25 ms·
GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. For extra privacy, you can sign
by pyrophane 15d ago
GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.
For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.
- attila-lendvai 15d agoi don't even have google play serices installed, let alone the play store...
- 1718627440 15d ago> with a Google Account that isn't tied to anything else. How can I get this wonderful thing?
- subscribed 15d agoTry installing an app that requires Play Store Integrity, say, ProShot by RiseUp Games. Braindead dev claims this is to limit the "piracy" and bug reports, nevertheless it's either Aurora or APKMirror.
- kasabali 14d ago> For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else. I dare you try creating a Google account that isn't tied to anything else. Nowadays you can't even create an account in desktop browser without first having to scan a qr code from a mobile device first.
- einpoklum 14d agoSo, GrapheneOS is a supposed alternative to using Google's OS and their surveillance and adware - except you're supposed to run it on Google hardware, and apparently with a Google account and connecting to Google's services. WTF?
- grapheneos 14d agoGrapheneOS does not include any support for using a Google account and does not require using Google apps/services. There are many inaccurate statements here about what we supposedly recommend. We do not specifically recommend using the Play Store as a source of apps in the first place. We recommend using the sandboxed Play Store for obtaining apps from the Play Store. GrapheneOS uses Pixels because those are still the only Android devices with reasonable security including decent updates, working encryption for users without a strong passphrase and the hardware functionality usable to provide decent exploit protection. GrapheneOS is in the process of adding support for upcoming Motorola devices meeting the official requirements.
- einpoklum 13d agoSo, what I said is true: You recommend using Google's phones and Google's app store. Maybe in the future you'll recommend other phones, so it'll be less bad, but for now - you've verified that the "inaccurate statements"
- grapheneos 9d agoNo, we do not recommend using the Play Store as a source of apps over other options such as Accrescent. We document how people can obtain apps from the Play Store via both the sandboxed Play Store and Aurora Store. We explain apps with store listings configuring to block a non-Google-certified OS can be obtained via Aurora Store but that the sandboxed Play Store is generally a better way to install apps from it. Giving people recommendations on how to use a certain source of apps is not a recommendation to use it over the options we recommend including Accrescent. Pixels are currently the only devices providing the updates and security features listed at https://grapheneos.org/faq#future-devices https://grapheneos.org/faq#future-devices. GrapheneOS has an official partnership with Motorola where their devices are being improved to meet these requirements and provide official GrapheneOS support. We're actively working on it with them. We've reported vulnerabilities, weaknesses and made feature proposals to Google for Pixels but they certainly haven't directly helped us or supported us.
- grapheneos 14d agoWe don't recommend using the Play Store as a first choice for obtaining apps. Aurora Store is another way to use the Play Store as a source of apps. If someone is using sandboxed Google Play in a profile, it makes sense to use the sandboxed Play Store to install apps. Aurora Store is mainly useful as a workaround for store listings enforcing Play Integrity and we do direct people to it for that. Aurora Store still works fine. It doesn't require the default-enabled account sharing feature. It's not Aurora Store which is getting blocked but rather account sharing. Account sharing is against Google's terms of use and is now being detected more aggressively. We've warned about this for years but it took longer than expect for them to ramp up banning it. It's likely going to continue getting stricter.
- DaSHacka 15d agoAlthough the nice thing about Aurora Store is it allows you to install apps without a google account linked to your device, keeping Google Play Services signed-out. Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't). Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play. That's personally what I used Aurora for, plus as an easy way to export APK files.
- aesh2Xa1 14d agoSome apps offer direct APK downloads from their websites. If Google Play Services is detected, they use it for push notifications. Otherwise, they fall back to an internal background connection. WhatsApp is an example. You still need to supply Play Services: GrapheneOS uses Sandboxed Google Play. LineageOS requires flashing a package like MindTheGapps. There is also microG, an open-source reimplementation of Play Services APIs.
- SahAssar 15d agoHaving to have a account is absolutely a downgrade and privacy-hostile.
- joekrill 15d ago> a Google Account that isn't tied to anything else. Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
- armadyl 15d agoAccounts created on stock Pixels don’t require phone numbers.
