15 ms·
The Vietnam government has banned rooted phones from using any banking app
- curt15 8mo ago>The Vietnam government has banned rooted phones from using any banking app The Vietnam government has banned phones under their user's control from using any banking app.
- TZubiri 8mo agoIf the banking apps have a Terms of Service, you are free not to use the banking app. To give a specific example, suppose a banking app wants to require location services in order to try to login. Some users can bypass or spoof this, (in fact that's what the thread is about entirely, and for that they root the phones. Not all users who root the phones violate ToS, but it's a majority, or even a possibility, so they choose to disallow such usage. Pretty sensible stuff to me.
- xandrius 8mo agoYep, you are also free not to have a phone. But good luck living in our current times.
- redeeman 8mo ago> Pretty sensible stuff to me. where exactly do you work with this agenda and reasoning? thats insane? banks have been more or less made mandatory by the regimes around the world, and now these things. How can anyone possibly consider it sensible?
- Ritewut 8mo agoJust let me pair my Yubikey to my bank and use my Yubikey if I need my banking app.
- Arbortheus 8mo agoDo those same banks have websites that you can access from a computer with root access? Most likely, yes.
- dingaling 8mo agoEventually though I suspect that web access to banks will be rescinded too, much like HMRC in the UK no longer permits companies to submit their taxes through the websites. In the future, everything will need an 'app'.
- dangus 8mo agoThis seems like a massive jump to conclusions.
- margalabargala 8mo agoYou should make a mat for that.
- TheGamerUncle 8mo agoIt is a massive observation of how things look already no more, no less.
- dangus 8mo agoLet me clarify my statement: one government agency’s election to use an app for a single purpose isn’t an indicator of much. It’s not like the UK sent out a mandate to private banks or any other private industry on this issue. It’s also only one small country of hundreds. I’d have to question this idea that this is how things “already look.” I can think of very few businesses that I interact with that force me to use an app.
- warkdarrior 8mo agoThis type of election to use an app by a government agency sets the tone, and more importantly tends to redefine "best practices." Would you want to be the one private entity known to not be using best practices? Would your risk officers or lawyers be OK with that decision?
- Magnusmaster 8mo agoThe Vietnamese government has mandated all banking apps to detect if either the phone has been rooted, the bootloader has been unlocked, or ADB is enabled and force quit if that's the case.
- therealmarv 8mo agothe funny thing is... you can go around that with root if you know how.
- tartoran 8mo agoOne phone for banking and another one for browsing.
- deleted 8mo ago[deleted]
- ycuser2 8mo agoEasier said than done. You have to maintain two phones then (updates, keeping charged). You don't want to carry two phones around. Also you have to have two SIM cards/telephone numbers which costs money.
- Aleklart 8mo agodon’t need sim card on second one it is even more secure that way it is very common to have different phones for people who work with money transfers (including crypto)
- BizarroLand 8mo agoYeah, if you need network on the secondary, then tether it to the primary, lol.
- rixthefox 8mo agoIn this economy? /s The other more compelling reason why people would have a rooted phone is to run ROMs that may still be providing OS support where the stock OS has been abandoned or EOL'd by the developer. Having an unlocked bootloader at the minimum would be required in those scenarios. It actually saves hardware that still works from ending up in landfills. edit: spelling
- bsimpson 8mo agoI have a cache of old devices, largely the freebies Google gave out at I/O in the early days of Android. Was prepping them to sell last week and saw most are running Cyanogen (the first big community Android fork). Even then, root was a popular way to gain more functionality and add features that haven't been released for a device. Incidentally, if anyone wants some collector's edition Google/Android devices...
- taosx 8mo agoI really don't understand this. My line of thinking is that if someone is technical enough to root his phone he understands the risks. Why would they force banking apps to detect and not work on rooted phones? Why would the government care so much?
- baal80spam 8mo ago> Why would the government care so much? My guess is: 1. Person with rooted phone uses a bank app, is hacked, has their money stolen. 2. Guess where the person turns to for help? The government.
- basilikum 8mo agoI don't think this is actually happening. There is an enormous loss to scams mostly by tech illiterate people using the preinstalled operating system. I don't think the losses that involve user installed OSes are in any way significant.
- cestith 8mo agoI think it has more to do with the phone being tied to an individual, the banking and spending activities being tied to the phone, and the government having some hardware attestation about how people are spending their money and with whom. If you root a phone, you can change things like the MAC addresses. You may be able to futz with a softSIM/eSIM. That makes you harder to track.
