Avatar
๐Ÿ„ท๐Ÿ„ธ๐Ÿ„ถ๐Ÿ„ทโ—๐Ÿ…‚๐Ÿ„ฒ๐Ÿ„พ๐Ÿ…๐Ÿ„ด
8b5a1b71dc21c6200f66f9d314f87b5333a545440aa9d5960155ba6b1352ee1d
#nostr only
Replying to Avatar Diyana

nostr:nprofile1qqs9g69ua6m5ec6ukstnmnyewj7a4j0gjjn5hu75f7w23d64gczunmgpz4mhxue69uhhyetvv9ujumt0wd68ytnsw43q4gnztg help! Seems like Deepseek doesn't wanna work for me due to my OS. I do have Google play but I think it's wrapped or something. What do you advice?

#asknostr

try a burner email / phone number instead

this week i listened to twenty minutes of a podcast where they complained about how UK had gone to shit because of migration, then said one solution is for the kids to move to cheaper places like eastern europe where housing is affordable...

...which they said unironically

migrations ok as long as we are doing it

people been migrating for economic reasons since beginning of time though

always has been ๐Ÿ‘ˆ

Replying to Avatar corndalorian

i don't know what this relates to specifically and don't care but i like it

Replying to Avatar Final

Revolut insecurely checks the ro.boot.verifiedbootstate property and forbids it being yellow, which means a locked device with an aftermarket OS that's being cryptographically verified by the firmware. They permit it being orange, which means an unlocked device with any OS.

They're specifically banning having a device that's locked with an aftermarket OS rather than banning having an unlocked device or an aftermarket OS in general. Similarly, they're specifically banning the value `grapheneos` for ro.build.user/ro.build.host.

Having the verified boot state at orange is unsafe, it means verified boot is disabled. There is no verification of OS integrity after each boot and update. There is no protection against exploit persistence nor a threat choosing to push a malicious update that is not signed with the same key as the originally installed operating system.

Both of these things and other similar insecure, useless checks are being done by several different SDKs. Revolut's app is full of sketchy, insecure third party libraries. They certainly don't take security seriously as they claim in their message about banning GrapheneOS.

We've fixed both of the ways they're banning GrapheneOS for our next release. Since third party SDKs are what's being used to do it, our hope is that this fixes a few other poorly written banking/financial apps doing similar stuff to ban aftermarket operating systems.

These are the full set of changes fixing Revolut's ban on GrapheneOS:

https://github.com/GrapheneOS/platform_build/commit/bcd027b1273db32d6361092c635bf52a5d08c0e7

https://github.com/GrapheneOS/platform_build_soong/pull/24/commits/cc62edd5c3af000a6089fe2cceef10b9458f8aae

https://github.com/GrapheneOS/platform_system_core/commit/971110e37d73b5acb6e806b62146dcdcb29277b2

https://github.com/GrapheneOS/platform_frameworks_base/commit/5c85337ba0c4f5e40811a5a753754f7ccc2bc72f

https://github.com/GrapheneOS/platform_frameworks_base/commit/29c31dcdb5f826f1032a1a4da4dc584dbee8f01d

Other banking apps banning #GrapheneOS will need to be retested after the next release.

nostr:nevent1qqsxy2uy6q6td05lc73lhhhv7w6frjcxjgv9a3dxu73gfhpq2qdcmmspzpmhxue69uhkummnw3ezumt0d5hsyg9e3hk5e6h2ypusm09ncv2qq6fqp8f5clueylpgdq66nxm5sxjuygpsgqqqqqqsthe8pl

sounds more like trying to stop P2P trade of bitcoin etc , and their 'keeping your data safe' charade is an act in order to sound legit