- iririririr 15d agothat haven't been true since pixel 4. it just picks your phone in the background. a burner sim, like a literal criminal, is the only way today.
- goodmythical 15d agoassuming the number you get hasn't previously been assigned to a google account
- drxzcl 15d agoI've had no end of trouble registering an account on our corporate SIMs as the phone numbers (not the actual SIM cards) had been recycled as employees leave.
- edoceo 15d agoSo many systems cannot handle known pattern of a phone number changing. Who's decided these are imutable values? That I have only one? That it's not shared?
- asnelt 15d agoEven with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission.
- talon8635 15d agoDoesn’t Google make it very hard to create an account tied to nothing (no phone or alt email)?
- armadyl 15d agoIf you create it on a stock Pixel device the phone requirement gets dropped.
- talon8635 15d agoIt’s undoubtedly tied to the phone with is tied to the owner
- armadyl 15d agoWell yeah. But if you care about anonymity on that level there are ways around that (i.e. buying in cash and creating the account using public WiFi).
- talon8635 15d agoWhat? Buy a phone in cash and have it billed to what, your monero wallet? This isn’t possible in today’s world, in the west anyways. Phones are tied to people. And “worried about anonymity in that way”… that’s the topic being discussed here.
- armadyl 15d agoYou can buy a phone with physical cash from a store or used p2p… As far as cell service goes well yeah there is no such thing as anonymity. Towers will always know your location as long as the radio is on and that can be correlated easily.
- gruez 15d agoPeople report that it works even on grapheneos with sandboxed google play. My guess there's some fingerprinting going on, not necessarily that they're tying the account to some account id.
- juiceland 15d ago> Google Account that isn't tied to anything else. At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.
- duskdozer 15d ago[flagged]
- HybridStatAnim8 14d agoGrapheneOS is a privacy first project. Security is improved for the sake of privacy.
- grapheneos 14d agoNo, GrapheneOS is a privacy project. The primary focus is providing usable privacy. GrapheneOS solely works on security to protect privacy.
- josefresco 15d agoPiggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.
- Forgeties79 15d agoMy experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that have them running around in the background or just straight up depend on them. All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them
- amaccuish 15d ago[flagged]
- Cider9986 15d agoGrapheneOS is focused on privacy but that must come from a secure baseline. GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm https://eylenburg.github.io/android_comparison.htm How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.
- dingaling 15d agoThe problem is that to achieve privacy through security, Graphene has to treat the user as a potentially hostile actor. Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.
- Cider9986 15d ago> Which is very much contrary to software freedom. Yeah, the goal is privacy although the OS is completely open source. They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes. You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.
- hadlock 15d agoIt seems wise to have at least one alternative mobile phone app store. Even if it isn't very good. If the government can tell Google to do trivial things like, for example, change the name of bodies (plural now) of water, it can turn off your app updates, trapping you on insecure versions indefinitely. This probably matters more if you live outside of the US, but if I had a plan B for an app store on my phone, I would certainly at least evaluate it.
- arjie 15d agoName changes happen all the time and I would expect Google to match what the government sources use locally. The fact that the government is capricious is no reason for me to desire Google to become an alternative naming center.
- alt227 15d agoThe government didnt ask google, they changed the name on the Geographic Names Information System (GNIS), which is the official legal mapping source which other companies like Google etc use. Hence the change filtered down through software from the top official channel.
- hadlock 15d agoRight, the government pulled a lever, and google complied within days. If the FTC declares app stores can't provide security updates without government license, that is another lever they can pull, and google will comply. Wether or not the most recent example is the best example, doesn't matter. What matters is when the government says "jump" in legalese, google's lawyers say "how high?"
- dmantis 15d agoSometimes you just can't. For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora. The check seems to be purely store-based and never enforced later.
- Biganon 15d agoSame. Twint (basically the Swiss Venmo) insists that my phone is not compatible with it. But using Aurora I can install it just fine and it works flawlessly.
- suddenlybananas 15d agoI have similar problems installing region locked apps as someone who's fairly frequently in different regions.
