Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

581–590 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#581
post #455

Earlier quoted context omitted.

[flagged]

There's a difference between many people preferring not to have control over the device they own and it being illegal to have such control. Yes, absolutely, most people would be better off not having that control and most of those people are also fine with not having it. But everyone, for better or worse, has the right to demand that control if they want it.

You do have that right. You just can't use banking apps in Vietnam on such devices.

This is really no different to the antivaxxer arguments in the peak pandemic era. Some people didn't want vaccines. Fine. Well, not fine. None of it is based on any kind of rational argument but nobody was strapped down and forced to have one. But not having one meant there were certain jobs you couldn't have. Just like for decades unvaccinated children couldn't go to public school.

You make a choice and if you don't like the consequences of that choice, that's a you problem.

Re: The Vietnam government has banned rooted phones from using any banking app

#582

Earlier quoted context omitted.

Root access is irrelevant; modification detection is relevant. If your OS was sealed-attested, root wouldn’t matter (Macs have this in shipping production by default and it works fine for everyday users). For modding, go for it; your modded OS will be signed by your own crypto key (or none at all). Unfortunately, the media and the businesses and quite a lot of expert users confuse root-access-enabled as a convenient…

Put like this, root access is indeed irrelevant. The ability to modify is what we want , i.e. what freedom of general-purpose computation is. The very thing banks and other businesses take away from us.

That's not exactly correct, at least in the U.S. Banks don't take away the right to modify, banks discriminate against modification.

Businesses, in general, have the right to refuse service to anyone for any reason except when their refusals either explicitly, or implicitly by pattern of behavior, derive from one or more characteristics that are protected from discrimination under law. The characteristic of having rooted, and/or having modified, a device is not currently protected from discrimination, and so businesses — who are self-serving to the extreme and minmaxing risk vs. profit just like any good video game player would — are within their legal rights to discriminate against users who modify their mobile phones.

You can see a similar pattern taking effect in the car modification industry; California requires tens of thousands of dollars to assess whether a car modification is "legal" to sell there, due to the intersections of gas vehicle smog laws and the tendency of vehicle owners who modify their vehicle to be likely to, just as businesses do above, selfishly minmax lower-emissions vs. higher-performance behaviors in the car's components and programming. As there exists no categorical protection against undue discrimination for "those who modify their property", one such as myself who modifies their vehicle without intent to reduce or defeat low-emissions behaviors has no recourse to claim that the state's $20,000 test fee is discriminatory against personal use by individuals. I support the societal-level necessity of enforcement in this area, but that doesn't excuse charging $20,000 to a for-profit business and then $20,000 to a personal-use resident.

So, the true solution, in a U.S. constitutional context anyways, is to amend the protected categories under the Bill of Rights to include "individuals who modify their own possessions" as a category that is protected from undue discrimination. It's a simple enough change from a written perspective. Perhaps California or the E.U. will enact it first?

Note, however, that undue does not mean always. Digital ID checks should be restricted to devices booted into sealed-attested mode for the same reason that notarization apps should — faked/stolen digital IDs carry severe and broad-spectrum risks to an entire society of individuals — but banks simply trying to decrease their fraud reimbursement expenses have insufficient cause to discriminate against account holders accessing their accounts. I would absolutely accepted "not permitted to initiate outbound transfers in excess of $10,000" as a compromise.

It becomes more unclear when you consider e.g. Apple Pay, and Apple Music. Both currently deny service to those whose macOS is not sealed and attested. One could make a very convincing case that digital wallets are a case where the benefits of sealed attestations are a necessary case of discrimination against those who modify their devices; financial fraud is a nightmare for both users and banks, after all! But there is no convincing case that being able to listen to music albums with a modified device is somehow a threat both to users and to the music industry, and so Apple would find their demand for sealed+attested to be illegal discrimination by Apple Music.

I suspect the outcome here is that we see devices that offer a sealed-attested 'wallet' mode, activated by a hardware switch function of some fashion, that temporarily seizes control of the device in order to create a protected environment — with some sort of indicator that can't be falsified by any other software on the device, i.e. the camera green / mic orange LED — so that users can interact with attestation-critical services like ID checks, NFC payment, and MFA requests without having to reboot their device from modified mode. Those who want to install their own attested environment can do so, with the understanding that a great deal of legwork remains to not only earn the world's trust that third-party environments can be secured, but also that both government and corporate environments detest having to decide who to trust themselves and will do their very best to either reject all parties other than a single corporation (E.U. age checks, I'm looking at you!) or will create arcane bullshit obstacles that make it difficult to DIY a secure wallet. Some of that difficulty is completely appropriate for exactly the reasons that secure attestations are appropriate in specific, narrow cases only (same reason I appreciate paper currency having physical anti-counterfeiting technology, but not the stupid constellation): counterfeiting predates humanity, sealed-attestation environments are an excellent defense against entire categories of attacks, and a reasonable level of bureaucratic slowdown is an excellent defense against opportunistic hit-and-run fraud.

Re: The Vietnam government has banned rooted phones from using any banking app

#583
post #5

I really don't understand this. My line of thinking is that if someone is technical enough to root his phone he understands the risks. Why would they force banking apps to detect and not work on rooted phones? Why would the government care so much?

> My line of thinking is that if someone is technical enough to root his phone he understands the risks.

That is a terrible assumption. I had a rooted phone when I was 12 to pirate games. Friends asked me to root theirs. Rooting isn’t hard and lots of people do it (absolute not relative terms)

And the idea that so-called “technical” people know what they’re doing and are hack-proof is hot garbage machismo BS. Modern attacks use social engineering and extremely technical people fall for it all the time. There were several stories on here just this week.

Re: The Vietnam government has banned rooted phones from using any banking app

#584
post #391

Earlier quoted context omitted.

