12 ms·
HSBC blocks its app due to F-Droid-installed Bitwarden
- itsthecourier 10mo agoprobably because bitwarden has a permission to overlay other apps and HSBC thinks it's malware stealing your access to your bank
- arccy 10mo agoI think from HSBC's risk management perspective, it's fairly reasonable
- makeitdouble 10mo agoA bank refusing you access because of your accessibility settings (app overlay is one) is not reasonable.
- arccy 10mo agorisk management is all about what the bank is willing to trust. in this case it decided it was risky because have any information on the provenance of your overlay, but you could source an overlay from somewhere they trust, like the default app store.
- makeitdouble 9mo agoThe bank wouldn't (hopefully ※) do that if it was illegal or technically too complex. Letting the bank decide is fundamentally problematic IMHO. ※ I'm aware expecting HSBC to follow the law would be extremely naive given their track record.
- rwmj 10mo agoThe problem (for the bank) is they are now liable in the UK[1] if you are defrauded because someone installs malware on the phone. There's basically zero upside for the bank to allow customers to use F-Droid, since probably 0.0001% of their customers would do this, compared to a vastly greater number of customers being tricked into installing random malware on their phones. Accessibility settings are a tricky one since that's a separate law. I wonder if they whitelist screen reader apps from the official app store. Anyway that's not the case in the original article. [1] https://www.bbc.co.uk/news/articles/cy94vz4zd7zo https://www.bbc.co.uk/news/articles/cy94vz4zd7zo
- makeitdouble 9mo agoFrom the bbc article, the number of fraud rose 12%, and you're presuming 0.0001% would be using F-Droid. Is preventing that an efficient ("reasonable") action from the bank ?
- rwmj 9mo agoFraud is 41% of all crime in the UK, affecting 3.2 million people. Number of people using F-Droid + a banking app is approximately zero in comparison. There is not the slightest chance in hell that taking on the legal risk from F-Droid users is a sensible use of the bank's resources. Sources: https://www.nationalcrimeagency.gov.uk/what-we-do/crime-threats/fraud-and-economic-crime https://www.nationalcrimeagency.gov.uk/what-we-do/crime-thre... https://www.nationalcrimeagency.gov.uk/threats-2025/nsa-fraud-2025 https://www.nationalcrimeagency.gov.uk/threats-2025/nsa-frau...
- deleted 10mo ago[deleted]
- zb3 10mo agoBut the user needs to be able to override this faulty check, albeit my solution is to never let any app decide what I can have on my device by not installing the app. EDIT: there's also Android Protected Confirmation that works in the TrustZone so apps can't display over that. It was made exactly for apps like banking apps, so they should use it.
- jeroenhd 10mo agoThis is "protect the users from themselves" as-a-feature to prevent scammers from using malware to obscure their scams. Letting the user override the warning would make the entire feature useless. Using overlay permissions, it's relatively simple to trick someone into transferring money by overlaying a different UI that the malicious app makes the user type or paste into. I believe blocking access to the app while such an overlay is present makes a lot of sense. Trusting apps from Google Play to do this while blocking other install sources would be an obvious mistake, though. I'd argue this feature shouldn't exist (because of things like the API you mention) but having a user override doesn't make sense here.
- graemep 10mo agoThe HSBC app will not work with apps with overlay permission OR with apps installed from outside the Play Store. I have stopped using the HSBC app and asked for a security device (which they will send you if asked) instead and use the web site instead.
- devsda 10mo agoIf Google can allow apps to block screenshot capability then it should also allow specific set of apps like financial apps having an option to block overlays too. It doesn't have to be all or nothing.
- zb3 10mo agoWe can't let banking apps invade our property.. things like banking apps need so much control in order to be secure that they need to exist on dedicated devices.
- notpushkin 10mo ago> things like banking apps need so much control in order to be secure They don’t. It’s a security theatre.
- internet101010 10mo ago"At <insert bank>, my voice is my password."
