Live data from Hacker News

Play Store blocks AuroraStore, hurting GrapheneOS users

gitlab.com

141–150 of 312 posts

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#141

Earlier quoted context omitted.

GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS. For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice a…

I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to downl…

> Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app.

Sounds like an accurate recreation of the Play Store experience to me.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#142

Looks like I might start using Aptoide again. I was using it back when I was running de-Googled LineageOS. What's the consensus on it vs. Play Store or F-droid? https://en.aptoide.com/

Play Store and F-Droid are both official software repositories. I'm not confident the same can be said for Aptiode.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#143

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

> a Google Account that isn't tied to anything else. Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.

> > a Google Account that isn't tied to anything else.

> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.

I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.

Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.

The trick is, that in the general case, you can not keep this account online indefinitely.

I once worked out a trick to get it going and I was feeling safe because I had setup 2FA and backup codes (see https://masysma.net/37/google_how_to_create_an_account_witho...).

First thing to note: This way of account creation does not seem to work anymore.

Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...

Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).

I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.

I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#144
post #14

I use Aurora on GOS. I get that they say sandboxed Play is more secure than Aurora, but I prefer it for its lack of toxicity and absence of shitty dark patterns. I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community.

> I hope it's not too annoying for their community There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero. The core dev team is obviously…

[flagged]

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#146

Earlier quoted context omitted.

GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS. For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice a…

I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to downl…

> never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app

You probably "just" need to pull down while on the "Latest" or "Updates" tab, to update your repository (it will show a small banner at the top while it's doing that). It's incremental, so it may take a while if it has been some time since you last did it (and auto-updates are disabled).

The way F-Droid works is that it downloads the whole index and then the catalog, version checks, etc, all runs locally, quite similarly to some package repositories actually.

I am not claiming its intuitive, but I think that part works fine once you understand how it works.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#147
Annoying but this kinda thing happens every 6 months or so. Sometimes Google starts throttling, other times doing some API checks. Every time the Aurora guys figure out a way around it. They're our heroes Even this particular error ("Server busy, try again later"). I've been seeing over the past weeks but then a few days later it worked again. I'm not too worried. It also happens or me right now indeed.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#148

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

There are apps I cannot install via the Play Store in GrapheneOS, only via Aurora store.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#149

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

Yes but Aurora isn't only for GrapheneOS.

I use it on a phone with (unfortunately) regular google play services. If I sign into the play store, that same account will be used for all other google services on the phone too. I'm not going to do that. I just don't want a google account (nor an apple one for that matter)

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#150
post #130

Earlier quoted context omitted.

True. I think this one is closer to the truth: https://github.com/GrapheneOS/platform_packages_apps_GmsComp... > There is no READ_PRIVILEGED_PHONE_STATE mentioned there.

That's also incorrect, because the gmscompat app is just a helper app. Play services can and does request additional permissions. Those permissions are handled by the OS under the play services app, not gmscompat. If you want RCS for instance, you must grant play services and google messages phone and ICC auth access, which isn't seen in gmscompat at all.

  > That's also incorrect, because the gmscompat app is just a helper app.
Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services.

  >  Those permissions are handled by the OS under the play services app
Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unprivileged app, and so any additional permission it would want would have to be consented by the user and should be visible to the user. If not, then GOS wording would be quite a bit unfortunate at least.

EDIT: "GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims." [1] This seems to indicate that the permissions requested by Play Services are being honored with the shims from the helper app. That would alleviate the permission problem.

1. https://github.com/GrapheneOS/platform_packages_apps_GmsComp...

Post reply on HN