Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

191–200 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#191
post #49

Earlier quoted context omitted.

This isn't about the bank's security - it is about the users'. Users are losing billions worldwide due to fraudulent apps. If a user has root and runs a malicious app, it can intercept what a legitimate banking app does. A scam app with root can draw over the screen and tell users to transfer money, or it can run a series of actions when the banking app is running, or do any of a hundred things to steal money.

> A scam app with root Sure. But the people who are actually rooting their phones are advanced users and aren't going to install a malicious custom OS. Are naive users getting tricked into rooting their own phones? I'm dubious what the security benefit is of this decision.

These types of discussions on HN get confused because people aren't always clear what they mean by the word "rooting".

There are two ways to root a phone:

1. Unlock the bootloader, install a well designed and highly secure aftermarket OS, relock the bootloader. The device is still just as secure against malware as it was before. Remote attestation shows the vendor that you're running Graphene or Lineage or whatever.

2. Exploit a local vulnerability to drop a sudo binary somewhere. RA shows you're running an exploitable version of Pixel Android, etc.

(2) is absolutely exploitable by fraudsters. They convince the user to run an app or visit a website that exploits their browser or whatever, and the vulns are used to escalate to root and keep it. Now when the user logs into their banking app the HTTP requests are rewritten to command the bank to send money to the adversary. This is why devices that allow escalation to root are excluded via remote attestation.

(1) isn't but it requires more coordination than the industry has proven capable of so far. Binary images of a custom OS could in theory be whitelisted by banks if it was known to be as secure as other operating systems. But there's no forum in which that information can be exchanged. Like, RandOS turns up and the maintainer "xyzkid", identity: anime avatar, claims his OS is super secure. How does random overworked bank developer John Smith know if this is true or not? RandOS doesn't come with any audits, it doesn't have a well paid security team. The brand is a big question mark. And if John makes the wrong call, maybe the bank is now on the hook for millions in losses because someone installed RandOS to get the shiny icon theme or whatever, and then got hacked.

So it's a hard problem. It's not actually a technical problem. Remote attestation is very general. The hard part isn't the tech. It's a social problem. How do you create and rapidly communicate trust in a new binary OS image if you don't have the security resources of an Apple or a Google or a Samsung? Google runs a whole accreditation programme for Android where you can turn up as a phone OEM and get your custom OS builds considered to be secure by passing a huge test suite. So the only issue is OS hackers who fall below the threshold where they can do that.

There's an alternative of course: go full libertarian. Means, just use a "bank" that doesn't care if its users get hacked. This is what the Bitcoin community enabled. It's there if you want it.

Re: The Vietnam government has banned rooted phones from using any banking app

#192

Earlier quoted context omitted.

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

the iPhone still does bluetooth transmissions/pings even in airplane mode (the find my device thing) and no way to disable the only way to disable any transmissions is to turn off the device

I've turned off find my device on my device.

Although, I am still using 17.7.2 that won't stop nagging me to upgrade to iOS 26.2.

I don't want to because I know I'll hate it.

Re: The Vietnam government has banned rooted phones from using any banking app

#193

Earlier quoted context omitted.

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

> By 2026, you'll need two phones... Need ? Unless and/or until the ability to log in and do your banking, healthcare, etc. via desktop/laptop goes away, then you don't need a phone to do any of that. Yes, 2FA may be required but in the tangential experience of myself, my partner and my two closest friends, we have multiple 2FA options available to us for our banking/healthcare apps that don't require a smartphone. I…

You don’t do any important stuff on your phone. Others might not have the luxury.

Notably, in Vietnam people use QR payments a lot. If you want to interact with them by, say, paying at a small local restaurant, you’ll need a phone (or a stack of cash, and please do prepare change).

Re: The Vietnam government has banned rooted phones from using any banking app

#194
post #185
post #166

Earlier quoted context omitted.

Hardware tokens are not allowed in Europe to authorize certain operations such as bank transfers: you need a device that can show the operation you are about to authorize ("enter 123456 to confirm your payment of 99.99 € to Pornhub"). And that essentially means using a phone.

Maybe it’s country-specific, but most banks I know support a card reader or photoTAN device. You don’t need to use a phone.

I don't think card readers can display payment information, can they?

And I have no idea why, but no bank offers photoTAN devices in my country. They seem like an interesting concept, even though I imagine the underlying hardware isn't far from that of a phone, in the end.

Re: The Vietnam government has banned rooted phones from using any banking app

#195
post #5

I really don't understand this. My line of thinking is that if someone is technical enough to root his phone he understands the risks. Why would they force banking apps to detect and not work on rooted phones? Why would the government care so much?

>I really don't understand this. My line of thinking is that if someone is technical enough to root his phone he understands the risks.

But you do understand. If someone is technical enough to root their phone, then he is the risk.

[cough]Monero[cough]

Re: The Vietnam government has banned rooted phones from using any banking app

#196
post #20

Unfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.

> Unfortunately the answer here is to not abide by the law You realize in Viet Nam this means getting a "friendly" visit by the MPS/BCA, and if you continue eventually getting branded as a troublemaker.

> [...] and there is reasonable expectation to not be caught [...]

Hence my qualifier. I'm not trying to incite anyone into personal danger.

Re: The Vietnam government has banned rooted phones from using any banking app

#197
post #190

Earlier quoted context omitted.

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

>An unmodified iPhone SE (2022 model) with OS support until 2032 What makes you think it'll be supported for a decade? Looking at the past models, the support period is around 5-7 years. If you count security updates that might get you to 10 years, but at the 7-9 year mark apps will eventually refuse to update because you're not on the latest ios. https://en.wikipedia.org/wiki/IPhone#Models

To be fair my 2016 iPad Pro is up to date and can still run any app I throw at it

Re: The Vietnam government has banned rooted phones from using any banking app

#198
post #20

Unfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.

I'm assuming you would do this out of a political reason, or as a very technical and privacy aware user. But you are providing an alibi for malicious users who, for example, might try to brute force logins from unidentified devices. That would be one reason aside from the law. You are essentially positioning yourself on the same side as intruders.

You're claiming that the only legitimate use of rooting is criminal activity, which is not true. Your argument is based on a faulty premise in my eyes.

Re: The Vietnam government has banned rooted phones from using any banking app

#199

Earlier quoted context omitted.

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

> By 2026, you'll need two phones... Need ? Unless and/or until the ability to log in and do your banking, healthcare, etc. via desktop/laptop goes away, then you don't need a phone to do any of that. Yes, 2FA may be required but in the tangential experience of myself, my partner and my two closest friends, we have multiple 2FA options available to us for our banking/healthcare apps that don't require a smartphone. I…

Just because you don’t need it doesn’t mean other people don’t. Heck, I have no need for a rooted phone so I only use a normal phone, but I respect that others might need a rooted phone.

Re: The Vietnam government has banned rooted phones from using any banking app

#200
post #187

Earlier quoted context omitted.

This is a sensible move. Plus you can just keep your "authentication" phone at home instead of having it on you when you're out for no good reason.

Not if you want to use tap-to-pay systems.

I wonder if this makes room in the market for some simpler device for payments. Something like a wearable that you can tap-to-pay and has the signed software attenuation but nothing else so you can't be tracked using GPS.
Post reply on HN