

I’m not disagreeing with anything you’re saying and I think the articles about this are sensationalized in the impact in some ways, but I think you’re focusing too much on the type of traffic that is typically encrypted with HTTPS/TLS.
I think the bigger issue is internal networks where it is still common to run non encrypted and/or unauthenticated services. This is particularly an issue when SSID segreagation (lile guest networks) was used to mitigate this kind of issue. The AirSniff paper shows that SSID isolation in many APs can be bypassed.












I started with graphene a few months ago and it worked from the beginning just following the instructions on the phone to enable it. That said I do recall aention of extra permissions for Bluetooth android auto, which I didn’t want. My car doesn’t support it over Bluetooth anyway so didn’t matter to me, but you may be interested in looking that up (I don’t recall the specifics).