13 ms·
Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their
by bergheim 7mo ago
Been using this for about a year on a p9 pro. It works very well. I hear the google tap to pay does not work, but I've never tried it. However Vipps with their tap to pay works fine. BankID works but not with biometric login, which some things require IIRC. And for some reason DnB private works fine, but you are not allowed in on the corp app.
It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro, crazy that they trust me since it is not Windows - the truly secure OS!
Knew about those things before I started, so all in all I'm pretty happy. I'd recommend NOT using different users for different things (I started with banking etc in one profile, that ended up being a huge PITA and according to their docs it is mostly security theater anyway). Happy tinkering!
- iamgrootali 7mo ago[flagged]
- vages 7mo agoThanks for the Norwegian perspective. I agree that the locking down is truly stupid. For what it’s worth, the reasoning for locking down mobile apps is allegedly that mobile users are a less technologically competent demographic than desktop users. I do not think so myself, given the difficulty in trying Graphene vs. Desktop Linux.
- malfist 7mo agoThose people who root their phone and install alternate OSes sure are less technologically competent than someone with a browser and a laptop
- UqWBcuFx6NV4r 7mo ago“Installing alternate OSs” is juicy bait for “tech enthusiasts” who know just enough to be effectively worse off than someone with a browser, yes, and at its core is this holier than thou attitude.
- microtonal 7mo agoI agree that the locking down is truly stupid. I don't agree that it is stupid. Both banking on a Windows PC or on an unlocked + rooted phone is potentially catastrophic. Windows because of the prevalence of malware, unlocked phones with custom AOSP forks because people download 'ROMs' (as they call them) from the most shady sites. Once 10,000s of Euros are siphoned from a bank account, it's usually the bank that has to deal with the mess. Especially if they cannot prove the transactions were done in on an insecure platform. Phones are generally safer (though there is a huge variance between the safety of different Android phones) because they use verified boot and strong application sandboxing. I think it is possible to believe the following two things a the same time: - Banking apps should only run on locked phones with secure boot. - Banking apps should not be limited to the Apple/Google duopoly. The solution is that there is some validation of alternative OS vendors, e.g. in the form of an audit, and that banks are required to approve apps on their platforms after the audit. This would be fairly straightforward tech-wise, because e.g. GrapheneOS supports remote attestation, but banking apps need to add/allow the hashes of the official boot keys: https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu...
- Aachen 7mo agoNeeding to use a verified boot chain with keys that the bank trusts is essentially the same as using the authenticator device from said bank, except this one costs 100€ or more, has a microphone and camera built in, and you use it for private messages as well. That's not a future I want to live in We have secure hardware already, it's called a smartcard and is what you find in all bank cards, SIM cards, authenticator devices... my phone is my phone, not a second factor, or at least I (as a hacker/tinkerer) don't want it to be that way, just like with my desktop which is also not the bank's to mandate whatever from Somehow they got the memo for devices where it is normal to have admin permissions, but for mobile devices the two big tech companies successfully scaremongered non-techies
- microtonal 7mo agoNeeding to use a verified boot chain with keys that the bank trusts is essentially the same as using the authenticator device from said bank, It's not, because even though the authenticator is secure, you are entering the auth codes in a browser in general purpose desktop OS with (if you use Windows or desktop Linux) little to no sandboxing outside the browser. You are one malware app (or NodeJS package for tech users who claim they'll never download malware) for your session getting hijacked. The sad reality is that phones (and some tablets) are the only relatively secure computing environments that we have. Thanks to Windows with it decades of piled up legacy and Linux with large sandbox and secure boot-hating parts of its community, we cannot have nice things. (The part about the Linux community, which I'm also part of is a generalization, but the hostility against Flatpak, secure boot, etc. is pretty big.)
- birdsongs 7mo agoI was the one that submitted the DNB Bedrift app report to the sec dev repo! I contacted DNB but they never responded to my email. I wonder if we can find a dev? I believe that's how the private app got fixed. Want to use Vipps tæpp so much but I have Nordea for private and they don't allow it on their cards, for whatever godforsaken reason.
- omgmajk 7mo agoDoes the Nordea app work on Graphene? I am curious because I have been itching to switch my main phone to an alternate OS.
- birdsongs 7mo agoYep! Perfectly, I use it daily. (The private customer one, not sure about business.)
- bergheim 7mo agoAh. Where did you send this in? I wouldn't mind sending in a complaint to both BankID (allow biometric login) and of course DnB corpo edition.
