Remix.run Logo
ggm 12 hours ago

Will the sandboxed google play permit banking apps to work using TPM and secured credentials?

Is it even possible to store secure credentials properly?

I would expect whatever you initialised before grapheneOS is wiped before you can run the alternate OS.

Is termux possible with a root/sudo function?

hashworks 12 hours ago | parent | next [-]

> Will the sandboxed google play permit banking apps to work using TPM and secured credentials?

Apps that don't work don't fail due to technical reasons but because upstream says so, i.e. Google Wallet. My banking app works just fine.

> I would expect whatever you initialised before grapheneOS is wiped before you can run the alternate OS.

Yes.

> Is termux possible with a root/sudo function?

GOS doesn't support root by itself since they deem it a security risk, but it's possible.

ulrikrasmussen 12 hours ago | parent | prev | next [-]

My banking app works fine on GrapheneOS today, but not every banking app does. If it depends on Google Play Integrity with strong integrity it won't because Google has successfully sold the blatant anti-competitive lie that you need to vendor lock-in your users to their OS to get security on mobile.

Secured credentials work fine, everything works fine except stuff that by design is locked in to Google like Google Pay.

microtonal 8 hours ago | parent [-]

And if a bank does this, tell them that they can do remote attestation for GrapheneOS phones as well:

https://grapheneos.org/articles/attestation-compatibility-gu...

em-bee 5 hours ago | parent [-]

tell them how? the clerk in my local branch won't be able to do anything with that information.

microtonal 5 hours ago | parent [-]

E-mail their support or technical department? I had some questions to my bank with regards to degoogled Android support and they just answered. Some banks have also fixed GrapheneOS support after customers asked.

anon5739483 12 hours ago | parent | prev | next [-]

I don't think GrapheneOS team would partner with a vendor unless their security/usability standards were met (considering how long it took since the initial announcement) so I'm expecting feature parity with Pixel variants.

kelnos 12 hours ago | parent [-]

I'm just really curious if this phone is going to pass Google's conformance tests and whatnot. I feel like some of that is incompatible with GrapheneOS's security model, so I wonder what's going to happen there.

goodpoint 11 hours ago | parent | prev | next [-]

No, grapheneOS fails both DEVICE_INTEGRITY and STRONG_INTEGRITY checks.

cromka 10 hours ago | parent | next [-]

By default. It can be mitigated.

7 hours ago | parent | prev [-]
[deleted]
kelnos 12 hours ago | parent | prev [-]

I think most banking apps already do work on GrapheneOS (not sure about TPM/secured credentials though). Graphene IIRC keeps a compatibility list somewhere. Some don't work, of course, but more do than I would have expected.

For me, the big question is if Google Wallet & its NFC payments will work. They don't on GrapheneOS currently, but if Motorola plans for this to be a fully Google-certified phone with GApps and everything, it will have to, somehow.

shakna 11 hours ago | parent [-]

https://grapheneos.org/articles/attestation-compatibility-gu...

ggm 10 hours ago | parent [-]

MyGov is my governments portal. (I'm australian) I'd have to maintain another path to do tax, Medicare, related functions. This is an embuggerance.

strcat 7 hours ago | parent | next [-]

You can keep your old phone around for it but they should solve the problem. Motorola can likely help us with getting it resolved once things are further along.

shakna 9 hours ago | parent | prev [-]

And its only getting worse. The extreme push for myID everything, is really not helping the ecosystem of things.

And on top of attestation, good luck if you've ever changed your legal name, in getting myID to behave at all.