Tell HN: PayPal blocks GrapheneOS
news.ycombinator.com · Read Story HN original
It seems like the PayPal app now refuses to run on GrapheneOS. I don't know if it's only because I have enabled the PayPal card for contacless NFC payments, but when opening the app it crashes with the following exception: com.paypal.oslo.app.rasp.RootDetectionSecurityException: Security policy violation: s=root
Comments
It's one of the toggles changed by the per-app exploit protection compatibility mode. If an app doesn't work, that's the first thing to try. It can then be narrowed down to a specific setting.
The more aggressive exploit protections uncovering a lot of compatibility issues are only enabled for the base OS and specific user installed apps by default. Those can be set to enabled by default for all user installed apps and then people have to deal with the per-app toggles a lot more. This applies to memory tagging, disallowing dynamic code loading via memory/storage and disallowing native debugging (ptrace).
https://wero-wallet.eu
I've read once that there are paid app testing labs which test if an app has root and custom ROM detection and when they don't have that it's a minus point on the report.
UK politics has been quite isolationist, though, so I doubt the banks will see much in interoperating with the rest of Europe.
What do you mean "some banks"? I thought the whole value proposition of Wero was instant bank transfers with SEPA but using phone numbers?
On the payment provider technology side, you're right, but the wallet feature uses phone numbers (and I think email addresses) so you can send each other money without sharing your IBAN (which is slightly longer and probably not in your contacts).
I'd wager that if it doesn't really hurt their bottom line to not support GrapheneOS, they won't really care.
Mistakes happen and ya can't fix what you don't know about. Always report issues.
Also strongly consider just using the website.
That would make a great blog post
Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good guy or a bad guy so it's easier to just ban guns.
They allow you to open PayPal.com on any web browser. Running Windows/macOS/Linux is basically identical to a rooted Android phone (you have local admin rights, you can modify and automate the browser, and can run unsigned code).
Apparently the world can't adult and be responsible for their actions, or people believe in that.
Also I highly doubt that there is any real statistics anywhere about whether this is a real threat or not. I guarantee that nobody did such statistics properly. The only known data is from companies which sell root prevention tools, so totally unreliable. And internally I guarantee, that no banks collect such info.
So no, banks lie about this only because they can sell this to judges as safety feature, when they fuck up, which happens continuously.
If you have a nominally unrooted phone on an old Android version and download malware, it can exploit a kernel bug and give itself root access and do whatever it wants.
Protecting against the first case and not the second is at best security theater.
On a side note, if you want to be extremely specific, the line between the physical and digital threat does not exist anymore. There are two things people need to be afraid of: incompetent friends and competent enemies. Tech giants are already filled to the brim with incompetent friends, which drastically lowers the bar for the competence of their enemies.
I assume the issue is it failing the deeper play integrity check which is about it not being "Google approved."
It's normal to have root (or Administrator) on your devices. After all, they are yours. They don't belong to the device manufacturer. You should have full access to your own devices by default.
Only recently did we somehow normalize the idea that the user should not be the ultimate decider over their own devices.
I propose you buy enough ingredients from the supermarket and make a big batch.
The scientific test is: how far do you get, before your door is kicked in?
If that fails, then science #2: have fun lighting it!!
You almost win both ways. (although I admit I wouldn't fund you even via a trustworthy intermediary say a Kickstarter campaign.
It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The blockades are one piece of a holistic security picture that frustrate the well intentioned users.
As for geo fencing or blocking Tor... HAH! As if that's ever stopped anyone with the will. That is the last concern of anyone with a malicious intent. Sure, it stops irritating kids but no one beyond that.
The simple fact is that cybersecurity was in an abysmal state before the slopification began and it's infinitely worse now. Paypal is no different given that much of their support has been outsourced to slop machines. Punishing the users that know what they are doing while rewarding the ones that don't is the most counter-productive and detrimental crap anyone could come up with.
No. It's the offensive fraud vector coming from unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.
Bullshit! Source:
> The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic
Sounds like someone who wanted to impress the audience with fluffed up claims.
