Device attestation needs to be made illegal at the EU level. Or perhaps better, needs to be mandated that users can supply their own secure element. But I understand that part is completely out of your hands.
What is TRID, exactly? A native variant of the wallet would e.g. allow online/iDeal/Wero payments and not tap to pay if no “secure element” is found?
There’s a lot of anticipation for Wero. But Walt is going to market on standard Visa and Mastercard rails. Wero has a lot of work to do before terminals accept tap-to-pay on Wero rails. So I will not be depending on their success (although very hopeful and will adopt, if they do). This means that Walt must pass EMVCo standards and therefore must enforce device attestation. So SFOS will have to provide something here for Walt to use, if it wants tap-to-pay to work.
Unfortunate but understandable. Hopefully the EU legislates device attestation BS out of existence before the US government decides to yolo sanction a bunch of random Android devices and break mobile payments for half of Europe.
It probably could. It’s still, however, perpetuating a concept that is fundamentally user/consumer-hostile by design. It’s “less bad,” but it keeps the control over your device in the hands of companies, instead of you. My guess is that this is the path that Jolla, Volla (especially Volla since they are behind this effort) will pursue.
It would be perfect if Unified Attestation gave control to the user for attesting. Then it would not be problematic.
I don’t understand enough to have that tough opinion on the matter, but most users probably aren’t capable to give attestation that is truly safe? For now I would be very happy with less bad and importantly European and OSS
Well, you must understand that I am a Free Software Extremist passionate about user rights. So anything less than full user control of devices and mandating that companies are not allowed to impede those rights, or block people off from important facets of society because “security,” is not gonna fly with me .
But I’m also not an idiot. I am well aware of what remote attestation does and why it exists, and why companies use it for “security.” Would most people be able to manage their own attestation? Probably not. And they don’t need to. Let them use Play Integrity or whatever. The key is the choice must be available, not hindered in any fashion, and not downgrade participation in society. Make it a USB stick from the bank you plug into the phone, for all I care. I care less about what goes on in the magical “security” black box, than I care about being able to choose the black box and not have it siphon my data to some random corporation or deny me access to supported features because I chose the wrong black box.
Less bad is a step towards good. We shouldn’t let perfect be the enemy of good. But at the same time, we shouldn’t stop the march towards good.
I think such a TOH would need a display and a PIN-pad, so that the TOH can show what’s happening (payment details) and get a PIN to unlock the secure element in a way that no software on the phone can tamper with.
I.e. untrusted software on the phone, like the Web Browser, could send a request for signing. The display on TOH ensures that you know what you are signing and the PIN will not be seen by any part of the phone, so impossible to log.
edit: The way I see this, is that you don’t need to get anyone’s blessing for the entire phone while still making sure that no evil software/hardware can snoop or interfere with the signing process. Of course, the secure element could be used like in a PC, where firmware and OS send measurements to the TPM and the TPM unlocks cryptographic keys only if measurements match.
The Secure Element establishes an encrypted channel for the PIN. Implementing an SE would facilitate the secure storage of data for banking applications, while concurrently providing hardware-backed security for the device’s encryption. Relying on a 6-digit PIN for SailfishOS encryption is cryptographically inadequate; generating encryption keys directly within the SE would yield significantly greater robustness.
In some way they are considering. This photo I took from Jolla’s road map presentation during the “Day1”.
The Other Half was presented as the next step in the road map for 2027.
“Going out?” as an example on the picture fits quite well actualle to your proposed idea. Thank you for casting new ideas, always a good thing.
you need to have a separate TOH for payments, would this be delivered with every phone - or if needed to buy separately might cause misunderstandings and frustrations - not everybody will be happy to pay for two NFC chips
NFC chips would most likely “collide” with each others and want to occupy the same physical space in the phone
if the damn attestation has come here to stay - can a removable piece of hardware be attested with upcoming Unified Attestation? (we cannot know now)
how this will be presented in the settings, because many will enable device’s NFC in settings and can’t understand why tapping doesnt work (minor problem)
If you are using another TOH on daily basis and also want to use tap-to-pay, then woul would need to carry extra TOH everywhere with you, not optimal I’d say
Just to name a few challenges, I’m sure my imagination didn’t even get all of them by this morning hour.
Of course challenges are made to overcome. However, is this really an optimal solution for Sailfish?
Not everyone even wants to make payments with a phone. NFC functionality is way down on my list compared to the myriad of other issues, so I can hardly understand why it is such a big deal.
But the fact that it is such a dynamic topic and has been requested so widely shows that there is immense demand.
It just shows what a diverse group SFOS users are. I just would not want to pay for something I would never use.
To the last point. I hope you can make stackable other halves so the attestation other half can be connected to the phone along with the other(s) you need.
I don’t think the attestation other half needs to be the last other half so better make it a middle other half.
I have never used payment with my phone. Mostly because I didn’t want my payments and all the tickets etc going through Google. But I have always been a little bit jealous for my wife who have all the things always with her. So if we get native Walt implementation, with the tap-to-pay, I sure will adapt to that and start using it Will I still carry my wallet and default to that most of the time, probably, but I surely will enjoy having that possibility with me all the time
Not really, I could probably fit one card there. How about the rest 20 cards? Or the tickets for theatre etc? Flight tickets? Would be quite thick TOH IMO best low tech solution is to just carry the wallet xD But would definitely like to have all other functions that those wallets offer
You’re describing quite a horror scenario for me, having all your cards/tickets/whatnot in one wallet on a phone that can crash or run out of battery
The second one would be having to use a phone to do banking.
But, again, I don’t want to dismiss that this is super important for many people. I just wanted to show that this is far from universal.
I think it depends on a country and style of living. 5 years ago I had to carry a wallet in Germany while in Poland it was not needed. Now in 2026 I only carry a phone with me too. I can ID with it (somehow people accept a Polish national ID as-an-app), pay with it and start paid parking session too.
Everything else the cops can check themselves if they need it.