Comment by giantg2
11 hours ago
Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?
11 hours ago
Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?
People use alternatives for many different reasons (or multiple at the same time):
- They might want privacy from Google. Using Google Pay probably doesn't make much sense.
- Security protection against Google. Google can remotely brick devices with unsandboxed Play Services. After blocking of ICC officials and all the Greenland threats, it's not odd that some European citizens would like to block this Google/US government attack vector.
- They want a clean phone without all kinds of crap like Gemini preinstalled.
- They want to reduce dependence on big tech/Google product in general.
In cases 2-4, using Google Pay with sandboxed Google Play services may be an acceptable compromise for convenience.
Minor note, you forgot battery life. Pinging your location every other minute for traffic and crowd denisty for Google Maps, even using AGPS, isn't cheap.
When you find battery life randomly tanks for a few days, despite not changing anything in your life, it's always Google Play Services that end up being the culprit
Great point! For me that was not a reason to get a phone with GrapheneOS, but definitely a noticeable/welcome side-effect.
Is this an AI response? I get why people want a de-googled phone. What I don't get is why they would want to use tap to pay, one of the payment methods with increased attack vectors.
> with increased attack vectors.
I don't follow. If you mean against fraudulent spending phone based tap to pay is probably the most secure. It demands user authentication (biometric or code) for any transaction so there's no real way to trigger a fraudulent spend without the user knowing. Pretty much any other system allows for at least some amount of unauthorized spending if it's stolen.
If you just mean it's less private than I don't really know that it's terribly different than using a card. Especially if the ecosystem were open and you could choose your payment provider and not just have to use Google/apple.
2 replies →
> Is this an AI response?
Probably not but you’re doing a bad job explaining what wanting to de-google your phone has to do with the choice of wireless payment methods.
It’s in the name, “de-googling”, not “de-attack-vectoring”. People want to break away from Google specifically. They’ll still use tap to pay because it’s convenient, secure enough, at least as private as any card/bank payment, and ideally not Google, which was what people de-googling want.
2 replies →
Is this an AI response?
No.
I hate AI writing, so I never use AI for writing. Randomly throwing in accusations in discussions sucks. I don't think my comment had any of the hallmarks of AI writing either, unless bulleted lists are also not-done these days.
I guess I should be happy that people don't recognize me as a non-native speaker anymore?
2 replies →
Without Google doesn't mean the same thing for everyone. I got a Motorola g moto stylus 2025 and have been running an experiment for almost a year now in which I use this device without ever logging into the device with a Google account. Fdroid and obtainium work flawlessly. Aurora Store works for the most part but some apps won't even let me open them without a play store signed in account which is sad.
Because people have different priorities than you do, and just because you can't imagine something, it doesn't mean it's not real or reasonable.
Some people like to have choices other than "all" and "nothing"
How about a way to use contactless payments on, say, a Pebble watch?
Xiaomi Mi Band 6 and 7 support NFC card emulation for payments, issued by Visa/MC.
Tap to pay apps, if the developer is trustworthy or if it’s from your bank, are significantly more secure than even carrying a physical card around as your payment is now locked behind biometrics/a pin.
Also de-googling isn’t the point of GrapheneOS.
Well it's going to be a matter of time anyway, I'm already forced to use an app when I'd rather not.
But more than that I want to have a choice.
Because it’s convenient?
I agree, it's very convenient to have a phone full of corporate malware. But I thought the point of GrapheneOS was to escape that. My corporate malware only runs on my secure card processor which sits in a pocket glued to my phone.
But I thought the point of GrapheneOS was to escape that.
I think the point of GrapheneOS is being as secure as possible first and within those parameters give people the choice how much of Google they want. They have implemented sandboxed Google Play Services for a reason. Many people need Play Services for practical reasons (e.g. because they need to run apps that require it), so let's then run it in the most secure/private way possible - make it a sandboxed app, allowing users to decide whether to install it or not and if they choose to, that they can assign/revoke permissions like any other Android app.
The very moment it becomes possible to create a Google Pay alternative, there will be at least a dozen choices, some of them fully open source and privacy conserving.
The only reason why we don’t have them is Google / Apple duopoly.
3 replies →
You're begging the question. The entire premise of this thread is "we should be able to pay without infesting our phone with corporate malware".
7 replies →
Because tap to pay has nothing to do with Google?
Some people just want a phone without the duopoly and nothing else.
Why can't I use my bank's app, which I presumably already trust, to tap-to-pay? Why should there be a third party involved at all?