5 ms·
A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs o
by madeforhnyo 8mo ago
A collegue of mine was tech lead at a large online bank. For the mobile app, the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". Security theater at its finest, checkboxes gotta be checked. The irony is that the devs were using rooted phones for QA and debugging.
- zobzu 8mo agoive seen: -"but ios can be jailbroken and it doesnt have an AV!" while the MDM does not allow jailbroken devices, and they also allowed sudo on linux. auditors are clueless parasites as far as im concerned. the whole thing is always a charade where the compliance team, who barely knows any better tries to lie to yhe auditor, and the auditor pick random items they dont understand anyway. waste of time, money and humans.
- virtue3 8mo agoat best it's "cover your ass security" so when you do get pwned you can say you went through an "accrediting auditor" - blah blah blah. Agreed on everything you said. Just wish there was a more efficient way to do things :/
- jamesfinlayson 8mo agoYep, some stakeholder wants a pen-test or an audit so you do it and address the findings to keep them happy. Going through it now at work - bunch of silly findings because the pen testers know they don't get paid to send back an empty report and tell you everything is fine.
- surcap526 8mo ago[dead]
- ACCount37 8mo agoOh how I fucking wish "security" wasn't a stupid cargo cult checkbox list 3/4 of the times. Unfortunately, the rot runs too deep.
- empyrrhicist 8mo agoYour password must be between 8 and 12 characters, and must have lowercase, uppercase, numbers, and punctuation. Pick up the can!
- barbazoo 8mo ago> Pick up the can! Gotta admit, this triggered me. I don’t think those are the same thing. If no one had a good password we wouldn’t affect each other negatively. If no one picked up trash, we would. Edit: Sorry folks, didn’t get the reference.
- smlavine 8mo agoIt's a Half-Life 2 reference: https://www.youtube.com/watch?v=nJshjMyg6no https://www.youtube.com/watch?v=nJshjMyg6no
- estebank 8mo agoI'm pretty sure it's referencing Half-Life 2, where an agent of an oppressive regime tells you to pick up a can that they just dropped on the floor as a sadistic display of authority (and to provide world-building and teach the grab mechanics to the player). The GP is equating policies for strong passwords that aren't trivially cracked with authoritarianism. If no one had a good password, we actually would affect each other negatively. If your personal banker can be easily compromised, that means that you could be easily parted with your money. I do agree that they are not the same thing.
- empyrrhicist 8mo ago> The GP is equating policies for strong passwords that aren't trivially cracked with authoritarianism. Incorrect - the requirements I mentioned make passwords less memorable and less secure (maximum length 12???). Obviously that's not as bad as authoritarianism, but I was trying to capture the arbitrary act being forced on us for no real justifiable reason.
- 8mo ago
- sunaookami 8mo agoYeah that's the first thing a pentest will complain about, had the same problem too. I pushed back enough so that it's trivial to bypass but the bank and pentesters also agreed with me that it's security theater or else I would never had the chance.
- hparadiz 8mo agoI always ask them if they have root/admin on their computer. Then follow up playing dumb with "shouldn't we lock out PCs too?". Watching them stammer is worth the 30 second aside.
- GoblinSlayer 8mo agoLocking down PCs is easy: just set a random password.
- LoganDark 8mo agoJust blow the right hardware fuses and secure boot will be forced with a key that doesn't (or can't) exist.
- JoshTriplett 8mo ago> Then follow up playing dumb with "shouldn't we lock out PCs too?". Unfortunately, some banks do, for various functionality; there are many things you can do via bank apps and not typically via their website.
- huflungdung 8mo ago[dead]
- NewJazz 8mo agoBut grapheneos doesn't need to be rooted!
- HybridStatAnim8 8mo agoUnfortunately, root detection is greatly flawed, most of the time.
- dlcarrier 8mo agoAs long as copying some numbers, printed on a piece of plastic, into an online order form is all the authentication that is needed for a transaction, anything more than that is inherently security theater.
- rahkiin 8mo agoThat’s why for most transactions I do with a credit card in my country, you need an extra validation with the mobile app. It is mostly American websites that do not enable this functionality.
- drnick1 8mo agoYes, because we don't want these stupid locked down apps. Credit cards give buyers many protections, it's very easy to dispute an illegitimate transaction.
- gwillem 8mo agoHowever, you pay 2.7% for that convenience
- drnick1 8mo agoThe consumer does not typically pay this directly. It may be passed onto the consumer indirectly through higher prices, but those apply to anyone regardless of payment method. On the contrary, I get cash back on purchases and other rewards.
