I’ve been looking at apps and realizing that I could likely remove Sandboxed play services from my GrapheneOS phone (at least from my always-on main Owner profile) without sacrificing anything…except Google Messages and RCS.
For RCS to work on GrapheneOS, Sandboxed Play Services and Google Messages needs to be installed on the Owner profile. Play Services also has to always be running with battery optimization turned off.
You also need to hand over multiple permissions including network, contacts or contact scopes, SMS, phone, and storage or storage scopes. Unless you get lucky with your carrier, you also likely need to toggle a special GrapheneOS permission to send device identifiers to Google. And you also need to verify your number with Google on the device.
The Google apps also need to be installed from the Play Store, so either logging into the play store on the Owner profile or updating the apps on another profile’s play store.
So yeah…that’s a LOT and pretty far from the vision of a degoogled privacy phone.
The perks or RCS is that it’s not SMS/MMS. Google and Apple have agreed to support E2EE RCS, but none of my iPhone contacts have E2EE enabled yet. I’m sure they will very soon though.
My closest contacts use Signal. But for non-close contacts and random people that message me, due to living in the USA, people will always default to messaging via SMS/MMS/RCS and you have to pull tooth and nail to get them to use anything else. This isn’t the type of off-topic thing I want to deal with when I talk to people I’m not close with or when I meet new people. I’m not socially up for it and I think many of you can relate.
Though, I’m also not sure if the RCS E2EE can even be trusted as being significantly more private than SMS/MMS. Like how do we know Google isn’t lying about the encryption or isn’t client side scanning messages?
Google requires the SMS permissions just for RCS to work and for Google Messages to display my messages - wouldn’t that mean they can read all of my messages, even my message history, regardless of E2EE claims? I just have to hope they’re not sending themselves my data in secret?
I’m so divided on this.