For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.
Play Store blocks AuroraStore, hurting GrapheneOS users (gitlab.com)
pyrophane 13 hours ago
DaSHacka 13 hours ago
Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't).
Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play.
That's personally what I used Aurora for, plus as an easy way to export APK files.
SahAssar 13 hours ago
joekrill 12 hours ago
Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
armadyl 12 hours ago
iririririr 12 hours ago
a burner sim, like a literal criminal, is the only way today.
goodmythical 12 hours ago
drxzcl 11 hours ago
edoceo 10 hours ago
asnelt 12 hours ago
exceptione 12 hours ago
As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.
Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.
I don't know however if sandboxed google play is such a privileged app.asnelt 12 hours ago
In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.
nickspacek 12 hours ago
> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.
It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."
exceptione 11 hours ago
That one lists:
ACCESS_NETWORK_STATE
ENFORCE_UPDATE_OWNERSHIP
FOREGROUND_SERVICE
FOREGROUND_SERVICE_SPECIAL_USE
INSTALL_PACKAGES
INTERNET
POST_NOTIFICATIONS
QUERY_ALL_PACKAGES
RECEIVE_BOOT_COMPLETED
REQUEST_DELETE_PACKAGES
REQUEST_INSTALL_PACKAGES
UPDATE_PACKAGES_WITHOUT_USER_ACTIONgruez 11 hours ago
exceptione 10 hours ago
There is no READ_PRIVILEGED_PHONE_STATE mentioned there.
gruez 10 hours ago
exceptione 9 hours ago
> That's also incorrect, because the gmscompat app is just a helper app.
Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services. > Those permissions are handled by the OS under the play services app
Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unprivileged app, and so any additional permission it would want would have to be consented by the user and should be visible to the user. If not, then GOS wording would be quite a bit unfortunate at least.EDIT: "GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims." [1] This seems to indicate that the permissions requested by Play Services are being honored with the shims from the helper app. That would alleviate the permission problem.
1. https://github.com/GrapheneOS/platform_packages_apps_GmsComp...
mindslight 11 hours ago
exceptione 11 hours ago
mindslight 10 hours ago
megagpt5 11 hours ago
alt227 11 hours ago
megagpt1 12 hours ago
You can also just get a burner phone number for a few bucks.
cube00 9 hours ago
But you have to keep paying the monthly cost, if you loose access to a phone number in your Google account it's game over for any account recovery or "let's verify it's you" it might decide to throw your way.
Linux-Fan 9 hours ago
> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.
Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.
The trick is, that in the general case, you can not keep this account online indefinitely.
I once worked out a trick to get it going and I was feeling safe because I had setup 2FA and backup codes (see https://masysma.net/37/google_how_to_create_an_account_witho...).
First thing to note: This way of account creation does not seem to work anymore.
Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...
Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).
I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.
I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...
talon8635 12 hours ago
armadyl 12 hours ago
talon8635 12 hours ago
armadyl 12 hours ago
talon8635 7 hours ago
And “worried about anonymity in that way”… that’s the topic being discussed here.
armadyl 7 hours ago
As far as cell service goes well yeah there is no such thing as anonymity. Towers will always know your location as long as the radio is on and that can be correlated easily.
gruez 12 hours ago
NewJazz 12 hours ago
weezing 11 hours ago
talon8635 7 hours ago
kotaKat 12 hours ago
"Hope ya got ten bucks!"
(I got a random 5G Moto phone for ~$10 on clearance and it was an absolute shitter of a phone full of garbage packed in malware, but after cleaning and debloating as much as I can, it's at least a nifty toy to poke at Termux or something.)
TeMPOraL 11 hours ago
juiceland 12 hours ago
At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.
josefresco 12 hours ago
Forgeties79 12 hours ago
All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them
kevin_thibedeau 9 hours ago
Their tracking is baked into various apps even if you don't have an account with them. Anything with social media integrations can report back to the mothership behind your back.
Forgeties79 9 hours ago
fc417fc802 5 hours ago
axus 9 hours ago
tredre3 12 hours ago
But my goal is to avoid a stranger gaining access to my google services if they manage to unlock a lost device or steal my TV/streaming box that has no lock at all.
I wish Google supported a permission system per device. For example on most of my android devices all I really want is to be logged into Youtube and the play store. I most certainly do not want those devices to have access to my contacts, emails, calendar, keep, drive, payment, etc. (I don't personally use all of those things, but you might and that's what a random thief would gain access to.)
deepsun 11 hours ago
- ALL: Log me in to all Google Services
- Calendar
- GMail
- YouTube
- ...
