Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't care about any of these, I just want to be able to have whatever Google pay does without Google.

You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.



We had that for many years. But banks stopped supporting their own payment solutions because despite not having to pay commission to Google, it was more expensive to support their own solutions.

That should also tell you that almost any open source / non-profit solution is doomed to fail due to costs. What could work is if, just like the UnifiedAttestation initiative has commercial backing, Wero is expanded to also have its own NFC payment stack. The EU already forced Apple to open up NFC, so it is possible to do it for both iOS and Android.


Would it be possible to build something that works at the os level? And is built in the system itself instead of depending on google services ? I mean I don’t think it requires internet access all the time


Yes, Russian MIR system works this way.

https://glenbrook.com/payments_news/russias-mir-domestic-pay...

Just an application which emulates the card over NFC. No need to Google Play Services. It's been this way for ≈10 years I guess.


Walt https://walt.is/ is building exactly that in Europe. They claim first tap to pay will happen later this year.

Some European banks including mine offer NFC payments via their app as well. You don't need Google services.


> They claim first tap to pay will happen later this year.

Big if true. I guess the main problem is, would the banks from all over the world join in?

Fidesmo (https://fidesmo.com/consumer/fidesmo-pay/) has managed to sidestep this by integrating with Curve (https://www.curve.com/), which issues their own card and then charges your bank’s card from their end when you pay with theirs (tokenized and emulated by Fidesmo).

(Fidesmo also integrates with a whole bunch of banks directly, though mainly EU.)


> offer NFC payments via their app

NAB here in Australia did previously as well, but then they stopped doing that in 2022.

https://www.zdnet.com/finance/banking/nab-waves-goodbye-to-n...


Unfortunately NFC payments via bank app is not a thing in the US to my knowledge, and I've not heard of any plans to start doing it, but good for Europe.


Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?


People use alternatives for many different reasons (or multiple at the same time):

- They might want privacy from Google. Using Google Pay probably doesn't make much sense.

- Security protection against Google. Google can remotely brick devices with unsandboxed Play Services. After blocking of ICC officials and all the Greenland threats, it's not odd that some European citizens would like to block this Google/US government attack vector.

- They want a clean phone without all kinds of crap like Gemini preinstalled.

- They want to reduce dependence on big tech/Google product in general.

In cases 2-4, using Google Pay with sandboxed Google Play services may be an acceptable compromise for convenience.


Minor note, you forgot battery life. Pinging your location every other minute for traffic and crowd denisty for Google Maps, even using AGPS, isn't cheap.

When you find battery life randomly tanks for a few days, despite not changing anything in your life, it's always Google Play Services that end up being the culprit


Great point! For me that was not a reason to get a phone with GrapheneOS, but definitely a noticeable/welcome side-effect.


Is this an AI response? I get why people want a de-googled phone. What I don't get is why they would want to use tap to pay, one of the payment methods with increased attack vectors.


> with increased attack vectors.

I don't follow. If you mean against fraudulent spending phone based tap to pay is probably the most secure. It demands user authentication (biometric or code) for any transaction so there's no real way to trigger a fraudulent spend without the user knowing. Pretty much any other system allows for at least some amount of unauthorized spending if it's stolen.

If you just mean it's less private than I don't really know that it's terribly different than using a card. Especially if the ecosystem were open and you could choose your payment provider and not just have to use Google/apple.


You might want to look into NGate.


if I’m reading the source I found correctly, that has got nothing to do with Tap and Pay, where a virtual card is stored/emulated on device via the secure element, instead emulating an Contactless reader and relaying a real card pressed up against the device.

If anything, this attack is a benefit of mobile payments, where you need a second device to perform the attack with, and the user to use verify themselves for the payment to go through.


> Is this an AI response?

Probably not but you’re doing a bad job explaining what wanting to de-google your phone has to do with the choice of wireless payment methods.

It’s in the name, “de-googling”, not “de-attack-vectoring”. People want to break away from Google specifically. They’ll still use tap to pay because it’s convenient, secure enough, at least as private as any card/bank payment, and ideally not Google, which was what people de-googling want.


Well, why do people want to de-google? Likely peivacy and security. There is significant overlap in that reasoning and not doing tap to pay.


> There is significant overlap in that reasoning and not doing tap to pay.

Or using a (smart)phone, right? No need to go to extremes, cutting Google specifically is the win because they centralize the “spying”, not cutting the technology.

