8 ms·
So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of t
by Fiveplus 9mo ago
So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy?
The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own hardware. The genius of the modders in that XDA thread is undeniable, but they are fighting a war against the fundamental architecture of modern trust and the architecture is winning.
- zb3 9mo agoThe problem is that we're supposed to use these "secure apps" on our own devices.. but since they need these enhanced security guarantees, our own devices cease to be ours.
- Helmut10001 9mo agoAs I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to this problem.
- ThePowerOfFuet 9mo agoGrapheneOS is not rooted. Most banking apps work fine on it. https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa... https://grapheneos.org/usage#banking-apps https://grapheneos.org/usage#banking-apps
- NoGravitas 9mo agoIt's true that GrapheneOS is not rooted, and, unlike other non-rooted custom ROMs, allows re-locking the bootloader. But, whether a banking app will work depends on what level of Google Play attestation they require. While most banking apps work fine on it, a significant minority do not.
- drnick1 9mo agoTo be fair, this seems to be mostly a European problem. U.S. banks do not seem to enforce Play (dis)Integrity.
- Stagnant 9mo agoNot necessarily an european problem either. Maybe It varies by country but at least none of my 3 finnish banks check for play integrity.
- morjom 9mo agoI know OP checks for integrity/for third party apps. My guess for your ones would be Nordea, Danske and S?
- wolvoleo 9mo agoYeah I wish we could do without a bank in modern life. When bitcoin first began I was really in support of it because I saw potential in freeing us from the dark stranglehold of the banking industry. Everyone just manages their own digital money. But nope the cryptobros just turned it into another pyramid speculation scheme and the governments ruined the customer independence with their KYC stuff. Now it's just an online version of the old system where the exchanges are the new banks.
- TimeBearingDown 9mo agoThere's a crowd-sourced dataset here: https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa...
- jrms 9mo agoSounds expensive using that hardware, but we can achieve the same using cheaper phones, I like the idea, thanks.
- drnick1 9mo agoCheapest new Googled Android phone is < $100, Pixel 9a on sale <$400 and Graphene is free, still (much) cheaper than the latest gen spiPhone.
- zozbot234 9mo agoThis is a sensible move. Plus you can just keep your "authentication" phone at home instead of having it on you when you're out for no good reason.
- derefr 9mo agoNot if you want to use tap-to-pay systems.
- ymyms 9mo agoI wonder if this makes room in the market for some simpler device for payments. Something like a wearable that you can tap-to-pay and has the signed software attenuation but nothing else so you can't be tracked using GPS.
- wrennes 9mo agoThis will be the answer as we move away from screens as phones. Smart watches have slowly edged in, but I foresee some 'no screen' being the answer to payments, access control, etc
- mystifyingpoi 9mo agoSounds like... a card?
- zozbot234 9mo ago> Something like a wearable that you can tap-to-pay and has the signed software attenuation but nothing else so you can't be tracked using GPS. That's a nice idea. You could have a simple card-shaped device with no screen or buttons, and call that a "credit card".
- refulgentis 9mo agohttps://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html “Be kind. Don't be snarky.” “Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.”
- seszett 9mo agoThat's what I do too (not iOS + GrapheneOS but the result is the same) as I was tired of fighting to make my bank apps and itsme (digital identity app in Belgium) work on my rooted phone. Everytime I have to use a stock phone I'm appalled at the ads and I have absolutely no trust in any US or Chinese manufacturer. So I use them only for banking and digital id because that's presumably not what they actually care about. It's not that expensive, I think many people have an old Android phone lying around, it doesn't have to be up to date.
- fph 9mo agoIt is very ironic that the solution is using an old, insecure phone full of unpatched holes for all important banking and id business, because that one is vendor-allowed while your state-of-the-art GrapheneOS is not.
- StrLght 9mo agoIf only banks cared about state-of-the-art security. In reality, banks couldn’t care less. They only care about checking boxes and don’t consider where these boxes come from; every unchecked box is a risk. Did the latest sham "security audit" say that root is bad? They'll block it.
