(Rant)

At somepoint, HSBC decided KDE Connect installed via F-Droid is less secure.

Show Photo of the HSBC UK app urging I install KDE Connect via GPlay or Galaxy Store

Then it decide non-whitelisted keyborads are a security risk. Only Gboard and Samsung Keyboard is confirmed within the whitelist.

Show Photo of the HSBC UK app telling me to switch input method citing security risk


I understand the point that risk can be introduce at various points, yet this is simply too much. Yeah there are people phone infected by malware but from Play Store. Not a single time I heard one ever happened on F-Droid distributed apps, at least not from the official repo. Also, I will put more trust on an open source keyboard than any proprietary keyboard.

Furthermore, I'm shocked that an app can read my app list, and current keyboard (introduced in Android 14). This just make building a profile much easier as I belive everyone almost have an unique set of apps they like. I don't think any apps need such functionality. Why the f it needs to care what input devices I uses? This make me worry more about untold (aka burried deep in Privacy Policy) data collection.

  • Paradox@lemdro.idM
    ·
    9 days ago

    We seriously need a way to sandbox apps, where they cant see shit outside their sandbox

  • Moonrise2473@feddit.it
    ·
    9 days ago

    And then i complained that my bank blocked access if adb was enabled...

    If there's no loan attached to that account, for me this message reads "sorry, we don't want you as a customer. Please contact a bank teller to have a full refund, uninstall this app and don't forget to leave a 1 star review"

    I'm not willing to compromise on this shit. My phone is my phone.

  • shortwavesurfer@lemmy.zip
    ·
    9 days ago

    Sounds like it's time to use the website and not the app. And if you can't use the website instead of an app, you should probably switch banks.

    • Moonrise2473@feddit.it
      ·
      8 days ago

      I don't know a single bank that hasn't reinvented the wheel and is using their app as a glorified authentication app for generating totp codes

      • shortwavesurfer@lemmy.zip
        ·
        8 days ago

        Mine actually. I'm in the United States, but I actually switched banks. And the vast majority of the reason I did so was because my bank did not allow me to use the website to use their functionality. And so I said fuck you and left them.

  • Railcar8095@lemm.ee
    ·
    8 days ago

    I thought this was for employees of the bank on the work phone.

    If my bank does this, they can kiss goodbye my $254.21.

  • LiveLM@lemmy.zip
    ·
    edit-2
    8 days ago

    Check out Shelter by PeterCxy [FDroid - Source]
    It uses Android's native work-profile feature to create a separate space for the apps you choose, so you could install the HSBC app there and it wouldn't be able to see anything outside its little bubble.
    The downside is that AFAIK you cannot have multiple work profiles on the same phone, so if you have a MDM solution from work already installed like Intune you won't be able to use this, and given how draconian this app is, it might refuse to run if it detects its inside one. Worth a shot though.

    This is the type of shit that has me losing faith in Android.
    They added a fuck ton of restrictions on Clipboard Access because 'Privacy,' yet this clear privacy violation (with 0 use cases!!!) is still here.

    You'd think that they'd create a permission you can toggle at will since they care about protecting you so much right?
    Nope. Google's the one who decides who gets to use this capability and your wishes as a user can go to hell.