It appears Google tries to degrade alternative application stores to just another app offered through the Play Store, and therefore subject to Google’s policies (including an annual $5,000 fee for policy and security reviews). So I wouldn’t be surprised this is very much intentional: as to force application stores through a channel controlled by Google, to technically allow competition (at Google’s discretion) while ultimately killing “side-loading” through other sources.
Remember when Microsoft was forced to give a “select your web browser” prompt when setting up a Windows computer?
Quaint times, those were…
Misleading title. After reading the linked Gitlab discussion it’s more likely a backend change from Google side. Aurora does use burner account but early reports seem to suggest they are not flagged or rate limited.
How is it misleading?
Google actively blocking Aurora Store would be much worse than them simply changing their backend. The latter can likely be quickly resolved while the former might lead to a cat and mouse game, where it gets increasingly difficult for Aurora Store to continue to work.
And what makes you think it’s the latter and not the former?
Is this sealioning? 🫴🦋
LOL yes, anyone asking you questions you can’t answer about the shit you’re saying is “sealioning”.
The thing is, it’s already been answered. The conclusion was made based on reading the gitlab discussion. 🤷♂️ I didn’t read that myself but maybe try doing that if you’re curious. 😉🫶
The thing is, the conclusion is not going to be in any discussion outside of a Google internal chat or meeting. We know what happened, we don’t know why it happened, or what it means.
The linked gitlab discussion suggests it. There’s intermittent successes, and the particular errors align with a backend change.
Yes. once again, we know there was a backend change. The question is “why was it changed”? We already know Google manipulates YouTube for the explicit purpose of breaking Firefox, adblockers and yt-dlp. Who’s to say this is different? Certainly not anyone on GitLab.
Ah, I think I understand you a bit better. It’s true that the reason for the change is unclear, and it definitely could be malicious. However, that lack of clarity is what makes the OP article title misleading.
The article title claims the certainty that Google has blocked the Aurora store outright. I think you’ll agree that frequent errors with some successes is not the same as an intentional, simple block.
We may find that, yes, Google is intentionally blocking Aurora. It is just misleading to say so at this point.
I noticed these intermittently, but retrying later has seemed to resolve the updates.
all updates were failing to download here.
rebooted the device, and i just tested one update right from the app’s details page and that went on ok. will try the others from the update ui later, after the battery gets charged up.
edit to update: broken. updates not coming in, nor are they one-at-a-time from the app pages, either.
Classic Graphene users, making this all about themselves. This hurts Aurora users, period.
Ironically, this hurts Graphene users the less because they can sandbox their google play services.
Classic Graphene users, making this all about themselves. This hurts Aurora users, period.
Edit: I ran into the same issue. For now, refreshing the anonymous Aurora account solved it.
Well looks like its time to start making alternatives or scream for Linux to come out with a phone.
I’m out of breath by this point. You want to scream now of all times?
Linux phones work, but they depend on many Google Android apps to be daily usable by normal people.
Honestly, at this point we just need alternatives to some of these Google apps in general.
The google apps themselves are largely replaceable, but stuff like banking and communication (WhatsApp, Outlook) is where things tend to get problematic. You can run Android apps in Linux, but it might not be the most convenient thing to keep running at all times, and many banking apps will fail as they recognize the device as “insecure”.
What alternative are you going to make? My bank only publishes their app on Play Store. I can either use Play Store app or Aurora to install it. You think that if you build alternative, open source store my bank will publish their app there? You think any bank will? F-Droid already exists, do you see any banks publishing their apps there? Do you see any of them dong Linux version of their apps?
The alternative here would be some other corporation building independent app store and getting everyone to publish their apps there. Amazon tried that many years ago. Maybe Samsung could do it now. It’s definitely not something we can make.
Thats why we need an alternative.someone, some company, anyone that can make software that dosent rely on Google just to work.
