Aurora Store Accounts Blocked by Google
gitlab.com
gitlab.com
* my bank app, and probably your's too
* iNaturalist
* various dating apps such as tinder, bumble, hinge, coffee meets bagel
Edit: wonder if I could use a mirror instead?
Edit2: ugh tried apkmirror. Might work. The client has ads (pretty sure google ads...) and popups. Some of the ads contained a download button? I got confused and concerned. Dipped out. I'll just be more dependent on my workstation(s). Phone still works as a phone, I presume.
F-droid repository format would be easy enough to support a commercial repository you could manually activate, with signing and all.
Google has huge numbers of engineers working on Android...
Although I do kinda wonder exactly what they're working on, considering each release of Android seems to be not very different from the previous one...
i just checked my banks, they are on google play and on the huawei app store, the latter though is not really an alternative i would trust any more than google, and i didn't see if it allows download without an account, but fortunately for myself i don't want banking on my phone anyways, as the phone is the most likely device to break, lost or stolen, nor do i care about those others. but that's just me.
i found apkmirror manageable, thanks to the adblocker i guess.
No, that's not true:
The client for Google Play Store can be replaced by other apps like the one you linked. Though this is against Google's TOS.
The server part of Google Play Store is where all the applications live. It is the biggest app repository for Android and most commercial apps are uploaded there. What the GP is advocating for is having developers upload their app to other app repositories in addition to the Play Store.
> Google's Play Store is the only source for a number of proprietary applications
I use grapheneos and have a separate profile that has GPS installed which allows me to download the apks. Then I adb in and transfer them from alt_profile->computer->no_gps_profile and install it.
I don't have a Google account and am unable to obtain Play Store APKs any other way, so Aurora Store fills an important niche for me.
I guess I will hold off on updating any Play Store apps until this is fixed or I can find another software/workaround.
Ironically when I tried to set up a legitimate Gmail account for my business and used it to set up several accounts, within few days it got locked with no recourse for unlocking - there was a comment box where I could beg for an unlocking, never even got a response though. So Gmail is only for throwaway accounts from now on.
Maybe it's location specific then or something...
All you get asked today (at least in Australia on a residential ISP) is a first name, last name, password, date of birth and gender (includes "prefer not to say").
Years ago I think you were correct, a phone number and SMS verification check was mandated, and each phone number could only be used so many times on different accounts.
[1] https://www.androidauthority.com/gmail-without-phone-number-...
It's about as awful as discord, who also locks account creation behind providing a phone number when an account is created from my residential IP. It almost feels like I've tripped some prevention mechanisms that all these companies are sharing and I have no idea of how to get my "goodness" score back up.
You should not have too, though. And as the discussion shows, Google requiring a phone number depends on luck.
As I've noted previously (<https://news.ycombinator.com/item?id=30953159>), I recall but cannot find the 2-ZIP-code example, though a paper describing four location points IDing 95% of the population uniquely is here: <https://www.nature.com/articles/srep01376>
ZIP + gender + date of birth is another highly-effective identifier, with 87% accuracy:
"What Information is "Personally Identifiable"?", by Seth Schoen: <https://www.eff.org/deeplinks/2009/09/what-information-perso...>
Latanya Sweeney, Computational Disclosure Control: A Primer on Data Privacy Protection (Thesis, 1977, Massachusetts Institute of Technology)
<https://groups.csail.mit.edu/mac/classes/6.805/articles/priv...>
"ZIP ruled personally identifying in California" (2011) <https://www.identityblog.com/?p=1168>
It will also indicate if the app requires Google Mobile Services, which would preclude correct functionality outside of MicroG or alternate implementations.
You can easily install the Google Play store on Kindle Fire tablets. It is installed on both the tablets in my household.
That's not true. You can download APKs from sites like APKPure (which has been a top search result for "[app name] APK" for many years on... Google).
- it's harder to trust apkpure than aurora
- apkpure has a lot of ads
- apkpure has some outdated packages
- apkpure is missing packages
apkpure is proprietary and store the apk in a intermediary opaque server. So basically they can inject pretty much anything in the packages you install, and it's much harder to check than aurora if they do.
