4 ms·
I wonder why almost no one in these GrapheneOS praise topic mentions that you won't be able to pay with your phone, and often even bank apps refuse to install o
by deeplowdock 6mo ago
I wonder why almost no one in these GrapheneOS praise topic mentions that you won't be able to pay with your phone, and often even bank apps refuse to install on it - it was a deal breaker for me personally, and now I'm back under Google umbrella :<
- znsdx 6mo ago[dead]
- cyanydeez 6mo agoPaying with your phone just seems like one of those separation of concerns problem. I'm sure you have backup forms, and cash, etc, but there's something about not having to worry about the multinefarious capabilities of my phone if it's not in my posession.
- deeplowdock 6mo agoYou could then separate the audio system from your car and drive around with a boombox
- NewJazz 6mo agoDifference is a plastic card that is lighter and smaller than the phone is just as effective as the phone is for payments. When it comes to audio, a car stereo is going to be much more convenient and brtter quality than a boombox or bluetooth. That said, i did know someone with an older car who used a bluetooth speaker instead of their stereo, so they could connect their phone audio.
- 0x3f 6mo agoI don't know about where you live but here contactless card payments have lower limits than phone-based ones. Also the phone allows me to switch between multiple cards, including transit-specific cards.
- unethical_ban 6mo agoIn the US IME there are not restrictions on card spending that are a barrier. In UK I had to sign for a purchase over £100. Extra 10 seconds. In UK, my credit card was my transit card. I find it easier to navigate my physical wallet than a phone for such things. Personal opinion. In any case, banking apps that don't function on graphene should be embarrassed by their stupidity. Amex forces sms/email 2fa to login on my graphene phone, when chase, fidelity and several other bank apps do not.
- zephen 6mo agoI forget. What are the security implications of having your car play your music again?
- thejazzman 6mo agoPretty sure Jeep was hacked via their infotainment system and remotely driven (by researcher Charlie Miller) So it’s actually kind of a real thing
- zephen 6mo agoI'm pretty sure that the infotainment hack was completely orthogonal to whether it was Beethoven, Iron Maiden, or blissful silence. Having said that, a successful car infotainment system attack on android auto or apple carplay could, of course, compromise your phone. So it's up to you whether you decide to cope with that possibility by breaking the law and navigating with a handheld device, or simply declining to do banking on your phone, since successful car exploits mean the attack surface against your phone is much larger than you might presume.
- thejazzman 6mo ago> separate the audio system from your car I was responding to a comment about the security implications of letting the infotainment system interact with the vehicle controls, and I referenced an incident where someone compromised a car via that. I have no idea how CarPlay would compromise your phone given apples sandbox but whomever finds it is gonna have a multimillion dollar payday since iOS jailbreaks are quite valuable.
- zephen 6mo agoThe initial convo went: > Paying with your phone just seems like one of those separation of concerns problem. Followed by: > You could then separate the audio system from your car and drive around with a boombox The first discusses behaviors of end-users. The second was a lame attempt to take the mickey of that, which is why my response clearly indicated that, to my knowledge there are zero security implications of playing your music through your car's entertainment system. This remains true. You are discussing design flaws, not user behavior flaws, which is why I pointed out that the design flaws you bring up, in addition to doing you bodily harm, could conceivably also be part of an exploit chain that validates the original poster's concern about using his phone for banking. But I still sincerely doubt that the choice of playing Beethoven or Iron Maiden either directly places you at risk*, or makes a difference to the ease of exploiting any design flaws in your vehicle. IOW, the first behavior given (not using your phone for banking) is easy to construe as prophylactic, given that, yes, in fact, peoples' credentials have been stolen from their phones and bad things have happened, due to using phones for financial transactions. The second behavior given (use a boombox instead of your car's audio) of course could theoretically alter outcomes, but to my knowledge, there has never been a car exploit that depends on whether you have fiddled with the volume control or station selector. * Assuming of course, that your volume isn't so loud that you've riled up other people. That's always a risk.
