4 ms·
You can default to a hardened, secure setup but provide an option to override to those who want to. I don't think anyone is against secure defaults, but many pe
by potamic 1y ago
You can default to a hardened, secure setup but provide an option to override to those who want to. I don't think anyone is against secure defaults, but many people have a problem with designs that say you must not even have an option to override.
- bongodongobob 1y agoYeah, that's rooting your phone. It should be a little difficult. You can do it. And it's good that most people don't.
- gyello 1y agoThe problem is not that rooting is difficult, it's that in most cases now it permanently renders parts of the phone inoperable or makes it impossible to use contactless payments or any banking apps or content streaming apps etc. These additional restrictions are not there for security despite what we are told.
- WarOnPrivacy 1y ago> it's that in most cases now it permanently renders parts of the phone inoperable or makes it impossible to use contactless payments or any banking apps or content streaming apps etc. I've had to cloak the rooted state from an app or two or they'd choose to withhold functionality. That was a couple of phones ago. I've not had trouble with banking, payments, etc since.
- miki123211 1y agoThey're for the bank's (and other customers') security, not yours. I think they're supposed to prevent people from reverse-engineering banking app APIs and writing bots that perform millions of requests per second, trying to brute force their way into peoples' accounts. As an extra protection, SafetyNet also makes it harder to distribute apps that repackage your genuine banking app, but with an extra trojan added.
- potamic 1y agoEvery bank of repute also has a web portal for internet banking. If it were about security, leaving this open while closing the mobile route doesn't make sense. The web is also vulnerable to scammers hosting trojan websites but somehow that doesn't seem to be a big problem. If a bank (or any entity for that matter) needs to control the client in order to make their systems secure, then it's bad security. The system must be secure despite the client.
- miki123211 1y agoThis depends on the bank and the country, but web portals usually have some kind of 2FA on them. This means hacking into somebody's web portal account isn't enough, you still need to hack that mobile device first.
- burnt-resistor 1y agoIt creates a Hobson's choice of no tinkering and less malware, or tinkering and greater risks from malware. There should be a "maintenance mode", but the onus of responsibility for breakage should be on the user for system update compatibility without the user being held hostage. This is a false choice and ostensible customizability. If the manufacturer wants to add an "OS warranty void sticker" flag because things maybe broken from tweaking, that's cool, but leaving the user less secure as punishment is wrong.
- sprinkly-dust 1y agoIt is my experience that this is what Google does with their Pixel phones. It is really quite simple to unlock the bootloader and do whatever you want on a Google Pixel you own (i.e unlocked, no carrier). They even give you this really handy Android flash tool which uses WebUSB to fully restore your device when you mess up. Heck, custom ROMs like GrapheneOS and CalyxOS are even able to sign their own images and allow you to lock the bootloader with a non Google OS. However, all this comes with the caveat that SafetyNet will flay you alive. The cat and mouse game with Magisk and other methods to maintain root undetected is moot when I've used apps these days that make a fuss when you have developer settings enabled. To be honest, that seems acceptable to me, I can do what I want with my device, software vendors like banks and the like have a say in how I choose to access their more convenient services. I can play nice with them if I want, even using a second phone perhaps, but I have a choice.
- encom 1y ago>banks and the like have a say in how I choose to access their more convenient services I disagree. I don't understand how it's fine that I can access my banking services with my Gentoo machine, with everything compiled from source by myself, but it's somehow a problem when I'm not using either Apple or Google certified OS on my phone. I'm sure they want to prevent the first scenario, like various streaming cartels already do, but I hope something like EU throws a fit if they do.
- keyringlight 1y ago