Security feature I really miss from iOS: biometric lock on ANY app

Security feature I really miss from iOS: biometric lock on ANY app

I'm currently transitioning from an iPhone to GrapheneOS on a Pixel 10a. Overall, I like the feeling of having more control over my OS. That said, there is one security feature from iOS that I really miss: biometric lock on any arbitrary app.

I think GrapheneOS is fantastic when the phone's state is before-first-unlock and when locked. However, if a malicious actor (thief) were to swipe the phone from your hands while you had it unlocked (or somehow learned your login PIN), I feel significantly worse on GrapheneOS than I did with iOS.

Now, is that a common or likely scenario? Probably not, so I'll live with it. But, on iOS, I felt very in control of locking any app with sensitive info or ability to initiate payments behind biometrics without relying on the app developer to implement it.

I don't know if this would require AOSP to adopt a similar feature, or if it's something Graphene can implement on top of AOSP, but I really do hope it eventually makes its way to the OS.

EDIT: to be clear, Private Space is close, but not the same. It can only automatically re-lock after reboot, system lock, or timed after system lock (as far as I can tell). With iOS, you can require biometrics on every app launch or returning to it.

EDIT 2: It looks like Android 17 was announced to be including this feature, but that it has been missing from the beta builds. I don't know if there are any more recent changes since this article was published in early July: https://www.androidheadlines.com/2026/07/android-17-missing-app-lock-feature-still-coming.html, or if it is/isn't still planned for Android 17.

u/Tight_Couture344 — 5 days ago

I really wish Joplin would put more effort into design

I’m using Joplin for E2EE notes and I’m okay with the utilitarian/antiquated UI if it gets the job done. But I’m also trying to convince my spouse to move to Joplin for our shared notes, instead of Apple Notes, and frankly it’s embarrassing.

Like, in 2026, a mobile notes app should not be this ugly.

reddit.com
u/Tight_Couture344 — 6 days ago

Sandboxed native app vs Vanadium PWA

Is there any appreciable security or privacy benefit to using Vanadium PWAs instead of sandboxed apps installed via the sandboxed Play Store, apart from Google associating the app download to the Google account you've signed into the Play Store with?

reddit.com
u/Tight_Couture344 — 10 days ago

How best to use Google Maps?

I live in a densely populated metro area with some of the worst traffic patterns you'll find. As such, I rely on traffic data in navigation and thus need Google Maps.

So, I'm trying to figure out the best apporach. I already use a throwaway-away google account for sandboxed Play store, should I just continue to do that for Maps?

What do you all do, assuming you've decided you need live traffic in navigation?

reddit.com
u/Tight_Couture344 — 10 days ago

How do I see how many LPs a booked flight will earn?

I'm new to AA from Delta and in Delta's website/app, you can see pending MQDs for upcoming flights. Is there anything similar for AA?

Assuming not, when I look at the cost summary, I see:

  • Base Fare: $453
  • Taxes & Fees: $193.78
  • Carrier-imposed fees: $0

So, I'm guessing I only take the $453 and then apply my status multiplier? I'll be Platinum Pro via status match when this flight occurs, so that would be $453 * 9 = 4,077 LPs?

reddit.com
u/Tight_Couture344 — 15 days ago

Should I just leave Ubuntu on my new Framework laptop or install Fedora?

I know...I know...not the first "which distro" question on this sub. But I'm really curious what y'all's advice would be for my situation.

First and foremost, I am a normie when it comes to laptop use. 95% of the time, I'm in a web browser or a spreadsheet. I'm not using it for gaming, photo/video editing, or any other "pro" use. I'm not running local LLMs or anything resource intensive, nor do I use any peripherals.

That said, I'm also more technically inclined than the average person. I've been using Asahi Linux on my 2022 Macbook M1 Pro (Fedora 44 with KDE Plasma) for the past month or so and I'm using my old 2017 Retina Macbook as a home server running Ubuntu, where I'm self hosting several light-weight things (contacts, calendar, rss, podcasts, music).

