Conversation

Follow lead developer and owner of the project for regular details on GrapheneOS development and research. This handle will be used for official announcements including releases of GrapheneOS and standalone sub-projects like Auditor. It'll be low volume.
4
82
Replying to and
You're incorrectly assuming that the project is unaware of how the baseline application sandbox and permission model work. I'd suggest familiarizing yourself with the current baseline (AOSP 10), how GrapheneOS changes it, what still needs to be added back and what's planned.
2
Replying to and
I mean no to hurt but i got a bit chocked how easy it was to upload malmware without any indication that os detected or tryed to stop..Btw i needed to give admin acess to the device to let spy work. Is it possible to lock the device with signature after installing wished apps?
1
Replying to and
You explicitly unlocked the device, allowed installing apps from an unknown source, manually installed an app, explicitly granted each of the permissions and then went into the device administration configuration and granted the listed administration capabilities it requested.
1
In the future, there will be a GrapheneOS app repository with hardened builds of carefully selected apps. There will also be an alternative set of locked down OS releases unable to install/run code from elsewhere. If you want that instead, wait for it to be available and switch.
1
11
Show replies