Skip to main content


A potentially OPSEC compromising open source contribution.


This entry was edited (3 weeks ago)
in reply to OppressedBread

if not that many people use it then the potential usefulness is greatly dimished right? So you gotta balance your OPSEC risk with that I suppose. Falsifying information where not pertinent or adding unpertinent wrong information might alleviate some of it (i bought it x months ago, it's a business account i am not in the country often etc.). It's fine to mislead some users about the specifics of your case, if the overall goal of helping them can still be achieved i would think, unless it misleads them in a way that might cause harm of course.
in reply to mathemachristian [he/him]

good point, I'm leaning towards just changing the device model in the report and calling it a day.
in reply to OppressedBread

What about just logging in with your web browser? I've been using GOS for going on 4 years now and haven't had any issues with it. Is there anything specific the app provides that you need that isn't available through browser?
in reply to tapdattl

as it stands right now, there is no clear benefit for me when it comes between choosing to bank on my browser vs just using the app while yea it does offer some fingerprinting resistance, I'd be still exposing my real IP address, otherwise the bank would flag any other IP address I'm using and will require me to verify myself.

I opted to run my banking apps in a separate profile without hiding behind anything while kewping my other profiles separate and behind proxies

in reply to OppressedBread

Assuming your bank already has all of your information, what's the problem with them knowing your IP?

And how often do you need to use your banking app? Could you connect from a local free WiFi network from a library or something?

in reply to OppressedBread

You’re overthinking it.

Post whatever you found and just don’t use the banking app.

in reply to doodoo_wizard

I have to use it, its part of my daily life, but thank you for your response.
in reply to OppressedBread

What do you use it for daily? I think a lot of us don't have to use banking apps very often.
in reply to OppressedBread

Sorry for derailing... But what was the workaround? Was the issue they used Play Integrity API and you managed to circumvent it?
in reply to mumblerfish

no, that's a well known workaround, but the banking apps I used were just giving me a generic error, while yes they used google play integrity API, they weren't enforcing it.

what it turns out is that they were checking for specific packages that come preinstalled with every copy of GOS, effectively blocking users of said operating system.

Luckily these packages aren't essential and could be disabled by users, bypassing their checks.

this is one of many that they implemented, there are 3 other checks but it was easy to bypass those too without compromise.

in reply to OppressedBread

Why are they explicitly going out of their way to block GrapheneOS despite not many people using it?
in reply to chicken

seeing how the tech space is around here and digging more into binaries, they most probably outsourced their stuff, that third party company probably blocked GOS out of discretion, I don't imagine they actually asked for that.
in reply to OppressedBread

First, don't destroy your opsec if you feel unsafe.
Open source can move forward with contributions from people who can safely contribute.

I would, however, consider sharing enough of the solution somewhere that others can find it. It can wait to join the official answer list until someone else verifies and contributes it - someone who faces less risks for doing so.

Also, as others have mentioned, the real long term answer is to reject banking apps. They're simply do invasive, and the web portals aren't going away until there aren't any more PC users.

in reply to pinball_wizard

I use my work computer and am using my desktop as a sacrificial machine. I feel like if it sits on a desk, it can only share one location point. Finding private apps is on my to do list. I might move funds to another country if there is one left that hasn't become facists yet.

Thinking of the insanity puppy meme.