Rendered at 10:54:40 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
pyrophane 18 hours ago [-]
GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.
For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.
DaSHacka 18 hours ago [-]
Although the nice thing about Aurora Store is it allows you to install apps without a google account linked to your device, keeping Google Play Services signed-out.
Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't).
Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play.
That's personally what I used Aurora for, plus as an easy way to export APK files.
juiceland 18 hours ago [-]
> Google Account that isn't tied to anything else.
At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.
tredre3 17 hours ago [-]
I'm under no illusion that google doesn't know I own my multiple accounts. They most certainly do. I usually use the same user agent (with containers) on the same IP, after all.
But my goal is to avoid a stranger gaining access to my google services if they manage to unlock a lost device or steal my TV/streaming box that has no lock at all.
I wish Google supported a permission system per device. For example on most of my android devices all I really want is to be logged into Youtube and the play store. I most certainly do not want those devices to have access to my contacts, emails, calendar, keep, drive, payment, etc. (I don't personally use all of those things, but you might and that's what a random thief would gain access to.)
deepsun 17 hours ago [-]
Yep, something like checkboxes on login:
- ALL: Log me in to all Google Services
- Calendar
- GMail
- YouTube
- ...
Adding more would require to login anew.
josefresco 18 hours ago [-]
Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.
axus 15 hours ago [-]
They have required unique phone numbers for accounts I've tried lately, or parent's phone numbers. Facebook is worse though, they are quick to ban an account/phone number.
Forgeties79 18 hours ago [-]
My experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that have them running around in the background or just straight up depend on them.
All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them
kevin_thibedeau 15 hours ago [-]
> leave their ecosystem
Their tracking is baked into various apps even if you don't have an account with them. Anything with social media integrations can report back to the mothership behind your back.
Forgeties79 15 hours ago [-]
yes I believe I said that in my previous comment more or less
fc417fc802 11 hours ago [-]
I'm happy enough not using them however lately even government services (which I have no choice but to use) require loading a captcha from either google or cloudflare. The situation is absurd.
duskdozer 4 hours ago [-]
AFAIK Graphene is mainly focused on security and not privacy. It just seems to have become a sort of go-to for people who want to deGoogle I guess.
henryfjordan 16 hours ago [-]
Google's business model is providing you services that are excellent, while also providing advertisers access to your willing eyeballs when you use those services.
Yes, the advertising targeting is incredibly invasive, but let's not pretend they aren't providing world class Search, Email, Docs, Maps, Video (YT), etc in exchange.
15 hours ago [-]
ravenstine 15 hours ago [-]
GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS.
For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.
So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.
welwala 13 hours ago [-]
Yes, F-Droid and its apps are great <3 They add so much security by simply not having a lot of tracking code that can be exploited and tries to hook all over your system. And they have reproducible builds which is something the commercial stores don't even bother with. This is really important for security. I don't understand that GrapheneOS advises against them.
And yeah the iris scans sound like a scare but only 2 years ago there was a constant line of zombies here in the shopping mall giving their eye scans to altman.
The masses really don't care about privacy if you give them a worthless trinket.
xingped 15 hours ago [-]
I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app. It's one of the worst pieces of software I've used in a while, and I can tolerate a good bit of jank from FOSS apps.
bilkow 15 hours ago [-]
> never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app
You probably "just" need to pull down while on the "Latest" or "Updates" tab, to update your repository (it will show a small banner at the top while it's doing that). It's incremental, so it may take a while if it has been some time since you last did it (and auto-updates are disabled).
The way F-Droid works is that it downloads the whole index and then the catalog, version checks, etc, all runs locally, quite similarly to some package repositories actually.
I am not claiming its intuitive, but I think that part works fine once you understand how it works.
xingped 13 hours ago [-]
The last time it wouldn't update an app, I could see in the app store and on the website that my app had a new version, but no matter what I did, I could not make it update the app. I don't know what I was doing "wrong", but I think if I couldn't figure it out or make it happen, there's something very wrong with either the app or how it's "supposed" to work. Neither of which is an acceptable user experience for me.
g-b-r 11 hours ago [-]
Ok, you clearly don't know what F-Droid is.
F-Droid builds all apps by themselves, which especially with their old servers took a lot (between detecting that the update exists, building the app and going to sign everything at their air-gapped signing computer).
Now a lot of apps use the "reproducible builds" feature, which means that F-Droid will distribuite them as they come from the author, leaving their digital signature; but they still need to build those apps before distributing them, to verify that what the author built corresponds to the declared source code.
With the much powerful servers that they've had for a few months builds are a lot quicker, but there are still steps that can take several days, especially the part of signing the apps' index on their air-gapped computer.
There's a ton of things that could be improved, and it would be best if there were an alternative with better maintainers, but they're currently the only service of this kind for Android (well, IzzyOnDroid is a partial alternative, if you're careful to check their reproducible builds results).
rpdillon 8 hours ago [-]
Doesn't match my experience (or anyone I know that uses F-Droid), FWIW.
We search for stuff, install it, it updates in the background. We install some of our own repos, but the bulk of our apps come from F-Droid's default repos.
Hard to reconcile your account with my experience without specifics.
cyberrock 9 hours ago [-]
My understanding is that F-Droid is hosted out of some home servers (instead of some universities like other similar package managers) so the bandwidth leaves much to be desired. But the UX is definitely a big part of the problem. I don't understand why it tends to abort downloads when I background it, and I don't understand why it doesn't show a toast that it aborted the download.
I very much prefer Obtainium these days despite the setup steps. I don't think it's a coincidence that Obtainium, Aurora, Zapstore, etc. are gaining mindshare over F-Droid, just like how Brave has explosive growth over FF.
anon5739483 4 hours ago [-]
Yeah, the experience isn't great and there are better alternatives but F-Droid was there before anything else existed. It's also great to just have it as an option.
though personally I use it only for Fdroid, Gitlab and Github
cf100clunk 14 hours ago [-]
Have you tried Neo Store for accessing F-Droid and other repositories? In particular, I use the IzzyOnDroid F-Droid and Guardian Project repos.
xingped 14 hours ago [-]
I have not, but honestly, at this point, I just don't really care anymore. I can only try and be rebuffed by a product so many times.
JadeNB 15 hours ago [-]
> Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app.
Sounds like an accurate recreation of the Play Store experience to me.
xingped 13 hours ago [-]
This is not me simping for Google, I would honestly prefer literally anyone else with an acceptable app store experience, but I can honestly say I've never had that experience with the Play Store. If there's an update, it updates. If there's an app, it appears in search. On the rare occasion an app doesn't appear and I go to the Play Store website looking for it, the reason the app didn't show up is because it's listed as incompatible with my device (usually Android version too low or too high).
g-b-r 11 hours ago [-]
The software and many parts of the project are bad, but I don't see how you can't understand its reason to exist.
You're sure you understand what it does?
subscribed 3 minutes ago [-]
Try installing an app that requires Play Store Integrity, say, ProShot by RiseUp Games.
Braindead dev claims this is to limit the "piracy" and bug reports, nevertheless it's either Aurora or APKMirror.
joekrill 18 hours ago [-]
> a Google Account that isn't tied to anything else.
Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
Linux-Fan 15 hours ago [-]
> > a Google Account that isn't tied to anything else.
> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.
Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.
The trick is, that in the general case, you can not keep this account online indefinitely.
First thing to note: This way of account creation does not seem to work anymore.
Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...
Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).
I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.
I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...
Cider9986 5 hours ago [-]
Same thing happens to me.
megagpt1 18 hours ago [-]
You can create an account with no phone number during Android device setup.
You can also just get a burner phone number for a few bucks.
cube00 14 hours ago [-]
> You can also just get a burner phone number for a few bucks.
But you have to keep paying the monthly cost, if you loose access to a phone number in your Google account it's game over for any account recovery or "let's verify it's you" it might decide to throw your way.
megagpt1 2 hours ago [-]
What's the problem then? If it happens, discard that account and make a new Aurora Store burner account.
armadyl 18 hours ago [-]
Accounts created on stock Pixels don’t require phone numbers.
iririririr 18 hours ago [-]
that haven't been true since pixel 4. it just picks your phone in the background.
a burner sim, like a literal criminal, is the only way today.
asnelt 18 hours ago [-]
Even with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission.
As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.
Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.
