8 ms·
It becomes much harder to force attestation on people if there's a significant user base that runs alternative operating systems.
by endgame 1y ago
It becomes much harder to force attestation on people if there's a significant user base that runs alternative operating systems.
- bombcar 1y agoDo you really NEED to be forced to attest if you can make your phone look like any damn PC using a browser?
- kube-system 1y agoI can’t tap my PC to buy a burrito at Chipotle.
- ray_v 1y agoThis sounds like a challenge to me.
- bitmasher9 1y agoIt’s actually super easy and not a challenge. The lowest tech way to do it would be the tape a cc with tap functionality to the inside of a laptop.
- deleted 1y ago[deleted]
- hn_user82179 1y agowhat a phenomenal comment, thank you for the laugh
- bombcar 1y agoI took "tap to pay" being clicking on Order in an app; and I have certainly made a "online order" from inside the Chipotle, on their wifi with my laptop (usually because walking to the counter would cost more because of stupid promotions). It makes more sense that they're referring to Apple Pay or similar shenanigans (which itself is more annoying than a credit card, to be honest, Face ID goes wrong or the double click closes the wallet app instead of authenticating way too many times, especially if you're trying to do it one-handed).
- hdseggbj 1y agoSo you pay more money and also give up your privacy for what you could pay cash for. I don't think you're the target market for this phone.
- kube-system 1y agoI pay less money for my burrito than I would with cash, but the reason I use my phone is convenience, not cost. > I don't think you're the target market for this phone. My comment is downstream of the entertaining of a possibility of: > a significant user base that runs alternative operating systems ... which isn't going to happen if you ask your users to give up commonly used features. It will forever be a niche project, at best.
- hdseggbj 1y agoAnd there are still folks who don't use ad blockers.
- deleted 1y ago[deleted]
- drnick1 1y agoYou seem to be part of the problem. As long as people like you are happy to run spyware on their phones for the sake of convenience or a meager discount, companies will be empowered to make such software and devices a requirement.
- austhrow743 1y agoDo you think the same for using credit cards in general or is using the phone somehow worse?
- drnick1 1y agoI use cash whenever possible, but carrying cash for larger transactions has its own risks and those risks need to be balanced against the privacy benefits it offers. The way I see it, carrying a credit card in addition to my phone when I might need it is a minor inconvenience relative to that of allowing Google complete control over my phone.
- bombcar 1y agoCredit cards have become mainly a way for the banks and visa/mc to use the customer to strong arm money out of the business. Get 3% and rebate some to the customer. For the convenience. It’s kind of sad, really.
- warkdarrior 1y agoI am all in favor of ways to strong-arm money out of businesses --- they seem to be doing quite well at the expense of customers.
- NoGravitas 1y agoI can tap my debit card to buy a burrito, no apps required on my end.
- jojobas 1y agoSome banks require app confirmation for PC-initiated transactions, using play integrity requiring apps. Cause security, you know.
- SchemaLoad 1y agoIt's because it's way easier to install malware on PC than mobile. None of us are immune either. In recent times there has been malware distributed by common NPM packages as well as game mods. Every NPM package you install has the ability to steal your browser session tokens and the only thing stopping the attacker from actually logging in and spending your money is the fact it has to be confirmed on your phone.
- jojobas 1y agoChoosing between a risk of that and preinstalled non-removable malware in every phone? Tough one, I know.
- array_key_first 1y agoThat doesn't require a bank approved app - we already have authentication mechanisms that are standardized. People do proprietary bullshit because they want to do proprietary bullshit. Anything else is made up.
- koolala 1y agoWhat kind of transactions require this? Normal bank transactions don't, right?
- deleted 1y ago[deleted]
- SchemaLoad 1y agoThese days browsers are becoming increasingly distrusted. My bank logs my browser out after 30 minutes inactivity and then to log back in I have to confirm the login on my phone.
- SoftTalker 1y agoThis seems desirable? Is your phone the only 2FA available?
- kennywinker 1y agoThat… seems reasonable? My bank does that with their website and their mobile app. I was able to setup 2fa using a totp app, so i don’t rely on sms for that part
- deleted 1y ago[deleted]
- SchemaLoad 1y agoIt is given the environment. But it does highlight the poor security of desktop browsers where they are only trusted to do anything when a phone app approves it. While the phone app is considered secure enough to just stay logged in perpetually without any external confirmation. To hack the banks app you have to find an exploit in iOS or Android which would allow you to read the other apps private storage, which is borderline impossible now. To hack the banks website you just have to buy some random browser extension and add malware to it, or break into someones NPM account and distribute it there, or any number of ways to run code on someone else's computer. Something very achievable by an individual.
- thwarted 1y ago> But it does highlight the poor security of desktop browsers where they are only trusted to do anything when a phone app approves it. Does it? The browser doesn't do anything, the person sitting at the computer where the browser is running is what performs the actions. The reauthentication and 2fa is meant to authenticate and authorize the user, not the browser. The attack vector of someone else using your phone using an app that doesn't require (re)authentication is independent of the browser or the app itself being trusted. That your bank doesn't periodically require some kind of re-authentication for their app is a security hole, but because the device could fall into the wrong hands, not because the code/app/browser used to access it isn't trusted.
- wongarsu 1y agoMy bank doesn't let me do anything in the browser without 2FA, and the only 2FA they offer is their smartphone app. My other bank offers 2FA via chip reader as an alternative. I guess that's somewhat viable for an alternative phone OS, if you want to carry the reader around with you That might just be European banks though
- seba_dos1 1y agoThat could be nice on the Librem 5 which has an integrated smartcard reader.
- pjmlp 1y agoWebsites are starting to make use of passkeys and TPM stuff on the device for workflows where money is involved.
- endgame 1y agoMy bank is migrating online banking to an app-only platform. I could see attestation following very shortly afterwards.
- bigstrat2003 1y agoI agree, but unfortunately I think the chances of that are just about zero. The reality is that the vast, vast majority of people don't care about software freedom. They care about the flashy marketing features in the newest iPhone (and competitors). I wish it were otherwise, but alas. Heck, you can't even get people to care about their physical freedom most of the time, let alone their digital life. It's hard to see this effort taking off as a result.