Back to stories
news.ycombinator.com

Tell HN: PayPal blocks GrapheneOS

511points byleumon3d
It seems like the PayPal app now refuses to run on GrapheneOS. I don't know if it's only because I have enabled the PayPal card for contacless NFC payments, but when opening the app it crashes with the following exception: com.paypal.oslo.app.rasp.RootDetectionSecurityException: Security policy violation: s=root

Comments

324 total · 178 loaded

Ranked by HN
axegon_3don HN
This is arguably the most irritating thing with just about every largecorp developer: "os that hasn't been updated in 6 years? Sure boss!". Os that is built specifically around security and privacy with daily updates: "No, you can't do that". Annoying - yes. Safe way to make sure I will stop being your customer - also YES!
fluidcruft3don HN
Generally I think the issue is that there's a tension between your security vs Paypal's security (deliberate, motivated bad actors).

Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies. A gun in a good guy's hands is a good thing to prevent robberies. Guns in a bad guy's hands are a bad thing to prevent robberies. Paypal knows you have a gun but they don't know if you're a good guy or a bad guy so it's easier to just ban guns.

That's your argument? Mate, you can make explosives out of stuff you can buy in literally any supermarket and no one bats an eyelash. You don't have to legally be adult to buy any of the things you'd need and I say that as someone who only struggled with chemistry in school, that's now low the bar is. What's the solution then? Ban sea salt? If someone is using Graphene, the chances of them getting hacked are astronomically lower than any Chinese spyware-infested phone.
Yea, years ago I was in the security space and got to talk to some paypal security folks at a symposium in San Diego. The level of stuff that they have to deal with is so extreme.

It's similar to how people don't like sites blocking entire countries or access from Tor, etc. You might be doing it for privacy...but all the people trying to commit fraud are also using those same channels to hide their identity. The blockades are one piece of a holistic security picture that frustrate the well intentioned users.

There's no tension between the security of PayPal against bad actors and support for GrapheneOS. GrapheneOS preserves the whole standard security model and greatly improves security. It's far more secure than anything permitted by the Play Integrity API device or strong integrity levels.

Thankfully, PayPal hasn't banned GrapheneOS and their app still works on it. They accidentally broke compatibility with our secure app spawning feature which has a per-app toggle to disable it along with the other exploit protections which can cause compatibility issues.

There's an overall per-app compatibility mode toggle instead of users needing to figure out which protection is an issue but it's best to figure out the minimal workaround after determining that works.

> Maybe an analogy could be about using metal detectors as a layer to reduce bank robberies.

A more apt analogy might be game developers who demand admin rights so they can install a rootkit to detect "cheating".

The cherry on top is that their web site invariably still works so the refusal to work via app is an intentional manipulation tactic to harvest more consumer data for sale.
I think the issue is more that big tech only trusts their own kind and usually has motives to exclude privacy conscious software because they can't datamine it or make backroom exclusivity deals.

The needs of the user don't matter to them at all.

How does a rooted phone enable bank fraud? This smells like pointless policy checkboxing.
To stay with your analogy, there is no technical obstacle to treating the customer of 15 years differently to the newly onboarded one.

They have all the data they need, and they choose not to use it.

This might make sense if you trusted clients,

and if GrapheneOS was a root-having OS.

this isn't quite true

From a Paypal security POV, weather you use "custom Android OS" or an hugely outdated Android phone, you have:

- a similar risk for the "you" want to mess with Paypal case, in both cases the "you" can technically most likely mess with anything including the "virtual secure module" thingy android uses for NFC

- a lower risk for "others" wanting to mess with Paypal through your phone, at least if "custom Android OS" is GrapheneOS or another up-to-date android fork with decent security handling

so as far as I can tell, this inconsistency is very clearly not about PayPal's security.

IMHO it's about two other things:

1. marketing, if PayPal doesn't work on Android they lose customers, GrapheneOS for now has a tool small customer base for them to care. Outdated Android phone do have a large customer base.

2. compliance/politics BS. including potentially involving insurance. Compliance is mostly about checking of tickmarks(1) on outdated Android they can check them off and blame the user, Goodle or "hackers" for the issue. On GraphemeOS they have a harder time checking it of. Add the smaller user base and end up with PayPal doesn't care. Also iff things go wrong with Paypal on GraphemeOS in a public manner you will have all the "crime os" bad news bs, you won't have that if things go wrong with a even more risky highly outdated Android phone.

