logoalt Hacker News

Arifcodesyesterday at 10:19 PM1 replyview on HN

The banking app compatibility issue gets framed wrong. The real problem is not "does Google Play work" but "does Play Integrity API work" - that is a device attestation mechanism, not a Google dependency per se.

Building fintech apps, we integrated Play Integrity as a fraud signal. Sandboxed Play Services on GrapheneOS actually passes most of these checks now, and false positive rates for legitimate users are negligible. The hardliners who refuse sandboxed Play can still use most banking apps that fall back to basic root detection rather than hardware attestation.

The real gap is NFC payments - Google Pay needs privileged hardware access that sandboxed apps cannot get. But that is one use case, not a reason to skip GrapheneOS entirely. Curve works fine in EU.


Replies

sfRattanyesterday at 10:23 PM

If you're willing to invest in a smartwatch principally as a secure payment appliance, tap-to-pay with Garmin Pay works when configured on Graphene OS, and most Garmin Smartwatches will happily stay in airplane mode for months once configured.

AFAICT, Garmin Pay works like Apple Pay, meaning (unlike Google Pay) no network connection is required.