7 ms·
Do those same banks have websites that you can access from a computer with root access? Most likely, yes.
by Arbortheus 9mo ago
Do those same banks have websites that you can access from a computer with root access? Most likely, yes.
- dingaling 9mo agoEventually though I suspect that web access to banks will be rescinded too, much like HMRC in the UK no longer permits companies to submit their taxes through the websites. In the future, everything will need an 'app'.
- dangus 9mo agoThis seems like a massive jump to conclusions.
- margalabargala 9mo agoYou should make a mat for that.
- TheGamerUncle 9mo agoIt is a massive observation of how things look already no more, no less.
- dangus 9mo agoLet me clarify my statement: one government agency’s election to use an app for a single purpose isn’t an indicator of much. It’s not like the UK sent out a mandate to private banks or any other private industry on this issue. It’s also only one small country of hundreds. I’d have to question this idea that this is how things “already look.” I can think of very few businesses that I interact with that force me to use an app.
- warkdarrior 9mo agoThis type of election to use an app by a government agency sets the tone, and more importantly tends to redefine "best practices." Would you want to be the one private entity known to not be using best practices? Would your risk officers or lawyers be OK with that decision?
- dangus 9mo agoSince when does government set trends in private industry? I’d like to know what private businesses are copying the kind of workflows and customer experience you get at the USPS or DMV.
- homebrewer 9mo agoIt's already reality in my country, where you cannot access online banking for any banks except via their mobile applications, which (of course) refuse to work on anything rooted or running non-stock firmware.
- dangus 9mo agoSo, I guess it’s a country-dependent jump to conclusions? I have had a lot of banks and credit cards, mobile payment apps like Venmo/PayPal in the US and they almost all work on mobile web and desktops. But I recognize that wealthy western countries didn’t really skip the personal computer like many mobile-first regions have done.
- acedTrex 9mo agoIt's moreso everything will need a signed hardware key of some sort. The app is just the easiest expression of that.
- tengwar2 9mo agoWith HMRC, the reasoning is that this forces the company to have an accounting package. They don't care which, they just define the API. Not unreasonable. There are more issues with MTD IT (making tax digital, income tax) due to some detailed requirement decisions such as the need to report different income streams separately.
- mothballed 9mo agoWould make a lot of sense for banks just to shut off online/mobile access and switch to in person only. That seems to be the way things are moving with KYC/AML and ensuring there is a material presence of the person in the banking jurisdiction in which they operate. Knowing the password / keys and providing a video 'proof of life' is no longer sufficient to presume you're dealing with the person you think you are and not just sold 'darks'. I've heard 3rd hand of some banks already doing this in i.e. Armenia where a foreigner can come in and open account easily but they block any online access to lock the control of funds in country to make it harder for the FATF psychopaths to find fodder to clamp down on them.
- SketchySeaBeast 9mo agoDon't like that. I'm of the "if you're going to do something important, do it on your PC" generation. I do not want a future where I lose my phone and I can no longer access my bank.
- immibis 9mo agoClaim you don't have a phone, and they'll find a solution.
- kube-system 9mo agoWhat is that supposed to accomplish? The service providers that require a phone will require one whether you have one or not.
- ryandrake 9mo agoWe need to act now, while there are still service providers that don't require a phone. If my bank said they wouldn't do business with me unless I used a phone and an app, I would immediately take my business and all my accounts to a different bank. Banks have no moat. You can pretty easily move accounts to a different one or to a credit union who won't abuse you.
- kube-system 9mo agoYou and the four other people who might do this are just delaying the inevitable.
- keybored 9mo agoOr they’re arguing with like four FUD contrarians on a website. No no no shut up, don’t speak up. No one thinks like you.
- ranger_danger 9mo agoOnly if people roll over and take it. The squeaky wheel gets the grease.
- simlevesque 9mo agoFirst it'll be apps, then it'll be one app.
- ecshafer 9mo agoChina is ahead of the curve here, the one app is wechat.
- silisili 9mo agoThat seems to be the way the wind is blowing. Most new 'challengers' I've tried in the US either have no web access at all, or limited access that lets you view balance but not do things like transfers.
- marssaxman 9mo agoI long ago decided never again to use anything but a credit union, and this makes me glad that credit unions tend not to ride the forefront of tech trends.
- pessimizer 9mo agoMe too, but credit unions are being rolled up by private equity.