-----------------------

I got a bit to much off topic below:

(^1): Technically compliance should be about building robust, secure, law compliant systems and "showing" that by being able to pass a compliance tests consisting about a bunch of requirements. Practically there is way to many ways you can be "fully compliant" (on paper) but not secure and "very secure" but not compliant (wrt. security regulations). In the former case this might still come back and bite you iff you get sued or people suing which should get right don't get it because of ad-absurbum reasoning like "they comply with security regulations, hence can't have acted negligent". It's a shit show I don't know how to fix even if I could just magically change laws as compliance rules need technological flexibility, but if you give them that that will be abused to make insecure things pass. And the whole industry around checking that isn't really one who cares about actual security, sometimes outright corrupt (like groups which have the necessary accredited to check your compliance, are strangely more expensive then other groups, and somehow find less issues in average, with some excuse of why that isn't strange ...) :/

---

Lastly similar to how Teams or Slack could easily support FF (^2) but not only don't but outright refuse to try to even work. PayPal likes to act similar and doesn't care about niches. E.g. at least on some Mobile browsers WebAuthn works, but the PayPal website refuses to _even try_ 2FA with WebAuthn on mobile no matter if the APIs are there or not.

(^2): Yes there are some challenges, AFIK especially in certain edge cases most user might never run into. But Jitsi made it work, other smaller apps also made it work. And Jitsi is open source, so they technically can "look up" all the tricks to make it work (algorithmic ticks, not copy-pasting code) or outright just use their system with an appropriate contract (probably would be even cheaper wrt. maintenance cost then building your own system). At Slack/MS Teams scale that behavior is just messed up.

Paypal's security? the same "security" which in 2026 still does no allow a passwords above 32 character (which most likely indicating that they don't hash passwords)?
PayPal app still works on GrapheneOS.

It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.

The first thing to try when an app doesn't work is trying the per-app exploit protection compatibility mode. That sets all the per-app exploit protection toggles to the compatibility mode. If that works which is likely the problem, it can be narrowed down.

Nearly all Android apps are compatible with GrapheneOS. The exception are around 10% of banking and government apps which use the Play Integrity API to ban using a non-Google-approved device or OS. That's visible to users on GrapheneOS via a Play Integrity API usage notification. After the first use by an app, GrapheneOS provides a menu for blocking using the Play Integrity API which sometimes gets apps working because many don't enforce it working. It's not fully reliable and can have downtime so apps often don't enforce providing a result.

It was never about your security, it was about the corporation's security from you!
The safety isn't for you, it's for the companies who want your data without you getting in the way.
fmajid2don HN
Revolut pulled that stunt, I cancelled my account with them.
This one is pretty interesting. I was ready to cancel my account on the spot when the news popped up but it still works on my phone. And I've updated the app as many times as they've made a release since the announcement. I honestly haven't got a clue what is going on with them.
It's not about protecting your security, it's about protecting the "security" of corporate profits.
Might be more a matter of "OS with millions of users" vs. "OS with dozens of users".
The largeCorp developer and their PM are many orgs and layers away from where these decisions are mandated.
tonyhart73don HN
"Safe way to make sure I will stop being your customer - also YES!"

I don't think they care at all about the size of graphene os market share

if its jeopardize entire userbase then its not worth it

Fine by me. My example illustrates their incompetence if they are willing to let a user with an OS that hasn't received any updates in half a decade, then clearly, they don't give a single crap about security.
With the way today's economy works, they probably wouldn't even care if they lost 1/4 of their customers in just one year. Maybe their share price would jump!
I'm sure their automatic bans have happened to more people than the number of grapheneOS users
With Silicon Valley "largecorp" the required "security" is to protect the company from (a) the privacy-conscious user who would object to the company's data collection, surveilllance or ads/tracking and (b) from competitors, i.e., other companies that would potentially do data collection, surveillance, advertising services if they had uncontrolled access to largecorp's users

"OS that user compiled herself" can avoid this nonsense

No "smallcorp" is safe from Silicon Valley "largecorp" for long with the amounts of money SV largecorp can, and will, offer smallcorp if smallcorp grows. SillyCon Valley "largecorp" wants data about/from users, not users' money

"Safe way to make sure I'll stop being your customer - also YES!"

