FBI warns hackers are targeting mobile banking apps
thehill.com
thehill.com
I would like to know who these people are who would download their banking apps from hax0rs.rus rather than, you know, the app store where they get all their other apps from.
False [1,2]. For a while iOS was hanging in there because persistence was difficult, but not anymore.
Banking on your phone, unless it is a segregated account with limited funds, is a seriously bad idea.
[1] https://www.wired.com/story/android-zero-day-more-than-ios-z...
[2] https://www.cyberscoop.com/ios-zero-day-zerodium-high-supply...
If your device can be persistently compromised and you use it for general purpose browsing/email, it follows that using it to manage your money is a seriously bad idea.
I linked an article that says the opposite.
> I haven’t heard of anyone persistently compromising iOS for quite a long time
a thread from a few weeks ago: https://news.ycombinator.com/item?id=23287364
> nobody is going to leverage on of those to part you from a couple thousand dollars
If the cost of countering the threat is using a $40 Raspberry Pi to do your banking, what's the problem?
So exploits for iOS have recently been published whereas Linux and Firefox have warm and fuzzy associations, so clearly Linux and Firefox will work better than iOS in this case. Is that your argument?
(I mention Firefox because all of the online banking arrangements I know of rely on iOS, Android or a web browser.)
> who would download their banking apps from hax0rs.rus
Having empathy with users that don't act perfectly skeptical 100% of the time and who don't read all of the text (like none of us read 100% of the EULAs every time we click the "accept terms" button/checkbox) will allow us to build systems which are more robust to the occasional distracted user, overlooked typo, user who doesn't know how o mentally parse a URL to identify the domain, etc.
Also, there are plenty of people on HN that advocate for breaking down all of the walled garden app stores, which necessarily means that users would have a higher cognitive load of researching which domains are more trusted app stores. It's ridiculously easy not to accidentally download an iOS app from a 3rd party app store, because they simply aren't possible without jailbreak / install developer cert.
I think most (myself included) are just advocating for Apple to allow side-loading. They can keep their app store intact. See https://en.wikipedia.org/wiki/Apple_Inc._v._Pepper for more about an ongoing case
Browsers used to allow any software to side-load extensions and you know how that went: They all moved to store-only installs because all kinds of software were able to affect the browsers.
Same way for side-loading apps to your phone. Sure it’s more difficult than just tapping something on the web, but it doesn’t mean it’s safe for the end user.
How about the bank's own website? I trust that more than any "app store" (which is, after all, run by a third-party) for downloading its app.
Return navigating to the bank website by bookmark on the OS/browser is great. Via link from SMS/Email... not so much.
Phishing via email, texts and ads in apps heck even Google at times had phishing URLs come up in search results, CDNs being compromised and transport attacks (e.g. hotspots) make distribution over browsers a problem.
AppStores allow you at least in theory to validate an app not only to be the app that you want to download but also that the app does what the developer claims it does, it also facilitates distribution segmentation by region and device (especially important for Android) and automatic updates.
Not sure about you but I’ll trust the Apple AppStore more than any given bank website simply by being familiar with the security teams and practices in FAANG vs commercial banking.
Customerprotection@Yourbank.com
Probably even my tech/developer etc friends some might click that update.
They (or we) are not stupid, they just don't know better and we should try to shield them from these risks as much as possible.
You’re welcome.
This happens more often than you’d think. It’s even easier when you get targeted attacks via sms saying approximately the same thing. People don’t look at the URL bar.
I'm guessing the people that believe the hax0rs.rus version believes something like, 'get extra money on each deposit with our hacked version' or 'don't like bank fees?? Try the hax0rs.rus version to avoid those pesky bank fees'.
But more realistically, I imagine it's people clicking fraudulent links disguised as legitimate looking things from their bank. As apparent as things like that may seem to people who understand the web, it's not always obvious to people who haven't spent a million hours on the internet.
Most people eventually learn to pick up a sense about what's legit and not on the web, but it really does take a long time. I'm sure at some point over all your years of computing and interneting you've probably downloaded at least one shady application or clicked one sketchy link by mistake, I know I have, and if you haven't I commend you honestly.
Begrudgingly shlupping myself to the other room to locate my phone and get a texted code...
But, after receiving 3 different password reset emails in a short period for different services, I decided to enable 2FA for everything that supports it. Where possible, choosing the Time Based 2FA instead of texting codes (just in case I lose my phone or something).
With the right mindset (and paranoia), I'm coming around to viewing this inconvenience as necessary, and wish more services supported it.
In terms of both UX and authentication strength it's infinitely better than SMS/email/TOTP 2FA in every way. (My understanding is most alternatives, including SMS and google auth type TOTP, are still vulnerable to MitM attacks whereas U2F tokens solve that too).
A Raspberry Pi 3 is like $40.
You shouldn't be doing banking on the same device you use for generic browsing and email.
It's really strange to me that the security community isn't proselytizing "security through compartmentalization".
No? 2FA exists precisely to prevent that sort of attack model.