Aurora is a lot less invasive while achieving that same goal, but they recommend installing Googleware instead. Wouldn't the open source front-end be the "bare minimum" standard to strive for, with all the added tracking when installing GMS falling below that standard?
> It was the best way for them to provide compatibility without destroying the privacy of their platform
Again mixing up threat models and equating it to privacy. It may not compromise the technical security (as GrapheneOS goes to incredible lengths to point out while implying that this covers everything), in that it doesn't allow Google to access data on the device that Android's security model says they shouldn't have, but Android's security model isn't my threat model. My threat model, and many other people's, includes Google tracking me. If nothing else, the servers can always see which IP addresses I pop up on together with other people and build a social graph if they wish (or if they're ordered to)
By just grabbing the apk files from their servers whenever I open aurora.apk, that issue can be almost entirely avoided, for example. There's the matter of microG but just to show that there are easy wins to be made that work for a lot of apps already (that don't depend on the rest of the framework) that GrapheneOS vehemently opposes 'for security'
It's not strange that they offer a way to install GMS in a secure manner, it's strange that they don't recommend open alternatives where possible
And you're surely aware of the obvious bias of that link you shared. It's like those tables on vendor websites that show their product as the only one that does virtually everything to perfection with everyone else far behind, by measuring and including only the metrics they focus on. Whoever made that takes GrapheneOS' statements at face value and assumes it must be great. And that's assuming that the sheer number of checkmarks is evidence of anything. Depending on what your threat model is, each one can outweigh all others