Earlier quoted context omitted.
This is a sensible move. Plus you can just keep your "authentication" phone at home instead of having it on you when you're out for no good reason.
Not if you want to use tap-to-pay systems.
The Vietnam government has banned rooted phones from using any banking app
291–300 of 643 posts
Re: The Vietnam government has banned rooted phones from using any banking app
#292Earlier quoted context omitted.
The card readers have an LCD display that shows the information.
How do they get this information in the first place, though? Do they have a QR code reader?
Previously there were also so called "flicker TAN" approaches: https://de.wikipedia.org/wiki/Transaktionsnummer#chipTAN_com...
Re: The Vietnam government has banned rooted phones from using any banking app
#293Earlier quoted context omitted.
Well, I've built a bunch of mobile banking apps and we did detect if the phone was rooted, was in dev mode, etc. and it is not because we were "stupid, consumer-hostile, and anti-competitive". If someone steals the secrets from a rooted phone and steals customer's money the bank is on the hook, so banks do everything they can to minimize this risk. There is no way to store customer's secrets in a PC browser securely,…
> If someone steals the secrets from a rooted phone and steals customer's money the bank is on the hook, so banks do everything they can to minimize this risk. Now that's just not true now, is it? Sure the lawyers told you that (the ones that get paid to tell you that), but nowhere in EU was a bank actually fined for not root checking a device. They were plenty fined by being utterly incompetent with security practic…
In some jurisdictions if bank can prove that transaction was made with customer's key then customer can not demand their money back. That's the best case, but there are only few of such jurisdictions and even there the burden of proof is on the bank and it costs a lot.
In other jurisdictions bank must reverse a transaction even if it was proven that the transaction was signed with a legitimate key, but the key _may_ have been stolen.
In some jurisdictions (i.e U.S.) banks are required to reverse a transaction at a customer’s request, even if the customer does not dispute having made the transaction.
In any case dealing with all this is too expensive and risky.
Re: The Vietnam government has banned rooted phones from using any banking app
#294Earlier quoted context omitted.
I'd be really interested to know whether a significant amount of fraud and fraud attempts involve devices with root or non-stock operating systems. This has always struck me as a matter of checkbox compliance rather than a commonly-exploited attack vector, though I'll grant that's partially because few people actually use such devices.
Devices that are easily rooted absolutely originate fraud. It's not like this is some wild claim. Look at how much financial fraud is driven by botnets running on old Windows PCs.
Re: The Vietnam government has banned rooted phones from using any banking app
#295I get the general skepticism and how this gives anti freedom vibes, but wouldn't this also prevent some actual rootkit like sideloaded apps stealing credentials? Not deep into rooting scene but seems plausible to me that this has some merit if you squint at it from the right angle
Trusted agents are useful. And I'm using legal meanings, not technical meanings here - so a "trusted agent" is someone or something that is legally acting on your behalf, to perform actions as though you were performing them.
The whole fucking promise of "general purpose computing" is that citizens should be able to delegate repetitive and tedious tasks to a computer. And they should have the full freedom to pick both which tasks are delegated, as well as which agent (program) is performing them.
Instead - what we're seeing is that companies are closing off as many avenues of automation for the average citizen as possible, under the guise of security.
The problem is that selecting a neutral (trusted!) agent is really, REALLY important, and companies are absolutely not neutral. They don't want the best results for "average Joe customer", they want the best results for themselves: the company.
They will make decisions that are contrary to your best interests all the time. They have exactly zero fiduciary duty to you, and boy do they know it.
In a decent world - in a decent CAPITALIST SOCIETY (which we can already debate the decency of in the first place) you allow space in the market for modification. Ex - don't like your desk? Change it. Don't like your car radio? Change it. Don't like that tool handle? Change it. Pick a different one, even one from a totally different company. Replace it.
This allows new ideas, new growth, and prevents stagnation.
In the digital world... there are a few companies that are trying as hard as possible to prevent you from being able to change anything.
---
Want a new browser? Fuck you.
Want a different UI for your banking needs? Fuck you.