- birdsongs 7mo agoOh! Sorry, you described the current state of things so well I assumed you were close to the project. Here is the github repo where banking app compatibilities are tracked: https://github.com/PrivSec-dev/banking-apps-compat-report https://github.com/PrivSec-dev/banking-apps-compat-report And it's rendered to a page here: https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa...
- bergheim 7mo agoHah - both were in my browser history, yes I know them :) I misunderstood and thought you had sent direct emails to relevant parties arguing for why they should be allowed on grapheneos. Thanks anyway!
- baq 7mo ago> I can use my bank on some linux distro, crazy that they trust me enjoy it while it lasts. hardware attestation requirement for (at least) banking apps is a question of 'when', not 'if'.
- deleted 7mo ago[deleted]
- BLKNSLVR 7mo agoI hope this isn't going to be the case universally. If my bank cuts off my access from my browser-on-linux setup, then I'm finding an alternative bank (hopefully some will always exist), which I don't say lightly since I've been with my current bank since I was old enough to have a bank account.
- izacus 7mo agoYou'll quickly find out - as people are finding out in EU nowadays - that *no* bank will go through the trouble of fighting checklist security auditors to keep your linuxes working. Wait till you find out that your prefered Linux bank won't have the same mortgage terms as you'd like and you'll be running to buy a Google/Apple phone to get those % down.
- monksy 7mo agoKeep complaining to the regulators that you're being locked out of your account. Sue them and keep escalating. Forcing you into a system where you have to pay, maintain, etc for access is often not legal.
- izacus 7mo agoThe regulators are the ones that support device attestation and security measures though.
- Aachen 7mo agoMy bank has always had hardware attestation, but it was their hardware that was being attested. Customers get it loaned when signing up I have no problem with a device that they trust being used for transaction approval, but that device shouldn't also be the device I use for my daily life and do all sorts of private things on. We should want to be able to inspect that one
- fodmap 7mo ago> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their app downloaded from Aurora Store in my Vollaphone.
- b112 7mo agoNot in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I've seen this elsewhere, and it's absolutely ridiculous. Why? Because in almost all cases, the apps may only be installed with Google Play, and require the framework to work correctly. And that means? If you are not in good standing with Google, you cannot bank!! I cannot stress how inane it is, to have Google or Apple as the gatekeeping to identify verification. How not having an active, in good standing account with one of these two, means you cannot bank. And it's happening more and more. Meanwhile, banks -- which tend to make billions in profits quarterly, do this to save on infrastructure costs. They do it so they don't have to stand up their own push servers, or have an app which doesn't require firebase. Well cry me a river, boo-hoo Mr Banker, I'm not even remotely interested in you saving on infra-structure costs at the loss of autonomy. And on top of this, many banks are reducing hours, closing branches, claiming that they don't need them. Leaving absolutely no other choice. This sort of thing should be illegal. Being in Spain, but requiring a US megacorp to tell your own bank, that you're you.
- bergheim 7mo agoEspecially with how things are currently, I whole heartedly agree - you cannot operate as a human being in Europe without having a good standing with either Alphabet or Apple. Absolute madness.
- 6LLvveMx2koXfwn 7mo ago
- Neil44 7mo agoSame with Lineage OS, may daughter has an old Samsung with Lineage on it and the Wallet app doesn't work because the phone's been rooted.
- Brybry 7mo agoYou're doomed to this issue with old phones in general. Even un-modified you'll then be stuck with an old version of Android that doesn't support the latest versions of apps and the old versions of apps won't work properly. It's really a shame because a lot of old phones work perfectly fine otherwise.
- gunapologist99 7mo agoGenerally Lineage is the latest. Unfortunately, there are other issues (such as the blobs that Lineage needs drifting out of date, and it's usually suggested that you'll should backup and then wipe to upgrade to the next major release, etc.)
