MicroG – Re-implementation of proprietary Android apps and libraries
microg.org
microg.org
My current phone no longer charges and I've already replaced so much stuff on it (back, camera, etc.) that I'm deciding to go the KDE Plasma route, starting with a new old-stock Nexus 5X.
I hope the Purism 5 and Pinephone get released as well. I really want to go the Plasma route. If there is tooling I need that's missing, I hope it will force me to write and contribute apps that can help myself and others.
We need a real open source mobile operating system, not Google's cripple-ware.
[0] https://www.xda-developers.com/nexus-5x-bootloop-fix-boot-ph...
[0] https://zeelogkang.blogspot.com/2017/05/lineageos-141-unoffi...
It _is_ only a temporary fix, though.
In reality, putting electronics in an oven usually has the effect of heating up some chips which are heat-sensitive and might temporarily give them new life.
I got it back about ~2 weeks later in working condition, at no cost. LG is repairing any Nexus 5X for the bootloop issue outside warranty. Apparently it's due to incomplete contact of the heatsink with the CPU.
https://www.theandroidsoul.com/lg-offering-free-repair-for-n...
For anyone who wants a really easy way to install and use LineageOS with MicroG, consider going for the MicroG-infused version of LineageOS: https://lineage.microg.org/ It's basically pure LineageOS with a small patch that allows MicroG to spoof the Google services' signatures. The ROM supports all the devices regularly supported by LineageOS and even gets weekly OTA updates, too.
(×) In case you agree, consider donating to the project: https://salt.bountysource.com/teams/microg (or, if you want a specific issue to be solved, you can put a bounty on it, too: https://bountysource.com/teams/microg )
> Why do we need a custom build of LineageOS to have microG? Can't I install microG on the official LineageOS?
> MicroG requires a patch called "signature spoofing", which allows the microG's apps to spoof themselves as Google Apps. LineageOS' developers refused (multiple times) to include the patch, forcing us to fork their project.
> Wait, on their FAQ page I see that they don't want to include the patch for security reasons. Is this ROM unsafe?
> No. LineageOS' developers decided not to include this patch for various reasons. The signature spoofing could be an unsafe feature only if the user blindly gives any permission to any app, as this permission can't be obtained automatically by the apps. Moreover, to further strengthen the security of our ROM, we modified the signature spoofing permission so that only system privileged apps can obtain it, and no security threat is posed to our users.
So "shady" might not be the right term..."untrustworthy" might be a better one, until they prove otherwise.
To be sure of the integrity of a binary and what it does, one must build it from source code that one has verified.
Making strong claims about privacy and then bundling pre-built binaries found on the internet (no matter what the site) does not inspire confidence in me about the team or its supposed dedication to privacy.
Does this mean I can use the Play store and apps such as Spotify without much issue?
LineageOS really should find a way of making Webview available for people who do not load Play/gapps - MicroG is the only way to run an up to date webview if gapps is not present.
There are also two versions of the "Aurora Store" in F-Droid. These require your Google account at startup, and they supposedly handle the split APKs.
Yalp does warn that using your own credentials is a violation of Google's terms of service. Because of this, I have never given these credentials to Aurora.
1. WebView comes pre-installed on LineageOS, irrespective of whether you install Gapps
2. WebView can be downloaded separately from the Play Store
Yes! (I used to have the Play Store installed on my phone with MicroG and it worked just as you would expect. As for Spotify, I use it on a daily basis.)
UPDATE: I should point out that I have since replaced the Play Store with Yalp/Aurora Store because the Play Store still needs to be installed as system-privileged app which I didn't like.
And I think it's more interesting in the context of the recent Huewai/Android story.
/.well-known/location_list
/.well-known/location/<code>/open_hours
/.well-known/location/<code>/phone
/.well-known/location/<code>/<other_metadata>
etc? Or even on-page microformats. Google used to do this until they got big enough that they didn't have to anymore. This would probably be the only way we could chip away at that moat, and ensure we don't fall into that trap again.Ultimately any kind of microdata has the same problems that OpenGraph or ye olde meta keywords etc. tags did, GOOG and Co. need to parse the human-readable content to confirm any extra data for bots is not a trick. Which tends to encourage them to just ignore it, at best it's a slightly more structured version of what they're scraping from the page, at worst it's a lie.
