This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!
Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors).
Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good guy or a bad guy so it's easier to just ban guns.
Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal with is so extreme.
It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The blockades are one piece of a holistic security picture that frustrate the well intentioned users.
Yet another weak point. My question stands: A user with an OS from 2019 is "secure" and dozens of unpatched CVEs but a literally-last-night-patch OS is not? That's the "stuff they have to deal with"? I was lucky and did not make the mistake of joining a payment provider in 2020 or 2021 (I can't remember). The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic(big part of the reason I did the "I accepted another offer already, sorry" card).
As for geo fencing or blocking Tor... HAH! As if that's ever stopped anyone with the will. That is the last concern of anyone with a malicious intent. Sure, it stops irritating kids but no one beyond that.
The simple fact is that cybersecurity was in an abysmal state before the slopification began and it's infinitely worse now. Paypal is no different given that much of their support has been outsourced to slop machines. Punishing the users that know what they are doing while rewarding the ones that don't is the most counter-productive and detrimental crap anyone could come up with.
No. It's the offensive fraud vector coming from unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.
> unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.
Bullshit! Source:
> The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic
Sounds like someone who wanted to impress the audience with fluffed up claims.
That's your argument? Mate, you can make explosives out of stuff you can buy in literally any supermarket and no one bats an eyelash. You don't have to legally be adult to buy any of the things you'd need and I say that as someone who only struggled with chemistry in school, that's now low the bar is. What's the solution then? Ban sea salt? If someone is using Graphene, the chances of them getting hacked are astronomically lower than any Chinese spyware-infested phone.
The cherry on top is that their web site invariably still works so the refusal to work via app is an intentional manipulation tactic to harvest more consumer data for sale.
Sadly, their website now appears to require an app in order to sign in.
Even before that it would often block me with text along the lines of "We don't know who you are, call our support number."
The analogy was not about new vs old customers being allowed to have guns.
I think that's a limitation of the analogy because there is no correspondence with trusted computing. I guess it would be some sort of a magical gun that some other company is endorsing as of limited use during bank robberies? Maybe like some sort of RFID thing that disables the gun when inside a bank?
Anyway it really stretches the analogy to get tied up in technical details (risks missing the forest for the trees type error).
If you run a rooted phone and download malware, that malware can gain root and do payments on your behalf.
Then PayPal has to deal with you revoking payments etc., they don't want to so they forbid you from using PayPal on a rooted phone.
Malwares can possibly do that even on non rooted phones if a privilege escalation attack is possible. And just yesterday, there was an article here about exactly one of those.
Also I highly doubt that there is any real statistics anywhere about whether this is a real threat or not. I guarantee that nobody did such statistics properly. The only known data is from companies which sell root prevention tools, so totally unreliable. And internally I guarantee, that no banks collect such info.
So no, banks lie about this only because they can sell this to judges as safety feature, when they fuck up, which happens continuously.
Which they would be anyway since PayPal isn’t a bank and isn’t FDIC insured.
They allow you to open PayPal.com on any web browser. Running Windows/macOS/Linux is basically identical to a rooted Android phone (you have local admin rights, you can modify and automate the browser, and can run unsigned code).
For that argument to hold, they'd also have to blacklist any phone not running the newest, most up to date Android version, because all older versions presumably have known exploits. So that basically leaves Pixel phones.
One thing that I'm actually excited about regarding AI is that the pointless policy checkboxes that have never been effective in adding any actual security are even less so effective now that everyone can wield their very own security researcher.
It's probably just a generic error message for failing that Google Play Protect thingamajigger that attests provenance of the vendor OS from boot. Will be interesting to see whether the Motorola phones have this endorsement when they ship. Most devices would probably fail because they are rooted rather than because they are GrapheneOS. I wouldn't put it past a scammer talking grandma into rooting their phone.
From a Paypal security POV, weather you use "custom Android OS" or an hugely outdated Android phone, you have:
- a similar risk for the "you" want to mess with Paypal case, in both cases the "you" can technically most likely mess with anything including the "virtual secure module" thingy android uses for NFC
- a lower risk for "others" wanting to mess with Paypal through your phone, at least if "custom Android OS" is GrapheneOS or another up-to-date android fork with decent security handling
so as far as I can tell, this inconsistency is very clearly not about PayPal's security.
IMHO it's about two other things:
1. marketing, if PayPal doesn't work on Android they lose customers, GrapheneOS for now has a tool small customer base for them to care. Outdated Android phone do have a large customer base.
2. compliance/politics BS. including potentially involving insurance. Compliance is mostly about checking of tickmarks(1) on outdated Android they can check them off and blame the user, Goodle or "hackers" for the issue. On GraphemeOS they have a harder time checking it of. Add the smaller user base and end up with PayPal doesn't care. Also iff things go wrong with Paypal on GraphemeOS in a public manner you will have all the "crime os" bad news bs, you won't have that if things go wrong with a even more risky highly outdated Android phone.
-----------------------
I got a bit to much off topic below:
(^1): Technically compliance should be about building robust, secure, law compliant systems and "showing" that by being able to pass a compliance tests consisting about a bunch of requirements. Practically there is way to many ways you can be "fully compliant" (on paper) but not secure and "very secure" but not compliant (wrt. security regulations). In the former case this might still come back and bite you iff you get sued or people suing which should get right don't get it because of ad-absurbum reasoning like "they comply with security regulations, hence can't have acted negligent". It's a shit show I don't know how to fix even if I could just magically change laws as compliance rules need technological flexibility, but if you give them that that will be abused to make insecure things pass. And the whole industry around checking that isn't really one who cares about actual security, sometimes outright corrupt (like groups which have the necessary accredited to check your compliance, are strangely more expensive then other groups, and somehow find less issues in average, with some excuse of why that isn't strange ...) :/
---
Lastly similar to how Teams or Slack could easily support FF (^2) but not only don't but outright refuse to try to even work. PayPal likes to act similar and doesn't care about niches. E.g. at least on some Mobile browsers WebAuthn works, but the PayPal website refuses to _even try_ 2FA with WebAuthn on mobile no matter if the APIs are there or not.
