While I would love to see native bank apps happen, I don’t understand how this would be possible.
Most bank apps actively work to detect the absence of Play Integrity, or a rooted phone. Banks don’t want to promote the use of websites, which already had TOTP or equivalent several years ago. Banks want an approver app which implements evidence it can’t be tampered with. This is their view on security.
A Jolla phone, where by definition we have root, we can see and tamper with the Android app data, is not something I expect promoting will have success. To the contrary, it is only allowed by chance by some apps because banks haven’t yet figured we exist.
What we need is to do at this stage is not work with the banks; it is to lobby the EC or take parts of the lobby experts group that define policies for the EC.
Claiming SFOS is a “European alternative” won’t be sufficient. SFOS will need to implement the same level of security that Android currently has. A locked down version of SFOS might do it for the EC and for the banks, but is clearly not what SFOS users want.
I forum users won’t like to read this, but I fear this is the truth.
In Europe, the PSD2 Directive requires banks to provide account access APIs, not only for data retrieval (AIS) but also for initiating payments (PIS).
This means that it is technically possible to link a bank account to a third-party app such as Wero and make account-to-account payments via SEPA credit transfers without relying on proprietary banking apps. Wero can therefore use these APIs to offer its direct payment service, provided that banks fully comply with these obligations and do not impose any additional restrictions (such as requiring validation via their own app).
I understood from earlier posts that Android apps (and realistically this is what most banks or payment providers could release to SFOS the quickest) cannot access the NFC chip for payments?
An additional NFC chip is no more accessible.
Actually, quite the opposite - as the built in one likely runs on Android drivers (that could be re-routed like what we have fro Bluetooth now), but one in a TOH likely would not.
OK I’m not an engineer, so not familiar with the technical intricacies. However, why would a Wero enabled NFC in a TOH not be able to circumvent any limitations of the built in NFC? If it were possible with the built in one, all the better…
You are asking the question backwards - why would a TOH NFC chip be any less limited than the existing one?
If the built-in one, running on Android drivers is “problematic” (i don’t think it is any worse than Bluetooth, but whatever) - why would a TOH one (a uniquely SFOS concept!) be any better? And especially any more Android-available?
Welp. I sent a message to Vipps customer support. I already know what their reply will be, if any, but every (potential) user sending an e-mail is a little bit of extra pressure.
Yeah, considering I already have Swish, and Vipps isn’t very large in Sweden, I don’t really need it, but Vipps is connected to Wero (If I understand correctly), and Swish is not (yet), so Vipps would be useful when making transfers to my family (which is spread out in Europe).
I posted in the TOH thread about a watch strap sold by Polar that contains an NFC chip which connects to an app/platform called Fidesmo which you can use for contactless payments (and eId services). I thought it was a good idea but lots of people started shouting so I left the discussion - however I think it could be a good solution for those interested and their app is so simple they may consider porting it to SFOS.
I think European banks are front of observing options for 2 big tech duopoly. At least I hope and believe in it. There will be more and more mobile OS’s and they cannot deny for serving customers. Of course more volume is needed but it will come
We need to ensure that both the app and the device it runs on are secure, have not been modified, and are protected against misuse. Unfortunately, this is not something we can make optional.
[…]
We are exploring possible alternatives that could provide the same level of security without this dependency, but this is technically and regulatorily complex
is such a lie, as if they pretended we’re stupid and don’t know about using banking services from a browser. Like… you can run whatever OS on any device and as long as it can run a browser that supports modern web, typically a Chrome or Firefox derivative but not necessarily, you will be able to use all your banking services through it. I just logged in to my bank whose Android apps don’t run with microG through Falkon on CachyOS, from a laptop with disabled secure boot, and I don’t even need the app for 2FA because it lets you do it via SMS. I’m 100% certain I could do it from my Raspberry Pi, and I’m also certain they don’t have a team constantly testing these software and device combinations, or any for that matter beyond browser features, yet everything just works. Are they saying banking through a browser is not secure and not supported? I’m certain they don’t, and I also suspect their app is nothing more than a stripped down browser like so many are nowadays that hardly does anything beyond the connection and of course logging whatever it can from your phone that it has no business logging.
Google Play Integrity should be investigated by the EC as an anti-competitive technology that serves to protect the Play Store’s near monopoly as well as Google Android lock-in.