- netc 8mo agoA phone given for repair by a non-technical person can be rooted without their knowledge. The repair person potentially can install malware. We cannot assume the owners of the rooted phone themselves have rooted the phone.
- h4x0rr 8mo agoHow would you root without resetting it?
- superkuh 8mo agoSmart phones are not personal computers. They're shopping/government/etc terminals. You don't and never have controlled them, even with root (re: tight integration of the baseband computer which only the telco has a license for, not you). Their best use re: computing is acting as wifi hotspot for their cell telco CNAT connection. The time to stop using them as computers is now, not when your local government passes these laws. Apple is already forcing it and Google has shown it's cards even if walked it back temporarily.
- negus 8mo agoSounds dystopian. I hope projects like OsmocomBB and Purism Librem will shape the future
- memoriuaysj 8mo agoyou are right, but you are misplacing the blame. it's not that you dont own your phone, it's that you dont own your bank account and the bank can dictate how you access it
- superkuh 8mo agoI see your point and it's valid in this context. But both ends of non-ownership contribute. One doesn't own the smartphone and one doesn't own the bank account. The National Credit Union Federation of Korea (NACUFOK) represents over 800 member-owned unions (https://www.cu.co.kr/english/main.do https://www.cu.co.kr/english/main.do), and then there is the even larger Saemaul Geumgo (MG) network which operates as community credit cooperatives with millions of members. These people ostensibly own their "bank" accounts.
- Magnusmaster 8mo agoYou don't own your PC either. All modern PCs have a Trusted Platform Module that the authorities can and will use to lock down PCs eventually. Multiplayer games are already using hardware attestation on PC for anti-cheat.
- superkuh 8mo ago
- grugdev42 8mo agoSerious question, what is gained from this move? Why would a government care? Are rooted phones really that much of a problem? Surely most people running a rooted phone are tech enthusiasts. Cybercriminals will just use regular phones bought under false names and dispose of them afterwards.
- memoriuaysj 8mo agothe banks would care. less money spent on security or dealing with clients who had their money stolen
- jamesnorden 8mo agoAre you implying there's a big percentage of people getting their money stolen because they rooted their phones? I'd like to see some data on that if so.
- TZubiri 8mo agoI think the point is that phone apps are more secure than, for example, web apps. Users that try to use mobile apps as if they were web apps, disabling location, and security features are just flagged by numerous security mechanisms.
- withinboredom 8mo agoProbably. I know a guy who roots phones for older people or friends parents, installs pirated games and such for them and making sure it is locked down in certain ways for the older generation. In other words, the correlation is that older people are more likely to have a rooted phone and are more susceptible to fraud. Dunno how widespread this is, just something to keep in mind.
- pmdr 8mo agoPerhaps people who unknowingly bought a rooted phone. I don't know how frequent this is, but it would be the only case it would matter.
- 8mo ago
- roflmaostc 8mo agoIsn't that what happens in Europe with most rooted phones and banks too? At least I can remember my banking apps stopped working.
- deleted 8mo ago[deleted]
- elric 8mo agoThere's no laws banning this in any European countries that I'm aware of, except maybe Hungary? It's just banks being stupid, consumer-hostile, and anti-competitive.
- Aspos 8mo agoWell, I've built a bunch of mobile banking apps and we did detect if the phone was rooted, was in dev mode, etc. and it is not because we were "stupid, consumer-hostile, and anti-competitive". If someone steals the secrets from a rooted phone and steals customer's money the bank is on the hook, so banks do everything they can to minimize this risk. There is no way to store customer's secrets in a PC browser securely, so all the "dangerous" transactions were outright prohibited in the web app or made available only via temporary QR login. All this is just is a negative side effect of customer protection laws.
- abdullahkhalids 8mo agoWhy don't banks just make desktop computer applications?
- Aspos 8mo agoPractically impossible to store secrets in a desktop app too. Besides, customers would not willing to install a desktop app. And those who would, will require support.
- mike_hearn 8mo agoPC platforms don't have remote attestation infrastructure working.
- Elfener 8mo agoThat link is to a page in that thread, but I guess it's supposed to be to this specific post: https://xdaforums.com/t/discussion-the-root-and-mod-hiding-fingerprint-spoofing-keybox-stealing-cat-and-mouse-game.4425939/post-90441375 https://xdaforums.com/t/discussion-the-root-and-mod-hiding-f...