I don't know however if sandboxed google play is such a privileged app.
asnelt 17 hours ago [-]
I couldn't immediately find whether GrapheneOS grants READ_PRIVILEGED_PHONE_STATE to Google Play. It might very well be that the GrapheneOS sandbox spoofs a fake IMEI, and I do hope so.
In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.
> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.
It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."
There is no READ_PRIVILEGED_PHONE_STATE mentioned there.
gruez 15 hours ago [-]
That's also incorrect, because the gmscompat app is just a helper app. Play services can and does request additional permissions. Those permissions are handled by the OS under the play services app, not gmscompat. If you want RCS for instance, you must grant play services and google messages phone and ICC auth access, which isn't seen in gmscompat at all.
exceptione 15 hours ago [-]
> That's also incorrect, because the gmscompat app is just a helper app.
Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services.
> Those permissions are handled by the OS under the play services app
Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unprivileged app, and so any additional permission it would want would have to be consented by the user and should be visible to the user. If not, then GOS wording would be quite a bit unfortunate at least.
EDIT: "GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims." [1] This seems to indicate that the permissions requested by Play Services are being honored with the shims from the helper app. That would alleviate the permission problem.
That's the application software side. I would assume the IMEI and IMSI are both going out to the cell network though, and I would presume that it's trivial to tie a phone number to those with how the mobile industry generally sells subscriber data to various data brokers. The only question is how permissive those data brokers are (their major constraint is how much most people become aware of this dynamic), but when dealing with a major APT like Google I'd assume they're tuned into the best ones with songs about bona fide purposes.
exceptione 16 hours ago [-]
Are you talking about the US here? I am hoping this would be off-limits in Europe.
mindslight 16 hours ago [-]
Yes I am talking with a US perspective. I would hope the GDPR would prevent such things in (most of) Europe. But I also personally wouldn't assume so given that there are still the same dynamics of keeping the info flows private to avoid scrutiny, and claiming plausible "legitimate purposes" and "consent".
alt227 17 hours ago [-]
Its possible to set up a phone with a google account without even a sim card in it and use it as a wifi only device, so Im pretty sure what your saying is wrong.
goodmythical 18 hours ago [-]
assuming the number you get hasn't previously been assigned to a google account
drxzcl 17 hours ago [-]
I've had no end of trouble registering an account on our corporate SIMs as the phone numbers (not the actual SIM cards) had been recycled as employees leave.
edoceo 16 hours ago [-]
So many systems cannot handle known pattern of a phone number changing. Who's decided these are imutable values? That I have only one? That it's not shared?
megagpt5 17 hours ago [-]
It still works without a SIM card, how do you explain that?
dmantis 17 hours ago [-]
Sometimes you just can't.
For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.
The check seems to be purely store-based and never enforced later.
Biganon 11 hours ago [-]
Same. Twint (basically the Swiss Venmo) insists that my phone is not compatible with it.
But using Aurora I can install it just fine and it works flawlessly.
CivBase 17 hours ago [-]
This is exactly why I switched to Aurora. I couldn't even install Balatro from the Play Store.
suddenlybananas 17 hours ago [-]
I have similar problems installing region locked apps as someone who's fairly frequently in different regions.
Flip-per 16 hours ago [-]
Do you trust the banking app installed from Aurora enough to do your online banking?
I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with.
(for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)
Gander5739 16 hours ago [-]
Android apps are signed. Can't you verify the signature?
lucb1e 15 hours ago [-]
Can you?
I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store
microtonal 1 hours ago [-]
Privacy Guides is building a database of signing keys with a verifier app:
I think in general trust is established for Play Store apps by downloading the app with the Play Store on a phone with Google Certified Android. Then the app can get the signing key for storage in the database. Then this can be used to verify APKs downloaded outside the play store.
Gander5739 15 hours ago [-]
Maybe not in practice, but in theory, it works. I don't think there's a better way of handling this without relying on some centralised authority (Google) to validate the authorship of an app, which is hardly desirable.
palata 14 hours ago [-]
Doesn't AppVerifier allow you to do just that?
panja 16 hours ago [-]
Doesn't Aurora download the packages directly from Google?
dooglius 15 hours ago [-]
Presumably the parent does not want to have to trust Aurora to do that
hadlock 18 hours ago [-]
It seems wise to have at least one alternative mobile phone app store. Even if it isn't very good. If the government can tell Google to do trivial things like, for example, change the name of bodies (plural now) of water, it can turn off your app updates, trapping you on insecure versions indefinitely. This probably matters more if you live outside of the US, but if I had a plan B for an app store on my phone, I would certainly at least evaluate it.
alt227 17 hours ago [-]
The government didnt ask google, they changed the name on the Geographic Names Information System (GNIS), which is the official legal mapping source which other companies like Google etc use. Hence the change filtered down through software from the top official channel.
hadlock 16 hours ago [-]
Right, the government pulled a lever, and google complied within days. If the FTC declares app stores can't provide security updates without government license, that is another lever they can pull, and google will comply.
Wether or not the most recent example is the best example, doesn't matter. What matters is when the government says "jump" in legalese, google's lawyers say "how high?"
arjie 17 hours ago [-]
Name changes happen all the time and I would expect Google to match what the government sources use locally. The fact that the government is capricious is no reason for me to desire Google to become an alternative naming center.
amaccuish 18 hours ago [-]
GrapheneOS is focused on absolute security. For those of us on more privacy-oriented ROMs with MicroG, we're very happy with Aurora.
Cider9986 18 hours ago [-]
GrapheneOS is focused on privacy but that must come from a secure baseline.
GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm
How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.
dingaling 17 hours ago [-]
The problem is that to achieve privacy through security, Graphene has to treat the user as a potentially hostile actor.
Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.
Ajedi32 16 hours ago [-]
Verified boot does indeed make this more complicated, but it's totally possible to build Graphene with your own signing key and get full control over the OS that way (i.e. https://github.com/schnatterer/rooted-graphene).
Looking at their public statements on the matter, it seems like the problem isn't exactly that they treat the user as a potentially hostile actor so much as that they treat the system UI and persistent storage as a potentially hostile actor (though I admit from a practical perspective that's nearly the same thing): https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root...
I believe you misunderstand what "software freedom" means. You can compile and install GrapheneOS yourself, and you can grant yourself admin access. This is software freedom.
Software freedom does not mean that you should run everything as an admin, always. And just in case: software freedom does NOT mean that you should remove your firewall and let everybody SSH into your server by having a blank password.
Ajedi32 14 hours ago [-]
You can't grant yourself admin access with the official build. Only the Graphene devs have the ability to push changes to the OS on your phone. Yes you can fork the software and build a version with your own signing key, then wipe your phone and install your custom build and thereby take back control, but then is that really still Graphene?
I think it's fair to say that that's at least borderline anti software freedom, even if it's true they have good security reasons for doing things that way.
palata 1 hours ago [-]
> I think it's fair to say that that's at least borderline anti software freedom
Then you don't understand software freedom either.
Software freedom doesn't mean AT ALL that random projects on the Internet MUST implement the features YOU want. Never, not at all, it's not borderline, it's not up to debate.
Software freedom is about being able to use the software the way you want, as in "you get access to the sources, you modify them, build them and run them". You can do that with GrapheneOS (well except for the binary blobs situation, but that's not in GrapheneOS' hands at all). Software freedom is NOT about GrapheneOS giving you root access on official builds because you want it. And it's also NOT about GrapheneOS installing Doom on the official builds because I want it.
Ajedi32 13 hours ago [-]
Thinking about possible ways they could retain the same security properties without impinging software freedom... maybe there's a way they could make the root of trust default to a signing key embedded in the device's own secure hardware? Then by default that key could sign Graphene's own signing certificate to allow them to push updates, but the user would retain the ability to revoke that signature and sign someone else's certificate instead (or their own certificate) if they decided they didn't trust Graphene anymore, or wanted to give themselves root.
Cider9986 16 hours ago [-]
> Which is very much contrary to software freedom.
Yeah, the goal is privacy although the OS is completely open source.
They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes.
You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.
welwala 15 hours ago [-]
GrapheneOS will always choose security over privacy, even if that means playing into the hands of malicious actors like Google. For example they have stated they won't try to spoof SafetyNet because "we don't lie about security features"
I personally would prefer to have both but choose the privacy side when both are into conflict.
Both viewpoints are valid, but I don't use GrapheneOS for this reason.
