This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!
Tell HN: PayPal blocks GrapheneOS
351–360 of 361 posts
Re: Tell HN: PayPal blocks GrapheneOS
#352I would bet that fewer than 1/1,000 non-HN users have ANY clue what it means to root a device. I sure don't!
GrapheneOS doesn't involve rooting a device. It's a privacy and security focused OS for hardware with official support for using another OS.
Re: Tell HN: PayPal blocks GrapheneOS
#353Earlier quoted context omitted.
Who is making these rules up? Why do you think they apply universally?
God made them, as far as I know. Humanity lived in gift economies long before the invention of barter and trade. These are etiquette rules, which have their benefits. Since nobody is forced to follow etiquette, they help you to learn things about people. Generosity is one of the easiest life hacks to find out who is friendly towards you and who is not. If you buy them a drink and they won't buy you a drink back, that…
Re: Tell HN: PayPal blocks GrapheneOS
#354Earlier quoted context omitted.
Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors). Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good g…
That's your argument? Mate, you can make explosives out of stuff you can buy in literally any supermarket and no one bats an eyelash. You don't have to legally be adult to buy any of the things you'd need and I say that as someone who only struggled with chemistry in school, that's now low the bar is. What's the solution then? Ban sea salt? If someone is using Graphene, the chances of them getting hacked are astronom…
Edit to clarify: I don't say I agree with that, I believe that if they don't want you messing around inside their app, then they shouldn't ask to be on your device.
Re: Tell HN: PayPal blocks GrapheneOS
#355It works for me after enabling exploit protection compatibility mode. Pixel 9a on latest versions of GOS and PayPal.
With the default settings, the latest versions of PayPal only require disabling secure app spawning. It may also require dynamic code loading via storage, dynamic code loading via memory and native debugging being permitted but those aren't blocked for user installed apps by default. People can opt-in to those being enabled by default for user installed apps similarly to memory tagging, but memory tagging has the big…
Re: Tell HN: PayPal blocks GrapheneOS
#356Re: Tell HN: PayPal blocks GrapheneOS
#357Earlier quoted context omitted.
Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal with is so extreme. It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The bloc…
This is interesting. You're gesturing at the idea that individual security practices can be at odds with those needed for group security. I'll be pondering on this.
Re: Tell HN: PayPal blocks GrapheneOS
#358Earlier quoted context omitted.
Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors). Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good g…
How does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.
Create lots of fake accounts, bounce transactions, use them to automate phishing scams, etc.
Massively harder to do that on a non rooted device.