I run a small business and I would like to accept credit / debit card payments on my Android phone running #GrapheneOS

Does anyone know of an app or paired terminal which will work?

SumUp asked me to turn off Developer Tools, but still said the device didn't meet the security requirements for accepting payments.
They offer a Bluetooth paired card reader - but I don't want to spend £30 if it won't work with Graphene.
Anyone have experience *receiving* tap-to-pay on their GrapheneOS device?

@Edent Damn, what a world we live in when a payment vendor says GrapheneOS, an OS built specifically with security in mind, isn't up to their security requirements. 🙃
@Edent @thedarkener The question is whos security is it protecting...
@abeorch @thedarkener
The banks'. That isn't a contentious question. It is their money at risk. They have to refund users. They get to choose their risk profile.
https://shkspr.mobi/blog/2023/05/the-limits-of-general-purpose-computation/
The limits of General Purpose Computation

Should my bank be able to block me from using their Android app, just because my phone is rooted? I'm reluctantly coming to the conclusion that... yeah, it's fair that they get to decide their own risk tolerance. Sage of the Internet, and general Sooth Sayer, Cory Doctorow once gave an impassioned speech on "The Coming War on General Computation". I'll let you read the whole thing but, I…

Terence Eden’s Blog
@Edent @thedarkener I have an idea that there is a #creditunion out there that could scoop up a whole bunch of tech literate high value clients with businesses by offering some banking services based on #openbanking that work with a range of opensource software.

@abeorch @thedarkener
Credit Unions aren't exempt from KYC checks. Like any financial institution, they can be liable if things go wrong.

I'm very pro FOSS and GrapheneOS. But I wouldn't expect a regulated financial institution or their insurers to be so blasé.

But, if you decide to set up a credit union, I'll happily join it.

@Edent @thedarkener I think its more about doing things in a way that work for tech people. Say using a website as primary interface rather than an app.. allowing key based api access etc.

They can still do #kyc