You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.
You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.
That should also tell you that almost any open source / non-profit solution is doomed to fail due to costs. What could work is if, just like the UnifiedAttestation initiative has commercial backing, Wero is expanded to also have its own NFC payment stack. The EU already forced Apple to open up NFC, so it is possible to do it for both iOS and Android.
https://glenbrook.com/payments_news/russias-mir-domestic-pay...
Just an application which emulates the card over NFC. No need to Google Play Services. It's been this way for ≈10 years I guess.
Some European banks including mine offer NFC payments via their app as well. You don't need Google services.
NAB here in Australia did previously as well, but then they stopped doing that in 2022.
https://www.zdnet.com/finance/banking/nab-waves-goodbye-to-n...
Big if true. I guess the main problem is, would the banks from all over the world join in?
Fidesmo (https://fidesmo.com/consumer/fidesmo-pay/) has managed to sidestep this by integrating with Curve (https://www.curve.com/), which issues their own card and then charges your bank’s card from their end when you pay with theirs (tokenized and emulated by Fidesmo).
(Fidesmo also integrates with a whole bunch of banks directly, though mainly EU.)
A first step would be requiring Google to attest all devices that have a locked bootloader, verified boot, signed with non-public keys, and have a recent Android version and patch level.
IMO they should also boot anything older than Android 16 and behind more than 1-2 ASBs, if security is the real reason to have Play Integrity remote attestation.
Source? I thought it was free for OEMs?
Seems to be only in the EU (because they're being forced to), and some other sources say google is offsetting the fee through revenue sharing back to the OEMs. In any case the original claim of "the purpose of remote attestation is to force people to buy devices that pay Google license fees" is questionable given that google had to be forced into charging money for it.
https://www.theverge.com/2018/10/19/17999366/google-eu-andro...
The only reason why we don’t have them is Google / Apple duopoly.
Banks letting an open source project run transactions through them... that's... hilarious.
I think the point of GrapheneOS is being as secure as possible first and within those parameters give people the choice how much of Google they want. They have implemented sandboxed Google Play Services for a reason. Many people need Play Services for practical reasons (e.g. because they need to run apps that require it), so let's then run it in the most secure/private way possible - make it a sandboxed app, allowing users to decide whether to install it or not and if they choose to, that they can assign/revoke permissions like any other Android app.
- They might want privacy from Google. Using Google Pay probably doesn't make much sense.
- Security protection against Google. Google can remotely brick devices with unsandboxed Play Services. After blocking of ICC officials and all the Greenland threats, it's not odd that some European citizens would like to block this Google/US government attack vector.
- They want a clean phone without all kinds of crap like Gemini preinstalled.
- They want to reduce dependence on big tech/Google product in general.
In cases 2-4, using Google Pay with sandboxed Google Play services may be an acceptable compromise for convenience.
When you find battery life randomly tanks for a few days, despite not changing anything in your life, it's always Google Play Services that end up being the culprit
No.
I hate AI writing, so I never use AI for writing. Randomly throwing in accusations in discussions sucks. I don't think my comment had any of the hallmarks of AI writing either, unless bulleted lists are also not-done these days.
I guess I should be happy that people don't recognize me as a non-native speaker anymore?
I don't follow. If you mean against fraudulent spending phone based tap to pay is probably the most secure. It demands user authentication (biometric or code) for any transaction so there's no real way to trigger a fraudulent spend without the user knowing. Pretty much any other system allows for at least some amount of unauthorized spending if it's stolen.
If you just mean it's less private than I don't really know that it's terribly different than using a card. Especially if the ecosystem were open and you could choose your payment provider and not just have to use Google/apple.
If anything, this attack is a benefit of mobile payments, where you need a second device to perform the attack with, and the user to use verify themselves for the payment to go through.
Probably not but you’re doing a bad job explaining what wanting to de-google your phone has to do with the choice of wireless payment methods.
It’s in the name, “de-googling”, not “de-attack-vectoring”. People want to break away from Google specifically. They’ll still use tap to pay because it’s convenient, secure enough, at least as private as any card/bank payment, and ideally not Google, which was what people de-googling want.
Or using a (smart)phone, right? No need to go to extremes, cutting Google specifically is the win because they centralize the “spying”, not cutting the technology.
You’re stretching this for no good reason and trying to find a connection that doesn’t exist just to save your argument.
But more than that I want to have a choice.
Some people just want a phone without the duopoly and nothing else.
Also de-googling isn’t the point of GrapheneOS.
You don't live life only having privacy or not having privacy. You fall somewhere in the middle. You can shift your overall privacy posture up if you de-google, even one service at a time.
Uninstalling Google Maps, whilst still using Gmail has privacy benefits. Each step improves your privacy. Some opt for convenience over privacy, you can pick and choose services to use whilst still retaining decent privacy.
Google Wallet currently will not run on a fully updated grapheneOS.
