Comment by platinum95
14 hours ago
Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
> Revolut is notrious in this regard. If memory serves, they explicitly check the build string for LineageOS and block the app if it matches. The workaround at the time was to build the ROM yourself with a new build name string.
What possesses companies to do things like this? A customer running a current version of LineageOS is going to have better security than running the out of date Android version that came with the phone. An attacker who wants root on something that will run the bank app doesn't have to use a different OS, they can just use any of this month's CVEs to root the "approved" version. Even requiring the latest patches -- which would exclude entirely too many actual customers' phones -- wouldn't stop attackers from controlling their own devices, because they could root the device before installing the patch and then install the patch for the vulnerability they used to get root on the device where they already have it.
And attackers who are going to modify the system to carry out an attack inherently have some kind of software development capacity, so measures like this have no effect on them and all they actually do is interfere with the ability of honest normies to replace their out of date OS with a version that is less likely to be compromised by attackers.
Are they just taking kickbacks from Google or something?
I suspect that especially banks have paranoid lawyers that probably don't understand the situation entirely, and perhaps because of that, mandate that all means have to be used to prevent non-official builds from being used, so that they cannot be sued (for some reason) if "something" goes wrong. Though I don't know if they are consistent and also apply the same reasoning to phones that don't have active security updates any more.
I feel like "the lawyers told us to do something stupid for no legitimate reason" is just one part of a bureaucracy trying to blame another part for the fact that the bureaucracy itself is doing something stupid for no legitimate reason.
4 replies →
This is the problem: it was a cat and mouse game always. I managed even strong integrity with keybox stuff and so on. Yes it is possible. But if you really need to do send money or e. g. want to pay with NFC, it gets rather stressful. Yes, I got everything working (Note 10 pro on LOS 23), but never longer than a few month.
There are alternatives to Google Pay in Europe which work on GrapheneOS and it's likely most of those work on a production (user) build of LineageOS with a locked bootloader too. Only a few are specifically permitting GrapheneOS, and those would also be willing to explicitly permit a subset of LineageOS devices too. They'd need to start keeping a bit more of the standard security model and features intact which wouldn't be a large change. They'd mostly just need to make full production builds and start officially supporting locking. Having the privacy and security improvements done by GrapheneOS is in no way a requirement for compatibility with those financial apps.
This really is really a great development. I really just hope that will be true for the new European Digital Identity Wallet as well and we see adoption across multiple industries.
The state for me personally is that my joint bank account with my wife uses a play integrity protected banking app (changing your own a accounts to a better bank is one thing). Also beyond banks things now require proprietary 'secure' TAN apps like my insurance broker. The issue is that for me every a new problem like this popped up and to find solutions take time over and over. Even thing that work now may stop working the next minute because there is no real effort of fintech and its management to keep compatible with niche devices. It is mostly either coincidence or the effort of tech savvy individuals at those companies.
We only can hope that a large group of people including regulators get sanctioned or mandated not to use any US tech even privately so they see little offer is left even inside Europe that is truly sovereign. I gave up for now (after about 10 years exclusive on LineageOS ). I actually bought a pixel to have Graphene as a way out of vendor ROMs again, but I still don't have the energy to switch (alone reregistration all those TAN apps takes ages often involving waiting weeks for stupi snail mail activation letters)
I just decided to completely stop paying with NFC. I always carry a few cards with me and Wero is already working in a few spots, which requires just your banking app and a working camera.
I don't even have Google Wallet installed anymore.
Go even further and carry cash! No technology dependency and "just works".
7 replies →
Good to know. I'm using N26 and they work just fine in Graphene OS. What I do is I create a private space for the apps needing play services, which I keep locked most of the time. This acts as a separate profile and when locked, the apps including play services are completely off. My main profile uses only open source apps and no play services.
I actually called N26 (I'm a Metal customer with my own phone support) and asked will they support Graphene OS or no, and they said to me they will and gave me instructions what to keep in mind when installing the app.
N26 also works fine on rooted devices. They don’t randomly block devices like others (besides Revolut, DKB comes to mind).
I applied to open an N26 account, and after completing all the necessary documentation they then told me I had to install their app to activate the account. Forget it.
Instead I opened an account with Wise, and have never once been forced to use their app. One occasion where some ID verification process pushed me towards the app online, I spoke with support and everything was sorted without it. Wise.com, just need a web browser and a phone number, zero phone app dependency.
3 replies →
Just be careful. I locked myself out from my bank when I installed a second phone that did not have sim card yet and had the app in my old phone.
It requires a sim card and cannot be used from multiple phones. So they put you to this endless face scan loop and then lock you out.