Want to watch something without the ads? Fuck you.
Want to watch something with the ads, but in a less miserable ui? Fuck you too.
Want to automate something? Fuck you.
Want to export your data? Fuck you.
Want to sell software without us taking our rent money? Fuck you.
Want to shop in a different store? Fuck you.
Can't be letting our users make decisions that might cost us money.
---
So we're seeing an absolutely insane number of "digital locks" being employed not to protect users. No - instead they're getting deployed to protect revenue at the expense of users.
The only possible outcome is that service quality degrades to the point where you literally are better off without. Because that's what happens to incentives when you let companies operate in this manner.
If the consumer has no choice - the market has no power, and what little value there is in capitalism goes right into the trash bin.
So sure - if you squint, this maybe prevents someone from making a bad decision on which agent they trust.
But the problem is that now they HAVE to trust an agent they know is going to make bad decisions for them. Hope you like the biggest ad company in the world owning you digitally... Serfdom here we come.
Re: The Vietnam government has banned rooted phones from using any banking app
#296Earlier quoted context omitted.
Why do people need these crappy fintech apps at all? Can you not give your friends cash or send a wire?
I don't understand either. My contact surface with my bank is so small. I log in once a month to download transactions. What is everyone doing that they need constant immediate access on their phones? I'd probably debank before buying a special iPhone to access a bank account.
1. Your employer pays your salary by bank transfer, which requires you to have a conventional bank account.
2. You then want to spend that money, how do you do that?
Debit card? You need the phone app to retrieve the PIN when the bank first sends you the card.
Cash withdrawals in the branch? For amounts less than €10,000, the staff will direct you to the ATMs in the branch. These require an activated debit card to withdraw money, and activating that card requires the phone app.
Manual money transfers in the branch? Once again, for amounts less than €10,000, the staff won't do it - they'll instead direct you to the PCs in the branch. These are just loading the same website you can access on yours, which will ask you to the confirm with a 2FA push notification to log in.
Try another bank? The legacy banks all got the same auditor who advised them that app based 2FA is the easiest way to implement PSD2, and reduce the likelihood they get held liable when customers get scammed, so they all implemented that as the only option. The neobanks of course, are accessed solely by apps.
Re: The Vietnam government has banned rooted phones from using any banking app
#297Earlier quoted context omitted.
As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…
Do you guys wear cargo pants to carry all these extra devices or are belt clips coming back into style? If I could get away with carrying a tiny device again instead of lugging around a brick I would, but the world has made it as inconvenient as possible not to. A BlackBerry from 15 years ago weighed just over 100g and did 80% of what your modern-day pocket computer can.
Re: The Vietnam government has banned rooted phones from using any banking app
#298Earlier quoted context omitted.
I guess you can still do banking on your PC? I stopped using banking apps on my phones a few years ago - they got more and more annoying, and I don't buy into the "the device is secure and should be used as a trust token". So I'm now back to banking only on my computer, with a hardware token for TAN generation.
Hardware tokens are not allowed in Europe to authorize certain operations such as bank transfers: you need a device that can show the operation you are about to authorize ("enter 123456 to confirm your payment of 99.99 € to Pornhub"). And that essentially means using a phone.
The old, standard RSA number generator token key ring device is not permitted in Europe for authorizing bank actions ?
Re: The Vietnam government has banned rooted phones from using any banking app
#299Earlier quoted context omitted.
And, of course, easier to get the valuable data about the person setting up an account.
Like what data? Curious because I built and launched a challenger bank.
Re: The Vietnam government has banned rooted phones from using any banking app
#300Why can't rooted phones pretend to be non-rooted phones for the purpose of certain apps? What's the point of rooting if you can't even selectively pretend?
Because root is not the ultimate authority of what goes on in the phone; the hardware is, and the hardware contains a TPM (Treacherous Platform Module). The TPM has secret cryptographic keys it never shares with anyone, neither root nor an unrooted OS. When the phone starts, the TPM checks if the OS has been modified from what the manufacturer supplies or not. The bank's app can then ask the OS to sign documents usin…