Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

121–130 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#121
This is likely part of the Vietnamese and Thai governments' rollout of biometric linking for bank accounts, similar to KYC regulations in the United States. The deadline for Vietnamese biometric linking was December 19th, 2025 [1].

The Vietnamese government has reported a rise in account takeovers and other banking thefts [2]. SIM-swapping has been a tactic used. Adding difficulty for fraudsters to trick unsophisticated banking customers is a valid security layer.

1. https://vietnamnet.vn/en/biometric-deadline-nears-millions-o...

2. https://evrimagaci.org/gpt/vietnam-faces-surge-in-sophistica... (expands upon https://vneconomy-vn/techconnect/mobile-banking-phat-trien-manh-tai-viet-nam.htm)

Re: The Vietnam government has banned rooted phones from using any banking app

#122

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

This is a sensible move. Plus you can just keep your "authentication" phone at home instead of having it on you when you're out for no good reason.

Re: The Vietnam government has banned rooted phones from using any banking app

#123

Do those same banks have websites that you can access from a computer with root access? Most likely, yes.

Many people also use their bank's app for mobile NFC payments though (more of a thing in EU than US), which you can't easily do with a device that doesn't fit in your pocket.

Re: The Vietnam government has banned rooted phones from using any banking app

#124
post #20

Unfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.

> Unfortunately the answer here is to not abide by the law

You realize in Viet Nam this means getting a "friendly" visit by the MPS/BCA, and if you continue eventually getting branded as a troublemaker.

Re: The Vietnam government has banned rooted phones from using any banking app

#125
post #20

Unfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.

There won't be a reasonable way to bypass it as it requires a Google authenticated manufacturer to leak the keys or an TEE exploit.

All public key boxes are banned and Google regularly bans new ones . That endpoint contains the list of revoked keyboxes : https://android.googleapis.com/attestation/status

Re: The Vietnam government has banned rooted phones from using any banking app

#126

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

> We are moving to a model where the user is considered the adversary on their own hardware.

That has been the model since day one, since you are using spectrum that, because the end users are not licensed, requires it. Radios in 100% of commercially available phones are locked to prevent user tampering.

You don't get root on your debit card either, despite it running a computer.

Re: The Vietnam government has banned rooted phones from using any banking app

#127

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

I guess you can still do banking on your PC?

I stopped using banking apps on my phones a few years ago - they got more and more annoying, and I don't buy into the "the device is secure and should be used as a trust token". So I'm now back to banking only on my computer, with a hardware token for TAN generation.

Re: The Vietnam government has banned rooted phones from using any banking app

#128
post #53
post #3

One phone for banking and another one for browsing.

You jest, but an actual "digital wallet" device is something I'd quite like to see. Something that's actually secure (like not running an ancient android version that never sees security updates). That only deals with money, without any garbage running on it. That displays and verifies the amount before processing any contactless payments. That supports multiple banks, multiple bank accounts, multiple payment cards e…

> without any garbage running on it

That sounds like a utopia we've passed by on our way here. Maybe it's possible to make such a dedicated hardware device when the digital wallet becomes available for a (mobile) linux distribution or a degoogled android. Let's see when the phone manufacturers think that's a good idea to lobby for

I'm cynical about the whole digital wallet idea because of this. Not that it's not useful, but it's tying your mobile surveillance unit and browser history to an identity on hardware that you are not meant to control

Re: The Vietnam government has banned rooted phones from using any banking app

#129

Earlier quoted context omitted.

the banks would care. less money spent on security or dealing with clients who had their money stolen

Are you implying there's a big percentage of people getting their money stolen because they rooted their phones? I'd like to see some data on that if so.

Perhaps people who unknowingly bought a rooted phone. I don't know how frequent this is, but it would be the only case it would matter.

Re: The Vietnam government has banned rooted phones from using any banking app

#130

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

> does stop malware.

unrelated to phones a lot of (more professional) malware has moved to not persist itself in root space (or at all) as to not leaf traces (instead it will just rely on being able to regain root access as needed every time you reboot with all the juicy parts being in memory only (as in how often do you even roboot your phone))

I think (but am not fully sure) this also applies to phone malware.

I.e. no it doesn't work.

Not unless you

- ban usage of all old phone (which don't get security updates)

- ban usage of all cheap phones/phones with non reliable vendors

- have CHERY like protections in all phones and in general somehow magically have no reliable root privilege escalations anymore

Oh and advanced toolkits sometimes skip the root level persistence and directly go into firmware parts of all kinds.

Furthermore proper 2FA is what is supposed to make online banking secure, not make pretend 2FA where both factors are on the same device (your phone).

And even without proper 2FA, it is fully sufficient to e.g. classify rooted phones as higher risk and limit how much money can be transmitted/handled with it (the limit should ignoring ongoing long term automated repeated transactions, like rent).

There really is no reason to ban it.

Post reply on HN