- anthk 10mo agoIn Spain (I think the whole Hispano-America by proxy) the BBVA's banking app just allow a 6 char long password. This is bullshit. Also, if you try to root the smartphone the app might disable itself. I'm tired of this. Can't wait to a good cyber attack from Russia+China so the whole security theater crumbles down (and in China too because of the social credit) until the civil rights get restored back.
- progbits 10mo agoBank security has and never had anything to do with real security. It's all stupid audit checkboxes and missing forest for the trees. I've dealt with PCI and similar auditors and I wouldn't trust them with my gym locker combination. My only solution is to have multiple accounts, spread the risk, and rely on legal protections and bailouts when they inevitably screw up.
- jeroenhd 10mo agoThat's not really necessary, though I understand why banks are doing this when they're held responsible for their customers' inability to spot fraud before hitting the "transfer my life savings into a Bitcoin wallet" button. Having a dedicated "banking device" is a good solution for power users, though I'd probably just switch banks if my bank tries to pull that bullshit on me.
- yellow_lead 10mo agoI thought Google removed the API that let you see other apps on the device. Maybe there's another API I'm not aware of though
- grahamedgecombe 10mo agoYou can still request permission to use it for apps distributed via Google Play for a limited set of use cases: https://support.google.com/googleplay/android-developer/answer/10158779?hl=en-GB https://support.google.com/googleplay/android-developer/answ... which is then subject to Google reviewing and approving it. I assume HSBC are using the "antivirus" use case.
- hn8726 10mo ago> I assume HSBC are using the "antivirus" use case. There's an exception for banking apps > Apps that have a verifiable core purpose facilitating financial-transactions involving financially regulated instruments (for example, dedicated banking, dedicated digital wallets) may obtain broad visibility into installed apps solely for security-based purposes.
- phantom784 10mo agoInteresting, that also permits: > Real-money gambling apps where the core purpose of the app is real money gambling and where the app requires broad package visibility in order to comply with technical standards mandated by applicable geofencing regulations. I presume that's to allow the gambling apps to make sure you don't have a location spoofing app installed?
- andrepd 10mo ago13 year olds can get groomed and addicted to gambling, be they at home, school, or a bus stop. But God forbid you install an app outside the approved™ app store®, citizen. What a world.
- hn8726 10mo agoIt's still possible, you just need to declare which other apps you query for. Even then, there are loopholes that still let you query for all apps installed on the device. But HSBC app declares "<uses-permission android:name="android.permission.QUERY_ALL_PACKAGES"/>" permission, which requires an explicit approval (https://support.google.com/googleplay/android-developer/answer/10158779 https://support.google.com/googleplay/android-developer/answ...) but > Apps that have a verifiable core purpose facilitating financial-transactions involving financially regulated instruments (for example, dedicated banking, dedicated digital wallets) may obtain broad visibility into installed apps solely for security-based purposes.
- hasperdi 10mo agoIt will not work either if you have developer mode enabled. These things HSBC app does, I think it's overreaching
- ValentineC 10mo ago> It will not work either if you have developer mode enabled. Many other banking apps in Singapore have this ridiculous restriction too, including Citibank. The third-party "security framework" most of them use to pass audits is ridiculous.
- mavamaarten 10mo agoMy country launched an identification app (https://mygov.be/ https://mygov.be/) that does the same thing. I have no idea what they're trying to achieve. Security through obscurity? Trying to piss off power users? I'm a developer and use adb and some dev settings daily. Annoying af to have to disable developer mode constantly.
- the_biot 10mo agoIt's fundamentally client-side security: the phone tells the server "no, I haven't been rooted" and the server believes it. Any security system that relies on any form of client-side security is going to have other problems as well, since its designers haven't grasped this basic principle.
- fc417fc802 9mo agoThat used to be a core principle but might not be guaranteed anymore. Depending on the implementation it can be near impossible to bypass modern hardware backed security. As it should be! The policy issue at this point is that users effectively aren't in control of their devices anymore.
