(Rant)

At somepoint, HSBC decided KDE Connect installed via F-Droid is less secure.

Photo of the HSBC UK app urging I install KDE Connect via GPlay or Galaxy Store

Then it decide non-whitelisted keyborads are a security risk. Only Gboard and Samsung Keyboard is confirmed within the whitelist.

Photo of the HSBC UK app telling me to switch input method citing security risk


I understand the point that risk can be introduce at various points, yet this is simply too much. Yeah there are people phone infected by malware but from Play Store. Not a single time I heard one ever happened on F-Droid distributed apps, at least not from the official repo. Also, I will put more trust on an open source keyboard than any proprietary keyboard.

Furthermore, I’m shocked that an app can read my app list, and current keyboard (introduced in Android 14). This just make building a profile much easier as I belive everyone almost have an unique set of apps they like. I don’t think any apps need such functionality. Why the f it needs to care what input devices I uses? This make me worry more about untold (aka burried deep in Privacy Policy) data collection.

  • pacjo
    link
    fedilink
    English
    11 hour ago

    With recent releases CorePatch can spoof app source, but it won’t help with keyboard whitelist.

  • ParadoxM
    link
    fedilink
    English
    207 hours ago

    We seriously need a way to sandbox apps, where they cant see shit outside their sandbox

    • Virkkunen
      link
      fedilink
      344 minutes ago

      You do know screenshots exist

      App doesn’t allow screenshots or screen sharing as part of the security features

      Also, don’t do mobile banking

      Many times that’s simply impossible depending on the bank, and it’s wholly inconvenient for most people. Security wise, it also depends on way too many variables, so you can’t just tell people to not do it and don’t elaborate further.

    • @[email protected]
      link
      fedilink
      English
      41 hour ago

      Actually, I wouldn’t be surprised if screenshots are disabled in that app considering the rest, to “stop leaking sensitive information”.

    • @T156
      link
      English
      42 hours ago

      If the app is so paranoid that it refuses to work after detecting a different keyboard, I should be surprised if it allowed screenshots.

    • @Robin
      link
      English
      11 hour ago

      You want us to yell out our credit card details over the phone like the good old days?

  • @[email protected]
    link
    fedilink
    English
    218 hours ago

    And then i complained that my bank blocked access if adb was enabled…

    If there’s no loan attached to that account, for me this message reads “sorry, we don’t want you as a customer. Please contact a bank teller to have a full refund, uninstall this app and don’t forget to leave a 1 star review”

    I’m not willing to compromise on this shit. My phone is my phone.

    • @RubberElectrons
      link
      English
      36 hours ago

      Imagine one of my medical apps refusing to run because of adb…

  • @[email protected]
    link
    fedilink
    English
    158 hours ago

    Sounds like it’s time to use the website and not the app. And if you can’t use the website instead of an app, you should probably switch banks.

    • @[email protected]
      link
      fedilink
      English
      12 hours ago

      I don’t know a single bank that hasn’t reinvented the wheel and is using their app as a glorified authentication app for generating totp codes

    • merde alors
      link
      fedilink
      English
      88 hours ago

      money laundering is alright but how dare they impose gboard to their clients

  • @Im_old
    link
    English
    49 hours ago

    Graphene and starling, works great