Earlier quoted context omitted.
Wifi? Because it is part 15. That spectrum is less strict. SDRs? Because they are not certified transmitters. They are test RF gear, or a component of a transmitter, not an end-user product. Cellular radios in a PC? You don't get root on those. Same situation as they are in a cell phone: They are licensed-band transmitters, and they are required to be tamper proof to protect the licensee.
> Cellular radios in a PC? You don't get root on those. Same situation as they are in a cell phone: They are licensed-band transmitters, and they are required to be tamper proof to protect the licensee. The original post said: > Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own har…
The Vietnam government has banned rooted phones from using any banking app
331–340 of 643 posts
Re: The Vietnam government has banned rooted phones from using any banking app
#332Earlier quoted context omitted.
Why don't banks just make desktop computer applications?
PC platforms don't have remote attestation infrastructure working.
Do peope get defrauded using online banking? Sure. But usually not in a way that would be stopped by secure attestation.
Re: The Vietnam government has banned rooted phones from using any banking app
#333The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…
App sandboxing and system file integrity is one of the most beneficial security features of modern computing, and the vast majority of people have no desire to turn it off. You can buy rootable phones. People overwhelmingly choose iPhones instead.
Even if Apple sold the SRD at scale, nobody would buy the weird insecure hacker iPhone except us and maybe kids who realllly want Fortnite.
Re: The Vietnam government has banned rooted phones from using any banking app
#334Earlier quoted context omitted.
Wifi? Because it is part 15. That spectrum is less strict. SDRs? Because they are not certified transmitters. They are test RF gear, or a component of a transmitter, not an end-user product. Cellular radios in a PC? You don't get root on those. Same situation as they are in a cell phone: They are licensed-band transmitters, and they are required to be tamper proof to protect the licensee.
> Cellular radios in a PC? You don't get root on those. Same situation as they are in a cell phone: They are licensed-band transmitters, and they are required to be tamper proof to protect the licensee. The original post said: > Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own har…
As of November 2023, zero applications are licensed and capable of playing UHD Blu-Ray disks [0], and PC manufacturers are just not including the hardware necessary to do so.
0: https://www.cyberlink.com/support-center/faq/content?id=2834...
Re: The Vietnam government has banned rooted phones from using any banking app
#335Earlier quoted context omitted.
It is a massive observation of how things look already no more, no less.
Let me clarify my statement: one government agency’s election to use an app for a single purpose isn’t an indicator of much. It’s not like the UK sent out a mandate to private banks or any other private industry on this issue. It’s also only one small country of hundreds. I’d have to question this idea that this is how things “already look.” I can think of very few businesses that I interact with that force me to use…
Re: The Vietnam government has banned rooted phones from using any banking app
#336Government banning insecure open standards and then not providing a secure open standard is atrocious. If I must have an official authorizing thing to prove I'm who I say I am, make it as small as possible. If you mandated that they have to support Yubikey or whatever on open platforms I'd take that as a decent alternative. But just "no you must use a device controlled by somebody else" is not acceptable.
Re: The Vietnam government has banned rooted phones from using any banking app
#337The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…
The real irony here is the use of free software to tear down everything the free software movement stood for.
Re: The Vietnam government has banned rooted phones from using any banking app
#338odd they legislate for it, banks usually do this anyway
The fact it’s the government who cares suggests whose interests the law is serving. Viet Nam is a pretty authoritarian country right now, and it loves the ability to track the activities of citizens.
Anyway it's not like they're the UK and have age ID's for their internet lol
Re: The Vietnam government has banned rooted phones from using any banking app
#339Earlier quoted context omitted.
There's no laws banning this in any European countries that I'm aware of, except maybe Hungary? It's just banks being stupid, consumer-hostile, and anti-competitive.
Well, I've built a bunch of mobile banking apps and we did detect if the phone was rooted, was in dev mode, etc. and it is not because we were "stupid, consumer-hostile, and anti-competitive". If someone steals the secrets from a rooted phone and steals customer's money the bank is on the hook, so banks do everything they can to minimize this risk. There is no way to store customer's secrets in a PC browser securely,…
Re: The Vietnam government has banned rooted phones from using any banking app
#340The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…
It’s not an evil at all. For 99% of people who aren’t “computer people”, when we gave them that, we got the Bonzai Buddy and 47 other malware toolbars installed. Did we forget 2003 already? App sandboxing and system file integrity is one of the most beneficial security features of modern computing, and the vast majority of people have no desire to turn it off. You can buy rootable phones. People overwhelmingly choose…
For the masses, lack of system-level access is a benefit because they won't be able to ruin their device. For hackers and hobbyists, lack of system-level access is a hindrance because they won't be able to control their device.