cross-posted from: https://slrpnk.net/post/15995282

Real unfortunate news for GrapheneOS users as Revolut has decided to ban the use of ‘non-google’ approved OSes. This is currently being posted about and updated by GrahpeneOS over at Bluesky for those who want to follow it more closely.

Edit: had to change the title, originally it said Uber too but I cannot find back to the source of ether that’s true or not…

  • orange@communick.news
    link
    fedilink
    arrow-up
    14
    ·
    15 days ago

    For GrapheneOS, it’s primarily that it’s re-lockable. That’s why other unlockable phones aren’t supported.

    The GrapheneOS install process sets new OS signing keys so you can lock the phone again and get full verified boot. However, most manufacturers haven’t implemented this feature.

    • fuzzzerd@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      15 days ago

      What do you get, app/feature wise for verified boot vs. Play integrity app? Does it increase the amount of apps that work on it?

      • orange@communick.news
        link
        fedilink
        arrow-up
        2
        ·
        11 days ago

        No, Play Integrity intentionally checks if it’s a Google-approved key. Android itself has an API to check verified boot and gives info on the signing key - most devs just want to know verified boot is working.

        I feel Play Integrity has a short life ahead of if competition authorities realise how exactly it works. “Anti-competitive” is the first thing policy-minded folks think when I explain the API to them.

      • lad@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        15 days ago

        I would guess that it allows to detect tampering if you have to give your phone to the security officers and they do or don’t do something with it without you present. I heard of such occurrences on the border, but this happens in other places and countries, too. Not sure if locked bootloader would help, though