But the Asahi situation, while impressive, is still not great (mainly terrible battery). So, I decided to preorder a Framework 13 Pro with Ubuntu pre-installed. I just can't decide if I want to leave it with Ubuntu (probably updating every 6 months) or put Fedora Workstation on it. (I prefer Gnome to KDE Plasma.)

The things I care most about:

  • Battery life
  • Restarting my machine as infrequently as possible
  • The hardware being rock solidly supported and zero issues (especially the fingerprint reader)

I am the type to want to be on the "latest version" of things, but that mainly applies to desktop apps and the base OS. I can't figure out if there's any practical difference between:

  1. Pre-installed Ubuntu updated with each interim release, every 6 months
  2. Fedora Workstation updated with each new release, roughly every 6 months

All things being equal (same DE, same base OS update cadence, and updating my installed software to their latest versions), I would tend towards just leaving the pre-installed OS as is. I think Framework has said that they've specifically worked with Ubuntu for optimal hardware compatibility & support, so that makes me lean towards them for that reason too...but I also may be grossly misunderstanding and Fedora could be just as compatible.

Anyway, apologies for the long-windedness. Would love to know your thoughts!

reddit.com
u/Tight_Couture344 — 21 days ago

Should I encrypt my home server’s disk?

I’m new to running a small home server and I’m pretty happy with it so far. But, I’m running it on an ancient, low-power laptop (2017 Retina MacBook running Ubuntu) at the moment while figuring out what permanent machine I want to use.

As of now, that laptop has full disk encryption. But I’m going to be traveling internationally for an extended period of time soon and I’m concerned that if for whatever reason the laptop reboots (extended power outage, auto-update, etc), I’d be locked out of my server until I get back home.

On the other hand, leaving my machine alone at home without full disk encryption also concerns me. I don’t live in a high crime area, but still, it doesn’t feel like the best choice.

When I get my new machine, I’ll need to decide whether or not to encrypt. I’m leaning towards yes, but I’m curious what y’all do. And if you do encrypt, what do you do to mitigate the risk or losing access while away?

Thanks!

reddit.com
u/Tight_Couture344 — 23 days ago

Keyboard input dies frequently in Brave

I have been using Asahi Fedora with KDE Plasma for the last few weeks on my M1 MBP and nearly everything has been great. Apart from battery life, the only really annoying thing I've been dealing with is that the keyboard input in Brave will often just "die" (for lack of a better word).

I don't know how best to explain it. I'll click into a text input area of a web page/app and it'll be fine but eventually I'll notice as I'm typing that nothing is happening. No amount of re-clicking the input kickstarts the keyboard entry to work.

BUT the quickest way to fix it has been to press Cmd + L to jump to the address bar, then click back into the page and suddenly keyboard entry will work again. It seems to only affect the page itself, not Brave as a whole. Nor have I experienced it in other apps (though admittedly, the vast majority of my time is spent in Brave).

It happens with high frequency. Once every 5 minutes or so at least while I'm working. But, it tends to happen more when I'm switching into/out of many text input areas within a page frequently.

I don't even know what to search to figure out how to fix this. Or if it's even fixable. Or if it's an Asahi issue at all.

reddit.com
u/Tight_Couture344 — 26 days ago

Would love FIDO2 support on mobile for always_uv

I just signed up for Tuta and wanted to get my Yubikey 5C added. I have always_uv turned on so that a PIN is always required in addition to possession + touch. Worked fine on my desktop/browser, it prompts for a PIN reliably during 2FA.

However, on my iPhone, it's broken. It keeps looping: ask for tap > ask for PIN > fail > ask for tap > ask for PIN > fail > ask for tap...etc.

I don't know a ton about the differences between U2F and FIDO2, but my research suggests that this is an issue with not supporting FIDO2, which is what implements always_uv. When I toggled that off on my Yubikey, the 2FA over NFC went fine.

I've never really liked the idea of mere possession of the key being enough for 2FA, so supporting possession + PIN is pretty important to me.

reddit.com
u/Tight_Couture344 — 1 month ago

Saturday morning musings: ProtonOS (for mobile, akin to GrapheneOS)

First, I want to state clearly that I don’t believe Proton should do this in the immediate future. It would be a distraction when the focus should be on stabilizing & improving their existing apps/services.

