NewsLab
Aug 28 13:38 UTC

Tell HN: PayPal blocks GrapheneOS (news.ycombinator.com)

493 points|by leumon||318 comments|Read full story on news.ycombinator.com
It seems like the PayPal app now refuses to run on GrapheneOS. I don't know if it's only because I have enabled the PayPal card for contacless NFC payments, but when opening the app it crashes with the following exception: com.paypal.oslo.app.rasp.RootDetectionSecurityException: Security policy violation: s=root

Comments (318)

120 shown|More comments
  1. 1. gib444||context
    With or without Google Play Services running?
  2. 2. leumon||context
    With. But disabling "Secure app spawning" seems to fix it for now.
  3. 3. gib444||context
    Ew that's a nasty workaround. But interesting to know!
  4. 4. grapheneos||context
    Secure app spawning is a per-app toggle now so it doesn't reduce OS security or the security of other apps without it disabled. It only reduces security of the app with it set to disabled. If multiple apps have it disabled, they share the same ASLR bases, memory tags for memory allocated before fork and other things.

    It's one of the toggles changed by the per-app exploit protection compatibility mode. If an app doesn't work, that's the first thing to try. It can then be narrowed down to a specific setting.

    The more aggressive exploit protections uncovering a lot of compatibility issues are only enabled for the base OS and specific user installed apps by default. Those can be set to enabled by default for all user installed apps and then people have to deal with the per-app toggles a lot more. This applies to memory tagging, disallowing dynamic code loading via memory/storage and disallowing native debugging (ptrace).

  5. 5. gib444||context
    Thanks Daniel. Nice to see you back again tirelessly educating the community about GrapheneOS, almost no comment not replied to!
  6. 6. grapheneos||context
    It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
  7. 7. leumon||context
    Update: it seems to work when disabling "secure app spawning" (for now)
  8. 8. zvmaz||context
    So it's not PayPal blocking GrapheneOS?
  9. 9. zem||context
    sounds more like grapheneos blocking paypal!
  10. 10. grapheneos||context
    No, they added incorrect anti-tampering code. It's wrongly detecting secure app spawning giving each app their own address space, memory tags, etc. via exec as tampering.
  11. 11. ttouch||context
    thank you!
  12. 12. paperscissors||context
    Great to know, thanks!
  13. 13. aabdelhafez||context
    Switched to Wero and haven't looked back.

    https://wero-wallet.eu

  14. 14. oniony||context
    The website is pages and pages of blankness for me on Firefox mobile.
  15. 15. unpopularopp||context
    Unfortunately peasants like us who don't live in the 5 countries where it's available still can't look back
  16. 16. Carbon1603||context
    I live where it's available and still can't use it to pay stuff, only to transfer money to friends.
  17. 17. therealmarv||context
    wait for it... I can see a future were every wallet, payment etc. app will block devices which are on custom ROMs and do not pass strong hardware integrity with blessing from Google.

    I've read once that there are paid app testing labs which test if an app has root and custom ROM detection and when they don't have that it's a minus point on the report.

  18. 18. muvlon||context
    You need to use your bank's app for Wero, and many EU banks' apps refuse to run on GrapheneOS for the same reasons as PayPal. This is sadly not a clear win for Wero.
  19. 19. savwolf||context
    Does this work in the UK?
  20. 20. doublerabbit||context
    No. We left the EU, so we don't get such fun.
  21. 21. jeroenhd||context
    Wero also isn't implemented EU-wide either, so it's still possible as long as the banks play ball.

    UK politics has been quite isolationist, though, so I doubt the banks will see much in interoperating with the rest of Europe.

  22. 22. sunaookami||context
    Wero is not a PayPal alternative. It doesn't even have buyer's protection and every bank must manually implement it which immediately makes it a failure. Some banks also connect it to your phone number so you can't link Wero to two different bank accounts with the same number when you have 2 bank accounts. Very messy.
  23. 23. master-lincoln||context
    > Some banks also connect it to your phone number

    What do you mean "some banks"? I thought the whole value proposition of Wero was instant bank transfers with SEPA but using phone numbers?

  24. 24. jeroenhd||context
    Wero is a payment provider technology, a money wallet, and a bank account integration technology under one single marketing name.

