logoalt Hacker News

tux3last Friday at 5:21 PM6 repliesview on HN

There's a trend of online banks forcing the use of an app. I can't login to one of my banks' website since last year without using a QR code from their app.

Of course they slathered the app with tracking, 'security', and analytics SDKs, so rooted devices are rejected. I had no way to log into this bank account after they made that change, which is simply wonderful.

Anyways, they're not yet at the point where they've learned to do the checks server-side. For now it's a one line patch to skip the root screen. But the Play Integrity API is designed correctly, if they learn to use it, there will be no workaround without someone finding a hardware vulnerability somewhere.


Replies

ljmlast Friday at 5:38 PM

Depends on what country you're in. In the UK, the banks are often held liable for various scams that involve the transfer of money, so they up the security over and over again. A bank will rightly argue why it's responsible for an old granny sending her life savings to her new lover in Namibia, so it seeks to block that transaction in the first place.

Some of that liability is fair but most of it is the government telling the banks to account for the loss when someone is scammed. They are obviously going to mitigate that as much as they can.

show 2 replies
cons0lelast Friday at 5:33 PM

Yep, hardware attestation is becomming more common, even with websites.

This is why LineageOS is actually dead in the water, even though they're "in talks with hardware vendors". It doesn't matter when people can't use the apps and services they need.

show 2 replies
adrrlast Friday at 5:38 PM

Bunch of fintechs only let your signup from an app. Easier to secure and prevent bots. Pin certs, detect virtualization, etc.

show 1 reply
jacobthesnakoblast Friday at 6:43 PM

Normiefication. Normies do everything on their phones; it’s the companies meeting the masses where they are. I’ve seen people fight for their lives to do a spreadsheet on their phones when there’s a laptop they own gathering dust less than 50 feet away.

show 2 replies
al_borlandlast Friday at 5:50 PM

This trend makes me want to find a small town credit union.

I chose my current bank because it was one of the few that had proper token based access for 3rd party integration. An overwhelming majority of banks were relying on a 3rd party holding your actual username/password and saying "trust me bro". I wasn't comfortable with that.

show 1 reply
bugbuddylast Friday at 5:37 PM

This is a very condescending toward Vietnamese tech people. According to Twitter/X, Vietnam’s GDP just surpassed Thailand and it’s on its way to joining the Great East Asian prosperity zone by becoming the last country to become fully industrialized and very rich. Many tech jobs in the US will move to Vietnam in the coming few years. You will be surprised where your future Tech conferences will be located.

show 1 reply