this post was submitted on 25 Jun 2025
835 points (98.7% liked)
Technology
71922 readers
4264 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Can you tell me about Graphene?
I got bank and government ID apps (manditory. Denmark uses MitID for all government related things), but they require things like locked bootloaders and Google security features.
Would those apps be functional on GrapheneOS?
ew. Tell your government to stop mandating spyware.
Graphene does let you re-lock the bootloader. IIRC, whether an app works depends on whether they require SafetyNet full, or just basic. I have so far only found one app that refuses to work. However... it looks like MitID was recently updated and no longer works.
https://gist.github.com/lbschenkel/4199be415f2a139b64688ae74c92a7fc
how do they make it mandatory? what happens if you don't have a smartphone?
is it strictly mandatory, or is the alternative intentionally very inconvenient?
I'm asking because it is very weird to me. but also, in my country also in the EU, there's this misunderstanding that it is mandatory, while actually it can be replaced with any 2FA code generator app. and then it has a bunch of administrative features in one place for convenience
MitID is hard-required to sign into anything government or personal information required. Previously people would be handed a key-card (a white, fold-out card with a bunch of numbers on it. The numbers were one-time use, so the card would eventually run out, requiring a replacement after a few months).
These key-cards have been completely phased out. Now there is the MitID app or a key-device that is almost impossible to get (you'll basically have to prove that you don't have/can't use a smart phone).
The MitID app has almost no features at all. It's specifically used for authentication. You log into the gooberment website or bank website, then a encrypted, constantly changing QR code pops up. You open the MitID app on your phone, scan the QR code, and then you gain access.
This is all run through the private security company the Danish government has hired, called "NETS".
Something must have changed since I got my physical code display then, because I simply went to their webpage and ordered a free code display device a while ago. https://www.mitid.dk/bestil-mitid-identifikationsmiddel/
I'm sorry you have to deal with this shit
I can also recommend CalyxOS. Locked bootloaders, open source emulation of all Google's play services (meaning an open source binary running on your phone, filtering requests to Google's servers with absolutely minimal/random info).
Basically I have anonymized access to the play store, and any apps I install other than Google pay work, no issue. ~~I believe even Google's secure features work. There's a reddit post about MitID: https://www.reddit.com/r/CalyxOS/comments/w2ordg/a_proven_way_to_use_calyxos_and_banking_apps_etc/~~
E: having read through the technical comments on graphene's forums, looks like play integrity prevents MitID from running. The service offers free code generators which hang on your keys though.
Do you happen to use android auto? Does that work OK? I could go without, but that's one integration that's just got it's hooks on me hard.
Android auto works on an ungoogled phone last i tried, it does take some tinkering though
Maybe? It depends on what exactly the app checks for. Some apps don't work because they check if it's running on the original ROM. It's hit or miss.
If you can access what you need through the web, you can go that route instead.
It's best to never use any apps or accounts for your business life on your personal device. I have two phones for this purpose.