Conversation

Android with Play is trending towards shipping a Google-built AOSP system image and kernel. I'm sure that's coming in the next couple of years. Mainline modules shipped via Play are already here though and include code loaded into system_server etc.
1
Ok, you've convinced me that if you're worried about backdoors from US state-level attackers, you shouldn't be using Google Play services. However, there are other reasons why this is bad, for example this one:
Quote Tweet
4: This will enable further modifications to apps, like injecting DRM libraries or possibly even security scanners, tracking or advertising.
Show this thread
1
Replying to and
I wouldn't necessarily say that someone with that threat model shouldn't be using Play services but by using an OS including Play they're using an OS with highly trusted core components built and shipped by Google via the Play Store.
2
1
Replying to and
As part of installing it, they need to add all the privileged permissions and whitelisting in order for it to work properly. They make an attempt to do it. It's not meant to be any less trusted. Play services is only designed to run as a privileged app with a ton of power.
1
1
In my opinion, the ideal solution to all of this is for governments to require that Google makes Play services available as a regular app functioning without privileged permissions. Most of all the functionality could work. Backups, etc. wouldn't and it'd have more UX friction.
1
3
No automatic app updates, needing to prompt users to install or remove apps, needing to ask for a battery optimization exception, needing to run a foreground service, etc. Of course, every service provider has all these restrictions unless an OEM bundles their stuff in the OS.
1
2
This Tweet was deleted by the Tweet author. Learn more
It's unnecessary to have backup services for specific service providers. Can simply have a generic service encrypting the data and not trusting the service where it stores it. Seedvault is a major step towards that. Definitely far from perfect but it goes a long way.
This Tweet was deleted by the Tweet author. Learn more
GrapheneOS still maintains the OS security model including the application security model. It has nothing to do with what you claim. Don't need to be have it explained why you think things are designed the way they are as someone deeply involved in implementing these things.
1
Show replies