You’re stretching this for no good reason and trying to find a connection that doesn’t exist just to save your argument.


Is this an AI response?

No.

I hate AI writing, so I never use AI for writing. Randomly throwing in accusations in discussions sucks. I don't think my comment had any of the hallmarks of AI writing either, unless bulleted lists are also not-done these days.

I guess I should be happy that people don't recognize me as a non-native speaker anymore?


The accusation was not random. That writing had an AI tone to it with the bulleting etc, and didn't address the actual point being questioned.


It did not have an AI tone, bullet points are not an indicator of AI, and it addressed the point well.


Nah, some people are just having too much !fun! witch-hunting.


Without Google doesn't mean the same thing for everyone. I got a Motorola g moto stylus 2025 and have been running an experiment for almost a year now in which I use this device without ever logging into the device with a Google account. Fdroid and obtainium work flawlessly. Aurora Store works for the most part but some apps won't even let me open them without a play store signed in account which is sad.


Because privacy isn't represented as a binary.

You don't live life only having privacy or not having privacy. You fall somewhere in the middle. You can shift your overall privacy posture up if you de-google, even one service at a time.

Uninstalling Google Maps, whilst still using Gmail has privacy benefits. Each step improves your privacy. Some opt for convenience over privacy, you can pick and choose services to use whilst still retaining decent privacy.


Because people have different priorities than you do, and just because you can't imagine something, it doesn't mean it's not real or reasonable.


Some people like to have choices other than "all" and "nothing"


Tap to pay apps, if the developer is trustworthy or if it’s from your bank, are significantly more secure than even carrying a physical card around as your payment is now locked behind biometrics/a pin.

Also de-googling isn’t the point of GrapheneOS.


Because it’s convenient?


I agree, it's very convenient to have a phone full of corporate malware. But I thought the point of GrapheneOS was to escape that. My corporate malware only runs on my secure card processor which sits in a pocket glued to my phone.


But I thought the point of GrapheneOS was to escape that.

I think the point of GrapheneOS is being as secure as possible first and within those parameters give people the choice how much of Google they want. They have implemented sandboxed Google Play Services for a reason. Many people need Play Services for practical reasons (e.g. because they need to run apps that require it), so let's then run it in the most secure/private way possible - make it a sandboxed app, allowing users to decide whether to install it or not and if they choose to, that they can assign/revoke permissions like any other Android app.


The very moment it becomes possible to create a Google Pay alternative, there will be at least a dozen choices, some of them fully open source and privacy conserving.

The only reason why we don’t have them is Google / Apple duopoly.


I seriously doubt that. There used to be more NFC payment apps, but most banks abandoned them since it was cheaper to just pay Google their cut through Google Pay. Or Wallet, or whatever the hell they renamed it to.

Banks letting an open source project run transactions through them... that's... hilarious.


It's possible right now, but you have to (as Google did) convince all banks, merchants, and card networks to let them use your system.


Merchants and card networks don't need to be convinced. From their PoV Google Pay device is just a regular payment card.


You're begging the question. The entire premise of this thread is "we should be able to pay without infesting our phone with corporate malware".


Well yes, but attacking Graphene for that is attacking the wrong layer. If you want an open payments system the government has to mandate it, or you could take the low chance of success with the free market competition method.


IMO the most annoying thing is that Google could solve this problem today by just adding the GrapheneOS signing keys to the whitelisted keys. Instead they decide to exclude GrapheneOS because security, while attesting phones that are still on Android 13 (multiple years without fixes for vulnerabilities that are not marked high/critical) and did not apply ASB patches for up to 12 months.

A first step would be requiring Google to attest all devices that have a locked bootloader, verified boot, signed with non-public keys, and have a recent Android version and patch level.

IMO they should also boot anything older than Android 16 and behind more than 1-2 ASBs, if security is the real reason to have Play Integrity remote attestation.


POSIWID: the purpose of remote attestation is to force people to buy devices that pay Google license fees.


>that pay Google license fees

Source? I thought it was free for OEMs?


I think there's a fee and also a long list of requirements - such as you must not sell any phone without Google Play Store.


