Remix.run Logo
Retr0id 2 hours ago

Interesting, just inferring from that it sounds like GrapheneOS's actual-security features might have been tripping up PayPal's root-detection "security" features.

(Rather than something fundamentally incompatible, like them using Play Integrity)

StrLght 2 hours ago | parent [-]

There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :)

IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.

skinfaxi 2 hours ago | parent [-]

So to use paypal you actually have to reduce the security of the phone?

StrLght 2 hours ago | parent | next [-]

As with all things about security — it depends on your threat model.

It reduces security of the app itself, but doesn't affect security of the phone by much.

iamnothere 2 hours ago | parent | prev [-]

Not too surprising. I usually have to reduce my browser security on the rare occasion that I access PayPal via the web.