Hacker News new | past | comments | ask | show | jobs | submit login

All in the name of reliability and security supposedly. For example not being able to use banking apps on a rooted phone… yet I can use them on my perfectly secure regular computer where I have full root/admin access.



> can use them on my perfectly secure regular computer where I have full root/admin access.

yooooooo shhhhhh

Don't give them any ideas :(

Also it's not like insane security ideas around banking access compliance are unprecedented, see e.g. South Korea's insane Internet Explorer deal (transitively caused by US's ITAR on encryption)

https://en.m.wikipedia.org/wiki/Web_compatibility_issues_in_...


Brazil once had a similar problem. Banks used to force users to install these obnoxious "security plugins" into their browsers. One day I got fed up with the inexplicable slowdown they were causing and decided to see what they were doing. Turned out they were intercepting every network connection.

There is no limit whatsoever to what a bank feels is justified in doing when it comes to preventing fraud, money laundering or whatever else that impacts their bottom line. They literally believe they are entitled to any and all access.


Can you confirm transactions there, though?

Many banks in the EU require a smartphone for that at this point (or a dedicated authentication device).

But instead of using actually secure technologies like Android’s protected confirmation (which couldn’t care less about running on a rooted phone, as it runs in a trusted HW enclave), they usually just settle for (often very spoofable) “root detection”. It’s quite sad.


Banking apps are usually huge data collectors (scaning installed apps for example) that invade privacy instead of giving proclaimed security.


I can- it is done over text so if you have apple devices, you can confirm on any of the devices. Technically it is routing through the phone though.


My bank will let me make deposits from my phone, but not from my computer. A few months ago, the phone app tightened its Play Integrity usage, and will now no longer run on the phone it had previously happily run on.


In the name of security, my workplace just enabled a policy that forces me to let them monitor my location 24/7 via Microsoft Defender.

Needless to say, I am happy I have a second work phone I keep disconnected from WiFi while not working.


just use the web site?




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: