Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

31–40 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#31

Do those same banks have websites that you can access from a computer with root access? Most likely, yes.

Eventually though I suspect that web access to banks will be rescinded too, much like HMRC in the UK no longer permits companies to submit their taxes through the websites. In the future, everything will need an 'app'.

This seems like a massive jump to conclusions.

Re: The Vietnam government has banned rooted phones from using any banking app

#32

Serious question, what is gained from this move? Why would a government care? Are rooted phones really that much of a problem? Surely most people running a rooted phone are tech enthusiasts. Cybercriminals will just use regular phones bought under false names and dispose of them afterwards.

the banks would care. less money spent on security or dealing with clients who had their money stolen

At the cost of making society even more dependent on Google and Apple.

Re: The Vietnam government has banned rooted phones from using any banking app

#33

Do those same banks have websites that you can access from a computer with root access? Most likely, yes.

yes. and the websites require you to verify transactions with (unrooted?) phone.

on the other hand phone does not require you to verify with your pc, so there's no second factor unless there is some unacessible secure island within the phone itself.

funny enough, you can probably use that website directly on the phone that you use as 2F, which probably circumvents the 2F idea (at least as long as you use SMS 2F instead of app that checks for root)

Re: The Vietnam government has banned rooted phones from using any banking app

#34
post #3

One phone for banking and another one for browsing.

In this economy? /s The other more compelling reason why people would have a rooted phone is to run ROMs that may still be providing OS support where the stock OS has been abandoned or EOL'd by the developer. Having an unlocked bootloader at the minimum would be required in those scenarios. It actually saves hardware that still works from ending up in landfills. edit: spelling

I have a cache of old devices, largely the freebies Google gave out at I/O in the early days of Android. Was prepping them to sell last week and saw most are running Cyanogen (the first big community Android fork). Even then, root was a popular way to gain more functionality and add features that haven't been released for a device.

Incidentally, if anyone wants some collector's edition Google/Android devices...

Re: The Vietnam government has banned rooted phones from using any banking app

#35

Do those same banks have websites that you can access from a computer with root access? Most likely, yes.

There's a trend of online banks forcing the use of an app. I can't login to one of my banks' website since last year without using a QR code from their app.

Of course they slathered the app with tracking, 'security', and analytics SDKs, so rooted devices are rejected. I had no way to log into this bank account after they made that change, which is simply wonderful.

Anyways, they're not yet at the point where they've learned to do the checks server-side. For now it's a one line patch to skip the root screen. But the Play Integrity API is designed correctly, if they learn to use it, there will be no workaround without someone finding a hardware vulnerability somewhere.

Re: The Vietnam government has banned rooted phones from using any banking app

#36
post #6

Smart phones are not personal computers. They're shopping/government/etc terminals. You don't and never have controlled them, even with root (re: tight integration of the baseband computer which only the telco has a license for, not you). Their best use re: computing is acting as wifi hotspot for their cell telco CNAT connection. The time to stop using them as computers is now, not when your local government passes t…

you are right, but you are misplacing the blame. it's not that you dont own your phone, it's that you dont own your bank account and the bank can dictate how you access it

I see your point and it's valid in this context. But both ends of non-ownership contribute. One doesn't own the smartphone and one doesn't own the bank account.

The National Credit Union Federation of Korea (NACUFOK) represents over 800 member-owned unions (https://www.cu.co.kr/english/main.do), and then there is the even larger Saemaul Geumgo (MG) network which operates as community credit cooperatives with millions of members. These people ostensibly own their "bank" accounts.

Re: The Vietnam government has banned rooted phones from using any banking app

#37
post #29

Do those same banks have websites that you can access from a computer with root access? Most likely, yes.

In Hungary, where the central bank created the same rule about not allowing banking apps on "unoffical" devices, they do, but you need either the app or SMS for 2FA. Apparently they consider SMS secure...

The idea is that while SMS may not be "secure" in general, it is secure enough when used as the second authentication factor.

Re: The Vietnam government has banned rooted phones from using any banking app

#39
post #32

Earlier quoted context omitted.

the banks would care. less money spent on security or dealing with clients who had their money stolen

At the cost of making society even more dependent on Google and Apple.

“Every high civilization decays by forgetting obvious things.”

Re: The Vietnam government has banned rooted phones from using any banking app

#40
post #5

I really don't understand this. My line of thinking is that if someone is technical enough to root his phone he understands the risks. Why would they force banking apps to detect and not work on rooted phones? Why would the government care so much?

A rooted phone is more capable of modifying the banking app itself and has 'freer reign' over the APIs that the app uses to interact with the bank.

Whereas previously the app displays a 'whitelisted' set of UI options to the user, the rooted user could use employee only methods. Somewhere or other every bank has methods that set balances on accounts.

To be honest a law like this makes security by the extremely modest obscurity of not having an "increase your balance" button on the app UI much more tempting.

Post reply on HN