- tetris11 9mo agoMy job's SSO moved to provider that either required an unrooted phone or a reliable Voice auth. For 2 years the voice authentication worked fine (they call me, I type in a number) on my regular rooted phone. Then one random morning I just stopped getting the phone calls. "Network said no". Complete lock out, nothing I could do except go out and panic-buy an unrooted phone not running Lineage and using a modern Android version. (I tried my older unofficial lineage phones without root, and no dice.) I opted for a good phone I could postmarket later, but gosh did it set me back almost 1/5 of my monthly salary.
- WhyNotHugo 9mo agoThis does sounds like the situation where the employer should provide you with the phone.
- jjulius 9mo ago> By 2026, you'll need two phones... Need? Unless and/or until the ability to log in and do your banking, healthcare, etc. via desktop/laptop goes away, then you don't need a phone to do any of that. Yes, 2FA may be required but in the tangential experience of myself, my partner and my two closest friends, we have multiple 2FA options available to us for our banking/healthcare apps that don't require a smartphone. I see this point all the time - "You can't bank or do important life stuff without a phone!!!" and it's just, largely, bullshit. I don't do any "important life stuff" on my phone. Beyond that, even if you had to have a phone to perform those tasks, I'd strongly argue that if you feel you need a second phone, then, and I know this will come off as reductive and unproductive, I think the idea of spending less time on your phone and on the internet, and more time "touching more grass" and interacting with the community and world immediately around you, might apply.
- deleted 9mo ago[deleted]
- notpushkin 9mo agoYou don’t do any important stuff on your phone. Others might not have the luxury. Notably, in Vietnam people use QR payments a lot. If you want to interact with them by, say, paying at a small local restaurant, you’ll need a phone (or a stack of cash, and please do prepare change).
- jjulius 9mo ago>... or a stack of cash... So I don't, actually, need a phone in that instance...
- notpushkin 9mo agoHmm, yeah, I guess you’re right. There are tradeoffs, but if they’re worth the benefits for you – yes, you can live without a smartphone. For this to work for me personally, I would need webapps for ride-hailing and preferably food delivery, and to learn how to navigate the city without a map. I think I might be able to pull it off for some of the places I live in.
- aspbee555 9mo agothe iPhone still does bluetooth transmissions/pings even in airplane mode (the find my device thing) and no way to disable the only way to disable any transmissions is to turn off the device
- NoMoreNicksLeft 9mo agoBluetooth's the same RF chip as wifi in new phones isn't it? Can't just exacto knife a trace on the board without murdering everything I take it?
- MobiusHorizons 9mo agoI could be wrong, but on a lot of mobile SOCs all of the modems are in the same chip as the CPU. I think you would have better luck removing the connection to the antenna
- doublerabbit 9mo agoI've turned off find my device on my device. Although, I am still using 17.7.2 that won't stop nagging me to upgrade to iOS 26.2. I don't want to because I know I'll hate it.
- hexagonwin 9mo agoyou can kill the ota nagging very easily without any side effects, try searching for tvos profile
- MonkeyClub 9mo agoWasn't aware of this, thanks! Also found out that the profiles also expire, so you need to update those in order to skip the update nagging. Apple's lolling all the way.
- GreenVulpine 9mo agoiPhones will transmit bluetooth beacons even if turned off. Fortunately the battery goes completely flat after a couple of weeks or so and then they no longer do. Unfortunately this is not very healthy for the battery.
- BeetleB 9mo agoFunny - in some ways I have the opposite. In my version: The iPhone SE would be the one I use for calls, SMS, etc. It has the SIM card. The Pixel 9a would be used for everything I don't need a data plan/SIM card (browsing etc). My needs are a bit different from yours. I like to separate telephony and communication (i.e. WhatsApp, SMS) from everything else. This way, if I want quiet, I just turn that phone to airplane mode. I really don't want to get random pings while I'm doing "real" stuff on my phone.