Adding more would require to login anew.henryfjordan 11 hours ago
Yes, the advertising targeting is incredibly invasive, but let's not pretend they aren't providing world class Search, Email, Docs, Maps, Video (YT), etc in exchange.
amaccuish 12 hours ago
Cider9986 12 hours ago
GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm
How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.
dingaling 11 hours ago
Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.
Cider9986 11 hours ago
Yeah, the goal is privacy although the OS is completely open source.
They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes.
You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.
Ajedi32 10 hours ago
Looking at their public statements on the matter, it seems like the problem isn't exactly that they treat the user as a potentially hostile actor so much as that they treat the system UI and persistent storage as a potentially hostile actor (though I admit from a practical perspective that's nearly the same thing): https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root...
I wonder how they'd feel about something like protected confirmation to enable sudo: https://source.android.com/docs/security/features/protected-...
palata 8 hours ago
I believe you misunderstand what "software freedom" means. You can compile and install GrapheneOS yourself, and you can grant yourself admin access. This is software freedom.
Software freedom does not mean that you should run everything as an admin, always. And just in case: software freedom does NOT mean that you should remove your firewall and let everybody SSH into your server by having a blank password.
Ajedi32 8 hours ago
I think it's fair to say that that's at least borderline anti software freedom, even if it's true they have good security reasons for doing things that way.
Ajedi32 8 hours ago
lol768 11 hours ago
Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.
welwala 9 hours ago
I personally would prefer to have both but choose the privacy side when both are into conflict.
Both viewpoints are valid, but I don't use GrapheneOS for this reason.
SXX 3 hours ago
hadlock 12 hours ago
arjie 11 hours ago
alt227 11 hours ago
hadlock 11 hours ago
Wether or not the most recent example is the best example, doesn't matter. What matters is when the government says "jump" in legalese, google's lawyers say "how high?"
dmantis 12 hours ago
For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.
The check seems to be purely store-based and never enforced later.
suddenlybananas 11 hours ago
CivBase 11 hours ago
Flip-per 11 hours ago
(for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)
panja 10 hours ago
dooglius 10 hours ago
Gander5739 10 hours ago
lucb1e 10 hours ago
I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store
Gander5739 9 hours ago
palata 8 hours ago
Biganon 5 hours ago
But using Aurora I can install it just fine and it works flawlessly.
khriss 12 hours ago
The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant.
The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past.
steelframe 8 hours ago
halyconWays 12 hours ago
lol. lamo, even.
slome 11 hours ago
Google states: Using a false name or incorrect information when creating a Google account is against Google's Terms of Service.
blablabla123 11 hours ago
Interesting, I never tried Aurora on Graphene. For me the combination of Play Store and F-Droid worked really well so far.
maybewhenthesun 10 hours ago
I don't really see the point of using GrapheneOS instead of Stock Android if I then have to use the play store.
palata 8 hours ago
Also on GrapheneOS, Play Services and Play Store come unprivileged, sandboxed like any other app. So Google is not an admin on your phone, which I would argue is one step towards "severing the umbilical cord".
Moreover, GrapheneOS doesn't have any issue with apps sideloading.
And more. There are many reasons to use GrapheneOS.
ravenstine 10 hours ago
For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.
So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.
xingped 10 hours ago
JadeNB 9 hours ago
Sounds like an accurate recreation of the Play Store experience to me.
xingped 7 hours ago
bilkow 9 hours ago
You probably "just" need to pull down while on the "Latest" or "Updates" tab, to update your repository (it will show a small banner at the top while it's doing that). It's incremental, so it may take a while if it has been some time since you last did it (and auto-updates are disabled).
The way F-Droid works is that it downloads the whole index and then the catalog, version checks, etc, all runs locally, quite similarly to some package repositories actually.
I am not claiming its intuitive, but I think that part works fine once you understand how it works.
xingped 7 hours ago
g-b-r 5 hours ago
F-Droid builds all apps by themselves, which especially with their old servers took a lot (between detecting that the update exists, building the app and going to sign everything at their air-gapped signing computer).
Now a lot of apps use the "reproducible builds" feature, which means that F-Droid will distribuite them as they come from the author, leaving their digital signature; but they still need to build those apps before distributing them, to verify that what the author built corresponds to the declared source code.
With the much powerful servers that they've had for a few months builds are a lot quicker, but there are still steps that can take several days, especially the part of signing the apps' index on their air-gapped computer.
