Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

281–290 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#281

Earlier quoted context omitted.

I guess you can still do banking on your PC? I stopped using banking apps on my phones a few years ago - they got more and more annoying, and I don't buy into the "the device is secure and should be used as a trust token". So I'm now back to banking only on my computer, with a hardware token for TAN generation.

Hyperbolic take - There won't be PCs, as we know them, for too much longer (both by way of being made into walled garden phone-like "appliances" by software, and by the hardware becoming unavailable).

yeah. Americans are one media campaign away from having to argue for their right to possess fully semiautomatic general purpose computers with high capacity peripherals. Europeans and the rest of the collective West won't even get such courtesy, their young global leaders don't need to justify their actions to the unwashed masses.

all they really need to do is to make the Internet inaccessible from any device except the castrated thin clients that our computers are doomed to be replaced with. and that can be done trivially.

Re: The Vietnam government has banned rooted phones from using any banking app

#282
post #76

Earlier quoted context omitted.

Recalling Venmo winding down web beginning in… let’s see… 2018! https://www.digitaltrends.com/phones/venmo-shutters-web-plat...

Why do people need these crappy fintech apps at all? Can you not give your friends cash or send a wire?

I don't understand either. My contact surface with my bank is so small. I log in once a month to download transactions. What is everyone doing that they need constant immediate access on their phones? I'd probably debank before buying a special iPhone to access a bank account.

Re: The Vietnam government has banned rooted phones from using any banking app

#283

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

> moving to a model where the user is considered the adversary on their own hardware

I think we’ve been there at least since the first iPhone, and it’s now entirely normalized for the average user.

Re: The Vietnam government has banned rooted phones from using any banking app

#284
post #194
post #185

Earlier quoted context omitted.

Maybe it’s country-specific, but most banks I know support a card reader or photoTAN device. You don’t need to use a phone.

I don't think card readers can display payment information, can they? And I have no idea why, but no bank offers photoTAN devices in my country. They seem like an interesting concept, even though I imagine the underlying hardware isn't far from that of a phone, in the end.

German VR Banken: https://genostore.de/Banking/Kartenlesegeraete/

Sparkassen: https://www.sparkassen-shop.de/home/shop/tan-generatoren,375...

Re: The Vietnam government has banned rooted phones from using any banking app

#285

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

I already willingly do this with browsers. Firefox gets maximum adblocking and other extensions, Safari gets to touch my bank.

Re: The Vietnam government has banned rooted phones from using any banking app

#286
Government banning insecure open standards and then not providing a secure open standard is atrocious. If I must have an official authorizing thing to prove I'm who I say I am, make it as small as possible.

If you mandated that they have to support Yubikey or whatever on open platforms I'd take that as a decent alternative. But just "no you must use a device controlled by somebody else" is not acceptable.

Re: The Vietnam government has banned rooted phones from using any banking app

#287
post #141

When I used to work on the Vanguard authentication team, we blocked Vietnam from access because of too much fraud (not my choice). But it was funny because we had Vietnam based clients, so there were a couple HNW clients in the logs that you could see who would log in from Vietnam/Russia/Wherever, get blocked, open their vpn, then log in from England. This was a while back, but even then there was a push for things l…

Oh yeah I remember adding my Yubikey to Vanguard as early as 2019! It felt amazingly modern compared to any other bank. I assume this is your or your team’s work. Thank you! I’ve also had other banks do the same. They provided me with a debit card that supports international transactions but they did not allow logging in from most Asian countries. So I would log in from Asia, be blocked, turn on my VPN and log in fro…

I always thought Vanguard was behind the curve on these types of things. They don't even have support for TOTP from an authenticator, do they?

Separately, I couldn't even log onto their system this week from my desktop browser because of some bug. (Accessing from the US). It didn't recognize my username or password, let me change my password, then said it didn't recognize the new password.

Re: The Vietnam government has banned rooted phones from using any banking app

#288

Earlier quoted context omitted.

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

the iPhone still does bluetooth transmissions/pings even in airplane mode (the find my device thing) and no way to disable the only way to disable any transmissions is to turn off the device

> iPhone still does bluetooth transmissions/pings even in airplane mode ... the only way to disable any transmissions is to turn off the device

I used to be under the impression that:

- Airplane Mode via Control Center icon, true.

- Cellular, WiFi, and Bluetooth off, via Settings, not true.

Meaning, if you turn those off specifically, you are not talking to towers or access points or broadcasting a persistent bluetooth ID.

Having Kagi'd a bit just now, maybe the thing that can't be turned off is NFC?

https://www.simplymac.com/ios/can-you-turn-off-nfc-iphone

If that's the case, then I'd hold this as a different threat model than not being able to turn off WiFi and Cellular.

Very curious if an iPhone or iPad with all accessible settings off, including for NFC turning off Apple Pay, NFC tag reading, etc., leaving only this background NFC on, if there are still persistent identifiers being broadcast.

Re: The Vietnam government has banned rooted phones from using any banking app

#289

When I used to work on the Vanguard authentication team, we blocked Vietnam from access because of too much fraud (not my choice). But it was funny because we had Vietnam based clients, so there were a couple HNW clients in the logs that you could see who would log in from Vietnam/Russia/Wherever, get blocked, open their vpn, then log in from England. This was a while back, but even then there was a push for things l…

When I was running a home server as a kid, I IP-blocked the entire continent of Asia because I was constantly getting pings, portscans, HTTP path guesses, SSH auth attempts, etc randomly from there. Of course I secured my stuff to the best of my knowledge, but I still didn't want that harassment cause 1. who knows 2. could be ddos'd.

When finding help on how to do this, people were saying it's useless cause they can proxy/VPN anyway, but obviously that has some cost to them because they weren't doing that. So seeing how I had no legitimate traffic from there, it was an easy choice and cut out like 99% of abuse.

Re: The Vietnam government has banned rooted phones from using any banking app

#290
post #104

Earlier quoted context omitted.

And, of course, easier to get the valuable data about the person setting up an account.

Like what data? Curious because I built and launched a challenger bank.

Theoretically any sort of data that apps in a given OS can access through an API.
Post reply on HN