I've said it before and saying it again on here for those that don't know: microG breaks the security model on android and adds in package signature spoofing. It's the only way to add a fake Google Play Services without needing to pull Google blobs. This is why projects like LineageOS are against using this method, it weakens overall package security.
However, it is still possible for the tinfoil hat crew to not use Google play services with OS like LineageOS. This will of course break some functionality (apps will have to poll instead of relying on push) but it will not break the security model.
I'd like a different, better set of options to choose from but we don't have it at this time. Most users should probably choose a minimal Google Play distribution if they value things like battery life and working apps while still maintaining protections against spoofed apps.