You punctuated your reply as a statement but phrased it as a question… but yes, it should just function as any other secondary device.
Lytia
- 0 Posts
- 47 Comments
Because you can’t run multiple accounts at once? Either I’m misunderstanding what you’re saying, or you’re missing the point of a signal backup.
OP is referring to the GrapheneOS feature, well really the android feature heavily enhanced by GrapheneOS, that allows you to run the OS as another user with their own apps and files. OP is asking for help running signal (Molly) in both profile A and profile B as one account. This is technically possible but realistically infeasible because of the way profile switching works on android. I explained why in a different comment.
Lytia @lemmy.todayto
Privacy@lemmy.ml•Signal on two different grapheneos profiles.English
61·1 day agoBad advice. Signal has its drawbacks, and yet you managed to avoid listing all but one of them. Impressive.
Signal has released an update recently that allows multiple devices (up to 10 I believe). Yes you still need a phone number, but newer commits suggest that is soon to change. Signal has local backups on android, and I haven’t heard of any issues restoring from them. Signal is far from perfect, but they are very trusted, battle tested, and overall a better service than what most people are using anyways. By all means, if you have a better service that works for you, go for it, but advising against using signal outright with no alternative is kinda weird.
I just tried with the official signal client, and I don’t think there’s a way to do it without transferring the account to another device. The second app must remain open while the first app scans the code, so while it’s possible in a private space, I think profiles are too isolated to run both at once. I’d be happy to be proven otherwise, but from what I can tell, it’s not possible on one device alone. I’d imagine Molly is the same.
If you have two seperate profiles on GrapheneOS, any apps inside the profile would generally assume it’s running on a completely seperate device. If the app was malicious it could technically tell that it’s installed on the same phone, but Signal is not. Using Signal across two profiles would be effectively the same as using Signal across two different phones.
I’ll start this by saying I do like and use proton, but their insistence to provide a hundred different services (and force you to pay for every single one in your subscription) really hurts the service. For example:
The 2FA had an issue that leaked every single service you used by connecting to their icon server over insecure http, for a month I believe and then downplaying the severity. This wouldn’t have happened if they focused on being an email provider and pointed users to existing services like Ente Auth, instead of pushing poorly tested software to production as fast as possible. You should never store 2FA with your password manager anyways, even if it’s stored in seperate apps, so I think their choice to make a 2FA app is quite silly.
They continue to prioritize building new services such as meet and lumo over compatibility with Linux (drive sucks, and only 9 years later do they support a buggy CLI. The VPN client is buggy as hell, and if you’re not careful could leak your VPN when it crashes for the hundredth time (crashes are less common on Gnome, which is technically the only DE it’s built for, but that doesn’t change the fact that it lacks critical features that exist exclusively on MacOS and Windows) (the killswitch works as far as I can tell, but with how poorly made the client is, you should bind it in the OS itself as well)).
They require the use of Google Play services, arguing that they don’t want to waste people’s battery by running websocket based notifications. It’s a stupid defense as people who don’t have Google play services wouldn’t mind the extra battery usage for notifications. Not to mention, they can use unified push since they already encrypt their notifications anyways (Proton says they don’t need to add unified push, the users just need to use Google Play because the notification are encrypted, completely disregarding the invasiveness of Google Play and the metadata leakage from using them for push notifs).
The UI for simplelogin has not changed since acquisition from what I can tell, and continues to look like it’s from 2014. Rather than adding features to simplelogin, as you would when you purchase an entire company, they almost exclusively add features to their password manager and email client instead.
They basically force their crappy photo storage down your throat on mobile, despite being offered to join an alliance with privacy services (including Ente, an amazing photo storage service) and rejecting the offer. That’s actually a whole issue on its own. For what reason, other than greed, would a privacy company choose not to join an alliance with very respected privacy services? Is it because Tuta joined? That would be dumb and petty.
Overall, I like and use many proton services, and I think a lot of the political controversies people like to throw at proton are FUD and/or blown out of proportion. That said, if a company could do what proton does for email (tuta is nowhere close to proton imo) and exclusively does email (fun fact, tuta is exploring the cloud drive space, because I guess people never learn) I would switch in a heartbeat. If proton separated their plans so you only pay for what you need, and let me use notifications on my phone, that would be basically all my gripes in my day to day dealt with.
Edit: It seems I’m significantly more out of touch with what Google et al. have been doing recently than I first thought. After reading many of the replies, I certainly failed to consider how much of their behavior impacts the average person. I’ll leave my old comment here, but I no longer stand by what I said.
Maybe an unpopular opinion, but compared to everything else big tech has been doing recently, Google almost doesn’t feel like a bad guy. They’re still invasive as hell, but compared to any other mainstream AI, search, email, cloud storage, VPN, etc. providers, they almost feel closer to Apple levels of evil rather than removing “don’t be evil” from your moto levels of evil. Crazy how humanity continues to outdo itself.
Personally, as much as I love the freedom of phones running desktop Linux on mobile (well most use Ubuntu as a starting point, so maybe “freedom”), I think freedom can only go so far with limited security.
Unfortunately so-called “Linux phones” (which is a horrible name imo, android is based on the Linux kernel, so really they should be called systemd phones) have very lackluster security on the device itself (app sandboxing is a joke on desktop Linux, which applies to mobile (non android) Linux too), not to mention physical security (“linux phones” are built with the goal of running Linux, not protecting their users from the combined hacking power of the US, Israel, China and other nation state actors). With the new terminal emulator allowing people to run desktop Linux apps on android, I really only see pinephone and other such devices as novelty phones, rather than a real daily driver smartphone. I don’t really understand the obsession with putting desktop Linux on the phone anyways.
