Hacker News new | ask | show | jobs
by TeMPOraL 1129 days ago
I guess this is a bit like my take on Uber - they may be rotten to the core and damaging the very fabric of society, but at the very least they pushed competitors of all kinds to improve the hailing/ordering experience, so now taxis and rideshares around the world can be ordered via an app, with built-in map and address search.

Back to Revolut - I'm of two minds about bank apps. On the one hand, good apps are good, and some things really get streamlined this way. On the other hand, this only sets us up for another battle in the war on general-purpose computing: a fight over mobile device ownership.

Banks didn't just improve the UX of their apps. Some made them the primary or sole remote interface to one's accounts. Many (most?) are now using apps for 2FA, and heavily pushing it - with such banks, using the web interface from a PC browser still requires confirming any meaningful operation via the smartphone app.

The problem here is, banks are one of the most eager users of remote device attestation features, and (by being big and full of money) they have all the leverage over users and smartphone vendors alike. Many bank apps will refuse to run if they detect the phone isn't pristine and fully locked down by the vendor - and with modern phones now coming with built-in APIs for such checks, rooting the phone or flashing it with custom firmware is quickly losing all value. After all, what good is a rooted phone if you can't use it for anything important that smartphones now do?

1 comments

Banks want to sink as much data from the consumer device as possible. Remember bank app wants a permission to access all files and calls and messages and location and physical sensors?

They don't care about security other than for avoiding devices that gives user a control over what data is accessible.

Security in banks is generally very basic (anyway, everything is covered with insurance, which is paid by the users, in the end).

User data is used mainly to calculate credit rating and for upselling.