- raw_anon_1111 9mo agoOr you could just turn on Do Not Disturb…
- BeetleB 9mo agoMore painful to manage turning it on/off than to simply leave it in my car. Over the years, I've spent far too much time with different solutions for managing notifications, etc. Turns out simply keeping the older phone after buying a newer one was the easiest approach. No downsides so far. The old phone has the SIM card. The new one doesn't.
- raw_anon_1111 9mo agoPulling down on control center and pressing “Do not disturb” is hard to manage?
- BeetleB 9mo agoLooking at the phone, disabling the lock, swiping down, and pressing "Do not disturb" is a lot more than just not looking at the phone. Also, that's only half of it. I have to move it out of "Do not disturb" at some point. Or set a timeline for it. Why should I when I just don't need to? Also, it's been years since I used "Do not disturb". Does it show notification icons in the drawer on top? That's a definite no-no.
- 9mo ago
- itsamario 9mo agoPhones are cheap, serivce isn't. If currency goes fully digital, not having two devices is irresponsible.
- gruez 9mo ago>An unmodified iPhone SE (2022 model) with OS support until 2032 What makes you think it'll be supported for a decade? Looking at the past models, the support period is around 5-7 years. If you count security updates that might get you to 10 years, but at the 7-9 year mark apps will eventually refuse to update because you're not on the latest ios. https://en.wikipedia.org/wiki/IPhone#Models https://en.wikipedia.org/wiki/IPhone#Models
- jama211 9mo agoTo be fair my 2016 iPad Pro is up to date and can still run any app I throw at it
- kennywinker 9mo agoIf you’re not using it regularly, why would you need anything except security updates?
- sorokod 9mo agoYou will also need to accommodate the banking apps updates, banks will not support very old versions of their apps( very old varies but probably about a few months ). Beyond that the new versions may require hardware support that may not be available in a decade old phone.
- fn-mote 9mo agoHistory here is they will require a recent OS version even if it is unnecessary.
- zozbot234 9mo agoBy the time that iPhone SE 3 finally goes unsupported (even the iPhone SE 2 from 2020 has yet to lose support) you'll just buy a cheap refurbished iPhone 16e. Old-gen iPhones are widely available and quite cheap.
- luqtas 9mo ago
- jama211 9mo agoWith all due respect - I totally understand you may need a rooted phone, I’m just curious what you use it for? I’ve never had a modified or rooted phone so I don’t know of any of the reasons you might need one.
- cl0ckt0wer 9mo agoSome people are really into security, some people are really into trains.
- spacebeer 9mo agoYou start to use it because you care about privacy and your data. But now it's just to avoid all the crap Google and OEMs put into the phone. Same story is with PC and Windows. To quote one smart guy: "I'm not in the mood to be treated as a chimp." And that's it.
- jama211 9mo agoThat’s fair! Doesn’t sound like something that’s likely to get the majority of users interested though unfortunately
- saidinesh5 9mo agoSystem wide adblocking, being able to backup any app are the top two reasons I'd still root my phones if i had any choice. You'd be amazed by the battery life improvement you'd get by just blocking ads.. I deliberately avoid all banking apps even though i didn't root my phone, but i have to use Google Pay a lot. So... That's the only reason this phone I'm typing on isn't rooted.
- jama211 9mo agoI do have a VPN which blocks a lot of ads at the dns level but better Adblock would be nice
- ZeWaren 9mo agoI want to backup my entire phone on a local server I own. Apps, app data, settings, WiFi passwords, call logs, etc. Good luck without root.
- jacobthesnakob 9mo agoWhy though? What are you doing on your Pixel that wouldn’t be more secure doing on an iPhone with a double hop or dual-encapsulated VPN?
- Helmut10001 9mo agoMy main reason is that I wanted to separate browsing/daily use from auth/banking. These two things just don't belong together, from my perspective.
- latentsea 9mo agoThis. I've had to run two phones for some time now, and have just accepted this is the new normal.
- Retr0id 9mo agoI do something similar but it's iPhone SE plus olympus camera plus laptop. The laptop is where all the libre software lives, and the camera is (of course) for taking pictures with. I don't use the phone for anything except boring essentials, for the most part.
