Live data from Hacker News

A big win for Android interoperability

openhomefoundation.org

171–180 of 194 posts

Re: A big win for Android interoperability

#171
post #99

Earlier quoted context omitted.

any legal entity can register their integrity attestation keys, with oversight by a bureaucracy in a process that takes 6 months and €100,000 That wouldn't be great, but at the same time an improvement over the current situation. attestation key that leaks into open circulation (such as FOSS) will be blacklisted in the registry because it no longer attests anything Which makes sense if remote attestation is what you…

Yes. It makes sense for well-regulated remote attestation. But is that what we actually want or do we want to destroy the concept altogether?

Exactly. There is no actual value provided by attestation that banks actually need. Banks have websites that work in web browsers, and those typically provide 99% of the functionality of the app, and yet the app demands attestation.

Re: A big win for Android interoperability

#172

Earlier quoted context omitted.

Phone tap to pay is really handy and provides more security than physical plastic cards. It should just not be used by Apple/Google to block out competitors. (Yes, I know banking apps can have their own tap-to-pay implementation on Android, but they all standardized on Google Pay because it's less work for them.)

How so?

Among many other things, with tap-to-pay you can use a different virtual card for every vendor, so that if it gets misused you can cancel it and know exactly which vendor mishandled it.

Re: A big win for Android interoperability

#173
post #50

I don't care about any of these, I just want to be able to have whatever Google pay does without Google. You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.

Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?

How about a way to use contactless payments on, say, a Pebble watch?

Re: A big win for Android interoperability

#174
post #87

Earlier quoted context omitted.

We had that for many years. But banks stopped supporting their own payment solutions because despite not having to pay commission to Google, it was more expensive to support their own solutions. That should also tell you that almost any open source / non-profit solution is doomed to fail due to costs. What could work is if, just like the UnifiedAttestation initiative has commercial backing, Wero is expanded to also h…

Would it be possible to build something that works at the os level? And is built in the system itself instead of depending on google services ? I mean I don’t think it requires internet access all the time

Yes, Russian MIR system works this way.

https://glenbrook.com/payments_news/russias-mir-domestic-pay...

Just an application which emulates the card over NFC. No need to Google Play Services. It's been this way for ≈10 years I guess.

Re: A big win for Android interoperability

#175
post #173
post #50

Earlier quoted context omitted.

Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?

How about a way to use contactless payments on, say, a Pebble watch?

Xiaomi Mi Band 6 and 7 support NFC card emulation for payments, issued by Visa/MC.

Re: A big win for Android interoperability

#176
post #117

Earlier quoted context omitted.

> with increased attack vectors. I don't follow. If you mean against fraudulent spending phone based tap to pay is probably the most secure. It demands user authentication (biometric or code) for any transaction so there's no real way to trigger a fraudulent spend without the user knowing. Pretty much any other system allows for at least some amount of unauthorized spending if it's stolen. If you just mean it's less…

You might want to look into NGate.

if I’m reading the source I found correctly, that has got nothing to do with Tap and Pay, where a virtual card is stored/emulated on device via the secure element, instead emulating an Contactless reader and relaying a real card pressed up against the device.

If anything, this attack is a benefit of mobile payments, where you need a second device to perform the attack with, and the user to use verify themselves for the payment to go through.

Re: A big win for Android interoperability

#177

Earlier quoted context omitted.

Is this an AI response? No. I hate AI writing, so I never use AI for writing. Randomly throwing in accusations in discussions sucks. I don't think my comment had any of the hallmarks of AI writing either, unless bulleted lists are also not-done these days. I guess I should be happy that people don't recognize me as a non-native speaker anymore?

The accusation was not random. That writing had an AI tone to it with the bulleting etc, and didn't address the actual point being questioned.

It did not have an AI tone, bullet points are not an indicator of AI, and it addressed the point well.

Re: A big win for Android interoperability

#178
post #42

Earlier quoted context omitted.

blows my mind that there’s not a single open solution for mobile wallets and nobody is saying anything.

Because a normal card is superior in most practical cases?

Haven't used a normal card in over a decade. I don't think my bank actually makes physical cards anymore, last time my card expired I just had a popup in the bank app that told me I have a new card. This was like 2-3 years ago. I use Google/Android Pay (or whatever it's called now) for NFC payments and have since 2018 and never carried a physical card since.

I would never use a physical card with NFC anyway because it is both inconvenient (have to enter PIN every 5 transactions) and insecure (for transactions without PIN there's no verification layer), whereas on my phone I have to unlock it for every transaction no matter how small, and doing so is a small matter of pressing my finger on the fingerprint reader.

I'm as anti-capitalist as they come but this is kind of a lost fight in my mind because if not Google - then Visa/Mastercard and the bank itself will know every transaction I make anyway.

Re: A big win for Android interoperability

#179
post #78
post #47

Earlier quoted context omitted.

No it’s not, all of my and my extended family cards (for… like a decade!) are never even leave the envelope they come in. I’m not sure I personally know people who use physical cards over Google or Apple Pay. I have seen the cards being used in the wild, of course. But I’m having hard time remembering anyone I personally know who does that.

How strange that culture is so different in different places. You can just start using them, though. Literally just swipe your card whenever you would swipe your phone. Do you guys not have wallets with card slots?

I've never had a physical wallet period. I'm not some Gen alpha baby either, I'm almost 30. I have like 4 bank accounts too.

Re: A big win for Android interoperability

#180
post #50

I don't care about any of these, I just want to be able to have whatever Google pay does without Google. You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.

Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?

Because privacy isn't represented as a binary.

You don't live life only having privacy or not having privacy. You fall somewhere in the middle. You can shift your overall privacy posture up if you de-google, even one service at a time.

Uninstalling Google Maps, whilst still using Gmail has privacy benefits. Each step improves your privacy. Some opt for convenience over privacy, you can pick and choose services to use whilst still retaining decent privacy.

Post reply on HN