logoalt Hacker News

philistinelast Thursday at 11:25 PM4 repliesview on HN

People tend to distrust websites. URLs are also an immutable ledger that guarantees you’re in the right spot. The web is surprisingly robust for security.

What guarantees your banking app is the right one? A PNG and an app name with no security whatsoever.


Replies

hellojesusyesterday at 1:15 PM

Isn't that more reason to go to your bank's website: to download the apk and then verify the hash of the downloaded apk before installing it? That would make me way more comfortable than the current system of "pray this app on the play store is actually my bank's".

curt15yesterday at 9:36 AM

> People tend to distrust websites.

How did the world come to this when the internet long predated smartphones and so many "apps" are little more than bookmarked wrappers around websites?

kuschkulast Thursday at 11:34 PM

But that doesn't guarantee anything? Even if the official banking app requires tons of verification, that doesn't prevent me from modding their banking app and redistributing the modded version to up to 20 people.

NekkoDroidyesterday at 6:52 AM

> People tend to distrust websites. URLs are also an immutable ledger that guarantees you’re in the right spot.

Typosquatting would like to have a word with you.