Specifically it complains:
"Your device doesn't meet tap to pay security standards. It may be rooted or running uncertified software."
Which is fair. But something that actually works would be nice. I can keep extremely tight control on the NFC stack by toggling NFC with a quick access icon.
Not something I use very often, but not getting locked out of specific, not all, financial rails is one of those things that feels like it rubs up against the perpetual friction that the US founders, framers, whatever; didn't enshrine economic freedom in the same way as speech.
And maybe that's a libertarian fantasy. Idk. Seems worth thinking about for five seconds tho.
Bringing it back to reality. There are an incredible number of issues with trying to set up some kind of a competing service to Google Wallet to the extent that you might as well just go start a bank. And companies like simple have tried that and ended up bought by other banks at the end of it. And they weren't even trying to do anything other than offer people a banking app that wasn't total crap back in the day.
So realistically Google wallet or anything like that is not something I expect to use on a graphene OS phone until the graphene OS Motorola device comes out in the next few years. And that is entirely speculation that services like Google Wallet might be able to work on that device. But honestly it's the only real hope I personally hold for getting access to Modern payment systems on a secure device.
define open wallet then
I don't really care, as I'm protected from fraud by the card issuer and regulations in my country.
> Having my phone stolen is pretty much another level of attack.
Stealing a wallet or a phone seems just about the same level of difficulty.
And you can trick an iPhone into believing you're a transit terminal and charge arbitrary amounts to real credit cards, without unlocking the phone. (And Apple thinks this is a feature.) The attack requires specialized hardware and physical access, but if you've stolen the phone, that's fine.
(Yes, I know, this article is about Android. But most people where I live have iPhones, even if I don't.)
I get that you might want one if you are a tech maximalist with a single focus. But that doesn't mean you should stop carrying your card.
And to add to payments, the store loyalty apps are the worst... Lidl over here has an app only (no physical loyalty card), and they should be hanged for developing that... first of all, you're waiting in line while a grandma takes her phone out of her purse, then unlock it, and of course android is not satisfied with her fingerprint right then but also wants a pin... then all apps, then scroll down to L, find LidlPlus app, tap on it... QR code? Nope, not yet! First you get a daily coupon wheel of fortune, tap, wait for it to spin, see what your award is... and if it's something that she just bought, she has to manually activate that coupon in the menu (again, tap, find, tap, tap back), and then click the card button to get the qr code to scan... it's literally minutes sometimes of just waiting, instead of scanning a simple qr code on a plastic card pulled from the wallet.
We even had one of our telcos break down (full internet loss, country wide), POS terminals not working at all, and there are actually people with zero cash with them, not even like 50 euros (for just-in-case (like this))... and then you have to wait for them to turn around, take their stuff back and go home hungry.
Do you guys not have wallets with card slots?
That people trade anything for even just perceived convenience? That isn't news either, but it does explain a lot of the sad state of affairs we are struggling with today.
You live in a pretty weird bubble. (And I live in San Francisco, so I know about weird bubbles.)
That's from a year ago, I'm sure it's only grown since.
I think it's you who's in a bubble, my friend.
I assume the same must exist for euros.
I would never use a physical card with NFC anyway because it is both inconvenient (have to enter PIN every 5 transactions) and insecure (for transactions without PIN there's no verification layer), whereas on my phone I have to unlock it for every transaction no matter how small, and doing so is a small matter of pressing my finger on the fingerprint reader.
I'm as anti-capitalist as they come but this is kind of a lost fight in my mind because if not Google - then Visa/Mastercard and the bank itself will know every transaction I make anyway.
I’m talking about in-person payments though. It would be so easy to implement QR payments backed by the existing SEPA Instant rails. Many bank apps already understand EPC QR codes (usually found on invoices), so shops could just show these to accept payment. In case your bank doesn’t support SEPA Instant, you could show the cashier the receipt in your bank app, which, well, horribly insecure, but probably fine for low-stakes cases like grocery shopping (you don’t want to be banned from your grocery store chain for forging a 35 € payment).
What a single hacker writes is on the other hand just what he wrote.
You can sidestep this however by not dealing with cards. I’d look into various QR payment schemes.
Android already supports this, and has supported this for over a decade. The restriction here is on the side of the finance ecosystem. Everyone has congregated on doing Apple/Google Pay because it's cheap and easy to maintain compared to the alternative. Cards companies and banks make deals with Google, just like they do with companies like Apple, Samsung, and Garmin.
Any fintech startup with serious backing can create an Android app that works on any ROM you can imagine. I don't think you'd have an easy time finding investors for this with how much money you need to partake in the ecosystem, but the API is ready for you to implement.
Anyway, looking forward to the widespread introduction of Wero. Maybe there will be some options for third party roms in the name of digital soveranity. Seems like they want to make the EUDI wallet for digital documents no-google capable for that reason at least.