That said, I’ve been going down the rabbit hole of de-Googling (and de-Microsofting/de-Meta-ing/de-Apple-ing) and also self-hosting/FOSS/E2EE.

It has been frustrating me how strong the technical limitations on Proton are because of the nature of E2EE. Specially, calendar and contacts. On any mobile operating system, the native dialer, texting apps, calendar apps, etc require a degree of interoperability that Proton cannot offer. Even on desktop, Mail Bridge is inherently less private/secure since it decrypts everything for your local client.

So it got me thinking…Proton should just have their own mobile OS (ala Graphene) where the native dialer, calendar, contacts, notes, tasks, file system, etc are all inherently compliant with E2EE.

Now, I am not an engineer nor a security expert. I have no idea if this even makes sense, or if that could be sandboxed in a way that still allows non-encrypted apps/services to sit side-by-side in the clients.

I’m actually kind of curious for those that understand this better than me - is this even technically feasible? Just conceptually?

reddit.com
u/Tight_Couture344 — 1 month ago

For contacts who won’t use Signal, which is better: WhatsApp or Telegram?

I already use Signal where possible, but I’ve got several contacts/friends (outside the US) who use both WhatsApp and Telegram and won’t switch. Most of them use both, so I could basically consolidate into one or the other.

Obviously, I know neither of these are open source. I just can’t decide which is worse: Meta harvesting metadata or Telegram not being E2EE for most purposes.

What would you do assuming cutting off ties with everyone who won’t use Signal is not an option?

ETA: I’m somewhat leaning towards Telegram but insisting on Secret Chats with everyone (except group chats since they don’t support it). I read Secret Group Chats are on in development though so hopefully they come sooner rather than later. I just really want to delete anything Meta.

reddit.com
u/Tight_Couture344 — 1 month ago

Sheets desperately needs improvements, should have been marketed as Beta at least

I am trying to de-Google/de-Microsoft right now and I was excited to see Proton debut Sheets, marketed as "New" (but not "Beta"). I don't do anything crazy with my Google Sheets, it's mainly just straightforward mathematical formulas and at worst, vlookups.

But wow, I spent this weekend trying to migrate 3 sheets, running into endless bugs. I've reported 9 different issues this weekend alone.

I get it, it's new. I've also worked my entire career at tech startups, so I know that moving quickly risks bugs, especially for a new product launch. But, this really should have been marketed as beta. "Usable" would be a stretch.

Now, I'm pretty committed to de-Googling, so I spent my time working around every bug I found to get my most frequently used Sheets working. And I'll continue to do so, reporting issues as I go. I just really hope the update that's coming this week delivers a lot of fixes for formulas and functionality that really should be working for a non-beta "stable" product (like paste special and dragging formulas not adjusting reference cells correctly).

reddit.com
u/Tight_Couture344 — 2 months ago

Running CLI on headless Linux server

Disclaimer: I am not a developer and ChatGPT has guided me through setting up my VM and attempting to set up the Drive CLI. Apologies if there are obvious things that I'm not catching.

I’m trying to use the official Proton Drive CLI on a headless Ubuntu Server VM for automated backups. The CLI itself installs and runs, but authentication fails when it tries to store the session in the Linux secret store. The server has no desktop environment.

Environment:

Ubuntu Server ARM64 VM
Headless / SSH-only
Proton Drive CLI installed
libsecret-1-0 and libsecret-tools installed
gnome-keyring and dbus-user-session installed

When running:

proton-drive auth login

I can open the browser login URL on another device and complete the login, but the CLI then fails with:

error: Object does not exist at path “/org/freedesktop/secrets/collection/login” (code: 19)
code: "ERR_SECRETS_PLATFORM_ERROR"

Testing secret-tool directly gives the same underlying issue:

secret-tool store --label="test secret" test proton-drive-test

returns:

secret-tool: Object does not exist at path “/org/freedesktop/secrets/collection/login”

I also tried running GNOME Keyring as a user systemd service, but it either hangs during startup or fails to create/use the expected login collection.

