# Aurora store not secure?

**URL:** https://discuss.privacyguides.net/t/aurora-store-not-secure/19692
**Category:** Questions
**Created:** 2024-07-27T12:05:36Z
**Posts:** 52

## Post 1 by @jerm — 2024-07-27T12:05:36Z

> **[Aurora does not install apps - GrapheneOS Discussion Forum](https://discuss.grapheneos.org/d/8255-aurora-does-not-install-apps/8)**
>
> GrapheneOS discussion forum

[https://xcancel.com/GrapheneOS/status/1817043028688642286#m](https://xcancel.com/GrapheneOS/status/1817043028688642286#m)

It is a bit hypocritical that Aurora store doesn’t get as much security concern warnings as F-droid does on PG.

---

## Post 2 by @dumpster — 2024-07-27T16:24:00Z

> Due to their process of building apps, apps in the _official_ F-Droid repository often fall behind on updates. F-Droid maintainers also reuse package IDs while signing apps with their own keys, which is not ideal as it gives the F-Droid team ultimate trust. Additionally, the requirements for an app to be included in the official F-Droid repo are less strict than other app stores like Google Play, meaning that F-Droid tends to host a lot more apps which are older, unmaintained, or otherwise no longer meet [modern security standards](https://developer.android.com/google/play/requirements/target-sdk).

All of that applies only to F-Droid, and not Aurora.

---

## Post 3 by @anon46412288 — 2024-07-28T05:57:24Z

> Calyx frequently spreads misinformation about sandboxed Google Play and microG. They falsely claim the microG approach avoids running proprietary Google Play code, which is untrue. Reality is you give more access to proprietary Google Play code on CalyxOS than with GrapheneOS.

Maybe I’m confused, but the microG client which Calyx runs is open source (i.e GmsCore). microG can be a user app (see DivestOS), but for a lot of functionality microG needs system privileges (ex SafetyNet bypass).

What I know for a fact is proprietary is the DroidGuard system that microG uses to bypass SafetyNet. Also of course, for providing push notifications, microG contacts Google Firebase. But this is an issue for both Google Play Services (sandboxed) and microG, and the alternative is using apps supporting something like [unifiedpush.org](http://unifiedpush.org) for push notifications.

> We aren’t going to build entirely unnecessary and extremely problematic privileged access for poorly secured third party like F-Droid and Aurora Store in GrapheneOS as CalyxOS does. Those apps use privileged install access insecurely… and automatic updates work fine without it.

Also, this is outdated. Calyx has ~~[already removed the F-Droid Privileged extension](https://calyxos.org/news/2023/09/04/f-droid/)~~ moved away from including F-Droid as a system app. They switched to the Basic version which auto-updates without privileged services.

F-Droid Privileged extension and Aurora Services still _exist_, but they are planned to be removed soon. Currently they exist for the welcome wizard on Calyx that allows users to pre-install apps.

Oh and here’s the issue regarding deprecation - [https://gitlab.com/CalyxOS/calyxos/-/issues/1943](https://gitlab.com/CalyxOS/calyxos/-/issues/1943)

---

## Post 4 by @anon48875053 — 2024-08-30T10:33:24Z

Wouldn’t recommend Aurora Store for several reasons.

My copypasta:

Aurora Store:

- Is unreliable and constantly breaks.
- Is buggy and doesn’t have good UX.
- Is completely reliant on Google, and Google could pull the plug at any moment, which would render Aurora Store unusable.
- [Play App Signing](https://support.google.com/googleplay/android-developer/answer/9842756?hl=en).
- Some apps check if they’re installed from Play Store, and if they aren’t, they will not work.
- Services like Play Asset Delivery, Play Feature Delivery and app / content license checks aren’t available.
- A lot of data gets sent to Google, like your IP address, your device model, your app list, etc.

* * *

There are two more points that I should add:

- Aurora Store is known to retrieve wrong versions of apps.
- Doesn’t verify signed metadata.
- No certificate pinning.

---

## Post 5 by @null — 2024-08-30T14:49:17Z

> [@anon48875053](#):
>
> Is unreliable and constantly breaks

“unreliable” Sound like you never used it.

“constantly breaks” is a lie. Yes Aurora Store breaks sometimes when play store has big update or google ban Aurora Store accounts has happened few times but it is normal for all frontends.

> [@anon48875053](#):
>
> - Is buggy and doesn’t have good UX.

