Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

591–600 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#591
post #99
post #43

Earlier quoted context omitted.

There's no laws banning this in any European countries that I'm aware of, except maybe Hungary? It's just banks being stupid, consumer-hostile, and anti-competitive.

Well, I've built a bunch of mobile banking apps and we did detect if the phone was rooted, was in dev mode, etc. and it is not because we were "stupid, consumer-hostile, and anti-competitive". If someone steals the secrets from a rooted phone and steals customer's money the bank is on the hook, so banks do everything they can to minimize this risk. There is no way to store customer's secrets in a PC browser securely,…

Great, so the no-name iPhone clone in China passes your test but EOS doesn't.

There's no way to assess the security of a rom from an app and it's about time that banks learn this reality.

Software on mobile is even more fragmented and less standardized than on desktop

Re: The Vietnam government has banned rooted phones from using any banking app

#592
post #205

Earlier quoted context omitted.

> If someone steals the secrets from a rooted phone and steals customer's money the bank is on the hook, so banks do everything they can to minimize this risk. Now that's just not true now, is it? Sure the lawyers told you that (the ones that get paid to tell you that), but nowhere in EU was a bank actually fined for not root checking a device. They were plenty fined by being utterly incompetent with security practic…

Literally three days ago: https://www.complianceweek.com/regulatory-policy/eu-agrees-r... "Payment service providers (PSPs) operating in the EU will have to cover customers’ losses from fraud if their fraud protection regimes are inadequate or poorly implemented under new EU rules." Other places like the UK had such rules already.

Note how this says nothing about root lockout.

The fact that no root lockout means "inadequate protection" is something you projected onto this statement and that's the part I'm addressing in my comment.

No one actually got fined for root protection specifically.

Re: The Vietnam government has banned rooted phones from using any banking app

#593

Earlier quoted context omitted.

What's a mobile deposit and why do you need an app to check it?

It's the ability to take a picture of a check and deposit it into your account that way, vs having to take the check to an actual branch of a bank. Here in the US, I still get checks frequently enough that it's nice to have.

Oh, cheques.

I don't think I've seen one of those since the early 90s. Do people still use them?

Re: The Vietnam government has banned rooted phones from using any banking app

#594
post #561
post #132

Earlier quoted context omitted.

I'd be really interested to know whether a significant amount of fraud and fraud attempts involve devices with root or non-stock operating systems. This has always struck me as a matter of checkbox compliance rather than a commonly-exploited attack vector, though I'll grant that's partially because few people actually use such devices.

I work at Grab (SEA rideshare and licensed bank, but not licensed in VN). A significant amount of fraud comes from scammers convincing victims to installed malicious apps. They fake being a customer service provider. Banks don't want their customer's to lose their money and they don't have the tools to protect them from themselves. For all the privacy reasons, app stores don't even banks enough tools to identify and…

Tricking someone into installing a malicious app usually doesn't involve them having a third-party or modified operating system on their phone. I'm asking about that because I believe it's a hypothetical risk rather than a problem in practice and I'm curious about any evidence to the contrary.

Re: The Vietnam government has banned rooted phones from using any banking app

#595
post #592

Earlier quoted context omitted.

Literally three days ago: https://www.complianceweek.com/regulatory-policy/eu-agrees-r... "Payment service providers (PSPs) operating in the EU will have to cover customers’ losses from fraud if their fraud protection regimes are inadequate or poorly implemented under new EU rules." Other places like the UK had such rules already.

Note how this says nothing about root lockout. The fact that no root lockout means "inadequate protection" is something you projected onto this statement and that's the part I'm addressing in my comment. No one actually got fined for root protection specifically.

Regulators love vague standards like "inadequate protection" because it means they can implement a ratchet effect without needing to understand anything or constantly rewrite the laws. If someone gets hurt they just look around at whatever the competition is doing, pick the most extreme thing, and declare that any other standard is inadequate.

So sure, if you want to not use security tactics your competitors are using and then try to lawyer out of it by arguing, "it didn't specifically say we had to do that" in front of the EU Commission, go ahead. But don't blame the banks that are more realistic about how this works.

Re: The Vietnam government has banned rooted phones from using any banking app

#596
post #481

Earlier quoted context omitted.

Nah, if a bank or some other civic entity wants to have a "secure agent" for transactions/communication with me, then they should be the ones providing that. Much like I expect my employer to provide me hardware, and that hardware is used exclusively for work. I shouldn't have to spend my own money on another device, nor should they be asserting their desires for control onto my own devices.

And exactly who's going to pay for that?

At least here in the UK for years if you opened a bank account, even a free one, you'd get a debit card + a device for generating secure keys for online and telephone banking. Like a standalone, battery powered device the size of a calculator.

Like....why can't we just go back to that? Banks were "fine"(doesn't mean happy) to shoulder the cost of these devices then.

Re: The Vietnam government has banned rooted phones from using any banking app

#599

The biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loadin…

I grew up in the 90s during a time where the only way to get software was from the local computer store. Pop the disk into your computer and you're running the software, warts and all.

Now that physical media is all but gone, computer manufacturers (both personal computers and phones) found it behooved them to essentially control the market with regards to what can get installed on your computer. Oh, and conveniently, they charge a fee for developers to use this "service," and take a percentage of what the developer earns by selling software on their "service." And somehow in the late 2000s early 2010s, it just became normalized, and somehow the term for being able to install software on a device you supposedly own became a scary term, "jailbreak."

Granted, jailbreaking was often used for piracy, but the fact that there needed to be a process at all confounds me.

My mom has an iPhone and she manages to install a bunch of weird things on her phone, like anti-virus software that almost certainly don't scan for viruses, but are all too happy to take your money to make your phone more secure. These are things that the App Store "service" should have guarded against if they were indeed doing their jobs and protecting consumers from bad software.

And, I wouldn't be surprised if she'd be locked out of her banking app eventually because [insert entity here] deems her phone too old to update her banking app. She's "following the rules" and still getting screwed over.

Re: The Vietnam government has banned rooted phones from using any banking app

#600

And so it begins... Or continues... Apple is already a walled garden, granting you only access to your hardware and they see fit. Google desperately wants to follow suit by enforcing developer registration (which is just the first step). And now this. This is will happen in the EU and US as well. And always in the name of security, safety, or "will nobody think of the children?!" My hardware, my choice, period.

> My hardware, my choice, period. You can choose to not use the app. The bank has a choice on how customers interact with it. The government, regulating banks, and often acting as insurance for lost money, has a choice on setting required security standards. Balancing all these is difficult.

Fair enough.

If there remains an option to still opt in to full control over my h/w at the expense of some vendors saying that I can't use my phone with them, that's good enough.

Post reply on HN