Live data from Hacker News

HSBC blocks its app due to F-Droid-installed Bitwarden

mastodon.neilzone.co.uk

211–220 of 242 posts

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#211
post #54

Earlier quoted context omitted.

The problem (for the bank) is they are now liable in the UK[1] if you are defrauded because someone installs malware on the phone. There's basically zero upside for the bank to allow customers to use F-Droid, since probably 0.0001% of their customers would do this, compared to a vastly greater number of customers being tricked into installing random malware on their phones. Accessibility settings are a tricky one sin…

From the bbc article, the number of fraud rose 12%, and you're presuming 0.0001% would be using F-Droid. Is preventing that an efficient ("reasonable") action from the bank ?

Fraud is 41% of all crime in the UK, affecting 3.2 million people.

Number of people using F-Droid + a banking app is approximately zero in comparison.

There is not the slightest chance in hell that taking on the legal risk from F-Droid users is a sensible use of the bank's resources.

Sources: https://www.nationalcrimeagency.gov.uk/what-we-do/crime-thre... https://www.nationalcrimeagency.gov.uk/threats-2025/nsa-frau...

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#212
post #7

It will not work either if you have developer mode enabled. These things HSBC app does, I think it's overreaching

My country launched an identification app ( https://mygov.be/ ) that does the same thing. I have no idea what they're trying to achieve. Security through obscurity? Trying to piss off power users? I'm a developer and use adb and some dev settings daily. Annoying af to have to disable developer mode constantly.

I had to turn on developer mode just to reduce blur in Android 16. It's incredible that's locked behind a developer mode setting.

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#213

That's Google's SafeNet. HSBC picked a level that causes this. Google manages the blacklist of apps. We are rapidly losing our freedoms to the will of these companies. If they decide they don't want to they can even if the law doesn't forbid it. People in Switzerland and the EU are being de-banked by local banks because of US pressure allowing them to force any bank that wants to use USD. The US has started to sancti…

> and the EU are being de-banked by local banks because of US pressure allowing them to force any bank that wants to use USD What is this about? I'm a EU citizen, never heard about any EU citizen getting removed from any EU bank because of USD. Nor have I heard anyone being sanctioned by the US in the EU unless they're Russia-related somehow. Is there any link to a story about this?

"I'm a EU citizen, never heard about any EU citizen getting removed from any EU bank because of USD ..."

US and USD need not be involved - EU does this on it's own without any pressure:

https://www.swissinfo.ch/eng/foreign-affairs/former-swiss-in...

"As a result Baud will not be allowed to travel within EU countries and his assets in the Euro zone will be frozen."

His assertions are not particularly extreme and, without question, fall into the realm of protected, free speech.

This is orthogonal to whether you or I agree with what he is saying. Finding his views "dangerous" is an admission of profound weakness.

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#214

Tangentially related, but some banking apps also implement their own in-app keyboard in their password fields, making password manager unusable and basically forcing me to use a easy to remember (to guess) password.

Yup, mine does this, even on the web. Oh god French banks do love their scrambled-digit-keyboards. And boy do they love 6 to 8 digits passwords. That you have to click on using your mouse. No password manager required! Their app also likes to prompt me periodically for the password instead of the phone's biometrics, which would be good, except it always happens in a public place like the subway, which is the last pla…

One of them has that “scrambled visual keyboard” for an 8-digit password, and at the same time proposes a passkey as an alternative on desktop. Go figure.

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#215
post #15

Ditch apps on your phone and pick banking that gives good, robust online banking. I was cut off by Starling for something similar and had to choose between a factory reset of my phone and my bank. I explained that my phone had free software on it, some of which I'd written, and it made no difference. Apps are a tool of control and surveillance and it is time we stopped tying ourselves to them. Dumb phones or degoogle…

Can you say more about what specific things you tripped over with Starling, and which bank you moved to? Worried I'll find myself in the same boat. It does seem like Starling has gone out of their way twice to exempt GrapheneOS from their checks, but only after users complained: https://github.com/PrivSec-dev/banking-apps-compat-report/is...

