These days I just care so much about "things should just work" that I cannot justify doing this. I cannot think about how I could spend time figuring out what to do when the repo is no longer maintained or something breaks for random reasons.
and if you did you could use curve pay instead. Basically the same thing with more features, the only catch is that they charge FX fees after surpassing a limit (but that can be mitigated by paying with the same currency of your linked card, thus never executing a change in the first place)
My tiny local credit union app isn't on there, but it worked fine. I miss wallet a bit and it's a shame that there are important apps which still refuse to act reasonably, but I don't think it's really that bad.
I also dont think everything needs to be an app.
Even my 2015 Mazda has enough vehicular settings in the infotainment menu that despite being replaceable with a double-din I haven't bothered because I'd lose all configurability there. I opted for a cheapo $100 carplay unit instead - the modern equivalent of the discman-to-tape adapters ;)
In UK, my credit card was my transit card. I find it easier to navigate my physical wallet than a phone for such things. Personal opinion.
In any case, banking apps that don't function on graphene should be embarrassed by their stupidity. Amex forces sms/email 2fa to login on my graphene phone, when chase, fidelity and several other bank apps do not.
So it’s actually kind of a real thing
Having said that, a successful car infotainment system attack on android auto or apple carplay could, of course, compromise your phone.
So it's up to you whether you decide to cope with that possibility by breaking the law and navigating with a handheld device, or simply declining to do banking on your phone, since successful car exploits mean the attack surface against your phone is much larger than you might presume.
I was responding to a comment about the security implications of letting the infotainment system interact with the vehicle controls, and I referenced an incident where someone compromised a car via that.
I have no idea how CarPlay would compromise your phone given apples sandbox but whomever finds it is gonna have a multimillion dollar payday since iOS jailbreaks are quite valuable.
> Paying with your phone just seems like one of those separation of concerns problem.
Followed by:
> You could then separate the audio system from your car and drive around with a boombox
The first discusses behaviors of end-users. The second was a lame attempt to take the mickey of that, which is why my response clearly indicated that, to my knowledge there are zero security implications of playing your music through your car's entertainment system.
This remains true.
You are discussing design flaws, not user behavior flaws, which is why I pointed out that the design flaws you bring up, in addition to doing you bodily harm, could conceivably also be part of an exploit chain that validates the original poster's concern about using his phone for banking.
But I still sincerely doubt that the choice of playing Beethoven or Iron Maiden either directly places you at risk*, or makes a difference to the ease of exploiting any design flaws in your vehicle.
IOW, the first behavior given (not using your phone for banking) is easy to construe as prophylactic, given that, yes, in fact, peoples' credentials have been stolen from their phones and bad things have happened, due to using phones for financial transactions.
The second behavior given (use a boombox instead of your car's audio) of course could theoretically alter outcomes, but to my knowledge, there has never been a car exploit that depends on whether you have fiddled with the volume control or station selector.
* Assuming of course, that your volume isn't so loud that you've riled up other people. That's always a risk.
also my bank apps install, but yes, no tap to pay