- mikestorrent 6mo agoWell, that's what we all did like 10-15 years ago with nice double-DIN decks that had nothing to do with the car besides taking power from it and perhaps some steering wheel controls. It was just a hard-wired boombox, 100%. Now, the stereo is in fact properly a part of the Infotainment System you cannot replace, so as it ages out in a perfectly good vehicle, the entire car deprecates faster than it would have in decades past. Even my 2015 Mazda has enough vehicular settings in the infotainment menu that despite being replaceable with a double-din I haven't bothered because I'd lose all configurability there. I opted for a cheapo $100 carplay unit instead - the modern equivalent of the discman-to-tape adapters ;)
- ramon156 6mo agoFair point, but how much extra effort is it to put a credit card between your phone? I'm still under the Google umbrella as well, but this would be my first issue solved.
- KetoManx64 6mo agoHonestly, it's a half hour of work to pull the chip out of a credit/debit card and put it into your phone case. (Just need to be careful and not cut the antennas)
- Pacers31Colts18 6mo agoNot every banking app is that way. Mine worked. I also dont think everything needs to be an app.
- throawayonthe 6mo agothis is the main point of discussion under every grapheneos thread though... also my bank apps install, but yes, no tap to pay
- BLKNSLVR 6mo agoI gets mentioned on every GrapheneOS thread I've read.
- hnuser435 6mo agoLimitations are on the website - https://grapheneos.org/articles/ https://grapheneos.org/articles/ I don't care about google pay/wallet or android auto. My credit union's app does work fine, but even if it didn't, I'd still use GOS. It's great.
- McDev 6mo agoFWIW I've tested Android Auto before with sandboxed Google Play, works fine.
- prg318 6mo agoYup! You can even get Android Auto to work without Google Play: - https://github.com/sn-00-x/aa4mg https://github.com/sn-00-x/aa4mg
- g947o 6mo agoOnce upon a time I would be happy to put custom ROMs on my phone and do all these patches. These days I just care so much about "things should just work" that I cannot justify doing this. I cannot think about how I could spend time figuring out what to do when the repo is no longer maintained or something breaks for random reasons.
- Itoldmyselfso 6mo agoAgreed. Sandboxed Google play really is the non-tinkerer's approach on GOS, including for Android Auto.
- KetoManx64 6mo agoThe value I get from either being degoogled or using GOS like I have for the last year and a half is worth the 3-5 hours time investment once a year or two when I get a new phone.
- KetoManx64 6mo agoThis is a fantastic find, thank you very much! I ended up switching from Lineage + MicroG to GOS for the android Auto support because I couldn't find something like this. I will be setting this up on my secondary Lineage device.
- edm0nd 6mo agoYup, Chase Bank app will not load at all. I think its a "security" feature that it wont load on rooted phones lol
- johnsea 6mo agoGrapheneOS phones are not rooted.
- mikestorrent 6mo agoThere's some reasonable fear that at some point large portions of the web will require secure attestation that a device is not rooted; this may come in the form of automating age verification for convenience. When all it takes is a checkbox on Cloudflare to require 18+, a lot of site operators will just use it.
- ethagnawl 6mo agoFor many GrapheneOS users, this class of annoyances is an acceptable concession.
- theandrewbailey 6mo agoI guess I'm so paranoid that not only do I run GrapheneOS, I've never had nor wanted banking nor payment apps on my phone. Having ALL my money be accessible from something so easily lost, stolen, or seized would be a constant source of stress for me. There's (hopefully) a lot of security around accessing it, but sometimes the only winning move is not to play.
- kajman 6mo agoYou've got a lot of people contesting the "often" part but I'll also add that there's a project tracking banking apps that do work: https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa... My tiny local credit union app isn't on there, but it worked fine. I miss wallet a bit and it's a shame that there are important apps which still refuse to act reasonably, but I don't think it's really that bad.
- KetoManx64 6mo agoSeconded. My credit union's app works just fine as well
- DANmode 6mo agoGet a case that holds your credit card, good grief lol
- mindslight 6mo agoBanks will readily send you a completely separate computer just to perform payment transactions with. It's very thin, and you can even get a phone case that holds it as well. There's really little reason to bundle all that functionality up into one device, especially if a consequence is that doing so requires you to run surveillance industry malware.