24 comments

  • pyrophane 3 hours ago
    GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.

    For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else.

    • ravenstine 1 minute ago
      GrapheneOS (the project) might recommend for or against certain things in relation to their specific objectives, but that doesn't mean all GrapheneOS users have the same objectives or need to comply with the opinions of GrapheneOS.

      For instance, I use GrapheneOS because it provides better security and privacy out of the box than LineageOS, but I'm also not so paranoid that I'm going to just blindly listen to advice against using F-Droid. What I want out of my Android instance is good security defaults with no bloatware, not to stop the NSA from looking at my travel photos and what HN articles I once looked at. It's okay if my OS is great but not perfect.

      So yes, I am a GrapheneOS user who is [modestly] hurt by this. Signing in with a dummy account is just another one of those things that will end up being futile in years to come when Google requires iris scans, DNA samples, and anal probes in order to get a new account. Personally, I'd prefer installing whatever software I want on whatever devices I [pretend like] I own, without telemetry or jumping through hoops.

    • DaSHacka 2 hours ago
      Although the nice thing about Aurora Store is it allows you to install apps without a google account linked to your device, keeping Google Play Services signed-out.

      Somewhere in the FAQ GOS advertises that Play Services can be used without signing in, but they also recommend the official Play Store (which requires signing in) and explicitly don't recommend Aurora (which doesn't).

      Unless I'm missing something, I don't see how you can functionally use Play Services signed-out when in order to obtain those apps in the first place, you need to sign into a Google Account for Google Play.

      That's personally what I used Aurora for, plus as an easy way to export APK files.

    • juiceland 2 hours ago
      > Google Account that isn't tied to anything else.

      At the risk of being a privacy absolutist / fatalist: Google’s entire business model is surveillance. They follow you around and track your habits so you can be influenced. Given that, a Google account is always tied to something else.

      • tredre3 1 hour ago
        I'm under no illusion that google doesn't know I own my multiple accounts. They most certainly do. I usually use the same user agent (with containers) on the same IP, after all.

        But my goal is to avoid a stranger gaining access to my google services if they manage to unlock a lost device or steal my TV/streaming box that has no lock at all.

        I wish Google supported a permission system per device. For example on most of my android devices all I really want is to be logged into Youtube and the play store. I most certainly do not want those devices to have access to my contacts, emails, calendar, keep, drive, payment, etc. (I don't personally use all of those things, but you might and that's what a random thief would gain access to.)

        • deepsun 1 hour ago
          Yep, something like checkboxes on login:

             - ALL: Log me in to all Google Services
             - Calendar
             - GMail
             - YouTube
             - ...
          
          Adding more would require to login anew.
      • josefresco 2 hours ago
        Piggybacking on this... I create my fair share of "burner accounts" and almost always they (not just Google) connect it to my true identity. Granted I'm not using VPNs or really trying to hide the connection but it seems trivial for them to associate.
        • Forgeties79 2 hours ago
          My experience has been that all the consumer privacy/security tools are varying degrees of “good” at keeping away bad actors, trackers, advertisers, and most third parties, but when it comes to the big dogs, there’s nothing you can really do to stop them. Google, Facebook, etc. just have too many data points already available to them so they can easily build a picture of you. There are simply too many services that have them running around in the background or just straight up depend on them.

          All you can do is leave their ecosystem as much as you can and accept you will never be fully rid of them

      • henryfjordan 1 hour ago
        Google's business model is providing you services that are excellent, while also providing advertisers access to your willing eyeballs when you use those services.

        Yes, the advertising targeting is incredibly invasive, but let's not pretend they aren't providing world class Search, Email, Docs, Maps, Video (YT), etc in exchange.

    • maybewhenthesun 5 minutes ago
      The main reason for me to use GrapheneOS would be to sever the umbilical cord to google.

      I don't really see the point of using GrapheneOS instead of Stock Android if I then have to use the play store.

    • joekrill 2 hours ago
      > a Google Account that isn't tied to anything else.

      Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.

      • megagpt1 2 hours ago
        You can create an account with no phone number during Android device setup.

        You can also just get a burner phone number for a few bucks.

