8 ms·
"needs root and patches to AOSP". So there go the banking apps mentioned elsewhere and you can just use postmarketOS. Still cool though!
by fock 2y ago
"needs root and patches to AOSP". So there go the banking apps mentioned elsewhere and you can just use postmarketOS.
Still cool though!
- bboygravity 2y agoI have a rooted phone and when you hide root (using Magisk app) all banking apps work just fine?
- kiney 2y agoSome, not all. Last time I checked magisk wasn't able to fake safetynet hardwareattestation
- igor47 2y agoYup. I gave up on trying to get Google wallet / Android pay to work on my lineage device. I got it working sometimes but it broke after update and just wasn't reliable enough to keep trying when paying for stuff. I'm not really sure whom they're protecting with this stuff -- the credit card processing companies, maybe?
- JonChesterfield 2y agowallet doesn't work reliably on a non-rooted pixel phone with approximately zero software installed on it either, you may not be doing anything wrong
- kotaKat 2y agoAs far as I also understand Google Messages now uses this as well to gatekeep access to carrier RCS. https://www.theverge.com/2024/3/1/24087418/google-messages-blocking-rcs-on-rooted-android-devices https://www.theverge.com/2024/3/1/24087418/google-messages-b...
- phh 2y agoHow do you know it's carrier RCS? To the best of my knowledge they are only gatekeeping access to Google Messages private network, not carrier RCS? (Considering the very little number of carrier RCS that's not very relevant though)
- kotaKat 2y agoAll US carriers are now using Google's hosted Jive RCS infrastructure which means "Google Messages".
- crms1496 2y agoI have found Play Integrity Fix [1] with playcurl [2] is reliable enough for passing Play Integrity in Wallet and other apps. My current issue is that Google Messages has its own integrity checks that are stricter than Play Integrity, and will silently stop handling RCS messages if it fails those checks. I currently have RCS disabled because it is too unreliable. [1] https://github.com/chiteroman/PlayIntegrityFix https://github.com/chiteroman/PlayIntegrityFix [2] https://github.com/daboynb/PlayIntegrityNEXT https://github.com/daboynb/PlayIntegrityNEXT
- LoganDark 2y agoHuh, I don't have issues with RCS on my rooted OP7Pro. Is my version just sufficiently out of date not to have those extra checks?
- freedomben 2y agoI also have OP7Pro (what an amazing phone btw), and yes, we're pretty much sufficiently out of date that they still work - a wild but true reality we find ourselves in.
- LoganDark 2y agoI mean my Messages app. I installed it years ago and never updated, because why would I ever updated an SMS app, the only thing that can ever happen is for things to break that used to be working, lol. I don't even know if I run A12. I do know, though, that the OP7Pro is one of the last Android devices that are whitelisted by Google to pass SafetyNet without hardware-backed attestation. Shame that TWRP wiped my working setup. I've been trying to get them to add any basic protection against that for over three years: https://github.com/TeamWin/Team-Win-Recovery-Project/issues/1597 https://github.com/TeamWin/Team-Win-Recovery-Project/issues/... It is an amazing phone. Notchless, relockable bootloader (not just unlockable, but custom AVB key support!!), in-screen fingerprint sensor, 90Hz AMOLED, and great build quality.
- sangnoir 2y ago
- LoganDark 2y ago> I'm not really sure whom they're protecting with this stuff -- the credit card processing companies, maybe? (small nit: does "whom" even go there?) They're protecting the TEE because they do not want third parties to be able to automate Google Pay through modified software. This isn't necessarily just about normal end users but more like smartphone farms.
- nobody9999 2y ago>They're protecting the TEE Why do Transesophageal Echocardiograms[0] need protecting, and from whom do such diagnostics require protection? I expect I'm missing something, but a web search for 'TEE' only returns that diagnostic test.[1] [0] https://www.webmd.com/heart-disease/atrial-fibrillation/transesophageal-echocardiogram https://www.webmd.com/heart-disease/atrial-fibrillation/tran... [1] Moral: Don't assume everyone knows what a particular acronym means. Just because it's in your head doesn't mean everyone else knows what you mean.[2] E.g., if I say 'JRE' I mean 'Java Runtime Environment' and not 'Joe Rogan Experience'. [2] According to Piaget[3], people are able to identify that others don't know what's in their heads sometime between ages two and seven. [3] https://psychcentral.com/health/piaget-stages-of-development#preoperational https://psychcentral.com/health/piaget-stages-of-development...
