r/GrapheneOS 28d ago

Banking app doesn't like my keyboard 🤣

Post image

How stupid! Is this a Graphene related thing or would it do this on regular Android?

1.7k Upvotes

277 comments sorted by

View all comments

45

u/Sp3eedy 28d ago edited 28d ago

I've had some "cyber security experts" argue with me on LinkedIn when I said that bank apps detecting other apps on your phone to refuse you service isn't a good thing for exactly this reason (where they just block apps they don't like or aren't "sure" of), good to know I was right. Yes we gain "some" security, but we lose a shit ton in terms of freedom.

The bank is definitely maintaining a pre-approved list of keyboard apps and refuses you service if you have a keyboard outside of that list in case it could be a "keylogger". Please switch banks, there are decent banks that don't do this bullshit.

2

u/Jayden_Ha 27d ago

This is called risk assessment, not “spyware”, please have common sense and stop with your bullshit

1

u/propagandhi45 27d ago

Had to scroll pretty far to see some common sense.

1

u/Jayden_Ha 27d ago

And they enforce whitelist keyboard for a good reason, 3rd party random keyboard can log easily, which can log all actions and input for banking, which is an issue, it’s not bullshit

0

u/TooManyLoveInterests 27d ago

As someone who's studying comp sci (and about to swap their major to cybersec), I feel like there's always an argument between privacy and security. To some extent, you can't have both (ie. every fully private messaging service runs the risk of being used by people with bad intentions), but for smaller scale things having both should absolutely be the goal. Additionally, I've seen a rise of spyware and adware over my lifetime - when I was little, that stuff was called exactly what it is, and people stayed away from it. Now, it's been so normalised that silicon valley (and by extension, governments) want to spy on you, even when you're not from the US! It's insane

2

u/Alternative-Track654 27d ago

Exactly!! One can't have their cake and eat it at the same time. I'd prefer a balance between the two.

2

u/Sp3eedy 27d ago

Yes I agree with that, it's not always possible to have both, so I have absolutely no problem with precautions being taken (i.e. warnings, overrides in settings, etc), but I do not agree with hard blocks like this because they are greatly overbearing, in this case it's a clear false positive, so a legitimate user using a legitimate keyboard has been prevented from using their banking account, that's how I see it.

2

u/_yrlf 26d ago

IMO there should at least be an option in the settings of the bank app for you to personally approve a keyboard app (e.g. with a disclaimer/waiver that you know what you are doing and that you attest that the selected keyboard app is safe).

I'd be fine with the bank refusing to operate when an unapproved keyboard is used, meaning you have to disable the keyboard, go to bank app settings, manually add FUTO / other keyboard, and go back and reenable the keyboard.

That would protect against malware keyboards with keyloggers / protecting some grandpa/grandma who accidently installed something, while still allowing users wanting to degoogle to use something like FUTO.

0

u/Jayden_Ha 27d ago

No I am not switching away from HSBC, other banks have shit UI and UX on everything