Ah shit, I’m getting the same. Never seen this error before.
I noticed these intermittently, but retrying later has seemed to resolve the updates.
all updates were failing to download here.
rebooted the device, and i just tested one update right from the app’s details page and that went on ok. will try the others from the update ui later, after the battery gets charged up.
Looks a lot like an issue, more than the reality that the title is suggesting?
click-bait?
Misleading title. After reading the linked Gitlab discussion it’s more likely a backend change from Google side. Aurora does use burner account but early reports seem to suggest they are not flagged or rate limited.
How is it misleading?
Google actively blocking Aurora Store would be much worse than them simply changing their backend. The latter can likely be quickly resolved while the former might lead to a cat and mouse game, where it gets increasingly difficult for Aurora Store to continue to work.
And what makes you think it’s the latter and not the former?
The linked gitlab discussion suggests it. There’s intermittent successes, and the particular errors align with a backend change.
Yes. once again, we know there was a backend change. The question is “why was it changed”? We already know Google manipulates YouTube for the explicit purpose of breaking Firefox, adblockers and yt-dlp. Who’s to say this is different? Certainly not anyone on GitLab.
Ah, I think I understand you a bit better. It’s true that the reason for the change is unclear, and it definitely could be malicious. However, that lack of clarity is what makes the OP article title misleading.
The article title claims the certainty that Google has blocked the Aurora store outright. I think you’ll agree that frequent errors with some successes is not the same as an intentional, simple block.
We may find that, yes, Google is intentionally blocking Aurora. It is just misleading to say so at this point.
Is this sealioning? 🫴🦋
LOL yes, anyone asking you questions you can’t answer about the shit you’re saying is “sealioning”.
The thing is, it’s already been answered. The conclusion was made based on reading the gitlab discussion. 🤷♂️ I didn’t read that myself but maybe try doing that if you’re curious. 😉🫶
The thing is, the conclusion is not going to be in any discussion outside of a Google internal chat or meeting. We know what happened, we don’t know why it happened, or what it means.
It appears Google tries to degrade alternative application stores to just another app offered through the Play Store, and therefore subject to Google’s policies (including an annual $5,000 fee for policy and security reviews). So I wouldn’t be surprised this is very much intentional, as to force application stores though a channel controlled by Google; as to technically allow competition (at Google’s discretion) while effectively killing “side-loading”.
Remember when Microsoft was forced to give a “select your web browser” prompt when setting up a Windows computer?
Quaint times, those were…
Well looks like its time to start making alternatives or scream for Linux to come out with a phone.
Linux phones work, but they depend on many Google Android apps to be daily usable by normal people.
Honestly, at this point we just need alternatives to some of these Google apps in general.
The google apps themselves are largely replaceable, but stuff like banking and communication (WhatsApp, Outlook) is where things tend to get problematic. You can run Android apps in Linux, but it might not be the most convenient thing to keep running at all times, and many banking apps will fail as they recognize the device as “insecure”.
I’m out of breath by this point. You want to scream now of all times?
What alternative are you going to make? My bank only publishes their app on Play Store. I can either use Play Store app or Aurora to install it. You think that if you build alternative, open source store my bank will publish their app there? You think any bank will? F-Droid already exists, do you see any banks publishing their apps there? Do you see any of them dong Linux version of their apps?
The alternative here would be some other corporation building independent app store and getting everyone to publish their apps there. Amazon tried that many years ago. Maybe Samsung could do it now. It’s definitely not something we can make.
I don’t know about FOSS stores but banks have been known to make apps and publish them on alternate stores (Samsung, Huawei, Amazon) if there are enough users. Off the top of my head, Revolut and ING Turkey have apps on the Huawei app store right now.
IMO this needs a regulatory push. If the EU encourages or requests EU-based app stores with relevant twists (regional for example), they will appear, and Google will have to accept them, and the banks will put their apps there.
No app developer wants to deal with Google Play, it’s ass and a pain in the. If a company has a local audience (like a national bank) and they get a store that caters specifically to that country and it’s easier to publish (and cheaper) than Google Play, they will use it.
