10 ms·
>Citation needed. grapheneos themselves sure doesn't understand this The GrapheneOS team understand full well that in cases where the Play Store does not allow
by ysnp 15d ago
>Citation needed. grapheneos themselves sure doesn't understand this
The GrapheneOS team understand full well that in cases where the Play Store does not allow installing an app on your device due to device or georestrictive rules you may have no choice. I have seen them mention this and acknowledge it first hand. What they do not want is for people to become satisfied with subpar solutions instead of striving for bare minimum privacy/security standards. They want a Play Store alternative front end to at least be able to guarantee you are receiving the right app you want instead of being a substitution attack risk. I don't think that is unreasonable.
>The official website has an install guide for google's background services, saying it's fine because it's in their security model.
The context is that before sandboxed-play-services were introduced people were sourcing APKs in unsafe/via unverified routes and having all sorts of problems with app compatibility because since GrapheneOS is a privacy project that do not accept sending copious amounts of data to one party with a mediocre privacy policy they included no Google services at all. sandboxed-play-services is a specific solution to the problem of apps being dependent on Google Mobile Services for functionality, and in that sense it is entirely optional. It was the best way for them to provide compatibility without destroying the privacy of their platform by introducing a privileged Google binary that can glean and abuse your production environment. It's reduced to the same level as any other app the user might choose to install themselves (which GrapheneOS want absolutely no say over as a user freedom protecting project).
GrapheneOS do not bundle any Google services in their official installation. They do not endorse Google's data collection and service practices. They do not believe Google tracking is fine in anyway, and the evidence is here: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm
What they have done is provide a workaround for people who have no alternative, while making sure it does not violate the device owners device in a special way compared to any other app they might install.
- einpoklum 14d ago[dead]
- lucb1e 13d ago> What they do not want is for people to become satisfied with subpar solutions instead of striving for bare minimum privacy/security standards. They want a Play Store alternative front end to at least be able to guarantee you are receiving the right app you want Aurora is a lot less invasive while achieving that same goal, but they recommend installing Googleware instead. Wouldn't the open source front-end be the "bare minimum" standard to strive for, with all the added tracking when installing GMS falling below that standard? > It was the best way for them to provide compatibility without destroying the privacy of their platform Again mixing up threat models and equating it to privacy. It may not compromise the technical security (as GrapheneOS goes to incredible lengths to point out while implying that this covers everything), in that it doesn't allow Google to access data on the device that Android's security model says they shouldn't have, but Android's security model isn't my threat model. My threat model, and many other people's, includes Google tracking me. If nothing else, the servers can always see which IP addresses I pop up on together with other people and build a social graph if they wish (or if they're ordered to) By just grabbing the apk files from their servers whenever I open aurora.apk, that issue can be almost entirely avoided, for example. There's the matter of microG but just to show that there are easy wins to be made that work for a lot of apps already (that don't depend on the rest of the framework) that GrapheneOS vehemently opposes 'for security' It's not strange that they offer a way to install GMS in a secure manner, it's strange that they don't recommend open alternatives where possible And you're surely aware of the obvious bias of that link you shared. It's like those tables on vendor websites that show their product as the only one that does virtually everything to perfection with everyone else far behind, by measuring and including only the metrics they focus on. Whoever made that takes GrapheneOS' statements at face value and assumes it must be great. And that's assuming that the sheer number of checkmarks is evidence of anything. Depending on what your threat model is, each one can outweigh all others
- ysnp 12d ago>Aurora is a lot less invasive while achieving that same goal, but they recommend installing Googleware instead... GrapheneOS vehemently opposes 'for security'.. It's more accurate to say they suggest improvements not vehemently oppose. The community/project have opened issues with the Aurora Store project to get them closer to that goal of making sure the app downloads cannot be intercepted https://gitlab.com/AuroraOSS/AuroraStore/-/work_items/697 https://gitlab.com/AuroraOSS/AuroraStore/-/work_items/697 and mitigating the TOFU problem by ensuring the first install is definitely the one the developer distributed via Play https://gitlab.com/AuroraOSS/AuroraStore/-/work_items/1177 https://gitlab.com/AuroraOSS/AuroraStore/-/work_items/1177 This is what I meant by standards. They only suggest Play Store because it is an existing solution that already meets those standards. >Again mixing up threat models and equating it to privacy. My threat model, and many other people's, includes Google tracking me. GrapheneOS are very conscious of avoiding sending data to Google where unnecessary. The evidence of that is in the link previously shared, but also in third-party reviews like https://www.kuketz-blog.de/grapheneos-der-goldstandard-unter-den-android-roms-custom-roms-teil7/ https://www.kuketz-blog.de/grapheneos-der-goldstandard-unter... They also do advise that if you want to avoid Google's gaze you should explore non-Play Store apps if they can meet all your needs because Play Store apps are extremely likely to include Google libraries and dependencies that expose even more data to Google. Apps on your phone may be able to determine your locality, and can definitely fingerprint you uniquely, so it is not enough to download an app via Aurora Store. I believe that from their perspective it takes a lot of careful consideration and planning to avoid exposing data to Google. This consideration and planning would never end with just Aurora Store so hopefully you can understand why they would not recommend it as a well thread-modelled privacy solution for Google. Instead they do suggest Aurora Store as a last resort in special cases where the Play Store prevents you from getting the app nonsensically. Does my explanation make sense? >... like those tables on vendor websites that show their product as the only one that does virtually everything to perfection with everyone else far behind, by measuring and including only the metrics they focus on. ...that's assuming that the sheer number of checkmarks is evidence of anything. Depending on what your threat model is, each one can outweigh all others I agree. Checklists are a bad way of conveying verified information and importance of each feature, and I do think the table can be improved. Thankfully it is open to contributions from Github account owners.