    On the payment provider technology side, you're right, but the wallet feature uses phone numbers (and I think email addresses) so you can send each other money without sharing your IBAN (which is slightly longer and probably not in your contacts).

  25. 25. Aachen||context
    FYI this comment was dead, not flagged. I wonder if you're hellbanned or if it was a keyword trigger
  26. 26. sunaookami||context
    ...why would I give my phone number to random people to pay them? I'd rather use an email address or user name. And using phone numbers means making it easier for normal people which means uploading the whole address book to the bank... just no.
  27. 27. Aachen||context
    I'd rather give the bank account number to people that need to send money there. Why bother with email address?
  28. 28. sunaookami||context
    With the number everyone can withdraw money (which is two clicks to cancel the transfer but still annoying).
  29. 29. master-lincoln||context
    Source needed. AFAIK that would mean faking a direct debit mandate which would be a criminal offense.
  30. 30. Carbon1603||context
    Sadly, not even close. I would even dare to say that Klarna is closer to what PayPal is, than Wero.
  31. 31. zerof1l||context
    I see this happen from time to time. Lately, almost all of the apps work fine on GrapheneOS. The best strategy is to keep writing the business once every two or so weeks that you can’t log in to and use the app. Don’t go too technical at first, because most of the time, the moment they hear things like “rooted” or “unofficial,” they just say your phone is the issue. To date, I was able to convince, or at least contribute to, making three apps work on GOS.
  32. 32. basilikum||context
    Great job, man. We have to make ourselves get heard. It's a social problem after all. Technical workarounds are great and sometimes the only practical short term option, but we have to fix the social issue at the root.
  33. 33. dvoros||context
    I had the same experience. Asked in an email why an important government app won't work on GrapheneOS, first without any technical details. Got the response that it's "because security". I sent some technical details and argued that they're denying service to their most security-conscious users. 3 months later the app started to work!
  34. 34. dinfinity||context
    To be fair, governments might be much more receptive to the argument of not having to rely on (possibly foreign) megacorporations than a company like Paypal.

    I'd wager that if it doesn't really hurt their bottom line to not support GrapheneOS, they won't really care.

  35. 35. microtonal||context
    I think in this case it's also them just introducing a new check that either GrapheneOS will need to work around or Paypal needs to refine. I can reproduce the issue, but it doesn't seem like it did a failed Play Integrity check at that point.
  36. 36. Groxx||context
    Honestly there's a decent chance they don't even know, in most cases, because corporate environments generally try hard to have as few as possible hardware/software setups to maintain. And they're unlikely to proactively test on Graphene unless it's closely related to what they do (and it definitely is not for most apps).

    Mistakes happen and ya can't fix what you don't know about. Always report issues.

    Also strongly consider just using the website.

  37. 37. lta||context
    Would you mind elaborating a bit on your process ? Or share a few relevant exchanges, I've no clue how to start having this discussion.

    That would make a great blog post

  38. 38. cromka||context
    My backwards bank blocked my mobile app access after detecting Debugging was enabled in the system. Have to call them to unlock it. I could download that APK and disassembly it with an LLM in 20 minutes, but sure, a Debug mode prevents something.
  39. 39. downrightmike||context
    Which is the opposite reaction for PC problems, because people actually have choice and historically don't accept malware being the default
  40. 40. hd4||context
    did you re-lock the bootloader?
  41. 41. grapheneos||context
    It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
  42. 42. axegon_||context
    This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!
  43. 43. fluidcruft||context
    Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors).

    Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good guy or a bad guy so it's easier to just ban guns.

  44. 44. encom||context
    How does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.
  45. 45. biosboiii||context
    If you run a rooted phone and download malware, that malware can gain root and do payments on your behalf. Then PayPal has to deal with you revoking payments etc., they don't want to so they forbid you from using PayPal on a rooted phone.
  46. 46. master-lincoln||context
    If this happens it's the device owners fault and they should be responsible for it.
  47. 47. Grombobulous||context
    Which they would be anyway since PayPal isn’t a bank and isn’t FDIC insured.

    They allow you to open PayPal.com on any web browser. Running Windows/macOS/Linux is basically identical to a rooted Android phone (you have local admin rights, you can modify and automate the browser, and can run unsigned code).

  48. 48. bayindirh||context
    No, no... In 2026, all footguns are banned. Even in programming, so if something allows a footgun, it's banned now.

