8 ms·
Tell HN: PayPal blocks GrapheneOS
It seems like the PayPal app now refuses to run on GrapheneOS. I don't know if it's only because I have enabled the PayPal card for contacless NFC payments, but when opening the app it crashes with the following exception: com.paypal.oslo.app.rasp.RootDetectionSecurityException: Security policy violation: s=root
- freakynit 1mo ago[flagged]
- leumon 1mo agoWell I haven't rooted my device. It's just normal grapheneos
- freakynit 1mo ago[dead]
- therealmarv 1mo ago[flagged]
- grapheneos 1mo agoGrapheneOS isn't rooted. PayPal works on GrapheneOS and doesn't try to ban using it. However, they recently shipped incorrect anti-tampering code incompatible with our secure app spawning feature (exec-based app process spawning). It can be worked around by disabling the per-app secure spawning toggle for PayPal. For simplicity, there's a per-app exploit protection compatibility mode toggle which sets all the finer grained exploit protection toggles to the compatibility mode.
- deleted 1mo ago[deleted]
- windowliker 1mo agoIsn't it more likely to be saying that the app is running with root privileges?
- tensegrist 1mo agoiirc grapheneos can't be rooted unless you do your own build
- futune 1mo agoThat's the bizarre thing about this hn discussion... A lot of people referencing rooted phones, but to the best of my knowledge GrapheneOS is almost never rooted?
- grapheneos 1mo agoThere's only root if people make a userdebug build with user-accessible root or make a derivative of GrapheneOS with major modifications. The production builds don't have uncontained root since it would greatly roll back the security model. Only a few core processes run as a limited subset of root.
- Sophira 1mo agoIt can be rooted just fine without doing your own build. It's just that if you do, the GrapheneOS community will claim that it is no longer GrapheneOS and that it's separate.
- grapheneos 1mo agoReplacing a large portion of the core operating system code and SELinux policies with a third party project is making a derivative of the OS. It can no longer receive standard updates anymore and won't pass verified boot without resigning it. A derivative of GrapheneOS with significantly different code, SELinux policies and distinct signing keys is not GrapheneOS. Verified boot will no longer work as intended anymore even after resigning and the same applies to a large portion of the security model in the OS. Giving root to a huge portion of the OS greatly reduces security even if it's never granted to any apps.
- grapheneos 1mo agoThere's only root if people make a userdebug build with user-accessible root or make a derivative of GrapheneOS with major modifications. The production builds don't have uncontained root since it would greatly roll back the security model. Only a few core processes run as a limited subset of root.
- grapheneos 1mo agoGrapheneOS isn't rooted. PayPal works on GrapheneOS and doesn't try to ban using it. However, they recently shipped incorrect anti-tampering code incompatible with our secure app spawning feature (exec-based app process spawning). It can be worked around by disabling the per-app secure spawning toggle for PayPal. For simplicity, there's a per-app exploit protection compatibility mode toggle which sets all the finer grained exploit protection toggles to the compatibility mode. GrapheneOS is an operating system rather than read-only memory firmware. There's a ROM in early boot (boot ROM) which loads the SoC boot firmware from the SSD which loads other SoC firmware from the SSD and then loads the OS from the SSD.
- gib444 1mo agoWith or without Google Play Services running?
- leumon 1mo agoWith. But disabling "Secure app spawning" seems to fix it for now.
- gib444 1mo agoEw that's a nasty workaround. But interesting to know!
- grapheneos 1mo agoSecure app spawning is a per-app toggle now so it doesn't reduce OS security or the security of other apps without it disabled. It only reduces security of the app with it set to disabled. If multiple apps have it disabled, they share the same ASLR bases, memory tags for memory allocated before fork and other things. It's one of the toggles changed by the per-app exploit protection compatibility mode. If an app doesn't work, that's the first thing to try. It can then be narrowed down to a specific setting. The more aggressive exploit protections uncovering a lot of compatibility issues are only enabled for the base OS and specific user installed apps by default. Those can be set to enabled by default for all user installed apps and then people have to deal with the per-app toggles a lot more. This applies to memory tagging, disallowing dynamic code loading via memory/storage and disallowing native debugging (ptrace).
- gib444 1mo agoThanks Daniel. Nice to see you back again tirelessly educating the community about GrapheneOS, almost no comment not replied to!
- grapheneos 1mo agoIt's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
- leumon 1mo agoUpdate: it seems to work when disabling "secure app spawning" (for now)
- zvmaz 1mo agoSo it's not PayPal blocking GrapheneOS?
- zem 1mo agosounds more like grapheneos blocking paypal!
- grapheneos 1mo agoNo, they added incorrect anti-tampering code. It's wrongly detecting secure app spawning giving each app their own address space, memory tags, etc. via exec as tampering.