Non issue.

> [@anon48875053](#):
>
> - Is completely reliant on Google, and Google could pull the plug at any moment, which would render Aurora Store unusable.

No sh\*t statement.

> [@anon48875053](#):
>
> - [Play App Signing](https://support.google.com/googleplay/android-developer/answer/9842756?hl=en).

explain

> [@anon48875053](#):
>
> Some apps check if they’re installed from Play Store, and if they aren’t, they will not work.

If you relies on google servies for apps, yeah Aurora Store is probably a bad choice. But I think Aurora Store is mostly for people who has a degoogled phone and just need 1 or 2 apps from play store. So yeah some apps doest works.

> [@anon48875053](#):
>
> Services like Play Asset Delivery, Play Feature Delivery and app / content license checks aren’t availab

Sound like a feature. :wink:

> [@anon48875053](#):
>
> - A lot of data gets sent to Google, like your IP adress, your device model, your app list, etc.

Ofc it is google after all but Aurora Store can spoof device and language.

---

## Post 6 by @anon48875053 — 2024-08-30T16:37:06Z

> [@null](#):
>
> “unreliable” Sound like you never used it.

It sounds like you started using Aurora Store recently and haven’t experienced the broken token dispenser. Google just lifted a finger, which broke the token dispenser and Aurora Store didn’t work for weeks if not months, don’t remember how long it took for them to fix this.

---

## Post 7 by @null — 2024-08-30T17:53:52Z

> [@anon48875053](#):
>
> It sounds like you started using Aurora Store recently and haven’t experienced the broken token dispenser. Google just lifted a finger, which broke the token dispenser and Aurora Store didn’t work for weeks if not months, don’t remember how long it took for them to fix this.

Happens all the time with frontends lol. I’ll say Aurora Store breaks way less then others frontends like newpipe, nitter.

I do remember the so called “broken token dispenser” there was a work around where you could go to play stores website with Firefox/mull _open in app_ you could still use Aurora Store almost as normal.

I personally don’t use Aurora Store because I don’t need any apps from the play store. But I did use it for years.

---

## Post 8 by @anon48875053 — 2024-08-30T17:55:18Z

> [@null](#):
>
> I do remember the so called “broken token dispenser” there was a work around where you could go to play stores website with Firefox/mull _open in app_ you could still use Aurora Store almost as normal.

That only worked when Aurora Store would get rate limited by Google. When the token dispender broke, Aurora Store became useless unless you used your own Google account.

---

## Post 9 by @anon94009837 — 2024-08-30T17:56:15Z

> [@anon48875053](#):
>
> - Is unreliable and constantly breaks.
> - Is buggy and doesn’t have good UX.

I would not say it constantly breaks. There was the major breakage that occurred a while ago when Google decided to change something. One major problem Aurora Store had was that the accounts were constantly rate-limited but they have fixed this issue by generating the token on device as of the latest update. UX and UI have both vastly improved recently and I have not personally experienced any bugs.

> [@anon48875053](#):
>
> Is completely reliant on Google, and Google could pull the plug at any moment, which would render Aurora Store unusable.

Yes that is true for any front-end. Front-ends are merely band-aid solutions. A more long term solution would be something like Accrescent, which is already in the works.

> [@anon48875053](#):
>
> [Play App Signing](https://support.google.com/googleplay/android-developer/answer/9842756?hl=en).

This is not related to Aurora Store as all apps on Google Play use Play App Signing. Whether you use Sandboxed Google Play or Aurora Store, Play App signing is still an issue.

> [@anon48875053](#):
>
> Some apps check if they’re installed from Play Store, and if they aren’t, they will not work.

This is problematic yes, and there is no workaround. Another option other than Aurora Store should be considered if an app someone relies on does this check.

> [@anon48875053](#):
>
> A lot of data gets sent to Google, like your IP adress, your device model, your app list, etc.

Device model can be spoofed in Aurora Store. Aurora Store has a blacklist feature which you can use before ever signing into the app to prevent your app list getting sent. All this info will be sent anyway when you use Sandboxed Google Play so in this context, it doesn’t make sense to list this as a con of Aurora Store.

> [@anon48875053](#):
>
> Aurora Store is known to retrieve wrong versions of apps.

