Tragically, Linux phones have languished and are in an absolute state these days, but a lot of the building blocks are in place if user adoption occurs en masse. (Shout out to the lunatics who have kept this dream alive during these dark years.)
Tragically, Linux phones have languished and are in an absolute state these days, but a lot of the building blocks are in place if user adoption occurs en masse. (Shout out to the lunatics who have kept this dream alive during these dark years.)
I know banking apps are the typical example, but I've always wondered why. I use my bank's app maybe once or twice a year when I need to Zelle someone, which I only need to do when they don't have Venmo. (Unless we consider Venmo a banking app.)
I only have one bank's app installed, the rest of my banks I only interact with over their website, on desktop.
As for insurance, I've never had an insurance company's app installed.
Am I just an outlier here? Honestly, if I switched to a non standard OS, I'd be more annoyed about losing, say, Google Maps, Uber/Lyft, or various chat apps. Banking and insurance just don't come to mind at all as something I need my phone for.
I haven't seen a cheque my entire life, and I'm born in the last century
I get an alert when a payment comes it - handy for knowing if a client has paid.
I can quickly check my balance - handy for knowing if I can afford another round of drinks.
I can repay a friend in two taps - handy if they've paid for dinner.
Is anything essential? No. Is it something people use multiple times per day? Yes!
We are so boned
What do you suggest? Everyone carry around their desktop computers and our CRT monitors like we did when we wanted to play Quake with friends?
The exercise would do people good. Jokes aside though, there is a nuance between completely inconvenient and designed for the marching morons.
https://www.demandsage.com/smartphone-usage-statistics/
I am sure you are thinking I’m a “moron” because I didn’t drive to the library and use microfiche to find the information…
Or maybe you would have been okay if I used Veronica and searched Gopher sites like I did pre Web in the 90s?
Get real, dawg
Email is for old people has been a meme for two decades
https://www.techdirt.com/2007/11/15/email-is-for-old-people/
Heck even when we first start a project we either federate (or whatever you call it) the client’s Slack workgroup with ours or we ask to be on their Teams channel.
Before working where I worked now, I worked for the 2nd largest employer in the US, even there most communication happened over Chime or Slack.
On a personal level you actually email personal contacts - in 2026?
She is a retired high school math teacher - been retired for 30 years - and she has used every popular word processor/suite from the original AppleWorks for the Apple //e and she was tutoring friends kids and helping them use GSuite and PowerPoint until 5 years ago.
She uses her phone for everything and she has up to date computers a couple of printers on her network and two ISPs just in case one goes out. She kept the legacy DSL account that’s not available to new subscribers and she has cable internet.
No, it's cool tho, worry about being "hip" and enjoy the authoritarian surveillance state that you are enabling because you've been indoctrinated to want "new thing" and to reject "old thing".
You realize how ridiculous this sounds, right?
Which is a pretty funny illustration of the gist of what he was saying… it’s easier to make mistakes on phones.
I'm not doing autocorrect typos when I type on computer keyboard, also banking on no gapps rooted phone would be kinda PITA
For Bank Of America it’s:
1. Click on “pay & transfer”
2. Click on “transfer”
3. Click on “From” and choose account
4. click on “to” and choose account
Then type in the amount and and click on the date?
Is it really that much easier on a computer?
yes, especially the 4th point, the entering all the recipient's banking details on real keyboard is much more convenient than switching the windows and checking some microscopic numbers in PDF document on smartphone same copypasting them one by one between different fields (and yes, there are many companies which still don't provide QR code in their invoice)
It's surprising how we still see posts like these in 2026 on what should be a "future-friendly" forum.
No. The "banking app doesn't work" argument against non-corporate mobile OS, raised incessantly is HN comments, is bogus
I want a "phone", i.e., small form factor computer, that can run something like NetBSD, or Linux. But I have no intention of using it for commercial transactions. Mobile banking is not why I want to run a non-corporate OS
I want to use it for recreation, research and experimentation
NB. I have more than one "phone". The choice is not corporate mobile OS versus non-corporate mobile OS, i.e., "either-or". I can use both, each for specific purposes
> I want to use it for recreation, research and experimentation
I am a firm believer that phones are personal computers and should have all the end user freedom we have come to expect from personal computers. I am totally behind what your saying. (The amount of irrational anger that wells up in me when I hear someone make the argument that phones are somehow not general purpose personal computers and shouldn't provider their owners software freedom would astound you.)