(^2): Yes there are some challenges, AFIK especially in certain edge cases most user might never run into. But Jitsi made it work, other smaller apps also made it work. And Jitsi is open source, so they technically can "look up" all the tricks to make it work (algorithmic ticks, not copy-pasting code) or outright just use their system with an appropriate contract (probably would be even cheaper wrt. maintenance cost then building your own system). At Slack/MS Teams scale that behavior is just messed up.
Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.
As several others have already said here, GrapheneOS is not necessarily rooted. So that's a lie.
Also, I've seen such audits internally, and they don't care about security at all. They care about the theatrics of security waaaaay more.
For example, I was at Santander in 2024, during its huge data breach. Here is the list of actions which are supposed to prevent the same kind of attacks again in the future:
-
Yeah, it's an empty list.
But of course, they made our life more difficult. In the end, I literally had more permission than before, because they were even sloppier than before. But of course, I had to change my password more frequently, and I had to type it about 5x more.
I see this happen from time to time. Lately, almost all of the apps work fine on GrapheneOS. The best strategy is to keep writing the business once every two or so weeks that you can’t log in to and use the app. Don’t go too technical at first, because most of the time, the moment they hear things like “rooted” or “unofficial,” they just say your phone is the issue. To date, I was able to convince, or at least contribute to, making three apps work on GOS.
I had the same experience. Asked in an email why an important government app won't work on GrapheneOS, first without any technical details. Got the response that it's "because security". I sent some technical details and argued that they're denying service to their most security-conscious users. 3 months later the app started to work!
I think in this case it's also them just introducing a new check that either GrapheneOS will need to work around or Paypal needs to refine. I can reproduce the issue, but it doesn't seem like it did a failed Play Integrity check at that point.
Great job, man. We have to make ourselves get heard. It's a social problem after all. Technical workarounds are great and sometimes the only practical short term option, but we have to fix the social issue at the root.
Why would anyone still use PayPal after so many cases of accounts being banned and funds being frozen for no reason, and all the other terrible stuff they've done?
Easy to say when you are in a country where you have a lot of options.
There's some countries with very bad financial sector where your option is PayPal or Western Union as the local banks don't know how to do international transfers, Remitly doesn't support all countries and Wise also doesn't work. PayPal works, even if they charge fees.
We were having a lot of problems with that in Honduras, staff in the branch did not know how to do that, fees are extremely high and sometimes the bank system is just offline and you get sent home. There's a reason all these alternatives like Western Union etc. exist for this remittance use case.
It was a big reality check for me usually living in Germany and having access to a lot of banks and modern neo-banks.
My local banks know how to international transfers but I have to go into a bank office and fill out a paper form. Receiving international transfers they call and ask if I wish to accept it, if I can't answer the phone right then the transfer gets delayed. If the sender does not include my middle name, I have to come into the office and sign an affidavit that this person with this different name is also me. Each time.
I've had to use it when my bank's purchase limits did not allow for card (virtual or real), but the same purchase was allowed when going through PayPal. It was annoying AF, but was much faster than contacting my bank and getting permission to spend my money.
As a German that never has encountered PayPal in the wild and doesn't have a Paypal account either, your narration requires elaboration to be believable.
I wish. The small inconvenience of putting in an IBAN and a matching name instead of just an email address is already enough for many people to default to paypal. Just happened to me again yesterday, the guy preferred to bring cash next time we see each other instead of just receiving my info via text.
Sepa is how my kid's daycare debits me each month, or how I transfer money to other accounts (most bills are direct-debit, but sometimes I get a one-off invoice and I have to transfer the money myself).
But for the small person-to-person type thing, paypal is the defacto here (sadly).
SEPA uses your IBAN (account number), and one can also enter this account number for payment, implicitly allowing the store to withdraw money from it...
You must be referring to SEPA Direct Debit, which would be very risky to use to siphon funds. There's an 8 week no-questions-asked refund policy, 13 months for unauthorized transactions, if the payment fails (eg due to insufficient balance), the payee is charged a non-refundable cancelation fee. [0] And that's all separate from any legal troubles for fraudulent charges. I don't know why Germans use PayPal over SEPA, but I'd be surprised if SEPA Direct Debit was the reason.
IBANs aren't secret, they have the same level of confidentiality as your address or birth date.
One-off SEPA Direct Debit is virtually unheard of, recurring payments are a bit more common but usually involve a €0,01 payment to prove ownership of the account. The transactions are also trivial to undo, and can only be initiated by companies.
So no, "IBAN fraud" isn't a thing in practice. You can safely share your IBAN with your friends for instant free wire transfers.
Well yes. But just in case this wasn't clear: this is a crime, and you will get your money back in most cases. It's on the merchant to ensure a Direct Debit Mandate is actually valid.
I do not think it is possible to withdraw money having only an IBAN.
It would need a SEPA direct debit mandate for my bank to accept the transfer request.
because global-ish exchange of goods and services for money is a deliberately convoluted experience that only a handful of well-connected entities are allowed to facilitate, which enables each and every one of them to put "we reserve the right to fuck you in the ass for any or no reason" in their ToS.
A lot of NFC related tech is deeply rooted in having "trusted (aka large company)", "attested (aka you can't easily lie)", secure module functionality.
