On a Google Mobile Services OS, Play services is built into the OS as a highly privileged component with immense access and handles work across profiles.
Sandboxed Google Play are regular sandboxed apps without any special access. Each installation in a separate profile is entirely independent.
@GrapheneOS On this regard, knowing the answer might change in the future, can we have a somewhat official answer whether you suggest or not the use of 5g from a security perspective?
Thank you for all your great work, big fan!
@Baffling7384 No, that's the opposite of what we said.
This is about how it works on a Google Mobile Services OS instead of the stock Pixel OS::
> Setting up a work profile, Private Space and secondary user on the stock Pixel OS results in all 3 secondary profiles using the global Play services instance running in the Owner user for a shared FCM push connection, etc.
We're explaining sandboxed Google Play are regular sandboxed apps which means it can't operate across profiles like that.
Ey gude wie, there's this guide you could follow, it's from Molly herself:
https://github.com/mollyim/mollyim-android/wiki/Migrating-From-Signal
(I'm new to interacting with posts on mastodon and I didn't know if I should leave the others account from the thread or not. Is there an etiquette? 🙈)
@BackFromTheDud That's not a safe device to use regardless of OS. An alternate OS isn't going to provide firmware updates.It would also still be missing kernel and driver updates in practice too.
GrapheneOS exists to provide a high level of privacy and security. It doesn't exist to provide another insecure option for insecure devices. It has hardware requirements for updates and security features we need to protect users.
GrapheneOS also isn't a ROM, that's incorrect terminology for an OS.
@gbsills If people use sandboxed Google Play with a lightweight setup and don't have other stuff heavily running in the background, they'll tend to get better battery life. The stock Pixel OS has a ton of stuff installed and running in the background by default.
Many people don't use sandboxed Google Play or keep it in a dedicated profile they don't usually have running. They can get much better battery life if they avoid apps doing inefficient background work and use UnifiedPush for push.