Restrict apps, but can still log in via browser.
I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.
Restrict apps, but can still log in via browser.
I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.
Assume that if someone has your unlocked phone they own your life.
This isn't paradoxical. You treat the browser as a less trusted security domain than a phone, which usually has a secure boot chain, strong sandboxing, encrypted disk, reliable hardware cryptography etc, and therefore provide a different/better service on the phone. If a phone is missing one of these expected components then you're not the target market for the app, I guess. (Of course, your phone OS might be perfectly good, and the stock one might be crap, but the app developers don't care.)
It's completely ridiculous that I can't use my mobile banking app for day to day low risk, low volume transactions if my phone is rooted, yet I can do anything and everything with high values of cash and credit from a Linux machine running any web browser I wish, as root.
The reality is, the mobile app development is outsourced to incompetent teams for presumably the lowest price who "ensure security" by just saying, "lets chuck a library in that prevents running if the device is detected as being rooted, and call it a day".
These are protections any reasonably technical user can circumvent with the likes of Magisk and still, all to do far, far less damage than is possible than if they were to use a web browser.
I don't understand, why people think so. Banks hire good developers. They don't pay them well (by banks' own standards), but they still pay enough to hire competent programmers.
Unfortunately, working in bank is highly competitive environment, that fosters sycophants and rewards socially adept people, good at obeying orders to letter. Who cares, what the programmers think, they are at the bottom of command chain anyway.
The fraud prevention is often split into it's own department. As for "computer security" department, it is a fang-less security circus, that exists to satisfy PCI DSS. In some banks it outright pretends, that web sites and mobile apps don't exist. All your data will be processed in "secure server enclave", managed by "certified professionals", while sending hashes of credit card numbers to Google Analytics.
Don't give them any ideas. They'll just ban Linux browsers now.