- array_key_first 9mo agoI had to turn on developer mode just to reduce blur in Android 16. It's incredible that's locked behind a developer mode setting.
- sschueller 10mo agoThat's Google's SafeNet. HSBC picked a level that causes this. Google manages the blacklist of apps. We are rapidly losing our freedoms to the will of these companies. If they decide they don't want to they can even if the law doesn't forbid it. People in Switzerland and the EU are being de-banked by local banks because of US pressure allowing them to force any bank that wants to use USD. The US has started to sanction people for free speech resulting in de-banking. Swiss law requires one bank (Postfinance) to offer banking irregardless but if you are sanctioned you can't use the wire system, no other currencies, no credit cards and you cant use Twint either so it's in effect useless. You can't pay for your health insurance or rent.
- hkt 10mo agoAn Italian citizen who was debanked essentially because Trump didn't like her: https://english.elpais.com/international/2025-12-28/the-complicated-life-of-francesca-albanese-a-rising-figure-in-italy-but-barred-from-every-bank-by-trumps-sanctions.html https://english.elpais.com/international/2025-12-28/the-comp... When it comes to this kind of thing, an injury to one is an injury to all and we need to not tolerate it. At minimum, we need regulations guaranteeing that Visa and MasterCard, as well as participating banks, aren't allowed to debank anyone without judicial oversight. Make the same true of apps: call it a Banking Access Tribunal.
- neoromantique 10mo ago[flagged]
- sschueller 10mo agoFirst of all you need to provide some proof because being against a genocide is not antisemitic. Hating Israel is not antisemitic even if Bibi wants you to believe that. Second of all, what happened to free speech? In fact I can list several actual antisemites currently operating freely in the US political discourse who are gathering larger and larger audiences. Why aren't they being sanctioned?
- 10mo ago
- throwaway81523 10mo agoI use a separate phone for non-F-droid apps.
- hkt 10mo agoDitch apps on your phone and pick banking that gives good, robust online banking. I was cut off by Starling for something similar and had to choose between a factory reset of my phone and my bank. I explained that my phone had free software on it, some of which I'd written, and it made no difference. Apps are a tool of control and surveillance and it is time we stopped tying ourselves to them. Dumb phones or degoogled operating systems (like e/OS/) are probably the answer here.
- phantom784 10mo agoWould they not just let you keep the account but not use their app in that case?
- ajb 10mo agoStarling is an app-only bank.
- baloki 10mo agoSome banks only provide access via apps (at least in the UK) so loosing access to the app also means you loose access to the bank account.
- phantom784 10mo agoAh. I've never come across this in the US - every bank I've seen also has a website. The only thing the apps do that the website won't is mobile check deposit typically.
- hkt 9mo agoThey did indeed. I had to call customer services to get the account closed. The app being the only way to interact with the account, I was left without funds for days.
- callahad 10mo agoCan you say more about what specific things you tripped over with Starling, and which bank you moved to? Worried I'll find myself in the same boat. It does seem like Starling has gone out of their way twice to exempt GrapheneOS from their checks, but only after users complained: https://github.com/PrivSec-dev/banking-apps-compat-report/issues/39 https://github.com/PrivSec-dev/banking-apps-compat-report/is...
- noobermin 10mo agoMy wife has tried to use a flip phone just for nostalgia's sake and she has a newer phone that supports android 14 (technically android go 14) and thus should work with most basic apps. However, one of her banking apps refuses to work claiming an app is screensharing (the POSB bank app thankfully identifies it as the "android system" app.) likely what is occuring I think is the second screen is drawn using some sort of thing that is reported as screen sharing, that POSB thinks could be malware. Of course, asking POSB for help has lead to nothing being done. By and large the biggest threat to people finance wise in singapore isn't malware but are scams (what is called "pig butchering" in America is rampant here) whilst malware is always a threat sometimes I feel like just refusing to function is problem due to overzealous viligiance to a low probability threat.
