Private Space on Android 15 GrapheneOS
Can apps be installed via adb in private space or via copying it from the main profile, like to other users, or the only way to do it is via a store, like Play Store or Aurora?
- Edited
cdflasdkesalkjfkdfkjsdajfd Yes, you can adb install to the private space.
$ adb shell dumpsys user | grep "Private space"
UserInfo{##:Private space: ......
##
is the userid of your private space.
Then $ adb install --user ## file.apk
Is there a way to do not unlock private space using the fingerprint but configure fingerprint to unlock some apps in private space? I have set private space to be unlocked by password and fingerprint settings to do not be used to unlock the device but when I unlock private space the fingerprint unlock is displayed instead of the keyboard.
Thanks
- Edited
Will the settings on the Private Space be extended like those on the other profiles?
Is data unrecoverable when deleting Private Space as when deleting profiles?
Edit : It seems to be the same with the deletion of data :
All forms of profiles have separate encryption keys. You can keep a Private Space at rest while the Owner user is logged in just as you can with a secondary user.
Is data unrecoverable when deleting Private Space as when deleting profiles?
Yes, it's similar to a user profile especially if you set a dedicated lock method but can be reliably deleted even when sharing the lock method with the Owner user, since it still has separate encryption keys and protection. It shouldn't be possible to get the data when Owner is unlocked but the Private Space is not even when the lock method is the same. Reboot is still best to get data back at rest instead of relying on things being zeroed as they should be.
We strongly recommend it as a replacement for a work profile managed by a local profile admin app. It has better OS integration and isolation.
I am really struggling to understand the messaging here. I generally think of "integration" and "isolation" as generally diametrically opposed. I like how existing profiles are completely separate. I don't want any possibility of data leakage between/across them. Are you using "work profile" as a general term for any secondary profile (meaning one connected to a dayjob, etc) or is that something else?
@GrapheneOS What exactly would be the benefit of deleting my secondary profiles and recreating them as Private Spaces within the Owner Profile? What are the precise differences between these two feature sets?I'm sure I'm not the only one wondering this. A simple page in the docs would be greatly appreciated once this feature has matured a bit more.
Thanks for all you do.
strict-marsh Work profiles are exactly what it sounds like - a separate profile that runs side by side with the owner. Usually these will be created by an app like Shelter or Insular. They offer the least isolation compared to Private Space and secondary user profiles, but are probably the most convenient due to the amount of integration in the settings.
strict-marsh What exactly would be the benefit of deleting my secondary profiles and recreating them as Private Spaces within the Owner Profile?
Note that at present there is only one Private Space, associated with the sole owner profile. Secondary profiles are not the same thing as work profiles, so if you are using secondary profiles at present the recommendation to switch from a work profile to Private Space is not applicable.
Why Private Space unlock requires password only first time that's unlocked and no every time?
cdflasdkesalkjfkdfkjsdajfd APKExtractor
I was able to easily copy any app just install in owner profile with a 1-click share to the private space download folder.
- Edited
missing-root how to disable the system clipboard if I use Florisboard clipboard? Thank you.
UndercoverBozo is accessible the private space download folder from the normal space?
cdflasdkesalkjfkdfkjsdajfd is accessible the private space download folder from the normal space?
No. Its actually quite frustrating to move files between.
- Edited
secrec you can use LocalSend to send files BTW normal and privacy spaces. It's working very well.
But if it's not visible, I do not understand the answer from UndercoverBozo ...
strict-marsh What exactly would be the benefit of deleting my secondary profiles and recreating them as Private Spaces within the Owner Profile?
The advantage of "private space" over a secondary profile is the fact that the two profiles can be used simultaneously rather than needing to go through the cumbersome process of switching between them.
secrec yes, but for now, I think privacy will be compromised due to the PS cannot be locked with password if you configure fingerprint to access some apps in the PS.
cdflasdkesalkjfkdfkjsdajfd Private Space is fingerprint-locked if you have configured fingerprint locking, the PIN code is requested on first start-up. Even if you use the same PIN/fingerprint for the owner profile and Private Space, these are still two isolated profiles with separate encryption/decryption keys, so should be fairly secure, of course you can use a different locking method from the main profile.
cdflasdkesalkjfkdfkjsdajfd you can use LocalSend to send files
Like I said, the process is frustrating.
- Edited
Xtreix If someone takes my phone and wants to access the private space, they can force me to enter my fingerprint, but if I have to enter the password, I can use the Duress option to erase the device; but the password is only requested once