Personally, I opt out of services that require the use of phone "apps" and any potential attestation they provide. Unfortunately, I just offload those needs onto my wife and her iPhone.
Want to go to a concert in a TicketMaster venue? You have to have a phone. Pay to park in some places requires a phone. Mobile ordering for some restaurants requires a phone.
I don't think it should be this way, but it is. I think we need consumer regulation to insure software freedom on phones and curtail awful user hostile "features" like remote attestation.
Until that happens (if it ever does) there is a realpolitik with needing corporate phones for some activities that can't be denied.
Before you say “what about the poor people” in the US at least, even poor people can get a subsidized free phone through the UCF (?) government fund
Also see: no I’m not going to waste development time di you can get to a website I develop with JS disabled or so you can use lynx
And everybody should have the option of open computer systems
The assumption that everyone has a "smart phone" running locked-down Android or iOS is unreasonable. Just as race, sex, religion, national origin, etc, are protected classes, the "phoneless" should be a protected class. Denying people who choose not to use a locked down phone basic interaction with your business should be legally equivalent to posting a "No blacks allowed" sign on your door, and the consequences should be the same.
> Also see: no I’m not going to waste development time di you can get to a website I develop with JS disabled or so you can use lynx
I don't see what this non-sequitur has to do with the exchange. I didn't bring anything up about Javascript.
This conversation is officially done.
No, unfortunately some things can't be. There are venues that provide tickets exclusively via mobile applications, for instance.
So you only get 98% of the world instead of 100%. That 98% is far more than the the 100% of 10 years ago. Everyone wants perfection when they've already got abundance.
Ticketmaster is bullshit, for sure, but they're just one example of the problem of being forced to use proprietary user-hostile software.
So much self victimization to avoid using open alternatives.
So much confidence for an incorrect answer. As cited elsewhere in the thread, some venues are "no app, no entry", and do not have paper tickets.
Can you cite a venue that won't take printed tickets?
Edit: it looks like NFL doesn't take them, BUT you can go to the box office with an order number and still get in, so same thing.
Turns out Ticketmaster still has ticket printing machines at such venues
Was at a game at one of them, claimed I had a problem with the app and after some negotiation at the ticket window a millennial printed me a ticket
Why do they still have the printers
The "I'm having a problem with the app" strategy can work in other contexts too. The phone can be configured so that a young person trying to help gives up
"Modern" software is highly fallible and everyone knows it
I have recent (October and November, 2025-- venues in Indianapolis, IN and Cincinnati, OH) personal experience with this. With one venue I was able to play the "confused old man" card (via phone) and get the box office to print my tickets and hold them at will call.
At another venue I called prior to my show and tried the same tactic. They told me flat out "no phone, no admittance, tough luck for you" and cited the warnings and terms on the Ticketmaster website that I'd already agreed-to. I didn't want to chance losing out on $300 of tickets I bought so I knuckled under and loaded the Ticketmaster app on my wife's iPhone.
I don't think it's as cut-and-dried as you say it is, and I don't have the stomach to risk being denied access to events I bought tickets for-- particularly at the pricing levels of today's shows.
Perhaps this is why, e.g., venues that "require" apps still have ticket printing machines and still print tickets when there are problems with using the apps
The situation is not so "cut and dried" that no one ever attends an event at these venues using printed tickets instead of displaying the ticket on the phones they bring to the event
There are alternatives to apps that are sometimes used, e.g., when customers have problems, even when businesses try to "require" apps
As such, businesses do not always succeed in collecting the same amount of data from every customer
This is not to say customers who try to avoid unnecessary data collection always succeed, either
Generally, trying is a prequisite to succeeding
If most customers do not try it does not mean no customer succeeds. There are some who do, at least some of the time
Ditch your bank if they have issues. If their retention department asks why you're leaving, tell them their app doesn't work.