- ttouch 1mo agothank you!
- paperscissors 1mo agoGreat to know, thanks!
- aabdelhafez 1mo agoSwitched to Wero and haven't looked back. https://wero-wallet.eu https://wero-wallet.eu
- oniony 1mo agoThe website is pages and pages of blankness for me on Firefox mobile.
- unpopularopp 1mo agoUnfortunately peasants like us who don't live in the 5 countries where it's available still can't look back
- Carbon1603 1mo agoI live where it's available and still can't use it to pay stuff, only to transfer money to friends.
- therealmarv 1mo agowait for it... I can see a future were every wallet, payment etc. app will block devices which are on custom ROMs and do not pass strong hardware integrity with blessing from Google. I've read once that there are paid app testing labs which test if an app has root and custom ROM detection and when they don't have that it's a minus point on the report.
- muvlon 1mo agoYou need to use your bank's app for Wero, and many EU banks' apps refuse to run on GrapheneOS for the same reasons as PayPal. This is sadly not a clear win for Wero.
- savwolf 1mo agoDoes this work in the UK?
- doublerabbit 1mo agoNo. We left the EU, so we don't get such fun.
- zerof1l 1mo agoI see this happen from time to time. Lately, almost all of the apps work fine on GrapheneOS. The best strategy is to keep writing the business once every two or so weeks that you can’t log in to and use the app. Don’t go too technical at first, because most of the time, the moment they hear things like “rooted” or “unofficial,” they just say your phone is the issue. To date, I was able to convince, or at least contribute to, making three apps work on GOS.
- basilikum 1mo agoGreat job, man. We have to make ourselves get heard. It's a social problem after all. Technical workarounds are great and sometimes the only practical short term option, but we have to fix the social issue at the root.
- dvoros 1mo agoI had the same experience. Asked in an email why an important government app won't work on GrapheneOS, first without any technical details. Got the response that it's "because security". I sent some technical details and argued that they're denying service to their most security-conscious users. 3 months later the app started to work!
- dinfinity 1mo agoTo be fair, governments might be much more receptive to the argument of not having to rely on (possibly foreign) megacorporations than a company like Paypal. I'd wager that if it doesn't really hurt their bottom line to not support GrapheneOS, they won't really care.
- microtonal 1mo agoI think in this case it's also them just introducing a new check that either GrapheneOS will need to work around or Paypal needs to refine. I can reproduce the issue, but it doesn't seem like it did a failed Play Integrity check at that point.
- Groxx 1mo agoHonestly there's a decent chance they don't even know, in most cases, because corporate environments generally try hard to have as few as possible hardware/software setups to maintain. And they're unlikely to proactively test on Graphene unless it's closely related to what they do (and it definitely is not for most apps). Mistakes happen and ya can't fix what you don't know about. Always report issues. Also strongly consider just using the website.
- deleted 1mo ago[deleted]
- hd4 1mo agodid you re-lock the bootloader?
- grapheneos 1mo agoIt's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
- axegon_ 1mo agoThis is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!
- fluidcruft 1mo agoGenerally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors). Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good guy or a bad guy so it's easier to just ban guns.
- encom 1mo agoHow does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.
- biosboiii 1mo agoIf you run a rooted phone and download malware, that malware can gain root and do payments on your behalf. Then PayPal has to deal with you revoking payments etc., they don't want to so they forbid you from using PayPal on a rooted phone.
- master-lincoln 1mo agoIf this happens it's the device owners fault and they should be responsible for it.
- Grombobulous 1mo agoWhich they would be anyway since PayPal isn’t a bank and isn’t FDIC insured. They allow you to open PayPal.com on any web browser. Running Windows/macOS/Linux is basically identical to a rooted Android phone (you have local admin rights, you can modify and automate the browser, and can run unsigned code).
- gnoll_of_gozag 1mo agoCan it still run in browser like it would on a regular pc?
- qingcharles 1mo agoYes, but you might have to enable desktop mode on a mobile browser so it doesn't try force-spawning the app.
- grapheneos 1mo agoThe app still works too. PayPal just accidentally broke compatibility with secure spawning which can be toggled off per-app. We didn't used to have a per-app toggle since it wasn't expected to cause compatibility issues and it was non-trivial to add support for it, but we have it now.
- Itoldmyselfso 1mo agoYou can change the link handling in the app settings so it doesn't try to open it via the app. Or open the site in incognito window.
- Aachen 1mo agoI wish it ran in Firefox on my pc...
- grapheneos 1mo agoYes, but the app still works on GrapheneOS. They accidentally broke compatibility with the default settings with incorrect anti-tampering code. Disabling the per-app toggle for secure spawning works around it. We have per-app toggles for exploit protections known to have compatibility issues. Secure spawning wasn't expected to cause any compatibility issues so we didn't have a per-app toggle for it until recently but it's available now.