I have read reports of this in the past but I do not know the details. I have not read any recent reports of this happening even though I see this specific criticism talked about a lot. My theory is that the people who experienced this issue had spoofed their device model to one with vastly different characteristics to their original device. For example, they have a Pixel 7 with arm64-v8a architecture and API level 34 but they chose to spoof as a device model that supports many different architectures and has a different API level and so, Aurora Store retrieved the wrong version of the app.

> [@anon48875053](#):
>
> - Doesn’t verify signed metadata.
> - No certificate pinning.

Both valid criticisms of Aurora Store.

---

## Post 10 by @redoomed1 — 2024-08-30T18:07:55Z

> [@null](#):
>
> Happens all the time with frontends lol. I’ll say Aurora Store breaks way less then others frontends like newpipe, nitter.

I would be careful with this comparison because you are trusting Aurora Store to install other apps and deliver updates in a safe and timely manner.

This is not the case for the other frontends you mentioned.

---

## Post 11 by @anon94009837 — 2024-08-30T18:12:11Z

This is true and should be something people consider before using Aurora Store. I personally would not use Aurora Store to download all my apps and would opt for Sandboxed Google Play instead as a form of future-proofing. However, if you are using a small number of apps from Aurora Store, then it should be fine as if breakage does occur, it will not be much of a hassle to migrate to something else.

---

## Post 12 by @null — 2024-08-30T19:44:06Z

I agree but was only talking about “unreliable, constantly breaks” part not if it is safe or not.

Personally I think it’s better to use Aurora Store if you have 1-2 must have apps.

---

## Post 13 by @bigdzi — 2024-08-30T21:59:01Z

> [@anon48875053](#):
>
> how long it took for them to fix this.

around 2 months

---

## Post 14 by @anon46412288 — 2024-09-04T14:00:13Z

> [@anon48875053](#):
>
> - Some apps check if they’re installed from Play Store, and if they aren’t, they will not work.
> - Services like Play Asset Delivery, Play Feature Delivery and app / content license checks aren’t available.

Some of these are solved when using FakeStore and microG respectively :

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/2/233da874c14e27da81b35dc3ef69e93ca36211a7.png)

Though yes, nothing can be done about Play Asset Delivery and Play Feature delivery.

---

## Post 15 by @anon46412288 — 2024-09-04T14:03:30Z

> [@anon48875053](#):
>
> A lot of data gets sent to Google, like your IP address, your device model, your app list, etc.

Btw, this would still happen on the Google Play Store client right? And Aurora has an option to change the presented device model, if that is of concern :

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/f/f04095eb51e815f2418a25796a0e21df6306ed36.png)

---

## Post 16 by @anon94009837 — 2024-09-16T19:31:18Z

Aurora store has implemented certificate pinning.

Relevant issue: [[Security] Implement certificate pinning (#697) · Issues · Aurora OSS / AuroraStore · GitLab](https://gitlab.com/AuroraOSS/AuroraStore/-/issues/697)

---

## Post 17 by @anon48875053 — 2024-09-16T20:07:28Z

That’s great.

---

## Post 18 by @securitybrahh — 2024-09-17T07:01:20Z

Aurora IS secure but not be private if used a gmail or not a VPN.

---

## Post 19 by @anon48875053 — 2024-09-17T07:01:56Z

There is no such thing as private or not private, the world isn’t made from black and white.

---

## Post 20 by @ikelatomig — 2024-09-17T07:09:17Z

> [@anon94009837](#):
>
> be sent anyway when you use Sandboxed Google Play so in this context, it doesn’t make sense to list this as a con of Aurora Store.

Isn’t it possible to block internet access for it and just rely on Graphene for system updates considering you don’t use OTA updates ?

> [@anon46412288](#):
>
> Some of these are solved when using FakeStore and microG respectively :

So, If I use MicroG, it would act as Google Play Services but won’t report to GPlay what app I am using or installed ?

---

## Post 21 by @anon46412288 — 2024-09-17T07:35:25Z

> [@ikelatomig](#):
>
> So, If I use MicroG, it would act as Google Play Services but won’t report to GPlay what app I am using or installed ?

Not microG itself.

But if you use Aurora, then the app list is reported to Google to fetch updates as they come from the same account. Can’t do much about that part.

---

## Post 22 by @anon94009837 — 2024-09-17T15:23:19Z

> [@ikelatomig](#):
>
> Isn’t it possible to block internet access for it and just rely on Graphene for system updates considering you don’t use OTA updates ?

