logoalt Hacker News

brightballtoday at 2:58 PM0 repliesview on HN

I don't run their business. Just trying to explain.

From what we see above it sounds like the change trips their rootkit detection, which they are probably interpreting as a compromised device.

It sounds like you're expecting them to have a perfect security posture that can correctly identify fraud in call cases and only block the real thing. It's more complicated than that and there's typically some type of scoring system involved with numerous triggers that are higher value indicators of potential fraud. If they think the device is compromised, that's probably a high value indicator.

This is just me speculating.