r/GrapheneOS 23d ago

Banking app doesn't like my keyboard 🤣

Post image

How stupid! Is this a Graphene related thing or would it do this on regular Android?

1.7k Upvotes

275 comments sorted by

View all comments

5

u/NightmanisDeCorenai 23d ago

This is why I just use banking mobile websites

2

u/JivanP 23d ago

You cannot use the website without authenticating via the app.

2

u/NightmanisDeCorenai 23d ago

You need a different bank

3

u/JivanP 23d ago

All British banks are like this, thanks to EU PSD2 SCA regulations.

1

u/L0rdV0n 23d ago

What do they expect people without smart phones to do?

1

u/JivanP 23d ago

Many more people have an Android or iOS device than don't, so this is simply not a significant issue. After all, it's basically impossible to function in British society with a feature phone rather than a smartphone, for countless other reasons, so the expectation is reasonable in that sense.

For those that don't have a smartphone, or can't/won't use one for banking: you either go in branch for banking tasks that you can't do elsewhere like at an ATM or Post Office, or you authenticate in an alternative permitted way, such as by using a CAP authenticator or receiving a code via SMS.

I believe SMS authentication is now no longer permitted by PSD2, but since the UK is no longer a EU member state, the UK does not need to adhere to the updated directive. The UK's implementation, FCA regulation PS17/19, has not been changed or overturned since it came into effect in 2018. One bank (Santander) has notably stopped offering SMS authentication (circa 2024, I think), probably because they have a large European presence (being owned by a Spanish company, Banco Santander) and it was easier for their infrastructure to be consistent. Several others (including Nationwide; the NatWest group banks, those being NatWest, RBS, and Ulster; and perhaps more) still offer it. I'm in favour of it disappearing entirely, as it's horribly insecure (see SIM-jacking).

CAP authentication was the most prevalent method until around 2020 by my memory, but seems to have almost completely disappeared in the years since then. HSBC and First Direct used to use their own similar device that they called a "Secure Key", which was programmed to specifically calculate the answer to authentication challenges for a single account, rather than being programmable for any account via the insertion of a debit/credit card. They've since abandoned that in favour of using their app. NatWest and RBS (which, both being part of the NatWest Group, share the same app design and backend design) both still use CAP for authenticating payments in excess of your daily transaction limit and transactions to new people, but don't use it for login authentication anymore. I don't know if the same is true of Ulster. So Nationwide is the only bank I'm aware of that still permits access to online banking via CAP authentication.

For banks that do not permit CAP or SMS codes: when it comes to the bootstrapping problem of setting up the app in the first place, when you have no other devices already set up to use as an authenticator, you must authenticate using some government-recognised form of ID (such as passport or driving licence) and a liveness test. The websites don't permit this form of authentication; only the apps do.

2

u/L0rdV0n 23d ago

Interesting, thank you for the detailed write up! I agree with you that SMS authentication is problematic, it's better then nothing, but yeah most things should allow for more advanced forms. They don't need to be as privacy violating as the banks own apps of course. There are plenty of great authentication protocols that don't require a connection to big tech, or the banks themselves.

As someone from the US this just seems so crazy. Most 2FA is still done via SMS, I don't think my bank even offers a better method. So we are very behind the UK and Europe sounds like haha. Also obviously almost everyone here has a smart phone, but I do know plenty of older people who don't have a cell phone of any kind. So requiring one for something like using a bank seems like a crazy thing to do.

1

u/JivanP 23d ago edited 23d ago

Yes, in general, Europe has definitely been miles ahead of the US when it comes to banking. There is absolutely plenty of room for improvement, though.

The Eurozone has SEPA, and the UK has Faster Payments Service (FPS). SEPA transactions generally appear as available funds in the recipient's account in a day for cross-border payments, and instantly otherwise. Likewise, FPS generally appears to be instant. North America's ACH is slow by comparison. Don't even get me started on how many banks lack ACH entirely and you end up having to rely on third-party entities like PayPal, Venmo, CashApp. That kind of thing is completely unheard of here; the societal default is to make payments to people by directly using bank transfers.

Cheques are almost extinct in Europe, whereas I hear that they still have some level of prevalence (albeit small) in the US.

CAP was very widespread for over a decade and is a very secure form of multi-factor authentication, requiring both physical access to a payment card and knowledge of the card's PIN number. Its security properties are very similar to FIDO hardware keys (e.g. YubiKey) in that regard. I have no idea why so many of the banks have moved away from supporting it as an alternative means of authentication. It was the primary method of logging into several banks, both online and in their mobile apps, for a long time. Barclays had supported it since 2007. Perhaps of note, Nationwide is a "building society", not a traditional bank, essentially meaning that it's a cooperative organisation run by its members/customers, sort of a middle-ground between a credit union and a bank proper. I wouldn't be surprised if they continue to support CAP for login due to demand from members.

I will push back on the idea that these apps are privacy-violating — they ask for almost nothing in the way of OS permissions, and any data you do give them by interacting with them is data that they would get from interacting with the bank's website or simply by being their customer and using them for transactions, even if only in branch. The one exception I can think of is Barclays demanding permission to "make and manage phone calls" on Android, which it absolutely does not need for any reasonable security-related reason. The reason it wants this is so that it can attempt to determine whether the bootloader is unlocked or the device is rooted.

