yalpstore( bypass bloated Google play) questions - Security Discussion

I just found yalpstore on fdroid.
This is from their github
What does it do?
Yalp Store lets you download apps from Google Play Store as apk files. It searches for updates of installed apps when it starts and lets you search for other apps. Thats it. Yalp saves downloaded apks to your default download folder so you can later open it in your favorite file manager app and tap each one to install the apps.
Why would I use it?
If you are content with Google Play Store app, you will not need this app.
The point of Yalp Store is to be small and independent from Google Services Framework. As time passed, Google Services Framework and Google Play Store apps grew in size, which made them almost too big for old phones (Nexus One has 150Mb memory available for apps, half of it would be taken by Google apps). Another reason to use Yalp Store is if you frequently flash experimental ROMs. This often breaks gapps and even prevents their reinstallation. In this situation Yalp will still work.
How does it work?
Yalp Store uses the same (protobuf) API the android Play Store app uses. You are going to need a google account to use it. Please, keep in mind that technically Yalp Store violates Android Market Terms of Service (§3.3). In theory, you might get your account disabled by using Yalp Store. Thats why you might want to register a separate gmail account and use it at least once to log in to the Play Store android app on any device.
In practice, though, software like Yalp, Google Play Crawler and Raccoon has been used for years and it seems to be safe.
Yalp Store is derived from the following projects:
https://github.com/Akdeniz/google-play-crawler
https://github.com/onyxbits/Raccoon
Has anyone any experience with this app?
I usually strip Google play from ask my devices except one that I use to get apps I need.
This might be a way to dump Google from that device also.
But I'm not a programmer so I can't audit the code for issues
(Our much more than use netstat to check what apps connect where)
So the more info out there the better

nutpants said:
I just found yalpstore on fdroid.
This is from their github
What does it do?
Yalp Store lets you download apps from Google Play Store as apk files. It searches for updates of installed apps when it starts and lets you search for other apps. Thats it. Yalp saves downloaded apks to your default download folder so you can later open it in your favorite file manager app and tap each one to install the apps.
Why would I use it?
If you are content with Google Play Store app, you will not need this app.
The point of Yalp Store is to be small and independent from Google Services Framework. As time passed, Google Services Framework and Google Play Store apps grew in size, which made them almost too big for old phones (Nexus One has 150Mb memory available for apps, half of it would be taken by Google apps). Another reason to use Yalp Store is if you frequently flash experimental ROMs. This often breaks gapps and even prevents their reinstallation. In this situation Yalp will still work.
How does it work?
Yalp Store uses the same (protobuf) API the android Play Store app uses. You are going to need a google account to use it. Please, keep in mind that technically Yalp Store violates Android Market Terms of Service (§3.3). In theory, you might get your account disabled by using Yalp Store. Thats why you might want to register a separate gmail account and use it at least once to log in to the Play Store android app on any device.
In practice, though, software like Yalp, Google Play Crawler and Raccoon has been used for years and it seems to be safe.
Yalp Store is derived from the following projects:
https://github.com/Akdeniz/google-play-crawler
https://github.com/onyxbits/Raccoon
Has anyone any experience with this app?
I usually strip Google play from ask my devices except one that I use to get apps I need.
This might be a way to dump Google from that device also.
But I'm not a programmer so I can't audit the code for issues
(Our much more than use netstat to check what apps connect where)
So the more info out there the better
Click to expand...
Click to collapse
Im not a programmer neither, but im using Yalp Store since few weeks and everything seems fine. Im using it with a fake google account, not main one.

New update have credential access yalp store without need to have an account (experimental) but for me don't work..
Has not anyone tried it?
Regards.
Update: problem solved disabling signature check

I get an network.error when logging in with yalp account every time.
(LineageOS 13 and 14 without gapps)
Maybe anybody have an idea or solution?
Thanks

Related

Is there a good Non-Google App Store (already tried Amazon and LG)

