Thoughts on Using Separate Devices for “Private” and “Everyday” Activities?

Absolutely, especially if you live in a country that “requires” (or at least makes it very inconvenient not to) use a device blessed by Apple or Google for banking or some related “official” activities. This means a GrapheneOS device for everyday use, and one cheap secondary device for the handful of apps which need a “certified” device. For work, a secondary Graphene user profile and a separate SIM may be enough however.

Yes:

There is an email qube referenced in this example, but that can be easily changed to a whatsapp qube or whatever name you want to identify it against the untrusted application.

If you’re thinking smartphone, Graphene’s Users feature is pretty much already this. By making multiple User profiles for different everyday tasks, you’re segregating that data just like having multiple phones, without actually having to manage multiple phones. Not to mention if one of the phones you’re carrying around isn’t GrapheneOS, your microphone, location, sensors, etc are all being tracked/logged to a degree.

I do still believe that separating tasks like you’re talking about is worthwhile, but there are more realistic ways to approach it. For example, assuming GrapheneOS, on a singular user profile you could have three levels of separation. Your personal/default profile, a work profile through say Insular or Shelter, and lastly your Private Space. Keep in mind Private Space will shutdown when you turn off your phone, where’s your work profile will continue to be active unless toggled off. So for example if you turn your phone off, Spotify would continue to play if installed on your work profile, but not on your Private Space.

An approach you could take, is keeping your personal/default profile “clean,” meaning only privacy respecting open source apps you trust/”private” tasks. Your work profile “moderate” say social, shopping etc. And your Private Space for more “aggressive” apps, like Google Maps, maybe banking apps etc.

Another benefit to this approach is isolating where you HAVE to have Google Play Services installed. Some apps like Google Maps and banking apps require Google Play Services to function. So if you want/need Google Maps, Gmail etc but don’t want to install Google apps on your personal profile, thus forcing you to install Google Play Services alongside them, by following the approach I laid out above, you can sandbox Google Apps/Play Services onto a private or work profile without the risk of any leakage from your more private tasks you would do on your personal profile.

I’ve found this three layer approach to be a good balance of isolating different aspects of life without too much hassle. Even the Multiple Users feature included with GrapheneOS I mentioned briefly at first can get annoying to navigate, so I’ve personally found this to be a feasible middle ground.

Hope this helps

I don’t have any experience with profiles, but is there a lag when switching between them? Are they both active simultaneously?

GOS multiple user profile feature is not the silver bullet against Google’s extensive reach.

There is a user report on GOS forum where Google managed to link a users’ real google account (logged in on another device and GOS device on owner profile) with the disposable account (logged in on GOS device on a non-owner profile).

IIRC there is no definitive answer on how it happened, but I suspect it is due to how GOS’s app sharing between profile works.

So, the bottom line, I would say, even you have to enable Google play service and google play store (due to workpalce email client requirement, for example), do not log in, do not use it, instead ustilise Aurora Store to obtain and update apps.

I’d personally prefer such device for tours only with good cameras. I have a dedicated pixel 7a for this. Reason? Small, wireless charging, small battery, good signals, speakers, and good enough to be a private buddy on long tours instead of carrying main phone, i prefer some cash, card, and a private phone where only urgent calls can be received

Do you have a link to that thread?

It is a good idea. Internet Usage Segmentation Setup - The OPSEC Bible

Yep, I should’ve mentioned that in my post. Not a perfect solution, few things are, but yes definitely use Aurora Store instead of Google Play, and refrain from signing in at all. In the vein of workplace email/task requirements one must complete on their phone, I’m not sure if there is a good solution except simply not doing it, and only completing work tasks on a designated PC. Even carrying around a work phone with you could increase your attack surface to an extent. I guess it all depends on threat model and convenience.

I would be curious for a link to that thread if you happen to have it.

There is maybe a 5 second delay when switching between each user profile. The owner/system profile has some background services that persist, but secondary profile and apps are isolated and inactive until you switch to that profile.

I spent some time looking for that thread, unfortunately I couldn’t find it, could be me forgetting the name of the thread (hence missing the keyword in search), or it got removed by GOS team (unlikely).

It is not too recent so my memory is getting vague, one of the keywords was Xiaomi, as the OP used Xiaomi phone as daily driver (!). I will spend some more time in searching, wish me luck.

I am confident it is this topic:

I also don’t have a link, but this is absolutely the case between the main profile and the private space. Those two profiles enjoy some separation but also can very much share data (you don’t even need additional software to share files between these profiles).

On my gos phone it very much appears I can have two profiles running processes simultaneously. This seems to be the default actually.

I’m not sure if using private space is a better option of segregating data when there are now concerns that it’s not a foolproof solution. Having multiple devices is expensive, but buying used and not necessarily the latest models can make this very cost-effective.

Does stock Android on the Pixel series and GOS have the ability to minimize or even prevent cross-app tracking? iOS has it.

As part of my goal of segregating my activities to different devices, I’m leaning on using iOS as my apps phone. I’ll install all the Meta apps like Facebook and WhatsApp, and Google apps.

As I stated before, I’ll use GOS only for web browsing and communication via Signal. Only FOSS software will be installed on the GOS phone.

For the Pixel phone, I am still leaning towards not putting GOS on it, as I want to have Google Play and have a phone to test and use Android-only apps. I can also put my work/employer data on it.

My Pixel/GOS phone will only be used for personal use/data. So this is now my thinking for a 3 phone setup. Comments?

Try it out and see if it works for you.

Yes, I will, as I already have the devices. I just need to flash one of the Pixels to GOS. I guess what I wanted to ask is: better to install Meta apps on iOS or stock Android?

Neither, it is better not to install them at all to begin with.

Of course, but it’s not a viable option. Telling people to skip Meta and Google isn’t going to work for the general population.