I had rooted the phone and it gave me 90 days to reset with no extension at the end. I moved to the co-op bank, which is sufficiently old school that proper web based online banking is very important to them. Their products are a bit less advanced but I don't miss starling.

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#216
post #15

Ditch apps on your phone and pick banking that gives good, robust online banking. I was cut off by Starling for something similar and had to choose between a factory reset of my phone and my bank. I explained that my phone had free software on it, some of which I'd written, and it made no difference. Apps are a tool of control and surveillance and it is time we stopped tying ourselves to them. Dumb phones or degoogle…

Would they not just let you keep the account but not use their app in that case?

They did indeed. I had to call customer services to get the account closed. The app being the only way to interact with the account, I was left without funds for days.

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#217

Banks in the UK take partial liability for their customers succumbing to scams, and refund lost funds unless customers go out of their way to ignore warnings. Loss of control of devices is undeniably part of the scam lifecycle. Faking and intercepting messages from banks is a large part of that. An antivirus needs global permissions. All of that being true, you don't have to be a contortionist to understand why they…

Why should a bank be ever able to dictate what the user does with their device legitimately? They can't do so on the web through browsers, that is fine, why are we excusing this on phones? Next up banks will start requiring out MDM enrollment? Is that equally understandable? Where do you draw the line? It's unnecessary and intrusive to apply these methods unconditionally and on everyone.

> Why should a bank be ever able to dictate what the user does..

I'll deliberately answer early: because they're on the hook for your mistakes.

Your bank dictates security terms. This isn't new. They can demand you appear in person with multiple forms of identification. They can (and have) demand you use 2f hardware they provide. They can withdraw service if they think you're a risk to their business.

If I suddenly found myself with billions in potential liabilities, I'd do absolutely everything to ban footguns. Apps with system access installed from insecure sources. Yeah, no thanks.

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#218

Source post deleted

It originally contained a screenshot of a full-screen notice displaying:

  We've introduced additional checks to protect your
  account. The following apps have been downloaded
  from unofficial app stores.
  
  Your access to the HSBC UK Mobile Banking app
  has been suspended on this device until you've taken
  action to restore it.
  
  Identified apps:
  
    - Bitwarden
  
  How do I restore access?
  
    - Uninstall the identified apps from your device
      and download again from the default device
      app store, eg Google Play or Galaxy Store.
  
  For further assistance, please visit
  https://www.hsbc.co.uk/contact/

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#219

Tangentially related, but some banking apps also implement their own in-app keyboard in their password fields, making password manager unusable and basically forcing me to use a easy to remember (to guess) password.

Yup, mine does this, even on the web. Oh god French banks do love their scrambled-digit-keyboards. And boy do they love 6 to 8 digits passwords. That you have to click on using your mouse. No password manager required! Their app also likes to prompt me periodically for the password instead of the phone's biometrics, which would be good, except it always happens in a public place like the subway, which is the last pla…

This is only going to get worse as nepotistic brogrammers continue to take over the industry and gish gallop their bullshit over the experienced developers.

Re: HSBC blocks its app due to F-Droid-installed Bitwarden

#220
post #195

Earlier quoted context omitted.

At least in Switzerland banks can choose to not use Play Integrity, but they generally don't want to. Yuh, which once was owned by both Postfinance and Swissquote, works without Play Integrity. Support for GrapheneOS is confirmed - see https://github.com/PrivSec-dev/banking-apps-compat-report/is... The real issue is that most "legacy" banks have to comply with stupid regulations that force them to come up with these…

This goes beyond simply using Play Integrity, which normally just does remote attestation of the operating system. The next level is allowing an app to check its own package for modifications or installation from an unapproved source, but this goes beyond even that and gives the app the ability to check where a third-party app came from. Google are assholes for building this.

> The next level is allowing an app to check its own package for modifications

You can't modify them. They're signed. If you modify and resign it gets installed with a different key (ie the one you signed with) hence it's a different app as far as it's concerned.

To get around that you need signature spoofing which Lineage famously refused to include.

Agreed that BigTech in general is making the world worse by implementing security features in ways that erode user freedom.

Post reply on HN