| ▲ | fodmap 2 hours ago |
| > It's mind boggingly stupid that they lock down apps like this, when you can just open the thing in a website anyway. I can use my bank on some linux distro... Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I have several linux phones but I can only do banking with their app downloaded from Aurora Store in my Vollaphone. |
|
| ▲ | shevy-java an hour ago | parent | next [-] |
| This should be illegal that the government forces people into apps controlled by private, commercial entities. I call such a government corrupt. Here in central Europe I can still access the bank website fine without smartphone. I need a physical device to yield a TAN though, but I can access and do online transactions fine. So I think something is wrong with the spanish government. People need to protest. |
| |
| ▲ | dotancohen 6 minutes ago | parent | next [-] | | > This should be illegal that the government forces people into apps controlled by private, commercial entities. I call such a government corrupt.
Or how about schools requiring parents to use WhatsApp to receive updates and information? Luckily my ex forwards to me the important stuff, but not everyone is as lucky to have an ex like mine )) | |
| ▲ | microtonal 9 minutes ago | parent | prev | next [-] | | My bank still supports TAN codes with a device too. Unfortunately, once it breaks or the battery goes dead you cannot get a new one and have to use their app. Fortunately, their app works on GrapheneOS without issues. | |
| ▲ | phantom784 26 minutes ago | parent | prev | next [-] | | Especially in Europe! They shouldn't be forcing you to run an OS from an American company. | | |
| ▲ | wolvoleo 6 minutes ago | parent [-] | | Even the EU initiative Wero requires Google or Apple. You can't even use it on a desktop pc and you're not even allowed to have developer options on. Ridiculous. I've never seen any app that is so strict. |
| |
| ▲ | Mindwipe 4 minutes ago | parent | prev [-] | | The DSA European digital wallet spec currently requires Google or Apple attestation, so not for much longer. And that is mandated by the EU. |
|
|
| ▲ | Tharre 2 hours ago | parent | prev | next [-] |
| > Not in Spain. I can access my bank's website but I can't do anything without their bank app. I don't know about Spain specifically, but as far as I understand it no bank in the European Economic Area + UK should allow banking via just the website alone anymore, because of the "Revised Payment Services Directive" (PSD2) regulation. Essentially, banks are required to implement "strong customer authentication", which in essence is just multi-factor authentication with a password + either biometrics or a security device of some sort. And in practise that means a banking app, because most people do not want a separate token they have to buy and can lose. Though a lot of banks do offer those as well. |
| |
| ▲ | askonomm an hour ago | parent | next [-] | | In Estonia you can easily do banking via the website on all the banks (LHV, Swedbank, SEB). That said, we do have it all integrated with our digital-ID (which every ID card has private keys encoded into with a PIN you know) so it's not like you can access it with a simple password (our online voting works the same way). | |
| ▲ | gunapologist99 an hour ago | parent | prev [-] | | TOTP not accepted? (When will people learn that biometrics are not another factor: they're entirely public and irrevocable. It's not just security theater, but Apple & Google know that this forces you into their ecosystem, which should be illegal. Of course, Brussels is full of rubes anyway.) |
|
|
| ▲ | lejalv an hour ago | parent | prev | next [-] |
| > Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. https://triodos.es has 2FA via SMS, for what is worth. |
|
| ▲ | severino an hour ago | parent | prev | next [-] |
| I don't know which banks you are using but in my case I work with five Spanish banks and I can do everything from their websites, no app required. Yes, they try to push you to use their app, some tried to activate mobile 2fa for me when this psd2 thing became mandatory but I always told them their app doesn't work on my phone (which is true) and they offered me alternate methods like sms. |
| |
| ▲ | dotancohen 2 minutes ago | parent [-] | | In my country we have a large religious population who eschew the smartphone. This means that no government, banking, or other services require a smartphone. |
|
|
| ▲ | FullMetalBitch 2 hours ago | parent | prev | next [-] |
| I have been using GrapheneOS for a few months in Spain with and out of three banking apps only one gave me trouble, I had to enable "Exploit Protection Compatibility Mode" on "app information". Personally I refuse to pay with the phone so I am okay not having that option. If someone wants to try Graphene os maybe that option will work on their banks too. |
|
| ▲ | b112 2 hours ago | parent | prev [-] |
