you are viewing a single comment's thread
view the rest of the comments
[–] 15 points 1 year ago (5 children)

It's almost already like this. In my country every single bank reinvented the wheel by creating a single purpose app which does what aegis does (otp generation from a seed) but with some bits changed (one for example "encrypted" the seed with ROT13) and with draconian measures like bootloader must be locked, adb must be disabled, and are using literal exploits to see if you have "forbidden" directories on /sdcard like/sdcard/magisk even if no file access is granted

  • source
  • hideshow 5 child comments
  • [–] 4 points 1 year ago (2 children)
  • [–] 1 point 1 year ago (1 child)

    it's not almost worldwide? By reading all the forum posts with us nerds damning the bank app developers for the antiroot checks, it seems a widespread problem

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 1 year ago*

    Nah, Half of the credit unions in the US use online banking software that uses TOTP for 2FA.

    My bank in EU does not, so I have to have a physical hardware token to generate OTPs, due to broken regulations

  • source
  • parent