      • armadyl 2 hours ago
        Accounts created on stock Pixels don’t require phone numbers.
        • iririririr 2 hours ago
          that haven't been true since pixel 4. it just picks your phone in the background.

          a burner sim, like a literal criminal, is the only way today.

          • asnelt 2 hours ago
            Even with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission.
            • exceptione 2 hours ago
              That can't be true? <https://grapheneos.org/faq#hardware-identifiers>

                As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.
              
                Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.
              
              
              I don't know however if sandboxed google play is such a privileged app.
              • asnelt 2 hours ago
                I couldn't immediately find whether GrapheneOS grants READ_PRIVILEGED_PHONE_STATE to Google Play. It might very well be that the GrapheneOS sandbox spoofs a fake IMEI, and I do hope so.

                In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.

                • nickspacek 1 hour ago
                  https://grapheneos.org/usage#sandboxed-google-play

                  > Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.

                  It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."

                  • exceptione 1 hour ago
                    There is an AppStore app, I am not sure if this is the one we are talking about? <https://github.com/GrapheneOS/AppStore/blob/main/app/src/mai...>

                    That one lists:

                      ACCESS_NETWORK_STATE
                      ENFORCE_UPDATE_OWNERSHIP
                      FOREGROUND_SERVICE
                      FOREGROUND_SERVICE_SPECIAL_USE
                      INSTALL_PACKAGES
                      INTERNET
                      POST_NOTIFICATIONS
                      QUERY_ALL_PACKAGES
                      RECEIVE_BOOT_COMPLETED
                      REQUEST_DELETE_PACKAGES
                      REQUEST_INSTALL_PACKAGES
                      UPDATE_PACKAGES_WITHOUT_USER_ACTION
                    • gruez 1 hour ago
                      That's grapheneos's own app, separate from the play store or play services.
                      • exceptione 44 minutes ago
                        True. I think this one is closer to the truth: <https://github.com/GrapheneOS/platform_packages_apps_GmsComp...>

                        There is no READ_PRIVILEGED_PHONE_STATE mentioned there.

                        • gruez 2 minutes ago
                          That's also incorrect, because the gmscompat app is just a helper app. Play services can and does request additional permissions. Those permissions are handled by the OS under the play services app, not gmscompat. If you want RCS for instance, you must grant play services and google messages phone and ICC auth access, which isn't seen in gmscompat at all.
              • mindslight 1 hour ago
                That's the application software side. I would assume the IMEI and IMSI are both going out to the cell network though, and I would presume that it's trivial to tie a phone number to those with how the mobile industry generally sells subscriber data to various data brokers. The only question is how permissive those data brokers are (their major constraint is how much most people become aware of this dynamic), but when dealing with a major APT like Google I'd assume they're tuned into the best ones with songs about bona fide purposes.
                • exceptione 1 hour ago
                  Are you talking about the US here? I am hoping this would be off-limits in Europe.
                  • mindslight 23 minutes ago
                    Yes I am talking with a US perspective. I would hope the GDPR would prevent such things in (most of) Europe. But I also personally wouldn't assume so given that there are still the same dynamics of keeping the info flows private to avoid scrutiny, and claiming plausible "legitimate purposes" and "consent".
          • alt227 1 hour ago
            Its possible to set up a phone with a google account without even a sim card in it and use it as a wifi only device, so Im pretty sure what your saying is wrong.
          • goodmythical 2 hours ago
            assuming the number you get hasn't previously been assigned to a google account
            • drxzcl 1 hour ago
              I've had no end of trouble registering an account on our corporate SIMs as the phone numbers (not the actual SIM cards) had been recycled as employees leave.
              • edoceo 45 minutes ago
                So many systems cannot handle known pattern of a phone number changing. Who's decided these are imutable values? That I have only one? That it's not shared?
          • megagpt5 1 hour ago
            It still works without a SIM card, how do you explain that?
    • dmantis 2 hours ago
      Sometimes you just can't.

      For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.

      The check seems to be purely store-based and never enforced later.

      • CivBase 1 hour ago
        This is exactly why I switched to Aurora. I couldn't even install Balatro from the Play Store.
      • suddenlybananas 1 hour ago
        I have similar problems installing region locked apps as someone who's fairly frequently in different regions.
      • Flip-per 51 minutes ago
        Do you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with.