The user is not SV largecorp's customer

zerof1l3don HN
I see this happen from time to time. Lately, almost all of the apps work fine on GrapheneOS. The best strategy is to keep writing the business once every two or so weeks that you can’t log in to and use the app. Don’t go too technical at first, because most of the time, the moment they hear things like “rooted” or “unofficial,” they just say your phone is the issue. To date, I was able to convince, or at least contribute to, making three apps work on GOS.
dvoros3don HN
I had the same experience. Asked in an email why an important government app won't work on GrapheneOS, first without any technical details. Got the response that it's "because security". I sent some technical details and argued that they're denying service to their most security-conscious users. 3 months later the app started to work!
To be fair, governments might be much more receptive to the argument of not having to rely on (possibly foreign) megacorporations than a company like Paypal.

I'd wager that if it doesn't really hurt their bottom line to not support GrapheneOS, they won't really care.

Great job, man. We have to make ourselves get heard. It's a social problem after all. Technical workarounds are great and sometimes the only practical short term option, but we have to fix the social issue at the root.
I think in this case it's also them just introducing a new check that either GrapheneOS will need to work around or Paypal needs to refine. I can reproduce the issue, but it doesn't seem like it did a failed Play Integrity check at that point.
Would you mind elaborating a bit on your process ? Or share a few relevant exchanges, I've no clue how to start having this discussion.

That would make a great blog post

My backwards bank blocked my mobile app access after detecting Debugging was enabled in the system. Have to call them to unlock it. I could download that APK and disassembly it with an LLM in 20 minutes, but sure, a Debug mode prevents something.
Which is the opposite reaction for PC problems, because people actually have choice and historically don't accept malware being the default
Honestly there's a decent chance they don't even know, in most cases, because corporate environments generally try hard to have as few as possible hardware/software setups to maintain. And they're unlikely to proactively test on Graphene unless it's closely related to what they do (and it definitely is not for most apps).

Mistakes happen and ya can't fix what you don't know about. Always report issues.

Also strongly consider just using the website.

StrLght3don HN
Still works for me.

I had to update exploit protection after their latest update — I think it was enabling dynamic code loading via both memory and storage that did the trick.

Edit: checked now, I have also disabled secure app spawning.

Retr0id3don HN
Interesting, just inferring from that it sounds like GrapheneOS's actual-security features might have been tripping up PayPal's root-detection "security" features.

(Rather than something fundamentally incompatible, like them using Play Integrity)

There are valid RASP techniques that involve dynamic code loading, so it actually makes a lot of sense. Source: I worked on RASP a long time ago :)

IMO headline is very misleading, and OP should have tried disabling all exploit protection options before jumping to any conclusions. PayPal isn't actively trying to block GrapheneOS as of now.

codethief2don HN
Still works for me, too, and I haven't disabled any of Graphene's security features.
Based on user reports, there are recent updates to PayPal requiring disabling the per-app secure spawning toggle. It already required not enabling some of the other protections which are opt-in for user installed apps.

Secure spawning doesn't cause compatibility issues with non-buggy apps (unlike blocking dynamic code loading via memory/storage or native debugging) and apps rarely have issues with it (unlike memory tagging, which finds lots of bugs) so it's on by default.

It works here. Running in a work profile, no contactless payments.

Play Integrity API: Not blocked

Hardened memory allocator: Enabled

Memory tagging: Enabled

Extended virtual address space: Enabled

Secure app spawning: Enabled

Native code debugging: Allowed

WebView JIT: Disabled

Dynamic code loading via memory: Allowed

Dynamic code loading via storage: Allowed

dathinab3don HN
> no contactless payments.

I think this is the problem here.

A lot of NFC related tech is deeply rooted in having "trusted (aka large company)", "attested (aka you can't easily lie)", secure module functionality.

What should have happened is to just not enable the contactless payment functionality for given app, even if the user enabled it in general. And not crash.

Also as others have pointed out, this might be an accidental mishap not an intended outcome.

But it's not like PayPal is known to care about small user-base edge cases (quite the opposite). Which I guess is the actual root problem.

The issue turned out to be PayPal adding incorrect anti-tampering code incompatible with our secure app spawning feature. It's common for anti-tampering code to break real security features. It's a major reason for us having the per-app compatibility mode toggle and the finer-grained toggles for the individual exploit protections known to be incompatible with certain apps,
microtonal3don HN
Doesn't work here. No contactless payments, full Exploit protection compatibility mode.
This is the PayPal version I have installed that works:

Version 8.107.0

com.paypal.android.p2pmobile

This is my setup as well, though with JIT enabled (which is the default). Crashing at launch on:

    version 10.10.0

    com.paypal.android.p2pmobile
    versionCode 1160090162
Seems pretty likely a flawed root detection being rolled out (given the stack trace), my phone is not rooted.
sdcfgy3don HN
I'm starting to see these restrictions as a deterrent for using the products in question. My GOS handset is slowly fizzling away into a dumbphone with Firefox, organic maps and k9. And you know what, I am starting like it.
The vast majority of Android apps work on GrapheneOS. App compatibility is not diminishing in any significant way. We've improved app compatibility faster than Play Integrity API adoption has happen, which this isn't.