SXX 9 hours ago [-]
Its quite obvious they dont want to spoof SafetyNet because it would anger Google and GOS developers will no longer get privileged access to security bulletins.
lol768 17 hours ago [-]
> Accrescent is the end goal for a secure and private app store but it's still in alpha
Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.
SahAssar 18 hours ago [-]
Having to have a account is absolutely a downgrade and privacy-hostile.
slome 17 hours ago [-]
A Google account is a personal identifier, it is linked to your person. Therefor trying to untie it from anything else is futile.
Google states: Using a false name or incorrect information when creating a Google account is against Google's Terms of Service.
maybewhenthesun 15 hours ago [-]
The main reason for me to use GrapheneOS would be to sever the umbilical cord to google.
I don't really see the point of using GrapheneOS instead of Stock Android if I then have to use the play store.
palata 14 hours ago [-]
Better security, for once. You get (security) updates a lot faster with GrapheneOS.
Also on GrapheneOS, Play Services and Play Store come unprivileged, sandboxed like any other app. So Google is not an admin on your phone, which I would argue is one step towards "severing the umbilical cord".
Moreover, GrapheneOS doesn't have any issue with apps sideloading.
And more. There are many reasons to use GrapheneOS.
1718627440 2 hours ago [-]
> with a Google Account that isn't tied to anything else.
How can I get this wonderful thing?
talon8635 18 hours ago [-]
Doesn’t Google make it very hard to create an account tied to nothing (no phone or alt email)?
armadyl 18 hours ago [-]
If you create it on a stock Pixel device the phone requirement gets dropped.
talon8635 18 hours ago [-]
It’s undoubtedly tied to the phone with is tied to the owner
gruez 18 hours ago [-]
People report that it works even on grapheneos with sandboxed google play. My guess there's some fingerprinting going on, not necessarily that they're tying the account to some account id.
NewJazz 18 hours ago [-]
I tried and it didn't work, it kept asking for my phone number.
armadyl 18 hours ago [-]
Well yeah. But if you care about anonymity on that level there are ways around that (i.e. buying in cash and creating the account using public WiFi).
talon8635 13 hours ago [-]
What? Buy a phone in cash and have it billed to what, your monero wallet? This isn’t possible in today’s world, in the west anyways. Phones are tied to people.
And “worried about anonymity in that way”… that’s the topic being discussed here.
armadyl 13 hours ago [-]
You can buy a phone with physical cash from a store or used p2p…
As far as cell service goes well yeah there is no such thing as anonymity. Towers will always know your location as long as the radio is on and that can be correlated easily.
weezing 17 hours ago [-]
How is your phone tied to you? You bought it through GOogle store?
talon8635 13 hours ago [-]
What??
burningChrome 18 hours ago [-]
[flagged]
kotaKat 18 hours ago [-]
It's the SomethingAwful model: go to the store and find the cheapest Android phone from some prepaid company for :tenbux: then use it to set up your Google account during out-of-box-setup while on the store's free public WiFi (since Google OOBE allows free account creation without a number or existing email), then toss the phone in a drawer afterwards.
"Hope ya got ten bucks!"
(I got a random 5G Moto phone for ~$10 on clearance and it was an absolute shitter of a phone full of garbage packed in malware, but after cleaning and debloating as much as I can, it's at least a nifty toy to poke at Termux or something.)
TeMPOraL 16 hours ago [-]
The "Twitter counter" to that is, "We've detected suspicious activity on your account. To continue, please verify your phone number."
khriss 17 hours ago [-]
> you can sign into the Play Store with a Google Account that isn't tied to anything else.
The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant.
The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past.
steelframe 14 hours ago [-]
I recently had to set up a new Android device for work. Since I keep all my personal accounts separate from my work accounts, I needed to create a new Google account on that phone. I ended up paying $8 for a month of the cheapest service I could find just to get a phone number so I could create that account.
rkagerer 15 hours ago [-]
...with a Google Account that isn't tied to anything else
That isn't completely possible these days. Last I checked they want an existing email address and/or a cellphone number for verification. I guess "not tied to anything else" is proportional to how much you trust them to delete either of these bits of info after they are used, and not associate them with other accounts you might have used them with in the past/future.
welwala 15 hours ago [-]
Yes but Aurora isn't only for GrapheneOS.
I use it on a phone with (unfortunately) regular google play services. If I sign into the play store, that same account will be used for all other google services on the phone too. I'm not going to do that. I just don't want a google account (nor an apple one for that matter)
blablabla123 16 hours ago [-]
> GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.
Interesting, I never tried Aurora on Graphene. For me the combination of Play Store and F-Droid worked really well so far.
innocent_name 15 hours ago [-]
>For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.
Like my personal phone?)
Installing Google Play service is in itself a privacy downgrade.
zackify 15 hours ago [-]
It DOES still hurt.
For example the eBay app. Does not allow installing from the play store on grapheneos.
jsiepkes 15 hours ago [-]
There are apps I cannot install via the Play Store in GrapheneOS, only via Aurora store.
andrepd 14 hours ago [-]
GrapheneOS is defending against different things I guess. My personal threat model is protecting myself from the tentacles of these behemoth tech companies. To that end, GrapheneOS approach of "just install google play" is not good enough for me. I fail to see the privacy advantages compared to e.g. MicroG".
attila-lendvai 13 hours ago [-]
i don't even have google play serices installed, let alone the play store...
halyconWays 17 hours ago [-]
"For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else."
lol. lamo, even.
troyvit 18 hours ago [-]
I use Aurora on GOS. I get that they say sandboxed Play is more secure than Aurora, but I prefer it for its lack of toxicity and absence of shitty dark patterns.
I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community.
DaSHacka 18 hours ago [-]
I actually think there's already a lot of us in the 'community' as-is. I personally describe it as 'Valuing Privacy/Freedom over Security'. One pretty clear example of this is how they don't recommend using FireFox Mobile and F-Droid, both of which I use regardless because I'm not willing to put up with worse privacy/usability tradeoffs in the name of (imo 'hyper-')security.
I think it's fine the mission of the project isn't directly aligned with some of us, though I can tell we often get on the core contributor's nerves lol
Borealid 16 hours ago [-]
They're both security, just security "against" different things. Graphene frequently fails to clearly describe the threat model when calling something "more secure".
For example, let's say hypothetically I want to be secure against the threat of Google pushing a targeted update to my phone that runs malicious code. Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat. But Graphene devs say things like "MicroG is less secure than Google Play Services".
Similarly, if you want privacy you might secure your device by locking the bootloader with your own keys - not a third-party vendor's keys. Saying that's "insecure" is extremely misleading: it just puts you in charge of security, instead of abdicating to someone else.
I wish there were something like GrapheneOS that let you choose, yourself, who to trust instead of requiring you trust an OS vendor implicitly.
exceptione 16 hours ago [-]
> Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat
I would say that any auto-update mechanism is a threat, so in both cases you would disable auto-updates.
lucb1e 15 hours ago [-]
The point is that you might know the people behind microG or trust them for any other reason, but not the people at Google
exceptione 15 hours ago [-]
Fair point.
microtonal 55 minutes ago [-]
But Graphene devs say things like "MicroG is less secure than Google Play Services".
It is. microG runs Google DroidGuard blobs in a privileged process (to pass Play Integrity Basic). Reminder for those who forgot about DroidGuard: it's an obfuscated binary blob delivered to you by Google on each request that uses a special VM with constantly changing registers, etc. to avoid analysis.
On GrapheneOS that crap runs in a sandbox.
megagpt5 17 hours ago [-]
They actually ban people from their Discord (which is their official support channel - so much for privacy/security!) for mentioning F-Droid. I'm starting to think the creator of F-Droid must have run over their dog.
ysnp 1 hours ago [-]
I have mentioned F-Droid many times in they official Matrix before they moved to Discord and not been banned. You might be misunderstanding what actually happened or have not asked the moderators why someone was banned.
unrented7977 17 hours ago [-]
This is the exact reason I quit using Graphene. It felt exactly like selling out control of my device to the Graphene devs in the same way a stock phone is controlled by Google.
Far, far too "opinionated" for my taste. I frankly do not need the hyper paranoid security features like a hardened memory allocator or disabled root. I would rather be able to use my device the way I want, even if that's notionally "less secure".