| Not in Spain. I can access my bank's website but I can't do anything without their bank app. Even sometimes they require to confirm my identity using their app in order to access their website. I've seen this elsewhere, and it's absolutely ridiculous. Why? Because in almost all cases, the apps may only be installed with Google Play, and require the framework to work correctly. And that means? If you are not in good standing with Google, you cannot bank!! I cannot stress how inane it is, to have Google or Apple as the gatekeeping to identify verification. How not having an active, in good standing account with one of these two, means you cannot bank. And it's happening more and more. Meanwhile, banks -- which tend to make billions in profits quarterly, do this to save on infrastructure costs. They do it so they don't have to stand up their own push servers, or have an app which doesn't require firebase. Well cry me a river, boo-hoo Mr Banker, I'm not even remotely interested in you saving on infra-structure costs at the loss of autonomy. And on top of this, many banks are reducing hours, closing branches, claiming that they don't need them. Leaving absolutely no other choice. This sort of thing should be illegal. Being in Spain, but requiring a US megacorp to tell your own bank, that you're you. |
| |
| ▲ | jlokier 43 minutes ago | parent | next [-] | | > They do it so they don't have to stand up their own push servers I don't agree with this dependency on being in good standing with Google either. But there is a technical reason that isn't wanting to avoid using their push servers. It is about battery usage and radio bandwidth. Keeping open an idle connection over WebSocket, long-poll HTTP or TCP/IP needs regular pings (typically 30 seconds are used), one ping per connection. Otherwise your app can't be sure to receive messages from the server in real time, as the connection can disappear into CGNAT or similar hole where it doesn't receive messages sent by the server. To an app not using pings to check, such a blackholed connection is indisinguishable from an idle connection with no pending messages. Waking the radio every 30 seconds, times 2 (back and forth), times the number of registered applications, would be quite battery draining. It drains battery both for background CPU usage and radio processing. Those pings in aggregate can even amount to a significant amount of data usage for users on smaller plans. So there is a battery and radio advantage in using a shared push service, which only need a single idle connection to be kept live with 30 second pings. There's another level to this, not available to regular developers using TCP/IP, HTTP or WebSockets. The mobile network itself has to maintain handset connection liveness to the nearest tower, at a lower level than IP pings, and this is obviously optimised for battery and radio performance, and always running. With arrangements in place with the mobile networks (which Google and Apple have), the mobile OS can leverage that for more reliable, lower power push notifications, by either guaranteeing the network will send something technically similar to a low-level SMS when there's an outstanding message, or by guaranteeing their special push IP connection will stay live by itself (no CGNAT blackhole) or be notified if something happens to it. This allows the mobile OS to offer a shared push service that's fairly reliable at real-time notifications, with zero continuous CPU and radio power overhead for the idle connection. | |
| ▲ | vladms an hour ago | parent | prev | next [-] | | As far as I remember, last time I needed to use Google play on a shared phone I could just create a random Google address (I mean, completely invented name, etc.) and it allowed me to do anything, just as my normal Android. I am too lazy to test, but did this change? Can't you just make a "fake" account and continue with your life? The phone company knows where you are, the bank knows what you purchase. Compared to that Google will know far less (ofc, if you don't activate everything) I find it much more insane that it was possible for so long to do banking WITHOUT strong authentication (however implemented) by just providing those 3 numbers on the back of the card (strong security!) | | | |
| ▲ | afpx an hour ago | parent | prev | next [-] | | I thought this was what Larry meant when he said surveillance will keep citizens on their best behavior. If one’s reputation score is low, sorry no money. Also, if anyone in one’s network has bad behavior, no money and no friends. Maybe the kids will learn to accept it, but being of the last analog generation, to me it seems like a painful future. | |
| ▲ | derbOac 39 minutes ago | parent | prev | next [-] | | It seems like the right time to advocate for open standards in things like banking. | |
| ▲ | bytejanitor an hour ago | parent | prev | next [-] | | In Germany for some banks you can buy a TAN generator and then you do not need a smartphone app anymore.
Is this an option in your area as well? | |
| ▲ | FullMetalBitch 2 hours ago | parent | prev | next [-] | | Why? Technofeudalism is not going to impose itself | |
| ▲ | bergheim 2 hours ago | parent | prev [-] | | Especially with how things are currently, I whole heartedly agree - you cannot operate as a human being in Europe without having a good standing with either Alphabet or Apple. Absolute madness. | | |
| ▲ | 6LLvveMx2koXfwn an hour ago | parent [-] | | Absolute madness or complete nonsense - I have neither an Apple account or device, nor a Google account or mandated device (e/os on Fairphone 3+) and operate perfectly successfully in the UK with (almost [1.]) zero friction. 1. Revolut app stopped working so I emptied my account and opened a Wise account which is fully administer-able from their website. Revolut has subsequently started working again after a couple of app/OS updates. |
|
|