Hi! What would be the best way to limit play serbices to only selected apps. I still need notifications to work from them, but would like to be sure that google can’t access anything else

  • Remy Rose@lemmy.one
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 months ago

    If I’m understanding correctly, this sounds just about exactly how GrapheneOS works by default. All GPlay apps work and have notifications, but are sandboxed.

    • Roopappy@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      5 months ago

      I’m really interested in Graphene and Google privacy, but what does it mean when you say "Sandboxed? Like… I want to use Google Maps, does Google still track me? Maybe only when the app is open, and not when it’s closed?

      • Andromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 months ago

        but what does it mean when you say "Sandboxed?

        By default, on a normal Android device, Google Play services are installed as a system application. It means that you can’t remove it, and it can grant itself the permissions it needs. In contrary, regular user apps run in the Android application sandbox. They are installed by the user, have distinct permission controls that are enforced by the operating system and can be uninstalled at any time. Sandboxed Google Play is a compatibility layer created by the GrapheneOS team, which allows you to run Google Play services (which would normally require system privileges) to run as a normal user app in the regular application sandbox.

      • Remy Rose@lemmy.one
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 months ago

        I don’t really understand this stuff super well, but… I suspect what it means is that Google can track you while google maps is open, BUT since it doesn’t have access to the rest of your phone, they’ll have no idea who you are anyway?

        • mctoasterson@reddthat.com
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          5 months ago

          And you can also not log into Google Maps. It still lets you use map and navigation etc. But it is denied any explicit methods of identifying you and is left with only probabilistic methods (i.e. you are searching from the same network and therefore same public IP as another device that is known to Google as being associated with your account).