A tip for those who cannot run GrapheneOS…

… because they don’t have a Pixel phone. GrapheneOS is by far the best mobile OS, and its built-in Vanadium is the best browser engine for Android-based phones. But Vanadium only runs on GrapheneOS, so what should users of other systems choose?

That question was recently asked on the GrapheneOS discussion channel, and the answer was Cromite. And indeed, just look at the long list of features needed to make Chrome a bit more private and secure

You’re welcome.

Where the mice live…

We live in a housing area which is rather nice – it has a kindergarten nearby, several playgrounds for kids small and big, and lots of green areas, with bushes and trees. In between, there are some pathways for us humans to walk (and some like to cycle there, too, or ride their – now electric – scooters, or even drive in with cars).

I got up early this morning, before dawn, and let the cat out soon after sunrise. She disappeared on one of those pathways which we can see from our dining area window – and like last time, she was back after less than two minutes, carrying a mouse. I let her in, expecting to find a dead mouse which I could take away from her – but this time, the poor thing was still alive, so there was an inhouse chasing and hunting time for the cat, which she surely enjoyed.

I tried to catch the mouse as well to set it out again, but it ran under my computer desk to hide from that deadly predator. I was thinking about how to save the poor thing – doing nothing meant that it would starve if not moving, or being killed if it dared to come out again. Locking away the cat in another room and then moving my computer desk would mean that I would have to chase it through all of the flat. I also didn’t know how bad it was hurt already, so I thought about the mouse’s status as maybe in-between, like Schrödinger’s cat, of which you couldn’t really tell if it’s dead or alive, so in my thoughts I named that mouse “Schrödinger” already.

As it turned out, my wife was far more clever than me – when she returned home from work, she brought a shoe carton in which we could trap the mouse (after locking away the cat), so I could bring it out again and release it beside some big rock and bush. The mouse looked up at me, and I left it there…

It was the second time that our cat came back from that pathway carrying a mouse in under two minutes, so by now we know where the mice live – but so does the cat…

Interesting guesstimations about Linux usage

Liam Proven writes about Ubuntu Linux – and that’s all very nice to know. As the leading European “corporate” Linux vendor, I wish them luck – and suggest the usage of Ubuntu to our European parliament, the governments in European countries, and of course the business users as well.

Still happily running Debian here, as well as Arch for peeking into the newest stuff. But others in my family are happy with Ubuntu since years. And it’s indeed a nice one, including Ubuntu Studio for artists.

Like always, thanks for reading.

Even state hackers won’t get into your Pixel phones…

… but only if you run GrapheneOS on them. Here‘s a nice conclusion.

Oh, and for those who still think that they have nothing to hide – a user called “final” has a nice comment about that on the GrapheneOS forum. He wrote:

“GrapheneOS, Google, Samsung, Apple and the greater mobile security community is neither a “potential criminal” or a “malicious actor”. These authoritarian talking points are stale and come from the same playbook as “Think of the children” and other fallacy phrases meant to attack you as being a danger for something as simple as wanting to protect yourself. GrapheneOS protects users against criminals, from hackers, abusers, stalkers and corrupt up to the most capable and wealthy in business and government.

These companies do not engage in ethical practices and virtues that make you a trustworthy member of the security community, like responsible disclosure. A software developer is entitled to know that their software is being or is attempted to be exploited by a wealthy, influential threat actor. What we do against these groups is an act of self-defence. Not trying to do anything about it is complicity against the use of these tools to violate people’s basic human rights. Despite the amount of controls they claim to make on their products, they still cant combat illicit use of it, as seen in Serbia. At the bare minimum, single illicit use of these tools anywhere in the world immediately makes their exploit a cyberweapon that must be neutralised. Them being an exploit alone is the only justification we need to seek disrupting these threat actors’ work.”

More here

The reaction on being evil

I have written about Google becoming evil before, and that it’s getting even worse. And even if these aren’t really news for me because I’m following the GrapheneOS discussion forum, here is a nice conclusion on what will be their reaction.

The GrapheneOS team prefers to wait with the announcement until that “major OEM” does it. And whoever that is, I wish them both luck, and that this sole secure phone OS will become much more popular over time, and will sell like the proverbial hotcakes. There really is no need to be logged into any big provider all of the time, and that they can spy on your every move, in fact that should be forbidden – it’s NOYB guys!

So in case you want that only secure phone OS right now, get a Pixel 9a which is currently the newest supported device which can run it. Or if you can wait a year or two (like me), then this new and yet unnamed OEM might be the one to get a phone from.

Like always, thanks for reading.

Updated our Pi-Hole

This morning I read that the RaspberryPi OS has a new version, and is now based upon Debian Trixie. And although it is strongly recommended to not doing so, I’ve looked up their short howto on upgrading, and decided to do it. I did *not* de-install pihole, nor pivpn, or the radicale calendar/contact server, so I took quite a risk – but since I’m the only user of the latter two packages, I was okay with potentially losing that.

In the end, it all worked as expected, and I now have a debian_version of 13.1 running on our little DNS sinkhole and VPN and calendar server. Which is cool – but what should I say, it’s Debian after all, isn’t it? My last step was to ‘sudo apt modernize-sources’ after the needed reboot, and that was it – our anti-spam and anti-tracker filter just looks like before:

As always, thanks for reading.

Running backups

As regular readers of this blog might know, I’m using GrapheneOS on my phone. And no, I’m not using the sandboxed Google services, because I don’t want and need to. In fact, I’m totally off the Google network, not even using their Firebase push service for the Signal chat application, but an alternative one with a fork of Signal called Molly – which works perfect.

My wife recently got a new phone, and copying all of her stuff from the old to the new one was a piece of cake – other than me, she *is* using Google extensively, and so everything is backed up into their cloud anyway, just like others do it with Apple and within that ecosystem. But what do you do if you don’t want any of that, and want a not-logged-into-anything life?

Simple: GrapheneOS comes with an app called seedvault, originally funded by CalyxOS. That, too, could back up into a cloud, but why should you pay for an own cloud service when you can get alternative methods for a one-time payment? A 128GB USB stick at the local drugstore is about 10€ by now, and that’s exactly the size of my phone’s storage (and I don’t really use all of that), so once configured, backups are the proverbial “plug & play” solution. Yep, just like this:

And my October backup just finished faster than I could write this article…

Again, thanks for reading.