- lol768 10mo agoPlenty of UK banks that don't require this, and whose apps will also work on a rooted device. Monzo will display a warning that sets out the fact there's an increased risk, and then lets you be an adult and choose to continue to use the app if that's what you want to do. The best part is that the Current Account Switching Service makes it very easy to make the jump from a legacy bank like HSBC.
- aiiotnoodle 10mo agoThis was not my lived experience. I wanted to use the most common banks and most would not let me use it. Chip contacted me at one point via their live assistant randomly without my doing and told me to stop using the app because they would soon be enforcing that rooted devices would no longer work. I continued to use the app rooted and nothing came of it. Barclaycard, Nationwide and others don't let you use the app or require some circumvention of their detection to allow access. Sure there are plenty of other apps, but those apps and banks have a worse product I found.
- worble 10mo agoThey've all started cracking down, in the past year the Barclays and Lloyds app have broken on my phone. TSB still works for now, but even for a bank they're technologically incompetent so I'm going to just assume they're behind the curve rather than willingly not using SafetyNet. The only one I would bank on still working in the future is Monzo, since, like you say, they detect it and just give you scary warning and let you continue.
- lol768 9mo agoBarclays have always played silly games with this stuff, they used to fund a whole team whose job it was to waste time on security theatre (this was nearly ten years ago).
- charcircuit 10mo agoIt's worth trying to work around this by creating a work profile to isolate the apps.
- firen777 10mo agoTangentially related, but some banking apps also implement their own in-app keyboard in their password fields, making password manager unusable and basically forcing me to use a easy to remember (to guess) password.
- sdoering 10mo agoOn the same tangent. My former bank forced me to use a 6 - 8 digit password with only numbers allowed. Not sure if in the few years since I am not a customer anymore, they changed this policy, though.
- ivanjermakov 10mo agoJust begging for someones date of birth, lol.
- tuetuopay 10mo agoYup, mine does this, even on the web. Oh god French banks do love their scrambled-digit-keyboards. And boy do they love 6 to 8 digits passwords. That you have to click on using your mouse. No password manager required! Their app also likes to prompt me periodically for the password instead of the phone's biometrics, which would be good, except it always happens in a public place like the subway, which is the last place I'd want to enter a 6 digit code to my bank account on a scrambled visual keyboard which slows down typing to a point it's trivial to write down (instead of letting muscle memory do its job). Also, it seems like those apps did not get the ATM memo of giving visual/audio feedback on a random delay to user input, to y'know, not letting glancers know what you actually type. AFAIK this trend of visual scrambled keyboard on the desktop started when keyloggers were rampant. They quickly adapted to screenshot the 20px around the mouse on click when on a bank website. The banks never adapted.
- Avamander 9mo agoThat's incredibly primitive. It's about time some countries implemented proper digital IDs that would deprecate garbage approaches like these.
- SXX 10mo agoHSBC is also one of few apps that dont let you use it with iPhone Mirroring.
- Adesany 10mo ago[flagged]
- Adesany 10mo ago[flagged]
- nubinetwork 10mo agoMost banks do this, they won't let the app run if you have developer mode turned on as well, even if you're not using it for root (or anything else in the developer menu)
- greatgib 10mo agoHSBC is on my list of the worst bank anyway. Just connecting to their online banking portal you feel like throwing up!
- petre 10mo agoIsn't that the same bank accused of Mexican and Columbian drug cartel money laundering?
- nurumaik 10mo agoAt least now it should be pretty easy for any tech person to patch apk removing this check
- Zak 10mo agoProbably not, because whatever Google is calling its remote attestation scheme this week (SafetyNet? Play Integrity?) has a way to check where the app was sourced and whether it has been altered. Google is an asshole for making this. When Microsoft first proposed a scheme like that for PCs under the name Palladium, everyone knew it was a corporate power grab. Somehow, it got normalized.
- grishka 10mo agoIsn't it funny how most banking apps do all this borderline malware crap, yet most banks also have online banking that you use through a web browser that they have no technical means of "trusting"?