I really wish there were another option. Lineage is too far in the opposite direction and feels like ad-blocked stock. Google still owns my phone, there's just a more pleasant coat of paint on it.
tentacleuno 14 hours ago [-]
> I frankly do not need the hyper paranoid security features like a hardened memory allocator
I get the part about disabled root - you're choosing to sacrifice freedom for security - though I don't understand why you wouldn't want a hardened memory allocator. It provides additional security over the stock OS for very little cost (slightly more resource consumption), in an era where we absolutely need as much security as we can get; what are you losing by gaining this?
seany 17 hours ago [-]
they do similar things for people trying to use magisk, but also relock the boot loader. I gave up trying to bother, since the whole reason I use roms is for root first, privacy second.
throawayonthe 17 hours ago [-]
[flagged]
titularcomment 17 hours ago [-]
FYI, there are ungoogled chromium builds for Android. Firefox Mobile really is a lackluster browser unfortunately both from a usability and security standpoint (e.g. IonStack worked on Fennec)
Semaphor 17 hours ago [-]
I really like the Firefox usability. For what I do it works great. It has uBo and a bunch of other extensions, and if course it can sync with desktop.
tpm 17 hours ago [-]
I'm using Firefox mobile for many years exclusively (since chrome forced some stupid feature on me, I think it was tab groups which I hated and couldn't turn off. And of course no ubo). Could be a bit faster probably? Otherwise don't see any issues.
aaravchen 5 hours ago [-]
I would actually argue the exact opposite. All of the Chromium-based forks are a usability disaster. I have to use grid view only to see my tabs? It took them most of a decade to finally get the relatively common place bottom bar, and it still arbitrarily decides to ignore your setting if it thinks your screen is "too big"? It's just failure after failure. I absolutely dread when some shitty site I'm forced to use refuses to load in anything but chrome and I have to open up Vanadium for the first time in forever.
Markoff 1 hours ago [-]
pretty sure Cromite allows more options than just grid view which I hate, I usually use List, though I recently switched back to Firefox, already even forgot the reason
flexagoon 18 hours ago [-]
> I hope it's not too annoying for their community
There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.
The core dev team is obviously a bit more security absolutist, but even they usually dont mind
lucb1e 15 hours ago [-]
> Everyone generally understands that different people have different threat models
Citation needed. If there are such people in what can be considered a grapheneos community that haven't gotten fed up yet and left, grapheneos themselves sure doesn't understand this
> Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.
Nah, they're fine with tracking, so long as it happens in their sandbox. The official website has an install guide for google's background services, saying it's fine because it's in their security model. So long as the modem can't access your contacts without a permission prompt, there is no tracking in baghdad
ysnp 1 hours ago [-]
>Citation needed. grapheneos themselves sure doesn't understand this
The GrapheneOS team understand full well that in cases where the Play Store does not allow installing an app on your device due to device or georestrictive rules you may have no choice. I have seen them mention this and acknowledge it first hand. What they do not want is for people to become satisfied with subpar solutions instead of striving for bare minimum privacy/security standards. They want a Play Store alternative front end to at least be able to guarantee you are receiving the right app you want instead of being a substitution attack risk. I don't think that is unreasonable.
>The official website has an install guide for google's background services, saying it's fine because it's in their security model.
The context is that before sandboxed-play-services were introduced people were sourcing APKs in unsafe/via unverified routes and having all sorts of problems with app compatibility because since GrapheneOS is a privacy project that do not accept sending copious amounts of data to one party with a mediocre privacy policy they included no Google services at all. sandboxed-play-services is a specific solution to the problem of apps being dependent on Google Mobile Services for functionality, and in that sense it is entirely optional. It was the best way for them to provide compatibility without destroying the privacy of their platform by introducing a privileged Google binary that can glean and abuse your production environment. It's reduced to the same level as any other app the user might choose to install themselves (which GrapheneOS want absolutely no say over as a user freedom protecting project).
GrapheneOS do not bundle any Google services in their official installation. They do not endorse Google's data collection and service practices. They do not believe Google tracking is fine in anyway, and the evidence is here: https://eylenburg.github.io/android_comparison.htm
What they have done is provide a workaround for people who have no alternative, while making sure it does not violate the device owners device in a special way compared to any other app they might install.
g-b-r 12 hours ago [-]
> The core dev team is obviously a bit more security absolutist, but even they usually dont mind
Their absolutist of their own view of security
kjander79 18 hours ago [-]
I feel the title editorializes a bit too much. The thread only confirms the bug, not a specific cause yet. As sibling comments indicate, the effect on GrapheneOS users is undetermined.
kevincox 17 hours ago [-]
This also has nothing to do with GrapheneOS except for some user overlap.
tentacleuno 14 hours ago [-]
If anything, it seems more poised to damage the usability of systems which actively rely on Aurora Store, like CalyxOS and the likes. Graphene actively discourages using Aurora.
titularcomment 18 hours ago [-]
This is standart, and happens constantly with Invidious (youtube frontend). This happened before on AuroraOSS too. They probably just flagged the accounts and no API change or A/B testing an API change.
aniviacat 18 hours ago [-]
For me, the issue also only occurs sometimes. Usually I can download apps like normal.
g-b-r 12 hours ago [-]
Even in the last days? If you use anonymous accounts it seems to affect everyone, when it works it only works for a few downloads
skeledrew 18 hours ago [-]
I've been stuck with unupdated apps because Aurora hasn't been working for me for a while. A few of them have been nagging me to update. I have everything Google disabled or removed, and no I won't reenable any of it. Also I use anon strictly on Aurora, and no I won't login with my Google account; haven't logged in on a phone for over 8 years now and I have no intention of breaking the streak.
g-b-r 12 hours ago [-]
For a while as in more than a few weeks, when the current issues began?
Have you looked for help? It sure isn't because of any Google component being disabled
Markoff 1 hours ago [-]
I had last successsful update on August 26, which I wouldnt call for a while, tried yesterday, I've got error messages everyone mentions
today I bothered to try various anonymous Aurora accounts and found finally the one working (like 5th in row) and updated the apps, I can live with updates once a week, not exactly sure what is OP doing
I mean if they are really rate limited just give me waiting time, I don't really care whether I have to wait in queue for an hour if it will update the app later without my intervention
btw. I am not using graphene, find it too paranoid for my taste, though I use my phone without google account for like 10+ years and current phone is first where I have (not disabled/have preinstalled) google play services
ssernikk 17 hours ago [-]
I maintain my grandmothers phone, which comes down mostly to just updating WhatsApp once in a while. Obviously she doesn't have a google account, so I've installed her AuroraStore.
It's a shame that there is no official way to install apps on android without a google accout[1], since it's a basic functionality, just like calls or a web browser.
[1] For obvious reasons I don't want her to download apks from the internet.
dwedge 13 hours ago [-]
The official download page for WhatsApp provides the apk. Other apps are problematic
There are other Android stores. Amazon ran one for the longest time. Many brands have their own app stores as well.
It's the app publishers defaulting to Google that's the biggest issue.
At least WhatsApp has an official APK download, most apps don't.
That said, Google will still let you update apps without being signed in. Hold the Play Store icon to open the quick action menu. From there you can go to "my apps" and update all of the apps on your phone, bypassing the login prompt. Not great, but a workaround that should do the trick while Aurora finds another way to hack their way into the Play Store APIs.
lern_too_spel 16 hours ago [-]
App verification means she can safely install apps from the Internet. The app developers can simply serve the apks from their own websites.
catlikesshrimp 17 hours ago [-]
I am in the same boat. Keep in mind that you are trusting both google and meta. At least you can update whatsapp once every three months (for now)
alt227 17 hours ago [-]
Is it not possible to just download the updated whatsapp apk from some online source? That is the benefit of android after all, side loading is still possible relatively easily.
dwedge 13 hours ago [-]
The comments here specifically about WhatsApp are weird because WhatsApp download page links to the app store but also provides an APK right there
iAMkenough 16 hours ago [-]
I'll be your random online source if you want. Just give me a few days to work on an APK for you to download and install.
alt227 15 hours ago [-]
People download apks from pirate sites and install them all the time, I dont think this is much different
iAMkenough 15 hours ago [-]
Hell yeah they do. I should know.
crtasm 15 hours ago [-]
How do you plan to get Meta's private signing key so Android will allow it as an update?
iAMkenough 15 hours ago [-]
I’ll take the same approach Smarsh/TeleMessage uses to load modified WhatsApp, Signal and Telegram APKs on U.S. federal agency devices.
