pyrophane
4 hours ago
GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.
For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.
DaSHacka
3 hours ago
Although the nice thing about Aurora Store is it allows you to install apps without a google account linked to your device, keeping Google Play Services signed-out.
Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't).
Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play.
That's personally what I used Aurora for, plus as an easy way to export APK files.
juiceland
3 hours ago
> Google Account that isn't tied to anything else.
At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.
tredre3
2 hours ago
I'm under no illusion that google doesn't know I own my multiple accounts. They most certainly do. I usually use the same user agent (with containers) on the same IP, after all.
But my goal is to avoid a stranger gaining access to my google services if they manage to unlock a lost device or steal my TV/streaming box that has no lock at all.
I wish Google supported a permission system per device. For example on most of my android devices all I really want is to be logged into Youtube and the play store. I most certainly do not want those devices to have access to my contacts, emails, calendar, keep, drive, payment, etc. (I don't personally use all of those things, but you might and that's what a random thief would gain access to.)
deepsun
2 hours ago
Yep, something like checkboxes on login:
- ALL: Log me in to all Google Services
- Calendar
- GMail
- YouTube
- ...
Adding more would require to login anew.josefresco
3 hours ago
Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.
axus
19 minutes ago
They have required unique phone numbers for accounts I've tried lately, or parent's phone numbers. Facebook is worse though, they are quick to ban an account/phone number.
Forgeties79
3 hours ago
My experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that have them running around in the background or just straight up depend on them.
All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them
kevin_thibedeau
19 minutes ago
> leave their ecosystem
Their tracking is baked into various apps even if you don't have an account with them. Anything with social media integrations can report back to the mothership behind your back.
henryfjordan
2 hours ago
Google's business model is providing you services that are excellent, while also providing advertisers access to your willing eyeballs when you use those services.
Yes, the advertising targeting is incredibly invasive, but let's not pretend they aren't providing world class Search, Email, Docs, Maps, Video (YT), etc in exchange.
ravenstine
35 minutes ago
GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS.
For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.
So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.
xingped
29 minutes ago
I've honestly never understood why F-Droid even still exists. Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app. It's one of the worst pieces of software I've used in a while, and I can tolerate a good bit of jank from FOSS apps.
bilkow
9 minutes ago
> never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app. The other half of the time even when I did get something installed, it would just never understand that an update existed and needed to download and update a given app
You probably "just" need to pull down while on the "Latest" or "Updates" tab, to update your repository (it will show a small banner at the top while it's doing that). It's incremental, so it may take a while if it has been some time since you last did it (and auto-updates are disabled).
The way F-Droid works is that it downloads the whole index and then the catalog, version checks, etc, all runs locally, quite similarly to some package repositories actually.
I am not claiming its intuitive, but I think that part works fine once you understand how it works.
JadeNB
15 minutes ago
> Every time I've tried to use it (as recently as half a year ago) it's still a shitshow and never displays or updates apps correctly. Half the time an app showed up on the website that didn't show up on the phone app.
Sounds like an accurate recreation of the Play Store experience to me.
welwala
6 minutes ago
Yes but Aurora isn't only for GrapheneOS.
I use it on a phone with (unfortunately) regular google play services. If I sign into the play store, that same account will be used for all other google services on the phone too. I'm not going to do that. I just don't want a google account (nor an apple one for that matter)
joekrill
3 hours ago
> a Google Account that isn't tied to anything else.
Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
Linux-Fan
12 minutes ago
> > a Google Account that isn't tied to anything else.
> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.
Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.
The trick is, that in the general case, you can not keep this account online indefinitely.
I once worked out a trick to get it going and I was feeling safe because I had setup 2FA and backup codes (see https://masysma.net/37/google_how_to_create_an_account_witho...).
First thing to note: This way of account creation does not seem to work anymore.
Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...
Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).
I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.
I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...
megagpt1
3 hours ago
You can create an account with no phone number during Android device setup.
You can also just get a burner phone number for a few bucks.
armadyl
3 hours ago
Accounts created on stock Pixels don’t require phone numbers.
iririririr
3 hours ago
that haven't been true since pixel 4. it just picks your phone in the background.
a burner sim, like a literal criminal, is the only way today.
asnelt
3 hours ago
Even with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission.
exceptione
3 hours ago
That can't be true? <https://grapheneos.org/faq#hardware-identifiers>
As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.
Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.
I don't know however if sandboxed google play is such a privileged app.asnelt
3 hours ago
I couldn't immediately find whether GrapheneOS grants READ_PRIVILEGED_PHONE_STATE to Google Play. It might very well be that the GrapheneOS sandbox spoofs a fake IMEI, and I do hope so.
