There is a disagreement between the Graphene and CalyxOS community about which is more secure/private: Graphene's sandboxed Google play store, or CalyxOS's MicroG. I've read posts advocating for both sides, but I don't have the expertise to have an opinion, and I decided that I don't want either software on my phone, since I don't want to run google code or play store apps.
Although I'm not expert enough to validate the following claims, here's what I've read.
Graphene people claim that MicroG needs elevated privileges to run, privileges that Graphene doesn't grant to any app. MicroG also loads and runs Google code (in a context where that Google code would presumably have access to those elevated privileges). Graphene's version of the play store emulates some APIs without using Google code (for privacy), and sandboxes the Google code that it does run, running it with reduced privileges. This is a security first posture, keeping in mind that if you don't have security then you can lose privacy via exploits of your security holes.
CalyxOS's MicroG emulates a larger fraction of the google play APIs, making it less reliant on google code to operate, and this is the source of the claim that MicroG offers more privacy.
MicroG runs with elevated permissions to avoid being killed, and so that it can continue listening to socket events. Once an event arrives, it decodes it into a notification, packages into an RPC request, and awakes/runs the target application activity. Then it, crucially, uses the elevated privileges to override the default policy to also allow the target application to run without interruptions for 20 seconds (to process the notification).
The specific privilege that MicroG wants and that GrapheneOS doesn't allow is the ability to spoof the signatures of other apps. GrapheneOS runs the Google Play APIs in a sandbox, and this sandbox allows push notifications to work, so that's not the problem with MicroG from a GrapheneOS perspective.
- https://github.com/Divested-Mobile/DivestOS-Build/discussion... - https://discuss.privacyguides.net/t/divestos-unprivileged-mi...
> DivestOS will not include microG or the GrapheneOS' Play Services sandbox.
For a specific example within it, it does explicitly state "17.1 and higher have an unprivileged microG feature now: https://divestos.org/pages/faq#appCompatibility" in 2023. The comment was by the DivestOS project author.
The second link, also from 2023, starts with "Latest release of my DivestOS can now run microG in an unprivileged manner:" -- also by the DivestOS author.
I think that covers it for your reading of the links, no?
Anyway, the DivestOS project did have an implementation of microG, and it was sandboxed. As for my comment about projects goals, I also selected those two links because both include such commentary about DivestOS' implementation in relation to project goals and to the GrapheneOS implementation.
Before that I was using crDroid on a Poco F3 (I switched because the camera was quite awful and the battery got drained rather fast), and I was expecting some of crDroid's features that were just missing. A shortcut to the flashlight via power button long press, battery charge limit/smart charging, bandwidth display on the status bar, the option to add more columns to the quick settings, just to name a few.
I ended up running crDroid on the Pixel as well, overall it's a decent experience, but not nearly as polished, it turns out I had to manually grant Google Play Services the location permission via ADB so apps would know where I am (missed a train to that one).
I'd love it if there was some ROM that combined the security and sandboxing from GrapheneOS with all the neat little features in crDroid... or an actually good Linux phone.
My personal hill to die on is that the launcher uses lil tiny icons and text, which I find hard to read, and alternative launchers are a bit of a privacy and security disaster. They refuse to add anything to the built in launcher to adjust this, and suggest either raising all of the sizes (with accessibility, which affects all apps) or use an alternative launcher.
Alas it is still a very nice operating system.
Someone with a threat model that GrapheneOS addresses could always use access to a quick flashlight.
However I've found that flashlight is still relatively accessible. It's three actions - press power, drag finger down from top of screen, tap Flashlight. Not too bad, but not possible from muscle memory or with gloves on. Good for looking under the seat for your keys at a movie, bad for quick reactions.
When I'm traveling or outside at night, I tend to carry a dedicated flashlight, but I'm odd like that.
> Why is the recent screen buggy?
> Unfortunately, it is because the system launcher handles the Recents screen. Therefore, if you change the default launcher, weird things can happen [...] The only way to fix this is by having a Magisk module called QuickSwitch.
https://lawnchair.app/faq/#why-is-the-recent-screen-buggy
(Can't vouch for the accuracy of this information as of $CURRENT_ANDROID_VERSION.)
With one exception. The couple of times I've called emergency services, they were not able to detect my location since GrapheneOS does not support the protocol for this. So, I had to waste time giving directions. It's a tradeoff for privacy vs safety.
It might be something to think about before, say, putting this on someone's phone who has a medical condition or is elderly.
Some shown here: https://lineageos.org/Changelog-28/
In their "golden years" OEM Android distributions were just bad and came with inexcusable bloatware and restrictions. The main charm of Custom ROMs back then used to be that they were relatively cleaner. But now, with most Android phones coming with hardware powerful enough to make any impact of bloatware negligible, not to mention Android (and OEM iterations) itself having been converged into leaner, more efficient designs, the relative utility offered by Custom ROMs is fading fast.
Compared to the Pixel stock ROM, you aren't missing out on much, and you're gaining a few non-security bonus features, like unrestricted tethering, local/offline backups, call recording, and Network permission toggle [2].
[1] I don't really like the term "de-Googling" because it paints an all-or-nothing picture, despite alternative ROMs providing the option to use Google services in a safer and fairer way (fairer as in, non-Google apps are on a level playing field when it comes to OS integration).
[2] This is most certainly intended as a security/privacy feature, but I find it useful as an adblocker as well :)
It is based on Lineage.