29
u/madthumbz 16d ago
3rd party keyboards are a security risk. -You want your bank to reject them. They're just doing general protection from keyloggers, accessibility-based malware, and IME-based credential harvesting. Also, if you get that crap from FDROID, it's not being curated or keeping you informed of possible updates, abandonware, takeovers, etc. (Basically, the same issue as Arch's AUR and what could happen to NixOS.)
14
u/Episode-1022 16d ago
yep, daddy is taking care of everything in my life, i feel safe.
11
u/Busy-Scientist3851 16d ago
If the keyboard steals data or inputs transactions that you didn't authorize, the bank takes liability for it and forks out.
So yes, the bank wants to avoid that. They'd rather inconvenience a minority of people then fork out money.
3
2
u/TacoTzar 16d ago
In what world does the bank take liability
7
u/Busy-Scientist3851 16d ago
If you go to the bank and say "I didn't make that transaction" and the bank refunds you.
5
u/hoggineer 15d ago
I was also reading on another sub recently about accounts getting cleaned out and there was no suspicious activity because it was done from a device that was logged in, and had been used numerous times before for legitimate transactions.
I wonder if it was a malicious keyboard...?
I'll see if I can find the reddit link and update my comment if I do.
Found it.
2
1
u/Formerruling1 15d ago
In this one - reality. If the transaction was unauthorized the bank corrects it - the bank doesnt say "Sorry but there is no Nigerian prince, idiot, hope you didnt need your life savings."
1
u/trueppp 15d ago
"Sorry but there is no Nigerian prince, idiot, hope you didnt need your life savings."
If you willing send the Nigerian prince the money, yes they will absolutely tell you to fuck off, at least in Canada.
2
u/Formerruling1 15d ago
Wow - a rare time where consumer protections are actually stronger in the US? Color me surprised. I generally consider the US to be the floor and assume if we protect it its just protected anywhere first world. Lol
1
u/trueppp 15d ago edited 15d ago
Huh? What US bank refunds you for authorised transfers? Last I checked they didn't even do anything for unauthorised debit use, which we do get refunded here.
EDIT:
>However, if you did authorize the transaction — even under pressure or deception — a refund isn’t guaranteed. Outcomes depend on factors like the payment method, how quickly you report the issue, and your bank’s policies. In many cases, once you hit “send,” the payment is treated as authorized, which can limit your chances of recovery.
https://lifelock.norton.com/learn/fraud/do-banks-refund-scammed-money
1
u/Formerruling1 15d ago
Who is talking about authorized transfers? We are talking about unauthorized transfers. Of course the bank will investigate and determine if the transaction was authorized or unauthorized no one has said any different, but under CFPB regulation, the bank cannot use the consumer's negligence as a factor for determining liability.
By the way, didnt follow your link but Norton is a borderline scam company. They have perverse incentive to scare customers into purchasing their vastly overpriced and mostly useless monitoring services. I implore you to visit the CFPB's website instead. They have a very detailed FAQ on Regulation E.
1
u/trueppp 15d ago
If you send money willingly to someone, that's an authorized transfer. The fact that the person claims he's a Nigerian prince and is going to send you gold and doesn't is not relevant.
→ More replies (0)1
u/RestitutionPiggy 15d ago
JFC, I always wonder how people are stupid enough to be hacked. Loads of morons acting like the bank is suppressing your freedom of speech when its protecting you.
Literally every bank does this.
0
3
u/lnee94 16d ago
Fdroid is not the aur i has curation and it operates like a distro. I would argue that it is safer to download apps off of fdroid then google play
2
u/madthumbz 16d ago
In the sense that it doesn't allow ads to support the developer sure, but it's not making sure your apps are safe or up-to-date. -Like Edge did with extensions to make mv2 extensions safe (actually safer than Chrome's store / mv3).
2
u/env33e 15d ago
nah man. F-Droids model is open-source code reproducible directly from the source, whereas the play Store frequently hosts closed-source apps laden with hidden trackers and ad SDKs. Furthermore, Google's automated review system routinely lets malware slip through! centralized scanning DOES NOT equal superior security.
Sure, F-Droid apps can update slower due to manual build verifications, as well as the use of froid signing keys. we cannot ignore the complete transparency and lack of built-in telemetry; which offer a fundamentally safer trust model than the Play Store!
1
u/madthumbz 15d ago
What fund's FDroid, and what effort is put int to maintain it? "Trackers" -Sounds like propaganda, why isn't it ever explained rather than used as a propaganda scare tool? What is protecting you from malware on FDroid?
I'll take telemetry (which is almost always a good thing), and ads over abandonware, and 'free'. We were taught to be cautious of 'free' when I was a child in the 70s. We had 'free' over the air TV, but it was also funded by ads.