PayPal's app still works with our per-app secure spawning toggle disabled. It's a bug in their anti-tampering code.

aabdelhafez3don HN
Switched to Wero and haven't looked back.

https://wero-wallet.eu

Wero is not a PayPal alternative. It doesn't even have buyer's protection and every bank must manually implement it which immediately makes it a failure. Some banks also connect it to your phone number so you can't link Wero to two different bank accounts with the same number when you have 2 bank accounts. Very messy.
Unfortunately peasants like us who don't live in the 5 countries where it's available still can't look back
You need to use your bank's app for Wero, and many EU banks' apps refuse to run on GrapheneOS for the same reasons as PayPal. This is sadly not a clear win for Wero.
wait for it... I can see a future were every wallet, payment etc. app will block devices which are on custom ROMs and do not pass strong hardware integrity with blessing from Google.

I've read once that there are paid app testing labs which test if an app has root and custom ROM detection and when they don't have that it's a minus point on the report.

Sadly, not even close. I would even dare to say that Klarna is closer to what PayPal is, than Wero.
The website is pages and pages of blankness for me on Firefox mobile.
I'm on Debian Testing sometimes on amd64 and sometimes on m1. Paypal also doesn't like me. Than I have two options: I use a Windows VM to do the payment or I use another payment method. Most of the time I use the other payment method.
Can it still run in browser like it would on a regular pc?
Yes, but the app still works on GrapheneOS. They accidentally broke compatibility with the default settings with incorrect anti-tampering code. Disabling the per-app toggle for secure spawning works around it.

We have per-app toggles for exploit protections known to have compatibility issues. Secure spawning wasn't expected to cause any compatibility issues so we didn't have a per-app toggle for it until recently but it's available now.

Yes, but you might have to enable desktop mode on a mobile browser so it doesn't try force-spawning the app.
I have never been a crypto currency advocate, but if the banking utility of a mobile phone is going to be dictated by the operating systems that finance apps whitelist, I might want open rails that work with my open phone
onion2k3don HN
Has PayPal blocked GrapheneOS, or have they blocked every OS they're unable to verify and done a poor job of implementing their checks?

Hanlon's Razor is a useful tool. https://en.wikipedia.org/wiki/Hanlon%27s_razor

The very fact they've managed to convince anyone that checking what OS I decide to run on the devices I own to check my own banking is any of their concern is a problem in and of itself.
It is a useful tool, but is largely irrelevant to this issue. To the end user, this isn't really much of a difference. Whether the cause is malice or simply not choosing to use the smallest effective brush, they are still taking an action that is preventing legitimate users from accessing the service.
Ironically, I had to apply Hanlon’s Razor to the impolite tone of your post
PayPal accidentally broke support for GrapheneOS with the default settings for the app by adding incorrect anti-tampering code. It can be worked around using the per-app toggle to disable secure spawning. It shouldn't be necessary and we didn't expect there to be apps incompatible with secure spawning so we didn't originally design it to have a per-app toggle and had to add it.

Several of the more aggressive exploit protections are enabled for the base OS but are opt-in for user-installed apps. Memory tagging should work with all user installed apps but is opt-in because it's so good at detecting invalid memory accesses and uncovers a lot of bugs. Dynamic code loading via storage, dynamic code loading via memory and native debugging are allowed by default since a significant fraction of apps need those and it's not usually a bug. Users can set those as enabled by default for user installed apps which is particularly recommended for memory tagging but then people need to deal with the incompatibilities. The defaults don't cause issues with most apps so not everyone is aware of the per-app toggles.

You're a banking app. Why do you need to check my phone or my os? The security is not in what phone I use, but in how sane your 2-factor auth is and if even exists.
Hanlon's razor is for people. Organizations do not operate like people and do not deserve the same deference.
> have they blocked every OS they're unable to verify

This is evil in itself.