    Apparently the world can't adult and be responsible for their actions, or people believe in that.

  49. 49. fylo||context
    Graphene isn't rooted.
  50. 50. Grombobulous||context
    Not only is it not rooted, it runs real Google Play services. It’s not microG.
  51. 51. ruszki||context
    Malwares can possibly do that even on non rooted phones if a privilege escalation attack is possible. And just yesterday, there was an article here about exactly one of those.

    Also I highly doubt that there is any real statistics anywhere about whether this is a real threat or not. I guarantee that nobody did such statistics properly. The only known data is from companies which sell root prevention tools, so totally unreliable. And internally I guarantee, that no banks collect such info.

    So no, banks lie about this only because they can sell this to judges as safety feature, when they fuck up, which happens continuously.

  52. 52. encom||context
    For that argument to hold, they'd also have to blacklist any phone not running the newest, most up to date Android version, because all older versions presumably have known exploits. So that basically leaves Pixel phones.
  53. 53. yjftsjthsd-h||context
    If you have a rooted phone, download malware, and hit the allow button to give the malware root access, then it can do whatever it wants.

    If you have a nominally unrooted phone on an old Android version and download malware, it can exploit a kernel bug and give itself root access and do whatever it wants.

    Protecting against the first case and not the second is at best security theater.

  54. 54. iamnothere||context
    Graphene OS does not support root. This is a false positive based on some check they are doing.
  55. 55. fluidcruft||context
    It's probably just a generic error message for failing that Google Play Protect thingamajigger that attests provenance of the vendor OS from boot. Will be interesting to see whether the Motorola phones have this endorsement when they ship. Most devices would probably fail because they are rooted rather than because they are GrapheneOS. I wouldn't put it past a scammer talking grandma into rooting their phone.
  56. 56. grapheneos||context
    It isn't due to the Play Integrity API. That shows a notification on GrapheneOS with a toggle for blocking it to work around it for services not enforcing providing a result. If that was the issue, the original poster would have known from the notification. The issue ended up being PayPal shipping incorrect anti-tampering code incompatible with secure spawning. The original poster figured that out and got it working by disabling the per-app secure spawning toggle.
  57. 57. fluidcruft||context
    Thank you for the clarification!
  58. 58. goonersallofyou||context
    One thing that I'm actually excited about regarding AI is that the pointless policy checkboxes that have never been effective in adding any actual security are even less so effective now that everyone can wield their very own security researcher.
  59. 59. edoceo||context
    PHB at insurance company will still need them, so any company they insure will need them. Theater continues, the show must go on.
  60. 60. axegon_||context
    That's your argument? Mate, you can make explosives out of stuff you can buy in literally any supermarket and no one bats an eyelash. You don't have to legally be adult to buy any of the things you'd need and I say that as someone who only struggled with chemistry in school, that's now low the bar is. What's the solution then? Ban sea salt? If someone is using Graphene, the chances of them getting hacked are astronomically lower than any Chinese spyware-infested phone.
  61. 61. john_strinlai||context
    physical risks, like your example, do not map well to digital risks faced by large international companies.
  62. 62. axegon_||context
    It was a response to the gun example which is a physical risk. My argument is that Paypal (much like all other tech-bro companies) are incompetent. The incompetence grows exponentially the larger a software company is. I speak of experience.

    On a side note, if you want to be extremely specific, the line between the physical and digital threat does not exist anymore. There are two things people need to be afraid of: incompetent friends and competent enemies. Tech giants are already filled to the brim with incompetent friends, which drastically lowers the bar for the competence of their enemies.

  63. 63. pkulak||context
    It was an analogy, or metaphor, I forget the distinction. But I don't think it was stood up to be literally argued against though.
  64. 64. rc5150||context
    then it was a bad analogy.
  65. 65. HenriTEL||context
    The problem here seems to be that the phone is detected as rooted, not specifically that it's running grapheneOS. But I agree that it's a big problem. That's how you end up in a situation where google has full control from hardware to final apps like on iphones. When devs assume that everybody is using the stock android with google services enabled.
  66. 66. svpk||context
    GrapheneOS is not rooted. The phone not being rooted is part of the GrapheneOS' security model.

