Live data from Hacker News

GrapheneOS – Break Free from Google and Apple

blog.tomaszdunia.pl

481–490 of 967 posts

Re: GrapheneOS – Break Free from Google and Apple

#481
post #470
post #135

Earlier quoted context omitted.

> I can use my bank on some linux distro, crazy that they trust me enjoy it while it lasts. hardware attestation requirement for (at least) banking apps is a question of 'when', not 'if'.

My bank has always had hardware attestation, but it was their hardware that was being attested. Customers get it loaned when signing up I have no problem with a device that they trust being used for transaction approval, but that device shouldn't also be the device I use for my daily life and do all sorts of private things on. We should want to be able to inspect that one

I agree completely, except looking at my 2fa app I'd need 20 physical tokens, so we actually need a super-duper-yubikey

Re: GrapheneOS – Break Free from Google and Apple

#482

Earlier quoted context omitted.

> Can the PIN change? You can change it in the app, yes. > How to issue new key if needed? I think you’ll have to reissue your ID. There’s also digi-ID (similar e-signature certificate on a card, but without any ID features), Mobiil-ID (e-signature on a SIM-card, no idea how it works), Smart-ID (in app, tied to secure storage in Android/iOS, cross-signed by the server which is supposed to check the device somehow) an…

> You can change it in the app, yes. Is the app tied to Google or Apple?

Nope, there’s a desktop version, too. And it’s all free/open source: https://github.com/open-eid

(Though Smart-ID is its own thing and is a fair bit more locked down, but I’ve managed to get it running on a phone without Google services IIRC.)

Re: GrapheneOS – Break Free from Google and Apple

#483

Earlier quoted context omitted.

Lyft app works on GrapheneOS.

Using websites instead of apps, while often more annoying, minimizes dramatically the privileges you provide to services.

And the amount of lock-in. If they ever decide to kick out your favorite OS or hardware vendor, well, good luck doing that if you can use the services on a website. They'd have to port all the web users over to mobile and know they'll lose at least some of those customers

Re: GrapheneOS – Break Free from Google and Apple

#484

Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app. It's mind boggingly stupid that they lock down apps like this, when you ca…

It sorely needs to break free from the lackluster Pixel hardware. The OEM announcement can't come soon enough (and I hope it's Motorola).

Re: GrapheneOS – Break Free from Google and Apple

#487

Earlier quoted context omitted.

> You can change it in the app, yes. Is the app tied to Google or Apple?

Nope, there’s a desktop version, too. And it’s all free/open source: https://github.com/open-eid (Though Smart-ID is its own thing and is a fair bit more locked down, but I’ve managed to get it running on a phone without Google services IIRC.)

Wow, that is nice!

Re: GrapheneOS – Break Free from Google and Apple

#488

Earlier quoted context omitted.

TOTP not accepted, because the confirmation for payment must include the amount to be paid, which cannot be done under TOTP as far as I know.

Some UK banks (Nationwide and Barclays I know for certain) have had mini card-reader PIN devices since around 2010 that they've given customers, that basically generate on an LCD screen an 8-digit code for authentication. When confirming a large transfer, you also need to enter the payment amount in the device, and I assume this gets hashed into the number as well. More recently (last 3/4 years), you can also use the…

Moved from the UK to Germany. My German card reader is even better, no manually entering the transaction details, I just scan a QR code from my laptop, and the card reader display shows the IBAN and amounts, before I confirm to get the code.

Re: GrapheneOS – Break Free from Google and Apple

#489
post #372

Earlier quoted context omitted.

Did you miss the part where I said I use both? I'm not saying "yours" is less convenient. I'm saying the one you and I both use regularly is less convenient than anything NFC based, which I also use semi-regularly.

I'm confused. You say: > It's arguably quicker to open your wallet and use a debit card with an NFC chip than it is to use QR codes So I assume that even though QR codes are available where you live, you use your debit card with an NFC chip because it is quicker than using QR codes... Anyway, the important part is that NFC doesn't require an internet connection, and I had missed that. Now I wonder why a QR code could…

> So I assume that even though QR codes are available where you live, you use your debit card with an NFC chip because it is quicker than using QR codes...

Yes, I generally use my card rather than than QR unless the shop doesn't take cards, doesn't have a paywave/etc-enabled card reader, the card reader is broken, the sales person doesn't know how to use it, or the sales person insists I give them my card and PIN to pay (none of those are hypotheticals, I've experienced all of those first hand, some of them quite repeatedly).

> Now I wonder why a QR code couldn't work without an internet connection just the same.

Because a QR code is just a short piece of information to tell your banking app who to send funds to - it's like putting a mailto: link on a website rather than asking people to re-type your email address to contact you.

Re: GrapheneOS – Break Free from Google and Apple

#490

Earlier quoted context omitted.

Yeah that's the first thing a pentest will complain about, had the same problem too. I pushed back enough so that it's trivial to bypass but the bank and pentesters also agreed with me that it's security theater or else I would never had the chance.

I always ask them if they have root/admin on their computer. Then follow up playing dumb with "shouldn't we lock out PCs too?". Watching them stammer is worth the 30 second aside.

[dead]
Post reply on HN