• Cleisthenian@lemmy.ml
    link
    fedilink
    arrow-up
    24
    arrow-down
    1
    ·
    6 days ago

    Seems like clickbait but the graphene devs recommend against aurora store in favor of using a second profile with the sandboxed play store

    • artyom@piefed.social
      link
      fedilink
      English
      arrow-up
      27
      ·
      6 days ago

      The Play Store requires a Google account. Using a second profile is extremely inconvenient.

      • NuclearDolphin@lemmy.ml
        link
        fedilink
        arrow-up
        20
        arrow-down
        3
        ·
        6 days ago

        Graphene recommending this at all is extremely sus. My objective of using your operating system is to avoid giving Google any information I possibly can. Don’t know why they always recommend using Google shit in a sandbox like those packets aren’t still coming from my IP.

        • artyom@piefed.social
          link
          fedilink
          English
          arrow-up
          27
          ·
          6 days ago

          Its not sus. They’re just hyper-aware of security. And Aurora is just not terribly secure. Its just that you’re now choosing between privacy and maximum security. And I prioritize privacy, personally.

          They pretty much only recommend Accrescent.

          • NuclearDolphin@lemmy.ml
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            8 hours ago

            If your threat model includes Google as a trusted party, you’re an untrusted party to me.

            It is sus that they privilege Google software in so many ways over other FOSS implementations. Saying “well Google can be trusted to be reasonably secure” is not an excuse for anyone who considers Google to be one of the primary parties they wish to keep their information away from.

            I have a lot more trust in F-Droid because they take a principled stance against Google. Maybe their software is not as high quality as GOS devs would insist, but I can trust that they will not act against my interests, far more so than the GrapheneOS project.

          • vas@lemmy.ml
            link
            fedilink
            arrow-up
            8
            ·
            6 days ago

            I agree. Specifically, it’s privacy AND freedom (free software development model).

            If these two are against maximum security, GrapheneOS consistently chooses security. Which is unfortunate for me, because I would consistently choose freedom. (Especially due to long-term considerations.)

            • Cleisthenian@lemmy.ml
              link
              fedilink
              arrow-up
              5
              ·
              6 days ago

              You can disregard their recommendation if you wish, I do sometimes. If they were here, I imagine they’d say they don’t see privacy and security as contradicting each other, just that there are different threat models. I think they subscribe to the idea that not everyone is going to be sufficiently informed in order to make a rational judgement, so instead they default to lowering potential risk. They do value accessibility for the tech illiterate as well.

          • furry toaster@lemmy.blahaj.zone
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            3
            ·
            6 days ago

            how is Aurora less secure than PlayStore directly? GOS devs literally never make sense, and of course they recommend a app store that doesn’t even properly label non open/free apps distincly, it is not like they evwr cared about FOSS just vague “security” theater

            • Swedneck@discuss.tchncs.de
              link
              fedilink
              arrow-up
              3
              ·
              6 days ago

              because aurora store isn’t developed by a big team of professionals with a massive budget, and aren’t getting security audits by other teams of well-funded professionals.

              the point isn’t that aurora store is insecure, the point is that the play store is VERY secure (it’ll just also merrily sell your data to palantir)

              • F3lis_sylv4@anarchist.nexus
                link
                fedilink
                English
                arrow-up
                3
                ·
                6 days ago

                Isn’t the aurora store just a wrapper around the play-store using an anonimized account? That is exactly the reason that google can easily block them. They obviously found a way to stop the burner accounts that Aurora makes from accessing the store. It would be equal to making a container for each time you renew the anonymous account.

                In other words, unless the aurora app has a backdoor (and I believe it is FOSS, so that should show itself easily), it is as secure as the play store ( which has debatable security, I believe it served malware on several occasions )

                But please correct me if I’m wrong

                • Swedneck@discuss.tchncs.de
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  6 days ago

                  AFAIK aurora store is a completely separate implementation, it’s certainly not based on the play store in any way since it’s open source.