- wolvoleo 9mo agoYou'll still need to bring your iPhone out with you then and thus it will capture your location and more for the companies to data-mine.
- craftkiller 9mo agoWhy? Do you have many unplanned urgent banking needs? Everything that needs an unmodified phone can wait until I get home.
- wolvoleo 9mo agoYeah kinda. Because even paying something online now requires 2FA from that banking app :( Sometimes when party tickets come online I have to be really quick to buy them for early bird price.
- iso1631 9mo ago> This is expensive, but I found it to be the only viable solution to this problem. Is it really? £150 on backmarket for a phone which will last 10 years doesn't feel expensive. Makes sense to me to run any banking on a secure device anyway.
- wolvoleo 9mo agoHow is a pixel with grapheneos not a secure device? Ps no it's not rooted but it won't pass full play integrity so it will usually be treated as such. Also, a properly configured root is not a weakness just like having a computer where you don't log in as admin unless you really need to can be just fine.
- StrLght 9mo agoA £150 back market phone is not a secure device. It probably stopped receiving security patches a month after its release.
- Helmut10001 9mo agoThe iPhone SE 2022 I am speaking of above came 150 EUR used. It will receive updates till ~2032.
- zorked 9mo agoI used to get a physical security key from my bank. Perhaps I should get a bank device with a touch screen for banking only and they could then stay the hell off of my personal phone.
- kelvinjps10 9mo agoAt that point why not just use the bank's website?
- SoftTalker 9mo agoThat's what I do. I don't install apps for stuff I can just do on the web.
- mschild 9mo agoBecause that needs 2FA to login and guess what the only way to get the code is.
- bethekidyouwant 9mo agoDoes the government ban getting SMS messages on your rooted phone?
- schmuckonwheels 9mo agoDo you guys wear cargo pants to carry all these extra devices or are belt clips coming back into style? If I could get away with carrying a tiny device again instead of lugging around a brick I would, but the world has made it as inconvenient as possible not to. A BlackBerry from 15 years ago weighed just over 100g and did 80% of what your modern-day pocket computer can.
- squibonpig 9mo agoI mean, did it do 80% of the stuff? Devices have changed a lot.
- schmuckonwheels 9mo agoIt did, and some of the things it was more effective at. I remember BlackBerry OS 4.x (?) had a built-in password manager app and this was in the mid-2000s. By comparison this was added to iOS 18 in 2024. What it wasn't good at was things like games and toxic consumer rich media bullshit. The industry saw dollar signs with iOS and Android and never wrote apps for the ecosystem. Remember the days when Instagram was iOS-only? But here we are, resigned to typing on glass for the rest of our lives because some hippie burnout thought it was a good idea.
- tabiv 9mo agoYou may be intetested in this, if you haven't seen it already. https://crackberry.com/clicks-communicator https://crackberry.com/clicks-communicator
- grishka 9mo agoI've never used a Blackberry but it was much more efficient for me to input text (an essential task for a communication device!) on non-iPhone-style phones with physical buttons.
- danparsonson 9mo agoNothing useful to add except, god I miss my Bold 9700. Every time I slip on this stupid touchscreen keyboard and make a stupid typo on this stupid phone I howl inwardly and wish pain and endless torment upon everyone who took us down this path away from light and goodness. Grumble grumble
- morshu9001 9mo agoI already willingly do this with browsers. Firefox gets maximum adblocking and other extensions, Safari gets to touch my bank.
- miloignis 9mo agoI'm also a big GrapheneOS user, but I'm lucky enough that my banking and authentication apps run fine on GrapheneOS, so no need for a second phone. If they stopped, I think I would seriously consider swapping banks and whatever else instead of using a different OS.
- ryandrake 9mo agoThere are enough non-shitty banks and credit unions, at least in the US, that you should be able to easily switch banks to a better one. They have no moat.
- fn-mote 9mo agoThe most is ATM access if you want that.
- jp191919 9mo agoMost credit unions use "shared branching" which mostly solves ATM access.
