Live data from Hacker News

Play Store blocks AuroraStore, hurting GrapheneOS users

gitlab.com

221–230 of 312 posts

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#221

Earlier quoted context omitted.

The entire point is so you don't have to have a google account. Aurora actually works fine if you do sign in. This is just blocking anon downloads.

Market price for a Google account is about $1.50, you can also buy a burner SIM to set up the maximum number of accounts Google will let you with the same phone number.

You don't need a sim card to make accounts for a phone in the first place. Not sure how, but on android devices they let you make an account without giving them a phone number. Probably because even Google realizes how bad gating application installs on new phones on having a phone number would look.

The problem is that even if you have separate google accounts on each android device, Google can still track you by looking at your contacts.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#222
post #201

Earlier quoted context omitted.

What the hell are you talking about? Proton accounts to access the Play Store?

what happened? if you're trying to say that this is "impossible", its not. But if you're trying to say about privacy, that account I tried is another one of mine. im not stupid to use my primary proton account in my phone.

What are you talking about???

How could an account from a completely different company let you login to Google's Play Store???

You probably mean a Google account that uses your Proton mail address?

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#223

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

> with a Google Account that isn't tied to anything else.

How can I get this wonderful thing?

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#224
post #164

Earlier quoted context omitted.

You can create an account with no phone number during Android device setup. You can also just get a burner phone number for a few bucks.

> You can also just get a burner phone number for a few bucks. But you have to keep paying the monthly cost, if you loose access to a phone number in your Google account it's game over for any account recovery or "let's verify it's you" it might decide to throw your way.

What's the problem then? If it happens, discard that account and make a new Aurora Store burner account.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#225
post #9

[flagged]

GOS recommends play store

They suggest PlayStore if you need to get apps that are only available on the Play Store. They do not recommend it above other options, and have mentioned that they very much disapprove of Play App Signing being mandatory.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#226

Earlier quoted context omitted.

You could suck it up and do the phone number verification, it usually costs around $5 for a phone number. Or you could go through the android phone sign-up process which doesn't require one. Buy a cheap android phone and keep resetting it and making a new account each time. Or you could buy an account on the grey web from someone who already did this. Should be under $2. If you are really into this you could become a…

The whole point of avoiding the verification in my case is for privacy reasons... I don't want google or anyone else tracking what I do through the use of an account. > Or you could go through the android phone sign-up process which doesn't require one This is worse IMO because now the number is associated with that device forever. And unless I'm willing to risk my account to compromise from a future owner of the sam…

Bad news - Google doesn't need an account to track your app downloadsm

Perhaps you'd be more interested in creating a website that downloads all the apps from the play store using burner accounts and makes them easily anonymously accessible.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#227
post #202

Earlier quoted context omitted.

[flagged]

[flagged]

They (GrapheneOS development team) live and breathe the principled stance you seem to be describing.

They are staunchly against authoritarianism and mechanisms that are vulnerable to government coercion which is why they promote Android IAR and criticise Play App Signing for being mandatory.

I have understood their position to be that software is not automatically secure because it is open source, but being open source is one of the best ways to ensure to maximise attack resiliency (they believe in kerchoff's principle, shallow bugs, collaboration as a pragmatic help to get there not taken for granted or a guarantee). You'd probably be interested to know the founder once proclaimed publicly that they would never work on proprietary software.

Don't pay too much heed to how community members frame things, they are human and get things wrong in service of trying to reduce conversation to specific facts and technical assurances instead of discussing the bigger picture.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#228

Earlier quoted context omitted.

I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to downl…

Try using the Droid-ify client: https://f-droid.org/en/packages/com.looker.droidify/

or APKUpdater, which covers besides F-Droid as well APKMirror, Aptoide, IzzyOnDroid, APKPure, GitLab and GitHub

https://github.com/rumboalla/apkupdater

though personally I use it only for Fdroid, Gitlab and Github

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#229
post #144

Earlier quoted context omitted.

> I hope it's not too annoying for their community There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero. The core dev team is obviously…

[flagged]

>Citation needed. grapheneos themselves sure doesn't understand this

The GrapheneOS team understand full well that in cases where the Play Store does not allow installing an app on your device due to device or georestrictive rules you may have no choice. I have seen them mention this and acknowledge it first hand. What they do not want is for people to become satisfied with subpar solutions instead of striving for bare minimum privacy/security standards. They want a Play Store alternative front end to at least be able to guarantee you are receiving the right app you want instead of being a substitution attack risk. I don't think that is unreasonable.

>The official website has an install guide for google's background services, saying it's fine because it's in their security model.

The context is that before sandboxed-play-services were introduced people were sourcing APKs in unsafe/via unverified routes and having all sorts of problems with app compatibility because since GrapheneOS is a privacy project that do not accept sending copious amounts of data to one party with a mediocre privacy policy they included no Google services at all. sandboxed-play-services is a specific solution to the problem of apps being dependent on Google Mobile Services for functionality, and in that sense it is entirely optional. It was the best way for them to provide compatibility without destroying the privacy of their platform by introducing a privileged Google binary that can glean and abuse your production environment. It's reduced to the same level as any other app the user might choose to install themselves (which GrapheneOS want absolutely no say over as a user freedom protecting project).

GrapheneOS do not bundle any Google services in their official installation. They do not endorse Google's data collection and service practices. They do not believe Google tracking is fine in anyway, and the evidence is here: https://eylenburg.github.io/android_comparison.htm What they have done is provide a workaround for people who have no alternative, while making sure it does not violate the device owners device in a special way compared to any other app they might install.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#230
post #173

Earlier quoted context omitted.

> Which is very much contrary to software freedom I believe you misunderstand what "software freedom" means. You can compile and install GrapheneOS yourself, and you can grant yourself admin access. This is software freedom. Software freedom does not mean that you should run everything as an admin, always. And just in case: software freedom does NOT mean that you should remove your firewall and let everybody SSH into…

You can't grant yourself admin access with the official build. Only the Graphene devs have the ability to push changes to the OS on your phone. Yes you can fork the software and build a version with your own signing key, then wipe your phone and install your custom build and thereby take back control, but then is that really still Graphene? I think it's fair to say that that's at least borderline anti software freedo…

> I think it's fair to say that that's at least borderline anti software freedom

Then you don't understand software freedom either.

Software freedom doesn't mean AT ALL that random projects on the Internet MUST implement the features YOU want. Never, not at all, it's not borderline, it's not up to debate.

Software freedom is about being able to use the software the way you want, as in "you get access to the sources, you modify them, build them and run them". You can do that with GrapheneOS (well except for the binary blobs situation, but that's not in GrapheneOS' hands at all). Software freedom is NOT about GrapheneOS giving you root access on official builds because you want it. And it's also NOT about GrapheneOS installing Doom on the official builds because I want it.

Post reply on HN