3 ms·
How is Calyx more privacy respecting than GrapheneOS by default? Not sure about the defaults on Calyx, but AFAIK GrapheneOS has zero connections to Google. You
by tholdem 5y ago
How is Calyx more privacy respecting than GrapheneOS by default? Not sure about the defaults on Calyx, but AFAIK GrapheneOS has zero connections to Google. You choose to install sandboxed Play services only if you want to.
- phh 5y agoBy default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Yes, I'm very exaggerating the comparison, but still. My point is that the comment I'm answering touts the sandboxed Google Play Services. You can't tout it *and* say it's privacy preserving, it's a XOR.
- lberrymage 5y agoGrapheneOS doesn't automatically connect to Wi-Fi either unless you enable the option. It also has per-connection MAC randomization enabled by default so Wi-Fi is essentially anonymous when you use it anyway. > you can't tout it *and say it's privacy preserving. Why? Sandboxed Play Services has no special privileges on GrapheneOS and thus has the same level of access as any other app. How can it invade your privacy if you don't explicitly give it access to private information?
- strcat 5y ago> By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to. Going to simply interpret this as unhelpful sarcasm. > My point is that the comment I'm answering touts the sandboxed Google Play Services. Sandboxed Google Play isn't included in GrapheneOS. Users can choose to install apps which include Google's libraries and use the Google Play SDK. Regardless of whether people use sandboxed Google Play or microG, they're using the Google Play code inside each app using it. The whole point of sandboxed Google Play is that users can optionally choose to install Play services and the Play Store in the user/work profile(s) of their choice with it receiving ZERO additional access or privileges compared to the Google libraries / Play SDK within each app using it. GrapheneOS does not include Google Play and has no special sandbox for Google Play. It includes a compatibility layer for users to run it in the full, strictest API 32 app sandbox with all the standard GrapheneOS enhancements. It does not receive any special access or privileges. It can't do anything the Google libraries within apps can't already do themselves. The Sandboxed Google Play compatibility layer also includes the ability to redirect APIs like location services to the OS implementation. By default, location services are redirected to the OS implementation, so users don't need to give Location access to Play services. Of course, if users grant Location to apps using Google Play, they're trusting the app and all the included libraries, and any app using Google Play is using Google Play libraries. You can see for yourself that the full featured Google Maps app completely works without Google Play, and that their Ads SDK and other libraries work without it. Their libraries can do everything that sandboxed Google Play can do on their own without it. That's the whole point. Google Play is not required to contact Google services. Apps can do that on their own, and Google's libraries within those apps are fully capable of doing it. They largely choose not to implement fallbacks for features, but in some cases they clearly do as you can see from Google Maps and the Ads SDK. Only apps using the Lite variant of the Ads SDK need Google Play services for it to work. And again, sandboxed Google Play is not included in GrapheneOS. CalyxOS includes microG as part of the OS and encourages using it through the setup wizard. That uses Google's proprietary services and code. The Play code in each app is not replaced. It has a bunch of serious privacy and security issues from not implementing all the expected security checks, in some cases because microG is ideologically against enforcing the security model for things like location services. CalyxOS doesn't simply include microG with users encouraged to use it. They use Google services by default, with no way to turn them off. They significantly roll back the security model of the OS. They recently went almost 4 months without shipping the browser or Android security updates, including multiple vulnerabilities caught being exploited in the wild and announced as such in bulletins. How are users supposed to get privacy and security from an OS which lacks consistent security updates and has no problem rolling back or bypassing the standard OS privacy and security model? It isn't simply not a hardened OS. It's a dangerously insecure one.
- phh 5y ago> Going to simply interpret this as unhelpful sarcasm. I think it is helpful to convey the emotion that goes through me when I read such a remark. > It includes a compatibility layer for users to run it in the full, strictest API 32 app sandbox with all the standard GrapheneOS enhancements. How does it handle Doze? In original Android, no app is allowed to keep a TCP connection open forever. And without that, FCM is useless. Also I believe that having Google Play Services running permanently has an impact (more on that later in this comment) > You can see for yourself that the full featured Google Maps app completely works without Google Play, and that their Ads SDK and other libraries work without it. That's an interesting point, thanks, I'll probably spend some time exploring those things. That Google garden does such things doesn't really surprise me. > Only apps using the Lite variant of the Ads SDK need Google Play services for it to work. From the description of Lite Ads SDK, it sounds like something that every app developer should want, yet it looks like Google is down-publicizing it a lot, so noone actually use it, nice workaround from Google, thanks for the info. I see you're focusing your whole speech on Ads SDK. Does it mean only the ads SDK has this behavior? My personal use of microg is for apps I trust (mostly opensource, or where I'm a paying customer), which work (much) better with cloud messaging. (I have to admit, I trust those apps enough to know they don't have ads, but not enough to trust they don't have ads sdk). So I do believe that for my usecase, microg gives me a much better privacy than Play Services, because most apps won't contain the infinite list of trackers Google Play Services include. But if you have proofs of otherwise, please do enlighten me, you're more knowledgable than me on SDKs. FWIW, I have one metric (a rather stupid one, I agree) which is IMO showing that there is a huge difference: the data transferred and the battery usage. I have an order of magnitude difference in data transferred, and I get at least 3 times more battery life in suspend. Which IMO definitely highlights the fact that Google Play Services running permanently has its own privacy impacts, even when giving them minimal permissions. > CalyxOS doesn't simply include microG with users encouraged to use it. They use Google services by default, with no way to turn them off. "Google services" are 100MB+ proprietary code, sending god knows what to Google. CalyxOS doesn't have 100MB+ proprietary code, with microg you exactly know which data is sent. And actually if I'm not mistaken, microg doesn't do google registration or cloud messaging by default, so I don't think it does any Google connection by default? I'm not exactly sure there. I'm sure cloud messaging is disabled by default though, so no permanent connection > They recently went almost 4 months without shipping the browser or Android security updates, including multiple vulnerabilities caught being exploited in the wild and announced as such in bulletins. Just like the biggest (or maybe second or third, I don't really track that) corporation in the world on their flagship, while they are 50000 times smaller? But anyway, you're right: again, I said that on security grounds, I'd always pick GrapheneOS, and that the relation between privacy and security is pretty complicated, and I understand that some privacy threat models requires stronger security than trust. ---------------- Edit: Removed this part which is no longer relevant. > They significantly roll back the security model of the OS. I'm guessing you're speaking of microg implementation when you say "roll back the security model". I'm curious why you didn't answer to the comment where I ask to point out precisely how that roll backs the security model.