What should have happened is to just not enable the contactless payment functionality for given app, even if the user enabled it in general. And not crash.
Also as others have pointed out, this might be an accidental mishap not an intended outcome.
But it's not like PayPal is known to care about small user-base edge cases (quite the opposite). Which I guess is the actual root problem.
I had to update exploit protection after their latest update — I think it was enabling dynamic code loading via both memory and storage that did the trick.
Edit: checked now, I have also disabled secure app spawning.
Interesting, just inferring from that it sounds like GrapheneOS's actual-security features might have been tripping up PayPal's root-detection "security" features.
(Rather than something fundamentally incompatible, like them using Play Integrity)
There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :)
IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.
The very fact they've managed to convince anyone that checking what OS I decide to run on the devices I own to check my own banking is any of their concern is a problem in and of itself.
"Ironic" means saying the opposite of what you mean in order to be funny or sarcastic. So that would mean you think I was both polite and not an idiot.
You're a banking app. Why do you need to check my phone or my os? The security is not in what phone I use, but in how sane your 2-factor auth is and if even exists.
It is a useful tool, but is largely irrelevant to this issue.
To the end user, this isn't really much of a difference. Whether the cause is malice or simply not choosing to use the smallest effective brush, they are still taking an action that is preventing legitimate users from accessing the service.
They have blocked rooted phones based on the error provided. Nothing to do with verification. They treat rooted phones to a level they don't with phones without critical security updates. That's the tension. Non-rooted phones aren't necessarily unsafer.
I have never been a crypto currency advocate, but if the banking utility of a mobile phone is going to be dictated by the operating systems that finance apps whitelist, I might want open rails that work with my open phone
Dumb idea, but I wonder if the underlying os can see who is asking questions like do you have root, And if an app has no need to know, it just plays dumb and responds...of course not. It's a bit of a chicken and egg problem, in that if you don't know what apps need to know if you have root, or not, then you can't determine that at the OS level...maybe an option for the user (popup) to tell the program, tell them we are rooted or not? (Or a settings page you can determine what apps can know root or not)
That's exactly how modern Android rooting tools work. You select which apps you want to have root, in a manager app. No other app should be able to notice.
But GrapheneOS isn't root, that's just PayPal's thing being broken.
How does their web site do device attestation? The argument that apps have to be locked behind a validation mechanism controlled by Google to be secure is BS when a cookie is sufficient.
The best approach to combat this is to cause as much headache as possible: bombard them with 1-star reviews, contact news sites, post this on social media sites snd contact Paypal's support.
I'm on Debian Testing sometimes on amd64 and sometimes on m1. Paypal also doesn't like me. Than I have two options: I use a Windows VM to do the payment or I use another payment method. Most of the time I use the other payment method.
Wero is not a PayPal alternative. It doesn't even have buyer's protection and every bank must manually implement it which immediately makes it a failure. Some banks also connect it to your phone number so you can't link Wero to two different bank accounts with the same number when you have 2 bank accounts. Very messy.
You need to use your bank's app for Wero, and many EU banks' apps refuse to run on GrapheneOS for the same reasons as PayPal. This is sadly not a clear win for Wero.
wait for it... I can see a future were every wallet, payment etc. app will block devices which are on custom ROMs and do not pass strong hardware integrity with blessing from Google.
I've read once that there are paid app testing labs which test if an app has root and custom ROM detection and when they don't have that it's a minus point on the report.
I remember when I had to boot up an old windows machine because TurboTax refused to run on a Linux (might have been something related to flash as well... been too long to recall), then I just ran Windows in a VM, then extensions allowed me to do User-Agent spoofing (honestly should have thought of this sooner), and now they don't seem to care at all. I did my taxes on OpenBSD last year.
Confirmed on my phone too. I left a 1-star review on the play store saying it crashes on every launch, uninstalled and will use the website from now on. (Luckily, I dont use contactless payments, ai just send and receive money from friends from time to time)
I'm starting to see these restrictions as a deterrent for using the products in question. My GOS handset is slowly fizzling away into a dumbphone with Firefox, organic maps and k9. And you know what, I am starting like it.
This wouldn't be that bad if they had a functional website you could use instead, but their website doesn't even let you do things like pick your monthly rewards category or configure auto-replenish for your debit card.
This is what really makes me question if I want to continue to use GOS, already some UK banks apps (which are app only) don't want to run. I'm considering switching back to stock as I can't be bothered to try to find hacks and workarounds for daily necessities.
Does this really have anything to do with GOS and more to do with apps not wanting to run on rooted phones? A rooted phone is more likely to be tampered with and have its sandbox rules relaxed. There's a big business of security companies selling tools to harden mobile apps and the bare minimum is not running on rooted phones.
A normal GrapheneOS installation uses Android Verified Boot with a locked bootloader, and does not give the user root access. Google's Play Integrity cannot be used to verify the integrity of the OS (as GrapheneOS is not approved by Google), but equivalent verification can be done using standard Android APIs and GrapheneOS's public keys.
I also ran into the eBay application being blocked just recently. Other than that I've had no issues, but I imagine this is going to become more and more common as time goes on.
I've not been able to use Paypal on Firefox+Linux, on and off for years now. The pop-up appears where it would ask you to log in and then normally you log in and either get "something went wrong" or it works. Now, it just immediately goes to "please try again later", before asking for who I am. This has been an issue on and off for so long, it's just the normal state for Paypal to be in for me. We're currently in a "not working" spell. It'll pass. Or not. It's paypal..
