5 ms·
I think browser-based streaming is the only scenario impacted. Apps can already interrogate their platform and make play/no play decisions. They are also alrea
by btbuilder 5y ago
I think browser-based streaming is the only scenario impacted. Apps can already interrogate their platform and make play/no play decisions.
They are also already limiting (weakly) the max number of devices that can playback which requires some level of device identification, just not at the confidence required for authentication.
- dathinab 5y agoWell, the fact that I can't do credit card payments for some banks if I don't have an iphone or non rooted, google android phone is a problem which already exists. Worse supposedly this is for security, but attackers which pulled of a privilege escalation tend to have enough ways to make sure that non of this detection finds them. In the end it just makes sure you can't mess with your own credit card 2FA process by not allowing you to control the device you own.
- ryukafalz 5y agoThis should be obvious from your comment but I think it's worth calling something out explicitly here: a bank that does that is mandating that you accept either Apple's or Google's terms of service. That's a lot of power to give to two huge companies. I think we'd do well to provide the option to use open protocols when possible, to avoid further entrenching the Apple/Google duopoly.
- lotsofpulp 5y agoThat is a job for the government. They should have made electronic payments and electronic accounts for everyone a utility many years ago.
- franga2000 5y agoThis 10000x! A bank account is sure as hell more of a utility than a landline! You need a bank account to do basically anything and yet consumer banking is largely unregulated (in the consumer relation sense, they are regulated on the economic side of course). Payments take upwards of 24h and only during work hours (?!?), there are no "easy switch" rewuirements, mobile apps use shit like SafetyNet and I've had banks legit tell me "just buy a phone from this list of manufacturers"... PSD2 is trash that only covers B2B interoperability and mandates a security method that has been known as broken since its invention (SMS 2FA).
- floatboth 5y agoWhat bank doesn't have a regular web app?
- duckmysick 5y agoIn the future banks may start accepting connections only from a handful of approved browsers. Similarly to how 4k steaming on Netflix is not available on all browsers.
- dathinab 5y agoIt's about the EU mandated 2FA auth for online shopping. E.g. with an credit card. Due to the way it integrates into websites (or more specifically doesn't) classical approaches like SMS 2FA (insecure anyway) but also TOTP or FIDO2 do not work. Instead a notification is send to a preconfigured app where you then confirm it. Furthermore as the app and payment might be on the same device the app uses the fingerprint reader/(probably some Google TPM/secrets API idk.). Theoretically other approaches should work, but practically they tend to not work reliable or at all in most situations. Technically web based solutions could be possible by combining a FIDO stick with browser based push notifications, practicality they (Banks) bother or there are legal anoyences.
- jgerrish 5y agoI think we'd do well to provide the option to use open protocols when possible. Of course, the PR copy just writes itself, doesn't it? AD administrators, Apple and Google, banks and everyone else can benefit from context aware authorization. If the state of your phone is stolen or "compromised", you want immediate Peace of Mind. Even if it's just misplaced, having that kind of flexibility is just great.
- pishpash 5y agoIt does seem like a privilege escalation in the reverse direction, allowing banks to escalate a decision about security into one about devices. They should not have that power, and it's far from the only solution.
- themacguffinman 5y ago> but attackers which pulled of a privilege escalation tend to have enough ways to make sure that non of this detection finds them The point of these restrictions is to ensure that your device isn't unusually vulnerable to privilege escalation in the first place. If you let them, some users will root their phone, disable all protections, install an malware-filled Fortnite apk from a random website then stick their credit card company with the bill for fraud when their user-mangled system fails to secure their secrets. You want to mod the shit out of your Android phone? Go ahead. Just don't expect other companies to deal with your shit, they're not obligated to deal with whatever insecure garbage you turn your phone into.
- Dylan16807 5y agoThat might at least be half a reasonable argument if they didn't all allow desktop logins that could be stuffed with malware. > they're not obligated to deal with whatever insecure garbage you turn your phone into Banks probably should be obligated to let you connect over standard protocols.
- themacguffinman 5y agoIn practice, many credit unions/banks will only support recent versions of major desktop browsers (ie. the big three: Chrome, Firefox, Safari) which are known to mandate a good level of security. These browsers will usually have their own OS requirements. For eg Safari is tied to macOS versions directly while Chrome will drop support for older unmaintained operating systems like Windows XP. Any system can have malware. That's not the point. To repeat my point again: client restrictions are about making sure user devices are not unusually vulnerable to malware. For example, any Windows device may be infected with malware, but if you're still running Windows XP you're vulnerable to a much larger variety of known malware and more severe exploits. Hence why businesses will want to support only modern versions of eg Chrome which itself will require modern versions of operating systems.
- Dylan16807 5y agoSo require I have an up to date browser on my phone. Don't require that I haven't rooted it when every desktop is in an equivalent security state. That's not enough to be "unusually vulnerable". I'm not asking to use a 10 year old version of android that no modern browsers support any more and is missing many security features.
- 0xedd 5y agoCars come with AndroidAuto (and whatever is for iOS). Only apps signed by Google can communicate with AndroidAuto. I don't want to use a Google phone or app to display OSM on my car's media screen. Why is this legal?
- chipotle_coyote 5y agoOnce you're talking about interactive information displays in cars that can be accessed while the vehicle is in motion, traffic and highway safety regulations start cropping up. When you ask "Why is this legal," try rephrasing it to, "Why is it legal for companies to make it so difficult to play Doom on my BMW's touch screen," and you will probably arrive at the answer.
- HPsquared 5y agoAlso, "why is it illegal to sell cars that can play Doom while driving"