• 0 Posts
  • 7 Comments
Joined 11 days ago
cake
Cake day: September 27th, 2026

help-circle


  • That’s an extremely solid list, mate. You can be proud of that. May I ask how long it took you to transition to this state?

    In case you’re still willing to adjust one thing or another, here’s some food for thought:

    1. You’re still running a relatively Proton-heavy loadout. They’re hosting your mail, VPN, docs, calendar and AI services. In case of a breach (attacker gains access to your account) or a company employee / the company itself going rogue, you will have several eggs in that particular basket affected, and a few very sensitive ones at that. Diversification might be an option, e.g. getting a separate mail provider, running your docs and calendar through a (self-hosted?) Nextcloud instance, etc.
    2. Personally, I’ve never felt comfortable with the idea of my password manager being cloud-accessible, regardless of how tight the security on the other end claims to be. KeepassXC (on Linux) and KeepassDX (on Android/GrapheneOS) work extremely well. They’ve even gained Passkey support recently. Add Syncthing to the mix for cloudless cross-device sync and you’ve got yourself an entirely offline password manager.
    3. You may want to fix the “FUTO” spelling in those two headlines. ;)




  • I appreciate you taking the time to do this write-up, OP. Unfortunately, I believe it will not do what you hope it does, i.e.: “make you a it more private”.

    Think of this in terms of data points Google gets on you. As per the warning on FDroid, they get:

    the apps list and system details

    That alone is very likely enough to identify you, particularly if you

    • use a custom ROM: this will put you into a tiny pool of users
    • use any apps that not everybody has (e.g. apps for your public transport, government or financial institutions)

    Let’s say you’re running GrapheneOS on a Pixel 7a and have apps installed for Swiss Rail, Bern public transport, the UBS banking app and Signal. How many people will have this particular setup? I’d wager this would already narrow the pool down to a single-digit number of users, if not “one”, and any additional app off the Play Store will narrow it down even further.

    While using your native public IP will give them yet another data point to identify you, so will the use of TOR or a VPN, because, again, only a fraction of Aurora store users will do that.

    On the other side of the equation, the only “threat” I can think of is: “Google will know that I use these apps”. Outside of a targeted attack (i.e. Google sending you - specifically you - an update with malicious code injected into the APK), I cannot see any truly harmful scenarios arising from this.

    All in all, I don’t think there’s much to be gained here: both the effect (if it works at all) and the threat (if you don’t do anything) seem so miniscule that it’s hardly worth the time to set this up.

    Instead, this time is probably spent better on this here:

    When possible, use Obtanium or F-Droid instead. F-Droid has built in Tor as well.

    The only way not to be tracked by Google is not to get involved with Google. The only way to truly win the game is not to play it.