GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use
Modern smartphones collect continuous telemetry by default. This article provides an exhaustive engineering guide to deploying, configuring, and operating GrapheneOS, an operating system designed to return full control to the device owner.
Core Principles
The system rests on three fundamental principles: rejection of proprietary ecosystems to reduce surveillance risks, Zero Trust relying solely on cryptography and independent code audits, and strict compartmentalization that physically and logically separates work environments.
Compatibility and Installation
GrapheneOS officially supports only Google Pixel smartphones due to strict hardware security requirements including specialized chips and Verified Boot implementations. Devices must have an unlockable bootloader. Users should purchase only official factory-unlocked global versions and avoid carrier-locked models such as those from Verizon or AT&T.
Installation is performed through the official Web Installer at grapheneos.org/install/web. The process requires backing up data, enabling OEM unlocking in developer options, booting into fastboot mode, unlocking the bootloader, flashing the release, and then locking the bootloader again. After installation, OEM unlocking should be disabled for security.
Owner Profile Configuration
The owner profile must contain no proprietary software or Google services. Users set Russian as the primary language, install system updates, configure a strong PIN with shuffling enabled, and activate automatic reboot after 18–24 hours to clear encryption keys from RAM.
Applications are installed via the built-in Vanadium browser and the Obtainium package manager downloaded directly from its GitHub repository. F-Droid is avoided because it re-signs packages and delays updates.
FOSS Applications and Security Tools
The guide recommends numerous open-source applications installed through Obtainium: KeePassDX for password management, Aegis Authenticator for 2FA tokens, AmneziaVPN and Hiddify for VPN and proxy connections, Signal and Element X for encrypted messaging, and the full Fossify suite for files, gallery, music, documents, camera, and notes.
VPN kill-switch is enabled in network settings to block all traffic outside the encrypted tunnel. Additional utilities include PCAPdroid for traffic analysis, Shizuku for privileged API access, and App Manager for permission auditing.
Isolated Regional Profiles
Separate user profiles named American, European, Russian, and Chinese are created to isolate untrusted proprietary applications. Each profile disables calls and SMS. The American profile uses sandboxed Google Play, the European profile uses Aurora Store, the Russian profile uses RuStore, and the Chinese profile uses Huawei AppGallery. Basic utilities such as LocalSend and Inter Profile Sharing are copied into each profile to enable safe data transfer without network exposure.
Related articles
Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection
A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.
WhatsApp Introduces Parental Controls for Teen Privacy Settings
WhatsApp, owned by Meta (recognized as an extremist organization and banned in Russia), has rolled out new parental control tools for family accounts. Parents can manage privacy settings, group participation, channel access, status visibility, and Meta AI usage for teens, but cannot read personal messages due to end-to-end encryption. All controls are voluntary and require joint setup with the teenager, protected by a single PIN code that prevents easy reversal of restrictions. Notifications alert parents when teens join or leave groups or when group sizes change significantly. Separate options cover channel usage, viewable statuses, and audience controls for teen posts. Meta AI access can be set to a standard 13+ mode or a stricter Limited Content mode with undisclosed restrictions. The company plans to expand these features gradually based on family feedback while maintaining encryption protections.
Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained
A viral social media video sparked widespread concern that Wi-Fi owners could view users' search history and visited sites simply by knowing the router password. Security experts from Cybernews and Surfshark clarified that modern HTTPS encryption prevents reading of actual search queries or page content. However, metadata such as DNS requests, SNI fields in TLS handshakes, and device MAC addresses remain visible to the network administrator. The introduction of Encrypted Client Hello (ECH) under RFC 9849 aims to hide domain names, yet Russian authorities have blocked many ECH-enabled connections since November 2024. Corporate or school-managed devices with installed root certificates represent the main real-world exception where full traffic inspection is possible. VPNs hide destinations from the local router but transfer visibility to the VPN provider. The article emphasizes that password-protected Wi-Fi grants access only to connection metadata, not browser history.
Yandex Deploys OPRF Protocol to Protect Phone Numbers in Mandatory Audience Measurement Data Sharing
Yandex has detailed a cryptographic scheme using Oblivious Pseudorandom Function (OPRF) to help Russian audiovisual services comply with new legislation requiring transmission of user identifiers linked to phone numbers. The approach replaces a naive shared-secret hashing method that created a single point of compromise across dozens of competing companies. Instead, two independent third parties each hold separate secret keys and process blinded elliptic-curve points derived from normalized E.164 phone numbers. Services obtain deterministic identifiers without learning the third-party keys and without exposing raw numbers to the authorized research organization. The design distributes trust, limits offline brute-force attacks to scenarios requiring both keys plus final identifiers, and adds rate limits plus key-rotation capabilities to deter abuse. Yandex positions the solution as a practical compromise between regulatory demands, competitive secrecy, and user privacy.