps and POI search if you want.

      You could also run Google Maps web through Tor if needed. Tor is easy to use on Android.

    • mikeyouse 57 minutes ago
      Yeah I think most people use Organic Maps or Magic Earth (with the latter being closed and not as privacy-respecting as the former).
  • zikduruqe 19 minutes ago
    Finally. Someone in the wild that runs passwordstore.org

    I thought there was only a couple of us.

  • afarah1 1 hour ago
    FYI: NetGuard is an open source rootless firewall for vanilla Android which also allows per-app network access control, for those unable or unwilling to go with other OSs. Works by leveraging Android VPN to block instead of tunneling packets.
    • yjftsjthsd-h 20 minutes ago
      Doesn't running as a VPN mean it's incompatible with running an actual VPN at the same time? That's a pretty big caveat.
  • bstsb 1 hour ago
    excellent article, you've inspired me to get off Gmail finally (Google's been sending me angry emails about hitting my storage limit for ages anyway).

    side note, your link to Tuta is broken - think it's an internal link by accident

  • 50208 21 minutes ago
    The ad blocker is uBlock Origin ... the blog misstates it as uOrigin.
  • ignoramous 27 minutes ago
    > Domain: I switched to Cloudflare Registrar recently because they offered a lower price ... I don't think Cloudflare really cares to make money on domain registration.

    Well, they don't today.

    Speaking of "control", it is bad form to keep both the nameservers and registrar with the same company (think takedown requests / account lockout / etc).

  • riskeet 1 hour ago
    The average person won’t go through even 2% of the trouble. Your self inflicted lockdown is a niche within a niche. I respect it though!
    • dinkleberg 49 minutes ago
      Who cares what the average person will go through and do though? We’re each responsible for ourselves and how we choose to go about life, even if vastly differs from the general population.
  • 65 34 minutes ago
    This reminds me of the old meme:

    > Tech enthusiasts: My entire house is smart.

    > Tech workers: The only piece of technology in my house is a printer and I keep a gun next to it so I can shoot it if it makes a noise I don't recognize.

    • barishnamazov 5 minutes ago
      One of my computer science professors from MIT has installed a smart home. I was over for a dinner and he told me a story about how he hit a third-party API rate limit on opening his garage door. Apparently, these things aren't self-hosted for the most part.
  • Lapsa 46 minutes ago
    reminder - there's tech out there capable of reading your mind remotely and non-invasively
    • netule 14 minutes ago
      Care to elaborate?