Live data from Hacker News

Play Store blocks AuroraStore, hurting GrapheneOS users

gitlab.com

131–140 of 312 posts

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#131

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS.

For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.

So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#132
post #120

Earlier quoted context omitted.

Do you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with. (for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option…

Doesn't Aurora download the packages directly from Google?

Presumably the parent does not want to have to trust Aurora to do that

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#133
post #129

Earlier quoted context omitted.

I'll be your random online source if you want. Just give me a few days to work on an APK for you to download and install.

How do you plan to get Meta's private signing key so Android will allow it as an update?

I’ll take the same approach Smarsh/TeleMessage uses to load modified WhatsApp, Signal and Telegram APKs on U.S. federal agency devices.

Grandma doesn’t care if it looks like an update or not.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#134

Earlier quoted context omitted.

Do you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with. (for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option…

Android apps are signed. Can't you verify the signature?

Can you?

I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#135

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS. For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice a…

I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app. It's one of the worst pieces of software I've used in a while, and I can tolerate a good bit of jank from FOSS apps.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#136

Earlier quoted context omitted.

> Google Account that isn't tied to anything else. At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.

Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.

They have required unique phone numbers for accounts I've tried lately, or parent's phone numbers. Facebook is worse though, they are quick to ban an account/phone number.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#137

Earlier quoted context omitted.

Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.

My experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that h…

> leave their ecosystem

Their tracking is baked into various apps even if you don't have an account with them. Anything with social media integrations can report back to the mothership behind your back.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#139

Earlier quoted context omitted.

They're both security, just security "against" different things. Graphene frequently fails to clearly describe the threat model when calling something "more secure". For example, let's say hypothetically I want to be secure against the threat of Google pushing a targeted update to my phone that runs malicious code. Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG…

> Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat I would say that any auto-update mechanism is a threat, so in both cases you would disable auto-updates.

The point is that you might know the people behind microG or trust them for any other reason, but not the people at Google

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#140
post #134

Earlier quoted context omitted.

Android apps are signed. Can't you verify the signature?

Can you? I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store

Maybe not in practice, but in theory, it works. I don't think there's a better way of handling this without relying on some centralised authority (Google) to validate the authorship of an app, which is hardly desirable.
Post reply on HN