Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk  ·  activity timestamp 4 hours ago

@mensrea So far, none of the ones I use do...

Perhaps that will change, and if it does / becomes a sufficient problem, I will probably end up with a dedicated "banking apps only" device.

  • Copy link
  • Flag this post
  • Block
Adam Jacobs 🇺🇦
Adam Jacobs 🇺🇦
@statsguy@mas.to replied  ·  activity timestamp 3 hours ago

@neil So they think your app would be more secure if you used something like P@assword1 as your password instead of something like hs\3jz{7{}h./5yT/9x#H6d]9Hh?-

Er, OK then.

  • Copy link
  • Flag this comment
  • Block
Mark ☸
Mark ☸
@Duckbill4994@social.linux.pizza replied  ·  activity timestamp 3 hours ago

@neil

We are seeing and more of this, and we need to pressure our EU representatives to make it illegal. OR:

Make it legal in the EU to hack around this google stupidity.

@EUCommission

  • Copy link
  • Flag this comment
  • Block
Whatevs
Whatevs
@whatevs@mastodon.scot replied  ·  activity timestamp 3 hours ago

@neil what is the “legal” background for the HSBC app to check which other apps one has on their phone? Isn’t there some privacy breach? What if one has some more “sensitive” apps?

  • Copy link
  • Flag this comment
  • Block
helloyanis :veripawed3:
helloyanis :veripawed3:
@helloyanis@furries.club replied  ·  activity timestamp 3 hours ago

@neil Yup, when something has the "Query all packages" permission, it's always a huge red flag for me!

Permission list of the HSBC banking app. It is allowed full network access, to run at startup, take photos and videos and query all other installed packages
Permission list of the HSBC banking app. It is allowed full network access, to run at startup, take photos and videos and query all other installed packages
Permission list of the HSBC banking app. It is allowed full network access, to run at startup, take photos and videos and query all other installed packages
  • Copy link
  • Flag this comment
  • Block
Emilio ʕ̡̢̡ʘ̅͟͜͡ʘ̲̅ʔ̢̡̢
Emilio ʕ̡̢̡ʘ̅͟͜͡ʘ̲̅ʔ̢̡̢
@Minimac@mastodon.world replied  ·  activity timestamp 4 hours ago

@neil I deleted two bank apps I will use through website.

  • Copy link
  • Flag this comment
  • Block
Ozzelot :anarchy: :linux:
Ozzelot :anarchy: :linux:
@ozzelot@mstdn.social replied  ·  activity timestamp 4 hours ago

@neil Air Bank has recently blocked my entire account because I had NFCgate (which, to be fair, is at least an attack vector.)

I solved it by switching banks.

  • Copy link
  • Flag this comment
  • Block
Zoran Jeremić
Zoran Jeremić
@zoran163@mastodon.social replied  ·  activity timestamp 4 hours ago

@neil Spyware!

  • Copy link
  • Flag this comment
  • Block
James
James
@JHB17@mastodon.online replied  ·  activity timestamp 4 hours ago

@neil

That sounds almost legit. It doesn't like that Bitwarden was side-loaded rather than loaded from an 'approved' source.

However, I'd be ripped if it objected to an app I have from F-Droid that does not touch passwords.

My bank won't let me use a VPN because then they don't know where I'm logging in from. They require 2fa and passwords but VPNs throw them.

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

To be honest, this is just a timely reminder than I planned to move away from banking apps anyway, in favour of websites.

I'd started doing this kind of thing with other apps - e.g. parking apps - when I started using postmarketOS, but I had not got round to banking apps.

  • Copy link
  • Flag this comment
  • Block
Tim Ward ⭐🇪🇺🔶  #FBPE
Tim Ward ⭐🇪🇺🔶 #FBPE
@TimWardCam@c.im replied  ·  activity timestamp 4 hours ago

@neil I don't use banking apps except on the rare occasions that the bank requires me to (eg to take a photo as extra authentication for a transaction above the normal limits).

