4 ms·
What are you talking about?
by avalys 1y ago
What are you talking about?
- Dylan16807 1y agoRemote attestation on Android is one of the primary examples. Banking apps and a bunch of other apps that will cut you off if you do something like root your phone.
- matheusmoreira 1y agoSmartphones have cryptographic hardware that can provide proof that a device has not been "tampered with". This is called attestation. The hardware attests to the fact trust has been preserved since boot. Your device will not attest to this if you install your own operating system, if you root your phone, if you do anything that they don't like, anything at all. You install your bank's app and try to use it. The bank's servers ask for the attestation. You will not have one. They decide you cannot be trusted and deny you service. Even if you can program your own keys into your device, nobody is gonna trust those keys. Why would your bank trust your own keys? They'll trust Google's keys, Apple's keys, the government's keys. You? You don't get to participate. The corporations and governments want to own your computer. They demand cryptographic proof that your device is owned by them and that they have complete control. If you don't provide it, you're banned and ostracized from everything.
- leidenfrost 1y agoThe most absurd part is that you totally can access the home banking from your desktop PC with Linux, without any need of hardware attestation. Suddenly it's mandatory because the device is a phone?
- Hackbraten 1y agoPeople in Europe no longer can, thanks to PSD2.
- kuschku 1y agoOf course we can, even HBCI still works, and you can even access your (German) bank account from within KMyMoney. For the website, it's also easy, even with PSD2 you can just get a physical TAN generator.
- Hackbraten 1y agoI use GnuCash/aqbanking on Linux with a physical TAN generator myself to access my German bank account. The fact that this works is not up for debate. My point was that you can't do it *without hardware attestation*. You can choose between 1. a smartphone with hardware attestation, or 2. a physical TAN generator with hardware attestation.
- matheusmoreira 1y agoIn my country, banks force us to install "security modules" in order to do this. Once upon a time, back when I used Windows, I got bored and tried to pry one of these things open to see why they made the computer so unusably slow. I caught it intercepting every single network connection and doing god knows what with them. That told me all I needed to know. It used to be that Linux users like me were exempt but at some point they added Linux support. Now there's a goddamn AUR package for this thing. https://aur.archlinux.org/packages/warsaw https://aur.archlinux.org/packages/warsaw https://aur.archlinux.org/packages/warsaw-bin https://aur.archlinux.org/packages/warsaw-bin > Banking security tool developed by GAS Tecnologia Yeah. Banking security tool. Who the fuck even knows what it does? It sure as hell isn't me. That thing is not going anywhere near my system.
- RachelF 1y agoI really don't understand why they do this - what is so special about banking apps vs a banking site in a web browser. What is the particular threat model of a rooted phone?
- daemin 1y agoThese days banking is one of the things for which a phone is required for. It is used as the primary banking device for most people, and for the rest it is required for two factor authentication when logging in on a PC or to verify online transactions. Maybe some bank would allow you to use some third party two factor authentication device to log in sometimes, but most (if not all) would require you to use their "app".