    I assume the issue is it failing the deeper play integrity check which is about it not being "Google approved."

  67. 67. grapheneos||context
    It isn't due to the Play Integrity API. That shows a notification on GrapheneOS with a toggle for blocking it to work around it for services not enforcing providing a result. If that was the issue, the original poster would have known from the notification. The issue ended up being PayPal shipping incorrect anti-tampering code incompatible with secure spawning. The original poster figured that out and got it working by disabling the per-app secure spawning toggle.
  68. 68. ryandrake||context
    How did we let "rooting" become some evil thing?

    It's normal to have root (or Administrator) on your devices. After all, they are yours. They don't belong to the device manufacturer. You should have full access to your own devices by default.

    Only recently did we somehow normalize the idea that the user should not be the ultimate decider over their own devices.

  69. 69. 6510||context
    We've already progressed from "the user should not be" to "the user should never be". Perhaps we will even grow out of calling it "their own devices" eventually. If they can brick it remotely it kinda already isn't really yours?
  70. 70. iugtmkbdfil834||context
    Parent has a point by playing devil's advocate. Practical considerations indicate that platform is gonna platform. Solution here to greed driven development is some level of 'non possumus' from the general public. Sadly, I am starting to think is what we really need is a lot of valve like companies, where company stay private, founder is not a complete asshole and so on. Tall order, but that is the only real way to reverse some of the damage. I am done counting on the public to see light.
  71. 71. robocat||context
    Do you like science?

    I propose you buy enough ingredients from the supermarket and make a big batch.

    The scientific test is: how far do you get, before your door is kicked in?

    If that fails, then science #2: have fun lighting it!!

    You almost win both ways. (although I admit I wouldn't fund you even via a trustworthy intermediary say a Kickstarter campaign.

  72. 72. brightball||context
    Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal with is so extreme.

    It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The blockades are one piece of a holistic security picture that frustrate the well intentioned users.

  73. 73. axegon_||context
    Yet another weak point. My question stands: A user with an OS from 2019 is "secure" and dozens of unpatched CVEs but a literally-last-night-patch OS is not? That's the "stuff they have to deal with"? I was lucky and did not make the mistake of joining a payment provider in 2020 or 2021 (I can't remember). The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic(big part of the reason I did the "I accepted another offer already, sorry" card).

    As for geo fencing or blocking Tor... HAH! As if that's ever stopped anyone with the will. That is the last concern of anyone with a malicious intent. Sure, it stops irritating kids but no one beyond that.

    The simple fact is that cybersecurity was in an abysmal state before the slopification began and it's infinitely worse now. Paypal is no different given that much of their support has been outsourced to slop machines. Punishing the users that know what they are doing while rewarding the ones that don't is the most counter-productive and detrimental crap anyone could come up with.

  74. 74. browningstreet||context
    > That's the "stuff they have to deal with"?

    No. It's the offensive fraud vector coming from unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.

  75. 75. axegon_||context
    > unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.

    Bullshit! Source:

    > The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic

    Sounds like someone who wanted to impress the audience with fluffed up claims.

  76. 76. Zedfragg||context
    It's comments like yours that remind me of an important lesson.

    Just because you argue with vigor and intent, it doesn't make you right.

    People are offering their opinions, try not being a dick about it.

    GrapheneOS is a privacy orientated OS which is great. But if the vectors to achieve privacy are the same as used by bad actors, I'd block it too.

    Get over it, don't like it? Use a different product. Or make a better one.

  77. 77. brightball||context
    I don't run their business. Just trying to explain.

    From what we see above it sounds like the change trips their rootkit detection, which they are probably interpreting as a compromised device.

    It sounds like you're expecting them to have a perfect security posture that can correctly identify fraud in call cases and only block the real thing. It's more complicated than that and there's typically some type of scoring system involved with numerous triggers that are higher value indicators of potential fraud. If they think the device is compromised, that's probably a high value indicator.

    This is just me speculating.

  78. 78. a2ff6eeb0||context
    Yeah, they can track and profile the old os, and feed the data to the risk models.

    It's not about user security.

  79. 79. xelxebar||context
    This is interesting. You're gesturing at the idea that individual security practices can be at odds with those needed for group security. I'll be pondering on this.
  80. 80. dmichulke||context
    To stay with your analogy, there is no technical obstacle to treating the customer of 15 years differently to the newly onboarded one.