        (for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)

        • Gander5739 19 minutes ago
          Android apps are signed. Can't you verify the signature?
        • panja 34 minutes ago
          Doesn't Aurora download the packages directly from Google?
          • dooglius 1 minute ago
            Presumably the parent does not want to have to trust Aurora to do that
    • amaccuish 2 hours ago
      GrapheneOS is focused on absolute security. For those of us on more privacy-oriented ROMs with MicroG, we're very happy with Aurora.
      • Cider9986 2 hours ago
        GrapheneOS is focused on privacy but that must come from a secure baseline.

        GrapheneOS is much more privacy focussd than any other mobile operating system. Accrescent is the end goal for a secure and private app store but it's still in alpha. GrapheneOS is also the best for degoogling (eliminating all google services) because it comes with zero Google services unlike all the other ones listed here: https://eylenburg.github.io/android_comparison.htm

        How can you call other OSes more privacy focused when they haven't closed as many VPN leaks as GrapheneOS? That's like bare minimum for privacy.

        • dingaling 1 hour ago
          The problem is that to achieve privacy through security, Graphene has to treat the user as a potentially hostile actor.

          Therefore, the system needs to protect itself and other apps from the user. Which is very much contrary to software freedom.

          • Ajedi32 14 minutes ago
            Verified boot does indeed make this more complicated, but it's totally possible to build Graphene with your own signing key and get full control over the OS that way (i.e. https://github.com/schnatterer/rooted-graphene).

            Looking at their public statements on the matter, it seems like the problem isn't exactly that they treat the user as a potentially hostile actor so much as that they treat the system UI and persistent storage as a potentially hostile actor (though I admit from a practical perspective that's nearly the same thing): https://www.reddit.com/r/GrapheneOS/comments/13264di/is_root...

            I wonder how they'd feel about something like protected confirmation to enable sudo: https://source.android.com/docs/security/features/protected-...

          • Cider9986 1 hour ago
            > Which is very much contrary to software freedom.

            Yeah, the goal is privacy although the OS is completely open source.

            They do improve user experience by allowing disabling emergency alerts, call recording without alerts, no mandatory camera noise in Japan, no extra warning popup from installing APKs from the web (it's the same permission in every app store iirc), increases password length to 128 digits. All the network services are open source afaict while all the other mobile operating systems listed in that android comparison connect to Google's closed source services, netowrk permission, sensors permission, storage scopes, contact scopes.

            You can still easily install whatever Android app you want on GrapheneOS and you can install dangerous apps like shizuku and apps with way too many permissions. But yeah the goal is privacy so that everyday people can protect themselves as well as journalists can protect themselves. I want journalists to get the best privacy possible without having to know a ton of technical things or making many choices.

        • lol768 1 hour ago
          > Accrescent is the end goal for a secure and private app store but it's still in alpha

          Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.

    • slome 1 hour ago
      A Google account is a personal identifier, it is linked to your person. Therefor trying to untie it from anything else is futile.

      Google states: Using a false name or incorrect information when creating a Google account is against Google's Terms of Service.

    • SahAssar 2 hours ago
      Having to have a account is absolutely a downgrade and privacy-hostile.
    • hadlock 2 hours ago
      It seems wise to have at least one alternative mobile phone app store. Even if it isn't very good. If the government can tell Google to do trivial things like, for example, change the name of bodies (plural now) of water, it can turn off your app updates, trapping you on insecure versions indefinitely. This probably matters more if you live outside of the US, but if I had a plan B for an app store on my phone, I would certainly at least evaluate it.
      • alt227 1 hour ago
        The government didnt ask google, they changed the name on the Geographic Names Information System (GNIS), which is the official legal mapping source which other companies like Google etc use. Hence the change filtered down through software from the top official channel.
        • hadlock 1 hour ago
          Right, the government pulled a lever, and google complied within days. If the FTC declares app stores can't provide security updates without government license, that is another lever they can pull, and google will comply.

          Wether or not the most recent example is the best example, doesn't matter. What matters is when the government says "jump" in legalese, google's lawyers say "how high?"