It's honored by Google (it can enhance your search visibility) and that's why it's slowly getting popular. Far from wide adoption, though.
Over the last couple of years, I have noticed some shop owners (mainly chains, but also individual proprietors) adding their opening hours to OpenStreetMap themselves. Certainly more needs to be done to compete with Google, but OSM is still a libre alternative with some level of uptake. Plus, anyone walking past an establishment can add its opening hours from what the sign on the door says.
The choice is basically:
1. Privacy
2. Freedom of customization
3. Full participation in modern society
Pick two.
I had 1 and 2, and ended up resigning myself to 1 and 3 and getting an iPhone.
IME F-Droid usually has a working play store alternative/wrapper for those cases. Currently, "Yalp Store" has been reliable for my Play store needs over the past year. My bank keeps locking out old apk versions so Yalp Store comes in handy.
Edit: Yalp not Yelp. Don't get a Yelp app.
Have you run into a problem here?
Some apps attempt to check their license via PlayStore on startup and won't acknowledge your license otherwise (e.g. TitaniumBackup, DarkSky) Others require play services to download additional stuff and refuse to function without it - e.g. Monument Valley.
Some work fine when the pro version is restored via TitaniumBackup, though - Solid Explorer is one example.
Running MicroG makes you still under Google's thumb.
Additionally, Google can pull the rug out from under you at any time (by breaking MicroG with technical changes, or ToS).
(Personally, I've temporarily switched to a dumbphone for essential voice/SMS, while PostmarketOS gets developed for various Web/app purposes, and am also looking at the Librem 5 work.)
Two friends of mine migrated from Windows Phone directly to Samsung Galaxy S... uhm, not sure, 8 or 7 I think... with LineageOS+MicroG, and are quite happy as well.
I don't understand. What prevents you from installing Google Maps on your phone? It works perfectly fine on mine. (I'm running the MicroG-infused version of LineageOS. [1])
These run well on MicroG/Lineage, and I also was unable to run the full Maps APK.
It was tricky in places and fiddly in others, but overall I'm happy that I'm doing a reasonable amount to keep Google out of my life without being inconvenienced now. A piecemeal approach certainly worked for me, so I'd certainly recommend that to minimise impact for anyone thinking of doing the same.
Replacing gmail is possible, but annoying, because I've got way too many site subscriptions tied to it. I really need to start using email addresses on my own domain for everything from now on. That way, in the future it's painless to switch email providers.
Android is one of the hardest, because of all the Android apps that rely on Google services. I'll definitely be checking out Lineage + microG.
OTOH, you're totally right about striking a balance: If I'm sitting at work, looking something up and DuckDuckGo doesn't yield the expected results I'm quick to prepend a "!g" - which gets me the desired information in about 90% of the cases. Or if I plan a trip in advance I use Google Maps so I can get a good estimate of the travel time for a specific time of day.
Also: My SO and I have a shared Google Calendar, which I sync to my device via DAV.
I just stopped indiscriminately streaming all my personal information to Google, instead I gained some more control about what data the company gets.
Also, Maps is constantly harvesting location data and beaming it back to G servers, something many MicroG users are explicitly trying to prevent.
The latter of course rewards Google for their sleaziest, most locked-down services that everybody still needs. The former punishes the user for the same thing.
...or visiting maps.google.com ? Still works just as well, play services or not.
I run an older, unofficial LOS9 build. Thread on XDA: https://forum.xda-developers.com/htc-10/development/rom-line...
The latest built is from yesterday https://androidfilehost.com/?w=files&flid=283479
Generally the signatures are there as a tamper-proofing mechanism. Some builds (e.g. official-ish LineageOS for MicroG ROMs) have a hardcoded notification that's shown for the signature spoof permission so it can't happen in the background, though.
The possibility of widening the attack surface just triggers security paranoia in those of us ditching Big G for privacy reasons - that's why there's controversy over it at all.
- Getting SafetyNet to pass on Lineage-MicroG required installing the pirate/ad-remover app Lucky Patcher (which comes with some questionable adware) and using it to patch away APK installation signature checks. Lineage-MicroG's built in spoofing doesn't work.
