Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

111–120 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#112

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

[deleted]

Re: The Vietnam government has banned rooted phones from using any banking app

#113
post #35

Do those same banks have websites that you can access from a computer with root access? Most likely, yes.

There's a trend of online banks forcing the use of an app. I can't login to one of my banks' website since last year without using a QR code from their app. Of course they slathered the app with tracking, 'security', and analytics SDKs, so rooted devices are rejected. I had no way to log into this bank account after they made that change, which is simply wonderful. Anyways, they're not yet at the point where they've…

This trend makes me want to find a small town credit union.

I chose my current bank because it was one of the few that had proper token based access for 3rd party integration. An overwhelming majority of banks were relying on a 3rd party holding your actual username/password and saying "trust me bro". I wasn't comfortable with that.

Re: The Vietnam government has banned rooted phones from using any banking app

#114

Earlier quoted context omitted.

the banks would care. less money spent on security or dealing with clients who had their money stolen

Are you implying there's a big percentage of people getting their money stolen because they rooted their phones? I'd like to see some data on that if so.

Probably. I know a guy who roots phones for older people or friends parents, installs pirated games and such for them and making sure it is locked down in certain ways for the older generation.

In other words, the correlation is that older people are more likely to have a rooted phone and are more susceptible to fraud.

Dunno how widespread this is, just something to keep in mind.

Re: The Vietnam government has banned rooted phones from using any banking app

#115

Isn't that what happens in Europe with most rooted phones and banks too? At least I can remember my banking apps stopped working.

Most banking apps use a third party security solution . They then often implement Google play integrity .

Re: The Vietnam government has banned rooted phones from using any banking app

#116

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

GrapheneOS is not rooted. Most banking apps work fine on it.

https://privsec.dev/posts/android/banking-applications-compa...

https://grapheneos.org/usage#banking-apps

Re: The Vietnam government has banned rooted phones from using any banking app

#117

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

> you are locked out of the economy?

Not that it excuses the withdrawal of user agency. But I've never used a banking app on my phone before. Anything important I still like to do on a desktop.

Though how much longer that's safe, who knows. Apple's model of requiring their permission to run code on your own device will probably spread to everything given enough time.

Re: The Vietnam government has banned rooted phones from using any banking app

#118

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

Cory Doctorow predicted this outcome back in 2011:

The Coming War on General Purpose Computation

https://boingboing.net/2011/12/27/the-coming-war-on-general-...

Re: The Vietnam government has banned rooted phones from using any banking app

#119
When I used to work on the Vanguard authentication team, we blocked Vietnam from access because of too much fraud (not my choice). But it was funny because we had Vietnam based clients, so there were a couple HNW clients in the logs that you could see who would log in from Vietnam/Russia/Wherever, get blocked, open their vpn, then log in from England. This was a while back, but even then there was a push for things like yubikey, and hardware tokens, so its not surprising the wind is blowing in this direction of just hardware authenticated people. Financial companies are just constantly fighting fraud in a million ways.

Re: The Vietnam government has banned rooted phones from using any banking app

#120

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

Sounds expensive using that hardware, but we can achieve the same using cheaper phones, I like the idea, thanks.
Post reply on HN