Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

171–180 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#171
post #76

Earlier quoted context omitted.

That seems to be the way the wind is blowing. Most new 'challengers' I've tried in the US either have no web access at all, or limited access that lets you view balance but not do things like transfers.

Recalling Venmo winding down web beginning in… let’s see… 2018! https://www.digitaltrends.com/phones/venmo-shutters-web-plat...

Why do people need these crappy fintech apps at all? Can you not give your friends cash or send a wire?

Re: The Vietnam government has banned rooted phones from using any banking app

#172

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

> does stop malware. unrelated to phones a lot of (more professional) malware has moved to not persist itself in root space (or at all) as to not leaf traces (instead it will just rely on being able to regain root access as needed every time you reboot with all the juicy parts being in memory only (as in how often do you even roboot your phone)) I think (but am not fully sure) this also applies to phone malware. I.e.…

Yes that's what they are doing. Phones known to have live root exploits are detected and banned.

Re: The Vietnam government has banned rooted phones from using any banking app

#173

Earlier quoted context omitted.

That probably means giving up the ability to mobile deposit checks - every bank I've ever had only allows that through their app.

What's a mobile deposit and why do you need an app to check it?

It's the ability to take a picture of a check and deposit it into your account that way, vs having to take the check to an actual branch of a bank.

Here in the US, I still get checks frequently enough that it's nice to have.

Re: The Vietnam government has banned rooted phones from using any banking app

#174

Earlier quoted context omitted.

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

the iPhone still does bluetooth transmissions/pings even in airplane mode (the find my device thing) and no way to disable the only way to disable any transmissions is to turn off the device

Bluetooth's the same RF chip as wifi in new phones isn't it? Can't just exacto knife a trace on the board without murdering everything I take it?

Re: The Vietnam government has banned rooted phones from using any banking app

#175
post #132

When I used to work on the Vanguard authentication team, we blocked Vietnam from access because of too much fraud (not my choice). But it was funny because we had Vietnam based clients, so there were a couple HNW clients in the logs that you could see who would log in from Vietnam/Russia/Wherever, get blocked, open their vpn, then log in from England. This was a while back, but even then there was a push for things l…

I'd be really interested to know whether a significant amount of fraud and fraud attempts involve devices with root or non-stock operating systems. This has always struck me as a matter of checkbox compliance rather than a commonly-exploited attack vector, though I'll grant that's partially because few people actually use such devices.

Devices that are easily rooted absolutely originate fraud. It's not like this is some wild claim. Look at how much financial fraud is driven by botnets running on old Windows PCs.

Re: The Vietnam government has banned rooted phones from using any banking app

#176

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

[dead]

Re: The Vietnam government has banned rooted phones from using any banking app

#177

Earlier quoted context omitted.

It's true that GrapheneOS is not rooted, and, unlike other non-rooted custom ROMs, allows re-locking the bootloader. But , whether a banking app will work depends on what level of Google Play attestation they require. While most banking apps work fine on it, a significant minority do not.

To be fair, this seems to be mostly a European problem. U.S. banks do not seem to enforce Play (dis)Integrity.

Not necessarily an european problem either. Maybe It varies by country but at least none of my 3 finnish banks check for play integrity.

Re: The Vietnam government has banned rooted phones from using any banking app

#178
post #85
post #78

Earlier quoted context omitted.

Depends on what country you're in. In the UK, the banks are often held liable for various scams that involve the transfer of money, so they up the security over and over again. A bank will rightly argue why it's responsible for an old granny sending her life savings to her new lover in Namibia, so it seeks to block that transaction in the first place. Some of that liability is fair but most of it is the government te…

Rooted devices don't enable that transaction. That's all social engineering.

It's all social engineering now but that's because phones are secure and remote attestation infrastructure is in place.

Go back fifteen years and malware is absolutely submitting bank transactions after the user does a 2FA.

https://krebsonsecurity.com/2010/03/crooks-crank-up-volume-o...

Re: The Vietnam government has banned rooted phones from using any banking app

#179
post #20

Unfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.

I'm assuming you would do this out of a political reason, or as a very technical and privacy aware user. But you are providing an alibi for malicious users who, for example, might try to brute force logins from unidentified devices. That would be one reason aside from the law. You are essentially positioning yourself on the same side as intruders.

are you for real? no, its the government telling regular people that simply wants to control their device that THEY are criminals and on same side as intruders.

You should personally immediately return any computing device where you have control, this line of reasoning is insane

Re: The Vietnam government has banned rooted phones from using any banking app

#180
post #94
post #83

>The Vietnam government has banned rooted phones from using any banking app The Vietnam government has banned phones under their user's control from using any banking app.

If the banking apps have a Terms of Service, you are free not to use the banking app. To give a specific example, suppose a banking app wants to require location services in order to try to login. Some users can bypass or spoof this, (in fact that's what the thread is about entirely, and for that they root the phones. Not all users who root the phones violate ToS, but it's a majority, or even a possibility, so they c…

> Pretty sensible stuff to me.

where exactly do you work with this agenda and reasoning? thats insane? banks have been more or less made mandatory by the regimes around the world, and now these things. How can anyone possibly consider it sensible?

Post reply on HN