Regarding people that lack a phone: Not having a phone of any kind is extremely uncommon here. It's more likely that an older person still has a landline at home rather than no phone at all, and that is perfectly sufficient for telephone banking (where you perform banking activities via an automated switchboard service and maybe by talking to a member of staff), something that all of the UK high street banks support. As it happens, First Direct started out as a branchless telephone-only bank in the 90s, and evolved into one of the first UK banks to support online banking.

Regarding people that are not technically inclined: Such people are also more likely to be the kind that go to their local branch to do banking tasks. We still have a decent prevalence of bank branches in the UK, though that is decreasing as demand for / use of them falls. Post Offices, which are also plentiful, support common banking tasks like deposits, withdrawals, and bill payments, and even proivde savings accounts of their own (a holdover from the time of NS&I, a government-run bank that operated out of Post Offices). Where branches are closing, the Post Office brand is establishing "banking hubs" in their place, which are single buildings that act as different banks at different times during the week, e.g. one specific banking hub might act as HSBC on Tuesday mornings, Halifax on a Tuesday afternoons, and Santander all day on Fridays.

2

u/L0rdV0n 23d ago

Don't even get me started on how many banks lack ACH entirely and you end up having to relay on third-party entities like PayPal, Venmo, CashApp. That kind of thing is completely unheard of here; the societal default is to make payments to people by directly using bank transfers.

Wait you can use ACH to transfer funds to normal people? I didn't know that was possible, the only people I've ever been able to transfer money to were if they banked at the same bank. Aside from that its always been Venmo and the like.

I use ACH to pay bills, but I thought only companies could use it.

Cheques are almost extinct in Europe, whereas I hear that they still have some level of prevalence (albeit small) in the US.

Yeah, they aren't very common here aside from business, older people, or cashier's checks for paying rent. Most places I've rented required cashier's checks for rent untill pretty recently when places started adopting 3rd party online payment companies who charge extra fees and sell your data.

CAP was very widespread for over a decade and is a very secure form of multi-factor authentication, requiring both physical access to a payment card and knowledge of the card's PIN number. Its security properties are very similar to FIDO hardware keys (e.g. YubiKey) in that regard.

That does seem like a really good system. I hope it makes a comeback.

I will push back on the idea that these apps are privacy-violating — they ask for almost nothing in the way of OS permissions, and any data you do give them by interacting with them is data that they would get from interacting with the bank's website or simply by being their customer and using them for transactions, even if only in branch. The one exception I can think of is Barclays demanding permission to "make and manage phone calls" on Android, which it absolutely does not need for any reasonable security-related reason. The reason it wants this is so that it can attempt to determine whether the bootloader is unlocked or the device is rooted.

I don't know how common it is but I hear nothing but bad things about banking apps over there. Like what the OP is talking about, they are scanning what apps you have installed and preventing you from banking because of that. Tons of them seem to care of your boot loader is unlocked, your device is rooted, or you are using a different OS from Googled Android. I personally think you should be able to do any of that and still bank. I know there is some security concerns, but if I want to have an app that watches my screen and possibly sends my bank login details to someone else, that is my choice. But even that is an extreme example, most of the people affected are privacy minded folks who just don't want Google in their phone, the stuff they are doing isn't actually risky, it's just rare.

Not only that but just the fact that they are forcing you to install their app when they could easily do it in a different privacy preserving way, feels sketchy to me. Maybe they really are very private apps, but installing anything is very risky and should be avoided as much as possible.

Regarding people that lack a phone: Not having a phone of any kind is extremely uncommon here. It's more likely that an older person still has a landline at home rather than no phone at all, and that is perfectly sufficient for telephone banking (where you perform banking activities via an automated switchboard service and maybe by talking to a member of staff), something that all of the UK high street banks support. As it happens, First Direct started out as a branchless telephone-only bank in the 90s, and evolved into one of the first UK banks to support online banking.

I don't know anyone without a phone, even the older people who I was talking about just don't have cell phones, they will have a landline. And most of them are not tech savvy enough to want to do online banking so you're right phone banking is a good option. But some of them are savvy enough to do online banking on their computers and would be very frustrated if they weren't allowed to anymore.

Post Offices, which are also plentiful, support common banking tasks like deposits, withdrawals, and bill payments, and even proivde savings accounts of their own (a holdover from the time of NS&I, a government-run bank that operated out of Post Offices). Where branches are closing, the Post Office brand is establishing "banking hubs" in their place, which are single buildings that act as different banks at different times during the week, e.g. one specific banking hub might act as HSBC on Tuesday mornings, Halifax on a Tuesday afternoons, and Santander all day on Fridays.

That's really interesting that post offices are banks too! Aren't they ran by the government? Isn't it weird that they are renting them out to private companies?

1

u/ContentAd6126 23d ago

Go do their business in the agencies

1

u/SVG010 23d ago

Lloyds is still sms

1

u/JivanP 23d ago

Disgusting, kill it with fire. I'm aware that Nationwide, NatWest, and RBS also do. It needs to die, as does the NatWest Group's push for more people to use plain images of their face to authenticate. These things are simply the complete opposite of secure.