- sdcfgy 1mo agoI'm starting to see these restrictions as a deterrent for using the products in question. My GOS handset is slowly fizzling away into a dumbphone with Firefox, organic maps and k9. And you know what, I am starting like it.
- grapheneos 1mo agoThe vast majority of Android apps work on GrapheneOS. App compatibility is not diminishing in any significant way. We've improved app compatibility faster than Play Integrity API adoption has happen, which this isn't. PayPal's app still works with our per-app secure spawning toggle disabled. It's a bug in their anti-tampering code.
- sdcfgy 1mo agoThanks for the reply. Your efforts are more than appreciated!
- fenestella 1mo ago[dead]
- bit1993 1mo agoI was always suspicious of GrapheneOS, thought it was too good to be true. But this makes me reconsider and want to install GrapheneOS.
- kissiel 1mo agoI think if paypal not working on GOS makes you not use it, then GOS is definitely not for you...
- nicman23 1mo agoit is great and you know that because cops are pissy about it
- grapheneos 1mo agoThankfully, PayPal hasn't banned GrapheneOS and their app still works on it. They accidentally broke compatibility with our secure app spawning feature which has a per-app toggle to disable it along with the other exploit protections which can cause compatibility issues. There's an overall per-app compatibility mode toggle instead of users needing to figure out which protection is an issue but it's best to figure out the minimal workaround after determining that works.
- nunobrito 1mo ago[flagged]
- imska 1mo agoIt does work for me on lineages for microg with an Xperia 5 II. Haven't tried to activate contactless though.
- nunobrito 1mo ago[flagged]
- grapheneos 1mo agoPayPal works fine on GrapheneOS too. They recently shipped an update with incorrect anti-tampering code incompatible with our secure spawning feature. It can be worked around by toggling off secure spawning as the creator of this thread figured out on their own. For ease of use, we have a simple per-app exploit protection compatibility mode setting all these features to a compatibility mode instead of people needing to figure it out.
- grapheneos 1mo agoPayPal works well on GrapheneOS. PayPal shipped incorrect anti-tampering code wrongly detecting our secure spawning feature as tampering. It works fine when the per-app toggle for secure spawning is disabled. These incompatibilities with hardening features are relatively common in banking apps. We provide an overall exploit protection compatibility mode toggle for ease of use rather than people needing to figure out which feature is incompatible. GrapheneOS has never received or applied for any government grants. It doesn't have any involvement with any governments. GrapheneOS is banned by the Play Integrity API device and strong integrity levels. In practice, the only app compatibility issues which can't be worked around with our compatibility issues are apps adopting the Play Integrity API to enforce those.
- tombardier 1mo agoStill works on my up to date pixel 9 xl. I haven't enabled NFC payments though
- grapheneos 1mo agoTheir recent updates require disabling secure spawning via the per-app toggle, that's all. NFC payments still work.
- Kwpolska 1mo agoWhy would anyone still use PayPal after so many cases of accounts being banned and funds being frozen for no reason, and all the other terrible stuff they've done?
- deleted 1mo ago[deleted]
- rciorba 1mo agoCritical mass? I had to start using it after moving to Germany, because everyone else expects you to use it. One of the ladies at daycare is leaving? Here's a paypal link to chip in for a good-bye present. Split a take-out order with a German friend, but he paid? Here's his paypal to send him your share. It's just assumed that everyone has paypal over here...
- iammrpayments 1mo agoThought they use Sepa
- netsharc 1mo agoSEPA uses your IBAN (account number), and one can also enter this account number for payment, implicitly allowing the store to withdraw money from it...
- fuzzy2 1mo agoWell yes. But just in case this wasn't clear: this is a crime, and you will get your money back in most cases. It's on the merchant to ensure a Direct Debit Mandate is actually valid.
- master-lincoln 1mo agoI do not think it is possible to withdraw money having only an IBAN. It would need a SEPA direct debit mandate for my bank to accept the transfer request.
- deleted 1mo ago[deleted]
- onion2k 1mo agoHas PayPal blocked GrapheneOS, or have they blocked every OS they're unable to verify and done a poor job of implementing their checks? Hanlon's Razor is a useful tool. https://en.wikipedia.org/wiki/Hanlon%27s_razor https://en.wikipedia.org/wiki/Hanlon%27s_razor
- redleader55 1mo agoYou're a banking app. Why do you need to check my phone or my os? The security is not in what phone I use, but in how sane your 2-factor auth is and if even exists.
- onion2k 1mo agoYou're a banking app. I've been called worse.