They have blocked rooted phones based on the error provided. Nothing to do with verification. They treat rooted phones to a level they don't with phones without critical security updates. That's the tension. Non-rooted phones aren't necessarily unsafer.
prartichoke3don HN
Confirmed on my phone too. I left a 1-star review on the play store saying it crashes on every launch, uninstalled and will use the website from now on. (Luckily, I dont use contactless payments, ai just send and receive money from friends from time to time)
You can solve it with the per-app toggle for disabling secure spawning. PayPal only accidentally broke compatibility with secure spawning. You should still complain to them about it.
I tried it on my Pixel 10 Pro XL as well. Latest version of GrapheneOS, latest play store version of the app and it works.

Even tried completely nuking app data and logging in again. Login, security check, fingerprint setup, everything worked (I even got the alert that it used the Play Integrity API)

I assume if anything, this is probably the contactless payments. I do somewhat understand why they are really trying to lock something like this down, but as everyone pointed out, giving the green light to a CVE infested version of Android while prohibiting the use of a version that goes above and beyond when it comes to security is absurd.

The issue turned out to be PayPal adding incorrect anti-tampering code incompatible with our secure app spawning feature.
bit19933don HN
I was always suspicious of GrapheneOS, thought it was too good to be true. But this makes me reconsider and want to install GrapheneOS.
Thankfully, PayPal hasn't banned GrapheneOS and their app still works on it. They accidentally broke compatibility with our secure app spawning feature which has a per-app toggle to disable it along with the other exploit protections which can cause compatibility issues.

There's an overall per-app compatibility mode toggle instead of users needing to figure out which protection is an issue but it's best to figure out the minimal workaround after determining that works.

it is great and you know that because cops are pissy about it
I think if paypal not working on GOS makes you not use it, then GOS is definitely not for you...
bdzr3don HN
I also ran into the eBay application being blocked just recently. Other than that I've had no issues, but I imagine this is going to become more and more common as time goes on.
Most likely, unless the GrapheneOS user base can be grown quickly. We are at a point in time where the number of apps that block GrapheneOS through Play Integrity Strong is fairly small. So it's still possible to grow the user base since the inconvenience is not too large. Once the majority of banks would require passing Play Integrity Strong, far fewer people would switch.

So, best to grow the user base fast now and let every user send a complaint for every app that gets blocked. A few million users will be harder to ignore.

PayPal's app still works with the per-app secure spawning toggle disabling for it.
eBay has been enforcing Play Integrity for over a year now. Luckily you don't lose much by using it in a browser.

I also get why they'd be desperate to fight bots. It's a weak excuse for not doing it better, but at least it makes some sense.

Have you explicitly enabled root access? GrapheneOS does not do so by default, in fact their documents explicitly mention that enabling root access weakens the OS's security posture. Many app protection frameworks detect root access and block by default.
savwolf3don HN
This is what really makes me question if I want to continue to use GOS, already some UK banks apps (which are app only) don't want to run. I'm considering switching back to stock as I can't be bothered to try to find hacks and workarounds for daily necessities.
I would never use a bank that is app only. Sounds like a horrible experience.
PayPal's app still works with our per-app secure spawning toggle disabled. It's a bug in their anti-tampering code.

Have you tried the per-app exploit protection compatibility mode or the finer-grained toggles for those apps? 90% of banking apps work on GrapheneOS but MANY have problematic anti-tampering code requiring the per-app compatibility mode.

Same experience in the UK, but it was the push that got me to switch from Lloyds to Nationwide if you're looking for another option. They're great, they even have offline 2FA methods as they send you a card reader for things like authing purchases or sign-ins. And the app still works :-)
onaclov20003don HN
Dumb idea, but I wonder if the underlying os can see who is asking questions like do you have root, And if an app has no need to know, it just plays dumb and responds...of course not. It's a bit of a chicken and egg problem, in that if you don't know what apps need to know if you have root, or not, then you can't determine that at the OS level...maybe an option for the user (popup) to tell the program, tell them we are rooted or not? (Or a settings page you can determine what apps can know root or not)
That's exactly how modern Android rooting tools work. You select which apps you want to have root, in a manager app. No other app should be able to notice.

But GrapheneOS isn't root, that's just PayPal's thing being broken.

GrapheneOS isn't rooted. The issue is their flawed anti-tampering code shipped a new bug breaking compatibility with secure spawning. We have a per-app toggle for secure spawning due to seeing this with other banking/financial/government apps and it works for PayPal's app as the original poster discovered.

If they want to ban arbitrary operating systems, they can use attestation and it can't be fooled the way you're describing. Apps doing this can explicitly verify GrapheneOS and we've convinced some apps to do that. We've also convinced a smaller number to stop doing that at all.

