the point of oem unlock, and rooting at all, is diametrically opposed to the vendors interest in nearly every facet. The vendor will bark "hackers" as a thinly veiled threat for the uninitiated, but we are initiated. what the vendor doesnt need you doing is erasing their telemetry and walled garden spyware. they dont need you developing alternatives to their store and to their apps, and they especially dont need you turning this effort into something as simple as an ubuntu installation for older phones they expect to follow the strict trade-in model of "buy a new phone every year"
arguably Asus refunded the purchase because this person isn't playing by the rules and being a good consumer.
Do you mean "privacy nightmare"? Security-wise, Google Pay beats using your physical card since it uses a device-specific number that can't be skimmed by terminals and reused online.
> the custom rom is still far more valuable from a security perspective than bending the knee to some bespoke ecosystem payment app (especially if you have an older device.)
I'd argue that it only makes sense if you have an older device that's otherwise not receiving any more security updates.
Skimmers would need a way to also learn the CVC2 from the back of the card to use it at most (but not all!) online merchants, but that's feasible using a small camera or a waiter/cashier accomplice doing the skimming.
With Google Pay and Apple Pay, and similar mobile wallets, that number is never shared during payments (and in fact not even stored on the device).
https://en.wikipedia.org/wiki/Chip_Authentication_Program
You need to read the entire card number + cvc2 + expiry date with your camera. That's not skimming, that's just taking a photo of the card.
https://stackoverflow.com/questions/14861908/apdu-command-to...
In the end, you'll always have to enter it on payment websites anyway.
The more pertinent factor is probably the fact that you’re using an operating system built by an advertising company.
Unless you store it in a wallet with a faraday cage, this is a laughable opinion to express.
If you grab data from a tap transaction, you can't use that data to perform another tap transaction.
* use bank website for the one bank that requires it, otherwise I got a new bank account without silly fake security.
* thepiratebay has everything Netflix and Disney does and it works anywhere
Installing crDroid on my OnePlus 9 Pro took half an hour, another half to install Magisk Delta with a few modules. The universal dark mode alone (Xposed module "DarQ") is worth the effort, but also the ability to clone apps, have proper clipboard sync, make full-system backups and customise the look and functions of my OS to a currently unparalleled degree.
The only compromise is I can't seem to be able to do NFC card payments (send or receive), one of my 4 banking apps needs a custom patch every few months to start working and a friend tells me the McDonald's app doesn't work.
After OnePlus decided to stop publishing factory images, I decided to stop buying their phones. It's a real shame, because they really do make some great stuff and prices are quite reasonable generally speaking. I used to buy a new OnePlus phone nearly every year. The OnePlus 6 was one of my favorite phones of all time.
I agree the OP6 is great (my girlfriend is still using hers), but I was still on my OP 3 like a year ago, until future ROM updates were deemed impossible thanks to Qualcomm binary blobs.
It's a real shame it's all over now. The OP 9 Pro was the last OnePlus phone made in their old way (or close to it) - not too expensive, well built, close to stock ROM, easy to reflash, decently repairable. Hopefully it lasts me as long as the 3 did because currently I don't see anything else like that on the market.
https://oxygenupdater.com/article/438/
Yes, I am still on my beloved OnePlus 6 running Lineage and had been looking around for a used 7 or 8 for 5G capability (I'm a bit sketched out by the overall throttling hoopla of 9th gen). Perhaps it's time to expand the search beyond OnePlus.
Alas, it's also annoying that some dumb banks (I'm looking at you ING Poland) consider rooted device as "insecure" but thay have no problem if I open a bank page using admin/root account on the computer)
Hmm, funnily enough at least a few years ago German Ing-Diba didn't care about rooted phones. I switched banks at some point though, so I have no idea whether that's still true.
As for ING - about 4-5 years ago it was possible to spoof the check but about 3 years ago they went full bonkers and if you didn't get the app from playstore (so for example aurora) it refused to launch...
GrapheneOS also gives you a Network permission per-app; if you uncheck it, the app has no connectivity, period.