I have tried to use parking apps but have never succeeded in making one work. So if I can't pay for parking using card or cash I don't pay, and if anyone complains I'll post them a cheque for the amount I was unable to pay.

  • Copy link
  • Flag this comment
  • Block
ninkosan
ninkosan
@ninkosan@mas.to replied  ·  activity timestamp 4 hours ago

@neil banking apps are a unique form of bad. My favourite example being the Santander one as below. Over half a gig for a glorified web interface!

Santander UK App Store listing showing a size of 651.2MB
Santander UK App Store listing showing a size of 651.2MB
Santander UK App Store listing showing a size of 651.2MB
  • Copy link
  • Flag this comment
  • Block
nadja
nadja
@dequbed@mastodon.chaosfield.at replied  ·  activity timestamp 4 hours ago

@neil Yeah, banking apps are … scary. Not just because of the level of control they demand but also how badly their security tends to be for how devastating a breach is there and the general software deployment approach of “well bugs are acts of higher power so no we won't give you your money back *shrug*”.
I have used 1½ banking apps in total (one for paying with my phone which last I reviewed it is actually pretty secure) and a TAN app because that bank was weird about physical TAN generators

  • Copy link
  • Flag this comment
  • Block
cuan_knaggs
cuan_knaggs
@mensrea@freeradical.zone replied  ·  activity timestamp 4 hours ago

@neil good luck with that. our banks require their app to use the site

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

@mensrea So far, none of the ones I use do...

Perhaps that will change, and if it does / becomes a sufficient problem, I will probably end up with a dedicated "banking apps only" device.

  • Copy link
  • Flag this comment
  • Block
Ben Tasker
Ben Tasker
@ben@mastodon.bentasker.co.uk replied  ·  activity timestamp 3 hours ago

@neil @mensrea FWIW, I have a phone that's only for banking apps.

As you might expect, it's a bit of a pain in the arse: I have to keep it securely (because, unlike the phone I carry, I wouldn't notice it missing until I next needed it).

There was also some apps that I couldn't move onto it because the provider has decided to use the app for payment authentication, so I'd need to be by the phone to spend.

Overall though, it still feels worth it

  • Copy link
  • Flag this comment
  • Block
Steve Scott
Steve Scott
@wishy@tooter.wishy.co.uk replied  ·  activity timestamp 3 hours ago

@neil @mensrea There certainly seems to be a move towards 3DS transaction approval via Banking App push rather than SMS code.

For the general population that's probably a good thing for security. But there are groups affected by this. I think most have a fallback to SMS available, but that enables SIM Swap fraud...

  • Copy link
  • Flag this comment
  • Block
Yvan
Yvan
@yvan@toot.ale.gd replied  ·  activity timestamp 4 hours ago

@neil @mensrea yeah, banking-app-only-device is where I am heading... I have/use four of the damn things, they live on my "secure" (lol) Android "phone" which has a minimum of other junk on it (but isn't entirely clean as its my backup/second phone for essentials & main actual "calling" & sms number — rarely used mind, mainly gets those text message codes.)

Hoping to migrate my everyday use Android phone to something like PostmarketOS or Graphene in 2026 (probably need a whole different handset than this current Samsung S23 mind.)

  • Copy link
  • Flag this comment
  • Block
Derick Rethans
Derick Rethans
@derickr@phpc.social replied  ·  activity timestamp 4 hours ago

@neil HSBC requires the app for me to login on their website, although it's possible that I opted in into that and there is no way back.

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

@derickr

They were happy to send me a new security key today, and that entailed deactivating the mobile app provisioning, so hopefully the combination of the two will let me log in using the key they will send me :)

  • Copy link
  • Flag this comment
  • Block
cuan_knaggs
cuan_knaggs
@mensrea@freeradical.zone replied  ·  activity timestamp 4 hours ago

@neil so far none of the banks i use have started complaining about f-droid or lineageos but bank phone/android vm is likely

  • Copy link
  • Flag this comment
  • Block
LΞX/NØVΛ :lesbian_flag: 🇪🇺
LΞX/NØVΛ :lesbian_flag: 🇪🇺
@lexinova@toot.community replied  ·  activity timestamp 4 hours ago

@neil @GrapheneOS some question.

