759
submitted 1 week ago* (last edited 1 week ago) by Sunny@slrpnk.net to c/privacy@lemmy.ml

cross-posted from: https://slrpnk.net/post/15995282

Real unfortunate news for GrapheneOS users as Revolut has decided to ban the use of 'non-google' approved OSes. This is currently being posted about and updated by GrahpeneOS over at Bluesky for those who want to follow it more closely.

Edit: had to change the title, originally it said Uber too but I cannot find back to the source of ether that's true or not..

(page 2) 50 comments
sorted by: hot top controversial new old
[-] bitwolf@sh.itjust.works 77 points 1 week ago

McDonalds? Uber?

They both have fully functioning webapps btw.

[-] Wilmo@lemmy.world 54 points 1 week ago

Right people who install various apps like McDonalds apps etc, are these even typical to GrapheneOS users? I'd think most would avoid superfluous data stealing apps.

load more comments (5 replies)
load more comments (11 replies)
[-] zako@lemmy.world 69 points 1 week ago

the problem here is not the banks or apps, the problem is Google Play Integrity API, which is supposed to enforce to run apps in secured phones and it is used to ban secured ROMs such as GrapheneOS and it allows to run apps on outdated phones without security patches.

load more comments (24 replies)
[-] Anivia@feddit.org 58 points 1 week ago

Time to switch away from Auth I guess. Not even using GrapheneOS cause I have a Samsung phone, but this is not acceptable

[-] Sunny@slrpnk.net 27 points 1 week ago

Highly highly recommend Ente Auth!

Also featured on Privacy Guides

[-] dantheclamman@lemmy.world 20 points 1 week ago

Authy is no good anyway. Keeps codes hostage with no way to back them up. So many great open source alternatives

load more comments (2 replies)
[-] penquin@lemm.ee 51 points 1 week ago

Webapps everything you can like I do with Firefox and ublock origin. Fuck these assholes.

[-] stom@lemmy.dbzer0.com 22 points 1 week ago

Not for Revolut. App only.

load more comments (2 replies)
load more comments (3 replies)
[-] olafurp@lemmy.world 50 points 1 week ago
[-] granolabar@kbin.melroy.org 25 points 1 week ago
[-] Numenor@lemmy.world 22 points 1 week ago

He makes a solid point

[-] AlecSadler@sh.itjust.works 44 points 1 week ago

This surprises me because McDonald's app is hands down the worst app I've ever encountered in the history of all Android apps.

It's is sluggish, ignores touches/taps half the time, doesn't adhere to Android best practices for flow, crashes a lot, errors a lot, etc.

But OK McDonald's. Fuck off.

load more comments (2 replies)
[-] BigDanishGuy@sh.itjust.works 43 points 1 week ago

OK McDonald's, I will not use your most cost effective ordering method. I guess I will just have to order my 10 individually custom cheeseburgers at the counter instead. I might have to have e the order read back, and change my mind about a few burgers.

load more comments (29 replies)
[-] Samsy@lemmy.ml 41 points 1 week ago
[-] hiramfromthechi@lemmy.world 40 points 1 week ago* (last edited 1 week ago)

I can't prove it, but I'm 99% sure Lyft did the same thing. Had a perfect rating (and was even a driver at one point), and they banned me without explanation right after I switched to GrapheneOS.

Emailed them a few times asking for the reason, and they refused to tell me.

_"Legally, we cannot release any additional information except that we found your account to be violating our Terms of Service.

We will be in touch if we are able to reopen your account in the future."_

There's absolutely nothing else that they could've misconstrued as "violating the Terms of Service."

If Uber's going down the same path, no more ride-sharing for me I guess. ¯_(ツ)_/¯

load more comments (8 replies)
[-] Andromxda@lemmy.dbzer0.com 29 points 1 week ago

I don't think it's a coincidence that the shittiest companies are those, who enforce Google's broken and monopolistic "Play Integrity" API. Revolut has connections to Russia, McDonalds supports the Israeli genocide in Palestine and Authy has always just been a massive piece of shit, not even allowing users to export their TOTP seeds. These are three companies I would NEVER even consider using anyway.

And "Play Integrity" API actually does NOTHING, absolutely NOTHING for your security as an end user.
You use an outdated, unpatched Android version with multiple severe, publicly known exploits on an insecure device?
Google doesn't give a single fuck.
You use the newest version of Android with all the patches applied on Google's own hardware, with a locked boot loader and a hardened operating system?
That's not allowed by the "Play Integrity" API.
It's only purpose is to serve Google's monopolistic business interests.

load more comments (2 replies)
[-] tisktisk@piefed.social 28 points 1 week ago

Is this not a sign of the true intentions on both sides of the dilemma here!?!?
Let us go to the end. We cannot afford to carry on in fear of these bans. Let the lines be neatly placed and the sides chosen wisely. If sustained profits are desired, the walled-gardens must come down.

