microg / microg/GmsCore

Have I missed something? Doesn't DroidGuard make MicroG useless?

Open
#214 5 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

🔒 Integrity
Dominant language
Java
Stars
14.6k
Forks
3.2k
Avg merge
12d 11h
Merged PRs (30d)
4

Description

I don't know what's the reason for other users to run MicroG.
For me it is: I don't trust Google/Alphabet and I don't want them spying around on my phone.

Now we get new versions of SafetyNet and DroidGuard from Google quite often. As far as I know SafetyNets code is quite transparent, but nobody knows what DroidGuard exactly does.
We have found out that DroidGuard can detect system modifications, even those that are hidden very well: systemless programs for example.
This means DroidGuard is snooping on our phones, otherwise they couldn't detect this. And nobody knows what else they actually read and send and manipulate.

There is a DroidGuard Helper from MicroG which runs DroidGuard in an "isolated environment" but "Contains and downloads proprietary Google code to your device." With other words: unknown program code is downloaded from Google and does whatever it wants to do. Or what exactly means "isolated environment"? I guess the Google code still has access to the phone because otherwise DroidGuard couldn't detect our well hidden modifications.

And so we are back at a the beginning, where we were with Google Apps and without MicroG. Google runs unknown code and does whatever they want.

Please tell me what's wrong with this reasoning: does DroidGuard make MicroG useless?

How exactly does the "isolated environment" restrict DroidGuard? I've only found that a new Thread is started.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file, test, or entry point is named. Read the issue and its existing discussion first, then determine whether maintainers can explain DroidGuard's isolation and access; done would be a clear, authoritative answer or updated documentation.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
documentation, mobile-dev, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.