I am considering changing to an open source smartphone. However there are some apps that I must have, like authenticator, mobile bank and government apps. Does anyone have any experience with any of these brands, what are they like and also is it possible to install android apps?

  • JasonB@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    18 hours ago

    Unfortunately, in the country where I live pretty much everything requires requires a 2fa app from the government and also my job requires a 2fa app in general, so not having those would make the whole device useless.

    • sem
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      18 hours ago

      That is too bad. Scary what the government can do. Sounds like you will need two devices if you care to have one that is open source.

      • dan@upvote.au
        link
        fedilink
        English
        arrow-up
        3
        ·
        18 hours ago

        Scary what the government can do

        Requiring 2FA is a good idea though.

        • sem
          link
          fedilink
          English
          arrow-up
          3
          ·
          17 hours ago

          There are plenty of 2FA apps you can use that aren’t made by the government and will work fine on any phone.

          2FA isn’t the problem. It’s being required to use a specific app.

          • dan@upvote.au
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            17 hours ago

            My guess would be that a 2FA app from the government is likely using PKI (private + public keys) or something similar, rather than a basic TOTP algorithm. There’s not really a generic app for something like that. Many services are moving away from TOTP since it’s not phishing-resistant.

            • sem
              link
              fedilink
              English
              arrow-up
              1
              ·
              9 hours ago

              Nothing is phishing resistant though?

              • dan@upvote.au
                link
                fedilink
                English
                arrow-up
                2
                ·
                9 hours ago

                FIDO2 tokens (like Yubikeys and passkeys) can’t be phished.

                • sem
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  9 hours ago

                  Yes, it’s as easy as with the TOTP app. A message that says “ok, now tell us the code”

                  • dan@upvote.au
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    edit-2
                    7 hours ago

                    FIDO2/WebAuthn hardware tokens don’t use a code. That’s why they’re phishing resistant. You have to press a hardware token (usually plugged in via USB) to authenticate, but it doesn’t do anything obvious on the screen like type a code. On mobile, these tokens usually use NFC, so you just tap the Yubikey or whatever to the back of your phone.