- Barbing 9mo agoRecalling Venmo winding down web beginning in… let’s see… 2018! https://www.digitaltrends.com/phones/venmo-shutters-web-platform https://www.digitaltrends.com/phones/venmo-shutters-web-plat...
- drnick1 9mo agoWhy do people need these crappy fintech apps at all? Can you not give your friends cash or send a wire?
- silisili 9mo agoIn the US, in my experience, young people don't want to deal with cash at all. Older people do, but it's not always convenient to meet up. Most banks charge a fee for sending a wire. Sending an ACH is free, but most restrict that to your own account. Revolut is the only one I've seen that lets you just spam ACH to anyone. In both cases, it isn't instant. Zelle largely fixes those issues, but has its own issues, like a lot of banks not supporting it and/or arbitrarily low send limits.
- 9mo ago
- edent 9mo agoYes, but a web browser doesn't run HTML + JS as root.
- wdrw 9mo agoDependence on a secure client is generally a bad idea. Security should be server-side.
- edent 9mo agoThis isn't about the bank's security - it is about the users'. Users are losing billions worldwide due to fraudulent apps. If a user has root and runs a malicious app, it can intercept what a legitimate banking app does. A scam app with root can draw over the screen and tell users to transfer money, or it can run a series of actions when the banking app is running, or do any of a hundred things to steal money.
- hackyhacky 9mo ago> A scam app with root Sure. But the people who are actually rooting their phones are advanced users and aren't going to install a malicious custom OS. Are naive users getting tricked into rooting their own phones? I'm dubious what the security benefit is of this decision.
- mike_hearn 9mo agoThese types of discussions on HN get confused because people aren't always clear what they mean by the word "rooting". There are two ways to root a phone: 1. Unlock the bootloader, install a well designed and highly secure aftermarket OS, relock the bootloader. The device is still just as secure against malware as it was before. Remote attestation shows the vendor that you're running Graphene or Lineage or whatever. 2. Exploit a local vulnerability to drop a sudo binary somewhere. RA shows you're running an exploitable version of Pixel Android, etc. (2) is absolutely exploitable by fraudsters. They convince the user to run an app or visit a website that exploits their browser or whatever, and the vulns are used to escalate to root and keep it. Now when the user logs into their banking app the HTTP requests are rewritten to command the bank to send money to the adversary. This is why devices that allow escalation to root are excluded via remote attestation. (1) isn't but it requires more coordination than the industry has proven capable of so far. Binary images of a custom OS could in theory be whitelisted by banks if it was known to be as secure as other operating systems. But there's no forum in which that information can be exchanged. Like, RandOS turns up and the maintainer "xyzkid", identity: anime avatar, claims his OS is super secure. How does random overworked bank developer John Smith know if this is true or not? RandOS doesn't come with any audits, it doesn't have a well paid security team. The brand is a big question mark. And if John makes the wrong call, maybe the bank is now on the hook for millions in losses because someone installed RandOS to get the shiny icon theme or whatever, and then got hacked. So it's a hard problem. It's not actually a technical problem. Remote attestation is very general. The hard part isn't the tech. It's a social problem. How do you create and rapidly communicate trust in a new binary OS image if you don't have the security resources of an Apple or a Google or a Samsung? Google runs a whole accreditation programme for Android where you can turn up as a phone OEM and get your custom OS builds considered to be secure by passing a huge test suite. So the only issue is OS hackers who fall below the threshold where they can do that. There's an alternative of course: go full libertarian. Means, just use a "bank" that doesn't care if its users get hacked. This is what the Bitcoin community enabled. It's there if you want it.
- Macha 9mo agoI mean, if it's like Ireland, then no. While they (mostly) have websites, a computer with root access is not sufficient by itself to access them. You also need to perform 2FA via push notification to a proprietary app on an Apple or Google approved device.
- varenc 9mo agoI assume the bank apps have functionality that their websites lack. Like being able to tap to pay for things, etc. Where a rooted phone might make fraud easier. If not, then this really makes no sense.
- eastbound 9mo agoThe only way an app can contact a company is through REST APIs.
- immibis 9mo agoTrue. All internet packets are REST API packets - there's no other type of packet. And all cell radio traffic is internet packets (which are REST API packets).
