Remix.run Logo
ewuhic 2 days ago

Do bank apps work with GrapheneOS?

ysnp 2 days ago | parent | next [-]

In my country most of them do. It depends on the bank and their application. https://privsec.dev/posts/android/banking-applications-compa... offers a possibility to check which apps may work fine.

2 days ago | parent | prev | next [-]
[deleted]
npteljes 2 days ago | parent | prev | next [-]

Apps that need SafetyNet to be in a particular state won't work. I never experienced the downside, even with my smaller bank's app, it works seamlessly.

Although, keep in mind, this is subject to change. All they need to do is just introduce the requirement in an app update, and then you're screwed.

ewuhic 2 days ago | parent [-]

What is SafetyNet?

npteljes 2 days ago | parent [-]

Software tamperproofing. Or, at least an attempt to it. Apps can request the info from Android: "hey, is this a legit Android system? Everything in factory condition?" and this mechanism would respond. Some apps request this in the name of security. In an attempt to ensure that the user and their data via the app are safe.

Normal, unmodified Android systems report back that they are untouched. The system detects LineageOS, /e/OS, Graphene etc as modifications though, so then it reports that the system is compromised. As an option, it can be hacked, so it reports A-OK even on a modified phone - but this hack is prone to breaking, and not the easiest to do to begin with.

It's not straightforward which apps need this thing. I found a compilation here:

https://xdaforums.com/t/apps-games-need-pi-list.4677050/

But the list has YouTube, and I can report that I'm happily using that for years on a phone without this mechanism, so, I cannot vouch for this list.

lawn 2 days ago | parent | prev [-]

All my Swedish bank related apps work without issue.

But there are some exceptions out there so you need to be more specific.