Frankly I don't mind the incentive to not use Paypal; gives me a good reason to tell business owners to support giving them the money directly (not through paypal or visa or whatever, just offer pre-paying via normal bank transfer) if they want my custom
Hopefully these stupid companies that are refusing to allow their apps to run on GrapheneOS will have a change of heart when Motorola begins launching their new phones:
I've disabled auto-update for PayPal in the Play Store and also Disabled the app locally (so I can re-enable when rarely needed). They'll force people to update soon enough given how banking apps are.
I still remember when my bank wanted me to run Android 9 instead of my Android 15 rom (without root) on my Samsung S8 because "muh security!!"
Funnily enough, the only way to hide those detections was to Root my phone...
And i still remember when i had an appointment there, they wanted to see something in my Bank app, i opened it (and i assume it had an update since i then last used it) and a big "THIS DEVICE IS NOT SUPPORTED. ROOT IS NOT SUPPORTED" poped up
But was as simple as readding the bank app to my root hiders.
Graphene OS isn't part of the satanic elite then.
I mean, you could already tell that when they started arresting anyone with a pixel at any border crossing.
These days, root is mostly flagged via indirect indicators rather than detecting the root binary itself. For instance, detecting custom ROMs is a common clue. Does anyone remember the suhide days? ;)
That's the bizarre thing about this hn discussion... A lot of people referencing rooted phones, but to the best of my knowledge GrapheneOS is almost never rooted?
It can be rooted just fine without doing your own build. It's just that if you do, the GrapheneOS community will claim that it is no longer GrapheneOS and that it's separate.
Paypal doesn't work on LineageOS since a long time, even though the connections of that dubious Graphene distro with the US government are always in the horizon it is just natural that paypal doesn't work there now.
Otherwise it would just continue to raise suspicious that Graphene is favored by governments and big tech.
This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!
Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors).
Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good guy or a bad guy so it's easier to just ban guns.
Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal with is so extreme.
It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The blockades are one piece of a holistic security picture that frustrate the well intentioned users.
Yet another weak point. My question stands: A user with an OS from 2019 is "secure" and dozens of unpatched CVEs but a literally-last-night-patch OS is not? That's the "stuff they have to deal with"? I was lucky and did not make the mistake of joining a payment provider in 2020 or 2021 (I can't remember). The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic(big part of the reason I did the "I accepted another offer already, sorry" card).
As for geo fencing or blocking Tor... HAH! As if that's ever stopped anyone with the will. That is the last concern of anyone with a malicious intent. Sure, it stops irritating kids but no one beyond that.
The simple fact is that cybersecurity was in an abysmal state before the slopification began and it's infinitely worse now. Paypal is no different given that much of their support has been outsourced to slop machines. Punishing the users that know what they are doing while rewarding the ones that don't is the most counter-productive and detrimental crap anyone could come up with.
> That's the "stuff they have to deal with"?
No. It's the offensive fraud vector coming from unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.
> unsecured devices that account for a significant portion of the noise. Requiring device profiling aggravates this vector.
Bullshit! Source:
> The reality is that European laws are much harsher when it comes to payments and personal data protection and the security team I was being interviewed for was catastrophic
Sounds like someone who wanted to impress the audience with fluffed up claims.
That's your argument? Mate, you can make explosives out of stuff you can buy in literally any supermarket and no one bats an eyelash. You don't have to legally be adult to buy any of the things you'd need and I say that as someone who only struggled with chemistry in school, that's now low the bar is. What's the solution then? Ban sea salt? If someone is using Graphene, the chances of them getting hacked are astronomically lower than any Chinese spyware-infested phone.
It was an analogy, or metaphor, I forget the distinction. But I don't think it was stood up to be literally argued against though.
physical risks, like your example, do not map well to digital risks faced by large international companies.
> Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies.
A more apt analogy might be game developers who demand admin rights so they can install a rootkit to detect "cheating".
The cherry on top is that their web site invariably still works so the refusal to work via app is an intentional manipulation tactic to harvest more consumer data for sale.
Sadly, their website now appears to require an app in order to sign in. Even before that it would often block me with text along the lines of "We don't know who you are, call our support number."
Desktop mode fixes discrimination against small viewports.
To stay with your analogy, there is no technical obstacle to treating the customer of 15 years differently to the newly onboarded one.
They have all the data they need, and they choose not to use it.
The analogy was not about new vs old customers being allowed to have guns.
I think that's a limitation of the analogy because there is no correspondence with trusted computing. I guess it would be some sort of a magical gun that some other company is endorsing as of limited use during bank robberies? Maybe like some sort of RFID thing that disables the gun when inside a bank?
Anyway it really stretches the analogy to get tied up in technical details (risks missing the forest for the trees type error).
How does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.
If you run a rooted phone and download malware, that malware can gain root and do payments on your behalf. Then PayPal has to deal with you revoking payments etc., they don't want to so they forbid you from using PayPal on a rooted phone.
Malwares can possibly do that even on non rooted phones if a privilege escalation attack is possible. And just yesterday, there was an article here about exactly one of those.
Also I highly doubt that there is any real statistics anywhere about whether this is a real threat or not. I guarantee that nobody did such statistics properly. The only known data is from companies which sell root prevention tools, so totally unreliable. And internally I guarantee, that no banks collect such info.
So no, banks lie about this only because they can sell this to judges as safety feature, when they fuck up, which happens continuously.
Graphene isn't rooted.
Not only is it not rooted, it runs real Google Play services. It’s not microG.
If this happens it's the device owners fault and they should be responsible for it.
Which they would be anyway since PayPal isn’t a bank and isn’t FDIC insured.
They allow you to open PayPal.com on any web browser. Running Windows/macOS/Linux is basically identical to a rooted Android phone (you have local admin rights, you can modify and automate the browser, and can run unsigned code).
