<oembed><type>rich</type><version>1.0</version><title>final [GrapheneOS] 📱👁️‍🗨️ wrote</title><author_name>final [GrapheneOS] 📱👁️‍🗨️ (npub1c9…7sqfm)</author_name><author_url>https://yabu.me/npub1c9d95evcdeatgy6dacats5j5mfw96jcyu79579kg9qm3jtf42xzs07sqfm</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>For the people wishing to see on Nostr the features #GrapheneOS Vanadium browser has:&#xA;&#xA;- Type-based Control Flow Integrity enabled&#xA;&#xA;- Hardware memory tagging (MTE) enabled for the main allocator&#xA;&#xA;- Strict site isolation and sandboxed iframes&#xA;&#xA;- JavaScript JIT disabled by default with per-site override option&#xA;&#xA;- Native Android autofill implementation to avoid needing sandboxed Google Play for autofill support&#xA;&#xA;- WebGPU disabled for attack surface reduction&#xA;&#xA;- WebRTC IP handling policy toggle to control peer-to-peer WebRTC mode&#xA;&#xA;- Compiler hardening: automatic variable initialization, strong stack protector, well defined signed overflow&#xA;&#xA;- High performance content filtering engine using EasyList + EasyPrivacy with a per-site override option&#xA;&#xA;- More complete state partitioning without origin trial opt-out&#xA;&#xA;- High entropy client hints replaced with the frozen user agent values to avoid leaking device/OS info&#xA;&#xA;- Battery API always shows the battery as charging and at 100% capacity&#xA;&#xA;- Trivial subdomain hiding disabled&#xA;&#xA;- Consistent browser behavior across users without usage of feature flags and seed-based trials&#xA;- Nearly all remote services disabled by default or removed. Only connects to GrapheneOS servers by default. There are only 2 default services: component updates such as certificate authority and certificate revocation updates and DNS-over-HTTPS connectivity checks when enabled&#xA;&#xA;- Web search and global search intents to replace the need for an OS search app&#xA;&#xA;- Option to always open links from other apps, custom tabs and search intents in Incognito mode&#xA;&#xA;Better default settings, including non-user-facing flags:&#xA;&#xA;- Reduce Accept-Language header by default (only available via chrome://flags)&#xA;&#xA;- Third party cookies disabled by default&#xA;&#xA;- Payment support disabled by default&#xA;&#xA;- Website background sync disabled by default&#xA;&#xA;- Sensors access disabled by default&#xA;&#xA;- Protected media (DRM) disabled by default&#xA;&#xA;- Hyperlink auditing disabled by default&#xA;&#xA;- Do Not Track enabled by default mainly to avoid users differentiating themselves from others by enabling it since it has no real value&#xA;&#xA;- WebRTC IP handling policy set to the most private value by default instead of the least private value (turned into a user-facing option by Vanadium)&#xA;&#xA;nostr:nevent1qqstu7eafcpguaqfplrvh88vu5ked4ke6kcxh7svrllastrdh9vgnnspz3mhxue69uhkummnw3ezummcw3ezuer9wcpzps26tfjesmn6ksf5mm36hpf9fkjut49sfeutfutvs2phrykn25v9qvzqqqqqqyyjcwrn</html></oembed>