Grandma doesn’t care if it looks like an update or not.
catlikesshrimp 13 hours ago [-]
There are whatsapp cracked apks which actually work as whatsapp... and they have "extras", and I would never install it, although I have seen it installed
denzen 18 hours ago [-]
Using lineageos on an old samsung without any google services, I guess this would impact many "degoogled" users as well
nosioptar 17 hours ago [-]
Running LOS on some kind of oneplus.
Aurora hasn't worked right for the most part for a year due to device attestation shit.
I'm meh on it. Not being able to install the shit from play store isn't such a bad thing. It is lame as hell that Google is doing their damndest to make apple look user friendly.
CodesInChaos 18 hours ago [-]
For me anonymous use of Aurora never really worked, and with a google account it still works.
nfriedly 7 hours ago [-]
AuroraStore is/was really nice for running purchased games on Android-based game consoles (Retroid Pocket, Ayn Odin, etc.) because a lot of games seem to be incorrectly marked as incompatible with those devices.
Play Store won't let me install them, but AuroraStore will, and most of the time they work fine after that.
For example, I have Balatro running on my Ayn Thor this way.
Installing apps from Aurora Store still does seem to work, although only occasionally. It is more likely that Google is deploying a new API schema on its Play API endpoint that the app doesn't know how to parse correctly yet.
g-b-r 12 hours ago [-]
They'd cripple older versions of the Play Store if they did that, very unlikely
ChocolateGod 18 hours ago [-]
So an app that uses an unofficial API broke when that API changed?
Not news nor "blocking".
berkes 17 hours ago [-]
What is an "official API"?
Honest question, because AFAIK there's no guarantee or (legal) requirement to support any API. Whether that's fully documented, has SDKs or whether it's something reversed-engineered doesn't matter WRT the support the company owning the API is supposed or required to give.
Or am I wrong there?
g-b-r 12 hours ago [-]
An official API is an API described in official documentation and explicitly open to the public, an unofficial one is one not documented publicly and only meant for the company's products.
g-b-r 12 hours ago [-]
No API changed. They just, almost for sure, decreased their rate limits.
It affects using Aurora Store "anonymously" because that means using shared accounts, so far higher activity per account.
It's possible they're also detecting contemporary usage of the same account.
But there's a slight chance that it's just due to someone abusing the accounts outside Aurora Store.
t1234s 4 hours ago [-]
Anyone have issues getting Waymo app to work on Graphine OS?
welwala 15 hours ago [-]
Annoying but this kinda thing happens every 6 months or so. Sometimes Google starts throttling, other times doing some API checks. Every time the Aurora guys figure out a way around it. They're our heroes <3
Even this particular error ("Server busy, try again later"). I've been seeing over the past weeks but then a few days later it worked again. I'm not too worried. It also happens or me right now indeed.
Markoff 59 minutes ago [-]
yeah, nothing new really, last update I had on august 26 without issues, tried yesterday, had issues, so today switched couple of accounts until it worked, been using aurorastore for many years
and in the end I don't really care whether my apps won't get updated anyway, only app which will start bitching about being outdated is whatsapp, which can be for now downloaded directly from whatsapp without playstore (I have also telegram as backup which also allows direct APK download) so not too worried even if Aurora was down for couple of months, I don't use any banking/payment apps in my phone for a reason
theandrewbailey 15 hours ago [-]
Looks like I might start using Aptoide again. I was using it back when I was running de-Googled LineageOS. What's the consensus on it vs. Play Store or F-droid?
For F-Droid apps I don't use their app. I use Neo Store with the Guardian and IzzyOnDroid repos.
tentacleuno 14 hours ago [-]
I'm sure I got malware from there, once - it seems rife with illegitimate apps.
functionmouse 15 hours ago [-]
Play Store and F-Droid are both official software repositories. I'm not confident the same can be said for Aptiode.
ChrisArchitect 18 hours ago [-]
Title is: Aurora Store returns a “&$Server busy, please try again later.” error
erikvanoosten 17 hours ago [-]
Okay, it was a bit of clickbait. Didn't expect it to be picked up like this.
Mistake from me: apparently GrapheneOS does not recommend Aurora Store (citation needed). Kind of weird though; it means Google still knows a lot about you, which doesn't seem very privacy conscience.
Google blocking Aurora Store was a conclusion made in the bug thread. It was not my conclusion.
And for the nit pickers: Sailfish OS is not Android, but its emulation layer _is_. :shrug: Even though Sailfish is nice, without its Android layer it is practically unusable.
Funny thing: the 'busy server' problem existed for almost a week. I could download 1 app per day max on my Jolla C2. But just now, now that this thread makes top of Hackernews, everything started working just fine!
tentacleuno 14 hours ago [-]
> Kind of weird though; it means Google still knows a lot about you, which doesn't seem very privacy conscience.
I remember being in the GrapheneOS room and hearing them directly recommend using Windows 10 over Linux, as it was more secure. They are known to prioritize security over privacy.
g-b-r 12 hours ago [-]
Without realizing that a lack of privacy affects your security a lot
tentacleuno 12 hours ago [-]
Yeah, there's definitely a happy middle ground. I'm a firm believer in gaining a good understanding of your threat model before taking steps to protect it -- quite a surprising amount of people use Qubes, Graphene, Kicksecure and such without really understanding what they want to protect themselves against. In a lot of cases, that just adds unnecessary friction and overcomplexity that ends up doing more harm than good. I was guilty of this myself.
On paper, I'm sure Windows does have stronger userspace and kernel-space protections against intrusion and such, though I most certainly wouldn't use it.
g-b-r 11 hours ago [-]
It's not about a middle ground, their idea of security is wrong.
They largely ignore any threat that could come from US agencies, and are very presumptuous about some of their convictions (e.g. that open source is irrelevant for security).
There is a balance to be made, given that there often isn't any ideal option, but they often get that balance assessment wrong, in my opinion.
I appreciate exposing the security weaknesses of other products, but they end up adding threats that they don't have with some of their drastic views.
ysnp 2 hours ago [-]
They (GrapheneOS development team) live and breathe the principled stance you seem to be describing.
They are staunchly against authoritarianism and mechanisms that are vulnerable to government coercion which is why they promote Android IAR and criticise Play App Signing for being mandatory.
I have understood their position to be that software is not automatically secure because it is open source, but being open source is one of the best ways to ensure to maximise attack resiliency (they believe in kerchoff's principle, shallow bugs, collaboration as a pragmatic help to get there not taken for granted or a guarantee). You'd probably be interested to know the founder once proclaimed publicly that they would never work on proprietary software.
Don't pay too much heed to how community members frame things, they are human and get things wrong in service of trying to reduce conversation to specific facts and technical assurances instead of discussing the bigger picture.
gpvos 12 hours ago [-]
Does it? For me, updates still fail, but now silently.
thataccount 11 hours ago [-]
Update: As of this evening, not an issue for Calyx.
kotaKat 18 hours ago [-]
Didn't Epic get some kind of magic injunction saying that Google had to allow open access to the entire Play Store catalogue or something?
megagpt2 18 hours ago [-]
But not for everyone for free. What it means is Epic, or anyone like Epic, will be able to write to Google, send a nominal amount of money, and get some API key and bare documentation which is only allowed to be used in Epic. It's a B2B commercial transaction under court-ordered terms, not an open API. Same as the Apple browser API. If you want, you can register a company "Kotakat App Store Inc" and get access to the same terms but you'll probably need to sue Google to make them give you access. Apple hasn't approved any browsers, either.
Also, EU is pushing towards more "open" app-stores through anti-trust.
Not that it requires Google to "open up" their play-store, but that they must allow other app-stores to work on the same level. So basically allowing devs and users to move elsewhere.
zoobab 17 hours ago [-]
Well, i emailed the DMA team at the European Commission, they don't plan to do anything to Keep Android Open.
Apple moved first with making a special 'sideloading' case for apps not under their control, Google is just copying what they did.
No more free sideloading.
megagpt5 17 hours ago [-]
They did, but you still have to sign a contract with them to get access.
18 hours ago [-]
_leom 18 hours ago [-]
This happened to me but then got fixed the day later
thataccount 17 hours ago [-]
Looks like the same thing is true for Calyx.
welwala 15 hours ago [-]
Also for AuroraOS on other phones with google services but no signed-in play account.
g-b-r 11 hours ago [-]
Calyx funded Aurora's development for a long time, so it's very true
westurner 16 hours ago [-]
Web Native then. App Stores are lame anyway.