Not sure what you mean. Block internet access for what? What are you relying on Graphene to update?

---

## Post 23 by @ikelatomig — 2024-09-18T00:32:01Z

Block internet access to Google Play services and rely on system updates from graphene instead of OTA updates via Google play.

---

## Post 24 by @anon94009837 — 2024-09-18T14:10:31Z

yes that is possible. GrapheneOS app store would then update play services for you.

---

## Post 25 by @ikelatomig — 2024-09-18T15:38:55Z

Then why not use an official way. It seems good.

---

## Post 26 by @anon94009837 — 2024-09-18T15:45:56Z

I dont get all my apps mainly from Aurora Store. I only have Aurora Store on the few profiles that need 1 or 2 play apps.

---

## Post 27 by @securitybrahh — 2024-09-21T00:33:25Z

> [@anon48875053](#):
>
> the world isn’t made from black and white.

you would be surprised.

---

## Post 28 by @anon94009837 — 2024-09-21T02:49:43Z

Could be off topic for this conversation but the more I think about it, the more I believe that Aurora Store does not offer any benefits compared to using a throwaway Google account.

**Scenario 1: Stock Android with invasive system-level Play Services.**

Aurora Store would offer no benefits as all your data is sent to Google anyway.

**Scenario 2: GrapheneOS with no Play Services and no throwaway Google account**

Aurora store would still provide no meaningful privacy benefits but would merely allow you to access the Play Store without an account.

For example, one could argue that Aurora allows you to hide your device info from Google using the spoof manager. This would be true if you are only installing offline apps or apps that do not have any proprietary Play libraries embedded. Otherwise, your device information is getting sent to Google anyway. (Something I have somehow come to realise just recently.)

Another argument could be that Aurora allows you to hide your apps from being sent to Google. Same counter-argument. Any network-enabled app with a Google Play library is going to report to Google that it is installed on X device.

Best case scenario, you are **maybe** making it harder for Google to tie all your app installations to a single, potentially anonymous user.

**Scenario 3: Using Sandboxed Google Play**

- You benefit from the increased security of Play Store verifying security metadata (something Aurora Store is yet to implement)
- You benefit from proper support for apps dynamically loading content (Play Feature Delivery and Play Asset Delivery), which is something Aurora Store developers have said is out of scope for the app.
- You benefit from passing license checks and app installation source checks.

Honestly the benefits of scenario 3 vastly outweigh any possible privacy benefits that can be achieved from scenario 2.

If there are any points/arguments that I may have not taken into account, please bring them up.

PS. Mainly just convincing myself to use Sandboxed Google Play with a throwaway account and get it over with lol.

---

## Post 29 by @Regime6045 — 2024-09-24T16:26:27Z

Counter-argument: unless you’re very lucky, you won’t be able to create a new Google account without giving them your phone number

---

## Post 30 by @deviancy — 2024-09-24T16:27:59Z

Creating a google account on a phone on public wifi seems to pretty reliably keep people from getting the phone number requirement.

---

## Post 31 by @anon94009837 — 2024-09-24T16:45:59Z

> [@Regime6045](#):
>
> Counter-argument: unless you’re very lucky, you won’t be able to create a new Google account without giving them your phone number

Yeah thats the only valid argument tbh.

As @deviancy said, using public wifi without a vpn would probably work fine.

---

## Post 32 by @RadioAddition — 2024-10-16T06:06:20Z

One thing I didn’t see mentioned is rotating and recycling accounts. Most likely if you’re using an anonymous google play throwaway, you’re not making a new one every week. With aurora store, you can change to a new account every time you open the app if you want, and accounts are recycled and used by other people, so the list of apps you use is diluted by other users’ app lists

---

## Post 33 by @RadioAddition — 2024-10-16T11:36:08Z

Also aurora store can make the app think it was installed through Google play if you install through shizuku

---

## Post 34 by @PurpleDime — 2024-10-17T07:44:06Z

What is your recommendation, then?

---

## Post 35 by @anon48875053 — 2024-10-17T11:09:57Z

Google Play Services if you’re on stock OS and sandboxed Google Play Services if you’re on GrapheneOS.

Pro tip: You can now choose whether to install sandboxed Google Play Services in the owner profile or in the brand new Private Space.

---

## Post 36 by @PurpleDime — 2024-10-17T11:40:23Z

I was totally expecting you to recommend an alternative app store.

