Preferences

EMIRELADERO parent
So that's it then.

If this actually goes through, there will be no option in the mobile OS market for an OS that both:

a) allows the installation of apps without any contractual relationship with any party, and

b) allows the use of mainstream and secure apps like banking


CalRobert
In time, you will only be able to access banking from your desktop using an approved OS and browser with attestation...
ffsm8
For what conceivable reason would they make the users go on desktop, considering mobile is in the process of being fully locked down?

If anything, they'd eventually deny access from desktop, forcing everyone to login via the fully manages mobile devices without any user freedom.

Some banks are already getting there btw, as their preferred 2fa is a companion app... One small step away from making that the only option, effectively denying access to anyone without a locked down mobile device.

crvdgc
A recent real life example:

You can apply for an HSBC Global Money Account if you have: […] The HSBC UK Mobile Banking app (Global Money is only available via the app)

From https://www.hsbc.co.uk/current-accounts/products/global-mone...

homebrewer
It's already that way in my country. The few banks that still have the web version only support it for their business clients, and it's only something like two or three banks. If you're a regular client, there's not a single bank left that you can still use without a smartphone (unless you're ready to visit a branch for every little thing — so pretty much daily).
sznio
>(unless you're ready to visit a branch for every little thing — so pretty much daily).

What are you doing that you need to use your banking app daily?

It seems like a once a month affair. Pay the bills, take some cash out of the account, and you're done. Online shopping just needs a credit card, no apps required.

callc
Since most every transaction is digitalized, checking banking app is the same as looking in your wallet.

Any limitations to access to banking is serious f**ed. Makes me want to use cash.

xigoi
> Online shopping just needs a credit card, no apps required.

The app is required for two-factor authentication.

JoshStrobl
I'm not aware of your circumstances, but at least here in Finland I was able to get (and the bank was required to provide at my request) a cheap 2FA token generator device that can be used instead of the app (Danske ID). It works whether I am confirming an online transaction or signing into a service that uses the Suomi.fi centralized login system.

I requested it after they updated their Android app to have a check for pin-code enablement. Sailfish OS doesn't report it via the Android AppSupport system, so it was blocked before I grabbed an older build via Aurora and disabled it from updating. If it ever stops working, I'll only use the token. Once that stops working, I will switch banks.

ryandrake
My bank’s app doesn’t even work or even install on my phone because the bank considers my phone too old. So if they suddenly required the app to log in, I simply wouldn’t be able to bank with them. So they would lose my checking, investment, and HSA business when I move to another bank.
saurik
I think they worded that poorly, but didn't mean what you got from it: the point I'd take isn't that they will require you to have a desktop, but that even desktop will also have the same restrictions, so it isn't just a mobile problem.
ffsm8
I see, that makes sense in hindsight.

And I have to agree, sadly. We've been inching towards that over the years, and it's entirely possible banks cease providing regular web access to their accounts (which this would necessitate).

But I think there will always be at least some banks that will have web frontend, so you'll just have to be pickier.

green7ea
This happened to me recently in Austria, I had to get a new phone to be able to do internet banking. You can only use the app with attestation from the PlayStore, AppStore or surprisingly Huawai store.

When I complained repeately that this was forcing me into an American or Chinese ecosystem, they said that no one cares and I'm a minority :-(.

For the desktop, you need the phone for the 2FA.

blendergeek
What gp is saying is that to access banking form desktop will require an approved OS and attestation just like on mobile. The current state of affairs is that an approved OS and attestation are only required on mobile but not on desktop
dariosalvi78
most banks require 2FA or similar to confirm logins and operations. There is no way around it, this is the world we are heading towards: 2 companies in the entire planet decide who and what can be done online.
slyzmud
Actually my bank already requires me to use the phone app for any operation on the website. When I want to login from my laptop I need to use my phone with their app to approve the login, same for almost any operation.

Ah, and it can only be installed in one device at the same time :D Don't have your phone available? Bad luck for you

BLKNSLVR
> can only be installed in one device at the same time

I neither like nor understand this restriction. It makes device failure / loss / theft a much more difficult experience to recover from than it would otherwise be. The device should be throwaway. I specifically keep old phones in case something happens to the new one.

WhatsApp is probably the stupidest example of only being able to be on a single device (but I'm forced to use WhatsApp for one specific purpose, so I already resent it). Signal does the same thing, so maybe it's related to the E2EE that WhatsApp licensed from Signal...

sznio
>WhatsApp is probably the stupidest example of only being able to be on a single device

that's not really an artificial limitation but a design choice. They don't store your messages, only deliver them. Once the message is on your device, it's gone from their servers, like old POP3 mail.

xigoi
You think Meta would pass up an opportunity to harvest data from users?
gausswho
I use the Signal fork Molly to get messages on multiple phones. One remains the primary and the others linked, but I get messages even if the primary is off.
jollyllama
> It makes device failure / loss / theft a much more difficult experience to recover from than it would otherwise be.