- craftkiller 9mo agoFWIW my US bank works on GrapheneOS and they refund all ATM fees, so you can use any ATM you want. The only issue I've run into with them is they have a Zelle integration which is only available on the phone, and on GrapheneOS it just loads to a blank white screen. But that seems to be Zelle's fault. The bank is Charles Schwab if anyone is looking for a currently-compatible-with-GrapheneOS bank in the US.
- JCattheATM 9mo agoCharles Schwab also supports the current administration for anyone that wants to bank morally.
- betaby 9mo agoIs camera quality the same on rooted and locked Pixel? For example rooted Sony phones have terrible photo / video quality.
- jp191919 9mo agoYes, you can use the "pixel camera" app on GrapheneOS
- deleted 9mo ago[deleted]
- barbazoo 9mo agoMany of us would need the unmodified one to have a working SIM because a lot of those providers require SMS in their auth flow. Expensive for many of us. For me it'll mean I have to do these things on a computer. Until they come for that one too of course.
- craftkiller 9mo agoDon't they usually SMS you a TOTP code that you could then just type into the unmodified one? I've seen some apps that snoop on your SMS to automatically grab the TOTP code but I've never come across one that wouldn't let you manually type it in.
- Helmut10001 9mo agoI use the eSim feature in my iPhone, this worked well.
- barbazoo 9mo agoDo you mean you have the same esim on both phones but normally activated on the burner phone except when you need it on the unmodified one w/o access to burner phone?
- Helmut10001 9mo agoI can have multiple free esims with my operator. Since I have my auth-phone in airplane most of the time, I don't care about two ringing phones (or the small privacy caveat that comes with sharing the same phone number across multiple devices).
- pessimizer 9mo ago> As I mentioned in another post: By 2026, you'll need two phones. My current setup: Cheers, maybe by 2027 unattested devices won't be allowed on the internet. It's not a solution. The problem didn't exist a few years ago, the idea that it will not continue to its inevitable conclusion within a few years without real solutions is laughable. Wait until Graphene is classified as a hacking tool and Estonia convinces the EU to fine a million Euros a day any company providing services to host its website. Wait until, "in the spirit of reconciliation," the US goes along with it, too. Wait until unattested desktops aren't allowed on the internet.
- StrLght 9mo agoI understand that you’re using it as an example, but I still find it very misleading. Estonia is pro-privacy and has consistently voted against Chat Control. On the other hand, France has been undermining privacy for a few years now. They supported Chat Control, have attacked GrapheneOS, etc.
- firefax 9mo agoIs there a resource for what phones are known good to run GrapheneOS?
- danparsonson 9mo agoIt's Pixels only at the moment; the GOS team are apparently working with another hardware vendor to produce a suitable device, but that's still a long way off.
- Roark66 9mo agoI have a similar setup, but no need for your "bank/govt app phone" to be an expensive device. A cheapest $120 smartphone money can buy is good enough. Then you choose the flagship device you're going to use 99% of the time on the basis of how easily you can unlock the bootloader/root.
- Helmut10001 9mo agoYes, I got my iPhone SE 2022 used for 150 EUR!
- Flere-Imsaho 9mo agoI take a different approach: I run a proxmox server on my home Lan with all the services and storage I want, including a wireguard server. My Android phone can then connect to my home LAN services from anywhere in the world (my ISP provides static public IP addresses). My Android device is then a simple terminal to all my "stuff". It can be locked down as much as they want it to be, as long as it can run WireGuard. I have no use for a rooted phone. In fact I want it to be as hardened as possible in case of theft.
- Pfhortune 9mo agoPretty much the same setup here. Pixel 9 Pro GOS + iPhone 15 (USB-C everything!). The iPhone is a Canadian model that retains the SIM slot. Most of my banking apps work fine on GrapheneOS, but I've adopted this because I'm confident they'll eventually break. And access to Apple Pay is nice. Carrying two phones is annoying, but, agency over my main computing device is worth the price.
- karel-3d 9mo agomeanwhile, I have a problem remembering to charge one phone.
