Earlier quoted context omitted.
That seems to be the way the wind is blowing. Most new 'challengers' I've tried in the US either have no web access at all, or limited access that lets you view balance but not do things like transfers.
Recalling Venmo winding down web beginning in… let’s see… 2018! https://www.digitaltrends.com/phones/venmo-shutters-web-plat...
The Vietnam government has banned rooted phones from using any banking app
171–180 of 643 posts
Re: The Vietnam government has banned rooted phones from using any banking app
#172So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…
> does stop malware. unrelated to phones a lot of (more professional) malware has moved to not persist itself in root space (or at all) as to not leaf traces (instead it will just rely on being able to regain root access as needed every time you reboot with all the juicy parts being in memory only (as in how often do you even roboot your phone)) I think (but am not fully sure) this also applies to phone malware. I.e.…
Re: The Vietnam government has banned rooted phones from using any banking app
#173Earlier quoted context omitted.
That probably means giving up the ability to mobile deposit checks - every bank I've ever had only allows that through their app.
What's a mobile deposit and why do you need an app to check it?
Here in the US, I still get checks frequently enough that it's nice to have.
Re: The Vietnam government has banned rooted phones from using any banking app
#174Earlier quoted context omitted.
As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…
the iPhone still does bluetooth transmissions/pings even in airplane mode (the find my device thing) and no way to disable the only way to disable any transmissions is to turn off the device
Re: The Vietnam government has banned rooted phones from using any banking app
#175When I used to work on the Vanguard authentication team, we blocked Vietnam from access because of too much fraud (not my choice). But it was funny because we had Vietnam based clients, so there were a couple HNW clients in the logs that you could see who would log in from Vietnam/Russia/Wherever, get blocked, open their vpn, then log in from England. This was a while back, but even then there was a push for things l…
I'd be really interested to know whether a significant amount of fraud and fraud attempts involve devices with root or non-stock operating systems. This has always struck me as a matter of checkbox compliance rather than a commonly-exploited attack vector, though I'll grant that's partially because few people actually use such devices.
Re: The Vietnam government has banned rooted phones from using any banking app
#176So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…
Re: The Vietnam government has banned rooted phones from using any banking app
#177Earlier quoted context omitted.
It's true that GrapheneOS is not rooted, and, unlike other non-rooted custom ROMs, allows re-locking the bootloader. But , whether a banking app will work depends on what level of Google Play attestation they require. While most banking apps work fine on it, a significant minority do not.
To be fair, this seems to be mostly a European problem. U.S. banks do not seem to enforce Play (dis)Integrity.
Re: The Vietnam government has banned rooted phones from using any banking app
#178Earlier quoted context omitted.
Depends on what country you're in. In the UK, the banks are often held liable for various scams that involve the transfer of money, so they up the security over and over again. A bank will rightly argue why it's responsible for an old granny sending her life savings to her new lover in Namibia, so it seeks to block that transaction in the first place. Some of that liability is fair but most of it is the government te…
Rooted devices don't enable that transaction. That's all social engineering.
Go back fifteen years and malware is absolutely submitting bank transactions after the user does a 2FA.
https://krebsonsecurity.com/2010/03/crooks-crank-up-volume-o...
Re: The Vietnam government has banned rooted phones from using any banking app
#179Unfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.
I'm assuming you would do this out of a political reason, or as a very technical and privacy aware user. But you are providing an alibi for malicious users who, for example, might try to brute force logins from unidentified devices. That would be one reason aside from the law. You are essentially positioning yourself on the same side as intruders.
You should personally immediately return any computing device where you have control, this line of reasoning is insane
Re: The Vietnam government has banned rooted phones from using any banking app
#180>The Vietnam government has banned rooted phones from using any banking app The Vietnam government has banned phones under their user's control from using any banking app.
If the banking apps have a Terms of Service, you are free not to use the banking app. To give a specific example, suppose a banking app wants to require location services in order to try to login. Some users can bypass or spoof this, (in fact that's what the thread is about entirely, and for that they root the phones. Not all users who root the phones violate ToS, but it's a majority, or even a possibility, so they c…
where exactly do you work with this agenda and reasoning? thats insane? banks have been more or less made mandatory by the regimes around the world, and now these things. How can anyone possibly consider it sensible?