My questions:

  1. Is the Proton Drive CLI currently supported for fully headless Linux servers?
  2. Is there a recommended setup for the required Linux secret store on Ubuntu Server without a desktop environment?
  3. Is there a supported way to authenticate the CLI for scheduled/cron backups without GNOME Keyring or KWallet?
  4. If the CLI requires a desktop-style secret service, is server/headless backup automation not currently a supported use case?

My goal is simple scheduled backup automation: create Radicale backup archives on the server and upload them to Proton Drive.

reddit.com
u/Tight_Couture344 — 2 months ago

High-level de-Google/de-Microsoft plan, looking for feedback

Hi all, just looking for some feedback on my overall plan. My objective is to remove Google and Microsoft from my personal tech stack as completely as possible, while tolerating Apple where necessary. I use an iPhone, as does my spouse, and that part is non-negotiable, so I’m not trying to be perfectly anti-Apple. I’m mainly trying to stop depending on Google and Microsoft and remove my data from their servers completely.

Here’s my current high-level plan:

Domain Current Replacement / Plan Caveats / notes
Desktop OS macOS Linux as primary laptop OS iPhone remains & Mac is secondary laptop, so some Apple services stay.
Email Gmail / Outlook / Proton Proton Mail (with custom domain) Migration is underway
Calendar Apple Calendar (personal + shared) Radicale CalDAV on home Linux server, synced to iPhone + Thunderbird iCloud calendar for shared cal with spouse
Contacts Google Contacts / Outlook Contacts / iCloud Contacts / Proton Contacts CardDAV/Radicale iOS and Thunderbird as clients, Proton is only mail contacts
Tasks / reminders Apple Reminders Testing CalDAV/VTODO/Radicale Apple Reminders may stay because I use Siri heavily.
Files / cloud storage OneDrive / Google Drive / iCloud Drive Proton Drive for archive files; Syncthing/Möbius for active daily-use files Waiting for a proper Proton Drive Linux sync client.
Documents / office files Excel / Google Docs / Google Sheets ONLYOFFICE for Office files; Proton Docs/Sheets for lighter cloud docs
Notes Apple Notes Standard Notes for simple/personal notes; Apple Notes for rich/collaborative spouse notes Happy spouse, happy house
Browser Brave Brave Already using Brave.
Search Brave Brave Recently switched from DuckDuckGo to test
Maps Google Maps Apple Maps Functionality matters most here, so I’m tolerating Apple.
Messaging Apple Messages/SMS, Telegram, some WhatsApp Signal for those who will switch; keep Messages/SMS and Telegram where unavoidable Network effects make this hard. Goal is to use Apple Messages only for SMS
Music Apple Music Keep Apple Music Free from my Sapphire Reserve and I don't need it outside my phone
Passwords / passkeys 1Password Continue 1Password Might try out Proton Pass
MFA / backup codes KeePassXC + Strongbox via Syncthing/Möbius Current setup works; may consolidate into 1Password
Photos iCloud Photos iCloud Photos Not a priority right now

The biggest unresolved areas are Calendars, Contacts, Reminders/tasks, and whether CardDAV/CalDAV via something like Radicale and a local Linux server will ultimately work.

Maybe someday I'll try the GrapheneOS thing, but my spouse is very against moving away from Apple and I'm not looking to get a divorce. Admittedly, I do like Apple and between Google, MSFT, and Apple, I find them the least objectionable in terms of business practices. Still, I want to reduce my dependence where I can and focus Apple Services on places where I need to collaborate/share with my spouse.

Would appreciate thoughts, especially from anyone who has successfully de-Googled/de-Microsofted while still using an iPhone.

reddit.com
u/Tight_Couture344 — 2 months ago

Keep Dell’s pre-installed Ubuntu 24.04 or upgrade to 26.04?

