Earlier quoted context omitted.
last time I walked into the bank to do something, they tried to peddle their app. I giggled and said no, their developers don't understand security. my phone is rooted and their app won't work.
Unfortunately, I can say with 100% confident, the customer service of my bank will not freaking understand what is a rooted phone, or LineageOS ... And my bank's web app developer couldn't even fix their log in bug for several months. I realize, now, it's because they want to sunset their web portal. Which is extremely annoying ... what if I don't have my mobile!! Lazy, and greedy corporates, just trying to save thei…
Uncomfortable Questions About Android Developer Verification
231–240 of 311 posts
Re: Uncomfortable Questions About Android Developer Verification
#232Earlier quoted context omitted.
My bank blocks my mobile with Lineage OS, and it's not even possible to login to the web site without the mobile app. Absolutely pathetic. Now I have to keep my 4 year old phone with 2 year outdated Android to access the bank application. Which deemed more safe then my mobile with latest security updates. Haha
last time I walked into the bank to do something, they tried to peddle their app. I giggled and said no, their developers don't understand security. my phone is rooted and their app won't work.
Their developers usually understand security well enough.
The problem, especially for banks, is that they're zero-risk driven, their ideal world is the one where risk doesn't exist. So instead of mitigating it they chase risk elimination (!= reduction) at any cost, while middle management needs to report that they improved something for the quarter. This results in all these kinds of stupid policies, where a 6 year old mobile, unmaintained for 4, is considered more secure than the weekly build of the community-based custom ROM running with locked bootloader signed with user-managed keys with strong protection (these days it's almost infeasible).
EDIT: to be clear, it's normally not the developers thinking up these policies, I have worked in a bank.
Re: Uncomfortable Questions About Android Developer Verification
#233This is the sort of thug behavior you see in CCP China. If the govt can't directly detain overseas dissidents or other "undesirables", it goes after their families back in the mainland.
Re: Uncomfortable Questions About Android Developer Verification
#234Earlier quoted context omitted.
I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"
I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.
It shouldn't be a thing, but it is. In the Netherlands the newer digital-only banks are allowed to do this. No smartphone, no service.
The more established banks (systeembanken) do have alternatives, but realistically not using their app for login auth and transaction approval is a huge pain in the ass.
(My bank, ABN AMRO, has an app which thankfully works fine on GrapheneOS.)
Re: Uncomfortable Questions About Android Developer Verification
#235Earlier quoted context omitted.
Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…
> For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. Why are you only listing DEs and not operating systems? (You also missed SXMo and more.) There are many more operating systems [0] and two working GNU/Linux phones, Librem 5 and Pinephone. Why people are ignoring them on HN? [0] https://pine64.org/documentation/PinePhone/Software/
Re: Uncomfortable Questions About Android Developer Verification
#236Earlier quoted context omitted.
You do have the option to change your bank when they consistently do dumb stuff you don't approve of. Shopping around will probably get you a better savings rate anyway.
Unfortunately, not an option right now. Setting up foreign currency payout is difficult in my country, a lot of paperworks needed, we don't even have PayPal. Also, the previous autocratic government, that was forcefully expelled after a bloody movement, left most of the banks in ruin. So not a lot of options left.
Changing banks is easy when it's just about cash in a savings account. Not so easy in other cases.
Re: Uncomfortable Questions About Android Developer Verification
#237Earlier quoted context omitted.
last time I walked into the bank to do something, they tried to peddle their app. I giggled and said no, their developers don't understand security. my phone is rooted and their app won't work.
> I giggled and said no, their developers don't understand security. Their developers usually understand security well enough. The problem, especially for banks, is that they're zero-risk driven, their ideal world is the one where risk doesn't exist. So instead of mitigating it they chase risk elimination (!= reduction) at any cost, while middle management needs to report that they improved something for the quarter.…
I don't actually believe that. They chase risk elimination at any cost to you. If there's a significant cost to them, they're going to be all about quantitative tradeoffs.
Re: Uncomfortable Questions About Android Developer Verification
#238Re: Uncomfortable Questions About Android Developer Verification
#239I know I risk being down voted remorselessly but I have to put this in context. Where in the real world is anonymity considered ok? If I only put a flyer through someone's letterbox here in the UK, I have to identify myself. If I sell a physical product I not only have to identify myself but take on serious legal liability. An author can take on a pseudonym but only via an identified publisher. In fact that latter ex…
The thing is that so many people are used to doing whatever they want from behind the safety of their screen and are now able to do a lot of things they don’t want anyone to know about. Now the law and common sense is catching up and we’re starting to see things we take for granted in the physical world are coming to the digital world. And I think a lot of people are scared of not being able to do what they used to o…
Your concept of "common sense" is repulsive, as is your submissive attitude.
Re: Uncomfortable Questions About Android Developer Verification
#240Individual privacy and anonymity matter substantially less when Governments are basically decent and play by the rules, and so it seems there is a tendency to value convenience and utility over privacy and anonymity. When Government goes bad, suddenly we are faced with the utmost need for privacy and anonymity, but we may by then be in a situation where privacy and anonymity are difficult to obtain, with all the cons…
But notice that Google is doing this as the government in its home country is going bad (or at least getting dramatically, qualitatively worse than it has already been).
Some people see features where others see bugs.