The first ticket you link is not by someone who seems to work on GrapheneOS, at least there's nothing in their profile to suggest as much. The improvement they suggest is hardening, preventing basically nation state attackers who either compromise or compel a CA to issue a false certificate for Google's servers
The second ticket is about checking if the data that Google sent via TLS has a second signature from Google. It doesn't prove what you claim about ensuring the key is from the developers. This is more useful for places like apkmirror that distribute apps and could include the signature that Google tacked on, for people who trust but cannot use Google; to verify Google's signature without needing to be able to connect to Google. That's not what Aurora does, so it's not relevant to the project. Can be defense-in-depth in case Google's front-ends are compromised but the signing back-end is not, but again, that's less likely than getting struck by lightning and such a powerful attacker could also just compel the developers to make a special update that performs malicious actions on their target
This is the level of misunderstanding that I find very common among GrapheneOS users btw: it all sounds good if you don't know much about it, but when you drill down to what it actually does and consider a specific threat model, it's no reason to recommend Google Play over Aurora for 99% of people's threat models. If you're an oppressed journalist in Iran or whistleblower in the USA, then the cert pinning could help, but most of us are more impacted by everyday tracking than by targeted nation state attacks
> Apps on your phone may be able to determine your locality, and can definitely fingerprint you uniquely, so it is not enough to download an app via Aurora Store.
I'm probably misunderstanding you, but nobody said downloading an app via Aurora changes the contents of the download to become privacy-friendly. Like, downloading a .exe via an open source browser also doesn't change the download compared to if you download it with Google Chrome
You still have to be wary of what you download, deny it internet access if applicable, etc. It's just that you don't have to have google's stuff running in the background all the time, toggling internet access on (letting it upload queued telemetry) anytime you want to download or update an app that is distributed only via google
Aurora at least lets you filter on apps that don't have GMS listed as a dependency, and works with Exodus to show other trackers, making this process a lot easier than via Google Play
> Instead they do suggest Aurora Store as a last resort in special cases where the Play Store prevents you from getting the app nonsensically.
What do you mean by nonsensically? I didn't know they recommend it under any circumstance though, that's cool. Do you happen to have a link for that, or remember where they wrote that?