    They have all the data they need, and they choose not to use it.

  81. 81. fluidcruft||context
    The analogy was not about new vs old customers being allowed to have guns.

    I think that's a limitation of the analogy because there is no correspondence with trusted computing. I guess it would be some sort of a magical gun that some other company is endorsing as of limited use during bank robberies? Maybe like some sort of RFID thing that disables the gun when inside a bank?

    Anyway it really stretches the analogy to get tied up in technical details (risks missing the forest for the trees type error).

  82. 82. dathinab||context
    this isn't quite true

    From a Paypal security POV, weather you use "custom Android OS" or an hugely outdated Android phone, you have:

    - a similar risk for the "you" want to mess with Paypal case, in both cases the "you" can technically most likely mess with anything including the "virtual secure module" thingy android uses for NFC

    - a lower risk for "others" wanting to mess with Paypal through your phone, at least if "custom Android OS" is GrapheneOS or another up-to-date android fork with decent security handling

    so as far as I can tell, this inconsistency is very clearly not about PayPal's security.

    IMHO it's about two other things:

    1. marketing, if PayPal doesn't work on Android they lose customers, GrapheneOS for now has a tool small customer base for them to care. Outdated Android phone do have a large customer base.

    2. compliance/politics BS. including potentially involving insurance. Compliance is mostly about checking of tickmarks(1) on outdated Android they can check them off and blame the user, Goodle or "hackers" for the issue. On GraphemeOS they have a harder time checking it of. Add the smaller user base and end up with PayPal doesn't care. Also iff things go wrong with Paypal on GraphemeOS in a public manner you will have all the "crime os" bad news bs, you won't have that if things go wrong with a even more risky highly outdated Android phone.

    -----------------------

    I got a bit to much off topic below:

    (^1): Technically compliance should be about building robust, secure, law compliant systems and "showing" that by being able to pass a compliance tests consisting about a bunch of requirements. Practically there is way to many ways you can be "fully compliant" (on paper) but not secure and "very secure" but not compliant (wrt. security regulations). In the former case this might still come back and bite you iff you get sued or people suing which should get right don't get it because of ad-absurbum reasoning like "they comply with security regulations, hence can't have acted negligent". It's a shit show I don't know how to fix even if I could just magically change laws as compliance rules need technological flexibility, but if you give them that that will be abused to make insecure things pass. And the whole industry around checking that isn't really one who cares about actual security, sometimes outright corrupt (like groups which have the necessary accredited to check your compliance, are strangely more expensive then other groups, and somehow find less issues in average, with some excuse of why that isn't strange ...) :/

    ---

    Lastly similar to how Teams or Slack could easily support FF (^2) but not only don't but outright refuse to try to even work. PayPal likes to act similar and doesn't care about niches. E.g. at least on some Mobile browsers WebAuthn works, but the PayPal website refuses to _even try_ 2FA with WebAuthn on mobile no matter if the APIs are there or not.

    (^2): Yes there are some challenges, AFIK especially in certain edge cases most user might never run into. But Jitsi made it work, other smaller apps also made it work. And Jitsi is open source, so they technically can "look up" all the tricks to make it work (algorithmic ticks, not copy-pasting code) or outright just use their system with an appropriate contract (probably would be even cheaper wrt. maintenance cost then building your own system). At Slack/MS Teams scale that behavior is just messed up.

  83. 83. kevin_thibedeau||context
    The cherry on top is that their web site invariably still works so the refusal to work via app is an intentional manipulation tactic to harvest more consumer data for sale.
  84. 84. gvurrdon||context
    Sadly, their website now appears to require an app in order to sign in. Even before that it would often block me with text along the lines of "We don't know who you are, call our support number."
  85. 85. kevin_thibedeau||context
    Desktop mode fixes discrimination against small viewports.
  86. 86. gvurrdon||context
    This was happening to me on the desktop. I've not tried on a phone (I try to avoid PayPal).
  87. 87. HeyLaughingBoy||context
    PayPal? I sign in all the time. If you're referring to the popup to add a new authentication method, you can just escape past it.
  88. 88. fluidcruft||context
    I'm fairly skeptical the website supports NFC payments.
  89. 89. RunSet||context
    > Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies.