Am I correct to assume that you have to compile it yourself in order to keep this trust? Otherwise, there's no way to know if the binary being distributed alongside the source fetches from the same place, and we're right back to untrusted apps.
APKs are fundamentally extended JARs so you can easily check if an APK has been tampered with using standard Java tools [1].
[1] https://stackoverflow.com/questions/7104624/how-do-i-verify-...
For a security conscious developer such as Signal who publish an APK (.apk) and signatures publicly[2], a user with a rooted device could theoretically unpack the official application bundle received from the Google Play Store and check the executable code and resources match those in the publicly available APK. Or just not use the Google Play Store and obtain your applications directly from the developer or an intermediary you place more trust in.
[1] https://developer.android.com/studio/publish/app-signing
Google could have tampered with the file before the mirror site got it, but you can verify that whatever a mirror site is offering was signed by them.
All apks are signed so if you don't trust apkpure checking the certificates you can check the certificates yourself.
No, that's not true:
- You need a PC to run GooglePlay - You need to install Golang on that PC - You need a Google Account - You need to sign into the actual Google Play Store from a real or virtual device using that account - You need to know the Google Play Store package name (com.google.android.youtube) instead of just YouTube - You then have to transfer the APK to your Android device and install it. - You have to manually monitor your collection of apps on your device to see if there are updates and then go through the same process again to get the updated version.
With Aurora Store I had to
- Install F-Droid from https://f-droid.org/ - Install Aurora Store from within F-Droid - Open Aurora Store where it logs me in with a random Google Account from their pool of accounts. - Search for whatever app I want to install. - Tap Install. - For updates I tap on the Updates button and then tap Install All.
I didn't say it was an easy way, I said it was another way. and you dont need a golang environment to run, only to build.
I mostly wrote up that response because you took the time to post the link three different times in this thread, but there wasn't much elaboration about what was involved or why GooglePlay should be considered an alternative to Aurora Store.
Some might argue adversarial interoperability is fair game: https://news.ycombinator.com/item?id=20133151
There's also Raccon:
Organic Maps updates map data about once a month.
If you need help in editing - feel free to ask on https://community.openstreetmap.org/
(and bits of other sources like elevation data coming from elsewhere, but is primarily powered by OpenStreetMap data)
Yep. It lets people anonymously download apps from Google Play. It provides privacy and usability.
> I've gotta be misunderstanding something because that sounds like something that definitely should be blocked
Is there any reason why users shouldn't be able to download apps anonymously?
> and would be wildly outside of Google's terms.
Unfortunately Google does prohibit this. I wish Google would allow people to download no-cost apps without an account.
> How does this thingy work?
Unfortunately, it only works when few people know about it.
It would be helpful if others can share here how to extract and install APK's outside the Play store.
Supporting random other devices would be a nightmare.
I use APKPure. I have the suspicion that it must be some kind of malware/spying operation, but I couldn't find any proof so I kept it. Another HN user [1] followed up on a comment on mine on the topic and they didn't find anything particularly strange either.
Created by https://twitter.com/ArtemR which is known in the Android space.
Aurora wouldn't need to exist if they gave us an easy way to get apps from the Play store without giving control of our entire phone to the worst privacy offenders on earth.
That's been available on their site for as long as I can remember. Long before they had an app that would tell you as well. Heck, I'm pretty sure before Twitter even existed.
2. You run the risk of losing Google voice, if the main US account is switched to another country where they do not provide voice services
This is what Forbes had to say about it: https://www.forbes.com/sites/johnkoetsier/2021/10/19/apples-...
They're not the same. Google generates ~80% of its revenue from an ads product built on user data. Apple has an ad product which generates ~5% of its revenue (mostly from App Store ads), collects far less info¹, does not share user info with third parties, and lets users turn off personalized ad targeting with a simple toggle².
¹ https://www.apple.com/legal/privacy/data/en/apple-advertisin... ² https://support.apple.com/en-us/HT202074
¹ (because that behavior supports their primary sources of revenue)
And apple will chase that revenue if it sees the opportunity. With their control over iOS devices, when they do, you'll be powerless to stop them.