Its crazy that even in the degoogle world, we still have to rely on Google. if the whole point is to not use Google, then what’s the point? We should have our stand alone apps should we not? We can’t make them but someone our there can.
We should have our stand alone apps should we not?
We should but I’m afraid that ship has sailed and without EU’s intervention it’s not going to change. I was trying to buy a train ticket recently and the app for local train requires Google account now. It will just keep getting worse and more and more apps will rely on Google services and require play services and google accounts. This will not be solved by open source apps. Legal solution is required.
Why not use their mobile site?
It’s not as convenient as the app.
I get the issue with the bank apps. Especially if your someone who needs to do a lot of transactions over the phone. But all these other apps, at this point we should have alternatives, its ridiculous.
I was in the same situation, but I slowly started to get rid of android/ios only services. Now my new bank offers every service on their web page + it has very convenient REST API where I can monitor my account.
I don’t know about FOSS stores but banks have been known to make apps and publish them on alternate stores (Samsung, Huawei, Amazon) if there are enough users. Off the top of my head, Revolut and ING Turkey have apps on the Huawei app store right now.
IMO this needs a regulatory push. If the EU encourages or requests EU-based app stores with relevant twists (regional for example), they will appear, and Google will have to accept them, and the banks will put their apps there.
No app developer wants to deal with Google Play, it’s ass and a pain in the. If a company has a local audience (like a national bank) and they get a store that caters specifically to that country and it’s easier to publish (and cheaper) than Google Play, they will use it.
Local stores don’t have to accept all apps, either. They can be regulated stores that are only open to certain entities in that country like banks, government apps, telecom, utility, public transport etc. That would take care of the most immediate needs for their citizens and liberate those from Google’s control.
100% agree that regulatory push is needed. Everything uses an app now and it’s not possible to force all the different developers to support deGoogled devices just by user pressure. There’s simply not enough of us. EU has to treat it as strategic issue for their US tech sovereignty and start acting.
Everything uses an app now
Speaking of which, that’s an issue in itself. The vast majority of “apps” are basically webviews. And yet I’ve seen banks deprecate their website in favor of app-only access, which firmly locks them (and us) into the Google and Apple ecosystem, even when the website and the bank UI are one and the same.
I guess they won’t learn until there’s a major outage. I’ve had apps installed from Play that refused to start and were unusable for a whole week because Google fucked up something accidentally about the dev’s account. If that were to happen to a bank’s app they’d understand the issue. Especially if it’s one of the banks that are exclusively online, like Revolut.
On one hand apps are convenient. It’s nice to have my flight info and boarding passes on my phone when traveling. It’s nice to confirm my transaction with a finger print instead of writing codes that I get in SMS. It’s nice to buy a ticket in my app rather than stand in like to some machine. But it’s only nice when it works without tracking and mandatory google accounts. More and more apps are tied to google but since almost everyone is using them the alternatives (like websites) are slowly disappearing.
PostnarketOS sends their regards
But does it actually work like a phone? Calling, texting, no issues?
entirely depends on the phone and the setup you go with, postmarket is kinda more of a platform than a single specific OS, like if fedora made you choose one of their spins.
I’ve only used it on a pinephone (which isn’t exactly the ideal hardware…) and my experience on that was that you could probably survive using it as a fancy feature phone.
See that’s my gripe with Linux. I don’t want a PDA, I can do all of that tinkering on PC.
uhhh… yeah but even a laptop isn’t portable enough to put in your pocket, lol. They also generally can’t make phonecalls.
Thats why there are PDAs and Cyberdecks. Thats for that purpose. Cant make phone calls but its portable but for Linux mobile it should at least get that right.
It’s on fdroid.
I recommend blocking play store.
They are not blocking the download of the app from playstore. It was obviously not available there in the first place. They blocked API access to the google servers where aurora store was getting the apk files from. They just killed the concept of aurora store (and any alternative playstore frontend) entirely.
What?