As is with all two factor, but don't point that out, or the "but muh security" bros will shout you down.

BLKNSLVR
The authenticator app that I use for most 2FA can be on multiple devices, and you can export and import some or all of the entries, password protected.

I would be extremely F'd if my 2FA was able to be lost or stolen due to a single device limitation.

al_borland
I have a huge problem with companies using their own apps for 2FA.

Google started doing this for Gmail. To use Gmail on my laptop, I need to approve it with Gmail on my phone. I never signed up for this. I’m now afraid if I delete the Gmail app from my phone that I’ll lose access to my email.

I hate the direction “security” is taking us. It’s done in the name of security, but it feels more like blackmail to get and keep the company app on your phone.

c-hendricks
Is that a thing Google logins can be set to require? I _can_ use the Gmail app on a device for 2FA, I can also press "try another method" and use any 2FA app.
al_borland
I guess I’ll have to look. It just started happening one day.

One huge fear I have no is breaking my phone while away from home and getting locked out of everything.

I was on vacation several years ago and broke my phone (the only time I’ve ever done that), and got lucky in several ways. I had a 2nd work phone with me. I was able to use that to call an Uber to get to an Apple Store; I was lucky to be in a city with an Apple Store. Then I got lucky again that I was able to talk Apple into giving me a replacement right there instead of a repair, they happened to have a single phone in stock to do that with. Then I got lucky yet again when I went to set it up, because I had an iPad with me by dumb luck, which was able to do my Apple 2FA that I didn’t sign up for.

If I go somewhere with just my 1 phone and no second device… I’m thinking I need to setup and bring a bunch of recovery codes, which has its own risks. My plan would be to cryptically write them down and put them in a money belt, as if those got into the wrong hands I’d be screwed.

I really don’t know what people do who only have a phone and nothing else. It seems they would always have this risk.

i do like how many apps are starting to play nice with 3rd party authenticators. i use ms authenticator for a bunch of things. Although knowing MS it has some massive license fee for them to support.
tgsovlerkhgsel
De facto, this is already the case - you can use your computer as a display but to actually authorize a login or transaction you need your phone with said attestation.
arp242
Not true for either my AIB or Wise account.
zeta0134
True for PayPal though. I just recently had to jump through seven different hoops to verify my ID (with creepy, creepy face scans) and they absolutely refused to even start the process on desktop. Eventually got the stupid thing to work on my iPad; Android+Firefox was a no go, and it's stock Pixel 5a with Google OS.

Thankfully I don't actually rely on PayPal for anything serious, but there are artists whose commission I like to pay, and being able to actually pay them would be nice. :/

int_19h
For logins, at least, they support passkeys on the desktop as well, so long as the browser does it. Which basically means Win11 or macOS, either some Blink-based browser or Safari.
redrblackr
I use my yubikey on both my android and linux (tumbleweed) with exclusively firefox, I have not found something that does not work.. Maybe you mean non-hardware passkeys built into the os? But one could just use keepassxc or like bitwarden, those work in Firefox and Linux as well
arp242
I mean, I'm sure it's true for some banks or financial services, but that's not really the same thing.
CalRobert
Does AIB still give out hardware 2fa code generators? I liked having it not tied to a phone.
arp242
Yes, you need to specifically ask for it, but you can get them and it works. I got mine last year.
Night_Thastus
A dedicated app on a locked down OS is vastly more controllable than something like a browser that can do virtually whatever it wants.
tremon
Controllable by whom? I don't do any banking on my phone exactly because I don't trust my phone to keep anything I do on my phone private.
Gigachad
How it generally works iso low risk operations have no restrictions, but if you want to send a large amount of money to a new contact, the banks make you approve the transaction on the phone app.

Phone apps are generally significantly more trusted because of the fact you can’t install malware that steals the session token, and they can do a Face ID check before any risky operations.

prism56
I'll just have to disable it and choose a banking app that works on the browser. Tonnes of my apps are sideloaded. Quite a few are on the playstore or the dev might upload their details.
safety1st
Is it confirmed that we will even be able to disable this?
rbits
Worst comes to worse you can install something like GrapheneOS (assuming your device has an unlockable bootloader)
safety1st
Will my banking apps lock me out if I do that? Will any other apps?
trallnag
How will you login to the banking app in the browser without a locked down phone? In Germany, MFA is enforced and with many banks the only allowed second factor is an app on a phone.
rbits
Time to find an old second hand phone if you live in Germany, I guess. And start pirating Netflix shows that you want to watch on your phone.
ACCount37
Banking apps were at the forefront of freedom-eroding "safety" for a long time now.

This item has no comments currently.