No, no... In 2026, all footguns are banned. Even in programming, so if something allows a footgun, it's banned now.
Apparently the world can't adult and be responsible for their actions, or people believe in that.
For that argument to hold, they'd also have to blacklist any phone not running the newest, most up to date Android version, because all older versions presumably have known exploits. So that basically leaves Pixel phones.
One thing that I'm actually excited about regarding AI is that the pointless policy checkboxes that have never been effective in adding any actual security are even less so effective now that everyone can wield their very own security researcher.
Graphene OS does not support root. This is a false positive based on some check they are doing.
It's probably just a generic error message for failing that Google Play Protect thingamajigger that attests provenance of the vendor OS from boot. Will be interesting to see whether the Motorola phones have this endorsement when they ship. Most devices would probably fail because they are rooted rather than because they are GrapheneOS. I wouldn't put it past a scammer talking grandma into rooting their phone.
this isn't quite true
From a Paypal security POV, weather you use "custom Android OS" or an hugely outdated Android phone, you have:
- a similar risk for the "you" want to mess with Paypal case, in both cases the "you" can technically most likely mess with anything including the "virtual secure module" thingy android uses for NFC
- a lower risk for "others" wanting to mess with Paypal through your phone, at least if "custom Android OS" is GrapheneOS or another up-to-date android fork with decent security handling
so as far as I can tell, this inconsistency is very clearly not about PayPal's security.
IMHO it's about two other things:
1. marketing, if PayPal doesn't work on Android they lose customers, GrapheneOS for now has a tool small customer base for them to care. Outdated Android phone do have a large customer base.
2. compliance/politics BS. including potentially involving insurance. Compliance is mostly about checking of tickmarks(1) on outdated Android they can check them off and blame the user, Goodle or "hackers" for the issue. On GraphemeOS they have a harder time checking it of. Add the smaller user base and end up with PayPal doesn't care. Also iff things go wrong with Paypal on GraphemeOS in a public manner you will have all the "crime os" bad news bs, you won't have that if things go wrong with a even more risky highly outdated Android phone.
-----------------------
I got a bit to much off topic below:
(^1): Technically compliance should be about building robust, secure, law compliant systems and "showing" that by being able to pass a compliance tests consisting about a bunch of requirements. Practically there is way to many ways you can be "fully compliant" (on paper) but not secure and "very secure" but not compliant (wrt. security regulations). In the former case this might still come back and bite you iff you get sued or people suing which should get right don't get it because of ad-absurbum reasoning like "they comply with security regulations, hence can't have acted negligent". It's a shit show I don't know how to fix even if I could just magically change laws as compliance rules need technological flexibility, but if you give them that that will be abused to make insecure things pass. And the whole industry around checking that isn't really one who cares about actual security, sometimes outright corrupt (like groups which have the necessary accredited to check your compliance, are strangely more expensive then other groups, and somehow find less issues in average, with some excuse of why that isn't strange ...) :/
---
Lastly similar to how Teams or Slack could easily support FF (^2) but not only don't but outright refuse to try to even work. PayPal likes to act similar and doesn't care about niches. E.g. at least on some Mobile browsers WebAuthn works, but the PayPal website refuses to _even try_ 2FA with WebAuthn on mobile no matter if the APIs are there or not.
(^2): Yes there are some challenges, AFIK especially in certain edge cases most user might never run into. But Jitsi made it work, other smaller apps also made it work. And Jitsi is open source, so they technically can "look up" all the tricks to make it work (algorithmic ticks, not copy-pasting code) or outright just use their system with an appropriate contract (probably would be even cheaper wrt. maintenance cost then building your own system). At Slack/MS Teams scale that behavior is just messed up.
It was never about your security, it was about the corporation's security from you!
"Safe way to make sure I will stop being your customer - also YES!"
I don't think they care at all about the size of graphene os market share
if its jeopardize entire userbase then its not worth it
Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.
Noo, it’s the other way around lmao.
A financial security audit is one of the most thorough security audits you can ask for in software.
GrapheneOS gets blocked because it doesn’t follow the secure system requirements (root).
I suggest you read up the graphene documentation.
What requirements does it not follow?
>(root)
GrapheneOS is not rooted.
As several others have already said here, GrapheneOS is not necessarily rooted. So that's a lie.
Also, I've seen such audits internally, and they don't care about security at all. They care about the theatrics of security waaaaay more.
For example, I was at Santander in 2024, during its huge data breach. Here is the list of actions which are supposed to prevent the same kind of attacks again in the future:
-
Yeah, it's an empty list.
But of course, they made our life more difficult. In the end, I literally had more permission than before, because they were even sloppier than before. But of course, I had to change my password more frequently, and I had to type it about 5x more.
I'm sure their automatic bans have happened to more people than the number of grapheneOS users
I see this happen from time to time. Lately, almost all of the apps work fine on GrapheneOS. The best strategy is to keep writing the business once every two or so weeks that you can’t log in to and use the app. Don’t go too technical at first, because most of the time, the moment they hear things like “rooted” or “unofficial,” they just say your phone is the issue. To date, I was able to convince, or at least contribute to, making three apps work on GOS.
I had the same experience. Asked in an email why an important government app won't work on GrapheneOS, first without any technical details. Got the response that it's "because security". I sent some technical details and argued that they're denying service to their most security-conscious users. 3 months later the app started to work!
I think in this case it's also them just introducing a new check that either GrapheneOS will need to work around or Paypal needs to refine. I can reproduce the issue, but it doesn't seem like it did a failed Play Integrity check at that point.
Great job, man. We have to make ourselves get heard. It's a social problem after all. Technical workarounds are great and sometimes the only practical short term option, but we have to fix the social issue at the root.