Vote with your dollar and vote again with your data. Wary, but never afraid is the motto privacy comrades!

load more comments (1 replies)
[-] Roopappy@lemmy.world 27 points 1 week ago

Why would anyone load an app from McDonalds? You want to give them elevated access to your most personal data for a few dollars of coupons?

What are they taking from you that's worth more than the discounts they are giving you? Because they are definitely making a profit, or they wouldn't be doing it.

load more comments (11 replies)
[-] uriel238@lemmy.blahaj.zone 27 points 1 week ago

Can Graphene add a feature to run in emulation mode to allow apps to believe it's on an unrestricted OS?

[-] mikey@sh.itjust.works 17 points 1 week ago

Unfortunately, this is probably because of the apps started using the Play Integrity API, which is a hardware-based attestation and can only be faked in two ways that GrapheneOS isn't interested in:

  • you can fake an older device that didn't support hardware attestation yet, or had a broken implementation
  • or you can try getting leaked vendor keys and emulate the crypto with those until they get revoked
[-] taanegl@lemmy.ml 25 points 1 week ago

So, uh, the next version of GrapheneOS will probably come with some Android OS version spoofing tech that solves this - if there isn't something on F-Droid already.

load more comments (4 replies)
[-] VeganCheesecake@lemmy.blahaj.zone 25 points 1 week ago

Banks seem to be hit or miss, happy that mine works. Would rather switch Banks than use a stock Rom, though.

All the Uber stuff works in Browser, both eats and their fake taxi stuff.

Not having a subtle reminder to eat at McDonald's is probably better for you.

Honestly, if your app could be a website, and includes services not on your website, fuck you, I'm gonna go to the competition.

[-] AnEilifintChorcra@sopuli.xyz 25 points 1 week ago

Lol I spent a week going back and forth with Revolut support in august. I could sign into the app but it would always ask me for a "selfie" verification and every time support would say its a super dark selfie.

Eventually I decided to try a stock ROM and it just worked and I realised what was happening so I transferred all of my money out and deleted my account.

Most local banks here are terrible at making apps, some even require a separate device that looks like a calculator to use online banking, so hopefully they wont follow suit anytime soon

[-] kevincox@lemmy.ml 17 points 1 week ago

require a separate device that looks like a calculator to use online banking

To be fair this actually provides a very high level of security? At least in my experience with AIB (in Ireland) you needed to enter the amount of the transactions and some other core details (maybe part of the recipient's account number? can't quite recall). Then you entered your PIN. This signed the transaction which provides very strong verification that you (via the PIN) authorize the specific transaction via a trusted device that is very unlikely to be compromised (unless you give someone physical access to it).

It is obviously quite inconvenient. But provides a huge level of security. Unlike this Safety Net crap which is currently quite easy to bypass.

load more comments (11 replies)
load more comments (2 replies)
[-] yoshisaur@lemm.ee 23 points 1 week ago

man, and i was gonna switch to graphene this christmas. if every app can just ban my OS, i might have to rethink this. i would use the website but they restrict so many things to apps now…

[-] Im_old@lemmy.world 19 points 1 week ago

I was about to switch bank because for a few days my current one (inadvertently) blocked it on grapheneOS. We sent them a few emails and they fixed in less than a week.

load more comments (5 replies)
load more comments (7 replies)
[-] eleitl@lemm.ee 23 points 1 week ago

Apparently, they don't need my business. Acceptable.

[-] blind3rdeye@lemm.ee 22 points 1 week ago

This sounds like an antitrust legal problem...

load more comments (1 replies)
[-] shortwavesurfer@lemmy.zip 22 points 1 week ago

Use the websites whenever you can. That's what I do at least. Although I had to stop using Lyft entirely, because they stopped supporting rides from their website apparently. And that leaves just Uber. I actually left my bank for a similar reason. It supported my phone just fine, and it worked without Google Play Services, but the website wouldn't let me do everything that the app would, and the app required that I have Aurora Store to download their banking app from the Google Play Store, and I wanted to get away from that, so I switched banks so that I could use the bank website instead. From what I can tell, you run into this kind of stuff a lot with FinTech apps. But if you use older banks, like Discover or Wells Fargo or things like that, they tend to work better. Maybe because they're not up with the newest technology, LOL.

[-] Sunny@slrpnk.net 15 points 1 week ago

Yeah Revolut is also the kinda app that is almost only a mobile app, not much you can do with their website, last i checked.

load more comments (2 replies)
load more comments (1 replies)
[-] drmoose@lemmy.world 18 points 1 week ago

Authy has been utter garbage for a long time and if you ever needed a reason to migrate away then now is as good as ever.

load more comments (7 replies)
[-] Realitaetsverlust@lemmy.zip 18 points 1 week ago* (last edited 1 week ago)

Well that's bad. I've been using revolut for years now.

Does anyone have a suggestion for a new bank that's operating under european law?

load more comments (10 replies)
[-] LambdaRX@sh.itjust.works 15 points 1 week ago

Their loss.

load more comments
view more: ‹ prev next ›
this post was submitted on 09 Dec 2024
759 points (99.7% liked)

Privacy

32179 readers
162 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS