GrapheneOS Banking app help
from mikedd@lemmy.world to privacy@lemmy.ml on 30 Oct 14:47
https://lemmy.world/post/38080669

Hello all!

I have a situation and I was curious what other people recommend me do.

I have a Pixel 8a with GrapheneOS on it and have setup a separate user profile to have work stuff and my banking app on. At the moment my bank doesn’t have a web interface, it exclusively uses the phone app to do everything. (apparently they’ll be releasing the web version of the app next month but I have no other extra information on how it will work or whatever)

I’ve noticed that periodically they do some kind of scan that ends up blocking me from using the banking app (it locks it down with an alert that says something along the lines of: “your device might be rooted and compromised”).

First time this happened I had to call them up and they sent me from one department to another and 2 days later I had access back in the app. Now this happened again (3 weeks since the first time) and I’m gonna have to call them up again.

My question is, should I buy a cheap android phone (I’ve been looking at the Moto E15) and lug it around just for banking and occasionally for the microsoft authenticator for work? Is this a common thing that people with a similar issue do? Should I just wait for the web app (problem with that is that all internet purchases have to be confirmed via the stupid app and idk how that will be handled when the web app rolls out)?

Sorry if this is the wrong place to ask this and thanks in advance to those who take the time to reply! 🙏😅

#privacy

threaded - newest

anon5621@lemmy.ml on 30 Oct 14:51 next collapse

In ur working profile u installed google play service using graphene os appstrore and u installed it using play market .So does it happen inside container? Cause for now in container even revolut working without problem

mikedd@lemmy.world on 30 Oct 14:54 collapse

Yeah, I have a secondary user profile with google play services and google play and installed the banking app from there. My main user profile has no google at all, it’s the default GrapheneOS profile (haven’t really tweaked it much).

anon5621@lemmy.ml on 30 Oct 14:57 collapse

Hmm I think the best answer possible to get from grahene is forum from dev team about ur banking app.something triggering ur banking app and have to be spoofed

monovergent@lemmy.ml on 30 Oct 16:46 next collapse

The cheap secondary phone is the approach I have gone with for work apps. Powered up only when needed and doesn’t connect to my main home network.

AmbiguousProps@lemmy.today on 30 Oct 17:17 next collapse

Do you have the exploit compatibility mode enabled in the settings? Under Apps > [Your Banking App]

Tinkerer@lemmy.ca on 31 Oct 02:21 collapse

^^have you tried this? I needed to enable for my banking app to work.

artyom@piefed.social on 30 Oct 18:35 next collapse

I think what most of us do is not use a bank that requires using a fucking app to access.

Creat@discuss.tchncs.de on 30 Oct 20:55 collapse

That’s impossible in the EU, they all do by law.

artyom@piefed.social on 30 Oct 21:05 next collapse

Ah good ol’ EU once again contributing to the Apple/Google duopoly.

Creat@discuss.tchncs.de on 30 Oct 21:14 next collapse

They aren’t forced to lock them down, or prescribe any app store afaik. That’s the banks that do. Some lock it down, some not at all. But you’ll need some form of 2 factor “photoTAN” app. Unfortunately, common 2fa codes aren’t used (or allowed), I think this legislation is actually older than them becoming common.

And that’s quite all, they also offer hardware token generators. Not sure if they are required to, but i think so. You do have to pay for them once (20 or 30 bucks maybe?). In reality, this is somewhat impractical for a variety of reasons…

artyom@piefed.social on 01 Nov 18:16 collapse

They aren’t forced to…prescribe any app store afaik.

The app store ain’t the problem, it’s the apps themselves (and most likely Play Integrity shenanigans)

Unfortunately, common 2fa codes aren’t used (or allowed), I think this legislation is actually older than them becoming common.

Those hardware generators you mentioned have been around for at least 30 years. A TOTP app is just software that does the same thing as those hardware generators.

Creat@discuss.tchncs.de on 01 Nov 20:44 collapse

Those hardware generators you mentioned have been around for at least 30 years. A TOTP app is just software that does the same thing as those hardware generators.

I’m aware, but you’re not getting the secret token that you’d need to put into your TOTP app. At least not that I know of. I also haven’t checked in a very long time if there are open source reimplementations of the photoTAN apps. They all got their own flavors, but it’s also just a slight variation on a theme (initialize app with qr-like secret, then scan a similar code as a challenge/response using that secret to generate token). Probably should check that at some point.

themurphy@lemmy.ml on 31 Oct 08:23 collapse

Damn, if you’re not joking, my day is ruined.

Kajika@lemmy.ml on 03 Nov 01:51 collapse

could you be more explicit? not that I do not trust you but I’d like to know more.

Creat@discuss.tchncs.de on 03 Nov 08:00 collapse

See my reply in this thread to artyom, I assume that’s what you’re looking for?

RodgeGrabTheCat@sh.itjust.works on 30 Oct 18:43 next collapse

If my bank locked me out that often due to my phone OS, I’d switch banks. Sorry I can’t help.

shortwavesurfer@lemmy.zip on 30 Oct 19:56 next collapse

You should switch banks to a bank that already has a web application and doesn’t require you to use a mobile application to make purchases.

atmorous@lemmy.world on 31 Oct 20:56 collapse

Double agree

Truscape@lemmy.blahaj.zone on 30 Oct 22:14 next collapse

A patch was already released for this issue, fortunately: grapheneos.org/releases#2025102800

superglue@lemmy.dbzer0.com on 30 Oct 23:11 next collapse

If I’m you I’m changing banks, the problem is likely to return and just get worse.

atmorous@lemmy.world on 31 Oct 20:55 collapse

As alternative suggestion:

Switch Banks (Move to a Local Credit Union or at least a better one)