this post was submitted on 10 Mar 2026
240 points (98.8% liked)

Buy European

10022 readers
77 users here now

Overview:

The community to discuss buying European goods and services.


Matrix Chat of this community


Rules:

  • Be kind to each other, and argue in good faith. No direct insults nor disrespectful and condescending comments.

  • Do not use this community to promote Nationalism/Euronationalism. This community is for discussing European products/services and news related to that. For other topics the following might be of interest:

  • Include a disclaimer at the bottom of the post if you're affiliated with the recommendation.

  • No russian suggestions.

Feddit.uk's instance rules apply:

  • No racism, sexism, homophobia, transphobia or xenophobia.
  • No incitement of violence or promotion of violent ideologies.
  • No harassment, dogpiling or doxxing of other users.
  • Do not share intentionally false or misleading information.
  • Do not spam or abuse network features.
  • Alt accounts are permitted, but all accounts must list each other in their bios.
  • No generative AI content.

Useful Websites

Benefits of Buying Local:

local investment, job creation, innovation, increased competition, more redundancy.

European Instances

Lemmy:

Friendica:

Matrix:


Related Communities:

Buy Local:

Continents:

European:

Buying and Selling:

Boycott:

Countries:

Companies:

Stop Publisher Kill Switch in Games Practice:


Banner credits: BYTEAlliance


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] lemmysmash@beehaw.org 6 points 1 week ago

Actual NFC payments (as well as security in general) are absolutely irrelevant to this attestation technology. NFC for payments works perfectly (and not by a bit less securely) without all this "security" circus โ€” because NFC payments (and any other kind of banking or payments) is just a completely different thing.

The only thing that this kind of attestation does is proves to the app (in this example, a banking app), that the device it runs on has been deemed by the OEM (or Google in case of Play Integrity) as worthy.

And I specifically wrote it as "deemed as worthy" because it is exactly what it is: "deemed" doesn't mean that it was certified or analysed for vulnerability or even properly updated, and "worthy" doesn't mean that it's actually secure or even capable to be secure.

This whole technology and the claims about its "security" is just a marketing scam that allows Google/OEMs to control your phone by ensuring that you're not running some software not approved/sold by them specifically (e.g. GrapheneOS, LineageOS, PostmarketOS, your own Linux build, MS-DOS 6.11 โ€” doesn't matter) and for both the OEMs and the apps (banks in this case) to create a visibility of security without actually ensuring this security.

It doesn't matter who controls the attestation "authority" โ€” Google or random European companies โ€” in the end this technology is still evil and even harmful for real security โ€” by design.