>I think there's a fee

Seems to be only in the EU (because they're being forced to), and some other sources say google is offsetting the fee through revenue sharing back to the OEMs. In any case the original claim of "the purpose of remote attestation is to force people to buy devices that pay Google license fees" is questionable given that google had to be forced into charging money for it.

https://www.theverge.com/2018/10/19/17999366/google-eu-andro...


I read the very first message of the thread as "if you're going to regulate something, regulate that we should be able to pay without requiring Google", ie with Graphene and the like. I didn't read it as an attack on Graphene.


Well it's going to be a matter of time anyway, I'm already forced to use an app when I'd rather not.

But more than that I want to have a choice.


Because tap to pay has nothing to do with Google?

Some people just want a phone without the duopoly and nothing else.


How about a way to use contactless payments on, say, a Pebble watch?


Xiaomi Mi Band 6 and 7 support NFC card emulation for payments, issued by Visa/MC.


Why can't I use my bank's app, which I presumably already trust, to tap-to-pay? Why should there be a third party involved at all?


You are free to reverse engineer the whole system and find a way to make it work. The world will love you. I suspect there will be a Google hardware attestation at the core of it, but understanding how it works is still huge progress.


That is essentially it as far as my understanding goes.

Google Wallet currently will not run on a fully updated grapheneOS.

Specifically it complains:

"Your device doesn't meet tap to pay security standards. It may be rooted or running uncertified software."

Which is fair. But something that actually works would be nice. I can keep extremely tight control on the NFC stack by toggling NFC with a quick access icon.

Not something I use very often, but not getting locked out of specific, not all, financial rails is one of those things that feels like it rubs up against the perpetual friction that the US founders, framers, whatever; didn't enshrine economic freedom in the same way as speech.

And maybe that's a libertarian fantasy. Idk. Seems worth thinking about for five seconds tho.

Bringing it back to reality. There are an incredible number of issues with trying to set up some kind of a competing service to Google Wallet to the extent that you might as well just go start a bank. And companies like simple have tried that and ended up bought by other banks at the end of it. And they weren't even trying to do anything other than offer people a banking app that wasn't total crap back in the day.

So realistically Google wallet or anything like that is not something I expect to use on a graphene OS phone until the graphene OS Motorola device comes out in the next few years. And that is entirely speculation that services like Google Wallet might be able to work on that device. But honestly it's the only real hope I personally hold for getting access to Modern payment systems on a secure device.


There’s been some progress over at microG, however not fully reverse engineered obviously, and I wouldn’t hold my hopes up for now: https://github.com/microg/GmsCore/issues/361


blows my mind that there’s not a single open solution for mobile wallets and nobody is saying anything.


You have to negotiate directly with Visa to convince them why they should accept your system. How will you convince them?


We desperately need to break Visa's stranglehold on access to the consumer side of commerce. As long as everyone's only innovating and competing on the merchant side of things, we're not really going to get anywhere.


You're free to make your own card network. How will you convince banks to issue your cards and merchants to accept them?


You mean like the EU digital wallet


You're free to try and make something like that.


They are making something like that as we speak. I’m not sure why though, they’ve had free SEPA Instant transfers for ages now.


Many EU online shops accept SEPA payment. It isn't convenient, because it's a push payment (giro) which means the site can't stick it in the middle of the order flow and expect it to take a few seconds. Some users might have to visit a bank branch to send payment.


Not all banks do SEPA Instant, yeah. I suppose the answer to that is connecting using PSD2 and sending the payment request then checking payment actually went out (using something like https://gocardless.com/). Many countries also have local bank link systems (e.g. in the Baltics it’s common to have dedicated buttons in the payment form for the big 3 or 4 banks everyone uses).

I’m talking about in-person payments though. It would be so easy to implement QR payments backed by the existing SEPA Instant rails. Many bank apps already understand EPC QR codes (usually found on invoices), so shops could just show these to accept payment. In case your bank doesn’t support SEPA Instant, you could show the cashier the receipt in your bank app, which, well, horribly insecure, but probably fine for low-stakes cases like grocery shopping (you don’t want to be banned from your grocery store chain for forging a 35 € payment).


One problem with SEPA Instant is that it can sometimes fall back to regular SEPA which takes a few business days.


Are you prepared to protect customers by refunding them if they are victims of fraud when using your payment system? Visa and MasterCard are prepared to do that. That's how they could convince consumers to use their cards without worrying.


Clearly consumers do worry, since the ones found in this comment section are saying they refuse to use a card as it could be stolen.


