30
submitted 2 weeks ago by [email protected] to c/[email protected]

Hi! What would be the best way to limit play serbices to only selected apps. I still need notifications to work from them, but would like to be sure that google can't access anything else

you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 4 points 2 weeks ago

If I'm understanding correctly, this sounds just about exactly how GrapheneOS works by default. All GPlay apps work and have notifications, but are sandboxed.

[-] [email protected] 4 points 2 weeks ago

I'm really interested in Graphene and Google privacy, but what does it mean when you say "Sandboxed? Like... I want to use Google Maps, does Google still track me? Maybe only when the app is open, and not when it's closed?

[-] [email protected] 4 points 2 weeks ago

I don't really understand this stuff super well, but... I suspect what it means is that Google can track you while google maps is open, BUT since it doesn't have access to the rest of your phone, they'll have no idea who you are anyway?

[-] [email protected] 4 points 2 weeks ago* (last edited 2 weeks ago)

And you can also not log into Google Maps. It still lets you use map and navigation etc. But it is denied any explicit methods of identifying you and is left with only probabilistic methods (i.e. you are searching from the same network and therefore same public IP as another device that is known to Google as being associated with your account).

[-] [email protected] 1 points 2 weeks ago

This would only be true if you're using Google maps through a privacy respecting web browser like mull.

If you're using the Google maps app, it has hardware identifiers, and can uniquely identify the phone. No guessing required

[-] [email protected] 4 points 2 weeks ago

For grapheneos sandboxed means the Google apps are just regular apps, they don't have privilege, they're not escalated, they are exactly the same as other apps. Very specifically, it means Google services are only accessible in the user/profile that they are installed in, and not phone wide

If you use a Google service, or an app that interacts with the Google apps, then Google knows about it. In graphene OS you can choose what apps have access to Google services, by running them in a different profile.

[-] [email protected] 2 points 2 weeks ago

but what does it mean when you say "Sandboxed?

By default, on a normal Android device, Google Play services are installed as a system application. It means that you can't remove it, and it can grant itself the permissions it needs. In contrary, regular user apps run in the Android application sandbox. They are installed by the user, have distinct permission controls that are enforced by the operating system and can be uninstalled at any time. Sandboxed Google Play is a compatibility layer created by the GrapheneOS team, which allows you to run Google Play services (which would normally require system privileges) to run as a normal user app in the regular application sandbox.

[-] [email protected] 2 points 2 weeks ago
[-] [email protected] 1 points 2 weeks ago

Yes, because the Google Wallet app requires a higher level of SafetyNet attestation, which can only be achieved when running an OS that's specifically whitelisted by Google.

[-] [email protected] 1 points 2 weeks ago

That's super sucky. I have to use gwallet for my uni ID and mobile payment stuff :( gotta wait til I graduate to use graphene ig

this post was submitted on 10 Jun 2024
30 points (100.0% liked)

DeGoogle Yourself

8005 readers
4 users here now

A community for those that would like to get away from Google.

Here you may post anything related to DeGoogling, why we should do it or good software alternatives!

Rules

  1. Be respectful even in disagreement

  2. No advertising unless it is very relevent and justified. Do not do this excessively.

  3. No low value posts / memes. We or you need to learn, or discuss something.

Related communities

[email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

founded 4 years ago
MODERATORS