If you're a GrapheneOS user, it's worth being aware of the consequences of revealing device identifiers, which give away privileged device info, effectively fingerprinting your phone permanently. Much of this is tied to RCS as it stands today.

Firstly, whatever SMS/MMS/RCS app you set as your messaging app will have access to

READ_PRIVILEGED_PHONE_STATE

which the official FAQ notes, regarding the messaging app, is a

...special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.

This means that even if you change your messaging app for one moment with network access, that app can (and will) utilize that IMEI and any other identifiers that the privileged state allows. This is a necessary evil of carrier-based messaging.

Secondly, if you've settled on using RCS, which is currently only implemented through Google Messages, it's worth noting, as GrapheneOS devs say,

Some carriers use a verification method (GSMA TS.43) that requires Google Play services to have the permission to do ICC authentication with device identifiers.

This is done by visiting your settings, apps, Sandboxed Google Play, Play services special permissions, and enabling 'Allow ICC authentication with device identifiers'.


Currently, it's obvious that if you're using Google Messages, your only immediate RCS option, that enabling this toggle is not really leaking much additional data since you already spread 'dem cheeks to Google. Again, your carrier already knows a bunch, but that's the price of using modern telecommunications infrastructure. However, by enabling this setting, Google Play Services is also allowed the privileged state mentioned earlier.

If you must have RCS right away, then you're SOL anyhow. But in the future, GrapheneOS devs are planning to attempt their own RCS implementation that doesn't rely on Google (sorry I am not linking to the direct Twitter post). If/when this comes to fruition, RCS will be possible without relying on the infrastructure Google has so thoughtfully trapped us with set up for us.

If you can wait for that day to come, then you should wait for that day to come. Because if you really want to keep Google from having privileged info, you need to know that allowing it now and disabling it later is in part, though largely pointless because the consequences of the decision you made prior are permanent, in relation to identifiers leaked, so long as any of those identifiers remain the same.

Additionally, Google Play Services can communicate with other apps even without networking via an Android feature called inter-process communication (IPC). This allows apps designed for it to communicate directly with each other, in this case Google-to-Google. This includes apps that utilize tracking/analytics through things such as Firebase Analytics. That's a LOT of non-FOSS apps.

Though it's not proven what exactly Play Services exfiltrates via IPC, you don't need to be Sherlock Holmes to deduce that there may be foul-play involved. Maybe you have an app that is made by Google or uses Firebase that you keep network off for - if you allowed Play Services those ICC permissions, you are, at least in theory, creating a pathway to leak data you may not have intended.

There are a million more ways you might be giving valuable and private and identifying data to Google, but this is one I see often overlooked because RCS is the easiest way to enable encrypted communications with those who don't use any purpose built app such as Molly/Signal or SimpleX Chat etc.

For those wondering, "can't we configure IPC like with other permissions?", great question, you might wanna check out this forum discussion (amongst many others). For those wondering why RCS is so seemingly Google-dependant, check out the wiki page on RCS for some fun history on how Google fucks with everything and everyone on earth.

Caveats:

  • If you're running older Android =<10, check the FAQ more cause idk much about that.
  • There are things such as Openbubbles that serve a specific niche with different risks/benefits that I'm not covering here. The tech behind it is also very different.
  • I'm not a GrapheneOS dev, don't take my word for things, check out the official forums and Github for more in-depth discussion.
  • Things can change quickly and unpredictably. Make sure the reality still matches as of this post's date.
  • Your decision to use Google on GrapheneOS is not wrong, and it's up to the individual to determine their boundaries or what they deem acceptable.
  • Google IPC data exfilfration is not proven fact, maybe a heart still beats within the company somewhere, lol.
  • Google doesn't literally fuck everything and everyone on Earth - yet.
  • There's subtleties lost here and details simplified, but the overall point is not lost. If you're interested you should read more about it all, it's fun to learn about!

all 7 comments

sorted by: hot top controversial new old
[–] 1 point 1 hour ago* (last edited 1 hour ago)

My MMS, SMS is totally shut down on my phone. Always airplane mode. No sim or e-sim. Phone was bought in cash and was initialized originally on a public WiFi. Zero sandboxed google play programs on my phone.

Multiple vpn profiles. Main profile uses tor only.

Additionally the camera and mic are always given non permission on every online profile.

The only msnger I have is signal. The only social media is lemmy, the only AI is Lumo (in browser).

Even with all that, I strongly suspect that a state actor could identify me if they really tried.

  • source
  • [–] 3 points 5 hours ago* (2 children)

    Pixels ship with Google Messages and Android enables networking (and the cellular connection) during initial setup. Am I right in thinking that, unless you buy a brand-new phone and take special precautions to install Graphene without giving it any chance to phone home first, you're already screwed?

    I bought my Pixel used, so it certainly leaked its device identifiers to Google before I even owned it.

  • source
  • hideshow 2 child comments
  • [–] [S] 1 point 5 hours ago

    Yeah you're on the money. If it's bought new from a first-party or authorized retailer and you paid with a card linked to your name, Google's likely got you in the database or at least database-adjacent.

    Setting up without precautions is a way to leak a fuckload of identifiers instantly. But not all is lost, there's still a massive amount of value and protection provided by the OS. Hardware identifiers are just a piece of the puzzle. So don't stress, unless you have a reason you know is worth stressing about haha.

    Ironically, buying used is a big advantage because it creates either lack of a paper trail or at least plausible deniabity of some sort. Whether that matters is up to your country's laws and their willingness to enforce them.

  • source
  • parent
  • [–] [S] 8 points 10 hours ago

    If you found this post a little bit informative or helpful or interesting, please consider joining this community so it doesn't die. Tysm!

  • source
  • [–] 3 points 9 hours ago (1 child)

    Google IPC data exfilfration is not proven fact, maybe a heart still beats within the company somewhere, lol

    You mean maybe they're too incompetent to collect and parse data in a way that would harm us. Of course they would if they could.

    Thank you for this post. I want to get a degoogled phone when I can.

  • source
  • hideshow 1 child comment
  • [–] [S] 5 points 9 hours ago

    No, thank you for the comment!

    I like keeping my posts a bit more straight-laced than my comments. So I'll say it here, totally agree that Google will suck up whatever the fuck they possibly can. If they think they can get away with it they're sure as hell gonna try.

    It's funny cause they are so terribly incompetent and irresponsible with their consumer facing services. I mean, the very fact that KilledByGoogle.com exists...

    But under the hood, when it comes to long-plays and manipulation of standards and the practices used online, they're super fucking sneaky. Honestly some real sociopaths running the show there.

    Hope you can too! I'm excited to see what's in store with the future of the Motorola partnership. Software support is really good with GrapheneOS too so it's nice knowing those with a supported Pixel won't be left in the lurch.

  • source
  • parent