What is on fdroid??
this app called ‘aurora store’ which is a foss playstore client
Seems like clickbait but the graphene devs recommend against aurora store in favor of using a second profile with the sandboxed play store
The Play Store requires a Google account. Using a second profile is extremely inconvenient.
Graphene recommending this at all is extremely sus. My objective of using your operating system is to avoid giving Google any information I possibly can. Don’t know why they always recommend using Google shit in a sandbox like those packets aren’t still coming from my IP.
Its not sus. They’re just hyper-aware of security. And Aurora is just not terribly secure. Its just that you’re now choosing between privacy and maximum security. And I prioritize privacy, personally.
They pretty much only recommend Accrescent.
I agree. Specifically, it’s privacy AND freedom (free software development model).
If these two are against maximum security, GrapheneOS consistently chooses security. Which is unfortunate for me, because I would consistently choose freedom. (Especially due to long-term considerations.)
You can disregard their recommendation if you wish, I do sometimes. If they were here, I imagine they’d say they don’t see privacy and security as contradicting each other, just that there are different threat models. I think they subscribe to the idea that not everyone is going to be sufficiently informed in order to make a rational judgement, so instead they default to lowering potential risk. They do value accessibility for the tech illiterate as well.
how is Aurora less secure than PlayStore directly? GOS devs literally never make sense, and of course they recommend a app store that doesn’t even properly label non open/free apps distincly, it is not like they evwr cared about FOSS just vague “security” theater
because aurora store isn’t developed by a big team of professionals with a massive budget, and aren’t getting security audits by other teams of well-funded professionals.
the point isn’t that aurora store is insecure, the point is that the play store is VERY secure (it’ll just also merrily sell your data to palantir)
Isn’t the aurora store just a wrapper around the play-store using an anonimized account? That is exactly the reason that google can easily block them. They obviously found a way to stop the burner accounts that Aurora makes from accessing the store. It would be equal to making a container for each time you renew the anonymous account.
In other words, unless the aurora app has a backdoor (and I believe it is FOSS, so that should show itself easily), it is as secure as the play store ( which has debatable security, I believe it served malware on several occasions )
But please correct me if I’m wrong
AFAIK aurora store is a completely separate implementation, it’s certainly not based on the play store in any way since it’s open source.
If your threat model includes Google as a trusted party, you’re an untrusted party to me.
It is sus that they privilege Google software in so many ways over other FOSS implementations. Saying “well Google can be trusted to be reasonably secure” is not an excuse for anyone who considers Google to be one of the primary parties they wish to keep their information away from.
I have a lot more trust in F-Droid because they take a principled stance against Google. Maybe their software is not as high quality as GOS devs would insist, but I can trust that they will not act against my interests, far more so than the GrapheneOS project.
because graphene devs don’t know what they are talking about, they never do
where’s your Pegasus-proof OS, then?
Nothing is 100% pegasus/quadream/candiru proof. Up-to-date and BFU Graphene is Cellebrite proof, though.
It’s working fine for me while logged in. It’s always been crap when logged out. This is nothing new.
Isn’t the whole point of it to get apps without login/anonymously?
Install it so I don’t have to have Google Play. Yes, Google can see what apps I have installed, but they don’t have their code running on my device. I consider it a 99% harm reduction.
I hadn’t considered that. I might have to do that myself now that you mention it
for some people maybe, but if that was the whole point of the project then why would they even have the option to log in?
- GrapheneOS isn’t John Android. Stop black and white thinking. You don’t have to fit in with people when you post to .ml.
- If you have read the thread you are posting (relevant message 18 hours ago as opposed to this post 13 hours ago), you would have seen that you can just press “reload accounts” to fix it.
people treating graphene like the only android OS drives me up the fucking wall, i’m sure it’s great but holy SHIT lineage has existed for years and years but… now it’s suddenly irrelevant?