Is it possible to restrict the app access to the list of installed app on the device ? if yes how ?

  • Copy link
  • Flag this comment
  • Block
LΞX/NØVΛ :lesbian_flag: 🇪🇺
LΞX/NØVΛ :lesbian_flag: 🇪🇺
@lexinova@toot.community replied  ·  activity timestamp 4 hours ago

@neil what is your OS ?

i guess it's a stock android ?

If graphene i don't understand how they access this info without you giving it directly (as even some third party app store need "special permission" to list those app (but they may have found a way)), so if graphene maybe report it to them so in a next version they can lock thoses access to app.

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

@lexinova GrapheneOS.

  • Copy link
  • Flag this comment
  • Block
LΞX/NØVΛ :lesbian_flag: 🇪🇺
LΞX/NØVΛ :lesbian_flag: 🇪🇺
@lexinova@toot.community replied  ·  activity timestamp 4 hours ago

@neil answered by including graphene so if they answer and tell a trick you can maybe try it ^^.

But if you are in EU, you can try revolut, in my case it work wonder and they don't seem to do this.

But maybe they are afraid of EU regulation if they do this 😐 but it work

  • Copy link
  • Flag this comment
  • Block
devolute
devolute
@devolute@mastodon.social replied  ·  activity timestamp 4 hours ago

@neil Do they still support a post-it note with my HSBC password and National Insurance number fastened to the back of my spectacles case?

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

@devolute

I tried, but I couldn't find your spectacles case :(

  • Copy link
  • Flag this comment
  • Block
Compi
Compi
@compi@ceres.social replied  ·  activity timestamp 4 hours ago

@neil Imagine getting blocked for using a safety app. HAHA what a shitshow.

  • Copy link
  • Flag this comment
  • Block
Werner the Werewolf 🎃
Werner the Werewolf 🎃
@worldwidewerner@mastodon.social replied  ·  activity timestamp 4 hours ago

@neil
I'd be furious. Probably switch bank.

  • Copy link
  • Flag this comment
  • Block
Thomas Cloer
Thomas Cloer
@teezeh@ieji.de replied  ·  activity timestamp 4 hours ago

@neil Why not simply install Bitwarden from the Play Store?

And regarding F-Droid, I recommend reading

https://privsec.dev/posts/android/f-droid-security-issues/

F-Droid Security Issues

F-Droid is a popular alternative app repository for Android, especially known for its main repository dedicated to free and open-source software. F-Droid is often recommended among security and privacy enthusiasts, but how does it stack up against Play Store in practice? This write-up will attempt to emphasize major security issues with F-Droid that you should consider. Before we start, a few things to keep in mind: The main goal of this write-up was to inform users so they can make responsible choices, not to trash someone else’s work.
  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

@teezeh

> Why not simply install Bitwarden from the Play Store?

I don't use the Play Store.

  • Copy link
  • Flag this comment
  • Block
Thomas Cloer
Thomas Cloer
@teezeh@ieji.de replied  ·  activity timestamp 4 hours ago

@neil Where did you get the HSBC app then?

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

@teezeh Via Aurora

  • Copy link
  • Flag this comment
  • Block
zeitverschreib [friendica]
zeitverschreib [friendica]
@zeitverschreib@freundica.de replied  ·  activity timestamp 4 hours ago

@neil

So via the Playstore.