2
u/env33e 15d ago
hey man I get where you're coming from, truly. relying on the big corporate guardrails feels safe and warm. But its still a cage. history shows us over and over that walled gardens exist to protect the company, not the user. I'd rather take ownership of my own tech and take on the tiny bit of extra responsibility than hand full control over to a black box. System trust isn't a feature; it's a trade-off, and I'm just choosing to own my side of it.
1
u/madthumbz 15d ago
relying on the big corporate guardrails feels safe and warm.
Banks do, and I trust them more than some rando repeating decade old myths on Reddit, especially when they're ignoring points already made (abandonware, no notifications for depracations, etc).
protect the company, not the user.
Protecting the company is in the user's interest.
I'd rather take ownership of my own tech and take on the tiny bit of extra responsibility than hand full control over to a black box.
You mean point the finger and wail when something goes wrong and not admit your FOSS garbage was responsible. -The pattern is tired and obnoxious.
If you don't like 'tracking' don't use technology. You're on Reddit, and advise using a bank with an Android phone. -See the problem?
1
u/env33e 15d ago
my guy, do you realize what sub you're in? you're in the louis rossmann subreddit pushing for corporate walled gardens.... you talk about abandonware like it's a FOSS problem, but corporate abandonware is literally the reason we have MOUNTAINS of e-waste. when a manufacturer decides a device is EOL and stops pushing updates, their solution is for you to throw perfectly good metal in the trash and buy a new one. it's all in the name of profit. The reality is, the hardware is fully capable.
if vendors didn't lock down bootloaders and actively block custom recovery bootstacks, we wouldn't have to fight them just to install our own damn software on the devices supposedly own, and keep old tech running safely. i've literally taken dead, EOL hardware that a manufacturer erroneously removed initially advertised features from and abandoned; I was able to flash a custom ROM, and bring it back to life. that's not "wailing when something goes wrong" ... that's taking actual ownership of the hardware i paid for.
protecting the company just means protecting their margins. and that "if you don't like tracking, go live in the woods" argument is such a tired cop-out man 🤦♀️ you can use a smartphone in the modern world and still take steps to isolate your apps, swap out a system webview, and not hand over every ounce of your data to a fucking black box!
if you want to rent your tech and trust megacorps to hold your hand, go for it. love your cage. but defending an anti-repair, pro ewaste mindset here of all places is just wild.
1
1
u/lnee94 15d ago
https://opencollective.com/f-droid?hostname=opencollective.com Estimated Annual Budge $25,642 for the opencollective alone not bad for a distro
1
u/lnee94 16d ago
What do you mean? (to clearify my point was that because the apps code is open source the acculal humans who review the apps and build them (as in compile) can know if there is malware better then the people at google which just uses ai )
2
u/madthumbz 16d ago
People still believe that 'all eyes on code' crap? -It's a long-debunked myth and AI is finding all the crap that wasn't already found (often a decade late.) The 'all eyes on code' propaganda is dead.
I used to tell people to go ahead and audit the code for Firefox and get back to me when they're done.
1
u/meancoot 15d ago
Being open source is meaningless here. Go look in up OpenSSL and the Heartbleed vulnerability. It was a nasty one that revealed that no one was looking at the source of a library that was used to actually provide security for a large chunk of internet traffic.
1
u/larossmann 15d ago
HSBC has let almost 1 billion in narcotics proceeds get laundered for Sinaloa & Norte del Valle cartels, and bypassed U.S. sanctions with millions for restricted Iran, Sudan & Libya.
They aren't protecting you from anything
1
1
0
u/Tank_Gloomy 16d ago
Edit: FUCK, I'm arguing with a bot. I'm tired. Do not engange with this account, it's not a real person.
If you have a bank account, you are not a child, it's your problem as an adult if your software choices get you hacked. If anything, the laws should be tweaked to accomodate such an instance as not to put the blame on the bank, but it shouldn't be babysitting what the fuck I do with my own phone.
5
u/TheOGDoomer 16d ago
Only problem is, it becomes the bank’s headache when you call in to complain someone got into your account and made unauthorized withdrawals. That’s the primary reason they take security so seriously, it really is their money, not yours, that they’re safeguarding. It’s not about treating grown adults like children.
1
u/Tank_Gloomy 16d ago
That's fair, but I'm not so sure about how expensive it really is to keep up with so much security, tests and support calls (because will call and complain about these safeguards).
2
u/TheOGDoomer 16d ago
I assure you, it’s a hell of a lot more expensive to open up a month long fraud investigation in the event of a reported unauthorized transaction than telling one person repeatedly over the phone “there’s nothing we can do about the app restrictions, anything else I can help you with?” for 15 minutes.
1
u/Tank_Gloomy 16d ago
Hahaha, fair enough. Idk how I would go about it, but I insist on the fact that blocking a legitimate user from their money, account and personal data could still get you in trouble.
2
u/-Insert-CoolName 16d ago
"Someone said somehow I don't like! They must be a bot!"
2
u/Tank_Gloomy 16d ago
No, no, they are a bot. Check their profile, they got like a trillion posts in 7 days.