It almost works, but app developers don’t test with it, and also constantly push updates. The end result is that you never know which app is going to null pointer exception on startup this week (looking for unnecessary, but missing services), or which one will hellban your account for fraud false positives.
Also, for anything that wants google services, reading lat/long from the GPS is flaky at best. (Usually works, but sometimes puts you at a location from last week.)
Google is a clumsy puppy compared to Apple. Good luck making a client for the iOS play store.
It would be funny, if not for the fact that this duopoly is a dreadful break on innovation in the mobile software space. It is tragic
Yes, some apps are only available in the play store, and the maker of them does not publish them anywhere else. How's that google's fault again? Are you mad at Twitter because Starbucks doesn't sell their coffee there?
There is no vendor "duopoly" between google and apple. There are about a thousand flavors of Android, and a bunch of phone makers - and google isn't even the top Android seller. The only one I've used with a play store was for like a year in 2010.
There is a technology duopoly, but the technology part has nothing to do with google. Much like there's no triopoly between windows/macos/linux. Because "Linux" is not a vendor. Linux is like "car," not like "Toyota." Windows is like "bicycle with lawnmower engine held on with duct tape." Macos is like "you're eating this absolute shit, and it does taste good"
I can buy from Starbucks anonymously, or give my friend money to buy something for me. If they're calling it a "store" then that comes with an implication that you don't have to consent to being creeped on to get stuff from there.
They also did a bait-and-switch where they initially touted android's openness, but then moved an increasing amount of core functionality into google play services and encouraged app makers to depend on that.
> There is no vendor "duopoly" between google and apple. There are about a thousand flavors of Android, and a bunch of phone makers - and google isn't even the top Android seller. The only one I've used with a play store was for like a year in 2010.
There is absolutely an app store duopoly - it's a different duopoly in China than the rest of the world, but that's a distraction. The fact that they're able to sustain their 30% cut shows how much market power they have.
Starbucks (Google) and McDonalds (Apple) coffee are both available and control 98% of the coffee sales, with Starbucks owning about 70% by themselves. They each make their own special cups (hardware) that can only hold their coffee and require their special nozzles to fill, but Starbucks graciously allows a number of other retailers to make and sell compatible versions of their special cups. The fill nozzles of each require a special brewing process for the coffee to fit thru the nozzles, and a special grinding process for that brewing. Both own 99.9% of the market on services, tools, and aptents for the brewing and grinding. They also have 95% market share on bean buying and importing, and only ship to their own supply chains. To help with harvesting, McDonalds offers nice tools but will only buy beans harvested with those tools and charge $99/year/worker for them. Starbucks offers theirs for free, but the tools have to be taken apart if you don't your harvested beans ending up in a Starbucks purchasing truck. Not to be outdone by the lowly coffee farmers, both companies own large coffee plantations, and Starbucks owns 30% of the total coffee-growing land in the world and leases almost all of it to any type of farmer that will pay. Resultantly, it's less profitable and more work for farmers to not sell to Starbucks or McDonalds, even though they get paid very little for their beans.
Now you as a coffee drinker don't like that Starbucks is requiring you to provide 2 years of bank statements, your government ID card, birth certificate, body cam footage for the last 2 weeks, emails for the past 4 months, full text message history, and the passwords to every account you've had since you were 12 years old every time you want to buy a coffee. McDonalds is better, they only want the body cam footage, bank statements, and passwords, but you're not thrilled by that either. So you decide to find another coffee shop. You discover there are only a few, and they mostly just serve gas station drip coffee because they can't get growers to sell to them. Some try to get the grower to sell, but require the grower to also handle shipping and importing, but most want the growers to include shipping, importing, grinding, and brewing. Needless to say, not many growers are interested, especially ones that already have big name recognition among coffee drinkers.