I’m personally hoping for the GrapheneOS team to grow enough to build their own microkernel instead of relying on the relatively insecure monolithic Linux kernel. That said, I’m definitely a minority, so as long as big tech is losing its monopoly on the smartphone market, more power to you I suppose.
If you’re using GrapheneOS, it will continue to be as easy as it’s always been to use F-Droid.
FYI, firmware is technically the wrong term here (apologies for being pedantic), the correct term would be operating system, or custom operating system. A lot of the firmware, even after installing GrapheneOS, is closed source and managed by Google. There’s not much the project, or any project, can do about that, but their partnership with Motorola might help with the closed firmware problem.
If you have a pixel, I’d highly recommend avoiding custom OSs other than GrapheneOS unless you cannot use GrapheneOS for whatever reason. That said, in most cases running stock with modified settings can preserve the base android security while giving you more privacy.
If you can, you mention having a Samsung, avoid using Samsung with a 10 foot pole. Their security is laughably bad for a major OEM, and once you begin customizing anything with the phone, you’ll encounter bug after bug after bug.
If you want a handful of reasons to avoid non GrapheneOS custom OSs, here are some of the biggest offenders (if you want more, you could ask in various GrapheneOS chatrooms (such as on matrix or discord) and they’ll be happy to give you more reasons (be warned, some people will be very blunt)):
Most other custom OSs use privileged MicroG, as opposed to sandboxed Google Play which is mostly unique to GrapheneOS, as well as their own privileged serviced to provide things like parental controls or deeper app customization.
They’re also very lacking in security, being no better than stock android when faced against Cellebrite or Graykey.
Their updates tend to take weeks, if not multiple months in some cases, while also not updating when new vulnerabilities are found unless it’s patched upstream.
Most don’t support locking the bootloader due to the way they support devices (this is part of the reason GrapheneOS is pixel exclusive) which means your phone is vulnerable to having parts of the boot process modified potentially maliciously to allow an attacker access to your data.
User privacy on custom OSs is often really theater, promising privacy because they’ve removed Google Play Services by replacing it with a less secure, more vulnerable, and less user friendly version called MicroG.
Finally the /e/OS devs, an operating system recommended to you by another reply, straight up said they’re intentionally not making their OS any more secure, because only pedophiles need to worry about their privacy (the video is in French, and I don’t have it saved, but I can find it if you want).
All said, if you just want to avoid Google but don’t care about any other Tom, Dick, and Harry accessing your private information, custom OSs are great. If you care about other people, especially other companies, not having access to your private data, and you’re already getting a new phone anyways, I strongly recommend buying a pixel and slapping GrapheneOS on it. Sideofburritos is a great source of information for GrapheneOS, he even made a video trying to brick GrapheneOS during the install process (spoiler: he couldn’t) in case you’re worried about damaging the pixel in the process.
Disclaimer: I’m not associated with the GrapheneOS project, I’m just a user who cares a lot about their digital security. If it sounds like GrapheneOS is too good to be true, I’d be happy to include some drawbacks of the OS. There really aren’t many, as every news outlet that reviews the OS can agree, but there are a few.
ROM means read only memory, you are not modifying the phone’s read only memory. The term originated back operating systems and games were intended to be written once to a chip at the factory and never modified again.
Lytia @lemmy.todayto
Privacy@lemmy.ml•Make me feel better about Duck Duck Go Search?English
3·5 days agoDepending on the size of your city, they can estimate down to at least the city. In big cities or really small towns you can get it down to a street. In the event that your ISP has a data breach, they can see your exact house address.
If you want that in an image format:

Lytia @lemmy.todayto
Privacy@lemmy.ml•He Hacked Flock Cameras. What He Found Was Worse Than Expected
3·6 days agoI don’t think the go away challenge is valid with just the URL, so for privacy purposes it should probably just be https://inv.nadeko.net/p_vj_0IkO58 or better yet https://redirect.invidious.io/p_vj_0IkO58 for a wider variety of frontends.
Lytia @lemmy.todayto
Privacy@lemmy.world•He Hacked Flock Cameras. What He Found Was Worse Than ExpectedEnglish
7·6 days agoI don’t think the go away challenge is valid with just the URL, so for privacy purposes it should probably just be https://inv.nadeko.net/p_vj_0IkO58 or better yet https://redirect.invidious.io/p_vj_0IkO58 for a wider variety of frontends.
Apple, compared to most other big tech companies, are pretty private with data in their own apps. They lie a lot, so trust is a big issue, but they’re significantly better than most other companies who go out of their way to collect and sell everything they can. They’ve definitely gotten considerably worse recently though.
- Title that isn’t just video name: ❌
- Privacy respecting frontend: ❌
- Brief description of video content: ❌
Reject Convenience on privacy capitalism
https://redirect.invidious.io/watch?v=xFKSKjyBVDU
Reject Convenience discusses the various companies selling you private alternatives to invasive services.



Reminder though: If you’re on GrapheneOS, sandboxed Google play is the best you can get while using Google play. MicroG is just as, if not more, privileged than Google Play while lacking many genuine security features provided by Google Play. App stores like aurora don’t check app signatures and can fail if their “anonymous” accounts get banned. If you’re using GrapheneOS and want apps from the play store, making a seperate profile with sandboxed Google play is the best option.