- basilikum 1mo ago> have they blocked every OS they're unable to verify This is evil in itself.
- bossyTeacher 1mo agoThey have blocked rooted phones based on the error provided. Nothing to do with verification. They treat rooted phones to a level they don't with phones without critical security updates. That's the tension. Non-rooted phones aren't necessarily unsafer.
- Grisu_FTP 1mo agoI still remember when my bank wanted me to run Android 9 instead of my Android 15 rom (without root) on my Samsung S8 because "muh security!!" Funnily enough, the only way to hide those detections was to Root my phone... And i still remember when i had an appointment there, they wanted to see something in my Bank app, i opened it (and i assume it had an update since i then last used it) and a big "THIS DEVICE IS NOT SUPPORTED. ROOT IS NOT SUPPORTED" poped up But was as simple as readding the bank app to my root hiders. but still, i hate this security theater
- ThomasGlanzmann 1mo agoI'm on Debian Testing sometimes on amd64 and sometimes on m1. Paypal also doesn't like me. Than I have two options: I use a Windows VM to do the payment or I use another payment method. Most of the time I use the other payment method.
- 7r33 1mo agoP10F, 2026081301, Aurora Store, secondary profile, flawless. Try harder.
- grapheneos 1mo agoIt's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
- savwolf 1mo agoThis is what really makes me question if I want to continue to use GOS, already some UK banks apps (which are app only) don't want to run. I'm considering switching back to stock as I can't be bothered to try to find hacks and workarounds for daily necessities.
- depressedpanda 1mo agoI would never use a bank that is app only. Sounds like a horrible experience.
- microsoftedging 1mo agoSame experience in the UK, but it was the push that got me to switch from Lloyds to Nationwide if you're looking for another option. They're great, they even have offline 2FA methods as they send you a card reader for things like authing purchases or sign-ins. And the app still works :-)
- Flere-Imsaho 1mo agoI use revolut on a stock pixel 9, have been considering Graphene, but im worried about stuff like: https://grapheneos.social/@GrapheneOS/117045625230764434 https://grapheneos.social/@GrapheneOS/117045625230764434
- grapheneos 1mo agoRevolut still works for the vast majority of our users due to our workarounds for their attempted ban on it. We got in contact with Revolut due to our thread and they appear willing to avoid banning it going forward despite their past moves to do it.
- grapheneos 1mo agoPayPal's app still works with our per-app secure spawning toggle disabled. It's a bug in their anti-tampering code. Have you tried the per-app exploit protection compatibility mode or the finer-grained toggles for those apps? 90% of banking apps work on GrapheneOS but MANY have problematic anti-tampering code requiring the per-app compatibility mode.
- hoshi73 1mo agoDid you try enabling the exploit protection compatibility mode in the app settings? GrapheneOS should have shown you a Play Integrity API detection notification if the app is actively trying to block non-GMS-certified devices using Play Integrity API.
- grapheneos 1mo agoThis is a correct answer despite the fact that it was previously hidden by flagging. PayPal's recent updates with incorrect anti-tampering code work fine on GrapheneOS when secure app spawning is disabled. It's best to disable only secure app spawning (exec-based spawning) for it instead of using the whole compatibility mode. Using the whole compatibility mode is the first thing to check before narrowing it down though.
- ButlerianJihad 1mo agoSo the OP is just lying out of ignorance and rash judgement, and spreading calumny about PayPal. And PayPal has done nothing to their app to block GrapheneOS. And hundreds, thousands of participants on HN have been misled by another rogue "Tell HN". Good times.
- grapheneos 1mo agoThey're not lying but rather likely didn't know about the per-app exploit protection compatibility mode. They narrowed it down to secure app spawning needing to be disabled. Now they know what to do when an app doesn't work on GrapheneOS. You can help by upvoting the update they posted with the solution: https://news.ycombinator.com/item?id=49462575 https://news.ycombinator.com/item?id=49462575
- ButlerianJihad 1mo agoThey did actually and knowingly lie. Because I guarantee that they had no way to affirmatively know that PayPal themselves had done anything to their code. They didn't see no ChangeLog and they didn't see no Release Notes about it. They didn't read any news from the app developers. They jumped to conclusions about malice when it was actually incompetence and ignorance, much like their own. They could've simply neutrally stated that: "PayPal crashes when I try and run it under GrapheneOS" and that would be a true statement without assigning blame or malice. But, not knowing PayPal was innocence, they chose to assign malice to them instead. That's a choice. That is rash judgement and calumny.
- dennemark 1mo agoLooking at the description, the title should be changed to "Contactless PayPal card does not run on GrapheneOS" I use latest Aurora Store PayPal version and it still works. I just dont use contactless payment.