- jabwd 10mo agoKeep in mind this is also often caused by arbitrary "security" consultants that crap out a list of stuff you need to implement. Like jailbreak detection and the like. One I repeatedly got back in the day was hilarious: "After uninstalling the app credentials stay present in the keychain". Yes thanks genius, I don't get to run code on uninstall.
- lousken 10mo agoNever use a banking app on a phone especially since internet banking websites exist.
- danw1979 10mo agoHSBC still operate a perfectly functional website for banking. The more people who continue to use this, the better. It sends a clear signal that customers prefer the open web over restrictive and inconvenient mobile apps. I’m also hanging on to my bank’s physical RSA fob as my 2FA, instead of using their app based version.
- aliher1911 10mo agoAt least in UK, you'll need a physical token to do that. And you can't have both app and token. So if you had an app that is now not working, it'll take some time to get a token and restore your bank access.
- Arch-TK 10mo agoThere is actually mobile banking for these cases. Which at least for HSBC requires your account details, a (Up to? I don't know the minimum) 10 digit (numeric) pin and you have to say "My Voice is My Password" which sounds like complete theatre.
- danw1979 9mo agoI have both the app (“digital key”) and a physical RSA token with my bank in the UK.
- aliher1911 9mo agoHow did you manage to do that? Whenever I tried to activate the app it was asking me to create a digital key and warning me that I'm going to lose ability to use physical token.
- happymellon 10mo agoI switched away due to HSBCs final straw for me being blocked due to not using the phone built in keyboard. Apparently using an open source keyboard runs the risk of my keypresses being shared with a 3rd party. Unlike Googles keyboard?
- scientism 9mo agoSame reason here. It didn't like Florisboard.
- merek 10mo agoI recently came across Open Web Advocacy (OWA) who summarize my mobile-platform concerns well. They "advocate for the future of the open web by providing regulators, legislators and policy makers the intricate technical details that they need to understand the major anti-competitive issues in our industry and how to solve them." Their top 3 priorities: 1. Apple's ban of third party browsers on iOS is deeply anti-competitive 2. Web Apps need to become just Apps. Apps built with the free and open web need equal treatment and integration. Closed and heavily taxed proprietary ecosystems should not receive any preference. 3. All artificial barriers placed by gatekeepers must be removed. Web Apps if allowed can offer equivalent functionality with greater privacy and security for demanding use-cases. Website: https://open-web-advocacy.org/en/ https://open-web-advocacy.org/en/
- thevania 10mo agocan't wait for digital euro https://www.consilium.europa.eu/en/press/press-releases/2025/12/19/single-currency-council-agrees-position-on-the-digital-euro-and-on-strengthening-the-role-of-cash/ https://www.consilium.europa.eu/en/press/press-releases/2025... https://www.ecb.europa.eu/press/key/date/2025/html/ecb.sp251219~fd2fee081a.en.html https://www.ecb.europa.eu/press/key/date/2025/html/ecb.sp251... i hope it will be part of the digital wallet initiative: https://github.com/eu-digital-identity-wallet https://github.com/eu-digital-identity-wallet there is an active discussion there on NOT integrating play integrity API or any other US-dependent remote attestation: https://github.com/eu-digital-identity-wallet/av-doc-technical-specification/issues/18 https://github.com/eu-digital-identity-wallet/av-doc-technic...
- petre 10mo agoWhatever. They're just going to tie it to age verification, so it's only more control, only of the EU flavour. Might be an alternative for some people though. I've worked with digital and smart tachographs and seen their security implementation. Its not pretty, mirrors EU bureaucracy. If Franz Kafka wrote specs, those would be it.