When I share Bitwarden from Aurora, I get this:

play.google.com/store/apps/det…

Same for HSBC:

play.google.com/store/apps/det…

@teezeh

HSBC UK Mobile Banking - Apps on Google Play

The quick, simple, secure way to manage your finances on your mobile or tablet

Bitwarden Password Manager - Apps on Google Play

Bitwarden is a login and password manager that helps keep you safe while online.
  • Copy link
  • Flag this comment
  • Block
Holger Hellinger
Holger Hellinger
@holger@hellinger.wtf replied  ·  activity timestamp 4 hours ago

@neil Security by Obscurity

  • Copy link
  • Flag this comment
  • Block
ScriptFanix ❤️ ⏚ ⸫
ScriptFanix ❤️ ⏚ ⸫
@ScriptFanix@maly.io replied  ·  activity timestamp 4 hours ago

@neil "You have an Adidas hat? I'm sorry but this taxi will not go anywhere until you take it of"
Just as stupid

  • Copy link
  • Flag this comment
  • Block
Alexa Devreux-Swift
Alexa Devreux-Swift
@alexadeswift@lgbtqia.space replied  ·  activity timestamp 4 hours ago

@neil

This really grips my shit! I bet they won't allow their app to run on flashed devices then, or even devices that are OEM but NOT stock Android!?

  • Copy link
  • Flag this comment
  • Block
Tats 🇬🇧🫖
Tats 🇬🇧🫖
@Tattooed_Mummy@beige.party replied  ·  activity timestamp 4 hours ago

@neil God. Mine would be too! That's an appalling reach of power

  • Copy link
  • Flag this comment
  • Block
Arapalla
Arapalla
@Arapalla@aus.social replied  ·  activity timestamp 4 hours ago

@neil

I don't have very many apps on my phone at all.
If companies need to interact with me it's through the website.

Apparently I'm a weirdo. 🤪

  • Copy link
  • Flag this comment
  • Block
Simon Greenwood
Simon Greenwood
@simon@gotosocial.grnwds.uk replied  ·  activity timestamp 4 hours ago

@neil I'm surprised that's got past Graphene's devs. I don't have Bitwarden on F-Droid so I assume you have it as a repo?

  • Copy link
  • Flag this comment
  • Block
vepř jako pepř
vepř jako pepř
@vepr_jako_pepr@mastodon.social replied  ·  activity timestamp 4 hours ago

@neil if apps become the only way to online bank, with web interfaces replaced, I ask for people to quickly join me in a boycott of those banks by transferring funds to the best bank that offers a web interface, thank you

  • Copy link
  • Flag this comment
  • Block
FKA ZOG
FKA ZOG
@zog@jauntygoat.net replied  ·  activity timestamp 4 hours ago

@neil we gave HSBC Australia (used by my partner) the flick for similar idiocy.
Plus their crappy app can't even do an street address change without erroring out badly.

  • Copy link
  • Flag this comment
  • Block
thewinduppirate
thewinduppirate
@thewinduppirate@layer8.space replied  ·  activity timestamp 4 hours ago

@neil Jeez... I started moving away from HSBC a little while ago 'coz other silly shenanigans but this will make me finish jumping ship if / when it hits me. (No warnings about Bitwarden here, for now...)

  • Copy link
  • Flag this comment
  • Block
Rogan Dawes
Rogan Dawes
@RoganDawes@infosec.exchange replied  ·  activity timestamp 4 hours ago

@neil for a different perspective:

There is a scam going around, targeting Android phones, that involves convincing the custom to install a side-loaded app, and grant it all of the accessibility privileges that would allow it to operate your phone in the background while showing you something completely different.

This has resulted in significant financial losses for victims and/or their banks. Net result is that the banks are trying to detect sideloaded apps and warn/refuse to operate if any are present.

Seems like there is collateral damage due to this particular implementation. Providing feedback to your bank may be a productive thing to do in this case.