(this is a duplicate of my other thread. I realized the question doesn't ONLY apply to my old Nexus 4)
I'm trying to build an android phone with no Google apps on it, for privacy purposes.
I've got LineageOS on my rooted phone with no issues.
Getting apps is another matter. Amazon's app store doesn't even have Amazon's app, the LG store won't run on my phone. The various .apk-download sites I've seen either don't do paid apps, have outdated versions, or are basically for "cracked" apps, which i don't want to use.
Downloading .apk files can work, but most apps do not have such thing available, and I find often my phone's browsers choke on the link, and I have to download to my pc and then use adb to push the file across.
Is there a decent app store (or other app source) that isn't Google?
You could try Fdroid This is the website for Apk
Fdroid is all open source Apk's
bigfatguy said:
(this is a duplicate of my other thread. I realized the question doesn't ONLY apply to my old Nexus 4)
I'm trying to build an android phone with no Google apps on it, for privacy purposes.
I've got LineageOS on my rooted phone with no issues.
Getting apps is another matter. Amazon's app store doesn't even have Amazon's app, the LG store won't run on my phone. The various .apk-download sites I've seen either don't do paid apps, have outdated versions, or are basically for "cracked" apps, which i don't want to use.
Downloading .apk files can work, but most apps do not have such thing available, and I find often my phone's browsers choke on the link, and I have to download to my pc and then use adb to push the file across.
Is there a decent app store (or other app source) that isn't Google?
Click to expand...
Click to collapse
What's wrong with Google? Whatever I have a few:
GetJar (Has not be well maintained, spam, malware etc. Lurking on there now)
SlideME (Abondon, apps are so old)
Aptoid (Has some stolen apk, malware)
TutuApp (dumb kids use it to get modded games and apps, don't go there)
The Internet (APKMirror is the best)
Google Play
Sent from my KFAUWI using Tapatalk
dro3m said:
What's wrong with Google?
Click to expand...
Click to collapse
1: I've decided, if possible, to act on the privacy concerns I've had about google for quite some time now
2: I'm a gun nut law abiding firearms enthusiast and don't appreciate their recent policy changes on Youtube. Since my information is the product they sell to make money, I wish to withhold it.
it might be a pipe dream, but a guy can try.
Thanks for the places to try, all.
In addition to Google Play and Amazon Appstore, I suggest Huawei App Store. http://appstore.huawei.com/
Just for your reference.
You could use the Yalp store app which is an app that will get and down load your apk from play store anonymously
You can download it here
Hi7m3up said:
You could use the Yalp store app which is an app that will get and down load your apk from play store anonymously
You can download it here
Click to expand...
Click to collapse
That may be an ideal solution... use Google's store, but don't have Google's app on my phone...
Yeah ideal for people who have restriction's of some type.
You probably noticed that yalp store (well at least the yalp bit) is play store backward's "very fitting"

Fake google play store apk

I have a weird need. I want google play services but no access to the play store. I discovered thorught that the play services "require" the google play store to be installed for the play services to work. So I wanted to know if their is some sort of fake play store apk that I can install that will allow the play services to work without the play store?
Any other ideas would be appreciated.
I am on a moto e4 qualcomm stock rooted. And I dont have a way to enable signature spoofing since its odexed.
I need the same. Google play services and full functionality with Gmail, Maps etc, without PlayStore. Any ideas?
I found something called "FakeStore", which simulates the existence of Play Store, however I have installed it in replacement of PlayStore, but applications such as Gmail and Notes still do not work, just as if PlayStore did not exist.
I'm still investigating.
More.
The FakeStore needs a patch called "FAKE_PACKAGE_SIGNATURE" to work.
This is the link of that patch, but I can not find a way to implement it, if someone can shed some light it would be appreciated.
feanor_twh said:
More.
The FakeStore needs a patch called "FAKE_PACKAGE_SIGNATURE" to work.
This is the link of that patch, but I can not find a way to implement it, if someone can shed some light it would be appreciated.
Click to expand...
Click to collapse
Use fake store from MicroG download site.
You can use Aurora Store if you want access to playstore packages without using "Don't be evil".
Need some fake store spoofer to let apps think there is a playstore install for some of thoughs dependent apps that rely so much on daddy. So we can just get on with it.

Is non-root,google free android possible???

