It runs as an unprivileged user app and uses randomized accounts.
Google play services under graphene are all also unprivileged.
You can add all apps you dont want Google to know of to your blocklist, so the unique fingerprint from your app list is extremely reduced
I wouldn’t say extremely, as you still need to keep all of the apps which you install from the store itself unblocked to get updates. Anecdotally for me, that list is all of the niche apps which I can’t use FOSS alternatives for, like banking, work, transit, etc. so it’s very likely still uniquely identifying. If you’re hiding system services in Aurora that you don’t want it touching, that makes it even easier to identify you, because Google play doesn’t do that.
Aurora is WAY better for privacy
I’m not a security researcher and am basically regurgitating what the Graphene team has said about it, as I think they know a lot more about how the play store works under the hood and the information that is required to send to Google than I do. I think they have a blog post about it somewhere.
Yes they are unprivileged, and the gmscompat tool doesnt give them more access that is true. Still it is google software with the intention to control your device and spy on you, while Aurorastore is a slim app that even allows to restrict the apps it tells to Google.
If you’re hiding system services in Aurora that you don’t want it touching, that makes it even easier to identify you, because Google play doesn’t do that.
It is less data. GrapheneOS will have less system apps than stock android so that immediately gives it away.
Asking Google for updates is also different from telling it a complete list of your installed apps. You might simply not try to update these system apps currently.
In the end, it is really good that play services work on GrapheneOS, but they are still more invasive as regular user apps than alternatives.
Google play services under graphene are all also unprivileged.
I wouldn’t say extremely, as you still need to keep all of the apps which you install from the store itself unblocked to get updates. Anecdotally for me, that list is all of the niche apps which I can’t use FOSS alternatives for, like banking, work, transit, etc. so it’s very likely still uniquely identifying. If you’re hiding system services in Aurora that you don’t want it touching, that makes it even easier to identify you, because Google play doesn’t do that.
I’m not a security researcher and am basically regurgitating what the Graphene team has said about it, as I think they know a lot more about how the play store works under the hood and the information that is required to send to Google than I do. I think they have a blog post about it somewhere.
Yes they are unprivileged, and the gmscompat tool doesnt give them more access that is true. Still it is google software with the intention to control your device and spy on you, while Aurorastore is a slim app that even allows to restrict the apps it tells to Google.
It is less data. GrapheneOS will have less system apps than stock android so that immediately gives it away.
Asking Google for updates is also different from telling it a complete list of your installed apps. You might simply not try to update these system apps currently.
In the end, it is really good that play services work on GrapheneOS, but they are still more invasive as regular user apps than alternatives.