I am a normal, everyday computing user. I basically only use my laptop for web browsing, web apps, and Excel. That’s 99% of my use. I am not a gamer, not a developer, and not a “creative” (no need for video or image editing software).

I just ordered a Dell XPS 13 9350 pre-installed with Ubuntu 24.04 LTS, officially supported by Dell/Canonical. My primary goal is to have modern/premium hardware running an optimized version of Linux where I can expect most things to “just work”, including the fingerprint reader and basics like sleep, wifi, bluetooth, audio, etc.

That said, I’m a tinkerer at heart. In my past, I’ve unlocked bootloaders and flashed alternative AOSP distros and played around with various Linux distros on older hardware (I’ve currently got Ubuntu 26.04 running on my 2017 retina Macbook 12”). Point is, I’m not afraid to get my hands dirty, but I intend this to be a stable machine for my actual daily use, so any tinkering I do would be in a separate partition.

So, my question… I like being on the latest versions of things. With 26.04 LTS out, my natural inclination is to upgrade the pre-installed 24.04 LTS to the newer one. BUT I also don’t want to compromise on hardware compatibility. Is there much risk to this? How likely is it that things might break (irreparably without restoring 24.04) if I upgrade to the “unsupported” 26.04? Will the Dell/Canonical-blessed drivers carry over with an in-place upgrade?

Anything else I should consider?

reddit.com
u/Tight_Couture344 — 2 months ago

Keep Dell’s pre-installed Ubuntu 24.04 or upgrade to 26.04?

I am a normal, everyday computing user. I basically only use my laptop for web browsing, web apps, and Excel. That’s 99% of my use. I am not a gamer, not a developer, and not a “creative” (no need for video or image editing software).

I just ordered a Dell XPS 13 9350 pre-installed with Ubuntu 24.04 LTS, officially supported by Dell/Canonical. My primary goal is to have modern/premium hardware running an optimized version of Linux where I can expect most things to “just work”, including the fingerprint reader and basics like sleep, wifi, bluetooth, audio, etc.

That said, I’m a tinkerer at heart. In my past, I’ve unlocked bootloaders and flashed alternative AOSP distros and played around with various Linux distros on older hardware (I’ve currently got Ubuntu 26.04 running on my 2017 retina Macbook 12”). Point is, I’m not afraid to get my hands dirty, but I intend this to be a stable machine for my actual daily use, so any tinkering I do would be in a separate partition.

So, my question… I like being on the latest versions of things. With 26.04 LTS out, my natural inclination is to upgrade the pre-installed 24.04 LTS to the newer one. BUT I also don’t want to compromise on hardware compatibility. Is there much risk to this? How likely is it that things might break (irreparably without restoring 24.04) if I upgrade to the “unsupported” 26.04? Will the Dell/Canonical-blessed drivers carry over with an in-place upgrade?

Anything else I should consider?

reddit.com
u/Tight_Couture344 — 2 months ago
▲ 8 r/linux

Lack of reviews of Linux experiences from non-creators/non-gamers

I’ve been getting deep into trying to revive my old 2017 12” Retina MacBook by slapping Linux on it. It’s been a lot of fun, but ultimately doomed because the battery is garbage and not worth replacing.

I’m not new to Linux, and I am technically capable, but it’s been over a decade since I last used it. I’m also not an engineer, nor a content creator, nor a gamer.

What I’m trying to determine for myself is if I want to invest in a real, more modern laptop to see if I could really make Linux my personal daily driver. Honestly, it’s mainly just out of curiosity and interest - no other compelling reason. (My current MacBook Pro is fine, but it’s getting older and since it’s M2, only supports one distro with somewhat limited support.)

But every single review on YouTube and on most review sites/blogs is 90% dominated by choosing a distro then barely mentioning anything other than gaming and video editing.

I get it, the Venn diagram of people who produce “trying Linux” content and people who are PC gamers + content creators is probably just a circle. But it really tells me absolutely nothing about how good you’ve found the alternatives to Excel to be, especially if you’re syncing via OneDrive. Or how the open source mail clients work for you vs Apple Mail or Outlook.

