ehm...
ehm...
Strange, my phone shows exactly 27 too.void said:
easy to say but what do you suggest? I have 27 banking apps installed at this moment and zero time/motivation to play with each and every those to make it work in the emulated environment
Click to expand...
void said:
most of the idiotic backing services I'm forced to use require their own app for 2FA - horrible trend but it is what it is
Click to expand...
It really does not make any sense. X.509 client side certificates have been around for decades and are safe. WebAuthn has been supported since Q4 2018 on pretty much all browsers. And then, banks fiddle around with 2FA over SMS and the like while such data is regularly leaked in various ways and then call it secure.
I think you can run it in different profiles. Otherwise, you can use App Cloner or open the APK in Android Studio, change the package name and re-sign it with a test certificate.void said:
is to possible to have multiple isolated instances of the same app (not knowing about each other and sharing any common data) and running them at the same time?
like couple of whatsapp apps with different identities or banking app to represent two persons - Android 14 has the App cloner for this which is very convenient
Click to expand...
I'm stubborn. I say Signal is the only way to reach me. It surprises me how many people actually install Signal just for you when you tell them that. Family and friends is easy because if it's the only way to reach you, they'll install it. For others, I'm a bit machiavellian and tell them things like my phone is too old to install Whatsapp (was true with one of my phones). Or if they call or SMS me, I'll wait a week and say "sorry I missed your text, I never check it, but reach me on Signal and I check that all the time". You can use this trick on Whatsappers too. Just ignore them for a week and tell them you never check it, so they should install Signal to reach you instantly.void said:
sadly I cannot live without Whatsapp while traveling as for the rest of the world it represents their interface to the world - I hate it but don't know how to fight it... I'm all ears if you do
Click to expand...
Lol. I'll do 27 card readers if I have to! But some apps let you use open source authenticators like Aegis which doesn't spy on you. Maybe some of your banks will let you. Even SMS is better 2FA than bank's bespoke apps. See which ones give you options. I let them send SMS to a number I switch on only for 2FA.
I know, SMS is so not secure but they think it is. Stupid companies. I genuinely feel more secure using just a username and password.daniels27 said:
It really does not make any sense. X.509 client side certificates have been around for decades and are safe. WebAuthn has been supported since Q4 2018 on pretty much all browsers. And then, banks fiddle around with 2FA over SMS and the like while such data is regularly leaked in various ways and then call it secure.
Click to expand...
How about sessions and threema? I wonder when proton comes out with a messenger.cherry said:
I'm stubborn. I say Signal is the only way to reach me. It surprises me how many people actually install Signal just for you when you tell them that. Family and friends is easy because if it's the only way to reach you, they'll install it. For others, I'm a bit machiavellian and tell them things like my phone is too old to install Whatsapp (was true with one of my phones). Or if they call or SMS me, I'll wait a week and say "sorry I missed your text, I never check it, but reach me on Signal and I check that all the time". You can use this trick on Whatsappers too. Just ignore them for a week and tell them you never check it, so they should install Signal to reach you instantly.
Click to expand...
Why use Aegis? Just write a script yourself and use proper encryption of the secret.cherry said:
Lol. I'll do 27 card readers if I have to! But some apps let you use open source authenticators like Aegis which doesn't spy on you. Maybe some of your banks will let you. Even SMS is better 2FA than bank's bespoke apps. See which ones give you options. I let them send SMS to a number I switch on only for 2FA.
Click to expand...
I have about a dozen banking apps that work without SafetyNet. The few apps that I cannot use on my Pixel, I just download on another device. But the majority works fine. You could also have a look at: https://plexus.techlore.tech.aniglo22 said:
Are you using your device with GrpaheneOS for banking ?
As some EMI's/banks specifically blacklist GrapheneOS ( e.g Revolut
https://bsky.app/profile/grapheneos.org%2Fpost%2F3lgc3zj3izs2x
)
Click to expand...