> everyone will need at least a cheap-ish android or iphone, perhaps $300 No, the much more secure while at the same time liberty-preserving way to do this are heavily sandboxed secure enclaves with attestation, or even better standalone tamper-proof devices capable of attestation. Like the ones practically every bank customer already has in their wallet, and for which most phones have a built-in reader these days...…

There's a second layer to the conflict here, in that (e.g.) the banks will want to move the entire flow into whatever secure device, enclave, or "agent" they supply - meanwhile, the whole point of me having a general-purpose computer is to be able to do general-purpose computing that I want within this flow. My favorite, basic example is this: I'd like to create my own basic widget showing me my account balance on my…

> the banks will want to move the entire flow into whatever secure device, enclave, or "agent" they supply - meanwhile, the whole point of me having a general-purpose computer is to be able to do general-purpose computing that I want within this flow.

Sure, you should definitely be able to do what you want with your computer, but you're actually demanding more here (at least in the case of transaction initiation and confirmation): For others to also trust the outcome of whatever you did on your own computer.

Banks are often legally required to cover losses resulting from unauthorized account access, so I can somewhat understand them wanting to minimize the chance of that happening. Sandboxed trusted computing, when done well, can strike that compromise much better than annoying non-solutions like root detection heuristics or invasive full-system attestation.

> As far as I know it, there's no way of making it happen without breaking sandboxing or otherwise hacking the app and/or API endpoints in a way that's likely to break, and likely to get you in trouble with the bank.

Banks should probably be required to make such a read-only API available (and in the EU, they are, to some extent – unfortunately only to "trusted", i.e. regulated and registered, service providers, raising the old question of who determines who is and isn't trusted). This is a very different story from transaction initiation.

Unfortunately, there are also caveats here. It's getting more and more common for companies to require me to "connect my bank account", which often means nothing less than granting them full and persistent account view access.

I think having the API still outweighs the downsides of others also starting to make demands for that access, but it's a slippery slope. For example, Airbnb not too long ago wanted full access to all(!) my Chase accounts to "verify my credit card".

Re: The Vietnam government has banned rooted phones from using any banking app

#586
post #353

Earlier quoted context omitted.

lol you should see how bad it is nowadays. Like 90% of my traffic is from SE Asia or germany trying to scrape my site. I blocked like a dozen countries because of it. Singapore itself is an insane amount of traffic for me.

Singapore could be due to being a common VPN exit node for within SE Asia? Close by and avoids the most common regional blacklists (and gov firewalls of course).

I think it's due to Tencent Cloud providing cheap servers in Singapore. I had the same issue and blocked all of their offending IP ranges from these ASNs and it was all Tencent or Huawei Cloud.

Re: The Vietnam government has banned rooted phones from using any banking app

#587
post #423

Earlier quoted context omitted.

My (Canadian) bank extorted me into installing their app, literally blocking me from doing transfers of my own money without it - I had to install it and take a picture of myself and my ID. After this I was able to switch to sms authentication and delete it, but they’re obviously trying to force people onto the app, and eventually they will do so more aggressively. Of course in Canada we have a banking oligopoly that…

> Of course in Canada we have a banking oligopoly that is effectively there just to rob people Are there any OECD nations that don't have a banking oligopoly? I can think of at least one: Germany, because they have Sparkasse (community banks). Does Canada have community banks like Germany and the United States? If yes, then you should vote with your wallet and switch.

UK has building societies, they function like a bank mostly but are mutual (owned by it's members).

In my experience they are more pleasant to deal with, tend to be smaller/more conservative with tech and you can speak to a human when shit goes sideways.

Mine has never laundered money for the cartels (unlike my other bank) which is a plus as well.

Re: The Vietnam government has banned rooted phones from using any banking app

#588

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

> The biggest "evil" No need for the scare quotes. Forcefully removing people's agency over themselves is pretty much the definition of evil. We do not hurt criminals as punishment anymore, in the civilized age, but we still lock them up. Now, of course we should not equate physical prisons and digital prisons in any other way, but we should absolutely call both forms of imprisonment evil, plain and simple.

>We do not hurt criminals as punishment anymore, in the civilized age

Singapore is quite civilized, and they conduct caning strokes.

Re: The Vietnam government has banned rooted phones from using any banking app

#589
post #481

Earlier quoted context omitted.

And exactly who's going to pay for that?

The issuing entity. They want a "secure device" to do business with me, then they get to issue said device. Otherwise, they just get to be OK with offering me a website or letting me transact with them on my own device that's under my own control without stipulations like requiring attestation, or prohibiting root. The point is, governments nor banks or other private entities, should be getting to dictate what can an…

They're happy to provide that. It's a called debit card that you take to an ATM machine.

It's been popular demand, not financial institutions, driving the change to “the smartphone can do everything, I don't want to take debit/credit cards with me everywhere.”

People don't want an additional card, or yubi key, or printed second factor, or whatever, to authenticate.

They want an app that uses a data connection, and a fingerprint to replace even needed a PIN. They tolerate a second channel: an SMS, if the app automatically reads it. That's as much inconvenience as the general public is willing to put up with.

They're starting to demand that this works offline for smaller spends. And they'll put up with a phone call as a 3rd factor for when they want to unblock a really high spend, like purchasing a car, but it can't happen all the time.

They want this to work reliably, even on holidays, all around the world. And they want the banks to cover losses if it all goes south.

Now try to design a system that covers the requirements people are demanding for, without trusting the terminal the people decided they want to access it from.

Re: The Vietnam government has banned rooted phones from using any banking app

#590

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

I think in the future I will keep two phones, a secure phone for my data, communication and everything and an insecure old phone for banking and government apps.
Post reply on HN