And it’s almost always from the perspective of coming from Windows. It’s been longer since I’ve run Windows than Linux. What I want to know is how you’ve found the spotlight alternatives, or Airdrop alternatives. Yes, I could research what all these alternatives are, but I like to watch/read reviews from people who have actually experienced the switch and tried.

Anyway, just a rant as I’m trying to decide whether or not to buy a new laptop.

reddit.com
u/Tight_Couture344 — 2 months ago

Deciding between the new XPS 13 and the 2025 XPS 13 with Ubuntu pre-installed

I'm looking to buy a machine specifically only to run Linux. I'm tech-capable, but not an engineer.

I’m looking for the best build quality for the lowest cost. My initial instinct was to look for a machine that came pre-installed with Linux with official OEM support. That led me to the 2025 Dell XPS 13. But I also saw the new XPS 13 that was just announced at a lower price point. From what I gather, the pros/cons are:

- XPS 13 (2025): “official” Linux support, better processor. But worse keyboard, trackpad, function row.
- New XPS 13 (2026): slightly cheaper and better keyboard, trackpad, function row.

If I upgrade the new XPS RAM to 16 GB, the prices are basically the same, so it's not a price-driven decision ($50 unless I can find a student to buy the new one for me...). And I'd be wiping Windows unless there's a compelling reason to dual-boot.

Is there any real advantage to having "official" support for Ubuntu? Does that mean that machine has drivers specifically developed for it (fingerprint, audio, suspend/hibernate, etc) by Dell/Canonical and therefore more stable? Would those drivers be useful for any distro I put on it if I don't keep their build of Ubuntu?

I haven't actually tested the keyboards or touchpads myself, so I can't say for certain, but if the poor reviews are to be believed, is the "official" support and the better processor worth the tradeoff? What would you do?

reddit.com
u/Tight_Couture344 — 2 months ago

Best distro for 2017 12” Retina MacBook?

Following up on my recent post (https://www.reddit.com/r/linux\_on\_mac/s/ajEGk096U8) about issues running Lubuntu LXQt on my Retina Macbook 12” 2017, I’m asking the age-old question: which distro?

I’m asking this rather than just reading and picking another because this machine is, to my understanding, appreciably different from the Macbook Air and Pro models from the same era. It’s running a Kaby Lake CPU (Core i5-7Y54) processor rather than the U-series Intel chips in the Airs and Pros. It also has a non-standard screen size (2304 x 1440), used only in this model.

On Lubuntu, I was able to get the basics working: wifi, audio, trackpad. But the major issues left are:

- No suspend or hibernate (have to manually boot & shut down every time I use it)
- Poor scaling (different apps display at different sizes, tiny click targets, gigantic icons, wonky app header bars, etc)

First question: has anyone found a good distro for this model specifically? I suspect not, so I’ll ask my second question: given all that, what would y’all recommend?

I can deal with poor scaling if necessary, but not being able to close the lid and reopen it is kind’ve a deal breaker.

reddit.com
u/Tight_Couture344 — 2 months ago

Am I wasting my time trying to make Linux work for a Retina Macbook 12" from 2017?

I’m trying to revive an old Retina Macbook 12" from 2017. It's long unsupported by Apple and I wouldn't mind having a smaller machine to travel with vs my current Macbook Pro.

But the hardware and system resources are...mediocre:

* Intel Core i5-7Y54 (Kaby Lake, ultra-low power, dual-core mobile processor)
* 16 GB RAM
* 256 GB storage

All in all, that wouldn't be a deal-breaker. But, I've been fighting with Lubuntu LXQt to get suspend or hibernate working and I've basically accepted the fact that neither will work. And it cannot seem to figure out how to properly scale for the 2304 × 1440 pixel display (226 ppi) without individually scaling individual apps and hardcoding window header sizes.

Now, I'm not a software engineer, but I'm tech capable. I'm willing to try different configs, kernels, flavors necessary to get this machine in a functioning state. But I wonder if I'm chasing an unrealistic dream given how unique this specific machine is.

reddit.com
u/Tight_Couture344 — 2 months ago