The best approach to combat this is to cause as much headache as possible: bombard them with 1-star reviews, contact news sites, post this on social media sites snd contact Paypal's support.
It can be worked around with the per-app secure spawning toggle. Ideally people should still complain and get them to fix it.
steveharman2don HN
Isn't this more about PayPal disliking a rooted device rather than Graphene? I used to have all kinds of issues with financial apps when I was rooted, regardless of OS
It's been explained in this thread many times: not-rooted
GrapheneOS isn't rooted. The issue is their flawed anti-tampering code shipped a new bug breaking compatibility with secure spawning. We have a per-app toggle for secure spawning due to seeing this with other banking/financial/government apps and it works for PayPal's app as the original poster discovered.
Flawed root detection issues are kinda common to see when running Graphene, tbh I suspect this is just an accident - it very much is not the first time, nor the first for PayPal.
hkt2don HN
This happened to me with Starling Bank's app years ago. I have since conceded defeat. What is pernicious is how some of these services are unusable without an app, while also bossing the user around about what operating system they can use. Starling left me without any access to any of my bank accounts at the time (2022 or so) so now I use very old school online banking now to avoid this situation ever occurring again.
I still remember when my bank wanted me to run Android 9 instead of my Android 15 rom (without root) on my Samsung S8 because "muh security!!"

Funnily enough, the only way to hide those detections was to Root my phone... And i still remember when i had an appointment there, they wanted to see something in my Bank app, i opened it (and i assume it had an update since i then last used it) and a big "THIS DEVICE IS NOT SUPPORTED. ROOT IS NOT SUPPORTED" poped up

But was as simple as readding the bank app to my root hiders.

but still, i hate this security theater

It might involve the Google Play Integrity API.

GrapheneOS officially passes only the MEETS_BASIC_INTEGRITY tier of the Google Play Integrity API and fails the MEETS_DEVICE_INTEGRITY and MEETS_STRONG_INTEGRITY levels.

Many banking apps I use in my country require this level plus something from the GPI API, which makes them unusable. You need a regular, unmodified smartphone to use them.

I still don't understand why people atill use paypal. It has veena shitty and shady company from the start and never got any better. They are known thieves that use political games to illegally seize money and get to keep it until you "prove" that $100 is yours and not used for random bs like "terrorism".
I remember when I had to boot up an old windows machine because TurboTax refused to run on a Linux (might have been something related to flash as well... been too long to recall), then I just ran Windows in a VM, then extensions allowed me to do User-Agent spoofing (honestly should have thought of this sooner), and now they don't seem to care at all. I did my taxes on OpenBSD last year.
varispeed3don HN
This should be illegal, but it won't. Corrupt politicians want people to be only on the approved operating systems so they can be surveilled.
It does still work. It's just a bug in their anti-tampering code breaking it with secure spawning. Using the per-app secure spawning toggle or broader per-app exploit protection compatibility mode resolves it. PayPal should fix their code.
schnittbrot3don HN
I've been using it in the browser with GOS no problem. Any reason why one would need the app besides a little more convenience?
They require the app for certain things like managing which PayPal debit card category gets 5% cash back
The app can still be used too but requires the per-app secure spawning toggle with recent app versions. It's due to PayPal shipping buggy anti-tampering code.
Helmut100013don HN
Why do you need PayPal APP? I have grapheneos and just tested logging in to PayPal web. Works.
Some features are app specific such as tap-to-pay, which does work on GrapheneOS. PayPal's app still works with the per-app secure spawning toggle disabled. It's a bug in their recent updates causing an incompatibility with secure spawning and they should fix it.
This wouldn't be that bad if they had a functional website you could use instead, but their website doesn't even let you do things like pick your monthly rewards category or configure auto-replenish for your debit card.
PayPal's app still works with the per-app secure spawning toggle disabled. It's a bug in their recent updates causing an incompatibility with secure spawning and they should fix it.

Tap-to-pay is unlikely to be provided via their website and does work on GrapheneOS.

jordand3don HN
I've disabled auto-update for PayPal in the Play Store and also Disabled the app locally (so I can re-enable when rarely needed). They'll force people to update soon enough given how banking apps are.
The latest updates still work on GrapheneOS with the per-app secure spawning toggle disabled. It's a bug in their anti-tampering code.
dennemark3don HN
Looking at the description, the title should be changed to "Contactless PayPal card does not run on GrapheneOS"

I use latest Aurora Store PayPal version and it still works. I just dont use contactless payment.

