+1 to this topic. I set "Home Assistant" as the default Digital Assistant App in grapheneos, and turned on the gesture swiping (apparently the only way to start up the digital assistant in grapheneos...) and this is FULLY accessible from my lock screen. With a locked screen, I can swipe to start the conversation, and it has full permissions for mic and keyboard and has full access to anything accessible to that Home Assistant voice assist agent.
Clearly this a HUGE problem... we need an option to disable Digital Assistant access in lock screen, or some creative alternative solution. For Google Assistant (just for comparison) it looks like you can enable/disable it's use on the lock screen from the app itself, so I don't think there is precedent for this toggle to exist in stock Android lock screen or security settings.
Here are my observations/grievances:
- Stock android seems to be able to start your Digital Assistant from both (1) gestures and (2) power button long press (there is an option to set this to Digital Assistant). In GrapheneOS #2 is not present to even configure (only "double press power button"); it might be reasonable to add this option to the "Double press power button" options at least.
- Huge security issue that you can access the Digital Assistant (set as HA Assist) directly from the lock screen with full permissions and access, when the gesture settings to start your default Digital Assistant is turned on.