- fenaer 8mo agoUnfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.
- TZubiri 8mo agoI'm assuming you would do this out of a political reason, or as a very technical and privacy aware user. But you are providing an alibi for malicious users who, for example, might try to brute force logins from unidentified devices. That would be one reason aside from the law. You are essentially positioning yourself on the same side as intruders.
- redeeman 8mo agoare you for real? no, its the government telling regular people that simply wants to control their device that THEY are criminals and on same side as intruders. You should personally immediately return any computing device where you have control, this line of reasoning is insane
- fenaer 8mo agoYou're claiming that the only legitimate use of rooting is criminal activity, which is not true. Your argument is based on a faulty premise in my eyes.
- attila-lendvai 8mo agoaka guilty until proven innocent.
- alephnerd 8mo ago> Unfortunately the answer here is to not abide by the law You realize in Viet Nam this means getting a "friendly" visit by the MPS/BCA, and if you continue eventually getting branded as a troublemaker.
- 8mo ago
- Aleklart 8mo agoOf course if you have root, you can make other programs work as you please. They need to go further to outlaw hide root apps, and then install special app to track the status of the phone to make sure it is not rooted. Then allow police to randomly check the presence of this app on people phones. Every phone needs to be registered and pass hardware inspection every year. Even better, make so called offices where people can come and deposit or transfer money, it will be super safe.
- Magnusmaster 8mo agoThey won't need to do that. Once Google Play Integrity starts using remotely provisioned keys in a few years it will be impossible to hide root without exploiting a hardware or firmware vulnerability.
- akshitgaur2005 8mo agoYou jest but governments will not even think before doing stuff like this. The recent "Sanchar Sathi" fiasco by the Indian Government is an example.
- deleted 8mo ago[deleted]
- PunchyHamster 8mo agoPolish ones do that too, incl our govt ID app
- skirge 8mo agoSocialist Republic of Vietnam: our phone
- SXX 8mo agoVietnam is as far from socialism as China. It's more like wild capitalism.
- redeeman 8mo agois not capitalism, is just whatever the regime feels like
- skirge 8mo agowhen exactly Communist Party of Vietnam abandoned Marxism - Leninism? Any official statement claims that?
- SXX 8mo agoDoes it really matter what official statements say if a country have stock exchange, group of billionares and market economy? Iived there for quite some time to understand its likely less regulated and government controlled than many ex-USSR countries (im from russia). Of course politically Vietnam is what it state it is compared to e.g Indonesia that I now explore. But economically it's the same capitalism as everywhere else.
- skirge 8mo agoyes, socialism is goal and "capitalism" is a tool to reach the goal.
- Fiveplus 8mo agoSo, if you cannot cryptographically prove to a remote server that your device is running essentially unmodified, vendor-signed software, you are locked out of the economy? The irrefutable part here is that the security model works. Locking down the bootloader and enforcing TEE signatures does stop malware. But it also kills user agency. We are moving to a model where the user is considered the adversary on their own hardware. The genius of the modders in that XDA thread is undeniable, but they are fighting a war against the fundamental architecture of modern trust and the architecture is winning.
- zb3 8mo agoThe problem is that we're supposed to use these "secure apps" on our own devices.. but since they need these enhanced security guarantees, our own devices cease to be ours.
- Helmut10001 8mo agoAs I mentioned in another post: By 2026, you'll need two phones. My current setup: 1) An unmodified iPhone SE (2022 model) with OS support until 2032. This runs all my authentication, banking, health, etc. It is in airplane mode 99% of the time unless I need it. 2) The second is a Pixel 9a with Graphene OS for daily use, routing and internet access. This is expensive, but I found it to be the only viable solution to this problem.
- ThePowerOfFuet 8mo agoGrapheneOS is not rooted. Most banking apps work fine on it. https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa... https://grapheneos.org/usage#banking-apps https://grapheneos.org/usage#banking-apps
- NoGravitas 8mo agoIt's true that GrapheneOS is not rooted, and, unlike other non-rooted custom ROMs, allows re-locking the bootloader. But, whether a banking app will work depends on what level of Google Play attestation they require. While most banking apps work fine on it, a significant minority do not.
