3 ms·
I'd argue that banks DO need to know that you've unlocked your bootloader, but they should present you with a "Your phone bootloader is unlocked. If you don't k
by yoavm 8mo ago
I'd argue that banks DO need to know that you've unlocked your bootloader, but they should present you with a "Your phone bootloader is unlocked. If you don't know what it means or you didn't do it yourself, exit the app now and contact customer support."
The problem is that app makers are lazy.
- fc417fc802 8mo agoSo if I call in on the phone do they need a video feed of my surroundings to verify that I'm not being extorted? Perhaps if I come into a branch in person to make a large withdrawal they need a drug test to ensure that I'm not intoxicated? They absolutely do not have any need to know anything about my bootloader or OS version or safety net or otherwise. It's certainly true that it is within the realm of physical possibility for them to put that information to good use in a responsible manner if they had access to it. But being able to make use of something is not the same as a legitimate need.
- lotsofpulp 8mo agoI can see a future where a video from a hardware/software stack verified by Apple/Google is a required mechanism for authentication. For example, you have to say or otherwise signal that you authorize the transaction to x person for y amount on z date. I kind of do it with my tenants when I record a video walk through at the beginning and end of the lease to serve as proof of damages. I could use a checklist on paper and a signature, but I feel like a video is better evidence for me.
- yoavm 8mo agoThey don't check if you're not intoxicated, but yes it would be very sensible that when you walk into the bank and make a transaction the bank person would look at you, and if there's a strange person standing behind your back with sunglasses and a hat, they'd tell you "hey, this guy has been following you into the bank and is listening to everything you say, are you aware and are okay with that?"
- fc417fc802 8mo agoAgreed. However an unlocked bootloader or non-stock OS or not passing safety net or whatever aren't equivalent to that so I'm not sure what your point is. "We've imagined a hypothetical" is completely different from "we directly observed something that looks criminal". Like if they see that the OS version string is "known-malicious-image" fine but that's totally different. A good example might be the memo lines on checks. You can never be certain that a string of random numbers doesn't have something to do with criminal activity but the bank won't bother you about it. Whereas when an acquaintance tried to cash a check where someone had jokingly written "thanks for the sex" on the memo line the bank apologized for having to reject it despite realizing that it was almost certainly in jest.
- dheera 8mo agoEhhh most peoples' bank accounts don't get compromised by someone getting a hold of their phone long enough to hack their bootloader. Not to mention Android deletes all your apps and cache if you go from locked to unlocked, and you have to reinstall all of them again.