- deleted 9mo ago[deleted]
- hirako2000 9mo agoMalware is more easily spread onto rooted phone, that's for sure. From they you can keylog. Highjack input listeners, basically do anything you want.
- SkiFire13 9mo agoThat's what a malware can do on a rooted phone, _once it gets root access_, but that doesn't mean a rooted phone is easier for malware to attack. There's not even that many people using rooted phones, and many are tech savvy people that are generally a bit more careful, so even if a rooted phone gets infected by some malware chances are the malware won't even be written in such a way to try to obtain root permissions through the standard procedure and exploit it.
- Elfener 9mo agoIn Hungary, where the central bank created the same rule about not allowing banking apps on "unoffical" devices, they do, but you need either the app or SMS for 2FA. Apparently they consider SMS secure...
- harvie 9mo agoyes. and the websites require you to verify transactions with (unrooted?) phone. on the other hand phone does not require you to verify with your pc, so there's no second factor unless there is some unacessible secure island within the phone itself. funny enough, you can probably use that website directly on the phone that you use as 2F, which probably circumvents the 2F idea (at least as long as you use SMS 2F instead of app that checks for root)
- tux3 9mo agoThere's a trend of online banks forcing the use of an app. I can't login to one of my banks' website since last year without using a QR code from their app. Of course they slathered the app with tracking, 'security', and analytics SDKs, so rooted devices are rejected. I had no way to log into this bank account after they made that change, which is simply wonderful. Anyways, they're not yet at the point where they've learned to do the checks server-side. For now it's a one line patch to skip the root screen. But the Play Integrity API is designed correctly, if they learn to use it, there will be no workaround without someone finding a hardware vulnerability somewhere.
- cons0le 9mo agoYep, hardware attestation is becomming more common, even with websites. This is why LineageOS is actually dead in the water, even though they're "in talks with hardware vendors". It doesn't matter when people can't use the apps and services they need.
- hyghjiyhu 9mo agoA solution could be having a tiny non-rooted Android system as a "coprocessor".
- ExpertAdvisor01 9mo agoThis won't work. The tiny non-rooted system wouldn't get certified by Google and therefore not pass hardware attestation, which most banking apps use.
- NoGravitas 9mo agoI think they mean having a second non-rooted phone that is certified but cheap.
- hyghjiyhu 9mo agoWell you could take a certified system off-the-shelf and integrate it into a bigger thing.
- agumonkey 9mo agoMaybe a tiny difference though is that a phone is moved all day long, with a lot of people around to mess with or pick it. Your laptop is a bit larger and your desktop .. well is behind your door. But yeah ultimately a bank should not rely on phone OS to have security.
- abdullahkhalids 9mo agoTD Canada is forcing me to use their app. Every time I make an online transaction which to them is too large or fishy in some way, they make me login into the app on my phone to approve the transaction. That's the only way.
- JCattheATM 9mo agoClose the account to change banks and let them know why.
- whs 9mo agoThai banks are required by regulation to have facial recognition when transferring over 50k THB in one transaction or cumulative in a day. I believe most banks have shutdown their internet banking as it's not worth it for the low number of users to implement web-based secure facial recognition that don't allow you to feed spoofed video input. One of the bank that I use will send a push notification to their mobile app for you to confirm the transaction. I believe that previously internet banking, even before mobile banking, will limit the number of transfer recipients you can add per day/month. With the rise of QR payment I could see this limit being regularly hit if you scrape the web-based banking. Since the Bank of Thailand claims that they technically don't block many things (mobile banking technical requirements seems to also require blocking root, but they never banned internet banking), I wish there's a new bank that try to disrupt the existing players. But the latest "branchless" banking license were only acquired by existing banking groups, so API-first personal banking remain impossible.
- ranger_danger 9mo agoMany people also use their bank's app for mobile NFC payments though (more of a thing in EU than US), which you can't easily do with a device that doesn't fit in your pocket.
- kube-system 9mo agoThere has been a trend away from this over the past decade. Some banks require mobile apps for some or even all interactions. The banks that allow you to do everything on their website trend towards legacy and US-centric.
- bakugo 9mo agoIn some countries, it's already impossible to make online payments without the bank's phone app. Only a matter of time until all banking is restricted to phones.
- a456463 9mo agoJPMCB Chase only allows an APP for 2FA auth
- karel-3d 9mo agoThey usually have a mobile companion app where you need to confirm login.