upvote
> It just puts Google in the same sandbox Google puts everyone else.

Yes, you can do that, but Graphene is probably best used without Google apps at all. If you use Google Maps, sandboxed or not, Google still knows where you are, what speed you drive, etc, and can rat you out to car insurance companies or the government.

reply
Yes, you can do that, but Graphene is probably best used without Google apps at all.

That totally depends on your goals. For some it's security, for some it's privacy from Google, for some it's removing the ability from Google to (worst case) remote brick/block your device. The latter may sound a bit far fetched, but if I was employed by, say the ICJ, I would know what system I'd run to avoid that.

One of the things that I like about GrapheneOS is that it accommodates all these use cases and on a gradient (e.g. personally privacy from Google is also important, but I like that I can use sandboxed Google Play Services with most of its permissions removed).

reply
Graphene OS devs themselves recommend that you install apps on Graphene OS via Google Play Store for security reasons. They also explicitly recommend Graphene OS users to not use F-Droid or Aurora Store. Make of that what you will.
reply
> Graphene OS devs themselves recommend that you install apps on Graphene OS via Google Play Store for security reasons.

Can you provide a source that they've said this recently? This seems to be a bit of a misrepresentation.

They say:

>The Play Store app is also the most secure way to install and update apps from the Play Store.

on /usage, but this does not indicate it's the most private way or that it's the recommended way to install apps. It seems to me to indicate that this is their assessment of the security of the ways to install apps that are distributed on the Play Store, not a recommendation or privacy assessment that applies to other apps or to their users in general.

They don't recommend against Aurora Store [1], but it is not user friendly as the Play Store because app installs frequently fail and automatic updates do not work as well. Installing apps from Aurora has the advantage of no google account, but Google is still handed a list of all the apps you have installed, IP address, app details, device details, and GSF ID. It will likely stop working or become even more broken. It is useful when apps block installs from the Play Store because of play integrity.

I use it myself for the few Google apps I install like Camera because I don't want to install play services.

I would consider their actual recommendation to be their own App Store and Accrescent (alpha).

Obtainium is great but not user friendly.

The claims about problems with F-Droid are true. It's not like they oppose FOSS, their whole operating system is FOSS and they've never said anything bad about IzzyOnDroid, which fixes the problems with F-Droid and even adds a bit of security.

[1] https://nitter.freedit.eu/GrapheneOS/search?f=tweets&q=auror...

reply
The thing I like about GrapheneOS is it's the most private operating system while still having great usability.
reply