  • Copy link
  • Flag this comment
  • Block
Ronan
Ronan
@ronanmcd@mastodon.green replied  ·  activity timestamp 4 hours ago

@neil the Hollow Sword Blade Company. They did not play a sympathetic role in Irish history: https://en.wikipedia.org/wiki/Hollow_Sword_Blade_Company

Hollow Sword Blade Company - Wikipedia

  • Copy link
  • Flag this comment
  • Block
Lozz
Lozz
@lozz@hostux.social replied  ·  activity timestamp 4 hours ago

@neil Yeah, an idiotic decision from HSBC. Creating and using a separate Android profile just for the HSBC app is the way forward. Since it's pretty easy to switch profile, it's a minor inconvenience...

  • Copy link
  • Flag this comment
  • Block
:debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse:
:debian: 𝚜𝚎𝚕𝚎𝚊 :opensuse:
@selea@social.linux.pizza replied  ·  activity timestamp 4 hours ago

@neil

This is disturbing

  • Copy link
  • Flag this comment
  • Block
F. Maury ⏚
F. Maury ⏚
@x_cli@infosec.exchange replied  ·  activity timestamp 5 hours ago

@neil Sooo "random app can scan my device and learn what is installed on it, and how it was installed", heh?
How about no?
Also, fuck HSBC.

  • Copy link
  • Flag this comment
  • Block
flux
flux
@flux@mastodon.unwi.re replied  ·  activity timestamp 5 hours ago

@neil total insanity, but unfortunately the trend with commercial entities, to have overzealous IT security staff who don't understand security or the impact of the policies they implement 🤮

  • Copy link
  • Flag this comment
  • Block
Henryk Plötz
Henryk Plötz
@henryk@chaos.social replied  ·  activity timestamp 5 hours ago

@neil Also, I'd be interested to hear their justification (chances are they have none). Because, yes, people disabling Android protections and installing malware because they got phished into "upgrading their security" is a thing.
But then either: the malware bypasses the HSBC security somehow. Then the screen is not doing anything.
Or: it doesn't, and the screen could show something like "you may continue, but make sure you know what you're doing; we certainly didn't ask for it" and be fine.

  • Copy link
  • Flag this comment
  • Block
Mike 🇬🇧 🇪🇺
Mike 🇬🇧 🇪🇺
@MikeFromLFE@cupoftea.social replied  ·  activity timestamp 5 hours ago

@neil It also gets hissy at certain Android keyboards even if installed using Play Store.

It's even stranger because the HSBC App does this, but the First Direct app is sensible - they are very similar in many other respects.

  • Copy link
  • Flag this comment
  • Block
markus
markus
@markus@toot.orchid-cottage.uk replied  ·  activity timestamp 5 hours ago
@neil the fact alone that they can go round seeing what else you're doing with your device is quite bad, isn't it?
  • Copy link
  • Flag this comment
  • Block
SamuelJohnson
SamuelJohnson
@samueljohnson@mstdn.social replied  ·  activity timestamp 5 hours ago

@neil As a matter of interest what's your solution for sharing links/text between devices?

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 4 hours ago

@samueljohnson

KDE Connect.

  • Copy link
  • Flag this comment
  • Block
Benjohn
Benjohn
@benjohn@todon.nl replied  ·  activity timestamp 5 hours ago

@neil 👍 can I make a further recommendation to change to another bank entirely? We _finally_ dumped HSBC earlier this year and switched to Nationwide. The switch genuinely is really very easy.

The only things that don’t transfer automatically are merchants that hold your card details and take payments from them - they also need updating if you are issued a new card though.

Very pleased with Nationwide so far. Very old school bank, but the app is far better than HSBC’s. Eg, more than a month of search history has sold it for me! They also *gasp* pay interest! And actually seem to value their customers.