- zb3 8mo agoGoogle is to blame, they're abusing device security by preloading their unremovable spyware with elevated privileges.. people then want to remove it but then find themselves unable to use banking apps because of this. I'm not against having a separate secure phone to use with banking apps, but that phone must be designed for security, not for Google's ad driven business model..
- patrakov 8mo agoYour words can be reasonably interpreted as "that phone must be an iPhone"; did you actually mean this?
- zb3 8mo agoI'm not a fan of Apple, but I have to admit they're less intrusive when it comes to unremovable unwanted software (it's less open for those making software though). I wish we didn't have to choose between Google and Apple, especially here in Europe where we can be sactioned by the US for doing our job..
- dizhn 8mo agoDon't mess with Vietnam please. My phone's CSC is set to Vietnam to enable call recording. I love that feature but I don't want to lose my banking apps.
- ThePowerOfFuet 8mo agoGrapheneOS allows call recording, period. Most banking apps work, too. https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa... https://grapheneos.org/usage#banking-apps https://grapheneos.org/usage#banking-apps
- alephnerd 8mo ago1. Don't people on HN realize Vietnam is a single party authoritarian state with a very active secret police (MPS/BCA)? 2. Vietnam has been in the process of rolling out national biometric identification for years now as part of the VNeID [0] project, and unifying that with banking and mobile phone identification is an important part of that such as with the recent FPT Telecom announcement [1]. The aim is to turn VNeID into a super-app by 2030 [2], and from what I've seen in rural areas of the Central Highlands, it's on track. [0] - https://vneid.gov.vn/ https://vneid.gov.vn/ [1] - https://tuoitre.vn/vneid-mo-rong-dich-vu-so-dang-ky-internet-truyen-hinh-camera-khong-can-giay-to-20260107190940395.htm https://tuoitre.vn/vneid-mo-rong-dich-vu-so-dang-ky-internet... [2] - https://tuoitre.vn/thieu-tuong-nguyen-ngoc-cuong-nang-cap-vneid-thanh-sieu-nen-tang-so-diem-truy-cap-duy-nhat-20251220151845288.htm https://tuoitre.vn/thieu-tuong-nguyen-ngoc-cuong-nang-cap-vn...
- npn 8mo ago[flagged]
- deleted 8mo ago[deleted]
- OutOfHere 8mo agoWhy can't rooted phones pretend to be non-rooted phones for the purpose of certain apps? What's the point of rooting if you can't even selectively pretend?
- redeeman 8mo agothey can to a large degree. but theres many layers to it. I for example hide root from my banking app in Portugal.
- snackbroken 8mo agoBecause root is not the ultimate authority of what goes on in the phone; the hardware is, and the hardware contains a TPM (Treacherous Platform Module). The TPM has secret cryptographic keys it never shares with anyone, neither root nor an unrooted OS. When the phone starts, the TPM checks if the OS has been modified from what the manufacturer supplies or not. The bank's app can then ask the OS to sign documents using the TPM's secret keys, and the OS forwards such requests to the TPM. The TPM refuses such requests from modified OS but obliges requests from an unmodified OS. The bank's servers refuse to accept documents not signed by the TPM. Root can't pretend to be a TPM and make up some secret keys to sign documents with because the TPM's signature is itself signed by Google, so the bank can tell the difference between root's signature and a treacherous signature.
- OutOfHere 8mo agoAnd is there no way to make the TPM think that the OS is unmodified?
- Magnusmaster 8mo agoTo avoid confusion, the actual name is Trusted Platform Module.
- netsharc 8mo agoIf this pretending works 100%, then a malware can use that technique to pretend that the phone is secure, to trick you into using your bank app and steal your money anyway. I also prefer to own my device and be root on it, while installing all the "pretend I'm non-rooted" functionality on it, I did think "this is basically installing a rootkit to tell the OS 'yes, I'm clean!'.". Then my bank (fuck them very much) decided to add a check for a locked bootloader and refused to work without it. I suppose maybe there's a way for the "rootkit" to lie and say "Yes the bootloader is locked!"? I didn't read all the comments, but it seems to have been lost that it's a fight between freedom (allowing people to "own" their devices) and protecting the general public from harm (being scammed and losing all their money). We also have to give up some freedoms, eg. we are forced to wear helmets or seatbelts as participants of traffic, to ensure a better protection.
