Live data from Hacker News

Play Store blocks AuroraStore, hurting GrapheneOS users

gitlab.com

301–310 of 312 posts

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#301
post #285

Earlier quoted context omitted.

I am confused, why were your messages flagged? I disagreed with you, but I didn't see a reason to flag them? Also I don't know how to flag a message, but that's another topic.

It's not flagged now. But yes, way too many people use flags as an "I disagree" button these days. I feel like that used to be very rare (even down-votes aren't supposed to be used that way) and is becoming more common, though maybe it's always been this way and I just hadn't been on HN long enough to notice the pattern until now.

Yeah people tend to downvote for "I disagree", which is... not how I believe it should be used.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#302
post #263

Earlier quoted context omitted.

> You can't use the software in the way you want if it uses hardware backed cryptography to block you from doing so. You can use the software the way you want, from sources . If I run an open source server at home, it does not give you the right to enter my house and come reboot my server, does it? > This is completely infeasible for 99% of the population Sure, it isn't. Still that's what software freedom is. > If yo…

> Well GrapheneOS would still be free software?!?!? It's the software from those companies that wouldn't be. I think I have a broader definition of software freedom than you do. In this hypothetical scenario, GrapheneOS itself may technically be "free software" in the sense that the source code is open, but it would still be cooperating in a intentional scheme to prevent you, the user, from modifying it to work the w…

I really want to insist on this: when someone develops software, you don't get to choose what they develop. That's just life.

If they make their software open source, you get to fork it (sometimes contribute to it) and this is already very generous. But that's all.

I say that as an open source author and maintainer, and my experience is that the vast majority of developers do NOT understand that. I have been criticised, insulted, sometimes bullied by people who wanted me to implement whatever they wanted ON TOP of providing my work for free.

You can have your own definition of "free software" that means "the developers have to agree with my personal taste", and say that "Linux is borderline not free software because I want them to officially support Zig and they don't", but it doesn't bring much. What makes Linux free software is that you can fork it.

I guess I don't understand the need to have a definition that only serves for complaining about a free project not implementing a feature you want. I get it, you wish GrapheneOS gave you root access. But it is not the choice of the people who do the work and make it available for free. But because it is free software, you can fork it and modify it yourself, and this is great.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#303

Earlier quoted context omitted.

[flagged]

GrapheneOS does not include any support for using a Google account and does not require using Google apps/services. There are many inaccurate statements here about what we supposedly recommend. We do not specifically recommend using the Play Store as a source of apps in the first place. We recommend using the sandboxed Play Store for obtaining apps from the Play Store. GrapheneOS uses Pixels because those are still t…

[flagged]

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#304
post #302

Earlier quoted context omitted.

> Well GrapheneOS would still be free software?!?!? It's the software from those companies that wouldn't be. I think I have a broader definition of software freedom than you do. In this hypothetical scenario, GrapheneOS itself may technically be "free software" in the sense that the source code is open, but it would still be cooperating in a intentional scheme to prevent you, the user, from modifying it to work the w…

I really want to insist on this: when someone develops software, you don't get to choose what they develop. That's just life. If they make their software open source, you get to fork it (sometimes contribute to it) and this is already very generous. But that's all. I say that as an open source author and maintainer, and my experience is that the vast majority of developers do NOT understand that. I have been criticis…

For what it's worth this isn't just my "personal taste". I think Richard Stallman and the Free Software Foundation, at least, would agree with my definition[1]:

> Freedom 1 includes the freedom to use your changed version in place of the original. If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known as “tivoization” or “lockdown,” or (in its practitioners' perverse terminology) as “secure boot”—freedom 1 becomes an empty pretense rather than a practical reality. These binaries are not free software even if the source code they are compiled from is free.

[1]: https://www.gnu.org/philosophy/free-sw.html#make-changes:~:t...

I didn't say anything about what GrapheneOS devs must do. They don't have to do anything. I just think that some of what they are doing comes close to impinging on software freedom in the same way proprietary software does regularly (though again, Graphene doesn't quite cross that line, in my opinion).

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#305
post #302

Earlier quoted context omitted.

