Live data from Hacker News

Tell HN: PayPal blocks GrapheneOS

news.ycombinator.com

151–160 of 361 posts

Re: Tell HN: PayPal blocks GrapheneOS

#151
It works here. Running in a work profile, no contactless payments.

Play Integrity API: Not blocked

Hardened memory allocator: Enabled

Memory tagging: Enabled

Extended virtual address space: Enabled

Secure app spawning: Enabled

Native code debugging: Allowed

WebView JIT: Disabled

Dynamic code loading via memory: Allowed

Dynamic code loading via storage: Allowed

Re: Tell HN: PayPal blocks GrapheneOS

#152
post #51

Earlier quoted context omitted.

How does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.

If you run a rooted phone and download malware, that malware can gain root and do payments on your behalf. Then PayPal has to deal with you revoking payments etc., they don't want to so they forbid you from using PayPal on a rooted phone.

For that argument to hold, they'd also have to blacklist any phone not running the newest, most up to date Android version, because all older versions presumably have known exploits. So that basically leaves Pixel phones.

Re: Tell HN: PayPal blocks GrapheneOS

#153
post #17

This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!

Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors). Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good g…

The cherry on top is that their web site invariably still works so the refusal to work via app is an intentional manipulation tactic to harvest more consumer data for sale.

Re: Tell HN: PayPal blocks GrapheneOS

#155
post #17

This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!

It was never about your security, it was about the corporation's security from you!

Re: Tell HN: PayPal blocks GrapheneOS

#156

Earlier quoted context omitted.

Yet another weak point. My question stands: A user with an OS from 2019 is "secure" and dozens of unpatched CVEs but a literally-last-night-patch OS is not? That's the "stuff they have to deal with"? I was lucky and did not make the mistake of joining a payment provider in 2020 or 2021 (I can't remember). The reality is that European laws are much harsher when it comes to payments and personal data protection and the…

> That's the "stuff they have to deal with"? No. It's the offensive fraud vector coming from unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.

> unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.

Bullshit! Source:

> The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic

Sounds like someone who wanted to impress the audience with fluffed up claims.

Re: Tell HN: PayPal blocks GrapheneOS

#157

Dumb idea, but I wonder if the underlying os can see who is asking questions like do you have root, And if an app has no need to know, it just plays dumb and responds...of course not. It's a bit of a chicken and egg problem, in that if you don't know what apps need to know if you have root, or not, then you can't determine that at the OS level...maybe an option for the user (popup) to tell the program, tell them we a…

perhaps but this is about device/os attestation, not rooting

How does their web site do device attestation? The argument that apps have to be locked behind a validation mechanism controlled by Google to be secure is BS when a cookie is sufficient.

Re: Tell HN: PayPal blocks GrapheneOS

#159

Earlier quoted context omitted.

Which countries have local banks that don’t know how to do international transfers?

My local banks know how to international transfers but I have to go into a bank office and fill out a paper form. Receiving international transfers they call and ask if I wish to accept it, if I can't answer the phone right then the transfer gets delayed. If the sender does not include my middle name, I have to come into the office and sign an affidavit that this person with this different name is also me. Each time.

Thank you for sharing your experience. I don’t know what your local banks are and what country you’re talking about.
Post reply on HN