Live data from Hacker News

Play Store blocks AuroraStore, hurting GrapheneOS users

gitlab.com

231–240 of 312 posts

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#231

Earlier quoted context omitted.

I actually think there's already a lot of us in the 'community' as-is. I personally describe it as 'Valuing Privacy/Freedom over Security'. One pretty clear example of this is how they don't recommend using FireFox Mobile and F-Droid, both of which I use regardless because I'm not willing to put up with worse privacy/usability tradeoffs in the name of (imo 'hyper-')security. I think it's fine the mission of the proje…

[flagged]

I have mentioned F-Droid many times in the official Matrix before they moved to Discord and not been banned. You might be misunderstanding what actually happened or have not asked the moderators why someone was banned.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#232

Earlier quoted context omitted.

FYI, there are ungoogled chromium builds for Android. Firefox Mobile really is a lackluster browser unfortunately both from a usability and security standpoint (e.g. IonStack worked on Fennec)

I would actually argue the exact opposite. All of the Chromium-based forks are a usability disaster. I have to use grid view only to see my tabs? It took them most of a decade to finally get the relatively common place bottom bar, and it still arbitrarily decides to ignore your setting if it thinks your screen is "too big"? It's just failure after failure. I absolutely dread when some shitty site I'm forced to use re…

pretty sure Cromite allows more options than just grid view which I hate, I usually use List, though I recently switched back to Firefox, already even forgot the reason

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#233
post #192

I've been stuck with unupdated apps because Aurora hasn't been working for me for a while. A few of them have been nagging me to update. I have everything Google disabled or removed, and no I won't reenable any of it. Also I use anon strictly on Aurora, and no I won't login with my Google account; haven't logged in on a phone for over 8 years now and I have no intention of breaking the streak.

For a while as in more than a few weeks, when the current issues began? Have you looked for help? It sure isn't because of any Google component being disabled

I had last successsful update on August 26, which I wouldnt call for a while, tried yesterday, I've got error messages everyone mentions

today I bothered to try various anonymous Aurora accounts and found finally the one working (like 5th in row) and updated the apps, I can live with updates once a week, not exactly sure what is OP doing

I mean if they are really rate limited just give me waiting time, I don't really care whether I have to wait in queue for an hour if it will update the app later without my intervention

btw. I am not using graphene, find it too paranoid for my taste, though I use my phone without google account for like 10+ years and current phone is first where I have (not disabled/have preinstalled) google play services

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#234
post #134

Earlier quoted context omitted.

Android apps are signed. Can't you verify the signature?

Can you? I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store

Privacy Guides is building a database of signing keys with a verifier app:

https://github.com/privacyguides/verified-apps-android

https://github.com/privacyguides/verified-apps/

I think in general trust is established for Play Store apps by downloading the app with the Play Store on a phone with Google Certified Android. Then the app can get the signing key for storage in the database. Then this can be used to verify APKs downloaded outside the play store.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#235

Annoying but this kinda thing happens every 6 months or so. Sometimes Google starts throttling, other times doing some API checks. Every time the Aurora guys figure out a way around it. They're our heroes Even this particular error ("Server busy, try again later"). I've been seeing over the past weeks but then a few days later it worked again. I'm not too worried. It also happens or me right now indeed.

yeah, nothing new really, last update I had on august 26 without issues, tried yesterday, had issues, so today switched couple of accounts until it worked, been using aurorastore for many years

and in the end I don't really care whether my apps won't get updated anyway, only app which will start bitching about being outdated is whatsapp, which can be for now downloaded directly from whatsapp without playstore (I have also telegram as backup which also allows direct APK download) so not too worried even if Aurora was down for couple of months, I don't use any banking/payment apps in my phone for a reason

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#236

Earlier quoted context omitted.

I actually think there's already a lot of us in the 'community' as-is. I personally describe it as 'Valuing Privacy/Freedom over Security'. One pretty clear example of this is how they don't recommend using FireFox Mobile and F-Droid, both of which I use regardless because I'm not willing to put up with worse privacy/usability tradeoffs in the name of (imo 'hyper-')security. I think it's fine the mission of the proje…

They're both security, just security "against" different things. Graphene frequently fails to clearly describe the threat model when calling something "more secure". For example, let's say hypothetically I want to be secure against the threat of Google pushing a targeted update to my phone that runs malicious code. Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG…

But Graphene devs say things like "MicroG is less secure than Google Play Services".

It is. microG runs Google DroidGuard blobs in a privileged process (to pass Play Integrity Basic). Reminder for those who forgot about DroidGuard: it's an obfuscated binary blob delivered to you by Google on each request that uses a special VM with constantly changing registers, etc. to avoid analysis.

On GrapheneOS that crap runs in a sandbox.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#237

Earlier quoted context omitted.

How does one even create a new google account in $current_year without requiring phone verification or worse?

You could suck it up and do the phone number verification, it usually costs around $5 for a phone number. Or you could go through the android phone sign-up process which doesn't require one. Buy a cheap android phone and keep resetting it and making a new account each time. Or you could buy an account on the grey web from someone who already did this. Should be under $2. If you are really into this you could become a…

btw. you can get prepaid physical SIM cards in Czechia for free send by mailbox, you just need some available mailbox wheere you can pick it up, like put Donald Duck sticker on your mailbox and address it to Donald Duck

I used android sign up process to create my other dummy account I use in TV only for smarttube and app updates, that seems like great option if it still works

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#238

GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

Try installing an app that requires Play Store Integrity, say, ProShot by RiseUp Games.

Braindead dev claims this is to limit the "piracy" and bug reports, nevertheless it's either Aurora or APKMirror.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#239

Earlier quoted context omitted.

GrapheneOS is focused on privacy but that must come from a secure baseline. GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.…

[flagged]

>For example they have stated they won't try to spoof SafetyNet because "we don't lie about security features"

They said they don't want to do it because it would stop working in the future when Google move to enforcing hardware-based attestation and it is not sustainable.

Post reply on HN