Local stores don’t have to accept all apps, either. They can be regulated stores that are only open to certain entities in that country like banks, government apps, telecom, utility, public transport etc. That would take care of the most immediate needs for their citizens and liberate those from Google’s control.
100% agree that regulatory push is needed. Everything uses an app now and it’s not possible to force all the different developers to support deGoogled devices just by user pressure. There’s simply not enough of us. EU has to treat it as strategic issue for their US tech sovereignty and start acting.
Everything uses an app now
Speaking of which, that’s an issue in itself. The vast majority of “apps” are basically webviews. And yet I’ve seen banks deprecate their website in favor of app-only access, which firmly locks them (and us) into the Google and Apple ecosystem, even when the website and the bank UI are one and the same.
I guess they won’t learn until there’s a major outage. I’ve had apps installed from Play that refused to start and were unusable for a whole week because Google fucked up something accidentally about the dev’s account. If that were to happen to a bank’s app they’d understand the issue. Especially if it’s one of the banks that are exclusively online, like Revolut.
I was in the same situation, but I slowly started to get rid of android/ios only services. Now my new bank offers every service on their web page + it has very convenient REST API where I can monitor my account.
Thats why we need an alternative.someone, some company, anyone that can make software that dosent rely on Google just to work.
Its crazy that even in the degoogle world, we still have to rely on Google. if the whole point is to not use Google, then what’s the point? We should have our stand alone apps should we not? We can’t make them but someone our there can.
We should have our stand alone apps should we not?
We should but I’m afraid that ship has sailed and without EU’s intervention it’s not going to change. I was trying to buy a train ticket recently and the app for local train requires Google account now. It will just keep getting worse and more and more apps will rely on Google services and require play services and google accounts. This will not be solved by open source apps. Legal solution is required.
Why not use their mobile site?
It’s not as convenient as the app.
I get the issue with the bank apps. Especially if your someone who needs to do a lot of transactions over the phone. But all these other apps, at this point we should have alternatives, its ridiculous.
PostnarketOS sends their regards
But does it actually work like a phone? Calling, texting, no issues?
entirely depends on the phone and the setup you go with, postmarket is kinda more of a platform than a single specific OS, like if fedora made you choose one of their spins.
I’ve only used it on a pinephone (which isn’t exactly the ideal hardware…) and my experience on that was that you could probably survive using it as a fancy feature phone.
See that’s my gripe with Linux. I don’t want a PDA, I can do all of that tinkering on PC.
uhhh… yeah but even a laptop isn’t portable enough to put in your pocket, lol. They also generally can’t make phonecalls.
I might be cooked
I just checked and get the same error.
Mine had the error and it started working after deleting cache/storage, uninstall and doing a clean reinstall.
I just tried again today and updates work again. I didn’t change anything from yesterday.
Oh I was wondering why Aurora had stopped working
Well, I don’t Aurora on my Graphene phone anyway.
I don’t use GrapheneOS anyway so fuck them, right? Why should I care about others when it does not directly impact me?
Set yourself up for pain, feel the expireince. We all make choices. Ive prepared.
congratulations on your study of the blade.
I study Anthropology
Just worked for me. So maybe they implemented a workaround.
It is not always immediate. I faced the issue only after 2 successful updates. Definitely looks more like rate limiting with minor response change than a block as OP is claiming. Will have to wait and see until someone can properly inspect it.
Seems like clickbait but the graphene devs recommend against aurora store in favor of using a second profile with the sandboxed play store
The Play Store requires a Google account. Using a second profile is extremely inconvenient.
Graphene recommending this at all is extremely sus. My objective of using your operating system is to avoid giving Google any information I possibly can. Don’t know why they always recommend using Google shit in a sandbox like those packets aren’t still coming from my IP.
Its not sus. They’re just hyper-aware of security. And Aurora is just not terribly secure. Its just that you’re now choosing between privacy and maximum security. And I prioritize privacy, personally.
They pretty much only recommend Accrescent.
If your threat model includes Google as a trusted party, you’re an untrusted party to me.