- LoganDark 2y agoSorry, TEE stands for Trusted Execution Environment. It's where stuff like DRM executes with access to secrets that the HLOS (Android) can't tamper with. On ARM SoCs the TEE is usually provided as part of TrustZone. No need to patronize.
- nobody9999 2y ago>Sorry, TEE stands for Trusted Execution Environment. No apology necessary. I was just a little confused. Thanks for straightening me out!
- Nexxxeh 2y agoI think, probably unintentionally, you've misjudged or ignored the tone your message is likely to be read as having. To me, your comment comes across as having a rude and insulting tone. I think the person you were replying to read it in a similar tone to me based on their response. ("No need to be patronizing.") Is that the tone you intended? A better way of handling it may have been with a simple, "What does TEE mean in this context please? Googling it didn't help me." I'm asking the question rather than assuming it was intentional, as you put more effort into your comment than is necessary to just be rude. It feels like you may have been trying to be helpful and just misjudged the tone. Maybe as a fellow neurodivergent person.
- ga2mer 2y ago>you can just use postmarketOS Only if your device is fully supported I have about 5 "post market" devices and only two of them have any support in postmarketOS: Redmi 4x, in which hardware acceleration does not work and I have not been able to run any DE on it and Pixel 4a, in which judging by the pmOS wiki page works just about everything except the most important part of a modern phone - touchscreen
- linmob 2y agopostmarketOS provides tooling, documentation and a helpful community ... at some point, you'll need to put in the work, or sell your used devices and buy other, better supported used devices to work around this. Is it really unfortunate that there's no (known) mainline/close to mainline touchscreen driver for the Pixel 4a? Absolutely. But it won't magically appear without somebody putting in the necessary effort.
- calgoo 2y agoAs it’s Linux could we run android in a vm and simulate a safe device? That’s my hope for the future of mobile devices, safe VMs that we can run on top of the spyware (government enforced stuff too) infested phones.
- franga2000 2y agoUnfortunately, most of those misguided "device integrity" checkers detect VMs and the best of them (luckily still not used very often) are essentially unbeatable (unless there's a critical bug) due to hardware-backed attestation.
- gigel82 2y ago*worst
- phh 2y ago> essentially unbeatable (unless there's a critical bug) due to hardware-backed attestation. FWIW Google started enforcing those attestations like one month or two ago, and there are many critical bugs. I haven't kept scores, but some other people did : https://x.com/wanghan1995315/status/1803063996204912873 https://x.com/wanghan1995315/status/1803063996204912873 And please note that they only list big brands leaks. Since you can use any OEM's attestation key, /any/ OEM leak can break those so-called "security protections". Even after all security flaws, there is still social engineering. I guesstimate that you could ask an ODM's engineer for an attestation key for like 1k$ and share it to like 20 persons. (200 would probably still remain under the radar, but you need to be capable of keeping a secret with 200 persons) Though the conclusion shouldn't be that attestation keys are insecure and we need a secure variant (because a secure variant is indeed coming). The conclusion must be that users own the device they bought. Not Google, not Apple.
- mschuster91 2y ago> And please note that they only list big brands leaks. Since you can use any OEM's attestation key, /any/ OEM leak can break those so-called "security protections". Inevitably though, the price of these will rise, the most capable eyes on the planet will have a few very thorough looks at all the TPM chip firmware they can get their hands on, and eventually platforms will be so secure and the price will be so high the only ones left to have them are three-letter agencies (if even these). Anti tamper measures have their place - I'd really love to have a device that cannot have a persistent backdoor implanted - but the very second the state of the anti-tamper measure becomes visible to user-level applications, they become an arms race between Big Money (=DRM rightsholders and big game studios) and my freedom.
- unicornhose 2y agoThere’s a place for DRM and similar protections, I don’t think they’re going anywhere. But I’m still hopeful that phone, email, web, voip, videochat, photo and video editing, location, maps, document sync, etc, will one day work seamlessly on FOSS devices. I do think that the apps will have to be recreated as FOSS, existing apps will always be antagonistic because they get a lot of revenue from being able to control how/when/where the software is run.