- ecshafer 8mo agoWhen I used to work on the Vanguard authentication team, we blocked Vietnam from access because of too much fraud (not my choice). But it was funny because we had Vietnam based clients, so there were a couple HNW clients in the logs that you could see who would log in from Vietnam/Russia/Wherever, get blocked, open their vpn, then log in from England. This was a while back, but even then there was a push for things like yubikey, and hardware tokens, so its not surprising the wind is blowing in this direction of just hardware authenticated people. Financial companies are just constantly fighting fraud in a million ways.
- Zak 8mo agoI'd be really interested to know whether a significant amount of fraud and fraud attempts involve devices with root or non-stock operating systems. This has always struck me as a matter of checkbox compliance rather than a commonly-exploited attack vector, though I'll grant that's partially because few people actually use such devices.
- browningstreet 8mo agoI worked in fraud compliance architecture at a bank.. they didn't checkbox anything. They had a lot of gathered data and justification for the limits they enabled. I'm sure not every bank does it that way, but they weren't trying to limit legit customer access, and they pained at enforcing limitations like this.
- Zak 8mo agoCan you share what limits they did and did not impose?
- IshKebab 8mo agoYeah I call bullshit. The number of people with rooted phones is going to be way less than 1%, and the number of those that are unsophisticated enough to fall for scams/malware is going to be miniscule. This is pretty clearly a case of "oh there's an option here that says 'allow on rooted phones', do we want to allow that?" "No that sounds scary and risky! Of course not. We must not allow it." The option is there, and nobody is going to try to sell not ticking it.
- linkregister 8mo agoThis is likely part of the Vietnamese and Thai governments' rollout of biometric linking for bank accounts, similar to KYC regulations in the United States. The deadline for Vietnamese biometric linking was December 19th, 2025 [1]. The Vietnamese government has reported a rise in account takeovers and other banking thefts [2]. SIM-swapping has been a tactic used. Adding difficulty for fraudsters to trick unsophisticated banking customers is a valid security layer. 1. https://vietnamnet.vn/en/biometric-deadline-nears-millions-of-accounts-face-online-suspension-from-2026-2474005.html https://vietnamnet.vn/en/biometric-deadline-nears-millions-o... 2. https://evrimagaci.org/gpt/vietnam-faces-surge-in-sophisticated-online-banking-scams-521355 https://evrimagaci.org/gpt/vietnam-faces-surge-in-sophistica... (expands upon https://vneconomy-vn/techconnect/mobile-banking-phat-trien-manh-tai-viet-nam.htm)
- alephnerd 8mo agoPartially, but it's also connected with the VNeID project [0]. The goal is by 2030 [1], all Vietnamese nationals and foreign visitors will have a digital biometric ID attached to themselves, and all services linked to said ID. [0] - https://vneid.gov.vn/ https://vneid.gov.vn/ [1] - https://tuoitre.vn/thieu-tuong-nguyen-ngoc-cuong-nang-cap-vneid-thanh-sieu-nen-tang-so-diem-truy-cap-duy-nhat-20251220151845288.htm https://tuoitre.vn/thieu-tuong-nguyen-ngoc-cuong-nang-cap-vn...
- basilikum 8mo ago> SIM-swapping has been a tactic used. Adding difficulty for fraudsters to trick unsophisticated banking customers is a valid security layer. You fight SIM-swapping by outlawing the moronic practice of using SMS for anything security sensitive. Not by blocking user modified OSes.
- morshu9001 8mo agoWhat's the alternative that regular people will understand how to use and not get locked out of?
- basilikum 8mo ago
- basilikum 8mo agoThere are two plausible explanations for this: 1. Incompetence. The same reason why many banks al around the world do this without regulations. Some snake oil salesman sold them a security theater SDK or library that blocks user installed or modified OSes. 2. Government control and surveillance. Vietnam is authoritarian. It only makes sense for them to participate in the global war against general purpose computing to gain complete control over their citizens' devices allowing them to restrict software, displayed content and communication to require government approval and enable total surveillance of all activity without any way to bypass this. Instead of outlawing user controlled general purpose computing directly they do it through the backdoor of pretending that it is for people's own safety.
- deleted 8mo ago[deleted]
- lawlessone 8mo agoodd they legislate for it, banks usually do this anyway
- cestith 8mo agoThe fact it’s the government who cares suggests whose interests the law is serving. Viet Nam is a pretty authoritarian country right now, and it loves the ability to track the activities of citizens.