Millions of card transactions are made every day. If consumers worried, they wouldn't have credit or debit cards and they wouldn't use credit or debit cards.

What a single hacker writes is on the other hand just what he wrote.


Millions of people type their banking username and password into services like POLi, too.


so what you're saying is we should be looking at competitors of Visa


MasterCard has the exact same issue.


Yep, the duopoly is pretty strong. There are national card networks (which sometimes make their own tap-to-pay apps!), but if you want universal acceptance you’ve got to deal with the big two.

You can sidestep this however by not dealing with cards. I’d look into various QR payment schemes.


Because a normal card is superior in most practical cases?


I'm starting to come the the same conclusion, but not for practical reasons. My thinking is about privacy. If I buy some chocolates from retailer X (with or without their loyalty system), these parties will know what I purchased and where: The retailer, the bank, the merchant (visa/mc), wallet provider (Google/Apple/Samsung). Any upstream 3rd parties for analytics, big data warehouses, ai companies (fraud detection, spending predictions), marketing companies, research companies, manufacturers. Then there are bluetooth beacons, microphones, cameras, facial recognition, keyboard/screen capture (Gboard, Samsung Keyboard, Whatsapp texts). Then there is sms and popup notification on device that gets ingested by x amount of systems too. So the whole pipe just exists to gather as much as possible data to sell me more stuff. Having a card will take some of them out of the loop or less rich metadata than using a digital wallet.


A card is a good step to reduce that. I want to go farther and pay cash as much as possible, but it's not trivial to manage when all I have is a pocket full of coins. Is there a 3D printed wallet with slots sized for European coins so you can quickly identify and extract the coins you need instead of rummaging through a mixed pocket?


For the Americans: https://www.officedepot.com/a/products/6844022/Nadex-Coins-4...

I assume the same must exist for euros.


Haven't used a normal card in over a decade. I don't think my bank actually makes physical cards anymore, last time my card expired I just had a popup in the bank app that told me I have a new card. This was like 2-3 years ago. I use Google/Android Pay (or whatever it's called now) for NFC payments and have since 2018 and never carried a physical card since.

I would never use a physical card with NFC anyway because it is both inconvenient (have to enter PIN every 5 transactions) and insecure (for transactions without PIN there's no verification layer), whereas on my phone I have to unlock it for every transaction no matter how small, and doing so is a small matter of pressing my finger on the fingerprint reader.

I'm as anti-capitalist as they come but this is kind of a lost fight in my mind because if not Google - then Visa/Mastercard and the bank itself will know every transaction I make anyway.


It is? I haven’t carried my wallet around in years, because Apple Wallet does everything I need. Concert tickets, boarding passes, bank cards, public transport cards, etc. A physical wallet and cards in comparison feels like stone age technology.


And your battery goes empty, and you just lost everything. Or your phone falls to the ground and breaks.

And to add to payments, the store loyalty apps are the worst... Lidl over here has an app only (no physical loyalty card), and they should be hanged for developing that... first of all, you're waiting in line while a grandma takes her phone out of her purse, then unlock it, and of course android is not satisfied with her fingerprint right then but also wants a pin... then all apps, then scroll down to L, find LidlPlus app, tap on it... QR code? Nope, not yet! First you get a daily coupon wheel of fortune, tap, wait for it to spin, see what your award is... and if it's something that she just bought, she has to manually activate that coupon in the menu (again, tap, find, tap, tap back), and then click the card button to get the qr code to scan... it's literally minutes sometimes of just waiting, instead of scanning a simple qr code on a plastic card pulled from the wallet.

We even had one of our telcos break down (full internet loss, country wide), POS terminals not working at all, and there are actually people with zero cash with them, not even like 50 euros (for just-in-case (like this))... and then you have to wait for them to turn around, take their stuff back and go home hungry.


I also have Apple Wallet on my Apple Watch. I can use the Apple Watch to also pay for things.


Yes it is. Doesn't break if drop it for one. Much smaller than a phone. Isn't tied to apples ecosystem. etc.

I get that you might want one if you are a tech maximalist with a single focus. But that doesn't mean you should stop carrying your card.


Don't you still have to carry cards for things that aren't digitally excepted, such as a drivers license in most states?


