Live data from Hacker News

The Vietnam government has banned rooted phones from using any banking app

xdaforums.com

611–620 of 643 posts

Re: The Vietnam government has banned rooted phones from using any banking app

#611
post #132

When I used to work on the Vanguard authentication team, we blocked Vietnam from access because of too much fraud (not my choice). But it was funny because we had Vietnam based clients, so there were a couple HNW clients in the logs that you could see who would log in from Vietnam/Russia/Wherever, get blocked, open their vpn, then log in from England. This was a while back, but even then there was a push for things l…

I'd be really interested to know whether a significant amount of fraud and fraud attempts involve devices with root or non-stock operating systems. This has always struck me as a matter of checkbox compliance rather than a commonly-exploited attack vector, though I'll grant that's partially because few people actually use such devices.

In my experience, people don't really care about rooted devices and non-stock Android -- if those devices are actually phones in the hands of human users.

The big fraud vector is running emulators in datacenters or skipping running the app entirely and talking directly to endpoints. Requiring that an entity making a request is from a real phone and is from (approximately) your app adds friction and is effective at reducing fraud.

Re: The Vietnam government has banned rooted phones from using any banking app

#612

Earlier quoted context omitted.

Only if people roll over and take it. The squeaky wheel gets the grease.

99.9999% of people are “rolling over and taking it” because they don’t have an aversion to installing their bank’s app on their phone. Most people would find this viewpoint to be strange.

IMO Most people simply lack the context and knowledge to understand the viewpoint.

Re: The Vietnam government has banned rooted phones from using any banking app

#613
post #603
post #293

Earlier quoted context omitted.

No bank got fined for not root checking, correct. However banks are on the hook for unauthorized transactions. And "unauthorized" means different thing in different countries. In some jurisdictions if bank can prove that transaction was made with customer's key then customer can not demand their money back. That's the best case, but there are only few of such jurisdictions and even there the burden of proof is on the…

> In any case dealing with all this is too expensive and risky. [Citation needed] How much does it cost? How risky?

Let's say you are a bank and you make $10 on each $100K transfer. If customer disputes a transaction and you must return the money, you lose the whole amount and twice as much on lawyers, internal audit, compliance people working on the case. With this math you can't afford the risk if it is more than 1 in 30000.

For many European banks the math is even more brutal.

Re: The Vietnam government has banned rooted phones from using any banking app

#614
post #54

Earlier quoted context omitted.

Let me clarify my statement: one government agency’s election to use an app for a single purpose isn’t an indicator of much. It’s not like the UK sent out a mandate to private banks or any other private industry on this issue. It’s also only one small country of hundreds. I’d have to question this idea that this is how things “already look.” I can think of very few businesses that I interact with that force me to use…

This type of election to use an app by a government agency sets the tone, and more importantly tends to redefine "best practices." Would you want to be the one private entity known to not be using best practices? Would your risk officers or lawyers be OK with that decision?

Since when does government set trends in private industry?

I’d like to know what private businesses are copying the kind of workflows and customer experience you get at the USPS or DMV.

Re: The Vietnam government has banned rooted phones from using any banking app

#615
Random Idea: A Completely Open-Source Banking App...

Consider an Open-Source Web Browser (Chromium, FireFox, ?, ???, or any open-source browser from: https://github.com/nerdyslacker/desktop-web-browsers).

OK.

We know the following:

A) That most Banks have web pages / websites which can be accessed via one or more of the above web browsers (AKA "Online Banking"), where the provided functionality is exactly the same, or very close to the functionality provided by stand-alone banking Apps

B) That the source code for any open-source web browser is available, and can be downloaded (A self-evident truth!)

From which the following understanding can be derived:

C) The security for the transactions (user authentication, authorization, etc., etc.) is NOT provided on the client side (the user's computer or smartphone) by an obfuscated "binary black box" piece of software where source code is not provided, but rather on the server side (the Bank's side!)

(Oh sure, Web Browsers provide encryption to prevent the middle segment of the communication path, the Internet, from listening in, but the encryption libraries of open-source web browsers are also typically themselves open-source, thus easily transferred to / imported into the source code bases / software component stack -- of other Apps!)

