Paying without Google: New consortium wants to remove custom ROM hurdles creating an open source alternative to Google Play Integrity
2026-03-16 12:53 UTC
Replies (16)
-
@Corngood@lemmy.ml 2026-03-16 13:42
> Furthermore, a peer review process is planned, through which the consortium members will mutually check and certify their operating systems and smartphone or tablet models. “This is intended to create transparency and replace trust with traceability.” Still doesn't sound very open. I should be able to tell my bank to only trust devices running an OS signed by the grapheneos key, and more importantly I should be able to tell them to trust an OS signed by my key. Edit: I don't mean to shit on this too hard. It might be the best next step.
-
@Nyadia@lemmy.blahaj.zone 2026-03-16 14:34
I see this topic come up often in conversations about degoogled Android and it makes me wonder what if anything I'm missing out on by just using cash/card for payments, cause not once have I been at checkout and thought to myself "man, I wish I could do this with my phone instead" but people talk about this like it's almost a dealbreaker that makes it hard for them to seriously consider switching to Graphene or Lineage or whatever.
-
@beyond@linkage.ds8.zone 2026-03-16 21:47
GrapheneOS is critical of this initiative [here](https://grapheneos.social/@GrapheneOS/116239523775374959) and I think their criticism has merit. This simply moves the gatekeeper from Google to a handful of OEM's who won't let you use anything other than their blessed OS's.
-
@JoeMontayna@lemmy.ml 2026-03-16 18:37
Honestly if there was an alternate and functional phone/OS/app store that early adopters who are a little technical can embrace, it would be the #1 platform in under 5 years. People in the know are chomping at the bit to get away from these big monopolzed platforms, and once it gains steam and polish, people will flock to it.
-
@pineapple@lemmy.ml 2026-03-17 21:15
I think it's cool trying to figure out a way to do this without google, but it still won't solve the fact that credit card payments aren't private and are linked to your identity. As always cash is the way to go. Also if you are still going to have a credit card (I mean fare I have one too) why not just use a physical card rather than paying on your phone?
-
@Armand1@lemmy.world 2026-03-16 15:30
I agree it would be good to have third party integrity checks to not require Google Services etc. as part of the chain. In GrapheneOS, many Google Play integrity check pass, but payments still do not work. You are notified when an app uses the integrity API, but probably only because they have spent a bunch of work sandboxing Play Services. This is what you see when you look at those details:  I guess the obvious problem is that so many apps rely on Google Services, such as for payments, opening the store, checking for integrity etc. On stock android, you can't pick and choose these services separately or use third party ones, unlike using a third party keyboard, for example. Everything is one big proprietary, data guzzling lump.
-
@gandalf_der_12te@discuss.tchncs.de 2026-03-17 11:56
i'm just guessing here but i think that the critical requirements to be able to run banking apps securely on your smartphone are: * lockable/unlockable bootloader * quality control of the operating system to make sure it doesn't contain malware/spyware * internet connection & open-protocol banking network the first two parts are general smartphone/laptop security and operating system integrity, which can only be done through hardware/general software developers. Like i think we need reliable hardware manufacturers but also institutions that check that open source software doesn't contain malware. Like when you run `apt install some-package` who says that some-package doesn't contain malware? The third one is the only part that is actually specific to banking. That's a whole separate topic and has barely anything to do with the first two steps.
-
@GMac@feddit.org 2026-03-18 08:11
I don't think I understand this. I don't actually want to pay with my phone, so thats a non-problem to me, but when I can access my bank with a browser on any pc in the world, why do they need attestation on a mobile? I dont see why the requirement is inconsistent.
-
@penguin@lemmy.pixelpassport.studio 2026-03-16 13:39
Really hope this happens
-
@flango@lemmy.eco.br 2026-03-16 18:20
PIX neles
-
@Retail4068@lemmy.world 2026-03-16 17:52
This works be fantastic and I might actually switch at that point.
-
@ohellidk@sh.itjust.works 2026-03-16 13:39
Would be cool, but i doubt any users in the US can benefit from it since google is so dominant.
-
@John_CalebBradberton@lemmy.world 2026-03-17 01:55
This is a fantastic initiative.
-
@zjti8eit@lemmy.dbzer0.com 2026-03-16 23:40
Why not just use cash? Untraceable, nearly ubiquitous acceptance, are they just too lazy to go to the bank?
-
@Chewy7324@discuss.tchncs.de 2026-03-16 15:23
I keep a single bill in my phone case for emergencies (be it an actual emergency or I just want to eat at some place which only takes cash). If my phone battery runs out I'm stranded anyway, since I can't call anyone or use my public transport ticket.
-
@grue@lemmy.world 2026-03-17 14:52
If this shit is what "ahead" looks like, I'm happy being "behind."