- lawlessone 8mo agoit's for banking apps specifically though. Anyway it's not like they're the UK and have age ID's for their internet lol
- cestith 8mo agoAuthoritarian governments have an interest in knowing where and how you spend your money, and from where you got it.
- anthk 8mo agoFree software, free society.
- exabrial 8mo agoNothing to do with security, everything to do with control.
- kachapopopow 8mo ago> bans rooted phones > malicious actors just compromise the firmware instead surprised pikachu face
- Havoc 8mo agoI get the general skepticism and how this gives anti freedom vibes, but wouldn't this also prevent some actual rootkit like sideloaded apps stealing credentials? Not deep into rooting scene but seems plausible to me that this has some merit if you squint at it from the right angle
- horsawlarway 8mo agoHere's the fundamental problem: Trusted agents are useful. And I'm using legal meanings, not technical meanings here - so a "trusted agent" is someone or something that is legally acting on your behalf, to perform actions as though you were performing them. The whole fucking promise of "general purpose computing" is that citizens should be able to delegate repetitive and tedious tasks to a computer. And they should have the full freedom to pick both which tasks are delegated, as well as which agent (program) is performing them. Instead - what we're seeing is that companies are closing off as many avenues of automation for the average citizen as possible, under the guise of security. The problem is that selecting a neutral (trusted!) agent is really, REALLY important, and companies are absolutely not neutral. They don't want the best results for "average Joe customer", they want the best results for themselves: the company. They will make decisions that are contrary to your best interests all the time. They have exactly zero fiduciary duty to you, and boy do they know it. In a decent world - in a decent CAPITALIST SOCIETY (which we can already debate the decency of in the first place) you allow space in the market for modification. Ex - don't like your desk? Change it. Don't like your car radio? Change it. Don't like that tool handle? Change it. Pick a different one, even one from a totally different company. Replace it. This allows new ideas, new growth, and prevents stagnation. In the digital world... there are a few companies that are trying as hard as possible to prevent you from being able to change anything. --- Want a new browser? Fuck you. Want a different UI for your banking needs? Fuck you. Want to watch something without the ads? Fuck you. Want to watch something with the ads, but in a less miserable ui? Fuck you too. Want to automate something? Fuck you. Want to export your data? Fuck you. Want to sell software without us taking our rent money? Fuck you. Want to shop in a different store? Fuck you. Can't be letting our users make decisions that might cost us money. --- So we're seeing an absolutely insane number of "digital locks" being employed not to protect users. No - instead they're getting deployed to protect revenue at the expense of users. The only possible outcome is that service quality degrades to the point where you literally are better off without. Because that's what happens to incentives when you let companies operate in this manner. If the consumer has no choice - the market has no power, and what little value there is in capitalism goes right into the trash bin. So sure - if you squint, this maybe prevents someone from making a bad decision on which agent they trust. But the problem is that now they HAVE to trust an agent they know is going to make bad decisions for them. Hope you like the biggest ad company in the world owning you digitally... Serfdom here we come.
- emsign 8mo agoSimple solution: Get a second phone just for banking and all the other enshitifying apps and keep it at home where it doesn't bother you.
- _ck_ 8mo ago[dead]
- pvsukale3 8mo agoIndia doesn’t have a single “govt ban rooted phones from banking apps” rule, but RBI’s digital payment security controls explicitly allow banks to block mobile apps on rooted/jailbroken devices, and many do. Combine that with device+SIM binding requirements and platform attestation (e.g., Play Integrity), and the practical result is often “no banking/UPI on rooted phones.”
- a456463 8mo agoNot only that, Android apps want full access to contacts and SMS but at the same iOS apps don't require those permissions. So it was never really a matter of security. This is all security theater from bootlickers
- Pxtl 8mo agoGovernment banning insecure open standards and then not providing a secure open standard is atrocious. If I must have an official authorizing thing to prove I'm who I say I am, make it as small as possible. If you mandated that they have to support Yubikey or whatever on open platforms I'd take that as a decent alternative. But just "no you must use a device controlled by somebody else" is not acceptable.
- a456463 8mo agoYAS!! The option is to provision an key from a server tied to a national id and downloadable only to specific device. BUT NO!!! Just ban things instead of doing the right thing!
- ryandrake 8mo agoThe biggest "evil" that has been committed (and is still being committed) against computing has been normalizing this idea of not having root access to a device you supposedly own. That having root access to your computer, and therefore being the ultimate authority over what gets run on it, is bad or risky or dangerous. That "sideloading" is weird and needs a separate name, and is not the normal case of simply loading and running software on your own computer. Now, we're locking people out of society for having the audacity of wanting to decide what gets run and not run on their computers?