- Helmut10001 9mo agoWow, my comment has really taken off! In both directions! Let me clarify some things. - I bought the iPhone SE 2022 second-hand for 150 EUR. I think this is a fair price, but it's still expensive given that I leave it lying around 99% of the time, which I still feel is a waste of resources, regardless of my motivation. - My main reason for having two phones is pretty simple. I think browsing and daily internet use just don't go together anymore with authentication, banking and health. I also didn't want to carry a critical key to my digital infrastructure around with me every day, especially in bars (etc.). Having a separate phone helps me to treat different aspects of my life differently. No worries, I don't have to carry two phones with me all the time. - Yes, I do other things to generally reduce my digital footprint: I use different browsers for different things, such as admin work and social media (in those rare cases where I still use it). I also self-host behind VPN and have moved many apps to my internal stack, which gives me better control over what communicates with what. For example, I use WhatsApp Bridge so I don't have to use the app directly on phones anymore. I self-host Invidious with privacy-redirect for Fennec for YouTube, etc. Over time, all of this has slowly helped me regain my freedom, and it actually feels liberating. - My path may not be your path.
- deleted 9mo ago[deleted]
- add-sub-mul-div 9mo ago> you are locked out of the economy? Not that it excuses the withdrawal of user agency. But I've never used a banking app on my phone before. Anything important I still like to do on a desktop. Though how much longer that's safe, who knows. Apple's model of requiring their permission to run code on your own device will probably spread to everything given enough time.
- mschuster91 9mo ago> But I've never used a banking app on my phone before. Here in Europe, good luck using any form of online payment without one due to 2FA requirements.
- duser1 9mo agoI don't have a problem with online payments, and I'm not using a banking app.
- cestith 9mo agoMuch of the world uses mobile payment apps instead of credit or debit cards. Some banks allow a setting that using a card can require a ping to the banking app for verification of the transaction. I don’t know if it’s legal to turn down cash payments in Vietnam, but some vendors may only accept digital payments. I guess you could take your laptop out at the restaurant and in the taxi to pay. It seems a little strange. You might better just use a browser on the smartphone instead of the mobile app.
- add-sub-mul-div 9mo agoI guess I take credit and debit cards for granted. Surely the rest of the world had some solution before smartphones, though. Hopefully the US doesn't descend into needlessly using the phone as a middleman as the norm.
- jolmg 9mo ago> But I've never used a banking app on my phone before. Anything important I still like to do on a desktop. A lot of banks require using their banking app to get a 2FA token to log-in on a desktop web browser.
- pwg 9mo agoCory Doctorow predicted this outcome back in 2011: The Coming War on General Purpose Computation https://boingboing.net/2011/12/27/the-coming-war-on-general-purp.html https://boingboing.net/2011/12/27/the-coming-war-on-general-...
- anthk 9mo agoAnd Richard Stallman since 1983 and before.
- lawlessone 9mo agoTbf it's been going on since before 2011
- kube-system 9mo ago> We are moving to a model where the user is considered the adversary on their own hardware. That has been the model since day one, since you are using spectrum that, because the end users are not licensed, requires it. Radios in 100% of commercially available phones are locked to prevent user tampering. You don't get root on your debit card either, despite it running a computer.
- te7447 9mo ago> That has been the model since day one, since you are using spectrum that, because the end users are not licensed, requires it. Radios in 100% of commercially available phones are locked to prevent user tampering. Why, then, can users be root on PCs that have wifi cards, SDRs or cellular radios?
- kube-system 9mo agoWifi? Because it is part 15. That spectrum is less strict. SDRs? Because they are not certified transmitters. They are test RF gear, or a component of a transmitter, not an end-user product. Cellular radios in a PC? You don't get root on those. Same situation as they are in a cell phone: They are licensed-band transmitters, and they are required to be tamper proof to protect the licensee.