This is what I was thinking as well, TBH. I'm not particularly tied to any of my banks, I already did mostly switch off of BoA because their website was so bad.
Good to hear everyone's responses in the thread though, some stuff I definitely didn't consider.
Then, a while later, CBA pretty much phased out SMS-based 2FA (or they said that if you had the mobile app installed then you can no longer use it?). Only other supported option is in-app 2FA (no support for third-party TOTP apps). So I had to start opening the mobile app every time I needed a 2FA code. Then, within the last year or so, they made a new rule, that in order to log in to the web UI at all (just initial login, I'm not talking about sending money or any other high-risk action), you had to receive a push notification via the mobile app and tap "allow". So now I literally can't log in to the web UI without also logging in to the mobile app!
So, unfortunately, "just keep using the bank's website on desktop" is increasingly and deliberately becoming not an option. I assume there are many similar stories with other banks around the world.
I've made a lot of noise about it so maybe they've "unblocked" me to shut me up. Email the CEO so it registers a complaint. Make some noise. Definitely have another bank though as you can't just depend on one.
I hope, now that the debate about our excessive reliance on American tech is on the table, that we also put limits on those essential services, like banks, imposing the usage of products from only two companies (Google or Apple) in order to operate. I think that goes at least against the spirit of the European Union.
LOL, you couldn't even place a phone call in Australia without some US technology connecting the call. I should know, we setup the app that calculates your bill. That's from the US too.
Another commenter mentioned needing to get alerts for fraud, but none of the financial institutions i'm currently doing business with have any trouble sending me text messages. In fact I have the opposite problem, I can't get them to stop using text for 2FA codes...
Many other countries simply rely on banking apps for these things, and don’t have a separate service for this kind of transaction.
Here in NL many banks (not all) require their iOS or Google app to log into their home banking on a PC/browser.
It's because Google created this thing during backroom conversations with bank associations from a handful of countries.
And this tendency will prevail as bank can collect way more data this way. Just a month ago one of banks that is often praised here sent me a letter saying “your IP activity doesn’t match your residence” (and i am not even installed their app, they pulled data from web ui usage. Imagine what happens when they get access to data mobile app can supply
Take Denmark, for example: most banking apps use eID for login, so that problem translates 1:1. But other apps who do the same include the national school communications platform (which is pretty much mandatory for a huge chunk of the adult population, who need to look at it almost daily). Also: social security card (including health portal/doctor booking/comms), driver's license, bus pass, parking app, used-stuff-marketplace, ... eID is _everywhere_ because it's a good idea.
Sure, all of this can be done on a computer. If you're near one. Or you can have separate and physical cards, like we used to have. That still works, mostly: more and more services (eg. bus pass) are going digital-only.
Really, what we need is a top-down embrace of open-source-based platforms as being _as_ (or more) secure than the established tech giants. From governments down, organisations _should_ move away from locked-down (foreign) commercial interests.
I'm not holding my breath though.
My bank uses the app for 2FA, and that became a sort of a standard in Brazil, AFAIK. Mine at least gave me the option of using an RSA SecurID or sth alike when I asked, but I don't know how much it would cost me.
My stock broker on the other hand does 2FA exclusively on mobile (and only Android and iOS). The same for the health insurer.
My car insurer didn't force me to so far, which I find strange, given their interest in tracking my location and speed.
These were some of the major factors leading me to give up on using a feature phone when I tried, a few years ago. It was a good experience, especially at those times of pandemics and political instability, but the inconveniences were many.
Make sure to leave one star reviews on all such apps that you run into.
Reddit is the epitome of enshittification.
One without, does not exist, or is in violation of their national obligations and likely to be cut off by the RBA.
The only "effective" complaint here, would be the gigantic effort to lobby for a change in laws entirely.
[0] https://www.apra.gov.au/use-of-multi-factor-authentication-m...
