• sugar_in_your_tea@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    Cool.

    Since you’re here, do you know if SIMs “just work” with different profiles? Can I restrict them to a specific profile? I’m guessing SIMs are a completely separate concept from profiles (which AFAIK just manages apps), but this is my first time with GrapheneOS.

    • As far as I can see, no. But what benefit would that really have? Network settings (including mobile networks) are global. The only thing that’s profile-specific is your VPN setting. You can only disable a profile’s ability to use the phone/SMS feature. Profiles generally manage apps, user data and some settings.

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 month ago

        The benefit is that I could block apps installed to one profile from using my data (i.e. wifi only), while allow apps on the other to use it. I could install something like NetGuard, but I also use a VPN, and it’s one or the other with that IIRC (at least on my old phone, I can only use one VPN at a time).

        • Ok that actually makes sense. I just realized that the fucking iPhone has this feature, but Android doesn’t. GrapheneOS doesn’t implement any custom features that aren’t privacy/security related. And no, unfortunately you don’t get a second VPN slot either.

              • sugar_in_your_tea@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 month ago

                I meant it more tongue-in-cheek :)

                My threat model isn’t such that I need it, it’s just really annoying. GrapheneOS does allow blocking network per-app, which is a sufficient workaround. It’s a bit tedious, but I can do the following:

                1. disable network on sensitive apps
                2. disable NetGuard and enable other VPN
                3. finish what I was doing
                4. undo step 2
                5. undo step 1

                I really wish there was a way to get VPNs and NetGuard playing nicely together. I want all traffic to be filtered by NetGuard, and then routed over the VPN. This is trivial on Linux, but apparently not so on Android, which is a shame.