- kevin061 10mo ago404 error
- haunter 10mo agoSource post deleted
- aendruk 9mo agoIt originally contained a screenshot of a full-screen notice displaying: We've introduced additional checks to protect your account. The following apps have been downloaded from unofficial app stores. Your access to the HSBC UK Mobile Banking app has been suspended on this device until you've taken action to restore it. Identified apps: - Bitwarden How do I restore access? - Uninstall the identified apps from your device and download again from the default device app store, eg Google Play or Galaxy Store. For further assistance, please visit https://www.hsbc.co.uk/contact/
- merek 10mo agoIf you've ever built a website for mobile but never heard of PWAs (Progressive Web Apps), I recommend checking them out. In essence, adding 2 files can make the site installable from a mobile browser and define caching behavior for offline functionality. 1. manifest.json: a JSON file that defines the app's name, icons, theme colors, and how it should launch when installed. 2. Service worker: a JS file that controls things like resource caching for offline usage Unfortunately PWAs don't receive first class support compared to native apps. Still, I still hope to see wider adoption. I think for many not-too-complex apps, they can significantly lower the cost of development, and the development experience could be as simple as - Building with HTML + JS + CSS. No clunky SDKs, reduced need to test on painfully slow emulators or expensive physical devices - Installable from a browser. No need to maintain a listing in the Playstore/App Store, avoiding policy headaches, rent, etc. https://developer.mozilla.org/en-US/docs/Web/Progressive_web_apps/Tutorials/CycleTracker https://developer.mozilla.org/en-US/docs/Web/Progressive_web...
- bdcravens 10mo agoPWAs have been around for several years, and have never caught on despite all the discussion about the evils of app stores, drama with side loading, etc. They're a fine solution, but not a good fit if you're expecting "normal" users to use the app.
- consumer451 9mo agoAlso, iOS really appears to go out of their way to make them work worse. For example, not loading new versions predictably, and the address bar not minimizing like it does on normal websites. I am sure there are many more.
- TheCleric 9mo agoConsidering Mozilla’s flagship browser (Firefox desktop) doesn’t even support the feature, I don’t exactly take that as a good sign.
- wopian 9mo ago
- csmpltn 10mo agoGetting a (cheap) dedicated device for banking purposes (perhaps without a sim card, wifi only) is a good way to «work around» this.
- tommica 10mo agoProblem is that you need to buy a new one of them once they do not get updated anymore, and the apps start requiring newer versions of android. But yes, this seems like the best possible option - also it enables the extra security through clean separation, as long as the phone is dedicated for that use case only.
- oliwarner 10mo agoBanks in the UK take partial liability for their customers succumbing to scams, and refund lost funds unless customers go out of their way to ignore warnings. Loss of control of devices is undeniably part of the scam lifecycle. Faking and intercepting messages from banks is a large part of that. An antivirus needs global permissions. All of that being true, you don't have to be a contortionist to understand why they might want to lock down client devices as far as they can. Google happens to offer them an easy method.
- Avamander 9mo agoWhy should a bank be ever able to dictate what the user does with their device legitimately? They can't do so on the web through browsers, that is fine, why are we excusing this on phones? Next up banks will start requiring out MDM enrollment? Is that equally understandable? Where do you draw the line? It's unnecessary and intrusive to apply these methods unconditionally and on everyone.
- oliwarner 9mo ago> Why should a bank be ever able to dictate what the user does.. I'll deliberately answer early: because they're on the hook for your mistakes. Your bank dictates security terms. This isn't new. They can demand you appear in person with multiple forms of identification. They can (and have) demand you use 2f hardware they provide. They can withdraw service if they think you're a risk to their business. If I suddenly found myself with billions in potential liabilities, I'd do absolutely everything to ban footguns. Apps with system access installed from insecure sources. Yeah, no thanks.
- luisschwab 9mo agoGrapheneOS fixes this
- JeremyNT 9mo agoI'm getting a 404 on the original post, but on GrapheneOS you'll fail SafetyNet attestation, so you've got a totally different (worse?) problem if your goal is compatibility with abusive proprietary apps.
- GeoAtreides 9mo agoTwo phones: personal and gov id/banking/2fa phone second phone never leaves home
- NGRhodes 9mo agoBitwarden is installed via F-Droid from the official Bitwarden repository and is a build provided directly from Bitwarden. F-Droid does not provide a build of Bitwarden.