- Hangouts would crash at launch unless you disabled some https/pinning/etc. I heard it was fixed.
The site does claim that you can more readily monitor and restrict what data is sent to Google with microG compared to Play Services though.
Amazon and Microsoft have both played with replacing Google's location API, basically by using their own location service but formatting it like a response from Google though. On the Fire Phone/Kindle line, and Microsoft's Android layer they built and abandoned for Windows Phone respectively.
- You might want to enable the Google Cloud Messaging feature inside MicroG, so that your apps can receive push notifications just like they would on a regular Google phone.
- SafetyNet. If you want some app to work that requires Google SafetyNet, your phone will necessarily have to communicate with the Google servers. MicroG provides functionality to do that. (Though, if you're worried about your phone's security, I strongly advise against using this feature because SafetyNet essentially requires the phone to download and run a binary blob from the Google servers.)
- If you want to install apps from the Play Store you will have to install the Google Play Store app or at least some open-source alternative like YalpStore or Aurora Store both of which will obviously download the .apks from and therefore connect to the Google servers. However, this has nothing to do with MicroG per se.
Anyway, you decide all this for yourself. If you don't want your phone to connect to Google at all, that's perfectly possible.
UPDATE: Indeed, I just checked and found a setting in MicroG saying "Allow connecting to Google servers. If disabled, all connections to Google servers usually done by microG will be denied. This overrides service-specific settings."
Worked for most things, the maps and location part was most dodgy though. Uber was almost impossible to use and Grindr stopped working. Other than that, things like G/FCM worked perfectly.
Does anyone have any idea why this is? Are the open source location provider backends just not as robust as Google's?
That said, I've actually (anecdotally, I guess) seen an improvement in the speed with which my device can locate me with LineageOS + microG. I've been using Unified NLP with the GSM location backend that you can find on F-Droid. Not sure how well this would work out if I, say, road tripped through an area without cell service - not sure if it uses ANY carrier's tower it can find (that your baseband supports) or just your carrier's towers. Waze finds me much faster on launch, though.
https://location.services.mozilla.com/
https://github.com/microg/IchnaeaNlpBackend
If you want to improve the data quality in your area, you can use the Mozilla Stumbler:
https://f-droid.org/repository/browse/?fdid=org.mozilla.mozs...
Firefox for Android also lets you opt in to help improve Mozilla Location Services whenever Firefox makes a location request. This is equivalent to using the Stumbler app (and you should check its battery/RAM usage to make sure this setting is acceptable for you):
https://support.mozilla.org/en-US/kb/improve-mozilla-locatio...
> Uber [..] Grindr
Can I just comment how contradictory this is? I understand "privacy" means different things to people, but when used like this it's diluted to an arbitrary buzzword. What I mean is:
Grindr Shares Personal Information With Third-Parties: https://news.ycombinator.com/item?id=16735956
Uber pulls U-turn on controversial tracking of users after trip has ended: https://www.theguardian.com/technology/2017/aug/29/uber-u-tu...
Uber has user route history, payment history, etc, and law enforcement is readily utilizing this data, e.g. in the recent Jussie Smollet fiasco, in cases. Even if you're not worried about that, Uber had a massive data breach, which they were investigated for and fined.
Since then, Google has lost my trust, and now I'd like to restrict their access to my data.
The App Store is a different ecosystem running on a different operating system designed for different hardware owned by a different company entirely?
There _are_ no legitimate alternatives. Not by Huawei, not by any western company, not by anyone. There's only one, and Apple has it on lock-down; it has zero bearing on anything not-Apple.
That guy has released a ROM patcher for most AOSP ROMs that can add in signature spoofing support. IIRC there was also flashable tooling for removing GApps from your device.
You'd need a custom recovery, though. Just flash your stock vendor image, remove GApps, flash the patcher, then flash microG. I'm simplifying a bit, but it might be possible.
https://forum.xda-developers.com/apps/magisk/module-nanomod-...
I had a Dutch boss, who once said, “you never put forward something as your opinion, you always state a secondary source. Why?”. I said it was to give credence to what I was saying, because I myself am only one data source. His answer was, “oh, that is very honest”. I never really understood that.