The best Linux for phones, SailfishOS, has a fairly good Android compatibility layer that runs many bank apps well. But despite that, it's an uphill battle. The network effect of the duopoly is gigantic.
Decentralized banking is the future!
INB4 someone mentions some edge case like 'grandma got scammed' or refunds.
Soon we Europians will only be able to pay using either an iphone or an Android device.
Hilarious
You can have a separate core and kernel to run such code. They don't have to be powerful, but they'll need to be small enough to be verified by the said provider. For most of the code that doesn't need attestation, they can be executed on normal hardware.
The provider also has to convince the regulator or banks to trust them. However, if that's solved, the user should feel no difference between pure Android and alternative platform plus attestation.
https://grapheneos.org/articles/attestation-compatibility-gu...
Some banks even do.
There is no reason whatsoever for a major corporation to not use remote attestation technology. Banks will use it because fraud. Streaming services will use it because piracy. Messaging services will use it because spam, bots. If you're the corporation, the user is your enemy and you want to protect yourself from him.
Governments want this too. Encryption. Anonymity. They need to control it all. Free computers are too subversive for them. They cannot tolerate it.
[Citation Needed]
I see this kind of claim made often, but never backed up with evidence that remote attestation of consumer devices has any real-world impact on fraud. It sounds like it could be true because it would detect compromised devices, but it could just as easily be false because people with devices that don't pass are usually technically sophisticated.
https://grapheneos.org/articles/attestation-compatibility-gu...
Some banks have added their verified boot keys. I think it helps that GrapheneOS is well-known by now for great security practices (most likely more secure than all vendor phones out there).
Seriously?? That was very unexpected... Here's to hoping this becomes standard practice!!
Of course, now Google is doing what Google was always going to do.
https://news.ycombinator.com/item?id=46723594 from Emre @emrekosmaz
It is a smartphone that runs Android, launches Debian, and dual-boots Windows 11
Actual link https://nexphone.com/blog/the-tale-of-nexphone-one-phone-eve...
If you can install a linux distro you can flash a custom rom on a well-supported phone.
If it were more mainstream I could see GUI apps to manage all this for people, if they don't already exist. Idk I just use adb.
Yes, that is generally the case. As a general rule with an Android phone reflashing the OS itself or the bootloader carries no risk of bricking the device (meaning making it impossible to recover without specialized hardware and/or opening up parts that were not intended to be opened).
There are plenty of ways to "soft-brick" a device such that you might need to plug it in to a computer, and adb/fastboot can definitely be a pain in the ass to use (especially on Windows), but if you have a device with an unlocked bootloader it's very rare to be able to actually brick the device while doing normal things.
Now, if you're doing abnormal things like reflashing the radio firmware you can absolutely brick some devices there, but you don't have to do that just to boot an alternative OS and generally shouldn't be doing it without very good reason and specific knowledge of exactly what you're doing.
I'm not going to say there are no devices where the standard process to flash an alternative OS is dangerous, but none of the relatively common ones I've ever owned or used have been built that way because OEMs don't want their own official firmware updates to be dangerous either.
tl;dr: It is sometimes possible to brick a device by flashing the wrong thing incorrectly, but the risk of doing that if you are just installing an alternative OS through a standard process is basically zero.
It really depends on the device. E.g. Pixel is quite hard to brick. Though they do sometimes increment the anti-rollback version:
https://developers.google.com/android/images
In that case you have to be careful to not flash an older version to both slots and lock the bootloader, which is possible, because many non-Google/GrapheneOS images are often behind on security updates.
But the Android SPL versions of OTA updates from Android vendors monotonically increase.
It might not boot to a working OS, but you can still get back to the bootloader to flash something newer. Unless you blindly lock the bootloader without testing if it boots first and the bootloader can't be unlocked again I guess,
This is false. As long as the boot loader is unlocked, many phones will boot the downgraded image fine. It stops booting it when you lock the boot loader and on many phones, you cannot unlock it again. You need to boot the OS to enable OEM unlocking again, but you cannot boot the OS because the bootloader refuses to.