In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.
nickspacek
2 hours ago
https://grapheneos.org/usage#sandboxed-google-play
> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.
It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."
exceptione
2 hours ago
There is an AppStore app, I am not sure if this is the one we are talking about? <https://github.com/GrapheneOS/AppStore/blob/main/app/src/mai...>
That one lists:
ACCESS_NETWORK_STATE
ENFORCE_UPDATE_OWNERSHIP
FOREGROUND_SERVICE
FOREGROUND_SERVICE_SPECIAL_USE
INSTALL_PACKAGES
INTERNET
POST_NOTIFICATIONS
QUERY_ALL_PACKAGES
RECEIVE_BOOT_COMPLETED
REQUEST_DELETE_PACKAGES
REQUEST_INSTALL_PACKAGES
UPDATE_PACKAGES_WITHOUT_USER_ACTIONgruez
2 hours ago
That's grapheneos's own app, separate from the play store or play services.
exceptione
an hour ago
True. I think this one is closer to the truth: <https://github.com/GrapheneOS/platform_packages_apps_GmsComp...>
There is no READ_PRIVILEGED_PHONE_STATE mentioned there.
gruez
36 minutes ago
That's also incorrect, because the gmscompat app is just a helper app. Play services can and does request additional permissions. Those permissions are handled by the OS under the play services app, not gmscompat. If you want RCS for instance, you must grant play services and google messages phone and ICC auth access, which isn't seen in gmscompat at all.
exceptione
6 minutes ago
> That's also incorrect, because the gmscompat app is just a helper app.
Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services. > Those permissions are handled by the OS under the play services app
Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unprivileged app, and so any additional permission it would want would have to be consented by the user and should be visible to the user. If not, then GOS wording would be quite a bit unfortunate at least.mindslight
2 hours ago
That's the application software side. I would assume the IMEI and IMSI are both going out to the cell network though, and I would presume that it's trivial to tie a phone number to those with how the mobile industry generally sells subscriber data to various data brokers. The only question is how permissive those data brokers are (their major constraint is how much most people become aware of this dynamic), but when dealing with a major APT like Google I'd assume they're tuned into the best ones with songs about bona fide purposes.
exceptione
2 hours ago
Are you talking about the US here? I am hoping this would be off-limits in Europe.
mindslight
an hour ago
Yes I am talking with a US perspective. I would hope the GDPR would prevent such things in (most of) Europe. But I also personally wouldn't assume so given that there are still the same dynamics of keeping the info flows private to avoid scrutiny, and claiming plausible "legitimate purposes" and "consent".
alt227
2 hours ago
Its possible to set up a phone with a google account without even a sim card in it and use it as a wifi only device, so Im pretty sure what your saying is wrong.
goodmythical
3 hours ago
assuming the number you get hasn't previously been assigned to a google account
drxzcl
2 hours ago
I've had no end of trouble registering an account on our corporate SIMs as the phone numbers (not the actual SIM cards) had been recycled as employees leave.
edoceo
an hour ago
So many systems cannot handle known pattern of a phone number changing. Who's decided these are imutable values? That I have only one? That it's not shared?
megagpt5
2 hours ago
It still works without a SIM card, how do you explain that?
dmantis
3 hours ago
Sometimes you just can't.
For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.
The check seems to be purely store-based and never enforced later.
CivBase
2 hours ago
This is exactly why I switched to Aurora. I couldn't even install Balatro from the Play Store.
suddenlybananas
2 hours ago
I have similar problems installing region locked apps as someone who's fairly frequently in different regions.
Flip-per
an hour ago
Do you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with.
(for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)
Gander5739
an hour ago
Android apps are signed. Can't you verify the signature?
lucb1e
30 minutes ago
Can you?
I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store
Gander5739
17 minutes ago
Maybe not in practice, but in theory, it works. I don't think there's a better way of handling this without relying on some centralised authority (Google) to validate the authorship of an app, which is hardly desirable.
panja
an hour ago
Doesn't Aurora download the packages directly from Google?
dooglius
35 minutes ago
Presumably the parent does not want to have to trust Aurora to do that
maybewhenthesun
40 minutes ago
The main reason for me to use GrapheneOS would be to sever the umbilical cord to google.
I don't really see the point of using GrapheneOS instead of Stock Android if I then have to use the play store.
jsiepkes
7 minutes ago
There are apps I cannot install via the Play Store in GrapheneOS, only via Aurora store.
amaccuish
3 hours ago
GrapheneOS is focused on absolute security. For those of us on more privacy-oriented ROMs with MicroG, we're very happy with Aurora.
