cross-posted from: https://slrpnk.net/post/15995282

Real unfortunate news for GrapheneOS users as Revolut has decided to ban the use of ‘non-google’ approved OSes. This is currently being posted about and updated by GrahpeneOS over at Bluesky for those who want to follow it more closely.

Edit: had to change the title, originally it said Uber too but I cannot find back to the source of ether that’s true or not…

  • BagOfHeavyStones@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 days ago

    Maybe it’s worth keeping a budget mobile phone at home with Rustdesk host running on it? When you have a need for an app that must run on a genuine Android, you just remote into that phone. Since the phone never leaves home, there’s less to track.

    • 4lan@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      5 months ago

      It’s crazy how they can just do illegal things because they have so much money…

      Do I own my phone or not??

        • theroff@aussie.zone
          link
          fedilink
          arrow-up
          1
          ·
          4 months ago

          Graphene shills have been banging on this point for donkey’s ages. Reality is that many people use phones that are out of OEM support and many OEM ROMs are bundled with questionable software (Oppo, Samsung etc.) There are some decent criticisms to be made about LineageOS, but others to be made about Grapheme, like its Google-suggestive configurations, which is quite bad for security and privacy. Graphene says this is all optional and not part of the OS, but doesn’t include any equivalent F-Droid installer.

  • HiddenLayer555@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    5 months ago

    This makes me want to use GrapheneOS more. If the dataminers don’t want you to use it then it must be doing something right.

      • Realitätsverlust@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        It’s only officially supported on google phones because sadly those are the only ones that are not modified to fuck which makes installing and supporting other OS’es way too much work.

        Giving google money once for a device is not a problem from a privacy or security standpoint.

        • Samsy@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          5 months ago

          That’s correct, but not the reason grapheneOS chooses only pixel phones. It’s the level of hardware security features.

        • 50MYT@aussie.zone
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          5 months ago

          Your options are:

          Apple phone

          Bloated android phone like Samsung etc.

          Chinese android phone (xiami etc)

          Google phone with Android

          Google phone with graphene. This still looks like the best of those options.

          Or no phone? I guess people are hardcore enough that will be the option.

          Edit: I stand corrected.

            • SeekPie@lemm.ee
              link
              fedilink
              arrow-up
              1
              ·
              5 months ago

              I don’t think LOS has any privacy/security improvements over the stock android?

              (IIRC) it’s even worse than stock because you can’t lock the bootloader after installation.

              Though if your phone isn’t getting official updates, it’s probably safer with LOS.

                • SeekPie@lemm.ee
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  edit-2
                  5 months ago

                  Yeah, I myself am using CalyxOS, because DivestOS doesn’t support the Fairphone 5 unfortunately. CalyxOS also has relocking.

                • Andromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  5 months ago

                  Not with GrapheneOS, since you can entirely disable the USB controller from the settings on a driver level, making it impossible to connect the phone to a forensic data extraction device. GrapheneOS also has a convenient auto-reboot feature, which (together with their patches to the Linux kernel and Fastboot recovery OS to include memory zeroing) erases the encryption keys from memory, putting the device in BFU state and requiring the PIN/password to unlock. This is additionally secured by the Titan M2 secure element, which makes use of the Weaver API and drastically throttles brute-force unlock attempts. https://grapheneos.org/faq#encryption

            • Andromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              5 months ago

              All of these are insecure as hell. Linux phones especially https://madaidans-insecurities.github.io/linux-phones.html

              Fairphone also really fucked up: They signed their own OS with the publicly available (!) AOSP test signing keys. These guys really don’t know that they’re doing, and I would trust their hardware or software whatsoever. And no, installing a custom ROM doesn’t solve this. Considering how bad their security practices are, we genuinely have to assume that there are security issues with the device firmware as well.

              /e/OS is based on the already insecure LineageOS, and it weakens the security further, so it’s not a good option either.

              None of the options you mentioned can be compared to GrapheneOS. It’s currently the best option if you value your privacy and security. You don’t have to give Google money either, since you can just buy a used device, which is also cheaper and more environmentally friendly. Google also makes repairing their devices pretty easy for consumers and even works with iFixit. Here’s a Mastodon post I recently saw about that: https://social.linux.pizza/@midtsveen/113630773097519792

  • Roopappy@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    5 months ago

    Why would anyone load an app from McDonalds? You want to give them elevated access to your most personal data for a few dollars of coupons?

    What are they taking from you that’s worth more than the discounts they are giving you? Because they are definitely making a profit, or they wouldn’t be doing it.

    • Sips'@slrpnk.netOP
      link
      fedilink
      arrow-up
      1
      ·
      5 months ago

      We are definitely in the era where people think discounts before user privacy. I bet most of people downloading the Mcdonald app do it exactly because of cheeper prices and easy of access.

      • dharmik@linuxusers.in
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        5 months ago

        just had medium fries and coke. many people i know, including myself, use the mcd app because of the discounts it offers when ordering through the app. however, i am under the impression that since i use an ios device and have the option to decline being tracked by the app—which i very eagerly press “no” to—i am on the safe side. am i?

