this post was submitted on 07 Mar 2024
8 points (100.0% liked)

Android

27549 readers
551 users here now

DROID DOES

Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


We are Android girls*,

In our Lemmy.world.

The back is plastic,

It's fantastic.

*Well, not just girls: people of all gender identities are welcomed here.


Our Partner Communities:

!android@lemmy.ml


founded 1 year ago
MODERATORS
 

I'm lucky my banking app works (GrapheneOS), as it's now requiring 2FA with the app anytime I login on the browser. Can't use an actually secure form like TOTP. At least they now allow passwords over 8 characters (yes, serious).

(Meme in comments)

top 21 comments
sorted by: hot top controversial new old
[–] Atemu@lemmy.ml 3 points 6 months ago (1 children)

At least they now allow passwords over 8 characters (yes, serious).

Are you 100% certain they don't just truncate your password to 8 characters?

[–] RebootRebootReboot@programming.dev 2 points 6 months ago (1 children)

I've seen a website that silently truncated my password during a password reset, but then wouldn't truncate it during login. It took me a while to figure out why my password never worked.

[–] davidgro@lemmy.world 2 points 6 months ago

Name & shame please

[–] MTK@lemmy.world 2 points 6 months ago (1 children)

I hate this so much!

My bank is like that and another horrible thing is that after you choose your password (which can be long and complex) you need to choose a 6 DIGIT restore code incase you forgot your password...

Why is is my BANK so bad at security??

[–] Dnn@lemmy.world 1 points 6 months ago

And they all develop their own shitty app for 2FA (the lazy ones just rebrand SecureGo as their own - you still have to install all of them separately) instead of using the 15 year old TOTP standard. The latter is good enough for tiny companies like Google and Amazon but what do they know about itsec, right?

[–] viking@infosec.pub 0 points 6 months ago (2 children)

Magisk plus DenyList luckily works for my banks. Couldn't imagine not having a rooted phone.

[–] Engywuck@lemm.ee 0 points 6 months ago

Non-rooted phones are just like iPhones. Ewww...

[–] PoorPocketsMcNewHold@lemmy.ml 0 points 6 months ago (2 children)

Beat the main purpose of GrapheneOS. Open the phone to a broad lot of security issues.

[–] viking@infosec.pub 0 points 6 months ago (1 children)

Graphene only works for Pixel phones, and I don't want a Google device.

[–] lseif@sopuli.xyz 0 points 6 months ago (1 children)

thats fair. device support is a major downside of GOS. but, remember: its not really the fault of the OS, as it requires a lockable/unlockable bootloader, which only pixel phones provide (at least in terms of mainstream phones). blame the OEMs like samsung

[–] deweydecibel@lemmy.world 0 points 6 months ago* (last edited 6 months ago) (1 children)

which only pixel phones provide (at least in terms of mainstream phones)

Mainstream phones? Pixel is a smaller market share than Motorola, and Motorola has unlockable bootloaders, and lineage supports a fair number of them.

[–] state_electrician@discuss.tchncs.de 0 points 6 months ago (1 children)

I thought Google owned Motorola, but I missed the sale to Lenovo ten years ago.

[–] BaardFigur@lemmy.world 1 points 6 months ago

Lenovo owns Motorola. Lenovo being chinese is somewhat a security risk.

[–] TWeaK@lemm.ee 0 points 6 months ago (1 children)

GrapheneOS is made by diva developers who frankly should not be trusted. "We only allow Google phones to run our OS!" as if they don't have a backroom deal with Google.

[–] PoorPocketsMcNewHold@lemmy.ml 0 points 6 months ago (1 children)

Proove us that you can get better security while remaining able to be fully modified with other phones and brands. https://www.privacyguides.org/en/android/#divestos

[–] TWeaK@lemm.ee 0 points 6 months ago (1 children)

Privacy Guides has a bit of a sordid history of their own diva behaviour.

[–] PoorPocketsMcNewHold@lemmy.ml 1 points 6 months ago (1 children)
[–] TWeaK@lemm.ee 1 points 6 months ago

Nah they've been accused of biases.

[–] onlinepersona@programming.dev 0 points 6 months ago (1 children)

I moved to a bank that allows non google phones and let my previous bank know why I left.

CC BY-NC-SA 4.0

[–] x4740N@lemmy.world 0 points 6 months ago (1 children)

Why are you licensing your comments

[–] fishos@lemmy.world -1 points 6 months ago

Because they think it matters. Same as people posting on Facebook some legalese saying "Facebook doesn't have the rights to my stuff.". They think that by slapping a copyright "claim" on their stuff that they supercede the agreements of the platform and somehow protect their comments from being scrapped by bots/advertisers, etc. All it really does is add a little "this guy is probably a sovereign citizen type" sign to every post they make.