Earlier quoted context omitted.
> Some banks also connect it to your phone number What do you mean "some banks"? I thought the whole value proposition of Wero was instant bank transfers with SEPA but using phone numbers?
Wero is a payment provider technology, a money wallet, and a bank account integration technology under one single marketing name. On the payment provider technology side, you're right, but the wallet feature uses phone numbers (and I think email addresses) so you can send each other money without sharing your IBAN (which is slightly longer and probably not in your contacts).
Tell HN: PayPal blocks GrapheneOS
261–270 of 361 posts
Re: Tell HN: PayPal blocks GrapheneOS
#262[flagged]
GrapheneOS doesn't give you root access. The OS is designed to offer privacy and security guarantees, which root access breaks, so they don't offer it.
Re: Tell HN: PayPal blocks GrapheneOS
#263I also ran into the eBay application being blocked just recently. Other than that I've had no issues, but I imagine this is going to become more and more common as time goes on.
Most likely, unless the GrapheneOS user base can be grown quickly. We are at a point in time where the number of apps that block GrapheneOS through Play Integrity Strong is fairly small. So it's still possible to grow the user base since the inconvenience is not too large. Once the majority of banks would require passing Play Integrity Strong, far fewer people would switch. So, best to grow the user base fast now and…
Re: Tell HN: PayPal blocks GrapheneOS
#264This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!
Revolut pulled that stunt, I cancelled my account with them.
Re: Tell HN: PayPal blocks GrapheneOS
#265Earlier quoted context omitted.
Nobody’s shaming you, reddit refugee. It is a common userspace decision to lock things to userspace. It’s good hygiene. If you want less-secure software, use AOSP or one of its many forks. You’re not defective: you just have different needs and threat model, and you’re harassing and degrading the public image of a project that’s opinionated in a very welcome way by folks in the security community - especially those w…
"It is a common userspace decision to lock things to userspace" Yes, running in userspace for the majority of tasks is good hygiene. Preventing the user from ever escalating beyond that layer on their own devices, however, is restricting their freedom to control their device. When that happens with tractors, cars or other gadgets that's considered anti-user. The same attitude should extend to phones.
You have complete control of the device.
You choose to lock certain things when using GrapheneOS. That’s their security model.
If you want to argue that, go study it and argue that.
If your threat model is different, if your desired security model is different, then: it’s not for you, use one of many other options.
Like all software projects, it doesn’t necessarily exist for you - or anyone specifically.
It’s not harming you for it to exist.
Re: Tell HN: PayPal blocks GrapheneOS
#266GrapheneOS officially passes only the MEETS_BASIC_INTEGRITY tier of the Google Play Integrity API and fails the MEETS_DEVICE_INTEGRITY and MEETS_STRONG_INTEGRITY levels.
Many banking apps I use in my country require this level plus something from the GPI API, which makes them unusable. You need a regular, unmodified smartphone to use them.
Re: Tell HN: PayPal blocks GrapheneOS
#267Re: Tell HN: PayPal blocks GrapheneOS
#268Earlier quoted context omitted.
This is the PayPal version I have installed that works: Version 8.107.0 com.paypal.android.p2pmobile
Looks like I have 10.10.0. They'll most likely remove support for older versions server-side at some point.
Re: Tell HN: PayPal blocks GrapheneOS
#269Earlier quoted context omitted.
"It is a common userspace decision to lock things to userspace" Yes, running in userspace for the majority of tasks is good hygiene. Preventing the user from ever escalating beyond that layer on their own devices, however, is restricting their freedom to control their device. When that happens with tractors, cars or other gadgets that's considered anti-user. The same attitude should extend to phones.
You can wipe the device and reinstall whatever at any time. You have complete control of the device. You choose to lock certain things when using GrapheneOS. That’s their security model. If you want to argue that, go study it and argue that. If your threat model is different, if your desired security model is different, then: it’s not for you, use one of many other options. Like all software projects, it doesn’t nece…
Re: Tell HN: PayPal blocks GrapheneOS
#270Earlier quoted context omitted.
The problem here seems to be that the phone is detected as rooted, not specifically that it's running grapheneOS. But I agree that it's a big problem. That's how you end up in a situation where google has full control from hardware to final apps like on iphones. When devs assume that everybody is using the stock android with google services enabled.
[flagged]