Why would anyone still use PayPal after so many cases of accounts being banned and funds being frozen for no reason, and all the other terrible stuff they've done?
Easy to say when you are in a country where you have a lot of options.
There's some countries with very bad financial sector where your option is PayPal or Western Union as the local banks don't know how to do international transfers, Remitly doesn't support all countries and Wise also doesn't work. PayPal works, even if they charge fees.
Which countries have local banks that don’t know how to do international transfers?
We were having a lot of problems with that in Honduras, staff in the branch did not know how to do that, fees are extremely high and sometimes the bank system is just offline and you get sent home. There's a reason all these alternatives like Western Union etc. exist for this remittance use case.
It was a big reality check for me usually living in Germany and having access to a lot of banks and modern neo-banks.
My local banks know how to international transfers but I have to go into a bank office and fill out a paper form. Receiving international transfers they call and ask if I wish to accept it, if I can't answer the phone right then the transfer gets delayed. If the sender does not include my middle name, I have to come into the office and sign an affidavit that this person with this different name is also me. Each time.
Thank you for sharing your experience. I don’t know what your local banks are and what country you’re talking about.
I simply use it as an intermediary between my bank and any website I don't fully trust
I use "virtual card" for those needs. For me, it doesn't justify bringing out PayPal
I've had to use it when my bank's purchase limits did not allow for card (virtual or real), but the same purchase was allowed when going through PayPal. It was annoying AF, but was much faster than contacting my bank and getting permission to spend my money.
Privacy.com is a better option, but some merchants block it.
Critical mass? I had to start using it after moving to Germany, because everyone else expects you to use it.
One of the ladies at daycare is leaving? Here's a paypal link to chip in for a good-bye present.
Split a take-out order with a German friend, but he paid? Here's his paypal to send him your share.
It's just assumed that everyone has paypal over here...
As a German that never has encountered PayPal in the wild and doesn't have a Paypal account either, your narration requires elaboration to be believable.
Time to start heralding change you want to see. Offer Wero instead. It’s really simple.
Thought they use Sepa
I wish. The small inconvenience of putting in an IBAN and a matching name instead of just an email address is already enough for many people to default to paypal. Just happened to me again yesterday, the guy preferred to bring cash next time we see each other instead of just receiving my info via text.
Sepa is how my kid's daycare debits me each month, or how I transfer money to other accounts (most bills are direct-debit, but sometimes I get a one-off invoice and I have to transfer the money myself).
But for the small person-to-person type thing, paypal is the defacto here (sadly).
SEPA uses your IBAN (account number), and one can also enter this account number for payment, implicitly allowing the store to withdraw money from it...
You must be referring to SEPA Direct Debit, which would be very risky to use to siphon funds. There's an 8 week no-questions-asked refund policy, 13 months for unauthorized transactions, if the payment fails (eg due to insufficient balance), the payee is charged a non-refundable cancelation fee. [0] And that's all separate from any legal troubles for fraudulent charges. I don't know why Germans use PayPal over SEPA, but I'd be surprised if SEPA Direct Debit was the reason.
[0] https://www.europeanpaymentscouncil.eu/what-we-do/sepa-direc...
IBANs aren't secret, they have the same level of confidentiality as your address or birth date.
One-off SEPA Direct Debit is virtually unheard of, recurring payments are a bit more common but usually involve a €0,01 payment to prove ownership of the account. The transactions are also trivial to undo, and can only be initiated by companies.
So no, "IBAN fraud" isn't a thing in practice. You can safely share your IBAN with your friends for instant free wire transfers.
Well yes. But just in case this wasn't clear: this is a crime, and you will get your money back in most cases. It's on the merchant to ensure a Direct Debit Mandate is actually valid.
I do not think it is possible to withdraw money having only an IBAN. It would need a SEPA direct debit mandate for my bank to accept the transfer request.
That sounds like the same info on a check, which people hand out freely. I'm probably misunderstanding.
because global-ish exchange of goods and services for money is a deliberately convoluted experience that only a handful of well-connected entities are allowed to facilitate, which enables each and every one of them to put "we reserve the right to fuck you in the ass for any or no reason" in their ToS.
It works here. Running in a work profile, no contactless payments.
Play Integrity API: Not blocked
Hardened memory allocator: Enabled
Memory tagging: Enabled
Extended virtual address space: Enabled
Secure app spawning: Enabled
Native code debugging: Allowed
WebView JIT: Disabled
Dynamic code loading via memory: Allowed
Dynamic code loading via storage: Allowed
Doesn't work here. No contactless payments, full Exploit protection compatibility mode.
> no contactless payments.
I think this is the problem here.
A lot of NFC related tech is deeply rooted in having "trusted (aka large company)", "attested (aka you can't easily lie)", secure module functionality.
What should have happened is to just not enable the contactless payment functionality for given app, even if the user enabled it in general. And not crash.
Also as others have pointed out, this might be an accidental mishap not an intended outcome.
But it's not like PayPal is known to care about small user-base edge cases (quite the opposite). Which I guess is the actual root problem.
Still works for me.
I had to update exploit protection after their latest update — I think it was enabling dynamic code loading via both memory and storage that did the trick.
Edit: checked now, I have also disabled secure app spawning.
Interesting, just inferring from that it sounds like GrapheneOS's actual-security features might have been tripping up PayPal's root-detection "security" features.
(Rather than something fundamentally incompatible, like them using Play Integrity)
There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :)
IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.
So to use paypal you actually have to reduce the security of the phone?
As with all things about security — it depends on your threat model.
It reduces security of the app itself, but doesn't affect security of the phone by much.
Not too surprising. I usually have to reduce my browser security on the rare occasion that I access PayPal via the web.
