Ironically when I tried to set up a legitimate Gmail account for my business and used it to set up several accounts, within few days it got locked with no recourse for unlocking - there was a comment box where I could beg for an unlocking, never even got a response though. So Gmail is only for throwaway accounts from now on.
Maybe it's location specific then or something...
All you get asked today (at least in Australia on a residential ISP) is a first name, last name, password, date of birth and gender (includes "prefer not to say").
Years ago I think you were correct, a phone number and SMS verification check was mandated, and each phone number could only be used so many times on different accounts.
[1] https://www.androidauthority.com/gmail-without-phone-number-...
It's about as awful as discord, who also locks account creation behind providing a phone number when an account is created from my residential IP. It almost feels like I've tripped some prevention mechanisms that all these companies are sharing and I have no idea of how to get my "goodness" score back up.
You should not have too, though. And as the discussion shows, Google requiring a phone number depends on luck.
As I've noted previously (<https://news.ycombinator.com/item?id=30953159>), I recall but cannot find the 2-ZIP-code example, though a paper describing four location points IDing 95% of the population uniquely is here: <https://www.nature.com/articles/srep01376>
ZIP + gender + date of birth is another highly-effective identifier, with 87% accuracy:
"What Information is "Personally Identifiable"?", by Seth Schoen: <https://www.eff.org/deeplinks/2009/09/what-information-perso...>
Latanya Sweeney, Computational Disclosure Control: A Primer on Data Privacy Protection (Thesis, 1977, Massachusetts Institute of Technology)
<https://groups.csail.mit.edu/mac/classes/6.805/articles/priv...>
"ZIP ruled personally identifying in California" (2011) <https://www.identityblog.com/?p=1168>
It will also indicate if the app requires Google Mobile Services, which would preclude correct functionality outside of MicroG or alternate implementations.
You can easily install the Google Play store on Kindle Fire tablets. It is installed on both the tablets in my household.
That's not true. You can download APKs from sites like APKPure (which has been a top search result for "[app name] APK" for many years on... Google).
- it's harder to trust apkpure than aurora
- apkpure has a lot of ads
- apkpure has some outdated packages
- apkpure is missing packages
apkpure is proprietary and store the apk in a intermediary opaque server. So basically they can inject pretty much anything in the packages you install, and it's much harder to check than aurora if they do.
Am I correct to assume that you have to compile it yourself in order to keep this trust? Otherwise, there's no way to know if the binary being distributed alongside the source fetches from the same place, and we're right back to untrusted apps.
APKs are fundamentally extended JARs so you can easily check if an APK has been tampered with using standard Java tools [1].
[1] https://stackoverflow.com/questions/7104624/how-do-i-verify-...
For a security conscious developer such as Signal who publish an APK (.apk) and signatures publicly[2], a user with a rooted device could theoretically unpack the official application bundle received from the Google Play Store and check the executable code and resources match those in the publicly available APK. Or just not use the Google Play Store and obtain your applications directly from the developer or an intermediary you place more trust in.
[1] https://developer.android.com/studio/publish/app-signing
Google could have tampered with the file before the mirror site got it, but you can verify that whatever a mirror site is offering was signed by them.
All apks are signed so if you don't trust apkpure checking the certificates you can check the certificates yourself.
No, that's not true:
- You need a PC to run GooglePlay - You need to install Golang on that PC - You need a Google Account - You need to sign into the actual Google Play Store from a real or virtual device using that account - You need to know the Google Play Store package name (com.google.android.youtube) instead of just YouTube - You then have to transfer the APK to your Android device and install it. - You have to manually monitor your collection of apps on your device to see if there are updates and then go through the same process again to get the updated version.
With Aurora Store I had to
- Install F-Droid from https://f-droid.org/ - Install Aurora Store from within F-Droid - Open Aurora Store where it logs me in with a random Google Account from their pool of accounts. - Search for whatever app I want to install. - Tap Install. - For updates I tap on the Updates button and then tap Install All.
I didn't say it was an easy way, I said it was another way. and you dont need a golang environment to run, only to build.
I mostly wrote up that response because you took the time to post the link three different times in this thread, but there wasn't much elaboration about what was involved or why GooglePlay should be considered an alternative to Aurora Store.
Some might argue adversarial interoperability is fair game: https://news.ycombinator.com/item?id=20133151
There's also Raccon:
* my bank app, and probably your's too
* iNaturalist
* various dating apps such as tinder, bumble, hinge, coffee meets bagel
Edit: wonder if I could use a mirror instead?
Edit2: ugh tried apkmirror. Might work. The client has ads (pretty sure google ads...) and popups. Some of the ads contained a download button? I got confused and concerned. Dipped out. I'll just be more dependent on my workstation(s). Phone still works as a phone, I presume.
F-droid repository format would be easy enough to support a commercial repository you could manually activate, with signing and all.
Google has huge numbers of engineers working on Android...
Although I do kinda wonder exactly what they're working on, considering each release of Android seems to be not very different from the previous one...
i just checked my banks, they are on google play and on the huawei app store, the latter though is not really an alternative i would trust any more than google, and i didn't see if it allows download without an account, but fortunately for myself i don't want banking on my phone anyways, as the phone is the most likely device to break, lost or stolen, nor do i care about those others. but that's just me.
i found apkmirror manageable, thanks to the adblocker i guess.
No, that's not true:
The client for Google Play Store can be replaced by other apps like the one you linked. Though this is against Google's TOS.
The server part of Google Play Store is where all the applications live. It is the biggest app repository for Android and most commercial apps are uploaded there. What the GP is advocating for is having developers upload their app to other app repositories in addition to the Play Store.
> Google's Play Store is the only source for a number of proprietary applications
I use grapheneos and have a separate profile that has GPS installed which allows me to download the apks. Then I adb in and transfer them from alt_profile->computer->no_gps_profile and install it.
I don't have a Google account and am unable to obtain Play Store APKs any other way, so Aurora Store fills an important niche for me.
I guess I will hold off on updating any Play Store apps until this is fixed or I can find another software/workaround.
Yep. It lets people anonymously download apps from Google Play. It provides privacy and usability.
> I've gotta be misunderstanding something because that sounds like something that definitely should be blocked
Is there any reason why users shouldn't be able to download apps anonymously?
> and would be wildly outside of Google's terms.
Unfortunately Google does prohibit this. I wish Google would allow people to download no-cost apps without an account.
> How does this thingy work?
Unfortunately, it only works when few people know about it.
Organic Maps updates map data about once a month.
If you need help in editing - feel free to ask on https://community.openstreetmap.org/
(and bits of other sources like elevation data coming from elsewhere, but is primarily powered by OpenStreetMap data)