I really want to insist on this: when someone develops software, you don't get to choose what they develop. That's just life. If they make their software open source, you get to fork it (sometimes contribute to it) and this is already very generous. But that's all. I say that as an open source author and maintainer, and my experience is that the vast majority of developers do NOT understand that. I have been criticis…

For what it's worth this isn't just my "personal taste". I think Richard Stallman and the Free Software Foundation, at least, would agree with my definition[1]: > Freedom 1 includes the freedom to use your changed version in place of the original. If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known as “tivoization” or “lockdown,” or (in it…

You misunderstand what Stallman says. The quote agrees with my definition.

You can do all that with GrapheneOS today.

What you are asking for is root access on the GrapheneOS official builds. Where does Stallman say you should get it?

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#306
post #305

Earlier quoted context omitted.

For what it's worth this isn't just my "personal taste". I think Richard Stallman and the Free Software Foundation, at least, would agree with my definition[1]: > Freedom 1 includes the freedom to use your changed version in place of the original. If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known as “tivoization” or “lockdown,” or (in it…

You misunderstand what Stallman says. The quote agrees with my definition. You can do all that with GrapheneOS today. What you are asking for is root access on the GrapheneOS official builds. Where does Stallman say you should get it?

I'm not asking for anything, I'm telling you what they are doing, and what they are doing is going right up to (but not quite crossing) the line of blocking you from modifying the software on your phone.

To re-iterate:

> If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known [...] in its practitioners' perverse terminology as “secure boot”—freedom 1 becomes an empty pretense

GrapheneOS literally implements secure boot, using a key you do not control. So if you install GrapheneOS, the Graphene devs have the ability to push updates to the code running on your phone but you yourself do not unless you completely uninstall GrapheneOS and wipe all data on the phone.

The only thing preventing this from being actually anti-freedom rather than merely borderline anti-freedom is that if you choose to completely un-install Graphene and wipe your phone there's currently nothing that will prevent you from installing another OS built with a different signing key (aside from the inconvenience and technical difficulty of doing so). If there were, then this would be a textbook example of what the FSF explicitly calls "not free software" in that quote.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#307
post #305

Earlier quoted context omitted.

You misunderstand what Stallman says. The quote agrees with my definition. You can do all that with GrapheneOS today. What you are asking for is root access on the GrapheneOS official builds. Where does Stallman say you should get it?

I'm not asking for anything, I'm telling you what they are doing, and what they are doing is going right up to (but not quite crossing) the line of blocking you from modifying the software on your phone. To re-iterate: > If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known [...] in its practitioners' perverse terminology as “secure boot”—fr…

Again you don't understand Stallman's quote. Let me try:

> If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known as “tivoization” or “lockdown,” or (in its practitioners' perverse terminology) as “secure boot”—freedom 1 becomes an empty pretense

Tivoisation or lockdown or abusively calling it "secure boot" is, according to Stallman, "non free". GrapheneOS does not do that. GrapheneOS does not even own the hardware that could do tivoisation. GrapheneOS is the fork of the original project that has been updated and installed on the original device. That means that not only GrapheneOS is free, but AOSP as well!

> is that if you choose to completely un-install Graphene and wipe your phone there's currently nothing that will prevent you from installing another OS built with a different signing key

And that's exactly what Stallman calls "free". If it prevents you from doing precisely that, it's not free. But it doesn't, so it's free.

Secure boot is a security feature. One that I want. One that makes GrapheneOS more secure than, say, a Linux on mobile (or all the other Android flavours that break secure boot, like it was for /e/OS on my FairPhone 3). The whole point of GrapheneOS is that it is secure, and therefore it is designed around that. Thanks to secure boot, if an app manages to get root access and modify the system, it will be detect on the next boot, and therefore it won't persist. This is a desirable feature.

You apparently don't want that, it's your choice. You can use LineageOS, which allows it, or you can fork GrapheneOS and modify that part.

This is all free, this is all how it's supposed to work, this is all desirable. GrapheneOS is free to make the product they want, and that product doesn't allow you to have admin access.