Has PayPal blocked GrapheneOS, or have they blocked every OS they're unable to verify and done a poor job of implementing their checks?
Hanlon's Razor is a useful tool. https://en.wikipedia.org/wiki/Hanlon%27s_razor
The very fact they've managed to convince anyone that checking what OS I decide to run on the devices I own to check my own banking is any of their concern is a problem in and of itself.
Ironically, I had to apply Hanlon’s Razor to the impolite tone of your post
"Ironic" means saying the opposite of what you mean in order to be funny or sarcastic. So that would mean you think I was both polite and not an idiot.
Jokes on you though, I'm neither of those things.
You're a banking app. Why do you need to check my phone or my os? The security is not in what phone I use, but in how sane your 2-factor auth is and if even exists.
You're a banking app.
I've been called worse.
It is a useful tool, but is largely irrelevant to this issue. To the end user, this isn't really much of a difference. Whether the cause is malice or simply not choosing to use the smallest effective brush, they are still taking an action that is preventing legitimate users from accessing the service.
Hanlon's razor is for people. Organizations do not operate like people and do not deserve the same deference.
> have they blocked every OS they're unable to verify
This is evil in itself.
They have blocked rooted phones based on the error provided. Nothing to do with verification. They treat rooted phones to a level they don't with phones without critical security updates. That's the tension. Non-rooted phones aren't necessarily unsafer.
Graphene isn't rooted....
I have never been a crypto currency advocate, but if the banking utility of a mobile phone is going to be dictated by the operating systems that finance apps whitelist, I might want open rails that work with my open phone
Dumb idea, but I wonder if the underlying os can see who is asking questions like do you have root, And if an app has no need to know, it just plays dumb and responds...of course not. It's a bit of a chicken and egg problem, in that if you don't know what apps need to know if you have root, or not, then you can't determine that at the OS level...maybe an option for the user (popup) to tell the program, tell them we are rooted or not? (Or a settings page you can determine what apps can know root or not)
That's exactly how modern Android rooting tools work. You select which apps you want to have root, in a manager app. No other app should be able to notice.
But GrapheneOS isn't root, that's just PayPal's thing being broken.
perhaps but this is about device/os attestation, not rooting
How does their web site do device attestation? The argument that apps have to be locked behind a validation mechanism controlled by Google to be secure is BS when a cookie is sufficient.
Update: it seems to work when disabling "secure app spawning" (for now)
Great to know, thanks!
So it's not PayPal blocking GrapheneOS?
thank you!
The best approach to combat this is to cause as much headache as possible: bombard them with 1-star reviews, contact news sites, post this on social media sites snd contact Paypal's support.
Good luck with 3.7M existing reviews.
Can it still run in browser like it would on a regular pc?
I'm on Debian Testing sometimes on amd64 and sometimes on m1. Paypal also doesn't like me. Than I have two options: I use a Windows VM to do the payment or I use another payment method. Most of the time I use the other payment method.
I was always suspicious of GrapheneOS, thought it was too good to be true. But this makes me reconsider and want to install GrapheneOS.
it is great and you know that because cops are pissy about it
I think if paypal not working on GOS makes you not use it, then GOS is definitely not for you...
They're saying the opposite, no?
They didn’t read it that closely, they just wanted to put someone down and move along.
Switched to Wero and haven't looked back.
https://wero-wallet.eu
Wero is not a PayPal alternative. It doesn't even have buyer's protection and every bank must manually implement it which immediately makes it a failure. Some banks also connect it to your phone number so you can't link Wero to two different bank accounts with the same number when you have 2 bank accounts. Very messy.
> Some banks also connect it to your phone number
What do you mean "some banks"? I thought the whole value proposition of Wero was instant bank transfers with SEPA but using phone numbers?
Unfortunately peasants like us who don't live in the 5 countries where it's available still can't look back
I live where it's available and still can't use it to pay stuff, only to transfer money to friends.
You need to use your bank's app for Wero, and many EU banks' apps refuse to run on GrapheneOS for the same reasons as PayPal. This is sadly not a clear win for Wero.
wait for it... I can see a future were every wallet, payment etc. app will block devices which are on custom ROMs and do not pass strong hardware integrity with blessing from Google.
I've read once that there are paid app testing labs which test if an app has root and custom ROM detection and when they don't have that it's a minus point on the report.
Sadly, not even close. I would even dare to say that Klarna is closer to what PayPal is, than Wero.
The website is pages and pages of blankness for me on Firefox mobile.
Does this work in the UK?
No. We left the EU, so we don't get such fun.
I remember when I had to boot up an old windows machine because TurboTax refused to run on a Linux (might have been something related to flash as well... been too long to recall), then I just ran Windows in a VM, then extensions allowed me to do User-Agent spoofing (honestly should have thought of this sooner), and now they don't seem to care at all. I did my taxes on OpenBSD last year.
Confirmed on my phone too. I left a 1-star review on the play store saying it crashes on every launch, uninstalled and will use the website from now on. (Luckily, I dont use contactless payments, ai just send and receive money from friends from time to time)
I'm starting to see these restrictions as a deterrent for using the products in question. My GOS handset is slowly fizzling away into a dumbphone with Firefox, organic maps and k9. And you know what, I am starting like it.
This wouldn't be that bad if they had a functional website you could use instead, but their website doesn't even let you do things like pick your monthly rewards category or configure auto-replenish for your debit card.
This is what really makes me question if I want to continue to use GOS, already some UK banks apps (which are app only) don't want to run. I'm considering switching back to stock as I can't be bothered to try to find hacks and workarounds for daily necessities.
I would never use a bank that is app only. Sounds like a horrible experience.
