telemetry from PlayStore/Aurora apps?
from kimchi@lemmy.world to privacy@lemmy.ml on 25 Feb 02:55
https://lemmy.world/post/43545089

Using GrapheneOS, my main profile has a handful of apps from PlayStore(Aurora): 1password, ProtonVPN, ProtonMail, etc.

I think I read somewhere that, for an app to appear in PlayStore, it must be compiled with linked libraries that implement check-ins with Google infrastructure… or something like that.

Obviously I’d expect apps like 1password and Proton to be “less evil,” but am curious whether everything from playstore leaks telemetry, or if it’s just “up to the developer”.

(in my case, I don’t have Google services or apps in the main profile at all)

#privacy

threaded - newest

LytiaNP@lemmy.today on 25 Feb 04:24 next collapse

FWIW, you can install the entire proton suite with Obtainium. For whatever reason though, 1password exclusively distributes through the Google play store, but AFAIK that doesn’t make the app itself any less private.

mrnobody@reddthat.com on 25 Feb 04:48 next collapse

Why not just use Proton Pass?

BladeFederation@piefed.social on 25 Feb 05:52 collapse

Because you should have your email, password manager, and authenticator be 3 different services. Otherwise there is 1 point of failure.

mrnobody@reddthat.com on 25 Feb 13:39 collapse

My understanding is the password manager is fully local to the device. Its only compromise-able if you back it up to their cloud. Same goes for the authenticator.

BladeFederation@piefed.social on 25 Feb 14:00 collapse

Offline mode is available for free on the mobile app, but not desktop. Doesn’t work offline for browser extension at all, which is how auto fill works on desktop, which is much more useful. And offline mode for Proton  just means you can view the passwords you already created, not create more.

There are true offline local password managers but as long as the cloud sync is encrypted, I see no reason to avoid using it and miss out on half the functionality. Auth is more debatable but I’ve found uses for cloud hosted Auth too.

ToTheGraveMyLove@sh.itjust.works on 25 Feb 14:02 collapse

Can you? I just looked into this this other day and I didn’t see proton calendar on github, it was just an apk you could download on protons site

LytiaNP@lemmy.today on 26 Feb 01:16 collapse

Looking at Proton calendar, it seems I just put the website into Obtainium, I think there’s a monorepo somewhere, but I couldn’t find it.

ToTheGraveMyLove@sh.itjust.works on 26 Feb 08:45 collapse

Huh, okay, I thought it had to be a github repo. I’ll look into that. Thx.

Truscape@lemmy.blahaj.zone on 25 Feb 05:18 next collapse

Aurora should actually say in the description of the installation/update screen if the app requires google play services or any telemetry at all (or for that matter, google sign in).

BladeFederation@piefed.social on 25 Feb 05:50 collapse

No, Play Store does not require Play Services integration, nor does it mandate any trackers.

In practice though, most use Play Services for lush notifications, and there are a LOT of apps with at least Google Crashlytics, Google Firebase Analytics, and Google Admob trackers. Check out Exodus for tracker reports. Or use the Tracker Controller app. Just note that some trackers are pretty benign, or even a security feature, like Sentry.