I want to switch my phone OS over to GrapheneOS, however the one app that has been giving me issue is Duo Mobile, which my work mandates.
I havent seen a lot of posts talking about it as of late, with posts from 2024 saying they work just fine from Aurora/APK. Im still very concerned about the google play integrity attestation though, and from what ive heard the sandbox can only perform a very basic attestation.
I dont know if anything about Duo has changed in the past year, so I would like to ask if anyone has duo on their graphene and what their experience looks like so far!
on GrapheneOS use sandboxes play services
I don’t use Duo specifically but my work has a different authenticator app.
(Duo looks like it requires Play Services but I am not sure on the strict integrity check.)
In my use case, I found it worthwhile to just buy a second vanilla Android normie phone (spent like $200 on a decent but non-flagship device). It has all my required work apps like authentication and the pager/notification app. The phone doesn’t have a sim and is WiFi only. In the rare case I need to take it outside my office I just do tethering/hotspot from my primary phone.
I never cross-contaminate work and personal stuff on the same device.
Yep, I’m forced to use it for work. Also, there’s a way you can export the totp keys, there are a couple github projects out there. But as I work in IT at work, I need to have the app for the admin account.
It does work with Google play services, but if you don’t run them, you can always run duo libre https://github.com/evan-goode/duolibre and drop it into something like aegis authenticator
Im pretty sure it does work but if it doesnt you can request your work to give you a work device.
It does work! If you are not using sandboxed google play services, you will not get them toast notification - but the workaround is just to open the app, and if necessary drag down to refresh to receive your Duo Push.
If you have SGPS running presumably you would receive the actual notification.
I had this exact same problem, so I purchased the Yubikey security key. My biggest gripe is how Duo prevents me from factory resetting my phone as it is tied to my device unlike email, SMS, or the passwords I use. It is such a hassle that I had to call the IT help desk to reset Duo instead of being able to do it myself. My work account out of the blue started requiring it, so I was caught flat footed. In addition, my state university also requires a security key.
Yes it works for me, installed using aurora without GPServices, works fine, no back ups obvs, highly recommend getting a 2fa key like yubikey, that is my set up for home and for uni
Depends on the security configuration of wherever you need to log in to. My work’s was set to disallow custom ROMs, but we also have to use MS Authenticator for a few things and that works fine. Currently they have me set on MFA bypass while they decide whether or not to allow custom ROMs
It does. I have been using it for a few years now without any issues. I also have Google Play Services installed, so I don’t know if it works without that.
I’ve switched our company from Duo (Cisco acquired) to Keeper. I feel it’s more trustworthy.
I had Duo installed in a separate profile and it worked fine.




