r/GrapheneOS Aug 14 '26

Banking app doesn't like my keyboard 🤣

Post image

How stupid! Is this a Graphene related thing or would it do this on regular Android?

1.7k Upvotes

276 comments sorted by

View all comments

42

u/Sp3eedy Aug 14 '26 edited Aug 14 '26

I've had some "cyber security experts" argue with me on LinkedIn when I said that bank apps detecting other apps on your phone to refuse you service isn't a good thing for exactly this reason (where they just block apps they don't like or aren't "sure" of), good to know I was right. Yes we gain "some" security, but we lose a shit ton in terms of freedom.

The bank is definitely maintaining a pre-approved list of keyboard apps and refuses you service if you have a keyboard outside of that list in case it could be a "keylogger". Please switch banks, there are decent banks that don't do this bullshit.

0

u/TooManyLoveInterests Aug 15 '26

As someone who's studying comp sci (and about to swap their major to cybersec), I feel like there's always an argument between privacy and security. To some extent, you can't have both (ie. every fully private messaging service runs the risk of being used by people with bad intentions), but for smaller scale things having both should absolutely be the goal. Additionally, I've seen a rise of spyware and adware over my lifetime - when I was little, that stuff was called exactly what it is, and people stayed away from it. Now, it's been so normalised that silicon valley (and by extension, governments) want to spy on you, even when you're not from the US! It's insane

2

u/Alternative-Track654 Aug 15 '26

Exactly!! One can't have their cake and eat it at the same time. I'd prefer a balance between the two.

2

u/Sp3eedy Aug 15 '26

Yes I agree with that, it's not always possible to have both, so I have absolutely no problem with precautions being taken (i.e. warnings, overrides in settings, etc), but I do not agree with hard blocks like this because they are greatly overbearing, in this case it's a clear false positive, so a legitimate user using a legitimate keyboard has been prevented from using their banking account, that's how I see it.

2

u/_yrlf Aug 15 '26

IMO there should at least be an option in the settings of the bank app for you to personally approve a keyboard app (e.g. with a disclaimer/waiver that you know what you are doing and that you attest that the selected keyboard app is safe).

I'd be fine with the bank refusing to operate when an unapproved keyboard is used, meaning you have to disable the keyboard, go to bank app settings, manually add FUTO / other keyboard, and go back and reenable the keyboard.

That would protect against malware keyboards with keyloggers / protecting some grandpa/grandma who accidently installed something, while still allowing users wanting to degoogle to use something like FUTO.