  • Copy link
  • Flag this comment
  • Block
Matt
Matt
@matt@oslo.town replied  ·  activity timestamp 5 hours ago

@benjohn I remember joining Nationwide as a teen. Disappointed to see they got rid of this beautiful logo for more "modern" one:

An old Nationwide UK logo. A white serif wordmark on a blue background with a red bar at the bottom and a white outline of a house and sun to the left.
An old Nationwide UK logo. A white serif wordmark on a blue background with a red bar at the bottom and a white outline of a house and sun to the left.
An old Nationwide UK logo. A white serif wordmark on a blue background with a red bar at the bottom and a white outline of a house and sun to the left.
  • Copy link
  • Flag this comment
  • Block
Colin the Mathmo
Colin the Mathmo
@ColinTheMathmo@mathstodon.xyz replied  ·  activity timestamp 5 hours ago

@neil They will continue with this nonsense until there is sufficient push-back against it.

Are you going to write them a formal letter informing them or your choice and their idiocy?

  • Copy link
  • Flag this comment
  • Block
Pierric
Pierric
@PierricD@mastodon.green replied  ·  activity timestamp 5 hours ago

@neil what the f...??? Security apps compromise security now?? I'd change banks just over the garbage statement this makes.

Like others I'm also wondering how an app is allowed to see the list of other apps unless specifically allowed to do so. In any android really. It *is* true that for some use cases like using macro droid or similar apps it helps to list the other apps's "intents". But this should be a specific permission, not required by a banking app?

  • Copy link
  • Flag this comment
  • Block
Dr Ro Smith
Dr Ro Smith
@Rhube@wandering.shop replied  ·  activity timestamp 5 hours ago

@neil D-: the notion of 'unofficial' app stores is downright strange. Who officiated Google Play?

  • Copy link
  • Flag this comment
  • Block
Dr Ro Smith
Dr Ro Smith
@Rhube@wandering.shop replied  ·  activity timestamp 4 hours ago

@neil No one has critiqued me on this, but I knew when writing it that 'officiated' is not the right word in this context. I thought it would be funny, but the need to express that I know it's incorrect was too much 😅

  • Copy link
  • Flag this comment
  • Block
Gerrit Niezen
Gerrit Niezen
@gendor@merveilles.town replied  ·  activity timestamp 5 hours ago

@neil don't you need the app to login to their website?

  • Copy link
  • Flag this comment
  • Block
Gavin
Gavin
@_calmdowndear@mastodon.social replied  ·  activity timestamp 5 hours ago

@neil isn’t the wording of that “we don’t like app stores” rather than it being because of Bitwarden though? Or are you saying you have other things installed via F-Droid that aren’t flagged?

  • Copy link
  • Flag this comment
  • Block
Neil Brown
Neil Brown
@neil@mastodon.neilzone.co.uk replied  ·  activity timestamp 5 hours ago

@_calmdowndear

> Or are you saying you have other things installed via F-Droid that aren’t flagged?

Yep, loads of things via F-Droid.

  • Copy link
  • Flag this comment
  • Block
Simon Zerafa
Simon Zerafa
@simonzerafa@infosec.exchange replied  ·  activity timestamp 5 hours ago

@neil

Is it looking more for the ability to sideload apps rather than the presence of FDroid?

I've just transferred from a Pixel 8 to a 9a and that particular banking app transferred fairly painlessly.

I did wonder if a non Android OS gives issues if I should bother with moving to a different one on the Pixel 8 😥

  • Copy link
  • Flag this comment
  • Block
LionelB
LionelB
@lionelb@expressional.social replied  ·  activity timestamp 5 hours ago

@neil

Triodos Bank excellent and they are trying to build a degoogled app.

  • Copy link
  • Flag this comment
  • Block
Ariel (🐿 arc)
Ariel (🐿 arc)
@arichtman@eigenmagic.net replied  ·  activity timestamp 5 hours ago

@neil you might be able to work around it using profiles. I haven't investigated much but it seems like some isolation between sets of installed apps

  • Copy link
  • Flag this comment
  • Block
Thibaultmol 🌈
Thibaultmol 🌈
@thibaultmol@en.osm.town replied  ·  activity timestamp 5 hours ago

@neil the logical assumption then is that HSBC themselves don't use password managers internally.... YIKES
/s

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct