logoalt Hacker News

wdrwlast Friday at 5:16 PM1 replyview on HN

Dependence on a secure client is generally a bad idea. Security should be server-side.


Replies

edentlast Friday at 5:26 PM

This isn't about the bank's security - it is about the users'.

Users are losing billions worldwide due to fraudulent apps. If a user has root and runs a malicious app, it can intercept what a legitimate banking app does. A scam app with root can draw over the screen and tell users to transfer money, or it can run a series of actions when the banking app is running, or do any of a hundred things to steal money.

show 2 replies