| ▲ | Play Store blocks AuroraStore, hurting GrapheneOS users(gitlab.com) |
| 198 points by erikvanoosten 2 hours ago | 58 comments |
| |
|
| ▲ | pyrophane an hour ago | parent | next [-] |
| GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else. |
| |
| ▲ | DaSHacka an hour ago | parent | next [-] | | Although the nice thing about Aurora Store is it allows you to install apps without a google account linked to your device, keeping Google Play Services signed-out. Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't). Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play. That's personally what I used Aurora for, plus as an easy way to export APK files. | |
| ▲ | juiceland 36 minutes ago | parent | prev | next [-] | | > Google Account that isn't tied to anything else. At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else. | | |
| ▲ | josefresco 17 minutes ago | parent [-] | | Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate. | | |
| ▲ | Forgeties79 14 minutes ago | parent [-] | | My experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that have them running around in the background or just straight up depend on them. All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them |
|
| |
| ▲ | khriss 4 minutes ago | parent | prev | next [-] | | > you can sign into the Play Store with a Google Account that isn't tied to anything else. The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant. The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past. | |
| ▲ | joekrill an hour ago | parent | prev | next [-] | | > a Google Account that isn't tied to anything else. Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number. | | |
| ▲ | armadyl an hour ago | parent [-] | | Accounts created on stock Pixels don’t require phone numbers. | | |
| ▲ | iririririr 43 minutes ago | parent [-] | | that haven't been true since pixel 4. it just picks your phone in the background. a burner sim, like a literal criminal, is the only way today. | | |
| ▲ | asnelt 28 minutes ago | parent | next [-] | | Even with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission. | | |
| ▲ | exceptione 19 minutes ago | parent [-] | | That can't be true? <https://grapheneos.org/faq#hardware-identifiers> As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.
Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.
I don't know however if sandboxed google play is such a privileged app. | | |
| ▲ | asnelt 5 minutes ago | parent [-] | | I couldn't immediately find whether GrapheneOS grants READ_PRIVILEGED_PHONE_STATE to Google Play. It might very well be that the GrapheneOS sandbox spoofs a fake IMEI, and I do hope so. In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread. |
|
| |
| ▲ | goodmythical 39 minutes ago | parent | prev [-] | | assuming the number you get hasn't previously been assigned to a google account |
|
|
| |
| ▲ | hadlock 27 minutes ago | parent | prev | next [-] | | It seems wise to have at least one alternative mobile phone app store. Even if it isn't very good. If the government can tell Google to do trivial things like, for example, change the name of bodies (plural now) of water, it can turn off your app updates, trapping you on insecure versions indefinitely. This probably matters more if you live outside of the US, but if I had a plan B for an app store on my phone, I would certainly at least evaluate it. | |
| ▲ | dmantis 11 minutes ago | parent | prev | next [-] | | Sometimes you just can't. For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora. The check seems to be purely store-based and never enforced later. | |
| ▲ | amaccuish 35 minutes ago | parent | prev | next [-] | | GrapheneOS is focused on absolute security. For those of us on more privacy-oriented ROMs with MicroG, we're very happy with Aurora. | | |
| ▲ | Cider9986 15 minutes ago | parent [-] | | GrapheneOS is focused on privacy but that must come from a secure baseline. GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy. |
| |
| ▲ | SahAssar an hour ago | parent | prev | next [-] | | Having to have a account is absolutely a downgrade and privacy-hostile. | |