Just because you argue with vigor and intent, it doesn't make you right.
People are offering their opinions, try not being a dick about it.
GrapheneOS is a privacy orientated OS which is great. But if the vectors to achieve privacy are the same as used by bad actors, I'd block it too.
Get over it, don't like it? Use a different product. Or make a better one.
From what we see above it sounds like the change trips their rootkit detection, which they are probably interpreting as a compromised device.
It sounds like you're expecting them to have a perfect security posture that can correctly identify fraud in call cases and only block the real thing. It's more complicated than that and there's typically some type of scoring system involved with numerous triggers that are higher value indicators of potential fraud. If they think the device is compromised, that's probably a high value indicator.
This is just me speculating.
It's not about user security.
They have all the data they need, and they choose not to use it.
I think that's a limitation of the analogy because there is no correspondence with trusted computing. I guess it would be some sort of a magical gun that some other company is endorsing as of limited use during bank robberies? Maybe like some sort of RFID thing that disables the gun when inside a bank?
Anyway it really stretches the analogy to get tied up in technical details (risks missing the forest for the trees type error).
From a Paypal security POV, weather you use "custom Android OS" or an hugely outdated Android phone, you have:
- a similar risk for the "you" want to mess with Paypal case, in both cases the "you" can technically most likely mess with anything including the "virtual secure module" thingy android uses for NFC
- a lower risk for "others" wanting to mess with Paypal through your phone, at least if "custom Android OS" is GrapheneOS or another up-to-date android fork with decent security handling
so as far as I can tell, this inconsistency is very clearly not about PayPal's security.
IMHO it's about two other things:
1. marketing, if PayPal doesn't work on Android they lose customers, GrapheneOS for now has a tool small customer base for them to care. Outdated Android phone do have a large customer base.
2. compliance/politics BS. including potentially involving insurance. Compliance is mostly about checking of tickmarks(1) on outdated Android they can check them off and blame the user, Goodle or "hackers" for the issue. On GraphemeOS they have a harder time checking it of. Add the smaller user base and end up with PayPal doesn't care. Also iff things go wrong with Paypal on GraphemeOS in a public manner you will have all the "crime os" bad news bs, you won't have that if things go wrong with a even more risky highly outdated Android phone.
-----------------------
I got a bit to much off topic below:
(^1): Technically compliance should be about building robust, secure, law compliant systems and "showing" that by being able to pass a compliance tests consisting about a bunch of requirements. Practically there is way to many ways you can be "fully compliant" (on paper) but not secure and "very secure" but not compliant (wrt. security regulations). In the former case this might still come back and bite you iff you get sued or people suing which should get right don't get it because of ad-absurbum reasoning like "they comply with security regulations, hence can't have acted negligent". It's a shit show I don't know how to fix even if I could just magically change laws as compliance rules need technological flexibility, but if you give them that that will be abused to make insecure things pass. And the whole industry around checking that isn't really one who cares about actual security, sometimes outright corrupt (like groups which have the necessary accredited to check your compliance, are strangely more expensive then other groups, and somehow find less issues in average, with some excuse of why that isn't strange ...) :/
---
Lastly similar to how Teams or Slack could easily support FF (^2) but not only don't but outright refuse to try to even work. PayPal likes to act similar and doesn't care about niches. E.g. at least on some Mobile browsers WebAuthn works, but the PayPal website refuses to _even try_ 2FA with WebAuthn on mobile no matter if the APIs are there or not.
(^2): Yes there are some challenges, AFIK especially in certain edge cases most user might never run into. But Jitsi made it work, other smaller apps also made it work. And Jitsi is open source, so they technically can "look up" all the tricks to make it work (algorithmic ticks, not copy-pasting code) or outright just use their system with an appropriate contract (probably would be even cheaper wrt. maintenance cost then building your own system). At Slack/MS Teams scale that behavior is just messed up.
A more apt analogy might be game developers who demand admin rights so they can install a rootkit to detect "cheating".
Similarly, payment processors lose their appeal if they can't prevent people stealing your money, or spending stolen money on your products.