I thought the point was to avoid Google Play Services? Also, what does sandboxed mean?

---

## Post 37 by @anon48875053 — 2024-10-17T12:07:54Z

> [@PurpleDime](#):
>
> I thought the point was to avoid Google Play Services?

It depends if you’re Googlephobic or not.

> [@PurpleDime](#):
>
> Also, what does sandboxed mean?

It means that Google Play Services are sandboxed  
like all the other regular apps.

---

## Post 38 by @PurpleDime — 2024-10-17T15:32:55Z

I would want to avoid the Google Play Store on stock Android phone.  
You didn’t really explain what sandbox means. I’m a newbie.

---

## Post 39 by @8pen-s8urce — 2024-10-17T15:58:49Z

The sandbox that @anon48875053 is talking about is the app sandbox applied to all Android apps installed by an Android user.

As for Google Play Services and some other Google apps that you can install in a sandboxed manner, it just means that the Android app sandbox that is usually applied to all user installed apps is also applied to Google Play Services in case you decide to install them, instead of having the Google Play Services installed by default with system privileges, which would give Google Play Services more access to your device.

To my knowledge, this is only available in GrapheneOS, no other Android based operating system or custom ROM supports this feature (installation of Google Play Services under the normal Android app sandbox).

The GrapheneOS website explains this in more detail in the following section:

> **[GrapheneOS features overview](https://grapheneos.org/features#sandboxed-google-play)**
>
> Overview of GrapheneOS features differentiating it from the Android Open Source Project (AOSP).

Also, the Android Open Source Project (AOSP) has official documentation about the Android app sandbox, in case someone is interested.

> **[Application Sandbox  |  Android Open Source Project](https://source.android.com/docs/security/app-sandbox)**

---

## Post 41 by @PurpleDime — 2024-10-18T15:34:19Z

Thanks, for explaining.

---

## Post 42 by @PurpleDime — 2024-10-18T15:45:42Z

It’s interesting that you say that the Google Play Store can’t be avoided on stock Android. I bought my current phone brand new from the store years ago, and the first thing I did was block the Google Play Store, and download F-Droid and Aurora.

I have never downloaded a single app from the Google Play Store on my phone, and I never logged into any official Google apple except Google Play Books after a couple of years. It’s the only official Google app I use, every other “Google app” is/was a modded app.

For years, I never had any issues from blocking and not using the Google Play Store. The only app that gave me any issue at the beginning is 1Password. The specific problem I had with one 1Password, and still have, is that whenever I scanned QR code to import a 2FA token, it didn’t work. I always had to manually add it, I don’t know why.

Then after a couple of years, a few other apps stopped working. Just 1 or 2 if I remember. But most of the apps work fine.

It’s my understanding that GrapheneOS works best on a Pixel phone, and I don’t have one. I find them a bit too expensive. Morever, as a newbie, I admit that I am nervous about installing GrapheneOS. For me to be comfortable with it, I would have to have a back up phone just in case something goes wrong.

---

## Post 43 by @anon48875053 — 2024-10-18T17:01:23Z

TThere is no way to disable, block, or remove Google from the stock OS. You should’ve just used the Play Store.

---

## Post 45 by @certainty — 2024-10-18T18:37:22Z

FYI: Play services can be disabled in samsung devices.

---

## Post 47 by @sha123 — 2024-10-18T19:48:49Z

> [@PurpleDime](#):
>
> It’s interesting that you say that the Google Play Store can’t be avoided on stock Android.

Google Play Store is not the problem, but also little to nothing to gain from not using it, if you are on a device with Play Services. The privileged Play Services are the problem.

---

## Post 48 by @KeepItSimple — 2024-10-19T11:22:18Z

It depends on a manufacturer, some allow it, one of my devices have USSD command to disable GMS. Also you may disable GMS completely with adb? Some manufacturers do not even install GMS at all, like Huawei.

---

## Post 49 by @PurpleDime — 2024-10-22T14:22:16Z

Using the PlayStore requires an account.

---

## Post 50 by @anon48875053 — 2024-10-22T16:57:04Z

Same goes for Aurora Store, but you’re just using a shared account.

---

## Post 51 by @Brisingr05 — 2024-11-04T10:37:17Z

What about using someone else’s mobile hotspot?

---

## Post 52 by @anon48875053 — 2024-11-04T10:53:51Z

That will work too.
