Live data from Hacker News

Play Store blocks AuroraStore, hurting GrapheneOS users

gitlab.com

261–270 of 312 posts

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#261
post #229
post #144

Earlier quoted context omitted.

[flagged]

>Citation needed. grapheneos themselves sure doesn't understand this The GrapheneOS team understand full well that in cases where the Play Store does not allow installing an app on your device due to device or georestrictive rules you may have no choice. I have seen them mention this and acknowledge it first hand. What they do not want is for people to become satisfied with subpar solutions instead of striving for ba…

[dead]

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#262
post #19

Using lineageos on an old samsung without any google services, I guess this would impact many "degoogled" users as well

Running LOS on some kind of oneplus. Aurora hasn't worked right for the most part for a year due to device attestation shit. I'm meh on it. Not being able to install the shit from play store isn't such a bad thing. It is lame as hell that Google is doing their damndest to make apple look user friendly.

Unfortunately, it is not uncommon for providers of apps you may want/need only put them on the Google store. Example: ProtonVPN.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#263
post #230

Earlier quoted context omitted.

> I think it's fair to say that that's at least borderline anti software freedom Then you don't understand software freedom either. Software freedom doesn't mean AT ALL that random projects on the Internet MUST implement the features YOU want. Never, not at all, it's not borderline, it's not up to debate. Software freedom is about being able to use the software the way you want, as in "you get access to the sources,…

> Software freedom is about being able to use the software the way you want You can't use the software in the way you want if it uses hardware backed cryptography to block you from doing so. > you get access to the sources, you modify them, build them and run them This is completely infeasible for 99% of the population. If you technically have a freedom but have no practical way to exercise it, it may as well not exi…

> You can't use the software in the way you want if it uses hardware backed cryptography to block you from doing so.

You can use the software the way you want, from sources. If I run an open source server at home, it does not give you the right to enter my house and come reboot my server, does it?

> This is completely infeasible for 99% of the population

Sure, it isn't. Still that's what software freedom is.

> If you technically have a freedom but have no practical way to exercise it, it may as well not exist.

I disagree, I'm very happy that free software exists.

> I think it's debatable at that point whether you'd still be running Graphene

It's not: you're running a fork at that point. That's precisely how free software works.

> And if exercising your freedom requires you to stop running Graphene and start running something else, is it really fair to say Graphene itself supports that freedom?

Yes! Again that's precisely what software freedom is about! When you run GrapheneOS, you have the freedom to fork it and run it however you want. When you run Windows or macOS, you don't.

> If you're still not convinced, consider what would happen if companies started using remote attestation to verify you're running the official GrapheneOS build and block forks...

Well GrapheneOS would still be free software?!?!? It's the software from those companies that wouldn't be. I hate remote attestation as much as the next person, and typically banks absolutely suck because they love doing that kind of bullshit. But because banks suck does not mean that GrapheneOS is not free software?

Note that I am not trying to contradict you for the sake of it. I believe too few people understand how open source works, and that is a pity because it is important to understand it. When I open source some code I wrote, I make it available for people to do whatever they want with the code. I don't give them ANY RIGHT on the products I sell (even if those products are running said open source software) or on the feature I implement.

Too many people believe that because it's open source, they have a right to tell the authors what features they should implement. This is wrong. You want root access on your GrapheneOS? Go fork it. I don't want it, I am happy with GrapheneOS. If GrapheneOS gave me root access, I would fork it to remove it. And that would still be free software!

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#264

Earlier quoted context omitted.

The whole point of avoiding the verification in my case is for privacy reasons... I don't want google or anyone else tracking what I do through the use of an account. > Or you could go through the android phone sign-up process which doesn't require one This is worse IMO because now the number is associated with that device forever. And unless I'm willing to risk my account to compromise from a future owner of the sam…

Bad news - Google doesn't need an account to track your app downloadsm Perhaps you'd be more interested in creating a website that downloads all the apps from the play store using burner accounts and makes them easily anonymously accessible.

GrapheneOS is not sending app downloads to Google that happen outside of Google's apps, which I don't use. And there are other ways to download APKs from the Play Store; EFF even makes their own tool for it, and there are third-party archive sites and alternative non-Google app stores as well.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#265

Earlier quoted context omitted.

GrapheneOS is focused on privacy but that must come from a secure baseline. GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.…

[flagged]

No, GrapheneOS is a privacy project. The primary focus is providing usable privacy. GrapheneOS solely works on security to protect privacy.

We never said that about the SafetyNet Attestation API and that's a dead service. We've explained that we cannot provide a long term for the Play Integrity device integrity level because they can easily detect spoofing and very easily block it. The device integrity level is also gradually phasing in a requirement for hardware attestation. Apps already use the strong integrity level to enforce it.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#266
post #209

Earlier quoted context omitted.

[flagged]

[flagged]

We don't receive early access to Android releases or security bulletins from Google.

SafetyNet Attestation API was replaced by the Play Integrity API and has been shut down.

Spoofing the checks needed to pass the Play Integrity device integrity level would only be a temporary workaround. It would stop working and we'd have to keep expanding it. It's easy for them to detect spoofing and ban it. They choose to focus on it happening at scale rather than individuals doing it with rare modifications. GrapheneOS is too widely used to get away with it.

Spoofing the device integrity level will become far more impractical once it requires hardware attestation. Remote key provisioning will also make it a lot more painful to use leaked keys for bypassing root-of-trust-based hardware attestation.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#267

Earlier quoted context omitted.

> Google Account that isn't tied to anything else. At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.

[flagged]

No, GrapheneOS is a privacy project. The primary focus is providing usable privacy. GrapheneOS solely works on security to protect privacy.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#268

[flagged]

GrapheneOS doesn't recommend Aurora Store for apps obtainable via sandboxed Play Store. We mention it as a workaround for apps setting their Play Store listings as requiring the Play Integrity device and strong integrity levels.

Aurora Store works without the default enabled account sharing feature. The account sharing feature is disallowed by Google's terms of use banning account sharing. We've warned about this very likely being banned for years and have recommended people make a purpose-specific Google account for this instead. Google often requires phone number verification for an account for anti-spam but many VoIP services work for it.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#269
post #9

[flagged]

GOS recommends play store

For people using sandboxed Google Play, we strongly recommend using the sandboxed Play Store as the primary way of obtaining apps from the Play Store. We don't recommend using the Play Store as a first choice for obtaining apps.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#270

[flagged]

Aurora Store still works fine without the default enabled account sharing feature. Google hasn't blocked using Aurora Store as an alternate Play Store client but rather account sharing. By default, Aurora Store violates the Play Store terms of use by sharing accounts. That's what's being detected and blocked.

Aurora Store isn't one of the main recommendations from GrapheneOS for obtaining apps. It's mainly useful as a workaround for installing Play Store apps requiring the device or strong integrity level for their Play Store listing. It would be better to find another way to deal with this.

Post reply on HN