Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

461–470 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#461

Earlier quoted context omitted.

The evil is enshrining other people's choices into law, unnecessarily. There was never going to be anything preventing non-technical folks from buying iPhones. They can and should have what they like. Why should there be a law that forces that same compromise onto anyone who can only afford a single device and needs to use it to access their bank?

Because when you don't do this, people get scammed out of money. If there is a series of buttons you can press to circumvent the anti-scam measures, then the scammers simply walk you through pressing those buttons. If you cover them in giant warning labels the scammers simply add explanations into their patter. The buttons must physically not exist, for gullible people to not get scammed out of money. The next respon…

> Because when you don't do this, people get scammed out of money.

I don't care. Society doesn't exist to keep people safe from their own bad decisions.

Re: The Vietnam government has banned rooted phones from using any banking app

#462

Earlier quoted context omitted.

More painful to manage turning it on/off than to simply leave it in my car. Over the years, I've spent far too much time with different solutions for managing notifications, etc. Turns out simply keeping the older phone after buying a newer one was the easiest approach. No downsides so far. The old phone has the SIM card. The new one doesn't.

Pulling down on control center and pressing “Do not disturb” is hard to manage?

Looking at the phone, disabling the lock, swiping down, and pressing "Do not disturb" is a lot more than just not looking at the phone.

Also, that's only half of it. I have to move it out of "Do not disturb" at some point. Or set a timeline for it. Why should I when I just don't need to?

Also, it's been years since I used "Do not disturb". Does it show notification icons in the drawer on top? That's a definite no-no.

Re: The Vietnam government has banned rooted phones from using any banking app

#463
post #423

Earlier quoted context omitted.

Or ... just don't install the apps and use the browser to do your banking.

My (Canadian) bank extorted me into installing their app, literally blocking me from doing transfers of my own money without it - I had to install it and take a picture of myself and my ID. After this I was able to switch to sms authentication and delete it, but they’re obviously trying to force people onto the app, and eventually they will do so more aggressively. Of course in Canada we have a banking oligopoly that…

May I ask what bank? I use CIBC and RBC. They do not require any apps on the phone to reach whatever services they offer. I use all my work on desktop.

I did install app from CIBC for one single and the only purpose - deposit cheques sent to me by clients to my business account without having to go to ATM or the bank teller.

Re: The Vietnam government has banned rooted phones from using any banking app

#464

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

A bigger evil than banking apps themselves? Commerce ruined computing.

Re: The Vietnam government has banned rooted phones from using any banking app

#465

buy two phones if ur that crazy

You need to use a digital biometric ID managed by the Ministry of Public Security for most services in Vietnam now.

i guess there is less fraud then

Re: The Vietnam government has banned rooted phones from using any banking app

#466
post #324
post #298

Earlier quoted context omitted.

Is this true? The old, standard RSA number generator token key ring device is not permitted in Europe for authorizing bank actions ?

Precisely. You can use and old-style hardware token that only generates numbers to log in, but not to authorize an operation such as a money transfer. The requirement is called "dynamic linking" (the 2FA code must be tied to the specific transaction) and the relevant regulation is PSD2.

There are "simple" hardware tokens that allow for that - you have to enter the amount and part of the destination IBAN and they generate a 2FA number based on that + probably the same number generator it uses for logins.

Re: The Vietnam government has banned rooted phones from using any banking app

#467
post #332

Earlier quoted context omitted.

PC platforms don't have remote attestation infrastructure working.

And surprisingly I can pay securely using my PC, fully rooted, on FOSS software. Hardware tokens have been a thing for decades. There are more second (or third) factor authentication and signing solutions than I can enumerate. Do peope get defrauded using online banking? Sure. But usually not in a way that would be stopped by secure attestation.

The hardware token is itself a form of remote attestation. The reason you need extra hardware is because the PC can't do it.

Re: The Vietnam government has banned rooted phones from using any banking app

#468
post #455

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

[flagged]

So, let root access be opt-in rather than opt-out.

Re: The Vietnam government has banned rooted phones from using any banking app

#469

So, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own…

As I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to…

I take a different approach:

I run a proxmox server on my home Lan with all the services and storage I want, including a wireguard server. My Android phone can then connect to my home LAN services from anywhere in the world (my ISP provides static public IP addresses).

My Android device is then a simple terminal to all my "stuff". It can be locked down as much as they want it to be, as long as it can run WireGuard. I have no use for a rooted phone. In fact I want it to be as hardened as possible in case of theft.

Re: The Vietnam government has banned rooted phones from using any banking app

#470
post #455

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

[flagged]

If it's mandated that banking apps must not run in a user-controlled environment for the sake of security, users should have the right to refuse such "protection" by signing a piece of paperwork at the banks office.
Post reply on HN