There's a ton of things that could be improved, and it would be best if there were an alternative with better maintainers, but they're currently the only service of this kind for Android (well, IzzyOnDroid is a partial alternative, if you're careful to check their reproducible builds results).
cf100clunk 8 hours ago
xingped 8 hours ago
g-b-r 5 hours ago
You're sure you understand what it does?
cyberrock 4 hours ago
I very much prefer Obtainium these days despite the setup steps. I don't think it's a coincidence that Obtainium, Aurora, Zapstore, etc. are gaining mindshare over F-Droid, just like how Brave has explosive growth over FF.
rpdillon 2 hours ago
We search for stuff, install it, it updates in the background. We install some of our own repos, but the bulk of our apps come from F-Droid's default repos.
Hard to reconcile your account with my experience without specifics.
nisiddharth 2 hours ago
welwala 8 hours ago
And yeah the iris scans sound like a scare but only 2 years ago there was a constant line of zombies here in the shopping mall giving their eye scans to altman.
The masses really don't care about privacy if you give them a worthless trinket.
jsiepkes 9 hours ago
welwala 9 hours ago
I use it on a phone with (unfortunately) regular google play services. If I sign into the play store, that same account will be used for all other google services on the phone too. I'm not going to do that. I just don't want a google account (nor an apple one for that matter)
zackify 9 hours ago
For example the eBay app. Does not allow installing from the play store on grapheneos.
innocent_name 9 hours ago
Like my personal phone?)
Installing Google Play service is in itself a privacy downgrade.
rkagerer 9 hours ago
That isn't completely possible these days. Last I checked they want an existing email address and/or a cellphone number for verification. I guess "not tied to anything else" is proportional to how much you trust them to delete either of these bits of info after they are used, and not associate them with other accounts you might have used them with in the past/future.
andrepd 8 hours ago
attila-lendvai 7 hours ago
troyvit 13 hours ago
I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community.
DaSHacka 12 hours ago
I think it's fine the mission of the project isn't directly aligned with some of us, though I can tell we often get on the core contributor's nerves lol
titularcomment 12 hours ago
Semaphor 11 hours ago
tpm 11 hours ago
megagpt5 11 hours ago
unrented7977 11 hours ago
Far, far too "opinionated" for my taste. I frankly do not need the hyper paranoid security features like a hardened memory allocator or disabled root. I would rather be able to use my device the way I want, even if that's notionally "less secure".
I really wish there were another option. Lineage is too far in the opposite direction and feels like ad-blocked stock. Google still owns my phone, there's just a more pleasant coat of paint on it.
seany 11 hours ago
tentacleuno 9 hours ago
I get the part about disabled root - you're choosing to sacrifice freedom for security - though I don't understand why you wouldn't want a hardened memory allocator. It provides additional security over the stock OS for very little cost (slightly more resource consumption), in an era where we absolutely need as much security as we can get; what are you losing by gaining this?
Borealid 11 hours ago
For example, let's say hypothetically I want to be secure against the threat of Google pushing a targeted update to my phone that runs malicious code. Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat. But Graphene devs say things like "MicroG is less secure than Google Play Services".
Similarly, if you want privacy you might secure your device by locking the bootloader with your own keys - not a third-party vendor's keys. Saying that's "insecure" is extremely misleading: it just puts you in charge of security, instead of abdicating to someone else.
I wish there were something like GrapheneOS that let you choose, yourself, who to trust instead of requiring you trust an OS vendor implicitly.
exceptione 10 hours ago
> Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat
I would say that any auto-update mechanism is a threat, so in both cases you would disable auto-updates.lucb1e 9 hours ago
exceptione 9 hours ago
flexagoon 12 hours ago
There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.
The core dev team is obviously a bit more security absolutist, but even they usually dont mind
lucb1e 9 hours ago
Citation needed. If there are such people in what can be considered a grapheneos community that haven't gotten fed up yet and left, grapheneos themselves sure doesn't understand this
> Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.
Nah, they're fine with tracking, so long as it happens in their sandbox. The official website has an install guide for google's background services, saying it's fine because it's in their security model. So long as the modem can't access your contacts without a permission prompt, there is no tracking in baghdad
g-b-r 6 hours ago
Their absolutist of their own view of security
kjander79 13 hours ago
aniviacat 12 hours ago
g-b-r 6 hours ago
titularcomment 12 hours ago
kevincox 11 hours ago
tentacleuno 9 hours ago
skeledrew 12 hours ago
g-b-r 6 hours ago
Have you looked for help? It sure isn't because of any Google component being disabled
ssernikk 12 hours ago
It's a shame that there is no official way to install apps on android without a google accout[1], since it's a basic functionality, just like calls or a web browser.