I have Samsung galaxy a50 ( a505f). I disable or removed all possible google products. I only use google play services and google play store. I do not use any google product. No gmail,youtube calender or sync android. If i also disable google play services and google play store + remove my google account from phone and instal apps from Amazon, appstore,appgalery or as apk from my browser. How will this affect my phone? And i do not know if apps i downloaded not from playstore gonna work normal and stabil. Notifications will work normal??? Are there any apps do not work without google play services? I know google cloud messaging is important. It looks like i only need google cloud messasing for now. How to replace gcm?? Without root.
Installing apps from outside of Google Play Store is a surefire way to put yourself in danger. By installing apps from third-party stores, you're bypassing security measures put in place to vet apps for malware threats, making it much easier for a hacker to infiltrate your device with an infected app .
Here on xda many people using root or open source apps. Let's say i bought a new phone and i did not add google account. I removed all possible google apps. I disabled all other google services i can not remove. I downloaded apps as apk files. Will apps update or send push notifications normally? That is all i need to learn. The apps i use are outlook,twitter,signal,telegram,duckduckgo,yandex navi,onedrive and samsung cloud for sync and back up. I do not use any google apps or facebook,whatsapp,instagram, messenger. I just do not know what will be effected with removing google account from phone and disabling google play services. I just need few apps keep sending notifications.
jwoegerbauer said:
Installing apps from outside of Google Play Store is a surefire way to put yourself in danger. By installing apps from third-party stores, you're bypassing security measures put in place to vet apps for malware threats, making it much easier for a hacker to infiltrate your device with an infected app .
Click to expand...
Click to collapse
^Truth^
At the very least scan any apks you intend to side load online with Virustotal. Just downloading them onto an Android without installing them isn't without risk. I side load only 2 or 3 apks from trusted sources.
You can download from Playstore then disable it, all apps will still function. I do this all the time.
Google Play Services* is needed for Playstore to run as well as some none Google apps.
You can then use ApkExport to copy your apps so you don't need to use Playstore next time you need to reload the OS. You save system apk updates as well so a full reload is possible with little or no internet connection. I store these on my SD card but a PC can be used.
Use Karma Firewall to block all the Google junk.
You can easily enable apks if needed.
It's freeware and uses very little battery.
*block Google Play Services with Karma Firewall when not using Playstore. A reboot will be needed after it's enabled for Playstore to work. GPS will waste battery by constantly connecting to the internet (4 times @ minute) if not firewall blocked.

Download and install apk privacy over aurora

Hi,
please please please have patient with with as i’m still on iphone waiting to sell it and buy android (after @5 years on apple ecosystem)
Before that, last android phone, i had note 3, rooted ...
My question is about having a degoogled phone with lineageos without any google service instaled (not even aurora that, from what i understood, can be installed via fdroid and used to install play apps) and use no more google/facebook services (e.g whatsapp).
The question: can i download an apk file from google store via a laptop (e.g: revolut, or other banks apps) upload them to the phone and install them?
If this will work, will be privacy compromised?
Is this safer than installing via aurora?
Another question: lets say ill use k9 mail for my gmail account. Will this help google target my phone in any way knowing at least my phone ip ?
Regards,
With Aurora ( a fork of Yalp ) app you download/update apps directly from the Google Play Store without a Google account.
Aurora is open-source hence you must not fear your Android gets compromised by it.
Downloading an app from 3rd-party websites - means not from Google Play Store - and installing it always carries the risk that malicious software is installed.
Note: Apps may not work if you uninstall Google Play Services.
jwoegerbauer said:
With Aurora ( a fork of Yalp ) app you download/update apps directly from the Google Play Store without a Google account.
Aurora is open-source hence you must not fear your Android gets compromised by it.
Downloading an app from 3rd-party websites - means not from Google Play Store - and installing it always carries the risk that malicious software is installed.
Note: Apps may not work if you uninstall Google Play Services.
Click to expand...
Click to collapse
Thank your for your answer.
If it will not work, then I'll skip the app
Thank you again

