Spyke

Can Apps Share Data Back n Forth on GrapheneOS?

Say I have Google Camera installed with network permissions revoked. Say I also install Play Services which does have network access. Would Google Camera be able to share data about my pictures to Play Services which would then phone home to Google?

View original on lemm.ee
lemmy.world

I don't know if Google Camera would share the information with Sandboxed Google Play. However, something to be careful of, is if you have two apps by the same developer (Google in this case), and you have network permissions for only one of them. The developer could share those permissions with their other app. TheHatedOne did a podcast episode on this. He checked with a GrapheneOS developer beforehand, and found, that this is possible.

22

Oh god the ui is so bad. Like what's so hard about multiple lenses that they can't have a single zoom slider?

2

Ultimately, it depends on if it is an issue in terms of your threat model. I have noproblems with people using some proprietary tools. Sometimes you do need things to just work, unfortunately.

2

Yes. Apps can consensually trade information. So if play services is connected to the network, it can share information it receives from other apps.

The only way to isolate an app from communicating is to put it in its own profile either a work profile or a secondary user.

Simply disabling network access does not prevent the app from talking to other apps that do have network access. You need to be careful based on your threat model

3
lemmy.zip

This is why I don't like Graphene os. Its encourages using proprietary apps that over Foss. With a Foss camera app from F-droid you don't need play services and the app with do exactly what its meant to do, nothing more.

-8
Gooey0210reply
sh.itjust.works

There's gos' camera already preinstalled, no need to download anything 🫣

They discourage fdroid because it's not very secure, until it ever gets better

There's the secure Accrescent, but it has almost no apps in it

(Yeah, but actually you can just use obtainium, this is probably the future)

5
VolunTerryreply
monero.town

I'd like to see some evidence that F-Droid is less secure (or privacy respecting) than using the big Gs playstore or services, which many, if not most, playstore apps depend on to function.

I mean this sincerely and respectfully. I'd love to look onto it.

Because in my current opinion and approach, if you vet your apps and practice good digital hygiene, then FOSS>GOOGL/Alphabet for nearly everything from a privacy and security perspective.

Edit: if I misunderstood and you were saying don't use G playstore or Aurora AND don't use F-Droid, then may I ask where are you getting your apps, other than directly from the devs page or github and so on?

4
lemmy.zip

For that to work you need to know the app exists first. I also like to look at F-droids anti feature list.

3

Me too, but good to know I can check that at F-Droid and then fetch from source if I want. Best of both.

2
jetreply
hackertalks.com

This is the best of both worlds. You verify the source code is actually what the developer says it is. And you verify the binary you're running was built by the developer.

5
lemmy.zip

Now if we only could get the F-droid project to be controlled by a board and not a single person.

4

https://f-droid.org/2023/03/20/f-droid-board.html

Recent drama aside they are trying to do exactly that

https://gitlab.com/fdroid/admin/-/tree/master/board/meeting_minutes

If you read the recent meeting minutes, it's just growing pains, they're doing the right things

If you really want to get into the recent drama, you can read the issues. But they are being open and transparent about everything. Which is exactly what you want in public governance.

https://gitlab.com/fdroid/admin/-/issues/448

4

Keep in mind that the security issues were addressed a while back. It was in a blog post.

4
Gooey0210reply
sh.itjust.works

I'm a little bit too late 🤪

I personally don't use anything of google, browsing and trying apps from fdroid, and have obtainium for the ones I usually use

But Graphene's approach is all about security, and privacy only after it So they recommend the most secure options first, and don't recommend minor options So, their current opinion on fdroid that it's less secure than googlag's store, so a more secure option would be googlag, or that second store that has 3 apps in it

But it's for "marketplace" apps, so obtainium not in the scope, but kinda should be (we just need to rethink where we get our apps from)

2
lemmy.zip

The lineage os camera is pretty good and can be installed outside of lineage os.

0

You reached the end