It is sus that they privilege Google software in so many ways over other FOSS implementations. Saying “well Google can be trusted to be reasonably secure” is not an excuse for anyone who considers Google to be one of the primary parties they wish to keep their information away from.
I have a lot more trust in F-Droid because they take a principled stance against Google. Maybe their software is not as high quality as GOS devs would insist, but I can trust that they will not act against my interests, far more so than the GrapheneOS project.
I agree. Specifically, it’s privacy AND freedom (free software development model).
If these two are against maximum security, GrapheneOS consistently chooses security. Which is unfortunate for me, because I would consistently choose freedom. (Especially due to long-term considerations.)
You can disregard their recommendation if you wish, I do sometimes. If they were here, I imagine they’d say they don’t see privacy and security as contradicting each other, just that there are different threat models. I think they subscribe to the idea that not everyone is going to be sufficiently informed in order to make a rational judgement, so instead they default to lowering potential risk. They do value accessibility for the tech illiterate as well.
how is Aurora less secure than PlayStore directly? GOS devs literally never make sense, and of course they recommend a app store that doesn’t even properly label non open/free apps distincly, it is not like they evwr cared about FOSS just vague “security” theater
because aurora store isn’t developed by a big team of professionals with a massive budget, and aren’t getting security audits by other teams of well-funded professionals.
the point isn’t that aurora store is insecure, the point is that the play store is VERY secure (it’ll just also merrily sell your data to palantir)
Isn’t the aurora store just a wrapper around the play-store using an anonimized account? That is exactly the reason that google can easily block them. They obviously found a way to stop the burner accounts that Aurora makes from accessing the store. It would be equal to making a container for each time you renew the anonymous account.
In other words, unless the aurora app has a backdoor (and I believe it is FOSS, so that should show itself easily), it is as secure as the play store ( which has debatable security, I believe it served malware on several occasions )
But please correct me if I’m wrong
because graphene devs don’t know what they are talking about, they never do
where’s your Pegasus-proof OS, then?
Nothing is 100% pegasus/quadream/candiru proof. Up-to-date and BFU Graphene is Cellebrite proof, though.
Yup can confirm. Some apps return this error (example tutamail and windscribe vpn). Fix it by downloading the apk in fdroid or github/ gitlab directly.
It’s on fdroid.
I recommend blocking play store.
They are not blocking the download of the app from playstore. It was obviously not available there in the first place. They blocked API access to the google servers where aurora store was getting the apk files from. They just killed the concept of aurora store (and any alternative playstore frontend) entirely.
What is on fdroid??
this app called ‘aurora store’ which is a foss playstore client
What?
I was wondering cant we just scrape Play Store and distribute the apks on a different website? most apks has checksums so we will know nobody has changes the apk
and distribute the apks on a different website
Or with distributed technologoes such as torrents. Then it’s cheaper to operate any required servers.
And also if a server goes down there are still dozens of seeders ready to seed you the files
That’s insecure
It is if you use cryptography or cryptographically secure hashing.
There are a bunch of sites like apkmirror etc. that do that but eventually the large ones started enshittifying their service. On apkmirror for example you used to be able to just download the apk’s, now they’ve invented a special “format” that can only be installed through their app. Needless to say that was the end of that, I’m not keen on giving install capability to any more apps than I absolutely have to. (Zero is the ideal answer in case you’re wondering, but in practice it’s usually one, the system file manager. Any other app can download apk’s to /Downloads or go fuck itself.)
now they’ve invented a special “format” that only can only be installed through their app
If I’m not mistaken, that’s the .apkm bundles right? That’s not their own format but another one Google invented to be able to dynamically install only the relevant parts of an app for a specific device type, locale, etc.
Android can’t install this on it’s own (I wonder who’s fault that is 🙄) but it can be installed via adb or through special installer apps like the Play Store, Aurora or I’m assuming the APKMirror app
For info - there is an alternative to APKMirror’s app On F-Droid. Still not ideal, but better than their proprietary nonsense.

