| ▲ | talon8635 an hour ago | parent | prev | next [-] | | Doesn’t Google make it very hard to create an account tied to nothing (no phone or alt email)? | | |
| ▲ | armadyl an hour ago | parent | next [-] | | If you create it on a stock Pixel device the phone requirement gets dropped. | | |
| ▲ | talon8635 an hour ago | parent [-] | | It’s undoubtedly tied to the phone with is tied to the owner | | |
| ▲ | gruez 42 minutes ago | parent | next [-] | | People report that it works even on grapheneos with sandboxed google play. My guess there's some fingerprinting going on, not necessarily that they're tying the account to some account id. | | | |
| ▲ | armadyl 44 minutes ago | parent | prev [-] | | Well yeah. But if you care about anonymity on that level there are ways around that (i.e. buying in cash and creating the account using public WiFi). |
|
| |
| ▲ | kotaKat 35 minutes ago | parent | prev [-] | | It's the SomethingAwful model: go to the store and find the cheapest Android phone from some prepaid company for :tenbux: then use it to set up your Google account during out-of-box-setup while on the store's free public WiFi (since Google OOBE allows free account creation without a number or existing email), then toss the phone in a drawer afterwards. "Hope ya got ten bucks!" (I got a random 5G Moto phone for ~$10 on clearance and it was an absolute shitter of a phone full of garbage packed in malware, but after cleaning and debloating as much as I can, it's at least a nifty toy to poke at Termux or something.) |
| |
| ▲ | halyconWays a minute ago | parent | prev [-] | | "For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else." lol. lamo, even. |
|
|
| ▲ | troyvit an hour ago | parent | prev | next [-] |
| I use Aurora on GOS. I get that they say sandboxed Play is more secure than Aurora, but I prefer it for its lack of toxicity and absence of shitty dark patterns. I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community. |
| |
| ▲ | DaSHacka 42 minutes ago | parent | next [-] | | I actually think there's already a lot of us in the 'community' as-is. I personally describe it as 'Valuing Privacy/Freedom over Security'. One pretty clear example of this is how they don't recommend using FireFox Mobile and F-Droid, both of which I use regardless because I'm not willing to put up with worse privacy/usability tradeoffs in the name of (imo 'hyper-')security. I think it's fine the mission of the project isn't directly aligned with some of us, though I can tell we often get on the core contributor's nerves lol | | |
| ▲ | titularcomment 9 minutes ago | parent [-] | | FYI, there are ungoogled chromium builds for Android. Firefox Mobile really is a lackluster browser unfortunately both from a usability and security standpoint (e.g. IonStack worked on Fennec) |
| |
| ▲ | flexagoon 13 minutes ago | parent | prev [-] | | > I hope it's not too annoying for their community There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero. The core dev team is obviously a bit more security absolutist, but even they usually dont mind |
|
|
| ▲ | skeledrew an hour ago | parent | prev | next [-] |
| I've been stuck with unupdated apps because Aurora hasn't been working for me for a while. A few of them have been nagging me to update. I have everything Google disabled or removed, and no I won't reenable any of it. Also I use anon strictly on Aurora, and no I won't login with my Google account; haven't logged in on a phone for over 8 years now and I have no intention of breaking the streak. |
|
| ▲ | kjander79 an hour ago | parent | prev | next [-] |
| I feel the title editorializes a bit too much. The thread only confirms the bug, not a specific cause yet. As sibling comments indicate, the effect on GrapheneOS users is undetermined. |
| |
| ▲ | titularcomment 18 minutes ago | parent | next [-] | | This is standart, and happens constantly with Invidious (youtube frontend). This happened before on AuroraOSS too. They probably just flagged the accounts and no API change or A/B testing an API change. | |
| ▲ | aniviacat 35 minutes ago | parent | prev [-] | | For me, the issue also only occurs sometimes. Usually I can download apps like normal. |
|
|
| ▲ | lenerdenator 2 minutes ago | parent | prev | next [-] |
