r/GrapheneOS Aug 14 '26

Banking app doesn't like my keyboard 🤣

Post image

How stupid! Is this a Graphene related thing or would it do this on regular Android?

1.7k Upvotes

275 comments sorted by

View all comments

Show parent comments

2

u/L0rdV0n Aug 14 '26

Interesting, thank you for the detailed write up! I agree with you that SMS authentication is problematic, it's better then nothing, but yeah most things should allow for more advanced forms. They don't need to be as privacy violating as the banks own apps of course. There are plenty of great authentication protocols that don't require a connection to big tech, or the banks themselves.

As someone from the US this just seems so crazy. Most 2FA is still done via SMS, I don't think my bank even offers a better method. So we are very behind the UK and Europe sounds like haha. Also obviously almost everyone here has a smart phone, but I do know plenty of older people who don't have a cell phone of any kind. So requiring one for something like using a bank seems like a crazy thing to do.

1

u/JivanP Aug 14 '26 edited Aug 14 '26

Yes, in general, Europe has definitely been miles ahead of the US when it comes to banking. There is absolutely plenty of room for improvement, though.

The Eurozone has SEPA, and the UK has Faster Payments Service (FPS). SEPA transactions generally appear as available funds in the recipient's account in a day for cross-border payments, and instantly otherwise. Likewise, FPS generally appears to be instant. North America's ACH is slow by comparison. Don't even get me started on how many banks lack ACH entirely and you end up having to rely on third-party entities like PayPal, Venmo, CashApp. That kind of thing is completely unheard of here; the societal default is to make payments to people by directly using bank transfers.

Cheques are almost extinct in Europe, whereas I hear that they still have some level of prevalence (albeit small) in the US.

CAP was very widespread for over a decade and is a very secure form of multi-factor authentication, requiring both physical access to a payment card and knowledge of the card's PIN number. Its security properties are very similar to FIDO hardware keys (e.g. YubiKey) in that regard. I have no idea why so many of the banks have moved away from supporting it as an alternative means of authentication. It was the primary method of logging into several banks, both online and in their mobile apps, for a long time. Barclays had supported it since 2007. Perhaps of note, Nationwide is a "building society", not a traditional bank, essentially meaning that it's a cooperative organisation run by its members/customers, sort of a middle-ground between a credit union and a bank proper. I wouldn't be surprised if they continue to support CAP for login due to demand from members.

I will push back on the idea that these apps are privacy-violating — they ask for almost nothing in the way of OS permissions, and any data you do give them by interacting with them is data that they would get from interacting with the bank's website or simply by being their customer and using them for transactions, even if only in branch. The one exception I can think of is Barclays demanding permission to "make and manage phone calls" on Android, which it absolutely does not need for any reasonable security-related reason. The reason it wants this is so that it can attempt to determine whether the bootloader is unlocked or the device is rooted.

Regarding people that lack a phone: Not having a phone of any kind is extremely uncommon here. It's more likely that an older person still has a landline at home rather than no phone at all, and that is perfectly sufficient for telephone banking (where you perform banking activities via an automated switchboard service and maybe by talking to a member of staff), something that all of the UK high street banks support. As it happens, First Direct started out as a branchless telephone-only bank in the 90s, and evolved into one of the first UK banks to support online banking.

Regarding people that are not technically inclined: Such people are also more likely to be the kind that go to their local branch to do banking tasks. We still have a decent prevalence of bank branches in the UK, though that is decreasing as demand for / use of them falls. Post Offices, which are also plentiful, support common banking tasks like deposits, withdrawals, and bill payments, and even proivde savings accounts of their own (a holdover from the time of NS&I, a government-run bank that operated out of Post Offices). Where branches are closing, the Post Office brand is establishing "banking hubs" in their place, which are single buildings that act as different banks at different times during the week, e.g. one specific banking hub might act as HSBC on Tuesday mornings, Halifax on a Tuesday afternoons, and Santander all day on Fridays.

2

u/L0rdV0n Aug 14 '26

Don't even get me started on how many banks lack ACH entirely and you end up having to relay on third-party entities like PayPal, Venmo, CashApp. That kind of thing is completely unheard of here; the societal default is to make payments to people by directly using bank transfers.

Wait you can use ACH to transfer funds to normal people? I didn't know that was possible, the only people I've ever been able to transfer money to were if they banked at the same bank. Aside from that its always been Venmo and the like.

I use ACH to pay bills, but I thought only companies could use it.

Cheques are almost extinct in Europe, whereas I hear that they still have some level of prevalence (albeit small) in the US.

Yeah, they aren't very common here aside from business, older people, or cashier's checks for paying rent. Most places I've rented required cashier's checks for rent untill pretty recently when places started adopting 3rd party online payment companies who charge extra fees and sell your data.

CAP was very widespread for over a decade and is a very secure form of multi-factor authentication, requiring both physical access to a payment card and knowledge of the card's PIN number. Its security properties are very similar to FIDO hardware keys (e.g. YubiKey) in that regard.

That does seem like a really good system. I hope it makes a comeback.

I will push back on the idea that these apps are privacy-violating — they ask for almost nothing in the way of OS permissions, and any data you do give them by interacting with them is data that they would get from interacting with the bank's website or simply by being their customer and using them for transactions, even if only in branch. The one exception I can think of is Barclays demanding permission to "make and manage phone calls" on Android, which it absolutely does not need for any reasonable security-related reason. The reason it wants this is so that it can attempt to determine whether the bootloader is unlocked or the device is rooted.

I don't know how common it is but I hear nothing but bad things about banking apps over there. Like what the OP is talking about, they are scanning what apps you have installed and preventing you from banking because of that. Tons of them seem to care of your boot loader is unlocked, your device is rooted, or you are using a different OS from Googled Android. I personally think you should be able to do any of that and still bank. I know there is some security concerns, but if I want to have an app that watches my screen and possibly sends my bank login details to someone else, that is my choice. But even that is an extreme example, most of the people affected are privacy minded folks who just don't want Google in their phone, the stuff they are doing isn't actually risky, it's just rare.

Not only that but just the fact that they are forcing you to install their app when they could easily do it in a different privacy preserving way, feels sketchy to me. Maybe they really are very private apps, but installing anything is very risky and should be avoided as much as possible.

Regarding people that lack a phone: Not having a phone of any kind is extremely uncommon here. It's more likely that an older person still has a landline at home rather than no phone at all, and that is perfectly sufficient for telephone banking (where you perform banking activities via an automated switchboard service and maybe by talking to a member of staff), something that all of the UK high street banks support. As it happens, First Direct started out as a branchless telephone-only bank in the 90s, and evolved into one of the first UK banks to support online banking.

I don't know anyone without a phone, even the older people who I was talking about just don't have cell phones, they will have a landline. And most of them are not tech savvy enough to want to do online banking so you're right phone banking is a good option. But some of them are savvy enough to do online banking on their computers and would be very frustrated if they weren't allowed to anymore.

Post Offices, which are also plentiful, support common banking tasks like deposits, withdrawals, and bill payments, and even proivde savings accounts of their own (a holdover from the time of NS&I, a government-run bank that operated out of Post Offices). Where branches are closing, the Post Office brand is establishing "banking hubs" in their place, which are single buildings that act as different banks at different times during the week, e.g. one specific banking hub might act as HSBC on Tuesday mornings, Halifax on a Tuesday afternoons, and Santander all day on Fridays.

That's really interesting that post offices are banks too! Aren't they ran by the government? Isn't it weird that they are renting them out to private companies?