    A more apt analogy might be game developers who demand admin rights so they can install a rootkit to detect "cheating".

  90. 90. BobaFloutist||context
    They wouldn't do that if there weren't market demand. Competitive games lose their appeal when cheating becomes too prevalent.

    Similarly, payment processors lose their appeal if they can't prevent people stealing your money, or spending stolen money on your products.

  91. 91. akimbostrawman||context
    Paypal's security? the same "security" which in 2026 still does no allow a passwords above 32 character (which most likely indicating that they don't hash passwords)?
  92. 92. DANmode||context
    This might make sense if you trusted clients,

    and if GrapheneOS was a root-having OS.

  93. 93. wolvoleo||context
    I think the issue is more that big tech only trusts their own kind and usually has motives to exclude privacy conscious software because they can't datamine it or make backroom exclusivity deals.

    The needs of the user don't matter to them at all.

  94. 94. grapheneos||context
    There's no tension between the security of PayPal against bad actors and support for GrapheneOS. GrapheneOS preserves the whole standard security model and greatly improves security. It's far more secure than anything permitted by the Play Integrity API device or strong integrity levels.

    Thankfully, PayPal hasn't banned GrapheneOS and their app still works on it. They accidentally broke compatibility with our secure app spawning feature which has a per-app toggle to disable it along with the other exploit protections which can cause compatibility issues.

    There's an overall per-app compatibility mode toggle instead of users needing to figure out which protection is an issue but it's best to figure out the minimal workaround after determining that works.

  95. 95. tonyhart7||context
    "Safe way to make sure I will stop being your customer - also YES!"

    I don't think they care at all about the size of graphene os market share

    if its jeopardize entire userbase then its not worth it

  96. 96. axegon_||context
    Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.
  97. 97. tonyhart7||context
    Noo, it’s the other way around lmao.

    A financial security audit is one of the most thorough security audits you can ask for in software.

    GrapheneOS gets blocked because it doesn’t follow the secure system requirements (root).

  98. 98. inexcf||context
    What requirements does it not follow?

    >(root)

    GrapheneOS is not rooted.

  99. 99. nekusar||context
    Yep, GrapheneOS is anti-user-freedom.

    They do their damndest to prevent owners from having full control of their property, over claims of 'insecurity'.

    And complaints of this nature get inane drivel responses of "lol just fork Graphene"

  100. 100. DANmode||context
    > GrapheneOS is anti-user-freedom.

    This is a really, really poor-quality take.

    > complaints of this nature get inane drivel responses of "lol just fork Graphene"

    It’s a fork of AOSP, which you can just…use.

  101. 101. nekusar||context
    Uh, no. Shaming a "take" is just tone policing. Owners should own the hardware along with the software both.

    Its only since the smartphone era (2008) with locked down shit devices has this view changed. And people challenging this are somehow defective, tone policed, shamed, or likewise.

    GrapheneOS users are treated as 'rooted phones', at the exact same time tools that would attack and prevent corporate surveillance (xprivacy, etc) are withheld cause they would involve root.

    Even this thread is full of a lot of anti-owner hand wavey shit that amounts to 'we don't trust our users, and fork you'. https://discuss.grapheneos.org/d/18953-why-the-stigma-agains...

  102. 102. DANmode||context
    Nobody’s shaming you, reddit refugee.

    It is a common userspace decision to lock things to userspace. It’s good hygiene.

    If you want less-secure software, use AOSP or one of its many forks.

    You’re not defective: you just have different needs and threat model,

    and you’re harassing and degrading the public image of a project that’s opinionated in a very welcome way by folks in the security community - especially those who value stability and usability.

  103. 103. dingaling||context
    "It is a common userspace decision to lock things to userspace"

    Yes, running in userspace for the majority of tasks is good hygiene.

    Preventing the user from ever escalating beyond that layer on their own devices, however, is restricting their freedom to control their device. When that happens with tractors, cars or other gadgets that's considered anti-user. The same attitude should extend to phones.

  104. 104. DANmode||context
    You can wipe the device and reinstall whatever at any time.

    You have complete control of the device.

    You choose to lock certain things when using GrapheneOS. That’s their security model.

    If you want to argue that, go study it and argue that.

    If your threat model is different, if your desired security model is different, then: it’s not for you, use one of many other options.