- notpushkin 7mo agoWallet app is still impossible to get working, but there’s been some development recently: https://github.com/microg/GmsCore/issues/361 https://github.com/microg/GmsCore/issues/361 Some other apps are often willing to accept my current setup (Lineage for microG [0], plus Magisk, if you don’t need root – Magisk Hide does some magic I don’t really understand, but even without Play Integrity passing, apps just start working). With more tweaks, you might be able to get Play Integrity to work to some extent, but it’s hit or miss. I’ve just stopped using apps that demand it. [0]: https://lineage.microg.org/ https://lineage.microg.org/
- notpushkin 7mo agoWell, I’ve jinxed it. My current “neobank” of choice, TNG eWallet, is onto me now :( (Not because of my comment, probably – I’ve upgraded LineageOS and had to reinstall everything. But just in case you guys read this – please, just let me bypass it, I’m aware of the risks :)
- BLKNSLVR 7mo agoI'd also recommend to slowly migrate to GrapheneOS, getting to know where the boundaries are for specific apps. Once you've got your 'dailies' all up and running predictably, then you're good to go, but it could take a few days depending on how much spare time you have to find said boundaries. Having said that, I turn on most of the higher level security protections, which quite a few apps need exceptions from. But, yes, you can't tap to pay and it's unlikely you ever will. Banking apps will be hit and miss depending on their (generally hypocritical) paranoia levels. I pay with a tap-to-pay card, and I have never needed to do banking related things immediately, I've always done it via the bank's website. I also still have a not-very-old 'normal' android phone for some edge cases - which are few and far between (actually, I think it's usually to cast youtube to the TV since I only have the revanced youtube app on the GrapheneOS device). P.S. On the use of profiles, I use them to separate work apps and notifications from personal, from sporting club, from X, Y, and Z. Yes, they're a pain in the arse to switch between, but I'd argue it's more of a pain in the arse to have them all jumbled together causing even more notifications, frustrations, and distractions from whatever one should actually be concentrating on in the present moment.
- HybridStatAnim8 7mo agoI recommend dividing per persona rather than per app category.
- BLKNSLVR 7mo agoYes, the way I explained it was misleading, mainly because the different persona's tend to use different sets of apps. The personas, in general, are: - Personal - Work - Sporting Club Committee - Testing (kinda persona, for things I'm not sure of yet and don't want jumbled together with one of the other personas) This is where it may become a pain, but for some people it may be worth it: sub-personas or topic-specific like streaming or finance or torrenting or porn or any other category you can think of if you want to keep certain things behind a boundary in case you need to share your phone (main profile) with friends or family members for whatever reason.
- jlokier 7mo ago> when you can just open the thing in a website anyway. I can use my bank on some linux distro Unfortunately not. I'm in the UK. Two of my personal banks, all four business banks that I need to use, and several credit cards, require authentication using their phone app to confirm login on their website. None of those I've seen are using TOTP or SMS, for which I could use a general security service. All use their own phone or tablet app. One does something interesting where the website shows a unique QR code on each login, the phone app reads it with the phone camera, and then website login proceeds instantly without clicking anything. Oh, and some of them also require phone app confirmation for card purchase transactions. When my last phone's screen stopped working, I called one bank's "phone banking" line (using another phone of course) to make an urgent transaction, and they told me they can't do that, as only service they offer by phone is registering a new phone or tablet. They told me explicitly that it's not possible to login to their web-based banking service without using their app for authentication, and on a registered device. It's the reason I have my current phone. I had to buy a cheap-ish Android in a hurry from a local shop, in order to proceed with my bank transaction. Back to the main topic: I love the idea of a properly open source phone, I used to own not one but two Nokia N900s, and I once toyed with the idea of building my own Linux phone from scratch, big project though that is. But the security ecosystem around logins has changed, and so have the services I depend on. These days I use many bank and other financial-service related apps, and I'm not, in practice, free to switch providers. So I couldn't use a Nokia N900 or modern equivalent any more as my only mobile device. I'd have to carry a second phone as well. (Banking and other service authentications are also the only reason I have my current passport. I resented having to pay to renew my expired passport, given I had no plans to travel (small children) and the expired passport used to be accepted, but I found some banks, credit cards and even government services increasingly requiring to see a non-expired passport from time to time. When I asked one of them what do they do for the large number of people who don't have one, they simply told me they close those people's accounts and that's ok, they don't need to serve everyone. But that's another story.)
- eloisius 7mo ago> require authentication using their phone app And banks often have their apps region locked, so if you live abroad or have accounts in more than one country, you’re fucked.
- pmontra 7mo ago> I can use my bank on some linux distro, Yes, I've been doing that since 2009 on Ubuntu and Debian but there are several caveats. One of those banks has its own TOTP device and they won't replace it when the battery dies. It's almost 20 years old now. Then it's the fingerprint sensor on my phone. The other banks authenticate accesses and many operations with either their app + fingerprint (all of them) or SMS (some of them). So basically I would still need a phone with a blessed OS. I could buy the cheapest one and store it in a drawer, but it's still a dependency on Google or Apple. GrapheneOS requirement of Pixel devices is a dependency on Google too.
- microtonal 7mo agoGrapheneOS requirement of Pixel devices is a dependency on Google too. They are currently working with an OEM to release a non-Pixel GrapheneOS phone in the future.
- dotancohen 7mo agoI hope and pray that is a Samsung S Ultra device. The built-in stylus transforms the whole user experience, I would not go back to a device that I must swipe my dirty fingers across.