[1] For obvious reasons I don't want her to download apks from the internet.
catlikesshrimp 11 hours ago
alt227 11 hours ago
iAMkenough 10 hours ago
crtasm 10 hours ago
iAMkenough 10 hours ago
Grandma doesn’t care if it looks like an update or not.
alt227 9 hours ago
iAMkenough 9 hours ago
catlikesshrimp 7 hours ago
dwedge 7 hours ago
lern_too_spel 11 hours ago
dwedge 7 hours ago
nfriedly 2 hours ago
Play Store won't let me install them, but AuroraStore will, and most of the time they work fine after that.
For example, I have Balatro running on my Ayn Thor this way.
denzen 12 hours ago
nosioptar 11 hours ago
Aurora hasn't worked right for the most part for a year due to device attestation shit.
I'm meh on it. Not being able to install the shit from play store isn't such a bad thing. It is lame as hell that Google is doing their damndest to make apple look user friendly.
CodesInChaos 12 hours ago
krunck 11 hours ago
rihegher 9 hours ago
welwala 9 hours ago
Even this particular error ("Server busy, try again later"). I've been seeing over the past weeks but then a few days later it worked again. I'm not too worried. It also happens or me right now indeed.
hoshi73 9 hours ago
g-b-r 6 hours ago
theandrewbailey 9 hours ago
functionmouse 9 hours ago
tentacleuno 9 hours ago
cf100clunk 8 hours ago
ChocolateGod 12 hours ago
Not news nor "blocking".
berkes 11 hours ago
Honest question, because AFAIK there's no guarantee or (legal) requirement to support any API. Whether that's fully documented, has SDKs or whether it's something reversed-engineered doesn't matter WRT the support the company owning the API is supposed or required to give.
Or am I wrong there?
g-b-r 6 hours ago
g-b-r 6 hours ago
It affects using Aurora Store "anonymously" because that means using shared accounts, so far higher activity per account.
It's possible they're also detecting contemporary usage of the same account.
But there's a slight chance that it's just due to someone abusing the accounts outside Aurora Store.
ChrisArchitect 12 hours ago
thataccount 5 hours ago
erikvanoosten 11 hours ago
Mistake from me: apparently GrapheneOS does not recommend Aurora Store (citation needed). Kind of weird though; it means Google still knows a lot about you, which doesn't seem very privacy conscience.
Google blocking Aurora Store was a conclusion made in the bug thread. It was not my conclusion.
And for the nit pickers: Sailfish OS is not Android, but its emulation layer _is_. :shrug: Even though Sailfish is nice, without its Android layer it is practically unusable.
Funny thing: the 'busy server' problem existed for almost a week. I could download 1 app per day max on my Jolla C2. But just now, now that this thread makes top of Hackernews, everything started working just fine!
tentacleuno 9 hours ago
I remember being in the GrapheneOS room and hearing them directly recommend using Windows 10 over Linux, as it was more secure. They are known to prioritize security over privacy.
g-b-r 6 hours ago
tentacleuno 6 hours ago
On paper, I'm sure Windows does have stronger userspace and kernel-space protections against intrusion and such, though I most certainly wouldn't use it.
g-b-r 5 hours ago
They largely ignore any threat that could come from US agencies, and are very presumptuous about some of their convictions (e.g. that open source is irrelevant for security).
There is a balance to be made, given that there often isn't any ideal option, but they often get that balance assessment wrong, in my opinion.
I appreciate exposing the security weaknesses of other products, but they end up adding threats that they don't have with some of their drastic views.
gpvos 6 hours ago
kotaKat 13 hours ago
megagpt2 12 hours ago
g-b-r 6 hours ago
berkes 11 hours ago
Not that it requires Google to "open up" their play-store, but that they must allow other app-stores to work on the same level. So basically allowing devs and users to move elsewhere.
zoobab 11 hours ago
Apple moved first with making a special 'sideloading' case for apps not under their control, Google is just copying what they did.
No more free sideloading.
megagpt5 11 hours ago
_leom 12 hours ago
thataccount 11 hours ago
welwala 9 hours ago
g-b-r 6 hours ago
westurner 10 hours ago
Try and find a category for "open source" apps on any app store.
Ajedi32 10 hours ago
ranger_danger 12 hours ago
This seems like it was destined to get banned somehow... and I don't think it means that the store itself is blocked, just the pool of accounts they (ab)use.
zoobab 11 hours ago
okokwhatever 11 hours ago
gruez 11 hours ago
lenerdenator 12 hours ago
Good times, good times.
catlikesshrimp 11 hours ago
lenerdenator 10 hours ago
The window to have a real open mobile OS is starting to close. If there is to be a meaningful change, it must happen soon.
lucb1e 9 hours ago
shevy-java 12 hours ago
hluska 12 hours ago