Revolut is blocking new logins from Android distributions that aren't certified by Google, incl. GrapheneOS

There’s an update for revolut in gstore, lucky I had randomly checked this forum and then disabled auto update. Does the app still work? Yep. For how long :person_shrugging:
On 10.58 wants to update to 10.58.2

Source from GrapheneOS

This tool exists for rooted devices

Alas:

Can this module pass MEETS_STRONG_INTEGRITY?

No…


Off-topic

I switched my main bank from one of these app-first online-only banks to a classic high street banks that still does everything via SMS (it’s Santander). The app is very old fashioned and clunky but that’s just what I want because it means it’s completely optional and all the important approvals are done through SMS codes.

but SMS is not secure, what about SIM jacking?

I don’t care, not my problem, probably safe enough. It’s more important to me to be able to use a fully FOSS operating system and not be forced to use a Google OS with Google Play and Google Account. (or same with Apple)

Not even Google Wallet requires MEETS_STRONG_INTEGRITY. There is the intermediate MEETS_DEVICE_INTEGRITY which that tool will allow you to pass but which GrapheneOS does not pass.

2 Likes

I just wanted to open the app and I had to sign in (version 10.58.2) then this screen popped up… using the most updated LineageOS version without root…

1 Like

That’s also lame though. Even if it’s undeniable that it improves security, it also means planned obsolescence is even worse.

FYI I downgraded to 10.56.2 but the same screen is popping up. So better think twice how much you rely currently on Revolut… b̶e̶f̶o̶r̶e̶ ̶i̶n̶s̶t̶a̶l̶l̶i̶n̶g̶ ̶y̶o̶u̶r̶ ̶n̶e̶x̶t̶ ̶O̶S̶ ̶(̶s̶e̶c̶u̶r̶i̶t̶y̶!̶)̶ ̶u̶p̶d̶a̶t̶e̶,̶ ̶a̶s̶ ̶i̶t̶ ̶w̶a̶s̶ ̶a̶t̶ ̶t̶h̶i̶s̶ ̶m̶o̶m̶e̶n̶t̶ ̶I̶ ̶g̶o̶t̶ ̶l̶o̶g̶g̶e̶d̶ ̶o̶u̶t̶ ̶(̶a̶t̶ ̶l̶e̶a̶s̶t̶ ̶I̶ ̶t̶h̶i̶n̶k̶ ̶s̶o̶,̶ ̶a̶n̶d̶ ̶I̶’̶m̶ ̶a̶l̶s̶o̶ ̶n̶o̶t̶ ̶o̶n̶ ̶G̶r̶a̶p̶h̶e̶n̶e̶O̶S̶ ̶b̶u̶t̶ ̶o̶n̶ ̶L̶i̶n̶e̶a̶g̶e̶O̶S̶,̶ ̶s̶o̶ ̶m̶a̶y̶ ̶b̶e̶ ̶d̶i̶f̶f̶e̶r̶e̶n̶t̶)̶ Edit: As phnx pointed out it is probably coincidental, so make sure you are not relying on it :confused:

Also the web app is requiring the app to authenticate fully and use more functions, the email code is only for viewing some basic stuff (give it a try and see what you are able to do there with and without app). Then I tried to use the live chat which is kind of working, but only for as long as you stay on the browser window, otherwise you are required to log back in and the chat disappears…

Not sure why you are encouraging people to avoid crucial OS security updates. This issue is solely due to Revolut and Google’s anti-competitive practices, nothing more, nothing less. The fact that you got logged out after updating is purely coincidental.

Sorry, that was not at all my intention, so I edited my post. Not sure what triggers log-outs, it was just a guess. I totally agree with the issue lying in the practices of Revolut and Google, just wanted to give a warning :slight_smile:

1 Like

I’m on gos and gos updates itself, revolut still works for now. Just logged in.

Tried this workaround when I tried to help with a virtual card to show details on, This did not work I got the exact pop-up, I’m trying the version I had, 10.38.1
Edit: Nothing works, either get error or “Update to latest version”
I’m logged in on an old phone till I figure it out.
Edit 2: Older versions from 10.40 are not working, let’s see…

It just got so much worse. It turns out Revolut has been intentionally blocking GrapheneOS specifically, and does not actually implement the Play Integrity API yet.

Revolut is specifically banning GrapheneOS by checking for the build machine hostname and username being set to grapheneos. We’ve changed these to build-host and build-user. Combined with another change, this allow our users to log in to it again until they roll out Play Integrity API enforcement.

There’s no legitimate excuse for banning using a much more private and secure operating system while permitting devices with no security patches for a decade. Meanwhile, Revolut’s shoddily made app tells users they’re banning GrapheneOS because they’re “serious about keeping your data secure”.

Revolut’s app will stop working against once they start enforcing having a Play Integrity API result showing it’s a Google certified device. This is not a security feature but rather anti-competitive behavior from Google deployed by apps like Revolut wanting to pretend they care about security.

Revolut uses a bunch of shady closed source third party libraries in their app and it’s one of these libraries banning GrapheneOS. These libraries are a major security risk and put user data at risk of being compromised. Revolut is not taking user security seriously at all and is cutting corners.

If this is true damn, this is so much worse.
I didn’t fully support protesting though if you wanted like fair and impactful type of thing if it was Play integrity API but now. Oh damn they want us to go full blast.
Let’s see…

A good opportunity to log in one last time to close your account

2 Likes

honestly if revolut just does absolutely nothing after the Custom ROM users protesting I can see myself ending up to Wise. Though I really don’t want to for 2 things:

  1. Revolut offers savings account
  2. If the data safety on the Google Play Store for both is anything to go by at this point I genuinely prefer Revolut. More importantly it’s genuinely asked permission for inter apps communication. Thank god they ask because if they didn’t it’s just scary. Can say revolut does the same sure but at least there’s no data potentially Being shared. Again if that alone is anything to go by.

TradeRepublic has better rates with a 3% annual rate.

1 Like

Alrite I will just file a complain and close the Revolut account.

Will also help them spread their words.

1 Like

It’s hard to know which neobank to trust going forward. Many don´t even seem to have a channel where you can ask if they are going to implement these practices.

I had tons of problems getting the N26 app to work on both iodéOS and GrapheneOS last year and eventually had to close the account. Without the app it was indeed a nightmare. Took me over a month of sending them mails and hassling them to get my money back.

Disappointing. They probably consider every custom OS to be “insecure”, which feels very reductive of efforts like GrapheneOS. Hope this changes.

Does Wise also have one-time use cards and free virtual cards?