    Like all software projects, it doesn’t necessarily exist for you - or anyone specifically.

    It’s not harming you for it to exist.

  105. 105. DANmode||context
    > prevent corporate surveillance

    Leave the abusive relationship with those entities. Don’t lay this at the feet of the GrapheneOS Project.

    If you read their FAQ, you’ll see how limited the OS actually is in retaining your privacy if you still insist on using these providers that don’t respect you.

    Said another way: stop trying to solve human problems with technical means.

    and definitely stop trying to get others to do it for you for free.

    Or, continue: I’m not a cop.

  106. 106. preg_match||context
    > Shaming a “take” is just tone policing

    No, that’s called sharing your opinion.

    You shared your opinion, someone else shared there’s that just so happened to be “I disagree with you” and suddenly that’s some type of censorship? Nobody is shaming you, either.

  107. 107. axegon_||context
    I suggest you read up the graphene documentation.
  108. 108. ruszki||context
    As several others have already said here, GrapheneOS is not necessarily rooted. So that's a lie.

    Also, I've seen such audits internally, and they don't care about security at all. They care about the theatrics of security waaaaay more.

    For example, I was at Santander in 2024, during its huge data breach. Here is the list of actions which are supposed to prevent the same kind of attacks again in the future:

    -

    Yeah, it's an empty list.

    But of course, they made our life more difficult. In the end, I literally had more permission than before, because they were even sloppier than before. But of course, I had to change my password more frequently, and I had to type it about 5x more.

  109. 109. fluidcruft||context
    Audits are primarily about liability and safe harbors in lawsuits. Companies get audits on record so that if something happens they have someone to throw under the bus and pass damages off onto.
  110. 110. dylan604||context
    I'm sure their automatic bans have happened to more people than the number of grapheneOS users
  111. 111. ravenstine||context
    With the way today's economy works, they probably wouldn't even care if they lost 1/4 of their customers in just one year. Maybe their share price would jump!
  112. 112. matheusmoreira||context
    It was never about your security, it was about the corporation's security from you!
  113. 113. xnx||context
    Might be more a matter of "OS with millions of users" vs. "OS with dozens of users".
  114. 114. RobotToaster||context
    It's not about protecting your security, it's about protecting the "security" of corporate profits.
  115. 115. exe34||context
    The safety isn't for you, it's for the companies who want your data without you getting in the way.
  116. 116. 1vuio0pswjnm7||context
    With Silicon Valley "largecorp" the required "security" is to protect the company from (a) the privacy-conscious user who would object to the company's data collection, surveilllance or ads/tracking and (b) from competitors, i.e., other companies that would potentially do data collection, surveillance, advertising services if they had uncontrolled access to largecorp's users

    "OS that user compiled herself" can avoid this nonsense

    No "smallcorp" is safe from Silicon Valley "largecorp" for long with the amounts of money SV largecorp can, and will, offer smallcorp if smallcorp grows. SillyCon Valley "largecorp" wants data about/from users, not users' money

    "Safe way to make sure I'll stop being your customer - also YES!"

    The user is not SV largecorp's customer

  117. 117. fmajid||context
    Revolut pulled that stunt, I cancelled my account with them.
  118. 118. axegon_||context
    This one is pretty interesting. I was ready to cancel my account on the spot when the news popped up but it still works on my phone. And I've updated the app as many times as they've made a release since the announcement. I honestly haven't got a clue what is going on with them.
  119. 119. grapheneos||context
    PayPal app still works on GrapheneOS.

    It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.

    The first thing to try when an app doesn't work is trying the per-app exploit protection compatibility mode. That sets all the per-app exploit protection toggles to the compatibility mode. If that works which is likely the problem, it can be narrowed down.

    Nearly all Android apps are compatible with GrapheneOS. The exception are around 10% of banking and government apps which use the Play Integrity API to ban using a non-Google-approved device or OS. That's visible to users on GrapheneOS via a Play Integrity API usage notification. After the first use by an app, GrapheneOS provides a menu for blocking using the Play Integrity API which sometimes gets apps working because many don't enforce it working. It's not fully reliable and can have downtime so apps often don't enforce providing a result.

  120. 120. factorialboy||context
    The largeCorp developer and their PM are many orgs and layers away from where these decisions are mandated.