Hey, howdy, hallo,
Public Service Announcement before we get started. If you were planning on buying the Pixel 11 to install GrapheneOS on, WAIT. It appears to be missing hardware memory tagging, an important security feature, and might not be supported by the GrapheneOS project. For up-to-date information, you can check this thread.
I wanted to cover a few settings this month that you should test enabling on your device. These stricter protections are not enabled by default for all third-party apps because of compatibility, so you might encounter some issues after enabling them.
If you do encounter any problems, first try toggling the individual exploit protection settings for that app one by one to see what is causing the issue. Long-press the app > App info, then scroll down to the individual settings below "Exploit protection compatibility mode." Sometimes multiple settings need to be toggled. This method can be more time-consuming, but you have the added benefit of being able to leave some of the additional protections enabled.
If you still can’t figure out what is causing the problem, you can enable "Exploit protection compatibility mode" for the app having issues. Long-press the app > App info > scroll down and toggle on "Exploit protection compatibility mode." This changes multiple protections at once. You can see what it changes by looking at what changes in the items below it as you toggle it on and off.
Some of these settings will generate a notification if an app tries to use something you blocked. For example, you might open an app and see a notification saying, "This app tried to use native code debugging" (I forget the exact wording). This does not mean the app is malicious or that something is wrong. It also doesn’t necessarily mean you need to allow it. Test the app first. If everything still works, you can leave the protection enabled.
Some apps do require these things to function, unfortunately. If the app doesn’t work right, you may need to allow the specific thing it is trying to use. I wish I could give a clearer explanation, but with how many apps are out there, it’s impossible to cover every scenario. The main thing to remember is, don’t be alarmed just because you see an app trying to use one of the things below.
Memory Tagging is a little different. Again, don’t be alarmed, and it still does not mean the app is malicious. A Memory Tagging alert means GrapheneOS detected a memory corruption error and stopped the app. If you need to use the app, disable Memory Tagging for that app. You can also reach out directly to the developer and notify them of the issue. There have been some reported cases of this working successfully and the developer making the necessary fixes to the app.
If any app has issues after you enable one of the settings below, follow the instructions above. Each settings page also has more information at the bottom if you want to read more.
This is arguably the most important one to enable. If you don’t feel like doing anything else I suggest in this email, at least do this. This section of the GrapheneOS website has more details on the feature if you want to read more.
To enable it, go to Settings > Security & privacy > Exploit protection > Memory tagging. Toggle on "Enable by default."
This one is more likely to cause you issues, especially with banking apps, but it’s still worth enabling.
To enable it, go to Settings > Security & privacy > Exploit protection > Native code debugging. Toggle on "Block for third-party apps by default."
I haven’t really seen any issues when enabling this one.
To enable it, go to Settings > Security & privacy > Exploit protection > WebView JIT. Toggle on "Disable for third-party apps by default."
This one is more likely to cause issues with some apps.
To enable it, go to Settings > Security & privacy > Exploit protection > Dynamic code loading via memory. Toggle on "Restrict for third-party apps by default."
This one is more likely to cause issues with some apps.
To enable it, go to Settings > Security & privacy > Exploit protection > Dynamic code loading via storage. Toggle on "Restrict for third-party apps by default."
This one is most likely to cause you to see notifications when opening apps. Be aware, this toggle does not remove the Sensors permission from existing apps, only from new ones you install. If you want to remove it from previously installed apps, you must go into each app’s permissions and remove it manually.
To enable it, go to Settings > Security & privacy > More security & privacy. Toggle off "Allow Sensors permission to apps by default."
This one is enabled by default for compatibility reasons because it’s a permission unique to GrapheneOS. Stock Pixel OS does not expose this permission. You can read more about the Sensors permission here.
In other words: "Camera, Microphone, Body Sensors, and Activity Recognition already have their own Android permissions. The Sensors permission covers other sensors, including the accelerometer, gyroscope, compass, barometer, thermometer, and any other sensors present on a given device."
A word of caution: be careful if you get…ambitious and decide to remove the Sensors permission from all your user-installed apps and then start removing it from system apps. I recommend leaving the system apps alone. You’re likely to cause issues with OS functionality without gaining much of anything.
I realize, after reviewing this wall of text, this might seem like a lot. Go one by one, maybe enabling one of the options every few days. Test your apps and see if anything broke. If you currently have none of them enabled and then enable all of them at once, be forewarned: you’re likely to have a bad time. So be ready for it if you decide to.
I hope you had a great August, and I’ll see you in September!
-Josh
If you ever wanted to build a tower out of junk, here you go.
Why I left Proton Mail and Tuta for Stalwart
Arrested After Using GrapheneOS’s Duress PIN
A few things I make and work on:
Membership Site — Bonus content, monthly livestream Q&A, and more.
Consulting — Personalized help for individuals and teams.
Yellowball — Podcast hosting. No BS, no tracking.
"I need privacy, not because my actions are questionable, but because your judgement and intentions are."
— u/starrywisdomofficial, Reddit (2020)