Posts by GrapheneOS@grapheneos.social
(DIR) Post #B69vSGHfXt1BcyTPY8 by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Play Integrity API is highly insecure and it isn't particularly hard to temporarily bypass it. There are frameworks for spoofing the software checks and leaked keys for bypassing hardware attestation can be purchased. However, bypasses are getting harder and are becoming increasingly short lived.
(DIR) Post #B69vSGTip4ewEM72Ku by GrapheneOS@grapheneos.social
0 likes, 0 repeats
It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source.
(DIR) Post #B69vSGfQ7a16odaNZQ by GrapheneOS@grapheneos.social
1 likes, 1 repeats
Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them.
(DIR) Post #B69vSGtxFXdvXiNzE0 by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security.
(DIR) Post #B69vSH88OozAFh1JKK by GrapheneOS@grapheneos.social
0 likes, 0 repeats
reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that.
(DIR) Post #B69vSHIPmbD0lZpWLo by GrapheneOS@grapheneos.social
0 likes, 0 repeats
This isn't about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don't license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere.
(DIR) Post #B69vSHVWzphVQFxznM by GrapheneOS@grapheneos.social
0 likes, 1 repeats
Services shouldn't ban people from using arbitrary hardware and operating systems in the first place. Google's security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It's for enforcing their monopolies via GMS licensing, that's all.
(DIR) Post #B6UsDEAusuatCTc4Ce by GrapheneOS@grapheneos.social
0 likes, 2 repeats
The first public release of GrapheneOS Speech Services is now available in our App Store. After installing it, it can be activated as a text-to-speech service by tapping it in Settings > System > Language & region > Speech > Text-to-speech output > Preferred engine and approving it in the dialog.
(DIR) Post #B6V7z3xff0uIjfgXYW by GrapheneOS@grapheneos.social
1 likes, 0 repeats
A fresh install of GrapheneOS has far lower idle power usage than the stock Pixel OS. Power usage while active is comparable. Making a similar setup to the stock Pixel OS by installing sandboxed Google Play and a couple dozen apps doing a bit of background work will result in similar battery life.
(DIR) Post #B6V7z5IcgbGEswUmqu by GrapheneOS@grapheneos.social
1 likes, 0 repeats
GrapheneOS doesn't come doesn't come with anything keeping open a push connection and barely has any scheduled work. Waking every 8 hours for update checks doesn't use significant power. It doesn't have better battery life due to any major efficiency improvements but rather the lack of bloatware.
(DIR) Post #B6V7z6LUnP9Y88qay8 by GrapheneOS@grapheneos.social
1 likes, 0 repeats
Installing sandboxed Google Play on GrapheneOS results in having a push connection for Firebase Cloud Messaging and doing a lot more work in the background. Idle power usage will still tend to be better than the stock Pixel OS, but adding more apps to match their bloatware will make it comparable.
(DIR) Post #B6V7z7Qqkz1vV2MNxA by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Battery life heavily varies based on apps, networks and OS configuration. Many people end up with far better battery life on GrapheneOS and many people end up with far worse battery life due to differences in how they set up their devices. It's easy to end up with either result with simple choices.
(DIR) Post #B6V7z8TirmvEkEiC4O by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Installing Signal in a profile without sandboxed Google Play and granting the power optimization exception it requests is enough to destroy battery life and end up worse than the stock Pixel OS. The power efficient choices are either using Molly with UnifiedPush (Signal fork) or Signal with FCM.
(DIR) Post #B6V7z9XIvxNi1dOZI8 by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Running both sandboxed Google Play and an efficient UnifiedPush app can have competitive battery life with the stock Pixel OS. Those should be the only 1-2 battery optimization exceptions for most users. Signal's fallback push will drain more power than all the bloatware in the stock OS itself.
(DIR) Post #B6V7zAat07qBJ24wVs by GrapheneOS@grapheneos.social
0 likes, 0 repeats
On a Google Mobile Services OS, Play services is built into the OS as a highly privileged component with immense access and handles work across profiles.Sandboxed Google Play are regular sandboxed apps without any special access. Each installation in a separate profile is entirely independent.
(DIR) Post #B6V7zBfX0L9OdjGAOO by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Setting up a work profile, Private Space and secondary user on the stock Pixel OS results in all 3 secondary profiles using the global Play services instance running in the Owner user for a shared FCM push connection, etc. Installing sandboxed Google Play in 4 profiles would run 4 FCM connections.
(DIR) Post #B6V7zCkB0YSbyQROGu by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Network-based location is much more power efficient than the power hungry GNSS radio for satellite-based location. Maps/navigation apps will continuously use both when available but many apps will avoid using GNSS to save power if network-based location is available, so it can save a lot of power.
(DIR) Post #B6V7zDqwsrTJPicJSy by GrapheneOS@grapheneos.social
0 likes, 0 repeats
For GrapheneOS, network-based location is an opt-in feature in the Owner user setup. For Google Mobile Services Android, it's opt-out there and you'll be regularly nagged to enable it if you didn't. It's a common pitfall since people expect indoor location positioning and it can save a bit of power.
(DIR) Post #B6V7zEsP4wEIaWIzNA by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Cellular, Wi-Fi and Bluetooth are power hungry. 5G is particularly power hungry prior to the improved cellular radio in 9th/10th gen Pixels with the exception of the Pixel 9a. Either way, setting the cellular mode to 4G (meaning 4G and below) or the GrapheneOS 4G-only mode can save a lot of power.
(DIR) Post #B6V7zG0EtI5k56ylE0 by GrapheneOS@grapheneos.social
0 likes, 0 repeats
Stock Pixel OS has an Adaptive Connectivity service which largely keeps 5G disabled. GrapheneOS doesn't have an equivalent to this yet but you can do it manually. Other than that, the stock Pixel OS doesn't really have any significant power saving tricks and it has a lot of bloatware draining power.