Well I just replaced my aging LG G6 with a new Google Pixel 8a running GrapheneOS. The G6 was based on Android 9 which was initially released in August 2018, and my last update was January 2019. The big issue, after 6 years since OS initial release, apps are starting to not support Android 9. Add to that, my USB-C plug was getting questionable in terms of retaining charging cables and my fingerprint reader has not worked for years.
So how to replace the G6? Well I choose a new Google Pixel 8a and GrapheneOS. The Google Pixel is one of the better supported hardware devices in the after market ROM landscape and GrapheneOS seems to be one of the most popular ROMs.
It took me about a week to do the transition. Lot of that was just normal when moving everything to a new phone and not using the vendors automatic tools. The actual initial setup and flashing though was pretty straight forward. It was a bit emotionally difficult to take new $400 hardware and then just simply re-flash it risking say bricking. This turned out to be a non-issue.
Benefits I see from doing this:
- Lack of Cruft. The lack of all the vendor loaded cruft was very nice. My old G6 has about 17 apps that I could never really delete because they were flashed into the ROM. Many of them fairly large Google suite apps.
- Profiles. The new phone can fully use user and work profiles, plus with Android 15 it has the Private Space feature. GrapheneOS also supports up to 31 user profiles, not the 4 supported by most distributions. I actually use the Private Space to contain my Google Play Services and Google Play Apps and otherwise just the owner profile. Might have been better to look at some of the other options, not sure.
- Storage Scopes are really useful. One can restrict App access to only certain folders. I have already used that a few times, probably more in the future.
- Backup. GrapheneOS allows one to do App backups to your own media or cloud storage. For stock systems normally only Google Drive is allowed, which I would never use.
- Sandboxed Google Play. I like the idea of sandboxing Google play. Presumably it should be more compatible then MicroG and some Apps require Google play. Interestingly the number that do seems fairly small. I actually further placed all my Play Services related stuff in a Private Space so I know what apps can actually use it.
- Device Integrity Check. Verified boot and some other device integrity checks are properly supported and so many apps that required them should run, though not all. This is not always the case with third party ROMs.
- Wifi Calling and Messaging seems more stable then my old G6. Maybe just the difference between Android 9 and 15.
- Updates should be supported for a full 7 years from initial device release which as of late 2024 is about another 6.5 years. My original G6 had about 1 year of updates.
- Hardening. Graphene has a bunch of hardening features not in typical distributions. Storage Scopes and really good Profile support are a couple I’ve mentioned, but there are many others.
One question that took me a while to consider is where to get Apps from. There are pros and cons and a lot of discussions about this. In the end, I used the GrapheneOS App Store, F-Droid, Accrescent, Obtanium, and the Aurora Store in that order for my owner profile, then installed sandboxed Google Play Services and the Google Play app in my Private Space.
As of now my limited experience with GrapheneOS has all been positive. The one App that I have had issues with is the UPS app for some reason. For that I’ll just use their website for now. Not sure if the UPS app can be made to run or not. My understanding too is that Google Wallet may not fully function though I have not tried it and have never used it before anyway.
If your interested in GraphneneOS and have any specific questions, feel free to ask. All the best.
I bought my Pixel 8a like a month ago for 380 euros and the first thing I did was install GrapheneOS
I only stayed on the stock system long enough to pull all the updates and make sure all the hardware worked just fine so I don’t know what I’m missing out versus stock ROM but so far it works absolutely perfect.
I compiled the system and kernel myself since it makes sense when you are installing a security/privacy centered OS and it instructions worked without a hiccup.
I have three users for compartimentation in my setup.
-
Owner user only has source available apps compiled by myself barring Firefox because its a pain. I run Shelter to create a work profile where I have the sandboxed Play Services for some critical proprietary apps that I need notifications from.
-
Games user is self explanatory. It’s not allowed to run any applications in the background and I am just there logged on my google account so I can get some of the subscriptions I pay.
-
“Swamp” user. It’s not allowed to run any applications in the backgrouns either and I just use it for bottom of the barrel apps like Discord, Instagram… to stay in touch with some irl friends.
This sounds pretty cool. Are there other types of restrictions you can have?
I just recently switched myself from a crusty old Motorola to a Pixel 7.
Only thing I hate is material you, which isn’t a grapheneOS specific thing so I don’t fault them for it. Otherwise I am enjoying grapheneOS so far.