- dangus 7mo agoI’m just imagining myself pulling out the stylus on the train/plane, dropping it, and watching it roll away forever.
- dotancohen 7mo agoThey thought of that! The cutaway of the stylus is a rounded rectangle, comfortable in the fingers but does not roll. In any case, replacement stylii are very cheap online. Less than a screen protector.
- dangus 7mo ago
- dotancohen 7mo agoI have a few features that I need that I'm not sure if Graphene supports. If you could check that would help! Can you record phone calls? Do third party voice recorders continue recording even when the screen is locked? Thank you!
- Cider9986 7mo agoYes to both.
- dotancohen 7mo agoThank you!
- tranq_cassowary 7mo agoThe last release (as of writing) even had some call recording goodness: https://grapheneos.org/releases#2026021200 https://grapheneos.org/releases#2026021200 Enjoy
- madeforhnyo 7mo agoA collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.
- zobzu 7mo agoive seen: -"but ios can be jailbroken and it doesnt have an AV!" while the MDM does not allow jailbroken devices, and they also allowed sudo on linux. auditors are clueless parasites as far as im concerned. the whole thing is always a charade where the compliance team, who barely knows any better tries to lie to yhe auditor, and the auditor pick random items they dont understand anyway. waste of time, money and humans.
- virtue3 7mo agoat best it's "cover your ass security" so when you do get pwned you can say you went through an "accrediting auditor" - blah blah blah. Agreed on everything you said. Just wish there was a more efficient way to do things :/
- jamesfinlayson 7mo agoYep, some stakeholder wants a pen-test or an audit so you do it and address the findings to keep them happy. Going through it now at work - bunch of silly findings because the pen testers know they don't get paid to send back an empty report and tell you everything is fine.
- surcap526 7mo ago[dead]
- ACCount37 7mo agoOh how I fucking wish "security" wasn't a stupid cargo cult checkbox list 3/4 of the times. Unfortunately, the rot runs too deep.
- stronglikedan 7mo ago> BankID works but not with biometric login Do you use any authenticator apps such as Okta? My org requires biometrics when using Okta on my phone.
- birdsongs 7mo agoI use microsoft authenticator, in its own work profile for work. I also use fingerprint login for Nordea, the Proton Suite, my personal 2fa program. Biometric works great on the Pixel 9A, at least, and it was fine on the 8 Pro when I had it. The BankID thing is a SW quirk on their end, but generic fingerprint seems works great across the ecosystem.
- RandomPenguin 7mo ago> It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro, crazy that they trust me since it is not Windows - the truly secure OS! I'm worried the day will come when some sites will require, even on a computer, a full-chain verification from the bootloader to the OS, all the way down to the browser. By requiring that each of these elements be digitally signed so that if you're not on a "secure" platform, from the bootloader to the browser, sites such as home banking could restrict access. Imagine not being able to login to your home banking because your linux box is rooted. Btw, the good old days of modding are gone...
- moogly 7mo agoIt sorely needs to break free from the lackluster Pixel hardware. The OEM announcement can't come soon enough (and I hope it's Motorola).
- mtlmtlmtlmtl 7mo agoAbout BankID: There was a regression in the app back in june that broke the app entirely. Back then I emailed the developers complaining about it, and their response indicated that there was no deliberate attempt at breaking BankID on GrapheneOS, and the specific developer who replied to me said he was a fan of the OS. Biometric login was also confirmed to work around the same time. I can however confirm that it doesn't work on the latest app version. It complains that the webview isn't Google Chrome. This is probably just an oversight. I will email them again; good chance they'll push a fix to recognise Vanadium webview.
- natterangell 7mo agoFwiw, biometric login works fine for me. You need to install something like DuckDuckGo or Brave and set as default browser during setup. And only Google Password manager works for storing the passkey.
- natterangell 7mo ago[dead]
- absqueued 7mo agoThis reads like a very norwegian experience!
- jcul 7mo agoAll of my banking related apps work fine. The only apps that haven't worked are Google wallet for NFC payments and, strangely "macrofactor" a calorie tracking app. Google wallet works for things like library cards, tickets etc, just not NFC payment. Macrofactor since seem to have fixed their app, the features that did not work now do. Graphene used to lack android auto support but it has since been added and works perfectly. They maintain a guide for app developers as well as a list of apps that refuse to add comparability here: https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu...
- alwyn 7mo agoFor the tap to pay I am now using my Garmin smartwatch. Still corporate, but not Google/Apple huge corporate. Very content with GOS otherwise. I blame app providers for their ridiculous limitations, not custom ROM developers.