Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

601–610 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#601
post #187

Earlier quoted context omitted.

Not if you want to use tap-to-pay systems.

Smartwatches are great for this.

In fact, a smartwatch might be the ideal "second personal portable computer that's just for auth and banking" that is being proposed by various commentors here.

Requiring that everyone carry a smartwatch (or other smartwatch-based compute nugget) around to participate in civic life is a bit less onerous than requiring everyone carry around a smartphone; smartwatches are both cheaper and smaller.

And, to me at least, smartwatches are much more of an appliance than a smartphone is. Nobody's really begging to sideload apps onto their smartwatch, or to install an alternate launcher onto them, etc. Smartwatches just kind of "do what they should obviously do given the hardware design and HCI affordances" — kind of like a calculator.

As a bonus, unlike smartphones, most smartwatches to this day still aren't independently connected to cellular networks; so the average wiretapped smartwatch can't be used to surveil your location and activities in quite the same way that a wiretapped smartphone can.

Re: The Vietnam government has banned rooted phones from using any banking app

#602
post #592

Earlier quoted context omitted.

Note how this says nothing about root lockout. The fact that no root lockout means "inadequate protection" is something you projected onto this statement and that's the part I'm addressing in my comment. No one actually got fined for root protection specifically.

Regulators love vague standards like "inadequate protection" because it means they can implement a ratchet effect without needing to understand anything or constantly rewrite the laws. If someone gets hurt they just look around at whatever the competition is doing, pick the most extreme thing, and declare that any other standard is inadequate. So sure, if you want to not use security tactics your competitors are usin…

Yeah, so you admit there's no real legal basis for those kind of restrictions.

Which anyone of us who worked with banks, mobile, banking security and their legal already knew. They're a source of greatest security hits like "let's use SMS for only auth for web banking" after all.

But what's really hiding behind all your fluff is something else: Abusing users with root lockouts is EASY for the programmers at banks. The auditors have a checkbox "root lockout" and they tick the box. Legal ticks the box. CISO ticks the box. All happy, who cares about user. That's what this is all about. The insulting thing is trying to sell it like some kind of security feature.

Re: The Vietnam government has banned rooted phones from using any banking app

#603
post #293
post #205

Earlier quoted context omitted.

> If someone steals the secrets from a rooted phone and steals customer's money the bank is on the hook, so banks do everything they can to minimize this risk. Now that's just not true now, is it? Sure the lawyers told you that (the ones that get paid to tell you that), but nowhere in EU was a bank actually fined for not root checking a device. They were plenty fined by being utterly incompetent with security practic…

No bank got fined for not root checking, correct. However banks are on the hook for unauthorized transactions. And "unauthorized" means different thing in different countries. In some jurisdictions if bank can prove that transaction was made with customer's key then customer can not demand their money back. That's the best case, but there are only few of such jurisdictions and even there the burden of proof is on the…

> In any case dealing with all this is too expensive and risky.

[Citation needed]

How much does it cost? How risky?

Re: The Vietnam government has banned rooted phones from using any banking app

#604

Earlier quoted context omitted.

With all due respect - I totally understand you may need a rooted phone, I’m just curious what you use it for? I’ve never had a modified or rooted phone so I don’t know of any of the reasons you might need one.

I want to backup my entire phone on a local server I own. Apps, app data, settings, WiFi passwords, call logs, etc. Good luck without root.

Cool

Re: The Vietnam government has banned rooted phones from using any banking app

#605
post #370

Earlier quoted context omitted.

With all due respect - I totally understand you may need a rooted phone, I’m just curious what you use it for? I’ve never had a modified or rooted phone so I don’t know of any of the reasons you might need one.

To stop third parties selling your location information. https://www.ftc.gov/news-events/news/press-releases/2024/12/...

Interesting, how does rooting your phone help you avoid that?

Re: The Vietnam government has banned rooted phones from using any banking app

#606

Earlier quoted context omitted.

With all due respect - I totally understand you may need a rooted phone, I’m just curious what you use it for? I’ve never had a modified or rooted phone so I don’t know of any of the reasons you might need one.

System wide adblocking, being able to backup any app are the top two reasons I'd still root my phones if i had any choice. You'd be amazed by the battery life improvement you'd get by just blocking ads.. I deliberately avoid all banking apps even though i didn't root my phone, but i have to use Google Pay a lot. So... That's the only reason this phone I'm typing on isn't rooted.

I do have a VPN which blocks a lot of ads at the dns level but better Adblock would be nice

Re: The Vietnam government has banned rooted phones from using any banking app

#607

Earlier quoted context omitted.

With all due respect - I totally understand you may need a rooted phone, I’m just curious what you use it for? I’ve never had a modified or rooted phone so I don’t know of any of the reasons you might need one.

You start to use it because you care about privacy and your data. But now it's just to avoid all the crap Google and OEMs put into the phone. Same story is with PC and Windows. To quote one smart guy: "I'm not in the mood to be treated as a chimp." And that's it.

That’s fair! Doesn’t sound like something that’s likely to get the majority of users interested though unfortunately

Re: The Vietnam government has banned rooted phones from using any banking app

#608
post #75
post #69

Socialist Republic of Vietnam: our phone

Vietnam is as far from socialism as China. It's more like wild capitalism.

when exactly Communist Party of Vietnam abandoned Marxism - Leninism? Any official statement claims that?

Re: The Vietnam government has banned rooted phones from using any banking app

#609

Earlier quoted context omitted.

Many of us would need the unmodified one to have a working SIM because a lot of those providers require SMS in their auth flow. Expensive for many of us. For me it'll mean I have to do these things on a computer. Until they come for that one too of course.

I use the eSim feature in my iPhone, this worked well.

Do you mean you have the same esim on both phones but normally activated on the burner phone except when you need it on the unmodified one w/o access to burner phone?

Re: The Vietnam government has banned rooted phones from using any banking app

#610
post #487
post #391

Earlier quoted context omitted.

> everyone will need at least a cheap-ish android or iphone, perhaps $300 No, the much more secure while at the same time liberty-preserving way to do this are heavily sandboxed secure enclaves with attestation, or even better standalone tamper-proof devices capable of attestation. Like the ones practically every bank customer already has in their wallet, and for which most phones have a built-in reader these days...…

In principle I'm certainly on board with the idea, but the problem is - at least in the Anglosphere, probably further - that the financial system is part of the military and policing systems. They are a powerful and persistent lobby that want a phone to be able to provide enough who-what-when-where to be able to put someone in jail or in extreme cases drop a missile on them. That is one of the reasons the crypto mark…

What kind of integrity are you talking about?

Merkle trees can prevent tampering after the fact, yes.

But if you include collusion, there's no way for the blockchain itself to know who is colluding and where they are so.

Smart contracts may be vulnerable or malicious.

Wallets can be emptied.

Centralized exchanges and similar entities still exist.

Policing systems are still needed, because as long as there is something of value and there is still "evil" in the world, someone will try to steal it or damage it.

Post reply on HN