Why do you need PayPal APP? I have grapheneos and just tested logging in to PayPal web. Works.
Does this really have anything to do with GOS and more to do with apps not wanting to run on rooted phones? A rooted phone is more likely to be tampered with and have its sandbox rules relaxed. There's a big business of security companies selling tools to harden mobile apps and the bare minimum is not running on rooted phones.
A normal GrapheneOS installation uses Android Verified Boot with a locked bootloader, and does not give the user root access. Google's Play Integrity cannot be used to verify the integrity of the OS (as GrapheneOS is not approved by Google), but equivalent verification can be done using standard Android APIs and GrapheneOS's public keys.
GrapheneOS doesn't give you root access.
The OS is designed to offer privacy and security guarantees, which root access breaks, so they don't offer it.
I also ran into the eBay application being blocked just recently. Other than that I've had no issues, but I imagine this is going to become more and more common as time goes on.
eBay has been enforcing Play Integrity for over a year now. Luckily you don't lose much by using it in a browser.
I also get why they'd be desperate to fight bots. It's a weak excuse for not doing it better, but at least it makes some sense.
I've been using it in the browser with GOS no problem. Any reason why one would need the app besides a little more convenience?
They require the app for certain things like managing which PayPal debit card category gets 5% cash back
I've not been able to use Paypal on Firefox+Linux, on and off for years now. The pop-up appears where it would ask you to log in and then normally you log in and either get "something went wrong" or it works. Now, it just immediately goes to "please try again later", before asking for who I am. This has been an issue on and off for so long, it's just the normal state for Paypal to be in for me. We're currently in a "not working" spell. It'll pass. Or not. It's paypal..
Frankly I don't mind the incentive to not use Paypal; gives me a good reason to tell business owners to support giving them the money directly (not through paypal or visa or whatever, just offer pre-paying via normal bank transfer) if they want my custom
Hopefully these stupid companies that are refusing to allow their apps to run on GrapheneOS will have a change of heart when Motorola begins launching their new phones:
https://arstechnica.com/gadgets/2026/08/motorolas-grapheneos...
if there is enough money to be made they will consider it...
I would bet that fewer than 1/1,000 non-HN users have ANY clue what it means to root a device. I sure don't!
I've disabled auto-update for PayPal in the Play Store and also Disabled the app locally (so I can re-enable when rarely needed). They'll force people to update soon enough given how banking apps are.
Looking at the description, the title should be changed to "Contactless PayPal card does not run on GrapheneOS"
I use latest Aurora Store PayPal version and it still works. I just dont use contactless payment.
I'm not using the contactless payment feature and get the same crash and error.
I still remember when my bank wanted me to run Android 9 instead of my Android 15 rom (without root) on my Samsung S8 because "muh security!!"
Funnily enough, the only way to hide those detections was to Root my phone... And i still remember when i had an appointment there, they wanted to see something in my Bank app, i opened it (and i assume it had an update since i then last used it) and a big "THIS DEVICE IS NOT SUPPORTED. ROOT IS NOT SUPPORTED" poped up
But was as simple as readding the bank app to my root hiders.
but still, i hate this security theater
Does the website still work?
It works for me after enabling exploit protection compatibility mode. Pixel 9a on latest versions of GOS and PayPal.
Still works fine for me. PayPal and GrapheneOS are both on the current release.
Why would you use PayPal anyway? It's a t#rd.
Graphene OS isn't part of the satanic elite then. I mean, you could already tell that when they started arresting anyone with a pixel at any border crossing.
Good job them. Can't wait for the motorola phones
Similarly, Cash App does not work on Graphene
This is likely incompetence. PayPal/Thiel are deep state and for sure the CIA has all PayPal transactions.
So they'd want to enable an app trojan on GrapheneOS.
The question is why anyone would use GrapheneOS and use apps from hostile publishers?
Funny how PayPal don't trust you to safely handle root but they will trust you to pay thousands in loans, credit, etc. What a joke.
Still works on my up to date pixel 9 xl. I haven't enabled NFC payments though
How is it that PayPal is still relevant? What does it even offer these days that other platforms don't do better?
P10F, 2026081301, Aurora Store, secondary profile, flawless. Try harder.
This should be illegal, but it won't. Corrupt politicians want people to be only on the approved operating systems so they can be surveilled.
When threat comes knocking, the door gets bolted-shut.
did you re-lock the bootloader?
With or without Google Play Services running?
With. But disabling "Secure app spawning" seems to fix it for now.
[dead]
[flagged]
[dead]
[dead]
"RootDetectionSecurityException" .. there's your answer ... it doesnt't want to run on "rooted" devices.
Well I haven't rooted my device. It's just normal grapheneos
These days, root is mostly flagged via indirect indicators rather than detecting the root binary itself. For instance, detecting custom ROMs is a common clue. Does anyone remember the suhide days? ;)
[dead]
iirc grapheneos can't be rooted unless you do your own build
That's the bizarre thing about this hn discussion... A lot of people referencing rooted phones, but to the best of my knowledge GrapheneOS is almost never rooted?
It can be rooted just fine without doing your own build. It's just that if you do, the GrapheneOS community will claim that it is no longer GrapheneOS and that it's separate.
Isn't it more likely to be saying that the app is running with root privileges?
Paypal doesn't work on LineageOS since a long time, even though the connections of that dubious Graphene distro with the US government are always in the horizon it is just natural that paypal doesn't work there now.
Otherwise it would just continue to raise suspicious that Graphene is favored by governments and big tech.
It does work for me on lineages for microg with an Xperia 5 II. Haven't tried to activate contactless though.
Never worked for me, tried with microg and plenty of other ways.