I'm not an American. In Estonia your ID is entirely digital, and I just show my e-Estonia government provided app to a scanner, which can scan my ID from there and verify it. Same with a drivers license. As long as I travel within EU I also don't need to carry a passport with me as a EU citizen.


Banks and card networks will only accept proprietary shitware as payment. Would you rather keep the malware confined to a separate processor chip or would you let it run on your phone?


In other words, would you like to have your physical card to be lost or stolen and someone paying with it? As small amounts don’t ask for a pin confirmation. Having my phone stolen is pretty much another level of attack.


> would you like to have your physical card to be lost or stolen and someone paying with it?

I don't really care, as I'm protected from fraud by the card issuer and regulations in my country.

> Having my phone stolen is pretty much another level of attack.

Stealing a wallet or a phone seems just about the same level of difficulty.

And you can trick an iPhone into believing you're a transit terminal and charge arbitrary amounts to real credit cards, without unlocking the phone. (And Apple thinks this is a feature.) The attack requires specialized hardware and physical access, but if you've stolen the phone, that's fine.

(Yes, I know, this article is about Android. But most people where I live have iPhones, even if I don't.)


Yes... that $25 if they manage to get even that before it is blocked I can live with. Loosing my phone, even if they can't do anything with it is a whole other scenario. Now I can't even get home.


Your bank will refund any stolen money if your card is stolen.


No it’s not, all of my and my extended family cards (for… like a decade!) are never even leave the envelope they come in. I’m not sure I personally know people who use physical cards over Google or Apple Pay. I have seen the cards being used in the wild, of course. But I’m having hard time remembering anyone I personally know who does that.


How strange that culture is so different in different places. You can just start using them, though. Literally just swipe your card whenever you would swipe your phone.

Do you guys not have wallets with card slots?


I've never had a physical wallet period. I'm not some Gen alpha baby either, I'm almost 30. I have like 4 bank accounts too.


Go buy one and put your cards in it


You need them in some scenarios. For example, lots of car rental companies refuse to take anything but a physical card.


So, the argument is that it is popular? I'm not arguing against that...

That people trade anything for even just perceived convenience? That isn't news either, but it does explain a lot of the sad state of affairs we are struggling with today.


> I’m not sure I personally know people who use physical cards over Google or Apple Pay.

You live in a pretty weird bubble. (And I live in San Francisco, so I know about weird bubbles.)


Like half of the UK adult population use them: https://www.bbc.co.uk/news/articles/c2ejvld0ypyo

That's from a year ago, I'm sure it's only grown since.

I think it's you who's in a bubble, my friend.


"open solution for mobile wallets"

define open wallet then


My bank had NFC payments for years. None of the remote attestation bullshit. I think it used Google's library for doing QR code scans so it wouldn't work without Google Play, but that's beside the point.

Android already supports this, and has supported this for over a decade. The restriction here is on the side of the finance ecosystem. Everyone has congregated on doing Apple/Google Pay because it's cheap and easy to maintain compared to the alternative. Cards companies and banks make deals with Google, just like they do with companies like Apple, Samsung, and Garmin.

Any fintech startup with serious backing can create an Android app that works on any ROM you can imagine. I don't think you'd have an easy time finding investors for this with how much money you need to partake in the ecosystem, but the API is ready for you to implement.


There's Curve Pay which works on GrapheneOS


What cards & banks does it work with these days? Last time I checked, it wasn't really a serious alternative.


The whole GrapheneOS thing is a bit of a joke. So you either have to buy google hardware or you run google software.

Anyway, looking forward to the widespread introduction of Wero. Maybe there will be some options for third party roms in the name of digital soveranity. Seems like they want to make the EUDI wallet for digital documents no-google capable for that reason at least.


You think Google puts backdoors in their hardware? They've consistently been one of the most open hardware brands since the start, always allowing bootloader unlocking and relocking and providing all required open source code. This is not the same as their software which is invasive spyware.


No, I don't know if they do and honestly this isn't why I wrote what I wrote. But what if I don't want to buy anything from them? I want to de-google and my only choice seems to be to have a device with a google logo on it that puts even more money in their pocket than if I just use normal Android with minimal google interaction on a Samsung or OnePlus device.


A phone case with your NFC credit card in a pocket on the back. Boom, problem solved.


This is a great solution if you have the physical card. One very nice use case of Google/Apple Pay is being able to pay with a virtual card in-person.


Google should've been broken up eons ago.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: