Earlier quoted context omitted.
If this is similar to LineageOS, then it's always potentially only a matter of time until some banking and payment apps stop working due to failing security attestation pushed by a Google update. We need native apps that pass attestation out of the box for that phone/OS, not relying on hacks that may or may not work in the future. This is not good UX and it poisons the well if you push users to a new platform then th…
Beats me why banks can't use a FIDO2 enabled web site.
The European PSD2 directive mandates that the 2FA scheme must let the user see what they’re about to sign. At the very least, that includes the amount and part of the recipient’s IBAN. FIDO2 doesn’t have that.
It’s the reason I own a device that looks like this [0]. Without it, I wouldn’t be able to transfer money at all due to the lack of banking apps that work on Linux phones.
[0]: https://en.wikipedia.org/wiki/Chip_Authentication_Program