- quicklime 8mo agoPretty cool that you have a system where poor people pay for your fraud protection, cash back and rewards!
- Hikikomori 8mo agoEurope mostly uses debit cards but also have most of those protections.
- mmooss 8mo ago> the first and foremost threat that security auditors would find was "The app runs on a rooted phone!!!". GrapheneOS is not rooted, or is not required to be.
- subscribed 8mo agoNo it's not, but it's bundled in the same basket. "Didn't pass DEVICE_INTEGRITY -> rooted"
- madeforhnyo 8mo agoYep that's my experience as well, if you don't get the play protect™ absolution your device is seen as rooted. Latest app to display this BS behavior was PagerDuty, I guess they have to protect their secret sauce of calling an API and showing notifications
- subscribed 8mo agoHuh, that would be absurd if PD did that. I know some people have issues with Duo, I don't, with pager duty i _just_ installed th last version from Play store, logged in with sso to my org and I'm in, can do or see everything. Maybe it's play services in your case, not play integrity? I'm on the last release from the stable channel.
- tranq_cassowary 8mo agoMoreso, the project advises against rooting your phone and tells you that if you install GrapheneOS and root it that you aren't running GrapheneOS anymore.
- bnjms 8mo agoWho do we lobby to get this removed from the auditors checklists? This is a solvable problem but it’s political. And if we don’t solve it personal computing is at risk.
- prasadjoglekar 8mo agoStart by calling (or visiting the area office of) your senator and congressman. If you are reasonably articulate, they engage and listen. Doesn't matter if the listener is not a techie; they will ask questions around policy and why it affects constituents. This is 1000x more useful than online petitions or other passive stuff. Politicians know that one person to have taken the effort to do this, means 1000 others are feeling the same thing but are quiet.
- jstanley 8mo agoThis is nothing to do with politicians.
- monksy 8mo agoFrom my experience with the fed level senator.. they're already lobbied to shit. For example, explaining to Duckworth that fed level id tying to your internet travel and encryption backdoors aren't safe.. they'll send you copy that she really wants you to know she's thinking about the children while rolling around in her wheelchair.
- protimewaster 8mo agoMeanwhile, it's probably A-OK for the app to run on a phone that hasn't received security updates for 5 years. I don't get it. If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? I'm guessing it's because there are a lot of phones floating around that aren't updated (probably far more than are rooted), and they're willing to pretend to be secure when it impacts a small number of users but not willing to pretend to be secure when it impacts many users.
- tadfisher 8mo ago> If they're worried about liability, why not check the security patch level and refuse to run on phones that aren't up to date? Google doesn't provide an API or data set to figure out what the current security patch level is for any particular device. Officially, OEMs can now be 4 months out-of-date, and user updates lag behind that. Your guess is good, but misses the point. Banks are worried about a couple things with mobile clients: credential stealing and application spoofing. As a consequence, the banks want to ensure that the thing connecting to their client API is an unmodified first-party application. The only way to accomplish this with any sort of confidence is to use hardware attestation, which requires a secure chain-of-trust from the hardware TEE/TPM, to the bootloader, to the system OS, and finally to your application. So you need a way for security people working for banks to feel confident that it's the bank's code which is operating on the user's behalf to do things like transfer money. They care less about exploits for unsupported devices, and it's inconvenient to users if they can't make payments from their five-year-old device. And this is why Web Environment Integrity and friends should never be allowed to exist, because Android is the perfect cautionary tale of what banks will do with trusted-computing features: which is, the laziest possible thing that technically works, and keeps their support phone lines open.
- protimewaster 8mo agoAll good points. Thanks for that! I'm not an Android developer, but I was thinking they could use something like the android.os.Build.VERSION.SECURITY_PATCH call to get the security patch level. Maybe that's not sufficient for that purpose, though.
- monksy 8mo agoA lot of that is security theater at its best. However given the forced attack surface I would imagine that there is a hard push from authoritarians and the finance world to make a "secure chain" from service to screen. My guess: They're afraid that the scammers are going to mirror the screen and remote control access to the app. (More orgs are moving to app/phone based assumptions because it saves the org money and pushes cost on the consumer) Instead of providing protections from account take over.. we're going to get devices we don't own and we have to to pay for, maintain and pay for services to get a terminal to your own bank account. Additionally, there are many dictatorships, like the UK, North Korea, etc, that are very adimate that you don't look at things without their permission. So they're trying to close the gap of avoiding age verification bypasses with VPNs.