- hashworks 1mo agoI'm not using the contactless payment feature and get the same crash and error.
- grapheneos 1mo agoThe app can still be used too but requires the per-app secure spawning toggle with recent app versions. It's due to PayPal shipping buggy anti-tampering code.
- grapheneos 1mo agoIt's not specific to contactless payments. It's a bug in the app and still works with the per-app spawning toggle disabled. The per-app exploit protection compatibility mode sets all these toggles to the compatibility mode but it's best to figure out the minimum required.
- StrLght 1mo agoStill works for me. I had to update exploit protection after their latest update — I think it was enabling dynamic code loading via both memory and storage that did the trick. Edit: checked now, I have also disabled secure app spawning.
- Retr0id 1mo agoInteresting, just inferring from that it sounds like GrapheneOS's actual-security features might have been tripping up PayPal's root-detection "security" features. (Rather than something fundamentally incompatible, like them using Play Integrity)
- StrLght 1mo agoThere are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :) IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.
- skinfaxi 1mo agoSo to use paypal you actually have to reduce the security of the phone?
- iamnothere 1mo agoNot too surprising. I usually have to reduce my browser security on the rare occasion that I access PayPal via the web.
- StrLght 1mo agoAs with all things about security — it depends on your threat model. It reduces security of the app itself, but doesn't affect security of the phone by much.
- anonymousiam 1mo agoHopefully these stupid companies that are refusing to allow their apps to run on GrapheneOS will have a change of heart when Motorola begins launching their new phones: https://arstechnica.com/gadgets/2026/08/motorolas-grapheneos-phones-will-launch-in-2027-priced-higher-than-pixels/ https://arstechnica.com/gadgets/2026/08/motorolas-grapheneos...
- master-lincoln 1mo agoif there is enough money to be made they will consider it...
- grapheneos 1mo agoPayPal's app still works with our per-app secure spawning toggle disabled. It's a bug in their anti-tampering code.
- bdzr 1mo agoI also ran into the eBay application being blocked just recently. Other than that I've had no issues, but I imagine this is going to become more and more common as time goes on.
- StrLght 1mo agoeBay has been enforcing Play Integrity for over a year now. Luckily you don't lose much by using it in a browser. I also get why they'd be desperate to fight bots. It's a weak excuse for not doing it better, but at least it makes some sense.
- microtonal 1mo agoMost likely, unless the GrapheneOS user base can be grown quickly. We are at a point in time where the number of apps that block GrapheneOS through Play Integrity Strong is fairly small. So it's still possible to grow the user base since the inconvenience is not too large. Once the majority of banks would require passing Play Integrity Strong, far fewer people would switch. So, best to grow the user base fast now and let every user send a complaint for every app that gets blocked. A few million users will be harder to ignore.
- silisili 1mo agoMotorola partnering is huge and should help this if it comes to fruition. They sell a -ton- of phones in the Americas. Best not to get on their bad side.
- grapheneos 1mo agoPayPal's app still works with the per-app secure spawning toggle disabling for it.
- doublerabbit 1mo agoWhen threat comes knocking, the door gets bolted-shut.
- zache6 1mo agoIt works for me after enabling exploit protection compatibility mode. Pixel 9a on latest versions of GOS and PayPal.
- grapheneos 1mo agoWith the default settings, the latest versions of PayPal only require disabling secure app spawning. It may also require dynamic code loading via storage, dynamic code loading via memory and native debugging being permitted but those aren't blocked for user installed apps by default. People can opt-in to those being enabled by default for user installed apps similarly to memory tagging, but memory tagging has the biggest positive impact.
- zache6 1mo agoI had those set to enabled by default, thanks for the clarification.
- prartichoke 1mo agoConfirmed on my phone too. I left a 1-star review on the play store saying it crashes on every launch, uninstalled and will use the website from now on. (Luckily, I dont use contactless payments, ai just send and receive money from friends from time to time)
- grapheneos 1mo agoYou can solve it with the per-app toggle for disabling secure spawning. PayPal only accidentally broke compatibility with secure spawning. You should still complain to them about it.
- deleted 1mo ago[deleted]
- paperscissors 1mo ago[flagged]
- schnittbrot 1mo agoI've been using it in the browser with GOS no problem. Any reason why one would need the app besides a little more convenience?
- aframemodular 1mo agoThey require the app for certain things like managing which PayPal debit card category gets 5% cash back
- grapheneos 1mo agoThe app can still be used too but requires the per-app secure spawning toggle with recent app versions. It's due to PayPal shipping buggy anti-tampering code.
- taegee 1mo agoStill works fine for me. PayPal and GrapheneOS are both on the current release.