      • arjie 1 hour ago
        Name changes happen all the time and I would expect Google to match what the government sources use locally. The fact that the government is capricious is no reason for me to desire Google to become an alternative naming center.
    • khriss 2 hours ago
      > you can sign into the Play Store with a Google Account that isn't tied to anything else.

      The problem with this is that increasingly Google is insisting on having a phone number to create a Google account. Further, they are aggressively deleting old accounts that appear to be dormant.

      The good old days of creating a Google account with just an email seem to be swiftly becoming a thing of the past.

    • talon8635 2 hours ago
      Doesn’t Google make it very hard to create an account tied to nothing (no phone or alt email)?
      • armadyl 2 hours ago
        If you create it on a stock Pixel device the phone requirement gets dropped.
        • talon8635 2 hours ago
          It’s undoubtedly tied to the phone with is tied to the owner
          • gruez 2 hours ago
            People report that it works even on grapheneos with sandboxed google play. My guess there's some fingerprinting going on, not necessarily that they're tying the account to some account id.
            • NewJazz 2 hours ago
              I tried and it didn't work, it kept asking for my phone number.
          • armadyl 2 hours ago
            Well yeah. But if you care about anonymity on that level there are ways around that (i.e. buying in cash and creating the account using public WiFi).
          • weezing 1 hour ago
            How is your phone tied to you? You bought it through GOogle store?
        • burningChrome 2 hours ago
          [flagged]
      • kotaKat 2 hours ago
        It's the SomethingAwful model: go to the store and find the cheapest Android phone from some prepaid company for :tenbux: then use it to set up your Google account during out-of-box-setup while on the store's free public WiFi (since Google OOBE allows free account creation without a number or existing email), then toss the phone in a drawer afterwards.

        "Hope ya got ten bucks!"

        (I got a random 5G Moto phone for ~$10 on clearance and it was an absolute shitter of a phone full of garbage packed in malware, but after cleaning and debloating as much as I can, it's at least a nifty toy to poke at Termux or something.)

        • TeMPOraL 1 hour ago
          The "Twitter counter" to that is, "We've detected suspicious activity on your account. To continue, please verify your phone number."
    • blablabla123 1 hour ago
      > GrapheneOS actually recommends against using Aurora and instead just using the Play Store, so this shouldn't really hurt users.

      Interesting, I never tried Aurora on Graphene. For me the combination of Play Store and F-Droid worked really well so far.

    • halyconWays 1 hour ago
      "For extra privacy, you can sign into the Play Store with a Google Account that isn't tied to anything else."

      lol. lamo, even.

  • troyvit 2 hours ago
    I use Aurora on GOS. I get that they say sandboxed Play is more secure than Aurora, but I prefer it for its lack of toxicity and absence of shitty dark patterns.

    I think the increased popularity of GOS is going to draw in more users like me who picked it for reasons adjacent to Graphene's original purpose, and I hope it's not too annoying for their community.

    • DaSHacka 2 hours ago
      I actually think there's already a lot of us in the 'community' as-is. I personally describe it as 'Valuing Privacy/Freedom over Security'. One pretty clear example of this is how they don't recommend using FireFox Mobile and F-Droid, both of which I use regardless because I'm not willing to put up with worse privacy/usability tradeoffs in the name of (imo 'hyper-')security.

      I think it's fine the mission of the project isn't directly aligned with some of us, though I can tell we often get on the core contributor's nerves lol

      • Borealid 54 minutes ago
        They're both security, just security "against" different things. Graphene frequently fails to clearly describe the threat model when calling something "more secure".

        For example, let's say hypothetically I want to be secure against the threat of Google pushing a targeted update to my phone that runs malicious code. Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat. But Graphene devs say things like "MicroG is less secure than Google Play Services".

        Similarly, if you want privacy you might secure your device by locking the bootloader with your own keys - not a third-party vendor's keys. Saying that's "insecure" is extremely misleading: it just puts you in charge of security, instead of abdicating to someone else.

        I wish there were something like GrapheneOS that let you choose, yourself, who to trust instead of requiring you trust an OS vendor implicitly.

