zlacker

[parent] [thread] 22 comments
1. ulrikr+(OP)[view] [source] 2025-08-26 13:35:40
Thats ... false. Every bank I have used in Denmark allows me to log in and do all operations without an app. They require authentication and authorization using the national digital identity (MitID) which comes as an app, but also as a TOTP token and a FIDO (or similar) chip. No apps needed.

I guess the smartcard reader is equivalent. But my point is that locking down the OS of the phone is sufficient to establish client trust but not necessary. You should always be allowed to run the app without strong Play Integrity verification but then just be required to scan your hardware token with NFC in every authentication and authorization flow.

replies(3): >>mike_h+y >>termin+73 >>gnagat+9b
2. mike_h+y[view] [source] 2025-08-26 13:38:22
>>ulrikr+(OP)
That's exactly what I'm saying. They don't let you take actions using only a web browser. If you don't use a mobile app they issue you with trusted hardware that performs a similar function (although usually less secure and not as convenient).

My bank does still allow login and txns to be authorized with a smart card reader. You have to type in fragments of the account number to authorize a new recipient. After that you can send additional transactions to that account without hardware auth.

Pure NFC tokens don't work because you need trusted IO.

replies(2): >>ulrikr+B2 >>niutec+L7
◧◩
3. ulrikr+B2[view] [source] [discussion] 2025-08-26 13:47:22
>>mike_h+y
Alright, I think I misunderstood you. I know most banks allow alternatives other than the app.

But just the fact that there are options which have the side effect of making you choose between convenience and digital autonomy is wrong, and I don't think remote attestation should even exist in the toolbox. We should make dedicated hardware solutions work better instead.

replies(1): >>mike_h+Of
4. termin+73[view] [source] 2025-08-26 13:49:55
>>ulrikr+(OP)
In the US too. I have never ran into a situation where I had to use the app instead of the browser. I don't know what that guy is talking about.
replies(2): >>fricki+t6 >>vbezhe+eO
◧◩
5. fricki+t6[view] [source] [discussion] 2025-08-26 14:04:18
>>termin+73
My US bank removed check deposits from the browser about a decade ago, and I haven't met anyone who can use Zelle without an app.
replies(3): >>hiatus+Ja >>termin+4b >>snark4+uE
◧◩
6. niutec+L7[view] [source] [discussion] 2025-08-26 14:10:47
>>mike_h+y
Not necessarily. In Poland you can do banking with a web browser + SMS code or one-time code card, no special hardware needed.
replies(1): >>mike_h+Te
◧◩◪
7. hiatus+Ja[view] [source] [discussion] 2025-08-26 14:26:48
>>fricki+t6
That is a far cry from the original comment "banks have never accepted browsers".
◧◩◪
8. termin+4b[view] [source] [discussion] 2025-08-26 14:28:53
>>fricki+t6
I have used zelle many times from the browser. It's been a while, so maybe that has changed, though. I never even tried to deposit a check from the browser or an app, so you may be right on that point.
9. gnagat+9b[view] [source] 2025-08-26 14:29:13
>>ulrikr+(OP)
That's mostly prevalent in third-world countries like Brazil. I work for a fintech-turned-bank here and the biggest problem we have to deal with is fraudulent actions made by scammers who got access to users' accounts via social engineering. Outsiders don't know how prevalent scamming is in Brazil and how much is spent/lost trying to fight them and how that shapes the security vs convenience landscape. For example:

- I can't transfer a single cent if I didn't had my face and documents scanned after installing the bank app.

- I can't have the same bank account logged in two of my devices at the same time, all banks require you to use an account on a "verified" device (previous point).

- If I want to use a desktop to access my bank account, I have to either install a desktop client provided by the bank or be limited to just checking my balance. Some banks doesn't even allow you to log in if you don't have a "verified" device for doing 2FA.

I am very sure my higher ups are cheering with these news, even though it solves none of the problems.

◧◩◪
10. mike_h+Te[view] [source] [discussion] 2025-08-26 14:45:04
>>niutec+L7
An SMS code can only be received by a phone (special hardware, not a browser). An OTC smart card is likewise special hardware, not a browser.
replies(1): >>kortil+ri
◧◩◪
11. mike_h+Of[view] [source] [discussion] 2025-08-26 14:48:53
>>ulrikr+B2
Dedicated hardware solutions are remote attestation. The smartcard OTC readers are doing exactly that: you sign a challenge with a private key that never leaves the smartcard and is paired to the bank at the factory. This is what remote attestation is doing behind the scenes, the only difference is the smartcard user interaction is much more limited. It's of no use for protecting your financial privacy, for example, only for stopping a hacked display device authorizing transactions.