- a456463 8mo agoAnd a full on fight against ownership of stuff you paid, right to repair something you own with your own money, and general computing access.
- qwertox 8mo agoPhones are no longer ours. A bit like bought ebooks, games, movies,and the like. we just payfor the right to use them. ok the phones we can keep, so we pay a lot for the hardware, but the OS: not. They like to advertise it as part of the phonev but it' not. The little surveillance machines.
- xeonmc 8mo agoIf buying is not owning, pirating is not stealing. Piracy isn’t merely a virtue, but a moral imperative, an obligation to uphold civic freedom. It is immoral not to pirate. It is everyone’s duty to do their part in normalizing and encouraging piracy.
- Sophira 8mo agoPirate... what? A phone? Android? Banking apps? The problem here isn't the money, it's the lack of privacy and control. The best analog I can think of to piracy in this situation would be rooting the phone/installing GrapheneOS. And, yeah, that's definitely something people should do if they want that control, but I really hope people don't put it in the same category as piracy...
- sgc 8mo agoSecurity question: Could we have the same level of security - or very close to it - from requiring a secure enclave like a vm running on the device for banking apps with hardware passthrough, or would there be no way for that vm to verify it has actual hardware passthrough and that it's not being tampered with? That way you would just get the entire vm with the app from the Play Store or Apple, and nobody needs to worry about root?
- deleted 8mo ago[deleted]
- yason 8mo agoProblem is that banks place a lot of trust on a locked-down phone and I have a hard time trusting a blackbox device I don't really own but only paid for. That's the reason I mostly use online banking on the web, not on a device. If it ever comes to that in my country I can also use my previous, unrooted backup phone to host these apps and keep it at home. I'm not at all thrilled of the idea of carrying your credentials to your bank account on your phone, accessible via a 4-digit PIN out there in the world in the first place. For some reason, banks think it's great.
- lucasjans 8mo agoI have a Vietnam bank account tho I live in the States now. I recently enabled developer mode in my Android phone, didn't think much of it. But later when I open my mobile banking app it told me to disable developer mode in order to open the app. It's not just root that they block.
- therealmarv 8mo agoyou are as developer already half way on the evil side in their opinion ;) It's ridiculous.
- deleted 8mo ago[deleted]
- GeoAtreides 8mo agoIt's clear that we will need two phones: one personal day to day driver and one for banking/gov/other official things.
- almosthere 8mo agobuy two phones if ur that crazy
- alephnerd 8mo agoYou need to use a digital biometric ID managed by the Ministry of Public Security for most services in Vietnam now.
- almosthere 8mo agoi guess there is less fraud then
- gethly 8mo agothe cage used to be golden. now it's digital.
- greentea23 8mo agoThere are a million legitimate reasons to root a phone (e.g. preserving the battery to minimize e-waste, blocking malicious trackers often allowed by Apple and Google, innovating on the UI, etc.). Apple/Google/Microsoft are run by uninspired, uncreative, and immoral people, and there is a world of innovation and forward thinking we lose out on by letting them rule our tech.
- nunez 8mo agoAs a person who was super into the rooting scene before getting iPhone-pilled in 2018 or so, I can see both sides to this issue. On one hand, people that jump through the crazy hoops phone manufacthrers put up to get root are either technically-proficient or willing to become so and are, usually, responsible enough to keep their devices locked down and secure. On the other hand, banks are subjected to literally all of the regulations, and breaking any of them usually incurs unbelieveable fines. Given that phones are the default computing device for most people these days and how (relatively) easily secrets can be extracted from rooted devices, blanket-banning them makes a lot of sense. Nonetheless, modern Android is just as locked down as modern iOS, with a few exceptions (like adb access) and without the awesome hardware and software optimizations for that hardware that make video recording fast and web browsing even faster. Between this and nobody having a real answer to Apple Watch, I'll be an iOS stan for the foreseeable future.
- RachelF 8mo agoI don't understand the threat model that banks worry about on rooted phones. What is it? I can access their websites on a PC running as root or Administrator. What is the problem with rooted Android phones?
- 8bitsrule 8mo agoOne more reason for phones to be modularized. Separate the comms from the (owner-controlled) computer module until needed. Use different CPU module when needed. Swap out battery module.