- CivBase 15d agoThis is exactly why I switched to Aurora. I couldn't even install Balatro from the Play Store.
- Flip-per 15d agoDo you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with. (for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)
- khriss 15d ago> you can sign into the Play Store with a Google Account that isn't tied to anything else. The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant. The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past.
- steelframe 15d agoI recently had to set up a new Android device for work. Since I keep all my personal accounts separate from my work accounts, I needed to create a new Google account on that phone. I ended up paying $8 for a month of the cheapest service I could find just to get a phone number so I could create that account.
- halyconWays 15d ago"For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else." lol. lamo, even.
- slome 15d agoA Google account is a personal identifier, it is linked to your person. Therefor trying to untie it from anything else is futile. Google states: Using a false name or incorrect information when creating a Google account is against Google's Terms of Service.
- blablabla123 15d ago> GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users. Interesting, I never tried Aurora on Graphene. For me the combination of Play Store and F-Droid worked really well so far.
- maybewhenthesun 15d agoThe main reason for me to use GrapheneOS would be to sever the umbilical cord to google. I don't really see the point of using GrapheneOS instead of Stock Android if I then have to use the play store.
- grapheneos 14d agoUsing the Play Store on GrapheneOS whether via sandboxed Google Play or another frontend definitely doesn't defeat any the purpose of it. You do not have to use the Play Store on GrapheneOS, but the privacy and security features it provides are not cancelled out by using it. GrapheneOS has privacy features such as Contact Scopes and Storage Scopes which are most useful when using privacy invasive apps. Using privacy invasive apps doesn't defeat the point but protecting against those is a core part of the purpose of GrapheneOS. Our Sandboxed Google Play compatibility layer is a privacy feature itself to enable people to use those as regular sandboxed apps without invasive access to be able to run apps depending on them.
- palata 15d agoBetter security, for once. You get (security) updates a lot faster with GrapheneOS. Also on GrapheneOS, Play Services and Play Store come unprivileged, sandboxed like any other app. So Google is not an admin on your phone, which I would argue is one step towards "severing the umbilical cord". Moreover, GrapheneOS doesn't have any issue with apps sideloading. And more. There are many reasons to use GrapheneOS.
- maybewhenthesun 9d agook, fair enough.
- ravenstine 15d agoGrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS. For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect. So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.
- xingped 15d agoI've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app. It's one of the worst pieces of software I've used in a while, and I can tolerate a good bit of jank from FOSS apps.
- g-b-r 15d agoThe software and many parts of the project are bad, but I don't see how you can't understand its reason to exist. You're sure you understand what it does?
- cyberrock 15d agoMy understanding is that F-Droid is hosted out of some home servers (instead of some universities like other similar package managers) so the bandwidth leaves much to be desired. But the UX is definitely a big part of the problem. I don't understand why it tends to abort downloads when I background it, and I don't understand why it doesn't show a toast that it aborted the download. I very much prefer Obtainium these days despite the setup steps. I don't think it's a coincidence that Obtainium, Aurora, Zapstore, etc. are gaining mindshare over F-Droid, just like how Brave has explosive growth over FF.
- jsiepkes 15d agoThere are apps I cannot install via the Play Store in GrapheneOS, only via Aurora store.
- welwala 15d agoYes but Aurora isn't only for GrapheneOS. I use it on a phone with (unfortunately) regular google play services. If I sign into the play store, that same account will be used for all other google services on the phone too. I'm not going to do that. I just don't want a google account (nor an apple one for that matter)
- zackify 15d agoIt DOES still hurt. For example the eBay app. Does not allow installing from the play store on grapheneos.
- innocent_name 15d ago>For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else. Like my personal phone?) Installing Google Play service is in itself a privacy downgrade.
- rkagerer 15d ago...with a Google Account that isn't tied to anything else That isn't completely possible these days. Last I checked they want an existing email address and/or a cellphone number for verification. I guess "not tied to anything else" is proportional to how much you trust them to delete either of these bits of info after they are used, and not associate them with other accounts you might have used them with in the past/future.
- andrepd 15d ago[flagged]