I just made the switch (from s22u to pixel 9 pro fold) over the weekend, the debloating and basic common sense security features are such a huge improvement.
Gonna give the whole “folding phone” thing a try for a while before I make any judgements on it, but im absolutely set on sticking with grapheneos.
basic common sense security features are such a huge improvement.
Can you list some common sense security features?
Disabling wireless when not in use
storage scope limitations for apps (random games don’t need full drive access)
fine control over USB-C port behavior (data and/or power while locked vs unlocked)
using passcode/password for device unlock while still being able to use fingerprint for individual apps.
Regarding folding phone, I admit I’m a little scared of that tech for now. Not saying bad, I have no experience to say either way. I’ll be interested in how that works out. In another life I use to work with some people that were trying to develop this sort of tech a decade or two ago. Never heard where their work went, and no idea if same.
I’m a bit undecided on it even with it in my hands. Not a fan of how cases have to be more or less glued onto the device, and that hinge is a major physical weak point (I’ve got a Ghostek case with hinge armor right now). So when I finish getting the device set up how I want and finally swap my sim over, I’ll need new adhesive (the sim card slot is not accessible with the case).
That said, the crease isn’t that bad. I anticipate being able to view manuals on the bigger screen to be very nice. The outer screen is apparently the same display panel as the pixel 9 pro, so it’s not an ultra narrow display like the samsungs.
It’s physically about the same size as my s22u, just slightly thicker
Edit: honestly, the more I think on it, I’m leaning towards returning the fold in favor of a regular 9 pro. I just don’t feel comfortable carrying around a nearly $2K device in my pocket. It’s a very nice device, but for a bigger screen, there are much cheaper options (actual tablets), and there’s much better case options for more main-line phones anyway.
I had been intending to replace my OS with GrapheneOS since last week but have been delayed—need to back up some stuff I haven’t done yet—and this post comes at a good time for me. Thank you for making it.
I did the same thing a few days ago. Just that I switched from an old Pixel with GrapheneOS to the 8a. It’s really come a long way and it’s ridiculously easy to flash GrapheneOS with their “web installer”. Took a few minutes of clicking on the next button. I’m always excited and eager to replace some firmware or operating system with a more free counterpart… But I still need to move a lot of stuff. I decided to clean up and not to move all my mess… Guess it’ll take a few more days until I’m done with that.
Yes. The actual move of apps and data takes a long time. Number of Apps on a phone tend to multiply over the years. Then there is the moving of app data if you don’t do App backup/restore. My old phone probably had about 130 apps on it which was nuts. I dropped about 50 apps on the transition though half of those will probably seep back in over time. I had to switch apps in about 20 cases, either app discontinued, deprecated, or just preferred to find a FOSS alternative. I also want to see if I can use the web and/or PWAs more rather then always installing an app for everything.
By the way, to move data, I found it helpful to setup syncthing-fork between the two phones.
Thanks. And good call, seems we’re doing similar things. I also had 100 more Free Software apps from F-Droid that sounded useful, or I wanted to try them and never did… These were easy to “clean up”.
The app for my password manager (pass) isn’t being developed any longer. Guess I have to tackle a few more things.
Btw, do you happen to know how I’m supposed to move apps which are paired to Bluetooth devices? I got a body weight scale and a fitness tracker, and I’m not sure if I can just copy it to the new phone and it’ll continue to work with the paired device…
Probably every App/Device is different, but I think you should be able to just install the app on the new device and re-pair. I know the Oxygen monitor I have was fine with that. A counter example, not sure about things like Chomecast… do thay need to be unpaired first if you move them to a new ‘Home’?
The bigger question is do you loose the data? If the data is all in the cloud and you have a user ID and pass, you probably don’t have to move the data yourself. If it’s on your device, then look for a backup/restore option in the App and move the data that way. Some apps have a special transfer procedure too (Signal, Libby, etc). If none of these, you may loose the data if you cannot find another way. For example “Hearing Test” an App I use explicitly prevents moving data unless you pay for the Pro version.
The other way to move apps (which I have no experience with) is App backup/restore as done by Google or through GrapheneOS with Seedvault but these tend to be limited to only same or similar OS/Device. That is App specific too in what the author allows as they have some choices of how they implement it.