- te7447 9mo ago> Cellular radios in a PC? You don't get root on those. Same situation as they are in a cell phone: They are licensed-band transmitters, and they are required to be tamper proof to protect the licensee. The original post said: > Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own hardware. The genius of the modders in that XDA thread is undeniable, but they are fighting a war against the fundamental architecture of modern trust and the architecture is winning. So, as I read it, Fiveplus is saying that we are moving to an architecture where the user is an adversary on the computer (the phone) as a whole. While licenses may require that specific components are out of bounds, the new thing is that the whole platform is denying the user the ability to do what they want with the parts that are not explicitly off-limits. IIRC, a Blu-Ray drive is required to store data about revoked keys and to stop playing discs if its own key is revoked. Presumably the BR license also states that the user can't be allowed to wipe this revocation list and start playing Blu-Rays again. But BR drives can still be fitted in computers where the user has root access, just like PC cellular radios. Phones are made to be default-deny instead of default-allow, and I think that makes it different from "enclosed modules you don't have control of".
- finaard 9mo agoI guess you can still do banking on your PC? I stopped using banking apps on my phones a few years ago - they got more and more annoying, and I don't buy into the "the device is secure and should be used as a trust token". So I'm now back to banking only on my computer, with a hardware token for TAN generation.
- phantom784 9mo agoThat probably means giving up the ability to mobile deposit checks - every bank I've ever had only allows that through their app.
- ErroneousBosh 9mo agoWhat's a mobile deposit and why do you need an app to check it?
- phantom784 9mo agoIt's the ability to take a picture of a check and deposit it into your account that way, vs having to take the check to an actual branch of a bank. Here in the US, I still get checks frequently enough that it's nice to have.
- gabrielhidasy 9mo agoI'll bet the confusion stems from the rest of the world having essentially forgotten what is a check/cheque almost a generation ago. I only used them twice in my life, last one was in 2012 and I had to get a supervisor at the bank to find the procedure to get a checkbook at the time.
- SoftTalker 9mo agoIn the US, a lot of small employers still issue paper payroll checks.
- dathinab 9mo ago> does stop malware. unrelated to phones a lot of (more professional) malware has moved to not persist itself in root space (or at all) as to not leaf traces (instead it will just rely on being able to regain root access as needed every time you reboot with all the juicy parts being in memory only (as in how often do you even roboot your phone)) I think (but am not fully sure) this also applies to phone malware. I.e. no it doesn't work. Not unless you - ban usage of all old phone (which don't get security updates) - ban usage of all cheap phones/phones with non reliable vendors - have CHERY like protections in all phones and in general somehow magically have no reliable root privilege escalations anymore Oh and advanced toolkits sometimes skip the root level persistence and directly go into firmware parts of all kinds. Furthermore proper 2FA is what is supposed to make online banking secure, not make pretend 2FA where both factors are on the same device (your phone). And even without proper 2FA, it is fully sufficient to e.g. classify rooted phones as higher risk and limit how much money can be transmitted/handled with it (the limit should ignoring ongoing long term automated repeated transactions, like rent). There really is no reason to ban it.
- mike_hearn 9mo agoYes that's what they are doing. Phones known to have live root exploits are detected and banned.
- StrLght 9mo agoWho exactly are "they" in this context? Shared documents don't mention anything like that.
- SkiFire13 9mo ago> Locking down the bootloader and enforcing TEE signatures does stop malware. I have no idea about the kind of malware you're talking about.
- cmxch 9mo agoOnly if the vendor isn’t plying malware themselves. The only solution is to force some semblance of user agency on those models, such that the vendor isn’t imposing from above.
- m4rtink 9mo agoAre you sure it actually works ? Outdated but signed ROM with tons of unfixed CVEs will be still considered totally fine. Latets Lineage OS or Graphene OS will be rejected.
- piyuv 9mo ago“Irrefutable part” is easily refutable. Malware ran by governments and agencies is still malware.
- davidf18 9mo ago[dead]
- unethical_ban 9mo agoDoes it? Are you telling me banking apps have no choice but to go to this extreme when none of my seven US financial institutions even implement TOTP? This is lazy control.
- raw_anon_1111 9mo agoThese banks don’t have websites?
