Will the sandboxed google play permit banking apps to work using TPM and secured credentials? Is it even possible to store secure credentials properly? I would expect whatever you initialised before grapheneOS is wiped before you can run the alternate OS. Is termux possible with a root/sudo function?
My banking app works fine on GrapheneOS today, but not every banking app does. If it depends on Google Play Integrity with strong integrity it won't because Google has successfully sold the blatant anti-competitive lie that you need to vendor lock-in your users to their OS to get security on mobile. Secured credentials work fine, everything works fine except stuff that by design is locked in to Google like Google Pay…
https://grapheneos.org/articles/attestation-compatibility-gu...