- grapheneos 1mo agoPayPal's app requires disabling the per-app secure spawning toggle for it now due to buggy anti-tampering code. You may have already enabled the per-app compatibility mode which includes that. You may also not have the update yet. Play Store supports staged rollouts where updates are only available to a set percentage of users.
- jadar 1mo ago[flagged]
- daveoc64 1mo agoGrapheneOS doesn't give you root access. The OS is designed to offer privacy and security guarantees, which root access breaks, so they don't offer it.
- Aachen 1mo agoHaving access to your own device doesn't break anything, they just don't want to be put in the same category as other FOSS Android distributions and play by Google's book so that apps will at least allow one open OS to work
- ledoge 1mo agoA normal GrapheneOS installation uses Android Verified Boot with a locked bootloader, and does not give the user root access. Google's Play Integrity cannot be used to verify the integrity of the OS (as GrapheneOS is not approved by Google), but equivalent verification can be done using standard Android APIs and GrapheneOS's public keys.
- p0w3n3d 1mo agoI wonder do you have administrator access on your Windows/Mac/Linux? Because your argument sounds like you gave the admin password to someone else to prevent yourself from tampering with your computer for the security reasons
- grapheneos 1mo agoGrapheneOS isn't rooted. It's caused by their anti-tampering code being buggy and recent releases of the app wrongly detecting secure spawning as tampering. We have a per-app secure spawning toggle due to these issues and that works around it.
- jordand 1mo agoI've disabled auto-update for PayPal in the Play Store and also Disabled the app locally (so I can re-enable when rarely needed). They'll force people to update soon enough given how banking apps are.
- grapheneos 1mo agoThe latest updates still work on GrapheneOS with the per-app secure spawning toggle disabled. It's a bug in their anti-tampering code.
- https443 1mo agoSimilarly, Cash App does not work on Graphene
- Helmut10001 1mo agoWhy do you need PayPal APP? I have grapheneos and just tested logging in to PayPal web. Works.
- grapheneos 1mo agoSome features are app specific such as tap-to-pay, which does work on GrapheneOS. PayPal's app still works with the per-app secure spawning toggle disabled. It's a bug in their recent updates causing an incompatibility with secure spawning and they should fix it.
- varispeed 1mo agoThis should be illegal, but it won't. Corrupt politicians want people to be only on the approved operating systems so they can be surveilled.
- grapheneos 1mo agoIt does still work. It's just a bug in their anti-tampering code breaking it with secure spawning. Using the per-app secure spawning toggle or broader per-app exploit protection compatibility mode resolves it. PayPal should fix their code.
- dingdong2026 1mo ago[flagged]
- helloiamantoine 1mo ago[flagged]
- goonersallofyou 1mo agoI remember when I had to boot up an old windows machine because TurboTax refused to run on a Linux (might have been something related to flash as well... been too long to recall), then I just ran Windows in a VM, then extensions allowed me to do User-Agent spoofing (honestly should have thought of this sooner), and now they don't seem to care at all. I did my taxes on OpenBSD last year.
- kova12 1mo agoHow is it that PayPal is still relevant? What does it even offer these days that other platforms don't do better?
- grapheneos 1mo agoPayPal and Curve Pay support tap-to-pay on GrapheneOS in Europe where they have it deployed. Google Pay bans using GrapheneOS for it via the Play Integrity API. Most banks only support using Google Pay rather than having an alternative in their apps. Many European banks have an alternative. PayPal's app does still work on GrapheneOS, they only accidentally broke it with the default settings due to bugs in their anti-tampering code. Disabling the per-app exploit protection compatibility mode works around it. They should fix it and start testing on GrapheneOS.
- josephcsible 1mo agoThis wouldn't be that bad if they had a functional website you could use instead, but their website doesn't even let you do things like pick your monthly rewards category or configure auto-replenish for your debit card.
- grapheneos 1mo agoPayPal's app still works with the per-app secure spawning toggle disabled. It's a bug in their recent updates causing an incompatibility with secure spawning and they should fix it. Tap-to-pay is unlikely to be provided via their website and does work on GrapheneOS.
- 12ahs71 1mo ago[flagged]
- grapheneos 1mo agoIt's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
- bookofjoe 1mo agoI would bet that fewer than 1/1,000 non-HN users have ANY clue what it means to root a device. I sure don't!
- grapheneos 1mo agoGrapheneOS doesn't involve rooting a device. It's a privacy and security focused OS for hardware with official support for using another OS.
- bookofjoe 1mo agoAlas, GrapheneOS doesn't work with iPhone.