- e2le 9mo ago>does stop malware Doesn't stop state approved malware in all its forms.
- Terretta 9mo agoI really like this comment. I similarly don't like that banking is, from no collusion just internal incentives, locking out any users not opted into the Chromium hegemony. > The irrefutable part here is that the security model works. Yes! And that business model should be allowed. This leads me to worry the notion of "user agency" may be misplaced, meaning, aimed at the wrong level of the stack. It would seem both open (general compute ethos) and secure devices (appliance ethos) have a right to be in the market. So… ### Perhaps user agency should be at the experience level. ### We couldn't plug Sega Genesis cartridges into Nintendo 64. We understand this about consoles. If we remap mobile devices into consoles, it seems less obvious their internals should be opened and tinkered with by end users. User agency seems more at the level of picking a console family, and it's often for the whole brand aura including both the console itself and safeness-to-permissiveness dial by which the brand curates its the cartridges (spectrum from Nintendo to Apple to Sony to Microsoft and Steam). A free market for mobile devices or desktops would likely sort out a similar spectrum of just-works to fidget-able. If you choose the Nintendo 64, you wouldn't expect to run arbitrary software on it as you would expect on Dell. We hackers are capable of figuring out how to make Nintendo 64 software; our neighbor does not need or want those affordances, they want just works, no headaches. This idea that the user must be able to open their digital watch or toaster oven and change how it is wired glosses what users actually choose: the conveniently toasted meal. At the same time, business models around the curation and appliancification of digital tools, blurring the lines from hardware through solid state through firmware to software into a single product users can choose, must be defended. If I want to dev for a secure product, I similarly must be OK opting into the supply chain security model (with Apple, registering as a dev in order to exchange cert material and bypass consumer paths to loading software I'm making for the platform) that allows that product to be secure, and opted into by users with money to buy my app, that caused me to want to develop for it in the first place. Users must have a right to buy an appliance that isn't fiddle-able. Not mandated to, as this article sounds, but allowed to as the EU is trying to deny. Such products have a right to exist, and such business models have a right to exist. And then, user agency remains as simple as use dollars to buy a product offered through a biz model that matches the user's goals, rather than regulate to disable business offerings offerings/products that don't, and developer agency is to pour energy into the platform that aligns with one's ethos. If more money is to be made on a platform with a different ethos, perhaps it's worth reflection rather than rants.
- zeta0134 9mo agoPersonally I just don't use a banking app. The website works fine? I don't like the idea of having to use something from the Apple App Store or the Google Play Store, both companies of which could randomly decide I don't need to exist and cut off my access. ... no thanks? So I don't run "apps" at all. If your business is only available that way, sorry! But "I don't have a smartphone" tends to signal to the receptionist that they'll need to explain the myriad of other ways to do business.
- dstroot 9mo agoConsumer level security always has to contend with the lowest common denominator. As my 80 year-old mother‘s technical support team I can testify that she will download and install anything she sees on Facebook. The consumer security world has to protect us from people like her. It’s also the reason I will only allow her iOS devices.
- grishka 9mo agoMaybe people like her should just, uh, not use technology? Or not do it as much? The fact that the society so heavily pushes everyone — regardless of their technical literacy and willingness to learn — to use internet-connected devices is also a huge part of the problem.
- emsign 9mo agoYeah. Tech companies are coming for our hardware. Next step is OSes with agentic AI turning it from a system with frameworks and libraries with apps seperate from the base system, into a system that only runs AI models that the "owner" of the hardwre has no control over and the lines between the OS and the AI is very blurred. This totally beats the purpose of owning or using tech. Might as well go off grid and live a non-tech life. Big tech wants to colonize our hardware completely because data centers alone ain't cutting it. 1$ Trillion has to be paid back to the investors plus interests. They screwed up with AI and we have to pay for it. Or maybe they didn't screw up because big money always gets bailed out by the plebs.
- aranelsurion 9mo ago> moving to a model where the user is considered the adversary on their own hardware I think we’ve been there at least since the first iPhone, and it’s now entirely normalized for the average user.