Well, if we know A), B), and C), then we also understand that a truly Open-Source Banking App, giving exactly the same security guarantees that an Open-Source Web Browser does today, is possible!

Such an app, if it were to exist, due to its open-source nature, would not be bound by artificial constraints, such as the absence or presence of an underlying rooted Smartphone, or not...

Also, in theory such an App, were it to exist, could be ran on very minimal, possibly more secure (than your average bloated Smartphone) alternative hardware...

Also, if you think about it... Bitcoin and other cryptocurrency apps -- are fundamentally that App (!) -- just that they use the Blockchain, and not a Bank, as the back-end! :-)

You know, you have a payment-provider App. It could have any number of back-ends to it... Bank, Blockchain, ?, ???

You tell me... :-)

Re: The Vietnam government has banned rooted phones from using any banking app

#616

Earlier quoted context omitted.

It's the ability to take a picture of a check and deposit it into your account that way, vs having to take the check to an actual branch of a bank. Here in the US, I still get checks frequently enough that it's nice to have.

Oh, cheques . I don't think I've seen one of those since the early 90s. Do people still use them?

"Check" is the US spelling, and I still see them often enough here.

Re: The Vietnam government has banned rooted phones from using any banking app

#617

Earlier quoted context omitted.

I’ve seen dedicated hardware devices which scan a QR-like code and show this in a little screen of their own. The bank provides them and does not require any app. I only know of a single bank using this.

>I only know of a single bank using this. If it's not Crédit Mutuel then you now know of a second bank using this method.

I am interested too, my fallback bank trapped me (or my courage to resist), the fallback of fallback would be crypto but i am not sure i want to depend on this too...

Meanwhile, the last hope is that people will use more cash (if the digital world is too hostile, oh wait it is!)

Re: The Vietnam government has banned rooted phones from using any banking app

#618
post #542
post #487

Earlier quoted context omitted.

In principle I'm certainly on board with the idea, but the problem is - at least in the Anglosphere, probably further - that the financial system is part of the military and policing systems. They are a powerful and persistent lobby that want a phone to be able to provide enough who-what-when-where to be able to put someone in jail or in extreme cases drop a missile on them. That is one of the reasons the crypto mark…

Crypto is decentralized but that only goes so far. There’s plenty of instances where bunch of armed guys have taken over data centers not just vaults.

I would like to have the opportunity to consider a decentralized consensus algorithm that could accommodate nation state adversaries regularly. Not simply something cryptographically secure and distributed but something which can retroactively route around nodes who are temporarily bad due to external circumstances.

Re: The Vietnam government has banned rooted phones from using any banking app

#619
post #22
post #5

I really don't understand this. My line of thinking is that if someone is technical enough to root his phone he understands the risks. Why would they force banking apps to detect and not work on rooted phones? Why would the government care so much?

A phone given for repair by a non-technical person can be rooted without their knowledge. The repair person potentially can install malware. We cannot assume the owners of the rooted phone themselves have rooted the phone.

Assuming the owner gave the shop the pin. If so, the shop can already steal a lot of data from the phone. Why bother with persistent malware at this point?

You already have to trust the repair shop with your data. Installing persistent malware on phones is already illegal. What's the point of this extra software protection in this case? To prevent a 0.00001% chance hack? The type of hack that would put the repair men in jail?

Not to even mention that modern phones are basically unfixable.

Re: The Vietnam government has banned rooted phones from using any banking app

#620

Earlier quoted context omitted.

I think, practically, everyone will need at least a cheap-ish android or iphone, perhaps $300 (and a new one every few years ...), to be their locked-down "agent" for using financial or government services. It's not for you, it's for the government/banks, it is their agent for talking to you. Kinda weird, if you think about it. But that seems to be the way it's heading.

Nah, if a bank or some other civic entity wants to have a "secure agent" for transactions/communication with me, then they should be the ones providing that. Much like I expect my employer to provide me hardware, and that hardware is used exclusively for work. I shouldn't have to spend my own money on another device, nor should they be asserting their desires for control onto my own devices.

You are free to use your pc. But it’s up to you if you want the more advanced features on a phone app.
Post reply on HN