Live data from Hacker News

Play Store blocks AuroraStore, hurting GrapheneOS users

gitlab.com

291–300 of 312 posts

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#291
post #14

I use Aurora on GOS. I get that they say sandboxed Play is more secure than Aurora, but I prefer it for its lack of toxicity and absence of shitty dark patterns. I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community.

I actually think there's already a lot of us in the 'community' as-is. I personally describe it as 'Valuing Privacy/Freedom over Security'. One pretty clear example of this is how they don't recommend using FireFox Mobile and F-Droid, both of which I use regardless because I'm not willing to put up with worse privacy/usability tradeoffs in the name of (imo 'hyper-')security. I think it's fine the mission of the proje…

GrapheneOS is a privacy project and solely works on security to protect privacy. The reason for our recommendations related to those areas is privacy.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#292

[flagged]

We don't recommend using the Play Store as a first choice for obtaining apps. Aurora Store is another way to use the Play Store as a source of apps. If someone is using sandboxed Google Play in a profile, it makes sense to use the sandboxed Play Store to install apps. Aurora Store is mainly useful as a workaround for store listings enforcing Play Integrity and we do direct people to it for that.

Aurora Store still works fine. It doesn't require the default-enabled account sharing feature. It's not Aurora Store which is getting blocked but rather account sharing. Account sharing is against Google's terms of use and is now being detected more aggressively. We've warned about this for years but it took longer than expect for them to ramp up banning it. It's likely going to continue getting stricter.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#294

Please add to the title "... and all other degoogled devices", which are many orders of magnitude more than GOS: almost all Huawei devices (degoogled out of the box), custom Roms, rooted and all non-logged in. I am a non-GOS hurt victim.

The title is incorrect as a whole. Aurora Store wasn't blocked and GrapheneOS has no specific dependence on it for installing Play Store apps. Shared accounts are being banned and Aurora Store uses those by default but it still works. Sandboxed Play Store and Aurora Store are both still available as options for installing Play Store apps on GrapheneOS.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#295

Earlier quoted context omitted.

> That's also incorrect, because the gmscompat app is just a helper app. Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services. > Those permissions are handled by the OS under the play services app Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unpri…

Google Mobile Services apps installed on GrapheneOS including Play services run as regular sandboxed apps. They receive absolutely no special access compared to other apps by installing and running them. There are the standard permission toggles for granting those but none of those are required for typical usage to provide compatibility with many apps from the Play Store depending on their services. There are additio…

Thank you for clarifying this.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#296
post #102

Earlier quoted context omitted.

GrapheneOS is focused on privacy but that must come from a secure baseline. GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.…

> Accrescent is the end goal for a secure and private app store but it's still in alpha Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.

Accrescent has been quiet for a while, but had claimed in the past they would open the store up for new submissions again soon, it will perhaps happen by the end of the year. Its self-imposed requirements for this are to provide a better developer experience and more common app store features developers (should) expect. They recently announced they will be posting more about the progress made towards such goal, after the big announcements and releases of some months ago.

I'm more worried about the lack of a police to take apps down when it is very clear they should not be there. This is a present problem, presently solvable and that is not acknowledged despite the fact it harms the user.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#297
post #263

Earlier quoted context omitted.

> Software freedom is about being able to use the software the way you want You can't use the software in the way you want if it uses hardware backed cryptography to block you from doing so. > you get access to the sources, you modify them, build them and run them This is completely infeasible for 99% of the population. If you technically have a freedom but have no practical way to exercise it, it may as well not exi…

> You can't use the software in the way you want if it uses hardware backed cryptography to block you from doing so. You can use the software the way you want, from sources . If I run an open source server at home, it does not give you the right to enter my house and come reboot my server, does it? > This is completely infeasible for 99% of the population Sure, it isn't. Still that's what software freedom is. > If yo…

> Well GrapheneOS would still be free software?!?!? It's the software from those companies that wouldn't be.

I think I have a broader definition of software freedom than you do. In this hypothetical scenario, GrapheneOS itself may technically be "free software" in the sense that the source code is open, but it would still be cooperating in a intentional scheme to prevent you, the user, from modifying it to work the way you want. Same deal if they started selling locked hardware with their signing key hard coded so you can't install a fork. You would legally have the ability to fork the software, but technical measures would be preventing you from running it.

Granted, they're not doing that, but it's one short step away. That's why I say it's borderline anti-freedom, not that it actually is.

I don't think it makes a difference whether the means employed to make a piece of software non-free are legal (copyright law) or technical (DRM, remote attestation, hardware locks). It's still restricting your freedom.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#298
post #285

Earlier quoted context omitted.

Thinking about possible ways they could retain the same security properties without impinging software freedom... maybe there's a way they could make the root of trust default to a signing key embedded in the device's own secure hardware? Then by default that key could sign Graphene's own signing certificate to allow them to push updates, but the user would retain the ability to revoke that signature and sign someone…

I am confused, why were your messages flagged? I disagreed with you, but I didn't see a reason to flag them? Also I don't know how to flag a message, but that's another topic.

It's not flagged now. But yes, way too many people use flags as an "I disagree" button these days. I feel like that used to be very rare (even down-votes aren't supposed to be used that way) and is becoming more common, though maybe it's always been this way and I just hadn't been on HN long enough to notice the pattern until now.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#299
post #240

Earlier quoted context omitted.

As far as I'm aware, they do not get the security patches and early bulletin access from Google. They get that from an undisclosed OEM.

The OEM is Motorola. The partnership was announced earlier this year. You are correct about them not getting early access from Google. There was a post within the last few months saying that Google no longer releases a lot of the code via git, but instead requires submitting a form and downloading the code via Google Drive. Google are actively trying to make third-party development difficult.

We are told the OEM in question is not Motorola, and it's likely some benefits of the Mototola partnership aren't yet in effect due to silly bureaucracy. Not sure there is any reason to lie about this.

Embargoed ASB patches started being used in release 2025092500, but I can't find now the message where a Motorola employee (confirmed by a community moderator, spring-onion, in a Side of Burritos interview) first reached out publicly on the GrapheneOS Discord guild about how to obtain further technical guidance than the requirements list in the website which claims to be non-exhaustive, in order to confirm such message's date. Still, GrapheneOS claims (after the partnership announcement March this year) that ASB patches are provided by (effectively) a distinct undisclosed OEM, really meaning an employee is leaking them. Maybe even the person didn't disclose the OEM they work for but they must be associated to one in order to have access to this material.

Re: Play Store blocks AuroraStore, hurting GrapheneOS users

#300

Earlier quoted context omitted.

[flagged]

GOS's intended audience are those who are in danger of being hacked or persecuted, not privacy conscious users trying to escape surveillance. Google, for all their faults, is pretty unlikely to hack your phone and reveal your secrets.

No, it's both, which is why it comes with zero connections to Google by default unlike all other alternative mobile operating systems listed here: https://eylenburg.github.io/android_comparison.htm

See the "degoogling" section.

There's many privacy features that work to allow users to use anti-privacy apps like WhatsApp with more privacy. Contact scopes, storage scopes, sensors permission, network permission, VPN leaks fixed and enhanced secondary profiles.

Plenty of less scrupulous surveillance companies like Facebook take advantage of security flaws for their surveillance so it's important to start from a secure baseline to guard against this threat.

Post reply on HN