| Remember when people kept justifying Android over Windows Phone/Maemo/WebOS/BlackBerry/FirefoxOS on the grounds that it was free and open source software, infinitely customizable, and that Google was a good-faith partner who wanted openness in the mobile market? Good times, good times. |
|
| ▲ | denzen an hour ago | parent | prev | next [-] |
| Using lineageos on an old samsung without any google services, I guess this would impact many "degoogled" users as well |
|
| ▲ | CodesInChaos an hour ago | parent | prev | next [-] |
| For me anonymous use of Aurora never really worked, and with a google account it still works. |
|
| ▲ | ChocolateGod 44 minutes ago | parent | prev | next [-] |
| So an app that uses an unofficial API broke when that API changed? Not news nor "blocking". |
|
| ▲ | _leom 36 minutes ago | parent | prev | next [-] |
| This happened to me but then got fixed the day later |
|
| ▲ | kotaKat an hour ago | parent | prev | next [-] |
| Didn't Epic get some kind of magic injunction saying that Google had to allow open access to the entire Play Store catalogue or something? |
|
| ▲ | ranger_danger 43 minutes ago | parent | prev | next [-] |
| > Aurora uses burner account for anonymous login. looks like their account pool is flagged This seems like it was destined to get banned somehow... and I don't think it means that the store itself is blocked, just the pool of accounts they (ab)use. |
|
| ▲ | ChrisArchitect an hour ago | parent | prev | next [-] |
| Title is: Aurora Store returns a “&$Server busy, please try again later.” error |
|
| ▲ | shevy-java 31 minutes ago | parent | prev | next [-] |
| Google becomes more and more evil by the second now. |
| |
| ▲ | hluska a minute ago | parent [-] | | That’s quite the conclusion to derive from a Gitlab issue. Do you mind sharing your thought process or was that just a knee jerk reaction without any reasoning behind it? |
|
|
| ▲ | v1z an hour ago | parent | prev | next [-] |
| Google needs to fuck off |
|
| ▲ | erikvanoosten 2 hours ago | parent | prev [-] |
| Android distributions that recommend AuroraStore (such as Graphene OS and Sailfish OS) are now mostly blocked by Google Play Store. |
| |
| ▲ | dxjxjdjsssb an hour ago | parent | next [-] | | Play store works just fine on GrapheneOS. All of play services run in a sandbox. You can install the Play store from the GrapheneOS App Store. In fact I'm pretty sure the GrapheneOS folks advise against Aurora Store, etc. | | |
| ▲ | himata4113 an hour ago | parent | next [-] | | The entire point is so you don't have to have a google account. Aurora actually works fine if you do sign in. This is just blocking anon downloads. | |
| ▲ | imzadi an hour ago | parent | prev [-] | | Yeah, was confused. I'm on GrapheneOS and don't even know what Aurora is. | | |
| |
| ▲ | bushwart an hour ago | parent | prev | next [-] | | I wasn't aware GOS recommended AuroraStore. | | | |
| ▲ | JoshStrobl an hour ago | parent | prev | next [-] | | Sailfish OS user on Jolla Phone 2: Aurora is working fine here. P.S. Sailfish OS is NOT an Android distribution. It is a proper Linux system and they have their own custom Android runtime (AppSupport) as a layer on top for running Android apps. This runtime _is_ Android under the hood, but is separate from Sailfish itself (has its own native app ecosystem). | |
| ▲ | Cider9986 11 minutes ago | parent | prev | next [-] | | Play store works fine on GrapheneOS. | |
| ▲ | iAMkenough an hour ago | parent | prev | next [-] | | AuroraStore uses a pool of burner Google Play Store accounts to facilitate anonymous downloads. This is what happens when those burner accounts get flagged. | | |
| ▲ | ErenayDev 30 minutes ago | parent | next [-] | | I'm using my Proton account in my phone and in play store. now i tried adding my proton account in AuroraStore, and it worked flawlessly. so my question: why AuroraStore uses google accounts instead of another providers? | |
| ▲ | ranger_danger 42 minutes ago | parent | prev [-] | | How does one even create a new google account in $current_year without requiring phone verification or worse? |
| |
| ▲ | savwolf an hour ago | parent | prev [-] | | GOS recommends play store |
|