Try and find a category for "open source" apps on any app store.
Ajedi32 15 hours ago [-]
On F-Droid that's just the entire store.
lenerdenator 17 hours ago [-]
Remember when people kept justifying Android over Windows Phone/Maemo/WebOS/BlackBerry/FirefoxOS on the grounds that it was free and open source software, infinitely customizable, and that Google was a good-faith partner who wanted openness in the mobile market?
Good times, good times.
lucb1e 15 hours ago [-]
This is exactly why I switched to Android. Running any Linux binary with just a small bit of patchwork to get Xorg running (this was before Wayland) felt like magic. So much power in your pocket, I could plug a keyboard and display into the device and use it as a computer! And internet-connected 24/7! Coming from a literal Nokia where I made some web-apps for the javascript-supported browser (that was already a major leap for a mobile phone), it blew my mind. The sole reason Android blew up is the endless possibilities developers saw (starting with the device manufacturers of course). Now the developers are here, the competitors haven't been competing because who cared about Firefox OS or Windows Mobile even back in 2014, and so Google can do whatever
catlikesshrimp 17 hours ago [-]
AOSP is still open. The problem is nobody wants to bear the (monumental) cost of polishing and convincing brands to allow installing it in THEIR devices. Google was motivated back then for creating an alternative and openness was a good bait.
lenerdenator 16 hours ago [-]
The fact that no one wants to bear the cost to pre-load it on devices, when combined with the fact that it's not nearly as easy to install OSes on mobile devices as it is on most laptop/desktop/server machines, means that it might as well be closed-source. The point of software is to be executed. If I don't have a good way to execute the software for its intended purpose, I have a collection of ones and zeros, and nothing more.
The window to have a real open mobile OS is starting to close. If there is to be a meaningful change, it must happen soon.
ranger_danger 18 hours ago [-]
> Aurora uses burner account for anonymous login. looks like their account pool is flagged
This seems like it was destined to get banned somehow... and I don't think it means that the store itself is blocked, just the pool of accounts they (ab)use.
zoobab 17 hours ago [-]
From bad to worse.
okokwhatever 17 hours ago [-]
Sadly I'm gonna have to migrate again to an ios device...
gruez 16 hours ago [-]
/s?
18 hours ago [-]
meehow 14 hours ago [-]
[dead]
heliskyr2 6 hours ago [-]
[flagged]
v1z 18 hours ago [-]
[dead]
shevy-java 18 hours ago [-]
Google becomes more and more evil by the second now.
hluska 17 hours ago [-]
That’s quite the conclusion to derive from a Gitlab issue. Do you mind sharing your thought process or was that just a knee jerk reaction without any reasoning behind it?
erikvanoosten 19 hours ago [-]
Android distributions that recommend AuroraStore (such as Graphene OS and Sailfish OS) are now mostly blocked by Google Play Store.
dxjxjdjsssb 19 hours ago [-]
Play store works just fine on GrapheneOS. All of play services run in a sandbox.
You can install the Play store from the GrapheneOS App Store.
In fact I'm pretty sure the GrapheneOS folks advise against Aurora Store, etc.
himata4113 18 hours ago [-]
The entire point is so you don't have to have a google account. Aurora actually works fine if you do sign in. This is just blocking anon downloads.
megagpt2 18 hours ago [-]
Market price for a Google account is about $1.50, you can also buy a burner SIM to set up the maximum number of accounts Google will let you with the same phone number.
ta8903 4 hours ago [-]
You don't need a sim card to make accounts for a phone in the first place. Not sure how, but on android devices they let you make an account without giving them a phone number. Probably because even Google realizes how bad gating application installs on new phones on having a phone number would look.
The problem is that even if you have separate google accounts on each android device, Google can still track you by looking at your contacts.
imzadi 19 hours ago [-]
Yeah, was confused. I'm on GrapheneOS and don't even know what Aurora is.
CodesInChaos 18 hours ago [-]
It's an alternative client app for the google store.
JoshStrobl 18 hours ago [-]
Sailfish OS user on Jolla Phone 2: Aurora is working fine here.
P.S. Sailfish OS is NOT an Android distribution. It is a proper Linux system and they have their own custom Android runtime (AppSupport) as a layer on top for running Android apps. This runtime _is_ Android under the hood, but is separate from Sailfish itself (has its own native app ecosystem).
g-b-r 11 hours ago [-]
With anonymous login?
17 hours ago [-]
bushwart 18 hours ago [-]
I wasn't aware GOS recommended AuroraStore.
Cider9986 17 hours ago [-]
They don't. It's unreliable but they have fixed security issues.
iAMkenough 18 hours ago [-]
AuroraStore uses a pool of burner Google Play Store accounts to facilitate anonymous downloads. This is what happens when those burner accounts get flagged.
ErenayDev 18 hours ago [-]
I'm using my Proton account in my phone and in play store. now i tried adding my proton account in AuroraStore, and it worked flawlessly. so my question: why AuroraStore uses google accounts instead of another providers?
g-b-r 11 hours ago [-]
What the hell are you talking about? Proton accounts to access the Play Store?
ErenayDev 4 hours ago [-]
what happened? if you're trying to say that this is "impossible", its not. But if you're trying to say about privacy, that account I tried is another one of mine. im not stupid to use my primary proton account in my phone.
g-b-r 3 hours ago [-]
What are you talking about???
How could an account from a completely different company let you login to Google's Play Store???
You probably mean a Google account that uses your Proton mail address?
ranger_danger 18 hours ago [-]
How does one even create a new google account in $current_year without requiring phone verification or worse?
megagpt2 18 hours ago [-]
You could suck it up and do the phone number verification, it usually costs around $5 for a phone number.
Or you could go through the android phone sign-up process which doesn't require one. Buy a cheap android phone and keep resetting it and making a new account each time.
Or you could buy an account on the grey web from someone who already did this. Should be under $2.
If you are really into this you could become a phone company and own a whole block of phone numbers.
Markoff 48 minutes ago [-]
btw. you can get prepaid physical SIM cards in Czechia for free send by mailbox, you just need some available mailbox wheere you can pick it up, like put Donald Duck sticker on your mailbox and address it to Donald Duck
I used android sign up process to create my other dummy account I use in TV only for smarttube and app updates, that seems like great option if it still works
ranger_danger 17 hours ago [-]
The whole point of avoiding the verification in my case is for privacy reasons... I don't want google or anyone else tracking what I do through the use of an account.
> Or you could go through the android phone sign-up process which doesn't require one
This is worse IMO because now the number is associated with that device forever. And unless I'm willing to risk my account to compromise from a future owner of the same number OR device, I must now keep both... forever.
> grey web
I don't want to give them my info either, nor have my account associated with sketchy individuals.
> you could become a phone company
I do own DID blocks but this is unhelpful because google's verification specifically requires SMS over real mobile numbers, and I'm not interested in becoming an MVNO or cellular carrier.
megagpt2 2 hours ago [-]
Bad news - Google doesn't need an account to track your app downloadsm
Perhaps you'd be more interested in creating a website that downloads all the apps from the play store using burner accounts and makes them easily anonymously accessible.
Cider9986 17 hours ago [-]
Play store works fine on GrapheneOS.
savwolf 18 hours ago [-]
GOS recommends play store
ysnp 2 hours ago [-]
They suggest PlayStore if you need to get apps that are only available on the Play Store. They do not recommend it above other options, and have mentioned that they very much disapprove of Play App Signing being mandatory.
For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.
Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't).
Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play.
That's personally what I used Aurora for, plus as an easy way to export APK files.
At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.
But my goal is to avoid a stranger gaining access to my google services if they manage to unlock a lost device or steal my TV/streaming box that has no lock at all.
I wish Google supported a permission system per device. For example on most of my android devices all I really want is to be logged into Youtube and the play store. I most certainly do not want those devices to have access to my contacts, emails, calendar, keep, drive, payment, etc. (I don't personally use all of those things, but you might and that's what a random thief would gain access to.)
All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them
Their tracking is baked into various apps even if you don't have an account with them. Anything with social media integrations can report back to the mothership behind your back.
Yes, the advertising targeting is incredibly invasive, but let's not pretend they aren't providing world class Search, Email, Docs, Maps, Video (YT), etc in exchange.
For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.