Highly recommended.
https://discuss.grapheneos.org/d/696-issues-with-netflix-app
I just verified that I could download it just fine using Aurora Store, and I don't have Google anything installed.
You can get unlucky with your bank app but someone maintains a wiki of compatible banking apps
Android auto works OK.
"The app can't function in a low security environment, but complainant is free to use the web client in such event." case dismissed
(obviously an oversimplification, but the point stands)
Where I live the app is 100% needed because it’s the „second factor“ in the login process.
Fallback should never be the weakest link in a security chain. Especially not in something as high stakes as your banking login.
I can’t remember how I got my first bank token in my phone. Probably by physically showing up in the bank office with my id.
The secure enclave on a rooted phone that no longer has execution integrity?
If your SMS OTP leaks to the attacker, they still need to know the first factor (password, biometrics) to gain access.
Meanwhile, if your rooted phone is controlled by an attacker ... that's it, the attacker has everything.
Well, some offer a hardware device for like 25€ that can do the same thing, but then if you have an account with multiple banks, you need multiple of these devices.
What happens when you primary bank has been one of these app-only banks for the last 5 years, and you decide to make a technology change to your phone, and can now no longer get into your banking app?
Even if someone hijacks my computers web browser, the worst they can do is see my statements, any attempt to transfer out will pop up a prompt in the phone.
Meanwhile my main phone is always on the mobile network, using a proprietary modem that's running ridiculously complex firmware that does edge, lte, 5g, VoIP, has its own tcp/ip stack and a dozen other super complex protocols, is closed source, gets no security reviews and is exposed to at least my mobile provider at all times. And that's just the modem. Don't let me get started with all the value-add software the phone vendor loaded the device up with. Some of which is running with elevated privileges. You seriously think this is more secure?
Though you get those newer "app only" banks. I've never used any since I see that as a major downside, not a selling point, so idk whether they tolerate root. Even with traditional banks, I've come across a few features which can only be accessed via the phone app - in this case likely due to the belief that "web? Everyone just uses apps!" rather than security
Both will nail you to the ground.
It's important to distinguish between banking app and payment app. If you just want to check your account balance or find an ATM, the banking app will probably not mind that you're on a device that can't pass integrity checks.
If you want to use your phone's NFC to pay for coffee, though, you're going to have a bad time.
Unfortunately, locking (and unlocking) it wipes user data, so it should be relocked right after installation of GrapheneOS.
Also can Graphene still update if the bootloader is locked?
Yes, it can still update just fine. It installs its own certificate at install time and all updates are signed with it.
I think since my first Android (HTC Desire Z/T-Mobile G2) I spent a total of 1 week on stock, never was a fan of any of them.
You can bypass all current app checks using Magisk and Play Integrity Fix, but it's a bit of work to maintain and can break occasionally. You gain in this case full control of your device like a desktop OS, block ads, modify app behavior, disable unwanted system features, but you have to put in effort to maintain it.
However if you don't want to deal with that, you can also just not use those apps, use it like you would a Librem or PinePhone, load primarily open source software to it, optionally don't even bother with play store, etc. Might not be for everyone, but if you don't care that much for Google Wallet or multi-player games on your phone, it's not a bad option.
Which is a major problem because my tolerance for my bank's app not working when I open it is so low it might as well be non-existent.
I personally gave up this fight.
Magisk and PINE[1] have solved this for me. Yes, even Google Wallet is all good with my LineageOS ROM. PINE is an auto-updating PIF.
...wha? I just installed GrapheneOS on my Pixel 8 Pro and it is, by a decent margin, the best custom ROM experience on a phone I've had to date.
This was not a project I expected to use Discord for support. Sad.
> Our chat rooms are bridged across Discord, Telegram and Matrix so you can choose your preferred platform.
> We have an official forum for longer form posts, which is publicly accessible and easier to search. We are using Flarum for our forum.
https://discuss.grapheneos.org/
If they mandated discord as a closed support community sure, but you can't be too upset by the mere affiliation with a discord channel when they also offer all the above
Do you happen to know a suitable alternative?
I guess I must not run any of those apps?