GrapheneOS is taking a firm stand against Revolut over aggressive security practices that compromise user privacy. For Pakistani tech enthusiasts and privacy-conscious professionals using custom ROMs, this conflict highlights the growing friction between banking security protocols and user-controlled operating systems.
Key details
- Incident Date: 14 May 2024
- Conflict Focus: Invasive attestation requirements
- Primary OS: GrapheneOS (Android-based)
- Official Website: https://grapheneos.org
- Regional Context: Not applicable for direct installation on local carrier-locked phones
- Cost: Free (Open Source)
Why GrapheneOS is fighting back
On 14 May 2024, the GrapheneOS development team explicitly addressed why users of their privacy-hardened Android distribution are facing issues with the Revolut banking app. The core of the issue lies in 'Remote Attestation.' Revolut, like many financial institutions, uses Google’s Play Integrity API to ensure that a device is 'certified' and not 'tampered with.'
Because GrapheneOS is a custom, hardened operating system, it fails these specific integrity checks by design. GrapheneOS argues that these checks are not a true measure of security, but rather a way for apps to force users into a Google-controlled ecosystem. The developers have stated they will not compromise the core security model of their OS just to appease a banking app's arbitrary requirements.
The impact on Pakistani banking users
Many tech-savvy users in Pakistan opt for GrapheneOS on devices like the Google Pixel to avoid tracking and intrusive data collection. However, the 'beef' with Revolut means that if you are a Pakistani freelancer or expat relying on Revolut, you may find yourself locked out of your account if you are running a custom OS.
For the average user in cities like Karachi, Lahore, or Islamabad, this serves as a warning: before switching to a privacy-focused custom ROM, you must verify if your essential banking apps (such as Meezan, HBL, or UBL) rely on the same aggressive Play Integrity checks. If they do, your phone might become unusable for mobile banking despite being more secure against hackers.
Can this be resolved?
As of now, the situation remains a stalemate. Revolut has not issued a statement indicating they will lower their security requirements, and GrapheneOS has doubled down on its commitment to privacy. The developers suggest that users should pressure banks to adopt more transparent security standards that don't rely on 'black box' integrity checks.
For those who need to use banking apps daily, GrapheneOS suggests using a secondary, stock-Android device for financial transactions while keeping your primary, privacy-hardened device for sensitive communication and browsing. There is currently no official patch or workaround that will bypass this block without potentially introducing security vulnerabilities, which defeats the entire purpose of using GrapheneOS.
