6 ms·
I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"
by rattyJ2 1y ago
I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"
- preisschild 1y agoWrite them. My bank's app had safetynet, but they disabled it and now it is usable over GrapheneOS. Unfortunately no NFC Payments though, since they are only available for Google Wallet (which uses safetynet)
- aspenmayer 1y ago> Unfortunately no NFC Payments though, since they are only available for Google Wallet (which uses safetynet) A workaround for NFC payments I've heard about for folks running OSes on their Androids that don't support that feature is a smartwatch with NFC.
- subscribed 1y agoPrecisely. Google pixel, Garmin watches, even Samsung watches. Or using a bank that supports NFC payments (not using Google Wallet). GrapheneOS Foundation raised this practice with European Commission because it unfairly penalises secure and safe competition giving instead a lie to the developers and banks that ancient, unsafe, vulnerable platforms are more secure.
- notpushkin 1y agoFidesmo Pay is another option, though the bank support is limited: https://fidesmo.com/consumer/fidesmo-pay/ https://fidesmo.com/consumer/fidesmo-pay/ Basically it’s a passive variant of smartwatch payments: you can pay with a ring, or bracelet, or a mechanical watch. The cheapest option is this plastic thingy (currently out of stock): https://eu.k-pay.com/product/mavericks https://eu.k-pay.com/product/mavericks I’m thinking about implanting one into my hand :^)
- aspenmayer 1y ago> I’m thinking about implanting one into my hand :^) On the one hand, I approve of self-administered biohacking. On the other hand, you might need a Faraday glove to prevent tap to pay shenanigans by folks with a mobile card reader who bump check you. I would not do this type of biohacking myself, but if you go down this path, look into how NFC skimmers work, because that and compromised card readers and unauthorized tap to pay events on portable card readers is a threat vector. I have heard that Google and Apple are working to roll out tap to pay from card to phone and phone to phone, which could allow folks to skim your NFC device to run an unauthorized transaction.
- notpushkin 1y agoIt is possible, but very unlikely. You’ll need to know where my chip is (I guess for an average thief an implant is not the first idea of where to look for an NFC card), and then get quite close to me to pull this off. Even if you do, I think it’ll take about one chargeback to get your merchant account blocked. > roll out tap to pay from card to phone and phone to phone It’s already here! Stripe has supported it for a while now, and I’ve seen a bunch of other payment providers have it, too: https://stripe.com/terminal/tap-to-pay https://stripe.com/terminal/tap-to-pay
- aspenmayer 1y ago> It is possible, but very unlikely. Life, uh, finds a way, after all. > Even if you do, I think it’ll take about one chargeback to get your merchant account blocked. Well, someone's merchant account might be blocked, but carders don't necessarily use their own accounts; in fact, I would doubt that many do, but criminals are often underestimating risks and overestimating rewards. It's almost a truism at this point that folks who do crime are not usually acting rationally, but I don't want to stereotype. > It’s already here! Stripe has supported it for a while now, and I’ve seen a bunch of other payment providers have it, too: https://stripe.com/terminal/tap-to-pay https://stripe.com/terminal/tap-to-pay Finally! This feature is going to help a lot of small businesses in isolated areas where mobile phones are the primary (or only) computing devices that are commonly owned. This can create virtuous cycles that are somewhat unpredictable, which should help make these markets more dynamic and competitive. Thanks for posting that Stripe link. Here's some more tap to pay links I was able to find, eventually. The search terms match too much, so it is a bit hard to disambiguate legacy NFC payment flows that use traditional or modern terminals from the new device to device payment flows. I remember hearing about Stripe's work on this feature, but since I didn't hear much after that, so I wasn't sure if the feature had ever shipped. I'm glad that this tech is getting in the hands of end users. Apple-specific roundup of apps and vendors that support the feature: https://apps.apple.com/story/id1620226212 https://apps.apple.com/story/id1620226212 https://www.apple.com/business/tap-to-pay-on-iphone/ https://www.apple.com/business/tap-to-pay-on-iphone/ These two are available on both iOS and Android, in case that is important for folks: https://squareup.com/us/en/payments/tap-to-pay-android https://squareup.com/us/en/payments/tap-to-pay-android https://www.paypal.com/us/business/pos-system/tap-to-pay https://www.paypal.com/us/business/pos-system/tap-to-pay
- SanjayMehta 1y agoMy bank used to block VPNs “for security reasons.” Now they very kindly just display a warning.