A couple enterprising companies however have figured out they can just resell the Starbucks coffee. Most of these just go buy all the types of coffees available and keep them on hand for anyone that wants them, but buyers are wary of whether they're really getting the Starbucks coffee or coffee with unknown fillers added. Only one company has decided they'll resell by offering to have a one of a dedicated team of people go buy the Starbucks for you while you watch (Aurora Store). Now Starbucks is getting angry because they specifically say you can't buy coffee for others, and they're banning the dedicated team of people from all Starbucks stores in retaliation.
Not saying they're right or wrong, but that's valid logic if true. Personally I find the other ways in which you get locked down+in to already be so not worth it that it's not even a question I've needed to consider.
I switched from the cheapest telco around (by a significant margin at the time, $10–25/month instead of $35–50 for what I needed), circles.life, in part because they had no website to control things, view usage, &c., but only exposed that stuff through a mobile app that I couldn’t run. (Also very clearly illegal conduct in matters like sending spam text messages from their service notifications number, which they refused to even acknowledge when directly confronted.) But the telco I’m on now, amaysim, introduced some new roaming arrangement a few months ago that you can only activate through their app, not their website. (I would like to use it next month, so hopefully talking to customer support will work. At least they actually let you talk to support without using their app, which circles.life made hard.) Also their website is painfully slow to log in: from hitting the login button to the next page starting to load takes fully 48 seconds, and their site is of the idiotic “insist on logging you out after ten minutes” variety (like most of these sorts of businesses, for baffling reasons), so viewing my usage is fairly painful. At least I can keep the tab open at the usage page, and then when I reload and get presented with the login form and press the login button, it’ll end up back at the usage page in a minute or so; some will lose what page you were on, so that you have to go through multiple steps each time.
Banks, most of the biggest ones in Australia still have online banking, but it’s generally painful to log into and use compared to their mobile apps, and they all have a nasty habit of adding new stuff to mobile either first or only. And newer bank labels are commonly mobile-only. Internet banking is largely treated as a legacy matter which they’re all just not particularly interested in.
for serious use i stick to /e/OS supported phones. /e/OS has its own store that also gets apps from google play using their API. i wonder if that will be affected too. so far it's still working
- You can flash anything on these.
- You have 5-10 years of update on the android out of the box
- huge communities.
- consistent VoLTE and VoWIFI support
- lines are easy to understand (only a few models in each generation)
Samsung offers no long term support of phone, do hardly any publication to help open source communities to make a new image of android, and have the knox thing that makes it harder that it could be to flash. They just poop billions of different models every year without further support.
Xiaomi is like Porsche with the 911, which means they brand all of their phones the same, even when they have very different processors, vowifi support or not,... So pay attention to your exact model (the "pro" keyword isn't marketing, it can make the difference between a locked in Mediatek processor and a open source snapdragon)
I'm annoyed to have got the only flavour of Mi10-something without Vowifi support, for example, because I didn't read properly.
Sony has some OK phones to hack as well. And they look good ! But I think there was an article on HN a few days ago, about the hardware of the XA2 that called home to send analytics even with a custom ROM.
I'm also annoyed because I have had that exact model with iodéOS.
So yeah, I'd recommend to just get a Pixel phone if you want something compact (the 6A is pretty narrow), or the Fairphone if you want something large that you can physically repair, and update for the longest even if you don't hack it.
(I now have a Mi10 Lite and a Pixel 6A. I just had the latter, so that I can use one of these to hack a bit.)
In addition to those devices, I also have another one running Lineage OS because I need some apps that I can't run in any other way, v.gr. Monash University Low FODMAP Diet App.
OTH I don't understand the point you're trying to make. Can you elaborate?
It isn't even obviously stated on their documentation either, yet their homepage has "Keep your data private with an operating system that's fully secure."
That's how I also read GP's comment, but your reading is also a valid one.
1. Settings -> Apps -> Default apps -> Opening links -> Aurora Store -> Add link -> check both boxes
2. Search for your desired app with any web browser + search engine, long press on the play store link
3. Open link in external app (Aurora Store)
4. No need to de-anonymize yourself or wait for an update. Hopefully this gets fixed soon.
"Advanced users with special needs can download the Signal APK directly."