So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.
And yeah the iris scans sound like a scare but only 2 years ago there was a constant line of zombies here in the shopping mall giving their eye scans to altman.
The masses really don't care about privacy if you give them a worthless trinket.
You probably "just" need to pull down while on the "Latest" or "Updates" tab, to update your repository (it will show a small banner at the top while it's doing that). It's incremental, so it may take a while if it has been some time since you last did it (and auto-updates are disabled).
The way F-Droid works is that it downloads the whole index and then the catalog, version checks, etc, all runs locally, quite similarly to some package repositories actually.
I am not claiming its intuitive, but I think that part works fine once you understand how it works.
F-Droid builds all apps by themselves, which especially with their old servers took a lot (between detecting that the update exists, building the app and going to sign everything at their air-gapped signing computer).
Now a lot of apps use the "reproducible builds" feature, which means that F-Droid will distribuite them as they come from the author, leaving their digital signature; but they still need to build those apps before distributing them, to verify that what the author built corresponds to the declared source code.
With the much powerful servers that they've had for a few months builds are a lot quicker, but there are still steps that can take several days, especially the part of signing the apps' index on their air-gapped computer.
There's a ton of things that could be improved, and it would be best if there were an alternative with better maintainers, but they're currently the only service of this kind for Android (well, IzzyOnDroid is a partial alternative, if you're careful to check their reproducible builds results).
We search for stuff, install it, it updates in the background. We install some of our own repos, but the bulk of our apps come from F-Droid's default repos.
Hard to reconcile your account with my experience without specifics.
I very much prefer Obtainium these days despite the setup steps. I don't think it's a coincidence that Obtainium, Aurora, Zapstore, etc. are gaining mindshare over F-Droid, just like how Brave has explosive growth over FF.
https://github.com/rumboalla/apkupdater
though personally I use it only for Fdroid, Gitlab and Github
Sounds like an accurate recreation of the Play Store experience to me.
You're sure you understand what it does?
Braindead dev claims this is to limit the "piracy" and bug reports, nevertheless it's either Aurora or APKMirror.
Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.
Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.
The trick is, that in the general case, you can not keep this account online indefinitely.
I once worked out a trick to get it going and I was feeling safe because I had setup 2FA and backup codes (see https://masysma.net/37/google_how_to_create_an_account_witho...).
First thing to note: This way of account creation does not seem to work anymore.
Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...
Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).
I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.
I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...
You can also just get a burner phone number for a few bucks.
But you have to keep paying the monthly cost, if you loose access to a phone number in your Google account it's game over for any account recovery or "let's verify it's you" it might decide to throw your way.
a burner sim, like a literal criminal, is the only way today.
In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.
> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.
It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."
That one lists:
There is no READ_PRIVILEGED_PHONE_STATE mentioned there.
EDIT: "GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims." [1] This seems to indicate that the permissions requested by Play Services are being honored with the shims from the helper app. That would alleviate the permission problem.
1. https://github.com/GrapheneOS/platform_packages_apps_GmsComp...
For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.
The check seems to be purely store-based and never enforced later.
But using Aurora I can install it just fine and it works flawlessly.
(for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)
I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store
https://github.com/privacyguides/verified-apps-android
https://github.com/privacyguides/verified-apps/
I think in general trust is established for Play Store apps by downloading the app with the Play Store on a phone with Google Certified Android. Then the app can get the signing key for storage in the database. Then this can be used to verify APKs downloaded outside the play store.
Wether or not the most recent example is the best example, doesn't matter. What matters is when the government says "jump" in legalese, google's lawyers say "how high?"
GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm
How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.
Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.
Looking at their public statements on the matter, it seems like the problem isn't exactly that they treat the user as a potentially hostile actor so much as that they treat the system UI and persistent storage as a potentially hostile actor (though I admit from a practical perspective that's nearly the same thing): https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root...
I wonder how they'd feel about something like protected confirmation to enable sudo: https://source.android.com/docs/security/features/protected-...
I believe you misunderstand what "software freedom" means. You can compile and install GrapheneOS yourself, and you can grant yourself admin access. This is software freedom.
Software freedom does not mean that you should run everything as an admin, always. And just in case: software freedom does NOT mean that you should remove your firewall and let everybody SSH into your server by having a blank password.
I think it's fair to say that that's at least borderline anti software freedom, even if it's true they have good security reasons for doing things that way.
Then you don't understand software freedom either.
Software freedom doesn't mean AT ALL that random projects on the Internet MUST implement the features YOU want. Never, not at all, it's not borderline, it's not up to debate.
Software freedom is about being able to use the software the way you want, as in "you get access to the sources, you modify them, build them and run them". You can do that with GrapheneOS (well except for the binary blobs situation, but that's not in GrapheneOS' hands at all). Software freedom is NOT about GrapheneOS giving you root access on official builds because you want it. And it's also NOT about GrapheneOS installing Doom on the official builds because I want it.
Yeah, the goal is privacy although the OS is completely open source.
They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes.
You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.
I personally would prefer to have both but choose the privacy side when both are into conflict.
Both viewpoints are valid, but I don't use GrapheneOS for this reason.
Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.
Google states: Using a false name or incorrect information when creating a Google account is against Google's Terms of Service.
I don't really see the point of using GrapheneOS instead of Stock Android if I then have to use the play store.
Also on GrapheneOS, Play Services and Play Store come unprivileged, sandboxed like any other app. So Google is not an admin on your phone, which I would argue is one step towards "severing the umbilical cord".
Moreover, GrapheneOS doesn't have any issue with apps sideloading.
And more. There are many reasons to use GrapheneOS.
How can I get this wonderful thing?
And “worried about anonymity in that way”… that’s the topic being discussed here.
As far as cell service goes well yeah there is no such thing as anonymity. Towers will always know your location as long as the radio is on and that can be correlated easily.
"Hope ya got ten bucks!"
(I got a random 5G Moto phone for ~$10 on clearance and it was an absolute shitter of a phone full of garbage packed in malware, but after cleaning and debloating as much as I can, it's at least a nifty toy to poke at Termux or something.)
The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant.
The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past.
That isn't completely possible these days. Last I checked they want an existing email address and/or a cellphone number for verification. I guess "not tied to anything else" is proportional to how much you trust them to delete either of these bits of info after they are used, and not associate them with other accounts you might have used them with in the past/future.
I use it on a phone with (unfortunately) regular google play services. If I sign into the play store, that same account will be used for all other google services on the phone too. I'm not going to do that. I just don't want a google account (nor an apple one for that matter)
Interesting, I never tried Aurora on Graphene. For me the combination of Play Store and F-Droid worked really well so far.
Like my personal phone?)
Installing Google Play service is in itself a privacy downgrade.
For example the eBay app. Does not allow installing from the play store on grapheneos.
lol. lamo, even.
I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community.
I think it's fine the mission of the project isn't directly aligned with some of us, though I can tell we often get on the core contributor's nerves lol
For example, let's say hypothetically I want to be secure against the threat of Google pushing a targeted update to my phone that runs malicious code. Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat. But Graphene devs say things like "MicroG is less secure than Google Play Services".
Similarly, if you want privacy you might secure your device by locking the bootloader with your own keys - not a third-party vendor's keys. Saying that's "insecure" is extremely misleading: it just puts you in charge of security, instead of abdicating to someone else.
I wish there were something like GrapheneOS that let you choose, yourself, who to trust instead of requiring you trust an OS vendor implicitly.
It is. microG runs Google DroidGuard blobs in a privileged process (to pass Play Integrity Basic). Reminder for those who forgot about DroidGuard: it's an obfuscated binary blob delivered to you by Google on each request that uses a special VM with constantly changing registers, etc. to avoid analysis.
On GrapheneOS that crap runs in a sandbox.
Far, far too "opinionated" for my taste. I frankly do not need the hyper paranoid security features like a hardened memory allocator or disabled root. I would rather be able to use my device the way I want, even if that's notionally "less secure".
I really wish there were another option. Lineage is too far in the opposite direction and feels like ad-blocked stock. Google still owns my phone, there's just a more pleasant coat of paint on it.
I get the part about disabled root - you're choosing to sacrifice freedom for security - though I don't understand why you wouldn't want a hardened memory allocator. It provides additional security over the stock OS for very little cost (slightly more resource consumption), in an era where we absolutely need as much security as we can get; what are you losing by gaining this?
There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.
