Banking Apps on Custom Android
Cluster focuses on banking apps refusing to run on modified Android devices like GrapheneOS, rooted phones, or custom ROMs due to SafetyNet/Play Integrity checks, with debates on bank policies, security trade-offs, and workarounds like dedicated devices.
Activity Over Time
Top Contributors
Keywords
Sample Comments
I've used GrapheneOS for years and I'm doing banking on my phone just fine.
It may not be banks themselves doing this.For example, my bank here in Hungary, Erste Bank has announced that the central bank requested that they stop allowing their android app to run on "modified" devices.They even have a workaround: switch to SMS-based 2FA and use their website (which works well on any screen and has all the features of the app except 2FA)
Doesnt that force people to not only use smartphones, but "approved" smartphones (read Android/iOS) with locked bootloaders and no root access (or the bank authenticator app will refuse to run)?
Won't work for any bank apps which require a passing check through the phone cryptographic integrity chip.
You don't trust Apple's and Google's mobile phones. And some bank doesn't trust open source android distros on mobile phones. Those are both fine positions. You are free to move to another bank, just like the bank is free to not accept you as a customer.
I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"
There are already countries where all banks in the country (and often it is a mere handful; not everywhere is like the USA with a big choice of banks) already require e.g. using their app on an Android version that passes SafetyNet, in order to log in to online banking.
Don't bank apps complain if the phone is rooted or runs anything than a stock OS?
Every bank app is different. I'd advise getting a cheap phone which supports LineageOS (ROM with the widest device support) and see if it works there first. You can also try LineageOS with microG builds to see if it only needs basic verification with Play Services in order to work.
Don't most banking apps reject non-GooglePlay/unofficial-image/rooted phones?