- deleted 1mo ago[deleted]
- onaclov2000 1mo agoDumb idea, but I wonder if the underlying os can see who is asking questions like do you have root, And if an app has no need to know, it just plays dumb and responds...of course not. It's a bit of a chicken and egg problem, in that if you don't know what apps need to know if you have root, or not, then you can't determine that at the OS level...maybe an option for the user (popup) to tell the program, tell them we are rooted or not? (Or a settings page you can determine what apps can know root or not)
- Retr0id 1mo agoThat's exactly how modern Android rooting tools work. You select which apps you want to have root, in a manager app. No other app should be able to notice. But GrapheneOS isn't root, that's just PayPal's thing being broken.
- NoidFonsense 1mo agoperhaps but this is about device/os attestation, not rooting
- kevin_thibedeau 1mo agoHow does their web site do device attestation? The argument that apps have to be locked behind a validation mechanism controlled by Google to be secure is BS when a cookie is sufficient.
- grapheneos 1mo agoGrapheneOS isn't rooted. The issue is their flawed anti-tampering code shipped a new bug breaking compatibility with secure spawning. We have a per-app toggle for secure spawning due to seeing this with other banking/financial/government apps and it works for PayPal's app as the original poster discovered. If they want to ban arbitrary operating systems, they can use attestation and it can't be fooled the way you're describing. Apps doing this can explicitly verify GrapheneOS and we've convinced some apps to do that. We've also convinced a smaller number to stop doing that at all.
- shaky-carrousel 1mo agoIt works here. Running in a work profile, no contactless payments. Play Integrity API: Not blocked Hardened memory allocator: Enabled Memory tagging: Enabled Extended virtual address space: Enabled Secure app spawning: Enabled Native code debugging: Allowed WebView JIT: Disabled Dynamic code loading via memory: Allowed Dynamic code loading via storage: Allowed
- dathinab 1mo ago> no contactless payments. I think this is the problem here. A lot of NFC related tech is deeply rooted in having "trusted (aka large company)", "attested (aka you can't easily lie)", secure module functionality. What should have happened is to just not enable the contactless payment functionality for given app, even if the user enabled it in general. And not crash. Also as others have pointed out, this might be an accidental mishap not an intended outcome. But it's not like PayPal is known to care about small user-base edge cases (quite the opposite). Which I guess is the actual root problem.
- grapheneos 1mo agoThe issue turned out to be PayPal adding incorrect anti-tampering code incompatible with our secure app spawning feature. It's common for anti-tampering code to break real security features. It's a major reason for us having the per-app compatibility mode toggle and the finer-grained toggles for the individual exploit protections known to be incompatible with certain apps,
- microtonal 1mo agoDoesn't work here. No contactless payments, full Exploit protection compatibility mode.
- shaky-carrousel 1mo agoThis is the PayPal version I have installed that works: Version 8.107.0 com.paypal.android.p2pmobile
- ethagnawl 1mo agoDoes the website still work?
- grapheneos 1mo agoYes, but PayPal's app still works on GrapheneOS too. It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
- Itoldmyselfso 1mo agoThe best approach to combat this is to cause as much headache as possible: bombard them with 1-star reviews, contact news sites, post this on social media sites snd contact Paypal's support.
- microtonal 1mo agoGood luck with 3.7M existing reviews.
- Itoldmyselfso 1mo agoWith a user base of 500k if every GOS user left a review that'd make a dent.
- microtonal 1mo agoTrue. But when the Volkswagen block was publicized a lot, last time I checked the number of stars didn't even decrease by 0.1 (even though there were a bunch of negative reviews). Admittedly, PayPal probably has more GrapheneOS users than VW, but with VW negative reviews could have made a serious dent.
- grapheneos 1mo agoIt can be worked around with the per-app secure spawning toggle. Ideally people should still complain and get them to fix it.
- 1970-01-01 1mo agoFunny how PayPal don't trust you to safely handle root but they will trust you to pay thousands in loans, credit, etc. What a joke.
- grapheneos 1mo agoPayPal still works on GrapheneOS. It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
- enos_feedler 1mo agoI have never been a crypto currency advocate, but if the banking utility of a mobile phone is going to be dictated by the operating systems that finance apps whitelist, I might want open rails that work with my open phone
- justmarc 1mo ago[dead]
- steveharman 1mo agoIsn't this more about PayPal disliking a rooted device rather than Graphene? I used to have all kinds of issues with financial apps when I was rooted, regardless of OS
- edoceo 1mo agoIt's been explained in this thread many times: not-rooted
- Groxx 1mo agoFlawed root detection issues are kinda common to see when running Graphene, tbh I suspect this is just an accident - it very much is not the first time, nor the first for PayPal.
- grapheneos 1mo agoGrapheneOS isn't rooted. The issue is their flawed anti-tampering code shipped a new bug breaking compatibility with secure spawning. We have a per-app toggle for secure spawning due to seeing this with other banking/financial/government apps and it works for PayPal's app as the original poster discovered.
