So you are using a Google app (Google Camera) in an objectively much weaker sandbox than the one provided by GrapheneOS. You're giving it shared storage access since it requires it and CalyxOS doesn't have features like https://grapheneos.org/features#storage-scopes. The whole point of sandboxed Google Play on GrapheneOS is that it runs in the full standard app sandbox. It has absolutely no special access or privileges. It's not different than running another app. Same sandbox, same permission model, and all the same GrapheneOS improvements to those including user-facing ones like Storage Scopes, Sensors permission toggle and the Network permission toggle which blocks more forms of access than a firewall-based approach.
You can even use Sandboxed Google Play in a specific user profile, instead of options like MicroG where it has to be privileged for a lot of its features/functionality to function, and where it's ever-present in all of your profiles.
Furthermore, since we're talking about Google apps and services, I find the fact that CalyxOS ships with the privileged eSIM activation Google app which is enabled by default and to my understanding cannot be disabled very concerning...
https://blog.privacyguides.org/2022/04/21/grapheneos-or-caly...
On the other hand, (again) GrapheneOS has it disabled by default and you're given the choice to use it if you need it, instead of having it forced on you by default.
After looking at all options for alternative Android OSes, not matter which way you slice it, GrapheneOS takes the cake, so I don't really understand how someone who has actually looked at both options can call it "terrible".
Be a tiny bit respectful at least.
Regarding community among people valuing security and privacy...
On my most recent big phone/handheld switch, I tried CalyxOS first, but found that I personally preferred GrapheneOS.
I think CalyxOS also has its merits.
Users of CalyxOS and GrapheneOS are relatively small groups, with overlapping interests, and together are stronger, if the tone is friendly competition and mutual assistance.
Check the recent screenshot I posted about a Calyx reseller who works with them (@maxtannahill) and is in several of their private Signal, Matrix and Discord chat rooms. I linked a thread where he openly states his neo-nazi views which he has done repeatedly. He's openly a holocaust denier who supports fascism, wants democracies turned into authoritarian dictatorships and overtly a white supremacist wanting the US as a white homeland. Calyx permits Kiwi Farms server in their room and has had no problem with the abuse targeted towards me. In fact, the leader of the organization has repeatedly participated in it when it happens, encouraging it while also steering it away from being done inside their rooms. These logs have been archived and while the lead CalyxOS developer has gone back and purged a lot of it from the Matrix history, much of it is still there. You can check for yourself what happened yesterday and can confirm the main person attacking me there and in other rooms is a Calyx community member friends with several of them and has openly told me to kill myself.
> Users of CalyxOS and GrapheneOS are relatively small groups, with overlapping interests, and together are stronger, if the tone is friendly competition and mutual assistance.
Calyx developers / leadership have repeatedly engaged in an extreme bullying/harassment campaign targeting me. They've heavily focused on spreading misinformation both about CalyxOS and GrapheneOS to mislead and scam users.
We're never going to work with people who have done these things. No one else should be working with them or tolerating them either, but unfortunately people don't do anything about the massive amount of charlatans and abusers in the privacy/security industries. It's sad. You should never expect that I'm going to tolerate it.
CalyxOS is not a hardened OS. It's also blatantly insecure by not shipping patches fully or on time while misleading users. I'm not sure how it's a competitor with GrapheneOS. Presenting it as a private and secure OS in their marketing doesn't make it one. Engaging in all kinds of abusive and underhanded behavior is not going to turn it into one either.
I hope any pressing harm to anyone stops immediately.
If necessary, I think you could get advice from US and Canada lawyers.
GrapheneOS handily beats out every other project on security and technical merit -- let the code and project speak for itself, because jumping in to every single convo between end users you can find, doesn't help quell any of it.
From a GrapheneOS user for many years who thanks you for your work and dedication