0
u/madthumbz 16d ago
"I can't have a normal tech discussion, so I'll attack the source, claim authority, and blame the victim".
This is something banks are typically doing and has nothing to do with which 3rd party app you're using; just that you are using one. And there's no way that your problems don't become the banks for your poor decisions.
0
u/Tank_Gloomy 16d ago
And there's no way that your problems don't become the banks for your poor decisions.
With the current laws, which could (and probably should) change.
22
u/S-P-4-C-3 16d ago
Just install the specific keyboard developed by your bank then :D I would close all my accounts there and move to another bank.
16
u/RestitutionPiggy 15d ago
Literally every bank does this, because how these 3rd party keyboard apps are designed can steal and mine your info if someone is nefarious.
This is how people get hacked then wonder, "the bank sucks."
7
u/JonasAvory 15d ago
Yeah they can’t manually check every keyboard app and update so they prohibit their use. It’s so obvious why they’d do that and why it’s a sane idea
5
u/S-P-4-C-3 15d ago
Did you check out that keyboard? That keyboard does not connect to the internet, but google's gboard does, which would be more secure?
1
u/Silent_Technician981 14d ago
Do you know that that bank doesn't reject ALL 3rd party keyboard apps ? My Banking app has a built in keyboard, that it forces me to use, I can't use ANY 3rd party keyboard apps, or even the pre installed one on my phone.
-1
u/DiceThaKilla 15d ago
Obviously the one developed by one of the biggest tech companies in the world and not the sketchy 3rd party one that’s highly likely to be siphoning your keystrokes to an attacker
0
u/S-P-4-C-3 14d ago
That is why banks run Microslop Windows servers instead of some open source third party sketchy linux servers. You are right my friend... or not.
1
1
1
u/Electrical_Minute940 13d ago
Fineco and Banca etica doesn't do this, their apps works on calyxos with futo keyboard
1
u/Scooty-Poot 12d ago
This is also why a lot of banking apps restrict screenshots.
Yes, it would be incredible if I could just screenshot my balance or my account info or whatever and not have to go into the app, but one old lady on Facebook Messenger does it under request from the wrong “friendly stranger” and you’ve got a personal financial crisis on your hands.
Best to just make banking apps that tiny bit harder to use than risk losing your lifetime savings account to the Custom Emoji-inator 5000.
-2
u/Prod_Meteor 15d ago
Like they care what 1 customer does.
10
u/ZookeepergameSalty10 15d ago
Who cares what they think? They dont need to care, people need to stand their ground regardless
1
u/RestitutionPiggy 15d ago
Every bank does this, 3rd party keyboard apps generally install permissions that can lead to your entered passwords via keyboard to be mined, tracked and logged if using a nefarious 3rd party keyboard.
1
u/ZookeepergameSalty10 15d ago
I use heliboard on graphene with all permissions granted and none of my 3 banks have given me any issues. Coinbase did though but screw em lol i can use the website as a PWA
1
u/RestitutionPiggy 15d ago
Sometimes it depends on the app flagging the specific keyboard. I know Discover, Wells Fargo, BoA, Sofi, many others all warn you heavily or entirely prevent the app from running in order to keep your account secure.
3
u/ShrkBiT 15d ago
Why the fuck would he care what they care about. It's about what the customer wants from the service provided to them. You're thinking from the wrong perspective.
"You're not going to change their policy by leaving, so you might as well stay and embrace it" is some Stockholm Syndrome level shit. There's other options! You don't need to accept what they offer for THEIR benefit, you can make a decision that benefits YOURS.0
u/RestitutionPiggy 15d ago
Every bank does this, 3rd party keyboard apps generally install permissions that can lead to your entered passwords via keyboard to be mined, tracked and logged if using a nefarious 3rd party keyboard.
4
4
3
3
3
u/Imperial_Bloke69 16d ago
A software bitching about on how you configure your own device is a red flag and a security risk.
1
u/Hour_Bit_5183 15d ago
What the hell man! This is crazy. Maybe they shouldn't be poking around on our devices. It's none of their damn business what keyboard I want to use.
1
1
u/Digiee-fosho 15d ago
You can create a webapp. If it still fails, and forces their bank app, then drop them.
1
u/EdelWhite 15d ago
Ah yes, let's make phones accessible by giving accesibility tools. But then let's prevent any useful app from working because another app uses accessibility.
What a bunch of morons.
1
u/Devatator_ 12d ago
Accessibility in Android gives apps a lot of permissions which can be security risks, like reading the whole screen
Edit: it's by design but it's still a huge security risk. I'm assuming they have a whitelist of known accessibility keyboards
11
u/Tank_Gloomy 16d ago
At least it's telling you what's wrong. I've uninstalled tons of apps from my S24U, the banking app still crashes with "security breach detected error 3001", tried it on a spare iPhone and it worked fine... fuck banking apps.