Cider9986
3 hours ago
GrapheneOS is focused on privacy but that must come from a secure baseline.
GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm
How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.
welwala
2 minutes ago
GrapheneOS will always choose security over privacy, even if that means playing into the hands of malicious actors like Google. For example they have stated they won't try to spoof SafetyNet because "we don't lie about security features"
I personally would prefer to have both but choose the privacy side when both are into conflict.
Both viewpoints are valid, but I don't use GrapheneOS for this reason.
dingaling
2 hours ago
The problem is that to achieve privacy through security, Graphene has to treat the user as a potentially hostile actor.
Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.
Ajedi32
an hour ago
Verified boot does indeed make this more complicated, but it's totally possible to build Graphene with your own signing key and get full control over the OS that way (i.e. https://github.com/schnatterer/rooted-graphene).
Looking at their public statements on the matter, it seems like the problem isn't exactly that they treat the user as a potentially hostile actor so much as that they treat the system UI and persistent storage as a potentially hostile actor (though I admit from a practical perspective that's nearly the same thing): https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root...
I wonder how they'd feel about something like protected confirmation to enable sudo: https://source.android.com/docs/security/features/protected-...
Cider9986
2 hours ago
> Which is very much contrary to software freedom.
Yeah, the goal is privacy although the OS is completely open source.
They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes.
You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.
lol768
2 hours ago
> Accrescent is the end goal for a secure and private app store but it's still in alpha
Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.
hadlock
3 hours ago
It seems wise to have at least one alternative mobile phone app store. Even if it isn't very good. If the government can tell Google to do trivial things like, for example, change the name of bodies (plural now) of water, it can turn off your app updates, trapping you on insecure versions indefinitely. This probably matters more if you live outside of the US, but if I had a plan B for an app store on my phone, I would certainly at least evaluate it.
alt227
2 hours ago
The government didnt ask google, they changed the name on the Geographic Names Information System (GNIS), which is the official legal mapping source which other companies like Google etc use. Hence the change filtered down through software from the top official channel.
hadlock
2 hours ago
Right, the government pulled a lever, and google complied within days. If the FTC declares app stores can't provide security updates without government license, that is another lever they can pull, and google will comply.
Wether or not the most recent example is the best example, doesn't matter. What matters is when the government says "jump" in legalese, google's lawyers say "how high?"
arjie
2 hours ago
Name changes happen all the time and I would expect Google to match what the government sources use locally. The fact that the government is capricious is no reason for me to desire Google to become an alternative naming center.
slome
2 hours ago
A Google account is a personal identifier, it is linked to your person. Therefor trying to untie it from anything else is futile.
Google states: Using a false name or incorrect information when creating a Google account is against Google's Terms of Service.
SahAssar
3 hours ago
Having to have a account is absolutely a downgrade and privacy-hostile.
khriss
3 hours ago
> you can sign into the Play Store with a Google Account that isn't tied to anything else.
The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant.
The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past.
talon8635
3 hours ago
Doesn’t Google make it very hard to create an account tied to nothing (no phone or alt email)?
armadyl
3 hours ago
If you create it on a stock Pixel device the phone requirement gets dropped.
talon8635
3 hours ago
It’s undoubtedly tied to the phone with is tied to the owner
gruez
3 hours ago
People report that it works even on grapheneos with sandboxed google play. My guess there's some fingerprinting going on, not necessarily that they're tying the account to some account id.
NewJazz
3 hours ago
I tried and it didn't work, it kept asking for my phone number.
armadyl
3 hours ago
Well yeah. But if you care about anonymity on that level there are ways around that (i.e. buying in cash and creating the account using public WiFi).
weezing
2 hours ago
How is your phone tied to you? You bought it through GOogle store?
kotaKat
3 hours ago
It's the SomethingAwful model: go to the store and find the cheapest Android phone from some prepaid company for :tenbux: then use it to set up your Google account during out-of-box-setup while on the store's free public WiFi (since Google OOBE allows free account creation without a number or existing email), then toss the phone in a drawer afterwards.
"Hope ya got ten bucks!"
(I got a random 5G Moto phone for ~$10 on clearance and it was an absolute shitter of a phone full of garbage packed in malware, but after cleaning and debloating as much as I can, it's at least a nifty toy to poke at Termux or something.)
TeMPOraL
2 hours ago
The "Twitter counter" to that is, "We've detected suspicious activity on your account. To continue, please verify your phone number."
blablabla123
2 hours ago
> GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.
Interesting, I never tried Aurora on Graphene. For me the combination of Play Store and F-Droid worked really well so far.
halyconWays
3 hours ago
"For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else."
lol. lamo, even.