        • exceptione 27 minutes ago

            >  Turning on automatic software updates from Google would make me vulnerable to that threat. Using MicroG instead of Google Play Services would make me less vulnerable to that threat
          
          I would say that any auto-update mechanism is a threat, so in both cases you would disable auto-updates.
      • megagpt5 1 hour ago
        They actually ban people from their Discord (which is their official support channel - so much for privacy/security!) for mentioning F-Droid. I'm starting to think the creator of F-Droid must have run over their dog.
      • unrented7977 1 hour ago
        This is the exact reason I quit using Graphene. It felt exactly like selling out control of my device to the Graphene devs in the same way a stock phone is controlled by Google.

        Far, far too "opinionated" for my taste. I frankly do not need the hyper paranoid security features like a hardened memory allocator or disabled root. I would rather be able to use my device the way I want, even if that's notionally "less secure".

        I really wish there were another option. Lineage is too far in the opposite direction and feels like ad-blocked stock. Google still owns my phone, there's just a more pleasant coat of paint on it.

        • seany 1 hour ago
          they do similar things for people trying to use magisk, but also relock the boot loader. I gave up trying to bother, since the whole reason I use roms is for root first, privacy second.
        • throawayonthe 1 hour ago
          > hyper paranoid security features

          > disabled root

          ah yes

      • titularcomment 2 hours ago
        FYI, there are ungoogled chromium builds for Android. Firefox Mobile really is a lackluster browser unfortunately both from a usability and security standpoint (e.g. IonStack worked on Fennec)
        • Semaphor 1 hour ago
          I really like the Firefox usability. For what I do it works great. It has uBo and a bunch of other extensions, and if course it can sync with desktop.
        • tpm 1 hour ago
          I'm using Firefox mobile for many years exclusively (since chrome forced some stupid feature on me, I think it was tab groups which I hated and couldn't turn off. And of course no ubo). Could be a bit faster probably? Otherwise don't see any issues.
    • flexagoon 2 hours ago
      > I hope it's not too annoying for their community

      There's plenty of people like that in the GOS community (the forum and the Matrix). Everyone generally understands that different people have different threat models and may want to do things that aren't the most secure. Otherwise everyone would be using GOS in airplane mode with disabled cameras and only paying for things with Monero.

      The core dev team is obviously a bit more security absolutist, but even they usually dont mind

  • kjander79 3 hours ago
    I feel the title editorializes a bit too much. The thread only confirms the bug, not a specific cause yet. As sibling comments indicate, the effect on GrapheneOS users is undetermined.
    • titularcomment 2 hours ago
      This is standart, and happens constantly with Invidious (youtube frontend). This happened before on AuroraOSS too. They probably just flagged the accounts and no API change or A/B testing an API change.
    • kevincox 1 hour ago
      This also has nothing to do with GrapheneOS except for some user overlap.
    • aniviacat 2 hours ago
      For me, the issue also only occurs sometimes. Usually I can download apps like normal.
  • skeledrew 2 hours ago
    I've been stuck with unupdated apps because Aurora hasn't been working for me for a while. A few of them have been nagging me to update. I have everything Google disabled or removed, and no I won't reenable any of it. Also I use anon strictly on Aurora, and no I won't login with my Google account; haven't logged in on a phone for over 8 years now and I have no intention of breaking the streak.
  • ssernikk 1 hour ago
    I maintain my grandmothers phone, which comes down mostly to just updating WhatsApp once in a while. Obviously she doesn't have a google account, so I've installed her AuroraStore.

    It's a shame that there is no official way to install apps on android without a google accout[1], since it's a basic functionality, just like calls or a web browser.

    [1] For obvious reasons I don't want her to download apks from the internet.

    • lern_too_spel 54 minutes ago
      App verification means she can safely install apps from the Internet. The app developers can simply serve the apks from their own websites.
    • catlikesshrimp 1 hour ago
      I am in the same boat. Keep in mind that you are trusting both google and meta. At least you can update whatsapp once every three months (for now)
      • alt227 1 hour ago
        Is it not possible to just download the updated whatsapp apk from some online source? That is the benefit of android after all, side loading is still possible relatively easily.
        • iAMkenough 27 minutes ago
          I'll be your random online source if you want. Just give me a few days to work on an APK for you to download and install.
          • crtasm 3 minutes ago
            How do you plan to get Meta's private signing key so Android will allow it as an update?
  • denzen 2 hours ago
    Using lineageos on an old samsung without any google services, I guess this would impact many "degoogled" users as well
    • nosioptar 1 hour ago
      Running LOS on some kind of oneplus.