I'm not using the contactless payment feature and get the same crash and error.
It's not specific to contactless payments. It's a bug in the app and still works with the per-app spawning toggle disabled. The per-app exploit protection compatibility mode sets all these toggles to the compatibility mode but it's best to figure out the minimum required.
Kwpolska3don HN
Why would anyone still use PayPal after so many cases of accounts being banned and funds being frozen for no reason, and all the other terrible stuff they've done?
Easy to say when you are in a country where you have a lot of options.

There's some countries with very bad financial sector where your option is PayPal or Western Union as the local banks don't know how to do international transfers, Remitly doesn't support all countries and Wise also doesn't work. PayPal works, even if they charge fees.

Critical mass? I had to start using it after moving to Germany, because everyone else expects you to use it.

One of the ladies at daycare is leaving? Here's a paypal link to chip in for a good-bye present.

Split a take-out order with a German friend, but he paid? Here's his paypal to send him your share.

It's just assumed that everyone has paypal over here...

I simply use it as an intermediary between my bank and any website I don't fully trust
For the unbanked, PayPal is like Chime and Cash App. A quick way to be able to deposit incomings and get a debit card where you can spend them.
because global-ish exchange of goods and services for money is a deliberately convoluted experience that only a handful of well-connected entities are allowed to facilitate, which enables each and every one of them to put "we reserve the right to fuck you in the ass for any or no reason" in their ToS.
kova123don HN
How is it that PayPal is still relevant? What does it even offer these days that other platforms don't do better?
PayPal and Curve Pay support tap-to-pay on GrapheneOS in Europe where they have it deployed. Google Pay bans using GrapheneOS for it via the Play Integrity API. Most banks only support using Google Pay rather than having an alternative in their apps. Many European banks have an alternative.

PayPal's app does still work on GrapheneOS, they only accidentally broke it with the default settings due to bugs in their anti-tampering code. Disabling the per-app exploit protection compatibility mode works around it. They should fix it and start testing on GrapheneOS.

zache63don HN
It works for me after enabling exploit protection compatibility mode. Pixel 9a on latest versions of GOS and PayPal.
With the default settings, the latest versions of PayPal only require disabling secure app spawning.

It may also require dynamic code loading via storage, dynamic code loading via memory and native debugging being permitted but those aren't blocked for user installed apps by default. People can opt-in to those being enabled by default for user installed apps similarly to memory tagging, but memory tagging has the biggest positive impact.

tombardier3don HN
Still works on my up to date pixel 9 xl. I haven't enabled NFC payments though
Their recent updates require disabling secure spawning via the per-app toggle, that's all. NFC payments still work.
taegee3don HN
Still works fine for me. PayPal and GrapheneOS are both on the current release.
PayPal's app requires disabling the per-app secure spawning toggle for it now due to buggy anti-tampering code. You may have already enabled the per-app compatibility mode which includes that.

You may also not have the update yet. Play Store supports staged rollouts where updates are only available to a set percentage of users.

7r333don HN
P10F, 2026081301, Aurora Store, secondary profile, flawless. Try harder.
It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
this is actually irritating. I can't even root my phone without everything breaking
chmod7752don HN
Works just fine for me on an unrooted Pixel 10 Pro.
PayPal's app requires disabling the per-app secure spawning toggle for it now due to buggy anti-tampering code. You may have already enabled the per-app compatibility mode which includes that.

You may also not have the update yet. Play Store supports staged rollouts where updates are only available to a set percentage of users.

cactusbee2don HN
Ah, that is why it was crashing on my device :(
PayPal's app requires disabling the per-app secure spawning toggle for it now due to buggy anti-tampering code.
gib4443don HN
With or without Google Play Services running?
With. But disabling "Secure app spawning" seems to fix it for now.
It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
bookofjoe3don HN
I would bet that fewer than 1/1,000 non-HN users have ANY clue what it means to root a device. I sure don't!
GrapheneOS doesn't involve rooting a device. It's a privacy and security focused OS for hardware with official support for using another OS.
ethagnawl3don HN
Does the website still work?
Yes, but PayPal's app still works on GrapheneOS too.

It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.

hd43don HN
did you re-lock the bootloader?
It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
1970-01-013don HN
Funny how PayPal don't trust you to safely handle root but they will trust you to pay thousands in loans, credit, etc. What a joke.
PayPal still works on GrapheneOS.