Leaves a bad taste in my mouth
Lineage and GrapheneOS are not even in similar levels here. Yes, LineageOS (or any of its commercial forks) is great I’d you have anything other than a Pixel phone. Definitely beats having any stock Android. But having the choice and telling people that “GrapheneOS is not the only option” without context is intentionally guiding people that could potentially have a much more secure and way more private mobile experience look somewhere else just “because”.
I don’t pretend to know what tour reasons are, could be because of Micay, could be because the GOS team of developers has no filter, I don’t know. But even Louis Rossmann, who openly chose to get away from GOS because of Micay’s actions has said, time and again, that nothing even comes close.
Just wait til the next time you’re arrested and the cops easily get into your phone.
yeah, regular AOSP-likes that need you to manually flash them after support for your device is finally added are not particularly relevant compared to a security-focused fork that’s supported by several flagship phones at release. the latter can actually make it into the hands of the average person. the former, not so much. imagine trying to explain to your elderly mother how to flash lineage onto her phone.
Which flagship phones support graphene OOTB with no bootloader unlocking? I certainly haven’t seen any
GrapheneOS and Motorola are currently working on making their next flagships launch with GOS out of the box.
Keyword: currently working on
Downgraded to Aurora Store 4.8.3 and now working well for the moment.
So that is why my Aurora store have been having trouble latley :(
How time flies, happy 1st cake day :)
Thanks! It has been a wonderful year here on the Fediverse!
I was wondering cant we just scrape Play Store and distribute the apks on a different website? most apks has checksums so we will know nobody has changes the apk
and distribute the apks on a different website
Or with distributed technologoes such as torrents. Then it’s cheaper to operate any required servers.
And also if a server goes down there are still dozens of seeders ready to seed you the files
this would be an ideal use case for IPFS, since that returns the same content address even if you upload something completely independently. I.e. no need for specific torrent files, just upload whatever apps you got and you’ll automatically be helping existing uploads.
(with the one caveat that you need to use the same settings, but if everyone uses the defaults that’s not a problem)
There are a bunch of sites like apkmirror etc. that do that but eventually the large ones started enshittifying their service. On apkmirror for example you used to be able to just download the apk’s, now they’ve invented a special “format” that can only be installed through their app. Needless to say that was the end of that, I’m not keen on giving install capability to any more apps than I absolutely have to. (Zero is the ideal answer in case you’re wondering, but in practice it’s usually one, the system file manager. Any other app can download apk’s to /Downloads or go fuck itself.)
For info - there is an alternative to APKMirror’s app On F-Droid. Still not ideal, but better than their proprietary nonsense.
now they’ve invented a special “format” that only can only be installed through their app
If I’m not mistaken, that’s the .apkm bundles right? That’s not their own format but another one Google invented to be able to dynamically install only the relevant parts of an app for a specific device type, locale, etc.
Android can’t install this on it’s own (I wonder who’s fault that is 🙄) but it can be installed via adb or through special installer apps like the Play Store, Aurora or I’m assuming the APKMirror app
That’s what a few sites like apkpure do…
That’s insecure
It is if you use cryptography or cryptographically secure hashing.
just tested it, at first i got rate limited(?) “server busy” but a minute later the updates went through fine
Yup can confirm. Some apps return this error (example tutamail and windscribe vpn). Fix it by downloading the apk in fdroid or github/ gitlab directly.
Aurora still works for me for now on Samsung stock OS. I now mostly install Google Play apps with APKPure over Obtainium tho and only use Aurora for those not on APKPure. And most of my apps are from GitHub/GitLab releases and F-Droid. I disabled Google Play and didn’t login to Google account. I don’t want the requirement of a Google account to install an app and Play Integrity to run an app. It is by no means acceptable that a company, using a closed source implementation that also tracks user and breaks Android security model, can censor what apps a user can install and decide what security and privacy compromises a user needs to agree to just use the normal phone functionalities that they pay for and by no mean require those compromises technically. They are turning Android into a service and a prison like iOS did rather than a software.




















