Table of Contents
Background
I had planned to wait for the Motorola Graphene phone, but my old Pixel 6 decided to die early, probably from a short circuit caused by a swollen battery.
GrapheneOS is fast to support new Pixel phones, so I grabbed a recently released Pixel 10A and used its stock Google firmware for about a month, just to set a reference point for my future GrapheneOS experience.
Stock Firmware
Stock firmware worked fine, but it was bloated with features I don’t need or like. The non-removable Google search widget on the home screen was annoying enough, but accidentally starting AI photo extraction when all I wanted was to return to a recent app was no less irritating.
The key issue, though, was the inability to install third-party apps. Well, those are third-party relative to the Play Store, but some are in fact my apps. I had to click through a gazillion warnings to test the latest BTC Map or Vesti app build. This is absolutely unacceptable and it’s going to get much worse.
First Impressions
The installation was smooth, and I’m impressed by the meticulous attention to detail in the installation guide itself.
For instance, the guide warned that many USB cables are unreliable and that you should use motherboard USB ports instead of hubs or front panel connectors. That kind of advice prevents a lot of issues. The whole installation took a few minutes and required nothing but a browser and a USB cable.
The key property of GrapheneOS, in my view, is that it’s not only open (LineageOS and Linux phones are open too) but that it’s pragmatic.
It’s actually usable. Even my banking apps work with no issues. I don’t need Google Play or Google Services, but they’re also one click away if I decide to get them. They lack root privileges, though, and can be pinned to a special quarantine environment, a sensible strategy in my opinion. The default browser, Vanadium, is also decent.
Scopes
GrapheneOS has many cool features, but I was particularly impressed with contact and storage scopes. You can deal with annoying apps requesting too many permissions by tricking them into thinking that all permissions are granted, while in fact they just got access to an empty sandbox.
You can drip-feed some apps with content. For instance, I often need to send screenshots via Telegram, so I can add the screenshot folder to Telegram’s scope while blocking it from accessing any other photos on my phone. I think Google will catch up at some point, but GrapheneOS is currently an uncontested champion of Android app isolation.
Drama
I avoided GrapheneOS for quite some time because of all the drama it generates online, but I must admit, none of that affects the product itself. It’s polished, and it didn’t require any sacrifices on my side, which is the only way for open software to succeed.
Future Plans
GrapheneOS documentation is vast and it’s actually a pleasure to read. Aside from the main documentation hosted on the official website, it’s worth subscribing to the project’s social networks because, for some weird reason, they post some valuable long-form advice as tweets.
While I do have some Twitter presence, I don’t trust the algo, so I subscribed to their Bluesky account via RSS to get all the content right inside Vesti. Mastodon also supports web feeds, so it’s just a matter of taste, but Twitter stopped supporting web feeds, unfortunately, so it’s nice that they’re cross-posting to alternative platforms.
I have a lot to learn, but the fact that I didn’t have to learn any of it in order to have a decent experience is a huge advantage of GrapheneOS compared to all the alternatives.