        • pound_heap@lemm.ee
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          5 months ago

          Apple does extensive audit of mobile apps, including limitations of tracking. So the app cannot spy on something you are not letting it to know. But you are giving it a bunch of info voluntarily.

          I’d say using that app on iOS is similar to making a food delivery order using a loyalty member ID. Basically, you are letting the company (McDonald’s) know who you are, what is your phone number, where do you live, and what do you like to eat. And if they wish to, they could use all that to purchase your profile from a data brocker. Or they can sell that info for a few cents to make up on that discount.

  • AstralPath@lemmy.ca
    link
    fedilink
    arrow-up
    2
    ·
    5 months ago

    Fuck both of these companies. Never used McDicks app in the first place. Spyware bullshit.

  • BigDanishGuy@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    5 months ago

    OK McDonald’s, I will not use your most cost effective ordering method. I guess I will just have to order my 10 individually custom cheeseburgers at the counter instead. I might have to have e the order read back, and change my mind about a few burgers.

    • Railcar8095@lemm.ee
      link
      fedilink
      arrow-up
      1
      ·
      5 months ago

      As a former employee… That does nothing. Crazies that spend 15 min to order some fries were common.

      If you go at rush hour it can be annoying to the employee and other customers, but at the end of the day nobody will remember and you would have spent 20 min and 10 dollars (which is 9 dollars material profit for MacDonald).

      Just. Don’t. Go. To. Macdonald’s.

    • bountygiver [any]@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 months ago

      that’s just screwing with the workers though, and the workers sure as hell is not going to get paid extra for your custom order

      • Woht24@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        5 months ago

        This viewpoint is so stupid.

        The cashier is paid to take orders, whether they take 1 long obnoxious order or 3 small orders, it’s the same shit.

        People are so swept up in ‘kindness and support’ (internet circlejerking), they think that the fact you inconvenienced some 17 year old, representing a massive corporation, as a fuck you to the company that employs them, you’ve committed some moral sin against your fellow man.

        • GHiLA@sh.itjust.works
          link
          fedilink
          arrow-up
          0
          ·
          5 months ago

          the cashier

          Who is also the manager, making drinks, doing the fries because that bitch called in sick…

        • neomachino@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          0
          ·
          5 months ago

          That worker doesn’t want to be there, that’s likely one of 3 jobs they need to barely scrape by.

          You holding them up from doing other tasks they need to do to keep a job that barely feeds them is doing nothing but making their day a little harder. It affects the company 0%. The company is faceless and doesn’t care how much you abuse the worker bees as long as they get your money.

          I don’t know what the answer is aside from not patronizing the company at all, but I know that’s not it.

          • Lag@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            5 months ago

            If the company is always too busy, they will need to hire more workers or the existing ones will leave.

    • Mike@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      5 months ago

      Unfortunately, this is probably because of the apps started using the Play Integrity API, which is a hardware-based attestation and can only be faked in two ways that GrapheneOS isn’t interested in:

      • you can fake an older device that didn’t support hardware attestation yet, or had a broken implementation
      • or you can try getting leaked vendor keys and emulate the crypto with those until they get revoked
  • kata_ton_daimona@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 months ago

    Small OT: In the article it’s mentioned also the app “IO” (italian for the english word “I”). There are also other important italian apps not working without play services. The serious thing is that that apps are almost mandatory to do the ordinary public administration bureaucracy. We can say that the italian state forces its citizens to use a smartphone with Google Play Services installed. This is no sense.

  • zako@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    5 months ago

    the problem here is not the banks or apps, the problem is Google Play Integrity API, which is supposed to enforce to run apps in secured phones and it is used to ban secured ROMs such as GrapheneOS and it allows to run apps on outdated phones without security patches.

    • kevincox@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      5 months ago

      which is supposed to enforce to run apps in secured phones

      The point of the Google Play Integrity API is to ensure that the user is not in control of their phone, but that one of a small number of megacorps are in control.

      Can the user pull their data out of apps? Not acceptable. Can the user access the app file itself? Not acceptable. Can the user modify apps? Not acceptable.

      Basically it ensures that the user has no control over their own computing.

      • umami_wasabi@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        5 months ago

        It’s simply the “secure” isn’t meant for users but the cooperations. Make it “secure” to their business.

    • jagged_circle@feddit.nl
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      5 months ago

      Oh, the banks and regulators are to blame. Especially in Europe.

      Find me a PSD2 bank bank that doesn’t require a phone number

  • Anivia@feddit.org
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    Time to switch away from Auth I guess. Not even using GrapheneOS cause I have a Samsung phone, but this is not acceptable

  • AlecSadler@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    This surprises me because McDonald’s app is hands down the worst app I’ve ever encountered in the history of all Android apps.

    It’s is sluggish, ignores touches/taps half the time, doesn’t adhere to Android best practices for flow, crashes a lot, errors a lot, etc.

    But OK McDonald’s. Fuck off.

    • ililiililiililiilili@lemm.ee
      link
      fedilink
      arrow-up
      1
      ·
      5 months ago

      I can add that it requires location permission (even when you attempt to search manually with zip or city). What a shitty, dystopian timeline we are experiencing when we’re mandated to run privacy invasive spyware, just to get a fucking discount on nugs.