      Aurora hasn't worked right for the most part for a year due to device attestation shit.

      I'm meh on it. Not being able to install the shit from play store isn't such a bad thing. It is lame as hell that Google is doing their damndest to make apple look user friendly.

  • CodesInChaos 2 hours ago
    For me anonymous use of Aurora never really worked, and with a google account it still works.
  • krunck 1 hour ago
    Yep broken on my /e/OS device too.
  • erikvanoosten 1 hour ago
    Okay, it was a bit of clickbait. Didn't expect it to be picked up like this.

    Mistake from me: apparently GrapheneOS does not recommend Aurora Store (citation needed). Kind of weird though; it means Google still knows a lot about you, which doesn't seem very privacy conscience.

    Google blocking Aurora Store was a conclusion made in the bug thread. It was not my conclusion.

    And for the nit pickers: Sailfish OS is not Android, but its emulation layer _is_. :shrug: Even though Sailfish is nice, without its Android layer it is practically unusable.

    Funny thing: the 'busy server' problem existed for almost a week. I could download 1 app per day max on my Jolla C2. But just now, now that this thread makes top of Hackernews, everything started working just fine!

  • westurner 41 minutes ago
    Web Native then. App Stores are lame anyway.

    Try and find a category for "open source" apps on any app store.

    • Ajedi32 5 minutes ago
      On F-Droid that's just the entire store.
  • ChrisArchitect 2 hours ago
    Title is: Aurora Store returns a “&$Server busy, please try again later.” error
  • thataccount 1 hour ago
    Looks like the same thing is true for Calyx.
  • ChocolateGod 2 hours ago
    So an app that uses an unofficial API broke when that API changed?

    Not news nor "blocking".

    • berkes 1 hour ago
      What is an "official API"?

      Honest question, because AFAIK there's no guarantee or (legal) requirement to support any API. Whether that's fully documented, has SDKs or whether it's something reversed-engineered doesn't matter WRT the support the company owning the API is supposed or required to give.

      Or am I wrong there?

  • kotaKat 3 hours ago
    Didn't Epic get some kind of magic injunction saying that Google had to allow open access to the entire Play Store catalogue or something?
    • megagpt2 2 hours ago
      But not for everyone for free. What it means is Epic, or anyone like Epic, will be able to write to Google, send a nominal amount of money, and get some API key and bare documentation which is only allowed to be used in Epic. It's a B2B commercial transaction under court-ordered terms, not an open API. Same as the Apple browser API. If you want, you can register a company "Kotakat App Store Inc" and get access to the same terms but you'll probably need to sue Google to make them give you access. Apple hasn't approved any browsers, either.
    • berkes 1 hour ago
      Also, EU is pushing towards more "open" app-stores through anti-trust.

      Not that it requires Google to "open up" their play-store, but that they must allow other app-stores to work on the same level. So basically allowing devs and users to move elsewhere.

      • zoobab 1 hour ago
        Well, i emailed the DMA team at the European Commission, they don't plan to do anything to Keep Android Open.

        Apple moved first with making a special 'sideloading' case for apps not under their control, Google is just copying what they did.

        No more free sideloading.

    • megagpt5 1 hour ago
      They did, but you still have to sign a contract with them to get access.
  • _leom 2 hours ago
    This happened to me but then got fixed the day later
  • zoobab 1 hour ago
    From bad to worse.
  • okokwhatever 1 hour ago
    Sadly I'm gonna have to migrate again to an ios device...
  • ranger_danger 2 hours ago
    > Aurora uses burner account for anonymous login. looks like their account pool is flagged

    This seems like it was destined to get banned somehow... and I don't think it means that the store itself is blocked, just the pool of accounts they (ab)use.

  • lenerdenator 1 hour ago
    Remember when people kept justifying Android over Windows Phone/Maemo/WebOS/BlackBerry/FirefoxOS on the grounds that it was free and open source software, infinitely customizable, and that Google was a good-faith partner who wanted openness in the mobile market?

    Good times, good times.

