I have no idea why GrapheneOS takes this risk, but am grateful to them nevertheless for the code.
I have no idea why GrapheneOS takes this risk, but am grateful to them nevertheless for the code.
And also, even if it's technically legal, it's such lawsuits/slappsuits can entirely bring down an organization as legal fees can be very expensive. They probably want to err on the side of caution so that Google can't, and wouldn't care to, sue them.
The SafetyNet part is something I read from somewhere else, though unfortunately I don't remember if that was LOS or some random developer on reddit/XDA. You can treat most of this as (oft-repeated) speculation by users.
> Yes MicroG is open source, but they probably had to reverse engineer something.
MicroG being open source is irrelevant. The relevant point is that google play services is not, so MicroG devs could not have copied source from it. Besides the fact that the API used by other programs to interact with play services is public and that the team had no access to the play services source code US law also has a specific carve out for "interoperability" which might (I'm guessing) apply here. Google has already spent many years and many millions in court arguing that an API is not copyrightable.
IANAL but it seems hard to argue that this would be an easy legal case.