Banking apps seem to be a motif among things that don’t play well with privacy ROMs. My bank’s website does everything I could want out of it. I think I might be ignorant to something.

  • What about banking apps is especially compelling?
  • How often do banks put must-have features behind an app?
  • And should I be concerned that banks might move away from offering services through browsers?
  • T (they/she)@beehaw.org
    link
    fedilink
    arrow-up
    1
    ·
    1 month ago
    • 2FA
    • Some banks I use require I aprove transactions on my phone when I am paying this online
    • One bank I use has tap to pay on the app instead of relying on Google Wallet
  • rar@discuss.online
    link
    fedilink
    arrow-up
    5
    ·
    1 month ago

    2FA must be done through the damn app. It’s TOTP (six digit) but locked behind god knows what. I asked for alternatives and they looked me like I was a caveman.

    • seaQueue@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      1 month ago

      That would tempt me to dump a backup with adb and rifle through the app data to find the seed

    • morph3ous@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      1 month ago

      When they give you that QR code for the 2FA app, print it out and file it away. That is the seed.

    • Bob@feddit.nl
      link
      fedilink
      arrow-up
      1
      ·
      1 month ago

      Could you elaborate? What kind of phone do you have and do you use a free messaging application like Whatsapp?

  • infeeeee@lemm.ee
    link
    fedilink
    arrow-up
    8
    ·
    1 month ago

    My bank’s 2FA works only via their app or via SMS. For SMS I would have to pay per each received SMS.

    The app perfectly works without safetynet, with microG, rooted with magisk but hidden by zygisk, so I’m lucky. At one update they added a popup at start after login about asking to add my card to Google Wallet (or whatever it’s called nowadays), and it’s not implemented in MicroG, so I can’t open it since that version. I just downgraded to the last working version and blacklisted its upgrades in Aurora, and I hope they won’t block my old version in the near future.

    It’s a very progressive small local bank, I will contact them about this issue if they block my old version to make that dialog optional.

    • seaQueue@lemmy.world
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      1 month ago

      Zelle is sketchy even when compared to other cash transfer apps. They do a lot of freezing people’s money. Don’t use them if you have any other option.

    • Dymonika@beehaw.org
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      1 month ago

      For some banks, like Ally, you don’t need the app to transact in Zelle. But yeah, I must have one for check-depositing.

    • Brickfrog@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      4
      ·
      1 month ago

      Same here, mobile check deposit and Zelle are literally the only things I’ve ever needed a bank app for.

      I used to never use Zelle for anything but too many friends/family want to use some sort of app for exchanging money & that’s usually what we settle on. And my old landlord wanted rent paid via Zelle so that was another thing that forced me to install a bank app for Zelle purposes.

      Mobile check deposit is a requirement when dealing with a bank without any locations nearby. In practice I only need to use that once a year or so, checks are kind of rare nowadays unless you’re a business owner with clients/customers paying with checks.

  • umbrella@lemmy.ml
    link
    fedilink
    arrow-up
    3
    ·
    1 month ago

    most banks here require 2fa so theres that

    and most block even it on custom roms

    cant wait for this shit to be cracked already

  • toastal@lemmy.ml
    link
    fedilink
    arrow-up
    3
    ·
    1 month ago

    Website here is awful. Paste is disabled, it’s not optimized for mobile, it’s a PitA to use, & there is literally code to check if the user is running Netscape Navigator 4. The site has a weird encoding that doesn’t allow English punctuation, & to change your email or phone number requires physical documents, ID, & a wait period. The app is poorly coded & doesn’t work if you have root, are running a custom ROM, (& likely if you don’t have Google services)—so I do just use the site. …But if we are being real, I actually always keep cash on me & cash is preferred so while the problem is still relevant, needing the app/site isn’t dire.

    What is really missing for my country on the site is QR code scanning for bank-to-bank transfers that a lot of vendors use & to do some bill payment. For instance, while I could set up the electric bill to auto-debit, my internet bill only has QR scan without a physical bank number I could transfer to (& the short list of utilities doesn’t include my net)—so I take a 25-minute bike ride in the heat once a month to pay that bill but I reward myself by getting to swing by the nearby-ish Hong Kong pie bakery to get a treat & a latte to make out-of-the-way trip feel worth it.

    When I do have to use the site & since there is no QR code scanning, the workflow is:

    • Login (I have a script to block their paste-blocker to use my password manager)
    • Create a new recipient which requires a unique name, the account number + their banking service provider, phone or email, and 12-digit SMS 2FA code (no TOTP or FIDO2 option); this process is done on a desktop-only site which is hard to work with
    • Confirm that with email
    • Go to transfers, select my from account (despite me only having one account & no default preference option), find that user I created, fill in an amount, do another 12-digit 2FA
    • Then they want to take a picture of my phone after the transfer for whatever reason reason

    This process due to bad UX can take up to 10 minutes if they are not ready. So the tl;dr is to carry cash or hope an ATM is nearby.