The core dev team is obviously a bit more security absolutist, but even they usually dont mind
Citation needed. If there are such people in what can be considered a grapheneos community that haven't gotten fed up yet and left, grapheneos themselves sure doesn't understand this
> Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.
Nah, they're fine with tracking, so long as it happens in their sandbox. The official website has an install guide for google's background services, saying it's fine because it's in their security model. So long as the modem can't access your contacts without a permission prompt, there is no tracking in baghdad
The GrapheneOS team understand full well that in cases where the Play Store does not allow installing an app on your device due to device or georestrictive rules you may have no choice. I have seen them mention this and acknowledge it first hand. What they do not want is for people to become satisfied with subpar solutions instead of striving for bare minimum privacy/security standards. They want a Play Store alternative front end to at least be able to guarantee you are receiving the right app you want instead of being a substitution attack risk. I don't think that is unreasonable.
>The official website has an install guide for google's background services, saying it's fine because it's in their security model.
The context is that before sandboxed-play-services were introduced people were sourcing APKs in unsafe/via unverified routes and having all sorts of problems with app compatibility because since GrapheneOS is a privacy project that do not accept sending copious amounts of data to one party with a mediocre privacy policy they included no Google services at all. sandboxed-play-services is a specific solution to the problem of apps being dependent on Google Mobile Services for functionality, and in that sense it is entirely optional. It was the best way for them to provide compatibility without destroying the privacy of their platform by introducing a privileged Google binary that can glean and abuse your production environment. It's reduced to the same level as any other app the user might choose to install themselves (which GrapheneOS want absolutely no say over as a user freedom protecting project).
GrapheneOS do not bundle any Google services in their official installation. They do not endorse Google's data collection and service practices. They do not believe Google tracking is fine in anyway, and the evidence is here: https://eylenburg.github.io/android_comparison.htm What they have done is provide a workaround for people who have no alternative, while making sure it does not violate the device owners device in a special way compared to any other app they might install.
Their absolutist of their own view of security
Have you looked for help? It sure isn't because of any Google component being disabled
today I bothered to try various anonymous Aurora accounts and found finally the one working (like 5th in row) and updated the apps, I can live with updates once a week, not exactly sure what is OP doing
I mean if they are really rate limited just give me waiting time, I don't really care whether I have to wait in queue for an hour if it will update the app later without my intervention
btw. I am not using graphene, find it too paranoid for my taste, though I use my phone without google account for like 10+ years and current phone is first where I have (not disabled/have preinstalled) google play services
It's a shame that there is no official way to install apps on android without a google accout[1], since it's a basic functionality, just like calls or a web browser.
[1] For obvious reasons I don't want her to download apks from the internet.
https://www.whatsapp.com/download
It's the app publishers defaulting to Google that's the biggest issue.
At least WhatsApp has an official APK download, most apps don't.
That said, Google will still let you update apps without being signed in. Hold the Play Store icon to open the quick action menu. From there you can go to "my apps" and update all of the apps on your phone, bypassing the login prompt. Not great, but a workaround that should do the trick while Aurora finds another way to hack their way into the Play Store APIs.
Grandma doesn’t care if it looks like an update or not.
Aurora hasn't worked right for the most part for a year due to device attestation shit.
I'm meh on it. Not being able to install the shit from play store isn't such a bad thing. It is lame as hell that Google is doing their damndest to make apple look user friendly.
Play Store won't let me install them, but AuroraStore will, and most of the time they work fine after that.
For example, I have Balatro running on my Ayn Thor this way.
Not news nor "blocking".
Honest question, because AFAIK there's no guarantee or (legal) requirement to support any API. Whether that's fully documented, has SDKs or whether it's something reversed-engineered doesn't matter WRT the support the company owning the API is supposed or required to give.
Or am I wrong there?
It affects using Aurora Store "anonymously" because that means using shared accounts, so far higher activity per account.
It's possible they're also detecting contemporary usage of the same account.
But there's a slight chance that it's just due to someone abusing the accounts outside Aurora Store.
Even this particular error ("Server busy, try again later"). I've been seeing over the past weeks but then a few days later it worked again. I'm not too worried. It also happens or me right now indeed.
and in the end I don't really care whether my apps won't get updated anyway, only app which will start bitching about being outdated is whatsapp, which can be for now downloaded directly from whatsapp without playstore (I have also telegram as backup which also allows direct APK download) so not too worried even if Aurora was down for couple of months, I don't use any banking/payment apps in my phone for a reason
https://en.aptoide.com/
Mistake from me: apparently GrapheneOS does not recommend Aurora Store (citation needed). Kind of weird though; it means Google still knows a lot about you, which doesn't seem very privacy conscience.
Google blocking Aurora Store was a conclusion made in the bug thread. It was not my conclusion.
And for the nit pickers: Sailfish OS is not Android, but its emulation layer _is_. :shrug: Even though Sailfish is nice, without its Android layer it is practically unusable.
Funny thing: the 'busy server' problem existed for almost a week. I could download 1 app per day max on my Jolla C2. But just now, now that this thread makes top of Hackernews, everything started working just fine!
I remember being in the GrapheneOS room and hearing them directly recommend using Windows 10 over Linux, as it was more secure. They are known to prioritize security over privacy.
On paper, I'm sure Windows does have stronger userspace and kernel-space protections against intrusion and such, though I most certainly wouldn't use it.
They largely ignore any threat that could come from US agencies, and are very presumptuous about some of their convictions (e.g. that open source is irrelevant for security).
There is a balance to be made, given that there often isn't any ideal option, but they often get that balance assessment wrong, in my opinion.
I appreciate exposing the security weaknesses of other products, but they end up adding threats that they don't have with some of their drastic views.
They are staunchly against authoritarianism and mechanisms that are vulnerable to government coercion which is why they promote Android IAR and criticise Play App Signing for being mandatory.
I have understood their position to be that software is not automatically secure because it is open source, but being open source is one of the best ways to ensure to maximise attack resiliency (they believe in kerchoff's principle, shallow bugs, collaboration as a pragmatic help to get there not taken for granted or a guarantee). You'd probably be interested to know the founder once proclaimed publicly that they would never work on proprietary software.
Don't pay too much heed to how community members frame things, they are human and get things wrong in service of trying to reduce conversation to specific facts and technical assurances instead of discussing the bigger picture.
Not that it requires Google to "open up" their play-store, but that they must allow other app-stores to work on the same level. So basically allowing devs and users to move elsewhere.
Apple moved first with making a special 'sideloading' case for apps not under their control, Google is just copying what they did.
No more free sideloading.
Try and find a category for "open source" apps on any app store.
Good times, good times.
The window to have a real open mobile OS is starting to close. If there is to be a meaningful change, it must happen soon.
This seems like it was destined to get banned somehow... and I don't think it means that the store itself is blocked, just the pool of accounts they (ab)use.
You can install the Play store from the GrapheneOS App Store.
In fact I'm pretty sure the GrapheneOS folks advise against Aurora Store, etc.
The problem is that even if you have separate google accounts on each android device, Google can still track you by looking at your contacts.
P.S. Sailfish OS is NOT an Android distribution. It is a proper Linux system and they have their own custom Android runtime (AppSupport) as a layer on top for running Android apps. This runtime _is_ Android under the hood, but is separate from Sailfish itself (has its own native app ecosystem).
How could an account from a completely different company let you login to Google's Play Store???
You probably mean a Google account that uses your Proton mail address?
Or you could go through the android phone sign-up process which doesn't require one. Buy a cheap android phone and keep resetting it and making a new account each time.
Or you could buy an account on the grey web from someone who already did this. Should be under $2.
If you are really into this you could become a phone company and own a whole block of phone numbers.
I used android sign up process to create my other dummy account I use in TV only for smarttube and app updates, that seems like great option if it still works
> Or you could go through the android phone sign-up process which doesn't require one
This is worse IMO because now the number is associated with that device forever. And unless I'm willing to risk my account to compromise from a future owner of the same number OR device, I must now keep both... forever.
> grey web
I don't want to give them my info either, nor have my account associated with sketchy individuals.
> you could become a phone company
I do own DID blocks but this is unhelpful because google's verification specifically requires SMS over real mobile numbers, and I'm not interested in becoming an MVNO or cellular carrier.
Perhaps you'd be more interested in creating a website that downloads all the apps from the play store using burner accounts and makes them easily anonymously accessible.