Earlier quoted context omitted.
EMV chip cards still contain your card number and expiry date. Skimmers would need a way to also learn the CVC2 from the back of the card to use it at most (but not all!) online merchants, but that's feasible using a small camera or a waiter/cashier accomplice doing the skimming. With Google Pay and Apple Pay, and similar mobile wallets, that number is never shared during payments (and in fact not even stored on the…
Any responsible user will learn the CVC, like any other password, and then erase it from the card.
Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
171–180 of 232 posts
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#172Okay - so which devices are left that are easily rootable? I will be in the market for new one soon. It's good if EU after mandating usb-c also mandates unlockable bootloaders for whomever wants it.
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#173Earlier quoted context omitted.
CalxyOS is the other one, with less problematic developer history.
Up until your comma the comment suited me just fine, but then... let's not get personal about developers' health issues. It isn't helpful, and there has already been an HN discussion on the topic that you've unfortunately exhumed. There has been great progress at solving problems that had come up during a sad time for GrapheneOS and CalyxOS.
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#174Earlier quoted context omitted.
There has to be a fallback like SMS and/or automated call.
SMS is magnitudes less secure than the Secure Enclave in my phone. Fallback should never be the weakest link in a security chain. Especially not in something as high stakes as your banking login. I can’t remember how I got my first bank token in my phone. Probably by physically showing up in the bank office with my id.
The secure enclave on a rooted phone that no longer has execution integrity?
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#175Earlier quoted context omitted.
There has to be a fallback like SMS and/or automated call.
SMS is magnitudes less secure than the Secure Enclave in my phone. Fallback should never be the weakest link in a security chain. Especially not in something as high stakes as your banking login. I can’t remember how I got my first bank token in my phone. Probably by physically showing up in the bank office with my id.
If your SMS OTP leaks to the attacker, they still need to know the first factor (password, biometrics) to gain access.
Meanwhile, if your rooted phone is controlled by an attacker ... that's it, the attacker has everything.
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#176[flagged]
I'm on a 5 years old phone with Android 14. The OEM stopped the update on Android 11 but the Custom ROM community is going strong. Not only do I now have the latest software that works smoother, but also better camera with GCam, no ads systemwide, better privacy controls through Warden and other similar apps. I just avoided e-waste.
Sounds like a lot of that functionality could be achieved by just buying an iPhone instead. The 6s received updates through 7 major versions.
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#177Earlier quoted context omitted.
So I guess next thing we need is someone sueing the fucking banks that do that. Mine luckily doesn't because I explicitly use an old phone with LineageOS, the banking app, and nothing else on it for online banking. It's arguably way more secure than using your main phone with a bazillion other Apps installed and online at all times.
How would that stick? You can just sign into the bank via your web browser in the case of a nonfunctional app. The apps just give you added security assurances beyond using the web. "The app can't function in a low security environment, but complainant is free to use the web client in such event." case dismissed (obviously an oversimplification, but the point stands)
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#178Earlier quoted context omitted.
This is definitely not the case everywhere. Where I live the app is 100% needed because it’s the „second factor“ in the login process.
Curious, can you name this institution that only allows the app to be used as the second factor without fallbacks?
Well, some offer a hardware device for like 25€ that can do the same thing, but then if you have an account with multiple banks, you need multiple of these devices.
Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#179Re: Asus refunds Zenfone buyer for failing to provide bootloader unlock tools
#180Earlier quoted context omitted.
Bank apps, Netflix, and Disney+ also won't work. There are spoofing measures though I've been burned by unlocking and rooting too often to try again, at least not while my devices are still under warranty.
My solution * use bank website for the one bank that requires it, otherwise I got a new bank account without silly fake security. * thepiratebay has everything Netflix and Disney does and it works anywhere