Play Store blocks AuroraStore, hurting GrapheneOS users
gitlab.com449 points by erikvanoosten 8 hours ago
449 points by erikvanoosten 8 hours ago
GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.
For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.
Although the nice thing about Aurora Store is it allows you to install apps without a google account linked to your device, keeping Google Play Services signed-out.
Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't).
Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play.
That's personally what I used Aurora for, plus as an easy way to export APK files.
> Google Account that isn't tied to anything else.
At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.
I'm under no illusion that google doesn't know I own my multiple accounts. They most certainly do. I usually use the same user agent (with containers) on the same IP, after all.
But my goal is to avoid a stranger gaining access to my google services if they manage to unlock a lost device or steal my TV/streaming box that has no lock at all.
I wish Google supported a permission system per device. For example on most of my android devices all I really want is to be logged into Youtube and the play store. I most certainly do not want those devices to have access to my contacts, emails, calendar, keep, drive, payment, etc. (I don't personally use all of those things, but you might and that's what a random thief would gain access to.)
Yep, something like checkboxes on login:
- ALL: Log me in to all Google Services
- Calendar
- GMail
- YouTube
- ...
Adding more would require to login anew.Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.
They have required unique phone numbers for accounts I've tried lately, or parent's phone numbers. Facebook is worse though, they are quick to ban an account/phone number.
My experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that have them running around in the background or just straight up depend on them.
All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them
> leave their ecosystem
Their tracking is baked into various apps even if you don't have an account with them. Anything with social media integrations can report back to the mothership behind your back.
Google's business model is providing you services that are excellent, while also providing advertisers access to your willing eyeballs when you use those services.
Yes, the advertising targeting is incredibly invasive, but let's not pretend they aren't providing world class Search, Email, Docs, Maps, Video (YT), etc in exchange.
GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS.
For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.
So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.
Yes, F-Droid and its apps are great <3 They add so much security by simply not having a lot of tracking code that can be exploited and tries to hook all over your system. And they have reproducible builds which is something the commercial stores don't even bother with. This is really important for security. I don't understand that GrapheneOS advises against them.
And yeah the iris scans sound like a scare but only 2 years ago there was a constant line of zombies here in the shopping mall giving their eye scans to altman.
The masses really don't care about privacy if you give them a worthless trinket.
I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app. It's one of the worst pieces of software I've used in a while, and I can tolerate a good bit of jank from FOSS apps.
> never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app
You probably "just" need to pull down while on the "Latest" or "Updates" tab, to update your repository (it will show a small banner at the top while it's doing that). It's incremental, so it may take a while if it has been some time since you last did it (and auto-updates are disabled).
The way F-Droid works is that it downloads the whole index and then the catalog, version checks, etc, all runs locally, quite similarly to some package repositories actually.
I am not claiming its intuitive, but I think that part works fine once you understand how it works.
The last time it wouldn't update an app, I could see in the app store and on the website that my app had a new version, but no matter what I did, I could not make it update the app. I don't know what I was doing "wrong", but I think if I couldn't figure it out or make it happen, there's something very wrong with either the app or how it's "supposed" to work. Neither of which is an acceptable user experience for me.
Have you tried Neo Store for accessing F-Droid and other repositories? In particular, I use the IzzyOnDroid F-Droid and Guardian Project repos.
I have not, but honestly, at this point, I just don't really care anymore. I can only try and be rebuffed by a product so many times.
> Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app.
Sounds like an accurate recreation of the Play Store experience to me.
This is not me simping for Google, I would honestly prefer literally anyone else with an acceptable app store experience, but I can honestly say I've never had that experience with the Play Store. If there's an update, it updates. If there's an app, it appears in search. On the rare occasion an app doesn't appear and I go to the Play Store website looking for it, the reason the app didn't show up is because it's listed as incompatible with my device (usually Android version too low or too high).
> a Google Account that isn't tied to anything else.
Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
> > a Google Account that isn't tied to anything else.
> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.
Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.
The trick is, that in the general case, you can not keep this account online indefinitely.
I once worked out a trick to get it going and I was feeling safe because I had setup 2FA and backup codes (see https://masysma.net/37/google_how_to_create_an_account_witho...).
First thing to note: This way of account creation does not seem to work anymore.
Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...
Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).
I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.
I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...
You can create an account with no phone number during Android device setup.
You can also just get a burner phone number for a few bucks.
> You can also just get a burner phone number for a few bucks.
But you have to keep paying the monthly cost, if you loose access to a phone number in your Google account it's game over for any account recovery or "let's verify it's you" it might decide to throw your way.
Accounts created on stock Pixels don’t require phone numbers.
that haven't been true since pixel 4. it just picks your phone in the background.
a burner sim, like a literal criminal, is the only way today.
Even with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission.
That can't be true? <https://grapheneos.org/faq#hardware-identifiers>
As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.
Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.
I don't know however if sandboxed google play is such a privileged app.I couldn't immediately find whether GrapheneOS grants READ_PRIVILEGED_PHONE_STATE to Google Play. It might very well be that the GrapheneOS sandbox spoofs a fake IMEI, and I do hope so.
In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.
https://grapheneos.org/usage#sandboxed-google-play
> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.
It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."
There is an AppStore app, I am not sure if this is the one we are talking about? <https://github.com/GrapheneOS/AppStore/blob/main/app/src/mai...>
That one lists:
ACCESS_NETWORK_STATE
ENFORCE_UPDATE_OWNERSHIP
FOREGROUND_SERVICE
FOREGROUND_SERVICE_SPECIAL_USE
INSTALL_PACKAGES
INTERNET
POST_NOTIFICATIONS
QUERY_ALL_PACKAGES
RECEIVE_BOOT_COMPLETED
REQUEST_DELETE_PACKAGES
REQUEST_INSTALL_PACKAGES
UPDATE_PACKAGES_WITHOUT_USER_ACTION