Yes, I segregate everything by profiles. You can manage app installations centrally. For example, you can enable or disable an already installed app for a specific profile. Although I have to admit, switching profiles can get tedious at times if you're trying to maintain privacy, but it's definitely more secure. You could have a "family" profile with chat apps and personal photos, while another profile stays free of sensitive information but still has the same chat apps for talking to different people.void said:
is to possible to have multiple isolated instances of the same app (not knowing about each other and sharing any common data) and running them at the same time?
like couple of whatsapp apps with different identities or banking app to represent two persons - Android 14 has the App cloner for this which is very convenient
Click to expand...
this might work with friends and family, perhaps in certain types of business relationship but with this approach you wouldn't survive one single day in Mexico, Dominican republic or Sri Lanka 😀cherry said:
I'm stubborn. I say Signal is the only way to reach me. It surprises me how many people actually install Signal just for you when you tell them that. Family and friends is easy because if it's the only way to reach you, they'll install it. For others, I'm a bit machiavellian and tell them things like my phone is too old to install Whatsapp (was true with one of my phones). Or if they call or SMS me, I'll wait a week and say "sorry I missed your text, I never check it, but reach me on Signal and I check that all the time". You can use this trick on Whatsappers too. Just ignore them for a week and tell them you never check it, so they should install Signal to reach you instantly.
Click to expand...
While we're at it, let's go back to pagers and payphones. 😉daniels27 said:
Why use Aegis? Just write a script yourself and use proper encryption of the secret.
Click to expand...
silly question perhaps as I don't have the experience (yet) but these alternative profiles are not all online, are they? I mean would it work if one needs to be online on all whatsapp clones and respond to new messages?0xDEADBEEF said:
Yes, I segregate everything by profiles. You can manage app installations centrally. For example, you can enable or disable an already installed app for a specific profile. Although I have to admit, switching profiles can get tedious at times if you're trying to maintain privacy, but it's definitely more secure. You could have a "family" profile with chat apps and personal photos, while another profile stays free of sensitive information but still has the same chat apps for talking to different people.
Click to expand...
Not a silly question at all. Once you activate a profile, it stays active until you manually close the session. While the session is active, the profile remains online and continues receiving messages. There's also an explicit option to keep the session running in the background. Additionally, you can configure the main profile to receive notifications from other profiles, so you only need to switch profiles when you want to interact with them directly.void said:
silly question perhaps as I don't have the experience (yet) but these alternative profiles are not all online, are they? I mean would it work if one needs to be online on all whatsapp clones and respond to new messages?
Click to expand...
If you need to switch regularly, why not add a second account on the same app?void said:
silly question perhaps as I don't have the experience (yet) but these alternative profiles are not all online, are they? I mean would it work if one needs to be online on all whatsapp clones and respond to new messages?
Click to expand...
I like Session and I do use it. I also use SimpleX which is probably the leader these days in terms of security. But Signal is the most normie-friendly, its interface is pretty much identical to WhatsApp and normies feel familiar right away. They would be a bit weirded out by the other two (unless mass adoption occurs).daniels27 said:
How about sessions and threema? I wonder when proton comes out with a messenger.
Why use Aegis? Just write a script yourself and use proper encryption of the secret.
Click to expand...
Then how about using OCT messages?cherry said:
I like Session and I do use it. I also use SimpleX which is probably the leader these days in terms of security. But Signal is the most normie-friendly, its interface is pretty much identical to WhatsApp and normies feel familiar right away. They would be a bit weirded out by the other two (unless mass adoption occurs).
Click to expand...
While I don't have direct experience of them yet, I see advantages, compartmentalizing your activities more conveniently from the same device. Right now I fiddle with multiple devices. I don't know if GrapheneOS has this built in (I actually use CalyxOS right now), but use a mac address spoofer too, so phone #165153517981 isn't correlated as having connected at this address + that address. Ideally, you'd get to a point where all calls and texts are done online behind a VPN instead of by phone carrier, but if you're talking about SIMs then I assume like me you still need to use them for now. Just make you're not on a registered contract tied to your identity. PAYG is great.void said:
how about dual eSIM + physical SIM - somebody can confirm it works with no issues?
Click to expand...
I don't understand how anyone could go for this... no chance to decide whether it's a honeypot or notdaniels27 said:
Do you think this one is safer?
https://www.4freedommobile.com/phones-3/
Click to expand...