- linuxhansl 8mo agoAnd so it begins... Or continues... Apple is already a walled garden, granting you only access to your hardware and they see fit. Google desperately wants to follow suit by enforcing developer registration (which is just the first step). And now this. This is will happen in the EU and US as well. And always in the name of security, safety, or "will nobody think of the children?!" My hardware, my choice, period.
- walkthisway 8mo ago> My hardware, my choice, period. You can choose to not use the app. The bank has a choice on how customers interact with it. The government, regulating banks, and often acting as insurance for lost money, has a choice on setting required security standards. Balancing all these is difficult.
- linuxhansl 8mo agoFair enough. If there remains an option to still opt in to full control over my h/w at the expense of some vendors saying that I can't use my phone with them, that's good enough.
- somat 8mo agoSo what's the mechanism here? I did not find any sort of api like isPhoneRooted() But also, I did not look very hard. I am probably missing something obvious(some sort of tpm key attestation) but it feels like it would be impossible task. I mean, theoretically higher layers can check that lower layers have the correct signed checksums, but they need to use the lower layer to do it and the lower layer could just lie to them. (if isSystemFile(f_name) then return originalFile(f_name); or provide a virtual tpm).
- miki123211 8mo agoThe point of blocking rooted devices often isn't to protect your account, it's to protect other (often unsophisticated) customers of the organization against automated attacks. Rooted devices aren't the problem, Python scripts pretending to be rooted devices are. There's just no way to distinguish between the two. The only way to disallow automated Python scripts from logging to your grandma's bank account is to also disallow you from logging into yours if your phone isn't blessed by Google.
- cwillu 8mo agoSo make a toggle in the account settings that requires a blessed phone or an authenticated visit to the branch to set. There's nothing here that requires _my_ device to be authenticated in order to protect my grandma.
- reyqn 8mo agoWhat stops people designing those automated attacks to run the python script on a phone that is blocked by Google?
- 7bit 8mo agoJust Yesterday I read that Vietnam banned unstoppable ads and was like: wow, Vietnam is really pro-consumer and progressive and gives a damn about lobbyists. Well. Gone is that notion ..
- steamer-signed 8mo agoHM? wondering if this article from Cybernews is true, I wouldn't blame Vietnam. Cyber incidents cost firms up to $5m and can take weeks to recover from: report....
- steamer-signed 8mo agoCyber incidents cost firms up to $5m and can take weeks to recover from: report. If this article by Cybernews is correct then I wouldn't blame a country to ban ROTTED phones.
- peter_d_sherman 8mo agoRandom Idea: A Completely Open-Source Banking App... Consider an Open-Source Web Browser (Chromium, FireFox, ?, ???, or any open-source browser from: https://github.com/nerdyslacker/desktop-web-browsers https://github.com/nerdyslacker/desktop-web-browsers). OK. We know the following: A) That most Banks have web pages / websites which can be accessed via one or more of the above web browsers (AKA "Online Banking"), where the provided functionality is exactly the same, or very close to the functionality provided by stand-alone banking Apps B) That the source code for any open-source web browser is available, and can be downloaded (A self-evident truth!) From which the following understanding can be derived: C) The security for the transactions (user authentication, authorization, etc., etc.) is NOT provided on the client side (the user's computer or smartphone) by an obfuscated "binary black box" piece of software where source code is not provided, but rather on the server side (the Bank's side!) (Oh sure, Web Browsers provide encryption to prevent the middle segment of the communication path, the Internet, from listening in, but the encryption libraries of open-source web browsers are also typically themselves open-source, thus easily transferred to / imported into the source code bases / software component stack -- of other Apps!) Well, if we know A), B), and C), then we also understand that a truly Open-Source Banking App, giving exactly the same security guarantees that an Open-Source Web Browser does today, is possible! Such an app, if it were to exist, due to its open-source nature, would not be bound by artificial constraints, such as the absence or presence of an underlying rooted Smartphone, or not... Also, in theory such an App, were it to exist, could be ran on very minimal, possibly more secure (than your average bloated Smartphone) alternative hardware... Also, if you think about it... Bitcoin and other cryptocurrency apps -- are fundamentally that App (!) -- just that they use the Blockchain, and not a Bank, as the back-end! :-) You know, you have a payment-provider App. It could have any number of back-ends to it... Bank, Blockchain, ?, ??? You tell me... :-)