I use Aurora on GOS. I get that they say sandboxed Play is more secure than Aurora, but I prefer it for its lack of toxicity and absence of shitty dark patterns.

I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community.

I actually think there's already a lot of us in the 'community' as-is. I personally describe it as 'Valuing Privacy/Freedom over Security'. One pretty clear example of this is how they don't recommend using FireFox Mobile and F-Droid, both of which I use regardless because I'm not willing to put up with worse privacy/usability tradeoffs in the name of (imo 'hyper-')security.

I think it's fine the mission of the project isn't directly aligned with some of us, though I can tell we often get on the core contributor's nerves lol

They're both security, just security "against" different things. Graphene frequently fails to clearly describe the threat model when calling something "more secure".

For example, let's say hypothetically I want to be secure against the threat of Google pushing a targeted update to my phone that runs malicious code. Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat. But Graphene devs say things like "MicroG is less secure than Google Play Services".

Similarly, if you want privacy you might secure your device by locking the bootloader with your own keys - not a third-party vendor's keys. Saying that's "insecure" is extremely misleading: it just puts you in charge of security, instead of abdicating to someone else.

I wish there were something like GrapheneOS that let you choose, yourself, who to trust instead of requiring you trust an OS vendor implicitly.

  >  Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat
I would say that any auto-update mechanism is a threat, so in both cases you would disable auto-updates.

The point is that you might know the people behind microG or trust them for any other reason, but not the people at Google

Fair point.

They actually ban people from their Discord (which is their official support channel - so much for privacy/security!) for mentioning F-Droid. I'm starting to think the creator of F-Droid must have run over their dog.

This is the exact reason I quit using Graphene. It felt exactly like selling out control of my device to the Graphene devs in the same way a stock phone is controlled by Google.

Far, far too "opinionated" for my taste. I frankly do not need the hyper paranoid security features like a hardened memory allocator or disabled root. I would rather be able to use my device the way I want, even if that's notionally "less secure".

I really wish there were another option. Lineage is too far in the opposite direction and feels like ad-blocked stock. Google still owns my phone, there's just a more pleasant coat of paint on it.

> I frankly do not need the hyper paranoid security features like a hardened memory allocator

I get the part about disabled root - you're choosing to sacrifice freedom for security - though I don't understand why you wouldn't want a hardened memory allocator. It provides additional security over the stock OS for very little cost (slightly more resource consumption), in an era where we absolutely need as much security as we can get; what are you losing by gaining this?

they do similar things for people trying to use magisk, but also relock the boot loader. I gave up trying to bother, since the whole reason I use roms is for root first, privacy second.

[flagged]

FYI, there are ungoogled chromium builds for Android. Firefox Mobile really is a lackluster browser unfortunately both from a usability and security standpoint (e.g. IonStack worked on Fennec)

I really like the Firefox usability. For what I do it works great. It has uBo and a bunch of other extensions, and if course it can sync with desktop.

I would actually argue the exact opposite. All of the Chromium-based forks are a usability disaster. I have to use grid view only to see my tabs? It took them most of a decade to finally get the relatively common place bottom bar, and it still arbitrarily decides to ignore your setting if it thinks your screen is "too big"? It's just failure after failure. I absolutely dread when some shitty site I'm forced to use refuses to load in anything but chrome and I have to open up Vanadium for the first time in forever.

I'm using Firefox mobile for many years exclusively (since chrome forced some stupid feature on me, I think it was tab groups which I hated and couldn't turn off. And of course no ubo). Could be a bit faster probably? Otherwise don't see any issues.

> I hope it's not too annoying for their community

There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.

The core dev team is obviously a bit more security absolutist, but even they usually dont mind

> Everyone generally understands that different people have different threat models

Citation needed. If there are such people in what can be considered a grapheneos community that haven't gotten fed up yet and left, grapheneos themselves sure doesn't understand this

> Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.

Nah, they're fine with tracking, so long as it happens in their sandbox. The official website has an install guide for google's background services, saying it's fine because it's in their security model. So long as the modem can't access your contacts without a permission prompt, there is no tracking in baghdad

> The core dev team is obviously a bit more security absolutist, but even they usually dont mind

Their absolutist of their own view of security