8 ms·
The first ticket you link is not by someone who seems to work on GrapheneOS, at least there's nothing in their profile to suggest as much. The improvement they
by lucb1e 11d ago
The first ticket you link is not by someone who seems to work on GrapheneOS, at least there's nothing in their profile to suggest as much. The improvement they suggest is hardening, preventing basically nation state attackers who either compromise or compel a CA to issue a false certificate for Google's servers
The second ticket is about checking if the data that Google sent via TLS has a second signature from Google. It doesn't prove what you claim about ensuring the key is from the developers. This is more useful for places like apkmirror that distribute apps and could include the signature that Google tacked on, for people who trust but cannot use Google; to verify Google's signature without needing to be able to connect to Google. That's not what Aurora does, so it's not relevant to the project. Can be defense-in-depth in case Google's front-ends are compromised but the signing back-end is not, but again, that's less likely than getting struck by lightning and such a powerful attacker could also just compel the developers to make a special update that performs malicious actions on their target
This is the level of misunderstanding that I find very common among GrapheneOS users btw: it all sounds good if you don't know much about it, but when you drill down to what it actually does and consider a specific threat model, it's no reason to recommend Google Play over Aurora for 99% of people's threat models. If you're an oppressed journalist in Iran or whistleblower in the USA, then the cert pinning could help, but most of us are more impacted by everyday tracking than by targeted nation state attacks
> Apps on your phone may be able to determine your locality, and can definitely fingerprint you uniquely, so it is not enough to download an app via Aurora Store.
I'm probably misunderstanding you, but nobody said downloading an app via Aurora changes the contents of the download to become privacy-friendly. Like, downloading a .exe via an open source browser also doesn't change the download compared to if you download it with Google Chrome
You still have to be wary of what you download, deny it internet access if applicable, etc. It's just that you don't have to have google's stuff running in the background all the time, toggling internet access on (letting it upload queued telemetry) anytime you want to download or update an app that is distributed only via google
Aurora at least lets you filter on apps that don't have GMS listed as a dependency, and works with Exodus to show other trackers, making this process a lot easier than via Google Play
> Instead they do suggest Aurora Store as a last resort in special cases where the Play Store prevents you from getting the app nonsensically.
What do you mean by nonsensically? I didn't know they recommend it under any circumstance though, that's cool. Do you happen to have a link for that, or remember where they wrote that?
- ysnp 8d ago>The first ticket you link is not by someone who seems to work on GrapheneOS https://github.com/flawedworld https://github.com/flawedworld for example as part of GrapheneOS organisation and has interviewed for GrapheneOS in the past (https://www.youtube.com/watch?v=WkQ_OCzuLNg https://www.youtube.com/watch?v=WkQ_OCzuLNg). >preventing basically nation state attackers who either compromise or compel a CA I don't think the compromising, self-compromise or compelling of a Certificate Authority is a feat reserved for state-level attackers. I am not sure why it would exclude any malware that gains enough privileges, or existing campus-enterprise mobility management apps/parental control/antivirus that get compromised or hijacked. But really it comes back to one of the original points which was that GrapheneOS are comfortable recommending and promoting solutions with a high level of security/privacy as a general rule. >The second ticket Yeah, I believe I confused the 'frosting metadata' part with the important whole APK Signing Block. The part I wanted which the app store client should verify would be the signing certificate hash which you compare to what the server says the package should give you. As far as TOFU mainstream users basically trust in Google's Play Security & reviews process instead of developer signing certificates/keys because most developers do not publish that out-of-band somewhere they individually control. Widget on Dev's Socials/Site + Publishing hurdles + Developer Console auth + Google security/review add up to a non-zero chance the listing is good. When you get the app you have the benefit of certificate pinning and app signature verification to make sure that non-zero isn't majorly reduced in distribution/transit. GrapheneOS don't even recommend getting apps from Play anyway if you can verify and source the apps directly from the developer. >very common among GrapheneOS users btw Can't say anything for your experiences, but of course I only speak for myself. I can say though that the GrapheneOS developers themselves will never tell you the OS is specifically for high-risk oppressed journalists and whistle-blowers. Another big disconnect is that GrapheneOS believe things need to be much more attack/abuse-resistant for the 99% than they are now, so asking them to aim a little lower than current standards will cause a lot of misunderstandings: https://xcancel.com/GrapheneOS/status/2044440381803069778#m https://xcancel.com/GrapheneOS/status/2044440381803069778#m >You still have to be wary of what you download, deny it internet access if applicable, etc. Aurora at least lets you filter on apps that don't have GMS listed as a dependency, and works with Exodus to show other trackers, making this process a lot easier than via Google Play I agree mostly with this, but I think you can see it would be a bit painful and tedious for GrapheneOS to say "We can't endorse violating Google's TOS but Aurora Store is an option under specific circumstances and technical conditions. Apps from Play/Aurora may not contain any Google libraries, GMS dependencies or involve sending data to Google as potentially stated in their privacy policy but there is no accessible way to determine this per-app at a glance." every time they need to talk about Aurora Store. >Do you happen to have a link for that, or remember where they wrote that? Recent examples: https://xcancel.com/GrapheneOS/status/2093353794247467344#m https://xcancel.com/GrapheneOS/status/2093353794247467344#m https://news.ycombinator.com/item?id=49548219 https://news.ycombinator.com/item?id=49548219