Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

251–260 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#251
post #215

Earlier quoted context omitted.

> We are moving to a model where the user is considered the adversary on their own hardware. That has been the model since day one, since you are using spectrum that, because the end users are not licensed, requires it. Radios in 100% of commercially available phones are locked to prevent user tampering. You don't get root on your debit card either, despite it running a computer.

> That has been the model since day one, since you are using spectrum that, because the end users are not licensed, requires it. Radios in 100% of commercially available phones are locked to prevent user tampering. Why, then, can users be root on PCs that have wifi cards, SDRs or cellular radios?

SDRs are (IIRC) low-power enough that they don't fall under FCC regulations.

Re: The Vietnam government has banned rooted phones from using any banking app

#252
post #200
post #187

Earlier quoted context omitted.

Not if you want to use tap-to-pay systems.

I wonder if this makes room in the market for some simpler device for payments. Something like a wearable that you can tap-to-pay and has the signed software attenuation but nothing else so you can't be tracked using GPS.

Curve sell rings to use for this. https://www.curve.com/wearables/

Re: The Vietnam government has banned rooted phones from using any banking app

#253
post #72

Earlier quoted context omitted.

The only way an app can contact a company is through REST APIs.

True. All internet packets are REST API packets - there's no other type of packet. And all cell radio traffic is internet packets (which are REST API packets).

[deleted]

Re: The Vietnam government has banned rooted phones from using any banking app

#254

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

I used to get a physical security key from my bank. Perhaps I should get a bank device with a touch screen for banking only and they could then stay the hell off of my personal phone.

Re: The Vietnam government has banned rooted phones from using any banking app

#255
post #5

I really don't understand this. My line of thinking is that if someone is technical enough to root his phone he understands the risks. Why would they force banking apps to detect and not work on rooted phones? Why would the government care so much?

> Why would the government care so much? My guess is: 1. Person with rooted phone uses a bank app, is hacked, has their money stolen. 2. Guess where the person turns to for help? The government.

I think it has more to do with the phone being tied to an individual, the banking and spending activities being tied to the phone, and the government having some hardware attestation about how people are spending their money and with whom. If you root a phone, you can change things like the MAC addresses. You may be able to futz with a softSIM/eSIM. That makes you harder to track.

Re: The Vietnam government has banned rooted phones from using any banking app

#256

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

I really like this comment. I similarly don't like that banking is, from no collusion just internal incentives, locking out any users not opted into the Chromium hegemony.

> The irrefutable part here is that the security model works.

Yes! And that business model should be allowed.

This leads me to worry the notion of "user agency" may be misplaced, meaning, aimed at the wrong level of the stack. It would seem both open (general compute ethos) and secure devices (appliance ethos) have a right to be in the market. So…

### Perhaps user agency should be at the experience level. ###

We couldn't plug Sega Genesis cartridges into Nintendo 64. We understand this about consoles. If we remap mobile devices into consoles, it seems less obvious their internals should be opened and tinkered with by end users.

User agency seems more at the level of picking a console family, and it's often for the whole brand aura including both the console itself and safeness-to-permissiveness dial by which the brand curates its the cartridges (spectrum from Nintendo to Apple to Sony to Microsoft and Steam). A free market for mobile devices or desktops would likely sort out a similar spectrum of just-works to fidget-able. If you choose the Nintendo 64, you wouldn't expect to run arbitrary software on it as you would expect on Dell.

We hackers are capable of figuring out how to make Nintendo 64 software; our neighbor does not need or want those affordances, they want just works, no headaches. This idea that the user must be able to open their digital watch or toaster oven and change how it is wired glosses what users actually choose: the conveniently toasted meal.

At the same time, business models around the curation and appliancification of digital tools, blurring the lines from hardware through solid state through firmware to software into a single product users can choose, must be defended.

If I want to dev for a secure product, I similarly must be OK opting into the supply chain security model (with Apple, registering as a dev in order to exchange cert material and bypass consumer paths to loading software I'm making for the platform) that allows that product to be secure, and opted into by users with money to buy my app, that caused me to want to develop for it in the first place.

Users must have a right to buy an appliance that isn't fiddle-able. Not mandated to, as this article sounds, but allowed to as the EU is trying to deny. Such products have a right to exist, and such business models have a right to exist.

And then, user agency remains as simple as use dollars to buy a product offered through a biz model that matches the user's goals, rather than regulate to disable business offerings offerings/products that don't, and developer agency is to pour energy into the platform that aligns with one's ethos.

If more money is to be made on a platform with a different ethos, perhaps it's worth reflection rather than rants.

Re: The Vietnam government has banned rooted phones from using any banking app

#257

Earlier quoted context omitted.

I guess you can still do banking on your PC? I stopped using banking apps on my phones a few years ago - they got more and more annoying, and I don't buy into the "the device is secure and should be used as a trust token". So I'm now back to banking only on my computer, with a hardware token for TAN generation.

Hyperbolic take - There won't be PCs, as we know them, for too much longer (both by way of being made into walled garden phone-like "appliances" by software, and by the hardware becoming unavailable).

I hate that future so much, but I don't know what to do to avoid it. My sole choice to bank on pc and use it as a pc will not be considered by the product people making the choice to go smart phone app only.

I'm essentially along for the ride because the masses will gobble it up.

Re: The Vietnam government has banned rooted phones from using any banking app

#258

Earlier quoted context omitted.

GrapheneOS is not rooted. Most banking apps work fine on it. https://privsec.dev/posts/android/banking-applications-compa... https://grapheneos.org/usage#banking-apps

It's true that GrapheneOS is not rooted, and, unlike other non-rooted custom ROMs, allows re-locking the bootloader. But , whether a banking app will work depends on what level of Google Play attestation they require. While most banking apps work fine on it, a significant minority do not.

There's a crowd-sourced dataset here: https://privsec.dev/posts/android/banking-applications-compa...

Re: The Vietnam government has banned rooted phones from using any banking app

#259
post #200

Earlier quoted context omitted.

I wonder if this makes room in the market for some simpler device for payments. Something like a wearable that you can tap-to-pay and has the signed software attenuation but nothing else so you can't be tracked using GPS.

> Something like a wearable that you can tap-to-pay and has the signed software attenuation but nothing else so you can't be tracked using GPS. That's a nice idea. You could have a simple card-shaped device with no screen or buttons, and call that a "credit card".

https://news.ycombinator.com/newsguidelines.html

“Be kind. Don't be snarky.”

“Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith.”

Re: The Vietnam government has banned rooted phones from using any banking app

#260

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

At that point why not just use the bank's website?
Post reply on HN