The Fairphone community is full of people who though 'oh it boots, so I can lock', locked it and they were in a boot loop and had to send their phone to Fairphone to get it repaired for 60-70 Euro (I don't remember the exact price, but that is the ballpark).
There is an adb command that can fairly reliably detect whether the boot loader can be locked. But I'm not going to post it here, because people have to read the full flashing manual, plus in the past there was a bug where the anti-rollback would trigger even with a newer SPL.
At any rate, flashing is not for most people and it was much easier when there was no rollback protection. Of course, rollback protection does make phones much more secure.
---
I wonder if your experience is based on Pixel or older/other Android devices that do not have rollback protection.
I'm running custom ROMs for the last 15 years
Also, /e/OS has pretty bad security practices (shipping very old kernels, very old vendor firmware, and missing most AOSP security patches).
Also, be careful to follow the instructions really carefully. For some devices it's really easy to get the phone in a boot loop, where the only resort is to get your vendor to repair it. E.g. Fairphone 6 has downgrade protection and will become a brick if you relocked the phone when the old system's Android SPL is newer than the new system's.
What you're saying should happen, but it will only happen when the government legislates it happens; which frankly they should be doing (along with nationalizing a few other software projects to be fair).
A trillion dollar transnational corporation with massive monopolistic tendencies will never ever do the right thing. Expect to force feed it down their throats.
Even the EU??? Huh? Did you misspell 'especially' there? Because when your governments want to spy on your own citizens more than the big tech companies want to collect data for advertising, you probably have a problem.
Sent from my Librem 5.
So practically I cannot use it as a daily driver.
Librem 5 does have enough GPU horsepower, a functioning camera, and good pmOS support. But $800 is a lot to ask to test out switching to linux with no guarantee that my workflow will work or I will have enough battery life. It looks like the librem 5 can't record videos or do GPS navigation yet.
I am looking at the librem 5 specs again. The EG25-G is probably a better starting point for the modem now that it has been better documented and reverse engineered as a result of the pinephone project. It is interesting that the L5 has a generic smartcard reader though.
Commercial phones' costs also include the data value they continuously steal.
> It looks like the librem 5 can't record videos
It can: https://social.librem.one/@dos/115893142828953827
> or do GPS navigation yet
Yes, it can: https://forums.puri.sm/t/is-gps-supposed-to-work/21147/76
> or I will have enough battery life
Fortunately, you can replace the battery on the go. But yes, if you make no compromises, you will never win a tiny bit of freedom.
Besides having terrible battery life and security, it's just a hobby thing. Android has had millions of dev hours poured into it to be what it is.
Free software ultimately has time on its side. As long as a project has enough mindshare to keep its momentum, it really is unstoppable in the long run.
Where Linux shines is the absolute for-profit cloud/server world.
Open source has places where it works really nice, bazaar is better at "wider" stuff (having an active community, etc), while cathedral is more deeper/better at vertical integration, etc.
It won't.
There's a whole lot of shady crap underlying the infrastructure and the hardware that consumers cannot touch, pinephone / librephone or otherwise. It's not designed for consent. At best you can gain ephemeral relief, but even that is illusory, because by simple process of elimination, differential analysis allows fine grained ID and tracking of people even if they don't have accounts, phones, interact with websites, etc.
It's not a shady cabal of lizard people, it's just the grubby natural alignment of interests by a wide ranging set of companies and regulators and groups who allow it to happen without imposing any accountability, and ensuring that the system remains structured such that no effective accountability can be imposed.
Extorting constant streams of data for adtech is too valuable and the entire thing is too complex for silly things like ethics to interfere.
Only when the kill switch is on. I control it.
Also, it's possible to get AweSIM service hiding your data from the mobile operators.
We should be enforcing informed consent regulation of network infrastructure, treating privacy and anonymity as synonymous with liberty and freedom. Allowing the system to operate as it does is a choice; those with lots of money get to make it grow by exploiting a constant invasion of privacy with no concurrent return to the society being exploited.
Phones aren't built to be privacy respecting, and kill switches are a mitigation of a symptom, they don't do anything to address the disease.