As a small tidbit of information, did you know iPhone users are ~40% less likely to default on a small loan than Android users (at least in my country).
And the differences go all the way to specific models, OS versions, installed apps, IP range, browser of choice...
From the perspective of a company, these things boil down to numbers. They have the data, and they can review it. If they find a correlation like that they lost large numbers to rooted phone, they will ban it.
I have had email forwarders and @protonmail.com accounts get blocked only because they are more likely to be fraudulent and companies can just block because the hassle isn't worth it.
Typically, the only thing an app offers that the web site doesn't is paper check scan and deposit. Do you really need this? I don't.
Lots of people seem to be unaware that a web site can be pinned to your home screen with an icon --- just like an app.
Tying account access to one small, portable, highly vulnerable device with questionable reliability is an inherently bad idea in my opinion. Lose access to the device for any reason (lost, stolen, dropped, the fingerprint reader fails or the phone simply dies) and you also lose access to your account.
I prefer to simply create decent login credentials and store them only in my head --- not in a app and not in a web browser either. This way, when (not if) my phone stops working, I can immediately switch to an older backup phone without missing a beat.
I tie my bank accounts to two devices in case one goes wrong, and neither of those leave the house to reduce the chance of getting lost or stolen.
Of course, the phone has Apple Pay and keychain access ...
The "benefit" of Apple Pay is that by regular use, I am constantly reminded where the phone is. The watch hasn't griped about leaving the phone home when I take a spin around the "estate" here, so I'll check on that today. Matter of fact, neither does the phone when I drive off, leaving the other Apple goodies home.
More settings to check.
I'm not aware of any US bank that *requires* an app. This rules out access from a desktop doesn't it?
You use the same procedure you used to register that phone, to register a new one.
> This rules out access from a desktop doesn't it?
Using the phone for 2FA means you are accessing from a desktop, and using the phone only as an extra confirmation for the transaction.
May not be possible if you need your old phone to login.
This reminds me of Internet Service Providers who direct you to get support online when failure to get online is the very reason why you need support.
If your phone die, you replace it or do your operations at the ATM or at the counter during opening hours.
Replacing it is the problem. This can't be done at an ATM and if you're on a trip or you use an online bank, a counter may not be available.
The root cause is malware. Intercepting the online banking session in the desktop browser to steal your money used to be very common.
Get your wallet’s private key yoinked and wallet drained? You are done.
And you get the added benefit of a highly volatile asset! Broke in 2023, but hitting it big in 2024.
I suppose you can just move assets into a stable coin, but what’s the fun in that?
(Being sarcastic by the way)
I doubt there’s any bank willing to design a custom legal agreement for those folks. The central bank system sort of relies on these systems as part of the FDIC member requirements. By opting out, you may also be opting out of insurance on your money in case of insolvency.
They could even check how able you are by making you fill forms, like they do it if you want to buy risky stocks.
And executives don't have enough tech knowledge to discern between security measures that are actually effective or not, so to avoid risks they just make their tech teams implement it because the consultancy said it should be done
Had a similar situation in my current job, and unfortunately it is not something worth picking a fight with senior leadership for.
Ironically most of these companies allow access from Web Browsers (which are completely controlled by the client).
The website is a legacy option and it will be removed eventually. Already many banks require to use their app in order to sign in to the website or approve transactions. New "challenge banks" are app-first. For example, Starling Bank will not let you create an account without a Google or Apple smartphone.
I also loathe that US banks don't use standard TOTP (which they could implement for free) but instead only offer SMS or app-based Symantec tokens, which are either insecure or impossible to backup.
Bigger banks meet the minimum standard for regular users and often hard tokens for bigger customers.
Source: I've had to add this to some apps I've worked on. I tried convincing managers and gave up. They _really_ think it adds security. Our apps didn't even handle sensitive user data or anything. It just looked good on some security report they ordered.