67 points

The privacy implications of this are not cool. I’m not OK with every app knowing which apps I have installed. Or any app knowing that, frankly.

permalink
report
reply
43 points

Same for DBS bank, also in Singapore. Their app, which is mandatory to generate login & transaction approval OTPs, doesn’t even work on a stock OnePlus phone since it detects part of the OS as “modified”.

Since I have to use that bank for my company, I had to buy a separate phone that’s now sitting in my drawer 24/7 for that purpose alone.

permalink
report
reply
10 points

WTF, I remember the UOB banking app not liking my phone being rooted and what not, but Magisk would work sometimes. But a stock phone not working is especially fucked up. Did you find out what was triggering the response?

permalink
report
parent
reply
7 points

I’ve escalated this all the way to their app developers and in the end they told me something about permissions to draw over other apps being enabled in the default launcher, which they consider to be “malicious”. So my options were to install a third party launcher and forcefully uninstall the default OnePlus launcher (via adb, since any other method would require root), or use a different phone altogether.

Now I’m using Nova Launcher anyway, but it had glitches every here and there where it would default back to the standard launcher, so uninstalling that was a risk I didn’t want to take.

permalink
report
parent
reply
3 points

Yeah, it’s the same for iOS when you sideload any app. You can always get an SMS OTP to login though

permalink
report
parent
reply
6 points

For sideloaded apps I can understand the rationale at least, but a stock phone really shouldn’t have any issues with a genuinely downloaded app from google play.

permalink
report
parent
reply
22 points

Why tf does android let apps see this sort of info? This absolutely should be sandboxed

permalink
report
reply
22 points
*

Could you sandbox the banking app in the work profile with something like Shelter?

It’s unfortunate for those that can’t switch banks, but this would be a strong reason for making me want to switch. I’d rather skip the one mobile banking app than uninstall every other app lol

Amid the complaints, industry regulator Monetary Authority of Singapore (MAS) released a statement voicing its support for the bank’s security feature, which it said aims to address risks associated with downloading applications from unauthorized sources, since these may contain malware.

Maybe I just haven’t encountered it, but are there malware apps? Just trying to get legitimate apps to work sometimes means having to enable debugging, approve permissions and jump through a whole bunch of warnings. Even then apps will get flagged by Play services (ex. Those game currency spoofer apps)

OCBC was the center of a spate of SMS phishing scams last year, which wiped out SG$13.7 million ($10.17 million) from the accounts of 790 customers. Scammers had manipulated SMS Sender ID details to push out messages that appeared to be from OCBC, urging the victims to resolve issues with their bank accounts. They then were redirected to phishing websites and instructed to key in their bank login details, including username, PIN, and One-Time Password (OTP).

That’s not from bad apps… If anything this new policy will make me use the mobile website instead of the app.

permalink
report
reply
14 points

That’s not from bad apps… If anything this new policy will make me use the mobile website instead of the app.

I’d also consider switching banks if it isn’t too much of a hassle. They clearly can’t invest well in terms of security for their users.

permalink
report
parent
reply
3 points

Can’t use the mobile website, because the OTP is generated via the app. So you’ll still need the app. Standalone OTP tokens are being phased out; my bank’s doing so from October this year.

permalink
report
parent
reply
19 points
*

Hide My Applist (root) should make it work.

permalink
report
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 12K

    Posts

  • 543K

    Comments