Banking apps can now require recent Android security updates

https://www.androidpolice.com/apps-can-require-recent-android-security-updates-play-integrity/

24 points · 14 comments · view on lemmy.world

14 Comments

3dogsinatrenchcoat@slrpnk.net · 16 pts · 1y

can't use app if you use custom rom to get updates

can't use app if you don't have updates

MaXimus421@lemmy.world · 15 pts · 1y (2 replies)

RIP Motorola

limerod@reddthat.com · 4 pts · 1y

Newer motorola smartphones promise 5 years of software updates. Everyone before is screwed. But, buying the newest should be fine if they research before making a purchase.

JustEnoughDucks@feddit.nl · 4 pts · 1y

Rip Sony.

01189998819991197253@infosec.pub · 12 pts · 1y (5 replies)

I see a lot of people going back to the old www . bankwebsite . com.

Phone apps are just modern toolbars.

And in case you forgot that scourge:

jol@discuss.tchncs.de · 4 pts · 1y (4 replies)

I have 3 bank accounts and all require mobile apps. The Web Apps are limited in what they can do.

01189998819991197253@infosec.pub · 5 pts · 1y (3 replies)

That really does suck, and is poor product design. Besides using the desktop site, I'm not really sure how to easily get around that.

ub0x5jtk@lemdro.id · 1 pts · 1y (2 replies)

It is a good design, especially security wise. Many banks require 2FA from their app/companion app.

01189998819991197253@infosec.pub · 1 pts · 1y (1 reply)

Logging into the bank app using the bank app as the mfa is good design? Is that what you mean?

ub0x5jtk@lemdro.id · 1 pts · 1y

Yes, not ideal, but better than mere website.

Even better option would be a dedicated password manager with MFA like Proton Pass etc. but banks use their authentications in various ways and are regulated more.

jeena@piefed.jeena.net · 9 pts · 1y (3 replies)

That will mean that they'll be able to sell more phones because people won't be able to run the bank app on a older machine?

limerod@reddthat.com · 8 pts · 1y (2 replies)

This will limit phones without longterm software support. The ones which don't provide decent enough software support will be left in the dust.

smeg@feddit.uk · 3 pts · 1y (1 reply)

Hopefully a small pain which will encourage better behaviour overall in the future. Hopefully.

ub0x5jtk@lemdro.id · 1 pts · 1y

You are mentioning a domino effect, but the main goal is beneficial in itself, increasing security. I hope people posting here are not using Windows XP in 2024, or have not updated their Linux packages since 2017.

Go search for how long companies take to patch a vulnerability. It is like 60 days for critical CVEs on average, 300 days overall.