4 ms·
We should be fighting against SafetyNet and similar attestation systems. The proper solution is one we had with desktop computing for decades. If you keep the
by kuschku 3mo ago
We should be fighting against SafetyNet and similar attestation systems.
The proper solution is one we had with desktop computing for decades. If you keep the key material on your eID or bank card, you don't need a locked down operating system. Which then allows devices to live for much longer.
We're slowly losing the war on General Purpose Computing.
https://media.ccc.de/v/28c3-4848-en-the_coming_war_on_general_computation https://media.ccc.de/v/28c3-4848-en-the_coming_war_on_genera...
- ChocolateGod 3mo ago> We should be fighting against SafetyNet and similar attestation systems. The proper solution is one we had with desktop computing for decades. If you keep the key material on your eID or bank card So you want a bank card/ID card to be required each time you use Google Pay? What's the point of Google Pay then.
- kuschku 3mo agoOnce upon a time(tm), Google had a great solution for that: You could get a credit card in nano SIM format, and insert into in your dual-SIM phone. That then allows you to do secure NFC credit card payments even on a rooted phone with custom ROM.
- skinfaxi 3mo agoDo you have more details on the sim credit card?
- inigyou 3mo agoI think some banks still do this with NFC instead?
- ChocolateGod 3mo agoThat doesn't work when someone has multiple or virtual cards. That also means if someone steals my phone they get my credit card too. Not a great solution.
- inigyou 3mo agoActually I have a better idea. What if, instead of holding my phone up to the payment terminal, the bank could give me a plastic card with an antenna and chip, that I could hold up to the payment terminal. The chip could be powered by induction from the terminal. Maybe I could even duct-tape it to my phone if I really want to do that.
- AnthonyMouse 3mo agoThe obvious way to do this is that you need to physically attach the bank card in order to authorize a new vendor. So then when you sign up for Google Pay or Paypal or what have you, you need to get out your card -- which is good. You can't steal a physical card by breaching some other merchant it was used at. From then your Google Pay account is authorized to initiate charges until you tell your bank otherwise and you don't need the card again unless you want to sign up for Venmo etc. And it makes things easy if someone steals your phone, because you just sign into the payment processor and deauthorize the device or, if they've already changed your password etc., sign into (or go to) the bank and deauthorize the payment processor.