I'm looking for people working at a bank in Europe who are interested in #EthicalTech and who would be interested to help us ensure that banking apps function well on European operating systems. Do you know anyone who might be interested? Please reach out to me via DM!

#DigitalSovereignty #banking #FairTech #banks #finance #tech #buyEU #DMA #DSA #SocEnt #EUtech

#Revolut #bunq #Curve #WERO #IDEAL #ING #ABNAMRO #ASN #Triodos #Rabobank #UBS #HSBC #BNP #Paribas #N26 #Wise #Qonto #BNP #Paribas

@rikviergever @yurukov Can you help out?
Would love to be in touch about this @yurukov if you can help!

@rikviergever

What about Sailfish OS, which is the most used European mobile OS not based on Android.

@bundyo Correct they have the same challenges as us with regards to banking apps! We collaborate with them in addressing this challenge

@rikviergever a quick scan with PCAPDroid shows that the new #Triodos app only connects to ecb.europa.eu and api.triodos.com

So far so good.

I run Android 16 with all google services, including play services disabled and blocked.

@chasalin @rikviergever Triodos also allows standard web access for online banking, without the need of any app, which is the best approach đŸ€—
@meanmicio @chasalin @rikviergever How are transfers approved when using the browser with Triodos?
@darkdragon @chasalin @rikviergever a keyword and, depending con the amount, you will get an SMS code
@meanmicio @chasalin @rikviergever Thanks. SMS are insecure and expensive compared to using a TPM but it might be an acceptable tradeoff when this allows using /e/OS or even Linux smartphones which is often otherwise not possible.

@darkdragon

I have an authenticator device from Triodos. But I keep that at home.

@meanmicio @rikviergever

@rikviergever

I recently installed 3 Dutch banking apps on my Fairphone with /e/OS. Triodos and ASN work without encountering problems until so far.

Rabo app was strange: installing seemed to work, but after closing the app all my credentials were gone. I tried another time, same result. Would be great when Rabo fixxes this.

@tammo yes indeed, we have a lot of apps working with /e/OS today, but we would like to make it 100% ! Therefore my request for contacts at banks.
@rikviergever @tammo Banks app are important, but direct payment apps like #Vipps / MobilePay in #Norway could hopefully also be part of this effort.

@tammo @rikviergever

I discovered that installing the Rabo app via Aurora solves the issue.

@rikviergever There is this maintained list of banking apps compatible with @GrapheneOS (security-oriented Android fork) (cf. https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/).

Some devs behind the Norwegian BankID (essential ID confirmation app in Norway) are approving of GrapheneOS (cf. https://github.com/PrivSec-dev/banking-apps-compat-report/issues/255#issuecomment-2975599573)

Banking Applications Compatibility with GrapheneOS

Maintained Compatibility List for International Banking Apps This list includes banking apps that have been tested, submitted, reviewed, and verified as compatible. LIST | SUBMIT | UPDATE | POSSIBLE WORKAROUND SOLUTIONS Introduction Welcome to the crowd-sourced dataset for GrapheneOS users on currently supported devices. New visitors are encouraged to read the official usage guide on banking apps for comprehensive details about how these apps function on GrapheneOS. IMPORTANT Please read GrapheneOS’s important announcement, officially released on Dec 1, 2023:

@rikviergever I don’t have any contacts at banks, but I started thinking, could this be solved through accessibility requirements?
In Finland you would contact this authority in that case.
https://saavutettavuusvaatimukset.fi/en
Web accessibility | Web accessibility

Web accessibility
@rikviergever I'm not at liberty to get involved but often it's a RASP library maintained by a 3rd party that gives the grief. They're used in the best intent, security *really* matters for a banking app (not only for customer impacts but regulatory consequences) so I get why it's in place. But it really makes it functionally challenging for a key service for many not to be reliable on alternative OSs. Would love to see an open, secure enough, option AND a route for encourage backs onto it.
Geben wir an unsren Entwickler weiter. GrĂŒĂŸe
@rikviergever I wish I could work on something like that
@rikviergever I don't know anybody personally, but I would contact the german GLS bank, which is an socially and ecologically ethical bank. So they might be interrested also to be it digitally.
And present on Mastodon 😉
@glsbank
@rikviergever I know it's a weird thing to ask, but you should create a LinkedIn post about this, as most relevant people are over there. I'd be happy to share too to my many bank IT peers (if the damn thing allows me to log in...).
@rikviergever BNP Paribas Polska worked well for me on both LineageOS/microG and SailfishOS/AlienDalvik/microG! Altough last time I tried was a few years ago
@rikviergever totally agree! Good initiative, although I don't know how I personally can contitrubute, I am curious to hear if you were also considering Contactless/NFC payments in the equation. Most banks stopped their own implementation and went full on Google(/Apple) Pay.
Quite har(/currently impossible) to find a non-big-tech & European alternative.
Just found out that Curve uses an Identity provider that was purchased by an US based company.

@rikviergever

If this issue would be solved with at least a few banks, that would be a gane changer and those would be very interesting to switch too!

@rikviergever

I know that @glsbank are already partnering with @Taler .

Maybe they would be open to such as well.

via @slowtiger

@rikviergever @pojntfx Yes, please! Take a look at the following related thread: https://mastodon.social/@pojntfx/116147290004033654
Note my comments in that thread with references to legal requirements and example APIs of BaaS providers.
@rikviergever
Actually the banking apps i have to use never had problems with Lineage, AOSP-Roms and GrapheneOS. I'm with the Raiffeisenbank, their Online-Banking-App works well as does the TAN-App. The Umweltbank-App also works without a hassle. Only one App refused to work because the OS is "not certified by google", and that is the TeleDoc-App of my health insurance TK.

@jafra @rikviergever TK wrote to me saying that they only trust devices that have been “verified” by Google. They could also have written that these devices are monitored by Google.

Unfortunately, C24 Bank also rejects my /e/OS FP6. This means that I cannot open a joint account with my partner there.

@funqr @rikviergever
Yeah, i know. TK doesn't want to change its way here, i wrote them, too. I guess it's easier to leave verification to google instead of writing something up yourself; I still stick with TK though, because they imho it's one of the few good health insurances.
Don't know about C24, i guess if there's no real need for this bank specifically maybe you can change your bank (resp. your partner).

Another try might be to use Magisk, it has tricks