Live data from Hacker News

Tell HN: PayPal blocks GrapheneOS

news.ycombinator.com

111–120 of 361 posts

Re: Tell HN: PayPal blocks GrapheneOS

#111

Switched to Wero and haven't looked back. https://wero-wallet.eu

Unfortunately peasants like us who don't live in the 5 countries where it's available still can't look back

I live where it's available and still can't use it to pay stuff, only to transfer money to friends.

Re: Tell HN: PayPal blocks GrapheneOS

#112
post #75
post #64

Earlier quoted context omitted.

Interesting, just inferring from that it sounds like GrapheneOS's actual-security features might have been tripping up PayPal's root-detection "security" features. (Rather than something fundamentally incompatible, like them using Play Integrity)

There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :) IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.

So to use paypal you actually have to reduce the security of the phone?

Re: Tell HN: PayPal blocks GrapheneOS

#114
post #84

Why would anyone still use PayPal after so many cases of accounts being banned and funds being frozen for no reason, and all the other terrible stuff they've done?

Easy to say when you are in a country where you have a lot of options. There's some countries with very bad financial sector where your option is PayPal or Western Union as the local banks don't know how to do international transfers, Remitly doesn't support all countries and Wise also doesn't work. PayPal works, even if they charge fees.

Which countries have local banks that don’t know how to do international transfers?

Re: Tell HN: PayPal blocks GrapheneOS

#115
post #51

Earlier quoted context omitted.

Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors). Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good g…

How does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.

Graphene OS does not support root. This is a false positive based on some check they are doing.

Re: Tell HN: PayPal blocks GrapheneOS

#116
post #72

Earlier quoted context omitted.

Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.

Noo, it’s the other way around lmao. A financial security audit is one of the most thorough security audits you can ask for in software. GrapheneOS gets blocked because it doesn’t follow the secure system requirements (root).

As several others have already said here, GrapheneOS is not necessarily rooted. So that's a lie.

Also, I've seen such audits internally, and they don't care about security at all. They care about the theatrics of security waaaaay more.

For example, I was at Santander in 2024, during its huge data breach. Here is the list of actions which are supposed to prevent the same kind of attacks again in the future:

-

Yeah, it's an empty list.

But of course, they made our life more difficult. In the end, I literally had more permission than before, because they were even sloppier than before. But of course, I had to change my password more frequently, and I had to type it about 5x more.

Re: Tell HN: PayPal blocks GrapheneOS

#117
post #76

Earlier quoted context omitted.

I use "virtual card" for those needs. For me, it doesn't justify bringing out PayPal

I've had to use it when my bank's purchase limits did not allow for card (virtual or real), but the same purchase was allowed when going through PayPal. It was annoying AF, but was much faster than contacting my bank and getting permission to spend my money.

Privacy.com is a better option, but some merchants block it.

Re: Tell HN: PayPal blocks GrapheneOS

#118
post #34

Why would anyone still use PayPal after so many cases of accounts being banned and funds being frozen for no reason, and all the other terrible stuff they've done?

Critical mass? I had to start using it after moving to Germany, because everyone else expects you to use it. One of the ladies at daycare is leaving? Here's a paypal link to chip in for a good-bye present. Split a take-out order with a German friend, but he paid? Here's his paypal to send him your share. It's just assumed that everyone has paypal over here...

Time to start heralding change you want to see. Offer Wero instead. It’s really simple.

Re: Tell HN: PayPal blocks GrapheneOS

#119
post #75

Earlier quoted context omitted.

There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :) IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.

So to use paypal you actually have to reduce the security of the phone?

Not too surprising. I usually have to reduce my browser security on the rare occasion that I access PayPal via the web.

Re: Tell HN: PayPal blocks GrapheneOS

#120
post #17

This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!

Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors). Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good g…

Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal with is so extreme.

It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The blockades are one piece of a holistic security picture that frustrate the well intentioned users.

Post reply on HN