Installation of google play services for a specific user profile

I wonder if I can create two (or more) user profiles on my android device, one of which I will use only open source stuff and everything else on the other.
As far as I know, it is possible to create several user profiles in Android that are isolated from each other.
I would probably install LineageOS for this as it doesn't have google play services pre-installed on it and it seems very "clean" in terms of these things (I have never used this system).
There is something like OpenGApps that allows you to install google play services but as far as I know it requires installation from twrp. So I suspect google play services will then be installed for all user profiles on the device.
So is there any possibility to install google services for one user only?
I also know that there is such a thing as microg (and Aurora stora). When I heard that there was such a thing as "LineageOS for microG" I thought it would be a very good option (on one android profile I just wouldn't use microg). But later I also found out that it is supposedly against the google policy and that they can ban my account for it, which I would prefer to avoid.
So I wanted to ask if the only option to do this is to install LineageOS, check what applications are installed by default, install OpenGApps to it and then disable all google related applications on one of the user profiles?
Does such disabling the application also ensure that Google will not be able to "work" on my device in any way? Does OpenGApps install any system level google stuff that will run in the background anyway?
And are OpenGApps not something that I should not install when I don't want to get a google ban?
You are confusing (Open)GApps - Google themselves call them Google Mobile Services (GMS) - and Google Play Services what are two completely different things.
Google Play Services is one of the most important parts of Android. It helps connect everything together and hold it all there. The Google Play Services are the interface to the Google Mobile Services as well as to the hardware functions of the Android device. Many of your apps use Google Play Services everyday.
GMS is a bunch of apps what includes
Google Play Store,
Google Now,
Google Play Music,
Google Maps,
Google+,
Gmail,
Google Photos,
Youtube
and the Android Device Manager.
Knowing the difference it should be clear that GMS can get installed on a per-user basis whereas Google Play Services not.
jwoegerbauer said:
You are confusing (Open)GApps - Google themselves call them Google Mobile Services (GMS) - and Google Play Services what are two completely different things.
Google Play Services is one of the most important parts of Android. It helps connect everything together and hold it all there. The Google Play Services are the interface to the Google Mobile Services as well as to the hardware functions of the Android device. Many of your apps use Google Play Services everyday.
GMS is a bunch of apps what includes
Google Play Store,
Google Now,
Google Play Music,
Google Maps,
Google+,
Gmail,
Google Photos,
Youtube
and the Android Device Manager.
Knowing the difference it should be clear that GMS can get installed on a per-user basis whereas Google Play Services not.
Click to expand...
Click to collapse
Thanks for the clarification, although I still don't really know what you meant. I thought that google play services is the name for all those components that are needed to run, for example, the google play store. If the google play store needs also other components (?), then when I wrote google play services, I meant all the components that are needed to run the play store.
In any case, I mean in practice whether I am able to install both the play store and the components needed for it only for one user in Android, but from what I understand it is not possible in your opinion.
The questions at the end of my post probably still remain the same. I can only clarify that I meant more general cases in these questions:
Does installing the play store (along with the necessary components) install any system-level Google stuff that will run in the background anyway even if I disable these apps?
And isn't installing the play store (along with the necessary components) by hand something that I shouldn't be doing when I want to avoid a Google ban?
Again:
Google Play Store simply is an ordinary user app as any other user app, too, nothing else. It itself installs , except some Android OS libraries, nothing. Only thing is it requires Google Play Services ( which are running in background ) to properly run. As already said: Google Play Services can only get installed once because it extends Android OS. And Android OS always is the same for all created users.
Don't understand what you mean with "Google ban".
Dani3I said:
I would probably install LineageOS for this as it doesn't have google play services pre-installed on it and it seems very "clean" in terms of these things (I have never used this system).
There is something like OpenGApps that allows you to install google play services but as far as I know it requires installation from twrp. So I suspect google play services will then be installed for all user profiles on the device.
So is there any possibility to install google services for one user only?
Click to expand...
Click to collapse
You can install those apps but you have to flash it via recovery. Also, you need to do that prior to booting into the os for the first time, which I think is related to encryption.
If you already booted into your os, you need to boot into recovery and perform a factory data reset, then flash those gapps (as far as I know dirty flashing those gapps will introduce instability to those gapps. That's why you need a factory data reset).
Keep in mind that factory reseting will delete all your person data.
After you flashed it, those gapps will be available for every user
Dani3I said:
I also know that there is such a thing as microg (and Aurora stora). When I heard that there was such a thing as "LineageOS for microG" I thought it would be a very good option (on one android profile I just wouldn't use microg). But later I also found out that it is supposedly against the google policy and that they can ban my account for it, which I would prefer to avoid.
Click to expand...
Click to collapse
Aurora Store provides an anonymous google account. It's data isn't linked to you which means they cannot ban your account.
Dani3I said:
So I wanted to ask if the only option to do this is to install LineageOS, check what applications are installed by default, install OpenGApps to it and then disable all google related applications on one of the user profiles?
Click to expand...
Click to collapse
LOS comes without any google apps preinstalled. So first flash LOS, then OpenGApps (follow their official guide. They describe it there).
And yes, after that you have to disable every google app you don't want to use for every new user profile.
Dani3I said:
Does such disabling the application also ensure that Google will not be able to "work" on my device in any way? Does OpenGApps install any system level google stuff that will run in the background anyway?
Click to expand...
Click to collapse
If you disable it for the current user, it won't run in any way, yes.
OpenGApps itself shouldn't install anything on system level. But those apps will be installed on system level since you flash them to the system (using your recovery). However, if you disable them they won't run in the background.
Dani3I said:
And are OpenGApps not something that I should not install when I don't want to get a google ban?
Click to expand...
Click to collapse
I don't know.
jwoegerbauer said:
You are confusing (Open)GApps - Google themselves call them Google Mobile Services (GMS) - and Google Play Services what are two completely different things.
Google Play Services is one of the most important parts of Android. It helps connect everything together and hold it all there. The Google Play Services are the interface to the Google Mobile Services as well as to the hardware functions of the Android device. Many of your apps use Google Play Services everyday.
GMS is a bunch of apps what includes
Google Play Store,
Google Now,
Google Play Music,
Google Maps,
Google+,
Gmail,
Google Photos,
Youtube
and the Android Device Manager.
Knowing the difference it should be clear that GMS can get installed on a per-user basis whereas Google Play Services not.
Click to expand...
Click to collapse
Yep that's absolutely correct

Categories

Resources