all 13 comments

sorted by: hot top controversial new old
[โ€“] 38 points 6 months ago (4 children)

GrapheneOS is against this and I think I agree: https://grapheneos.social/@GrapheneOS/116200110686604617

I don't see why any system of this sort is even necessary.

  • source
  • hideshow 4 child comments
  • [โ€“] 12 points 6 months ago (1 child)

    Yes the best thing is for regulators to forbid banks from serving you for "security" reasons.

    GrapheneOS is right, but again I can't help but note them again attacking small Android manufacturers with unfounded allegations.

    Comparatively their language on Google is very timid. Obviously they are not actually competing against Google in the mainstream part of the market.

  • source
  • parent
  • hideshow 1 child comment
  • [โ€“] 4 points 6 months ago (1 child)

    Best solution for Graphene OS seems to be to use a Garmin Smart Watch with Garmin Pay.

  • source
  • parent
  • hideshow 1 child comment
  • [โ€“] 6 points 6 months ago

    Actual NFC payments (as well as security in general) are absolutely irrelevant to this attestation technology. NFC for payments works perfectly (and not by a bit less securely) without all this "security" circus โ€” because NFC payments (and any other kind of banking or payments) is just a completely different thing.

    The only thing that this kind of attestation does is proves to the app (in this example, a banking app), that the device it runs on has been deemed by the OEM (or Google in case of Play Integrity) as worthy.

    And I specifically wrote it as "deemed as worthy" because it is exactly what it is: "deemed" doesn't mean that it was certified or analysed for vulnerability or even properly updated, and "worthy" doesn't mean that it's actually secure or even capable to be secure.

    This whole technology and the claims about its "security" is just a marketing scam that allows Google/OEMs to control your phone by ensuring that you're not running some software not approved/sold by them specifically (e.g. GrapheneOS, LineageOS, PostmarketOS, your own Linux build, MS-DOS 6.11 โ€” doesn't matter) and for both the OEMs and the apps (banks in this case) to create a visibility of security without actually ensuring this security.

    It doesn't matter who controls the attestation "authority" โ€” Google or random European companies โ€” in the end this technology is still evil and even harmful for real security โ€” by design.

  • source
  • parent
  • [โ€“] 24 points 6 months ago

    Ohhhhh thatbwould be swell

  • source
  • [โ€“] 22 points 6 months ago

    Been waiting years for this news.

  • source
  • [โ€“] 11 points 6 months ago

    Finally, some good news.

  • source
  • [โ€“] 9 points 6 months ago (2 children)

    Fairphone with /e/OS is worth trying

  • source
  • hideshow 2 child comments
  • [โ€“] 6 points 6 months ago (1 child)

    Google will fight this bitterly.

  • source
  • hideshow 1 child comment