Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

391–400 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#391

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

I think, practically, everyone will need at least a cheap-ish android or iphone, perhaps $300 (and a new one every few years ...), to be their locked-down "agent" for using financial or government services. It's not for you, it's for the government/banks, it is their agent for talking to you. Kinda weird, if you think about it. But that seems to be the way it's heading.

> everyone will need at least a cheap-ish android or iphone, perhaps $300

No, the much more secure while at the same time liberty-preserving way to do this are heavily sandboxed secure enclaves with attestation, or even better standalone tamper-proof devices capable of attestation.

Like the ones practically every bank customer already has in their wallet, and for which most phones have a built-in reader these days... The only thing missing is a secure input and output channel, like a small built-in display and a button or biometric input.

In any case, I somewhat empathize with banks in that they want to ensure that my transaction confirmation device is not compromised, but getting to dictate what software does and doesn't run on my own hardware outside of maybe a narrow sandbox needed to do that is a no-go.

Re: The Vietnam government has banned rooted phones from using any banking app

#392
post #187

Earlier quoted context omitted.

Not if you want to use tap-to-pay systems.

Just use your credit card

And adding to this: using the card gives me peace of mind because it never runs out of battery. If I only used my phone for payments and it died while I was out, I would be screwed. Can't call a friend, can't pay for transit, I guess I'm walking for hours to get home? Since I use the card to pay, if my phone dies, the worst thing that happens to me is I might need to look at a physical map to figure out which train to take home.

Re: The Vietnam government has banned rooted phones from using any banking app

#394

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

Root access is irrelevant; modification detection is relevant. If your OS was sealed-attested, root wouldn’t matter (Macs have this in shipping production by default and it works fine for everyday users). For modding, go for it; your modded OS will be signed by your own crypto key (or none at all). Unfortunately, the media and the businesses and quite a lot of expert users confuse root-access-enabled as a convenient modification-detection method (presumably Google’s core is more competent than that, has anyone studied it?). Sigh.

Re: The Vietnam government has banned rooted phones from using any banking app

#395
post #333

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

It’s not an evil at all. For 99% of people who aren’t “computer people”, when we gave them that, we got the Bonzai Buddy and 47 other malware toolbars installed. Did we forget 2003 already? App sandboxing and system file integrity is one of the most beneficial security features of modern computing, and the vast majority of people have no desire to turn it off. You can buy rootable phones. People overwhelmingly choose…

It is an evil because there are infinite ways to solve any problem, not just this one. Describing some problem in no way validates any particular response as being even worth the trade-off let alone flat out necessary and unavoidable.

Further, the people promulgating this sort of solution know this. The evil is that they are wittingly using a problem as the excuse and the cover to get something else they want which they would otherwise never get and have no right to.

For everyone who is doing this knowingly, there are countless other sincere but unwitting tools haplessly just buying the line sold to them. So you might be able to say you are not evil for supporting this kind of policy, but all that means is that you are either a witting or unwitting tool of the evil policy.

"Rapes happen behind closed doors, therefore we have to remove all doors. No one denies that rape happens and that it's a bad thing. And it's irrerfutable that without doors that close, no one would be able to get away with a rape. And so, the only grown-up thing to do is agree to give up doors that close. It's not an evil at all."

Re: The Vietnam government has banned rooted phones from using any banking app

#396
post #68

Earlier quoted context omitted.

Don't like that. I'm of the "if you're going to do something important, do it on your PC" generation. I do not want a future where I lose my phone and I can no longer access my bank.

Claim you don't have a phone, and they'll find a solution.

They won't find a solution to your problem, when one is obvious: buy a phone.

They'll find a solution to their problem, which is you: apologize for losing you as a customer, and express a hope that you'll consider them again after you've bought a phone.

Re: The Vietnam government has banned rooted phones from using any banking app

#397
post #390

Earlier quoted context omitted.

> App sandboxing and system file integrity is one of the most beneficial security features of modern computing, You can have sandboxing and system integrity while still giving the user overrides. But hey this is not Google and Apple's business model because it makes you less dependent on them. And it interferes with their sweet 30% rent-seeking app stores. Mobile security works this way not because it's best for us b…

> You can have sandboxing and system integrity while still giving the user overrides. How? What kind of overrides? You mean that Safetynet could still report attestations? I have no idea how it works, but doesn't it require a chain of trust, starting from a known boot image, then every process that can write to arbitrary memory needs to be a known image? (And even that might not be enough if there are ways to dynamic…

You can have integrity checks that allow the user to choose which signing keys to trust. Some PCs with secure boot, and some phones such as Pixel devices support this. GrapheneOS uses it.

In those systems, it won't boot without a good signature, so the user is protected against attacks that break the user's chosen chain of trust.

Remote attestation of consumer devices, e.g. Safetynet is evil.

Re: The Vietnam government has banned rooted phones from using any banking app

#398

Earlier quoted context omitted.

That seems to be the way the wind is blowing. Most new 'challengers' I've tried in the US either have no web access at all, or limited access that lets you view balance but not do things like transfers.

I long ago decided never again to use anything but a credit union, and this makes me glad that credit unions tend not to ride the forefront of tech trends.

Me too, but credit unions are being rolled up by private equity.

Re: The Vietnam government has banned rooted phones from using any banking app

#399

Earlier quoted context omitted.

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

Many of us would need the unmodified one to have a working SIM because a lot of those providers require SMS in their auth flow. Expensive for many of us. For me it'll mean I have to do these things on a computer. Until they come for that one too of course.

Don't they usually SMS you a TOTP code that you could then just type into the unmodified one? I've seen some apps that snoop on your SMS to automatically grab the TOTP code but I've never come across one that wouldn't let you manually type it in.

Re: The Vietnam government has banned rooted phones from using any banking app

#400
post #333

Earlier quoted context omitted.

It’s not an evil at all. For 99% of people who aren’t “computer people”, when we gave them that, we got the Bonzai Buddy and 47 other malware toolbars installed. Did we forget 2003 already? App sandboxing and system file integrity is one of the most beneficial security features of modern computing, and the vast majority of people have no desire to turn it off. You can buy rootable phones. People overwhelmingly choose…

The problem is mostly that normal people can't be trusted with system-level access but some people can. And it's literally, provably not possible to tell them apart. For the masses, lack of system-level access is a benefit because they won't be able to ruin their device. For hackers and hobbyists, lack of system-level access is a hindrance because they won't be able to control their device.

[deleted]
Post reply on HN