It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.

hoshi733don HN
Did you try enabling the exploit protection compatibility mode in the app settings? GrapheneOS should have shown you a Play Integrity API detection notification if the app is actively trying to block non-GMS-certified devices using Play Integrity API.
This is a correct answer despite the fact that it was previously hidden by flagging. PayPal's recent updates with incorrect anti-tampering code work fine on GrapheneOS when secure app spawning is disabled. It's best to disable only secure app spawning (exec-based spawning) for it instead of using the whole compatibility mode. Using the whole compatibility mode is the first thing to check before narrowing it down though.
freakynit3don HN
[deleted]
GrapheneOS isn't rooted. PayPal works on GrapheneOS and doesn't try to ban using it. However, they recently shipped incorrect anti-tampering code incompatible with our secure app spawning feature (exec-based app process spawning). It can be worked around by disabling the per-app secure spawning toggle for PayPal. For simplicity, there's a per-app exploit protection compatibility mode toggle which sets all the finer grained exploit protection toggles to the compatibility mode.

GrapheneOS is an operating system rather than read-only memory firmware. There's a ROM in early boot (boot ROM) which loads the SoC boot firmware from the SSD which loads other SoC firmware from the SSD and then loads the OS from the SSD.

Well I haven't rooted my device. It's just normal grapheneos
iirc grapheneos can't be rooted unless you do your own build
Isn't it more likely to be saying that the app is running with root privileges?
deepc4life2don HN
[deleted]
It doesn't defeat the purpose of GrapheneOS. GrapheneOS does not require people to do all their financial transactions with Monero to heavily benefit from it.

Their app can also still be used on GrapheneOS. It just requires the per-app secure spawning toggle due to a recently added app bug.

BoredSmurf2don HN
[deleted]
Android remains open source via the Android Open Source Project.

The vast majority of Android apps including PayPal work fine on GrapheneOS.

PayPal recently shipped incorrect anti-tampering code incompatible with our secure spawning feature. The feature spawns app processes with exec to provide their own address space layout randomization, random memory tags and canaries. We're aware of these kinds of incompatibilities and provide a per-app toggle for exec-based spawning which works for PayPal. PayPal made a mistake and didn't consider GrapheneOS as part of this recent change. They'll likely fix it since they don't ban using GrapheneOS and likely want it working on GrapheneOS.

jadar3don HN
[deleted]
GrapheneOS isn't rooted. It's caused by their anti-tampering code being buggy and recent releases of the app wrongly detecting secure spawning as tampering. We have a per-app secure spawning toggle due to these issues and that works around it.
GrapheneOS doesn't give you root access.

The OS is designed to offer privacy and security guarantees, which root access breaks, so they don't offer it.

A normal GrapheneOS installation uses Android Verified Boot with a locked bootloader, and does not give the user root access. Google's Play Integrity cannot be used to verify the integrity of the OS (as GrapheneOS is not approved by Google), but equivalent verification can be done using standard Android APIs and GrapheneOS's public keys.
I wonder do you have administrator access on your Windows/Mac/Linux?

Because your argument sounds like you gave the admin password to someone else to prevent yourself from tampering with your computer for the security reasons

nunobrito3don HN
[deleted]
PayPal works well on GrapheneOS. PayPal shipped incorrect anti-tampering code wrongly detecting our secure spawning feature as tampering. It works fine when the per-app toggle for secure spawning is disabled. These incompatibilities with hardening features are relatively common in banking apps. We provide an overall exploit protection compatibility mode toggle for ease of use rather than people needing to figure out which feature is incompatible.

GrapheneOS has never received or applied for any government grants. It doesn't have any involvement with any governments. GrapheneOS is banned by the Play Integrity API device and strong integrity levels. In practice, the only app compatibility issues which can't be worked around with our compatibility issues are apps adopting the Play Integrity API to enforce those.

It does work for me on lineages for microg with an Xperia 5 II. Haven't tried to activate contactless though.
iqra_c2don HN
[deleted]
PayPal doesn't ban GrapheneOS. They accidentally broke compatibility with secure app spawning (exec-based app process spawning). It can be worked around by disabling secure spawning for the app. That's done automatically by the simple per-app exploit protection compatibility mode which sets all of these exploit protection toggles to the compatibility mode.
12ahs713don HN
[deleted]
It's because PayPal shipped an update with incorrect anti-tampering code incompatible with secure app spawning. It can be worked around with the per-app secure app spawning toggle until they fix it.
Showing the first 178 comments to keep this page fast. Continue on Hacker News.