- glitchc 1mo agoHave you explicitly enabled root access? GrapheneOS does not do so by default, in fact their documents explicitly mention that enabling root access weakens the OS's security posture. Many app protection frameworks detect root access and block by default.
- nekusar 1mo ago[flagged]
- chmod775 1mo agoWorks just fine for me on an unrooted Pixel 10 Pro.
- grapheneos 1mo agoPayPal's app requires disabling the per-app secure spawning toggle for it now due to buggy anti-tampering code. You may have already enabled the per-app compatibility mode which includes that. You may also not have the update yet. Play Store supports staged rollouts where updates are only available to a set percentage of users.
- BoredSmurf 1mo ago[flagged]
- romanovcode 1mo ago[flagged]
- grapheneos 1mo agoAndroid remains open source via the Android Open Source Project. The vast majority of Android apps including PayPal work fine on GrapheneOS. PayPal recently shipped incorrect anti-tampering code incompatible with our secure spawning feature. The feature spawns app processes with exec to provide their own address space layout randomization, random memory tags and canaries. We're aware of these kinds of incompatibilities and provide a per-app toggle for exec-based spawning which works for PayPal. PayPal made a mistake and didn't consider GrapheneOS as part of this recent change. They'll likely fix it since they don't ban using GrapheneOS and likely want it working on GrapheneOS.
- hkt 1mo agoThis happened to me with Starling Bank's app years ago. I have since conceded defeat. What is pernicious is how some of these services are unusable without an app, while also bossing the user around about what operating system they can use. Starling left me without any access to any of my bank accounts at the time (2022 or so) so now I use very old school online banking now to avoid this situation ever occurring again.
- grapheneos 1mo agoPayPal still works on GrapheneOS. It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it. Starling Bank app still works on GrapheneOS too. See here: https://github.com/PrivSec-dev/banking-apps-compat-report/issues/39 https://github.com/PrivSec-dev/banking-apps-compat-report/is...
- cactusbee 1mo agoAh, that is why it was crashing on my device :(
- grapheneos 1mo agoPayPal's app requires disabling the per-app secure spawning toggle for it now due to buggy anti-tampering code.
- thomasmarton 1mo agoI tried it on my Pixel 10 Pro XL as well. Latest version of GrapheneOS, latest play store version of the app and it works. Even tried completely nuking app data and logging in again. Login, security check, fingerprint setup, everything worked (I even got the alert that it used the Play Integrity API) I assume if anything, this is probably the contactless payments. I do somewhat understand why they are really trying to lock something like this down, but as everyone pointed out, giving the green light to a CVE infested version of Android while prohibiting the use of a version that goes above and beyond when it comes to security is absurd.
- grapheneos 1mo agoThe issue turned out to be PayPal adding incorrect anti-tampering code incompatible with our secure app spawning feature.
- iqra_c 1mo ago[flagged]
- grapheneos 1mo agoPayPal doesn't ban GrapheneOS. They accidentally broke compatibility with secure app spawning (exec-based app process spawning). It can be worked around by disabling secure spawning for the app. That's done automatically by the simple per-app exploit protection compatibility mode which sets all of these exploit protection toggles to the compatibility mode.
- Eval-Apply 1mo agoIt might involve the Google Play Integrity API. GrapheneOS officially passes only the MEETS_BASIC_INTEGRITY tier of the Google Play Integrity API and fails the MEETS_DEVICE_INTEGRITY and MEETS_STRONG_INTEGRITY levels. Many banking apps I use in my country require this level plus something from the GPI API, which makes them unusable. You need a regular, unmodified smartphone to use them.
- deepc4life 1mo ago[flagged]
- grapheneos 1mo agoIt doesn't defeat the purpose of GrapheneOS. GrapheneOS does not require people to do all their financial transactions with Monero to heavily benefit from it. Their app can also still be used on GrapheneOS. It just requires the per-app secure spawning toggle due to a recently added app bug.
- deepc4life 1mo agoAll true things. I'm suggesting for the user, who chose to use GrapheneOS - why did they choose GrapheneOS? Many think an OS or doing one thing or another 'protects' them - and they certainly can, but from whom and why? I have a GrapheneOS phone but I would never do any PayPal transaction on it.
- AngryData 1mo agoI still don't understand why people atill use paypal. It has veena shitty and shady company from the start and never got any better. They are known thieves that use political games to illegally seize money and get to keep it until you "prove" that $100 is yours and not used for random bs like "terrorism".
- heyaco 1mo agofuck oaypal. cancer.
- KinetiNode 1mo agothis is actually irritating. I can't even root my phone without everything breaking
- knutt3 1mo ago[flagged]
- justinfuego07 1mo ago[dead]