    • catlikesshrimp 1 hour ago
      AOSP is still open. The problem is nobody wants to bear the (monumental) cost of polishing and convincing brands to allow installing it in THEIR devices. Google was motivated back then for creating an alternative and openness was a good bait.
      • lenerdenator 30 minutes ago
        The fact that no one wants to bear the cost to pre-load it on devices, when combined with the fact that it's not nearly as easy to install OSes on mobile devices as it is on most laptop/desktop/server machines, means that it might as well be closed-source. The point of software is to be executed. If I don't have a good way to execute the software for its intended purpose, I have a collection of ones and zeros, and nothing more.

        The window to have a real open mobile OS is starting to close. If there is to be a meaningful change, it must happen soon.

  • shevy-java 2 hours ago
    Google becomes more and more evil by the second now.
    • hluska 1 hour ago
      That’s quite the conclusion to derive from a Gitlab issue. Do you mind sharing your thought process or was that just a knee jerk reaction without any reasoning behind it?
  • v1z 2 hours ago
    [dead]
  • erikvanoosten 3 hours ago
    Android distributions that recommend AuroraStore (such as Graphene OS and Sailfish OS) are now mostly blocked by Google Play Store.
    • dxjxjdjsssb 3 hours ago
      Play store works just fine on GrapheneOS. All of play services run in a sandbox.

      You can install the Play store from the GrapheneOS App Store.

      In fact I'm pretty sure the GrapheneOS folks advise against Aurora Store, etc.

      • himata4113 3 hours ago
        The entire point is so you don't have to have a google account. Aurora actually works fine if you do sign in. This is just blocking anon downloads.
        • megagpt2 2 hours ago
          Market price for a Google account is about $1.50, you can also buy a burner SIM to set up the maximum number of accounts Google will let you with the same phone number.
      • imzadi 3 hours ago
        Yeah, was confused. I'm on GrapheneOS and don't even know what Aurora is.
        • CodesInChaos 2 hours ago
          It's an alternative client app for the google store.
    • JoshStrobl 2 hours ago
      Sailfish OS user on Jolla Phone 2: Aurora is working fine here.

      P.S. Sailfish OS is NOT an Android distribution. It is a proper Linux system and they have their own custom Android runtime (AppSupport) as a layer on top for running Android apps. This runtime _is_ Android under the hood, but is separate from Sailfish itself (has its own native app ecosystem).

    • bushwart 3 hours ago
      I wasn't aware GOS recommended AuroraStore.
      • Cider9986 2 hours ago
        They don't. It's unreliable but they have fixed security issues.
    • Cider9986 2 hours ago
      Play store works fine on GrapheneOS.
    • iAMkenough 3 hours ago
      AuroraStore uses a pool of burner Google Play Store accounts to facilitate anonymous downloads. This is what happens when those burner accounts get flagged.
      • ErenayDev 2 hours ago
        I'm using my Proton account in my phone and in play store. now i tried adding my proton account in AuroraStore, and it worked flawlessly. so my question: why AuroraStore uses google accounts instead of another providers?
      • ranger_danger 2 hours ago
        How does one even create a new google account in $current_year without requiring phone verification or worse?
        • megagpt2 2 hours ago
          You could suck it up and do the phone number verification, it usually costs around $5 for a phone number.

          Or you could go through the android phone sign-up process which doesn't require one. Buy a cheap android phone and keep resetting it and making a new account each time.

          Or you could buy an account on the grey web from someone who already did this. Should be under $2.

          If you are really into this you could become a phone company and own a whole block of phone numbers.

          • ranger_danger 1 hour ago
            The whole point of avoiding the verification in my case is for privacy reasons... I don't want google or anyone else tracking what I do through the use of an account.

            > Or you could go through the android phone sign-up process which doesn't require one

            This is worse IMO because now the number is associated with that device forever. And unless I'm willing to risk my account to compromise from a future owner of the same number OR device, I must now keep both... forever.

            > grey web

            I don't want to give them my info either, nor have my account associated with sketchy individuals.

            > you could become a phone company

            I do own DID blocks but this is unhelpful because google's verification specifically requires SMS over real mobile numbers, and I'm not interested in becoming an MVNO or cellular carrier.

    • savwolf 3 hours ago
      GOS recommends play store