If you evolve the smartcard based systems with better I/O capabilities, then you end up with a modern smartphone. At which point you may as well let the user supply their own rather than charging them lots of money for a dedicated device that's not much different.

replies(1): >>ulrikr+Ym
◧◩◪◨
12. kortil+ri[view] [source] [discussion] 2025-08-26 14:57:40
>>mike_h+Te
Google voice is not special hardware. You’re confusing attestation with 2fa and that’s why you’re getting downvoted.
replies(1): >>mike_h+Qk
◧◩◪◨⬒
13. mike_h+Qk[view] [source] [discussion] 2025-08-26 15:07:44
>>kortil+ri
Yeah but Google Voice isn't something you're meant to use to receive SMS codes. That's very US specific, and if you go there you've undermined the security the bank was trying to provide.

The reason they used SMS codes for a while is because phones have always tried to block malware from reading your screen or SMS storage whereas PCs don't, and because phones can do remote attestation protocols to the network as part of their login sequence. The SIM card contains keys used to sign challenges, and the network only allows authorized radio firmwares to log on. So by sending a code to a phone you have some cryptographic assurance that it was received by the right user and viewed only by them.

2FA and RA are closely related for that reason. The second factor is dedicated hardware which enforces that only a human can interact with it, and which can prove its identity cryptographically to a remote server. The mobile switching center, in the case of SMS codes.

Obviously, this was a very crude system because malware on the PC could intercept the login after the user authorized, but at least it stopped usage of the account when the user wasn't around. Modern app based systems are much more secure.

replies(2): >>Shroud+BH >>kortil+F1p
◧◩◪◨
14. ulrikr+Ym[view] [source] [discussion] 2025-08-26 15:16:30
>>mike_h+Of
No, I reject the idea that general purpose computing devices should be locked down to satisfy a very narrow security use case. I really don't believe that you end up with a smartphone, and I don't think you give a very good argument for why.

I am fine with locking down devices that have very limited security purposes. I am fine with my passport containing locked down hardware if it makes it harder to forge. But I am also not browsing the web on my passport, and therefore its security requirements cannot prevent me from removing ads.

replies(1): >>mike_h+Jy
◧◩◪◨⬒
15. mike_h+Jy[view] [source] [discussion] 2025-08-26 16:09:46
>>ulrikr+Ym
OK, use a browser that lets you remove ads then! Android isn't iOS, you can run browsers that aren't Chrome and nothing about this change would stop you installing a custom browser with whatever features you want. Your banking app doesn't care what browser you use.
replies(1): >>ulrikr+9F
◧◩◪
16. snark4+uE[view] [source] [discussion] 2025-08-26 16:32:31
>>fricki+t6
I have 3 different banks (well 2 banks and a credit union.) I can use Zelle in my browser from all 3. I don't even have the app installed for 2 of them.
replies(1): >>fricki+YQ
◧◩◪◨⬒⬓
17. ulrikr+9F[view] [source] [discussion] 2025-08-26 16:34:46
>>mike_h+Jy
You are fundamentally misunderstanding my point about freedom.

Yes, I can do it now, but this is only because Google allows me to do that on their approved Android distribution, not because they are unable to prevent me from doing it. I don't trust them to not take away that freedom from me as soon as they can be sure that they can afford the anti-trust lawsuit since their core business model is to show me ads.

I know that my bank doesn't care about my browser, but by relying on Play Integrity they are indirectly forcing me to operate in Google's control regime in every other aspect on my device.

I don't want them to control my software stack, period. I don't care if they act as the good guys right now, they have been steadily doing downhill in the moral department and I expect them to continue to do so.

I don't understand how you can act like there is no problem at all with technology like this.

◧◩◪◨⬒⬓
18. Shroud+BH[view] [source] [discussion] 2025-08-26 16:45:21
>>mike_h+Qk
The SMS stuff seems like theatre when SS7[1] has been known to need a nuclear-powered auto bailer for how porous it is.

[1] https://en.wikipedia.org/wiki/Signalling_System_No._7

replies(1): >>mike_h+BG2
◧◩
19. vbezhe+eO[view] [source] [discussion] 2025-08-26 17:12:14
>>termin+73
In my country almost all banks removed their web apps. They existed like 15 years ago, before smartphones became widespread, but nowadays very few banks offer web apps, only mobile apps.
◧◩◪◨
20. fricki+YQ[view] [source] [discussion] 2025-08-26 17:27:02
>>snark4+uE
Hmm...I wonder if it matters which browser is being used.
◧◩◪◨⬒⬓⬔
21. mike_h+BG2[view] [source] [discussion] 2025-08-27 07:52:46
>>Shroud+BH
... which is why none of the banks I've used support it for many years now. It's a legacy example. Modern banks all rely on apps that bind to the secure element in the phone or they issue a smartcard reader.
replies(1): >>niutec+sfc
◧◩◪◨⬒⬓⬔⧯
22. niutec+sfc[view] [source] [discussion] 2025-08-30 10:15:09
>>mike_h+BG2
Not all modern banks, e.g. Santander Bank in Poland still uses one-time SMS codes.
◧◩◪◨⬒⬓
23. kortil+F1p[view] [source] [discussion] 2025-09-04 01:48:45
>>mike_h+Qk
Don’t know what to tell you dude but you’re really out of touch on this one. Anyone with osx and iPhone also gets text messages on their laptops.
[go to top]