- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
AuroraStore is working fine on my lineageOS phone
Saw protonmail screenshotted and got triggered. @[email protected] refuses to make an fdroid build. It’s one of the reasons I stopped using them (and their CEO supports Trump).
Doesn’t sound like it’s specific to grapheneos. It’s probably on any android.
Don’t be afraid to use grapheneos. Grapheneos works perfectly fine. It’s a normal android just with more control over your phone.
Yeah, the person who opened the case uses CalyxOS. I’m getting the issue on a manufacturer build, OxygenOS **updating is fine but installing a new app is not
GrapheneOS is the ONLY free android build that has an alternative by installing the playstore…
The GrapheneOS team explicitly recommends against installing the aurora store for that exact reason. If you can install the stock play store with a burner email then the aurora store doesn’t actually give much of a privacy benefit (you are still uniquely identified either way) but aurora store is playing a game of whack-a-mole with Google.
Ah yes let me hand Google access into what apps I have installed on my phone. Definitely a reasonable thing to do.
If you have Aurora installed that is still being done. If you don’t want to send that list then don’t use any play services.
It’s different
No, Aurorastore is still worlds more private than Google Play, and until now it was really reliable!
It runs as an unprivileged user app and uses randomized accounts. You can add all apps you dont want Google to know of to your blocklist, so the unique fingerprint from your app list is extremely reduced. Google Play doesnt do that. Aurora is WAY better for privacy
For security yeah, you can use google play and add the signatures to VerifiedApps
It runs as an unprivileged user app and uses randomized accounts.
Google play services under graphene are all also unprivileged.
You can add all apps you dont want Google to know of to your blocklist, so the unique fingerprint from your app list is extremely reduced
I wouldn’t say extremely, as you still need to keep all of the apps which you install from the store itself unblocked to get updates. Anecdotally for me, that list is all of the niche apps which I can’t use FOSS alternatives for, like banking, work, transit, etc. so it’s very likely still uniquely identifying. If you’re hiding system services in Aurora that you don’t want it touching, that makes it even easier to identify you, because Google play doesn’t do that.
Aurora is WAY better for privacy
I’m not a security researcher and am basically regurgitating what the Graphene team has said about it, as I think they know a lot more about how the play store works under the hood and the information that is required to send to Google than I do. I think they have a blog post about it somewhere.
Yes they are unprivileged, and the gmscompat tool doesnt give them more access that is true. Still it is google software with the intention to control your device and spy on you, while Aurorastore is a slim app that even allows to restrict the apps it tells to Google.
If you’re hiding system services in Aurora that you don’t want it touching, that makes it even easier to identify you, because Google play doesn’t do that.
It is less data. GrapheneOS will have less system apps than stock android so that immediately gives it away.
Asking Google for updates is also different from telling it a complete list of your installed apps. You might simply not try to update these system apps currently.
In the end, it is really good that play services work on GrapheneOS, but they are still more invasive as regular user apps than alternatives.
I have heard it has some security problems as well, which might be a big deal if your threat level is higher. At the same time, Aurora store works without google play services installed, doesn’t that have some privacy benefits? I have heard that google play services in GrapheneOS has the same permissions as a regular app, however, I still feel the pull to be without them on my main profile and feel like I don’t really get the implications of that. Maybe it collects less data but surely it’s still a lot?
to me it’s pretty simple: Do you value privacy more than having easy access to “normal” apps? If yes, skip aurora store; if no, use aurora store.
Anything more than that gets into putting in a bunch of effort and worry for not much benefit.
Google scared of a little competition, easy lawsuit for being anticompetitive, not the first one either.
Well yes but nobody forces devs to only upload on Playstore, they simply do because they suck. Even quite a few open source projects!
Ignorance is the problem, most people don’t know there are alternatives to the Playstore.
The title is misleading, GrapheneOS users are the only ones who have an alternative lol
Most other open source Android builds simply rely on Aurorastore and we see how unreliable that is
/e/OS uses some weird shady appstore that contains a lot of playstore malware (literally anything) and is completely intransparent.
Apkmirror and apkpure rely on other people extracting and uploading APKs.
Tips for everyone
Install the following apps:
VerifiedAppsAndroid (Github) also available through their F-Droid repo
This app contains a growing database of signatures so you can verify that APKs you get are legit. Make sure to submit all the playstore apps you rely on, as those are especially affected!
Signature of the app:
org.privacyguides.verifiedapps 40:5C:6B:D2:CA:7C:3A:AE:8F:46:3C:6F:8B:55:BC:F0:DD:AC:43:1C:5E:D8:EA:FF:65:D1:06:C9:81:7A:20:7FVadhod APK Extractor contains AI code but it is the only updated and well working app I know that can extract split-APKs and regular ones. Also it doesnt need filesystem permissions!
Universal Installer allows you to install split-APK files like you might get from extracting Playstore apps.
It might be a good idea to make an F-Droid repo with essential proprietary apps, as the combination with VerifiedApps allows users to not need to trust the repo but be able to verify the App’s origin securely. Android will only allow updates if the signature matches, so you only need to do this once on install.
Note that Obtainium+Apkpure have frequently installed 32bit APKs on recent Android phones that still supported those, which is a security issue. Might not happen if your phone doesnt even support them anymore like recent Pixels do.
Oh it’s not a me problem this time? I thought my firewall was somehow blocking it but I just did a download both with and without a VPN on, so I guess it is Google banning shit like usual…
I use obtainium because I’m a big nerd loser but f-droid works fine anyways; you can install all the stores you want, including aurora
The issue isn’t installing the Aurora Store, it’s using it after install.
Aurora Store allows (allowed?) people to download apps from the Play Store without logging in - frankly I’m shocked it lasted this long to begin with. It gives full access to the Play Store library (you still have to log in for paid apps), but it serves a very different service from Obtanium, F-Droid and the rest
Ah I see thanks for the correction
it’s working for some apps
Fix your title. It doesnt match the link’s title
It’s still working on my phone.
I get server busy all the time when downloading now