    I had discussed it with a local & he said there has been more push towards cashless brought on by businesses/government wanting to track everything & tourists demanding their privacy-invasive ‘comforts’ like $BIG_TECH_PAY & $CREDIT_CARD options despite most folks being fine with cash. Cryptocurrency is basically never accepted either.

    • toastal@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      1 month ago

      If the day comes where I don’t have a choice, I will start carrying a second device with nothing but banking & similar nonsense that prevents my freedom to do what I want with the device I own. OP knows the website experience matter since it not only gets ported to platforms outside the mobile monopoly but sandboxes the banks for spying on your device & asking questions that aren’t their business like if I run an unGoogled ROM. Good thing there was a mass of pushback against Google trying to add attestestion to Chromium ore we’d enjoy the same nonsense on the web too where I’m sure Linux would be block by these goobers.

    • shortwavesurfer@lemmy.zip
      link
      fedilink
      arrow-up
      17
      ·
      1 month ago

      Can’t do anything about mobile deposits, but for notifications, you could get the notifications emailed to you and your email app has push notifications.

      • QuadratureSurfer@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 month ago

        Depends on the bank and what kind of notifications you want.
        Some banks only allow certain types of notifications to occur through the app.

      • hydration9806@lemmy.ml
        link
        fedilink
        arrow-up
        4
        ·
        1 month ago

        Bold of you to assume my email app has push notifications

        • A sad Proton user using a de-Googled device
      • MotoAsh@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        1 month ago

        I mean, they could offer it through the browser. All modern browsers have more than enough hooks and permissions control to do something as simple as take a couple pictures and make a basic request to a back end.

        Though making nice things costs money, so…

        • shortwavesurfer@lemmy.zip
          link
          fedilink
          arrow-up
          4
          ·
          1 month ago

          Oh, of course they could do so, but they won’t do it because they want you to use their app. They want you to use their app because they control it and can mine data from it more so than on a web browser. Take Cime, for example. It has all kinds of Google trackers in it.

        • adarza@lemmy.ca
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 month ago

          i worked on someone’s laptop recently that was set up for mobile deposits via web browser. they also had a bank-provided scanner, too, that worked with it. so it is possible, and it is being done.

      • lazynooblet@lazysoci.al
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 month ago

        I wouldn’t want bank notifications emailed to me. Maybe a notification that I have a notification, but no real content. Email is incredibly insecure.

        • shortwavesurfer@lemmy.zip
          link
          fedilink
          arrow-up
          1
          ·
          1 month ago

          Yeah, that’s a good point. Although I don’t know of many banks that would send the actual notification through email, just a message that you have a notification.

  • solrize@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    1 month ago

    I don’t use them and haven’t missed them. I see one of my local branches has ripped out its outdoor ATM’s though. Wonder if that’s related to moving stuff to apps.

  • Zak@lemmy.world
    link
    fedilink
    arrow-up
    12
    arrow-down
    1
    ·
    1 month ago

    Mobile check deposit is the only thing I want from my bank’s app.

    I’m running LineageOS with Magisk and Play Integrity Fix. That works for my bank’s app, but I’m annoyed that they make me do it and gave their app a 1-star review on Google Play for it.

  • radamant@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    1 month ago

    Depends on the country. I’m teaching in Thailand and here you can’t do any banking through a browser. You can only use the bank’s official app and you don’t even have a login/password for it, you have to go to the bank and activate the app in person as a foreigner (I think Thai citizens can do it online but foreigners have to do it in person). Nobody takes actual cards for the payment and you pay everywhere by scanning QR codes which has to be done through the app. If you buy a new phone you have to activate the app again at the bank’s office. It’s really annoying and the reason I probably can’t go with GrapheneOS or any other custom roms because the bank app is absolutely essential.

    • EngineerGaming@feddit.nl
      link
      fedilink
      arrow-up
      6
      ·
      1 month ago

      Is using cash impossible in daily life instead? It is hard to imagine for me that a smartphone may be outright required for daily life…

      • radamant@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        1 month ago

        It’s possible, just very inconvenient. You end up getting massive amounts of change that you have to lug around to spend.

    • OhVenus_Baby@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      1 month ago

      Seconded and I DO NOT use Google services. So I consider it atleast for banking unnecessary. Apps say they require it. But its usually for Push notifications. Mine work just fine without it. YMMV.

  • NGC2346@sh.itjust.works
    link
    fedilink
    arrow-up
    2
    ·
    1 month ago

    • Convenience, no need to waste time and car fuel going back and forth to the bank all week as i get a lot of cheques and i can just deposit straight after reception from my phone itself

    • Mine put new ones in all year round as its not really a bank, kind of the same but it’s a “caisse populaire” in my language.

    • Not really. If they offer it to mobile, they’ll offer it to computers always.