You seem to misunderstand "owning your device". It does not mean "the software allows you to do everything you want", it means "you can install whatever you want on it". If you install something that does not give you root access (i.e. GrapheneOS), it is your choice.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#308
post #229
post #144

Earlier quoted context omitted.

[flagged]

>Citation needed. grapheneos themselves sure doesn't understand this The GrapheneOS team understand full well that in cases where the Play Store does not allow installing an app on your device due to device or georestrictive rules you may have no choice. I have seen them mention this and acknowledge it first hand. What they do not want is for people to become satisfied with subpar solutions instead of striving for ba…

> What they do not want is for people to become satisfied with subpar solutions instead of striving for bare minimum privacy/security standards. They want a Play Store alternative front end to at least be able to guarantee you are receiving the right app you want

Aurora is a lot less invasive while achieving that same goal, but they recommend installing Googleware instead. Wouldn't the open source front-end be the "bare minimum" standard to strive for, with all the added tracking when installing GMS falling below that standard?

> It was the best way for them to provide compatibility without destroying the privacy of their platform

Again mixing up threat models and equating it to privacy. It may not compromise the technical security (as GrapheneOS goes to incredible lengths to point out while implying that this covers everything), in that it doesn't allow Google to access data on the device that Android's security model says they shouldn't have, but Android's security model isn't my threat model. My threat model, and many other people's, includes Google tracking me. If nothing else, the servers can always see which IP addresses I pop up on together with other people and build a social graph if they wish (or if they're ordered to)

By just grabbing the apk files from their servers whenever I open aurora.apk, that issue can be almost entirely avoided, for example. There's the matter of microG but just to show that there are easy wins to be made that work for a lot of apps already (that don't depend on the rest of the framework) that GrapheneOS vehemently opposes 'for security'

It's not strange that they offer a way to install GMS in a secure manner, it's strange that they don't recommend open alternatives where possible

And you're surely aware of the obvious bias of that link you shared. It's like those tables on vendor websites that show their product as the only one that does virtually everything to perfection with everyone else far behind, by measuring and including only the metrics they focus on. Whoever made that takes GrapheneOS' statements at face value and assumes it must be great. And that's assuming that the sheer number of checkmarks is evidence of anything. Depending on what your threat model is, each one can outweigh all others

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#309
post #307

Earlier quoted context omitted.

I'm not asking for anything, I'm telling you what they are doing, and what they are doing is going right up to (but not quite crossing) the line of blocking you from modifying the software on your phone. To re-iterate: > If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known [...] in its practitioners' perverse terminology as “secure boot”—fr…

Again you don't understand Stallman's quote. Let me try: > If the program is delivered in a product designed to run someone else's modified versions but refuse to run yours—a practice known as “tivoization” or “lockdown,” or (in its practitioners' perverse terminology) as “secure boot”—freedom 1 becomes an empty pretense Tivoisation or lockdown or abusively calling it "secure boot" is, according to Stallman, "non fre…

I said it's borderline not-free, not actually not-free so I don't know why you just wrote 7 paragraphs arguing against something I didn't say and have explicitly and repeatedly disclaimed.

Yes, GrapheneOS is free, but it has implemented features that are designed to make it harder to exercise that freedom, namely secure boot which puts it one short step (of baking their key in hardware) away from being exactly what that paragraph describes as not free.

(And I think you are the one misunderstanding the FSF's quote. They're mocking "secure boot" as perverse terminology for what the FSF calls "tivoization" or "lockdown". They're saying those things are one in the same. I personally wouldn't go that far, as I agree with you the software is still free as long as the key used for secure boot is not baked in to the hardware, and I think the security benefits of secure boot are real and not perverse. But the FSF itself is arguing against the whole idea, at least in this article.)

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#310
post #99

Earlier quoted context omitted.

that haven't been true since pixel 4. it just picks your phone in the background. a burner sim, like a literal criminal, is the only way today.

Its possible to set up a phone with a google account without even a sim card in it and use it as a wifi only device, so Im pretty sure what your saying is wrong.

you will be asked for a phone number then.
Post reply on HN