logoalt Hacker News

vagestoday at 11:53 AM2 repliesview on HN

Thanks for the Norwegian perspective.

I agree that the locking down is truly stupid. For what it’s worth, the reasoning for locking down mobile apps is allegedly that mobile users are a less technologically competent demographic than desktop users. I do not think so myself, given the difficulty in trying Graphene vs. Desktop Linux.


Replies

microtonaltoday at 2:47 PM

I agree that the locking down is truly stupid.

I don't agree that it is stupid. Both banking on a Windows PC or on an unlocked + rooted phone is potentially catastrophic. Windows because of the prevalence of malware, unlocked phones with custom AOSP forks because people download 'ROMs' (as they call them) from the most shady sites.

Once 10,000s of Euros are siphoned from a bank account, it's usually the bank that has to deal with the mess. Especially if they cannot prove the transactions were done in on an insecure platform.

Phones are generally safer (though there is a huge variance between the safety of different Android phones) because they use verified boot and strong application sandboxing.

I think it is possible to believe the following two things a the same time:

- Banking apps should only run on locked phones with secure boot.

- Banking apps should not be limited to the Apple/Google duopoly.

The solution is that there is some validation of alternative OS vendors, e.g. in the form of an audit, and that banks are required to approve apps on their platforms after the audit. This would be fairly straightforward tech-wise, because e.g. GrapheneOS supports remote attestation, but banking apps need to add/allow the hashes of the official boot keys: https://grapheneos.org/articles/attestation-compatibility-gu...

show 1 reply
malfisttoday at 12:56 PM

Those people who root their phone and install alternate OSes sure are less technologically competent than someone with a browser and a laptop

show 1 reply