- maximilianthe1 1y agoGas station app I use asks to turn VPN off every launch (even when it is disabled)
- mschild 1y agoWhy does a gas station need an app?
- maximilianthe1 1y agoBonus/loyalty programm
- spaqin 1y agoMore likely getting data on your usage in some part, or most likely, pushing notifications reminding you about the particular brand, so you'll keep spending the money there.
- loloquwowndueo 1y agoThen the app gets no notification permissions. Also why does a gas station app need to send notifications? :)
- userbinator 1y agoTo tell you the gas prices are low? (Don't know for sure, wouldn't use one myself.)
- positr0n 1y ago
- t_mahmood 1y agoMy bank blocks my mobile with Lineage OS, and it's not even possible to login to the web site without the mobile app. Absolutely pathetic. Now I have to keep my 4 year old phone with 2 year outdated Android to access the bank application. Which deemed more safe then my mobile with latest security updates. Haha
- Andrex 1y agoIf you're going so far as to install Lineage, couldn't you take the small step further and download alternate browsers to change the user agent? (Unless the default Lineage browser can do this already.) I run a Google'd OS for now but I haven't used my bank's terrible app in years and years. I use their terrible website via desktop mode instead.
- t_mahmood 1y agoWell, to add insult to the injury, this bank does not allow website login without the mobile app. Which is absolutely infuriating. I did mention that on my comment :-)
- exe34 1y agolast time I walked into the bank to do something, they tried to peddle their app. I giggled and said no, their developers don't understand security. my phone is rooted and their app won't work.
- t_mahmood 1y agoUnfortunately, I can say with 100% confident, the customer service of my bank will not freaking understand what is a rooted phone, or LineageOS ... And my bank's web app developer couldn't even fix their log in bug for several months. I realize, now, it's because they want to sunset their web portal. Which is extremely annoying ... what if I don't have my mobile!! Lazy, and greedy corporates, just trying to save their costing with shortcuts, never realizing security is never achieved by taking shortcuts.
- lrvick 1y agoI have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.
- adrian_b 1y agoIn Europe there are, e.g. at least some subsidiaries of Societe Generale, which have closed their Web sites on which their online banking services were previously available, and which refuse to provide their mobile apps otherwise than through the Google Store. I doubt very much that it is possible for this practice to be legal, i.e. to condition the services of an European bank of the existence of a contractual relationship with a third party, which is non-European. Nevertheless, nobody has enough spare time and money to challenge legally such banks. Now I do my operations mostly through other banks that still have browser-based online banking, but I have not closed yet my last account at such a Societe Generale subsidiary, because I have regressed to use an antique SMS-based substitute for online banking, which is good enough for that account, which I keep only for a credit card used mostly for shopping in supermarkets or the like.
- teekert 1y agoBunq comes to mind, I'm guess N26 and Revolut are similar, app first "fin-tech" banks.
- 654wak654 1y ago> I have never heard of a bank that has a hard requirement of a mobile app My bank's app recently started warning me that I should "Turn off developer mode" for """security""" on every sign-in. This warning doesn't stop me from using the app yet, but I'm sure it'll get there.
- dijit 1y agoIn Sweden we use BankID (there is a similar service with the same name in each Scandinavian country). It's impossibly convenient to be perfectly fair with you, however I know that my bank has stopped issuing the "BankID Card" (which was a card and pin device that allowed you to generate challenge numbers)- and now forces you to use the BankID app -- which will not run on rooted phones of course. It's even slightly worse as the App requires NFC; so I can't keep a backup on my iPad (which is what I was doing before).