I created a google takeout and in that zip file I found some files containing a ton of data about me. It has logged every single page I visited while using the google search engine and chrome browser. It even logged every single time I opened an app on my old android phone. It even has VOICE RECORDINGS of me and a log of every time I used google assistant. This is just some of the data and I’m very sure there is even more data they have.

        • 🦄🦄🦄
          arrow-up
          4
          arrow-down
          0
          ·
          8 months ago
          edit-2
          8 months ago
          link
          fedilink

          Will this still be true after safetynet is deprecated? Not trying to be difficult, just don’t want to get my hopes up.

          Edit: ah its adressed in the link lol

      • delirious_owl
        arrow-up
        4
        arrow-down
        2
        ·
        8 months ago
        link
        fedilink

        Why would you want to use a banking app on something as insecure as a phone??!?

        • Hamartiogonic
          arrow-up
          5
          arrow-down
          0
          ·
          8 months ago
          link
          fedilink

          When your bank tells you that the code booklet will be phased out and mobile app will be the only way in the future.

        • suppenloeffel
          arrow-up
          3
          arrow-down
          1
          ·
          8 months ago
          link
          fedilink

          As long as you don’t use some shady, unofficial ROM on a phone, most phones are actually vastly more secure than your typical Linux/Windows OS.

          • delirious_owl
            arrow-up
            2
            arrow-down
            1
            ·
            8 months ago
            link
            fedilink

            How long is your passphrase on your phone compared to your Linux/windows OS?

            A phone is designed for quick usability, which is the enemy of security.

            Sure, if you have a 20 char password on your phone and never install any sketchy apps, then it might be ok. But the whole phone ecosystem is just less secure because its designed for convince, not security.

          • delirious_owl
            arrow-up
            1
            arrow-down
            2
            ·
            8 months ago
            link
            fedilink

            Riiight, someone’s phone with a 4 digit pin that they tap out 100x per day in public in plain view of others (that I can easily pick out of your pocket) is more secure than a laptop with a 20 character passphrase that never leaves my house.

            Do you even think about what you’re saying?

            • EpicVision
              arrow-up
              2
              arrow-down
              0
              ·
              8 months ago
              link
              fedilink

              I’m talking about the security model of the platform, not the way you use your devices. If you do your online banking in a browser on your computer and your system gets infected with malware, that malware can access all the files on your computer. Including application data of your browser. It can access your cookies, which your bank’s website uses to store your login information. Such an attack is impossible on a mobile device, since apps can only access their own data, and inter-process communication is heavily restricted. Additionally, mobile operating systems like Android have complex permission systems, as well as kernel-based mandatory access control like SELinux/SE for Android. Your typical desktop OS has none of that. Android also has a strong implementation of Verified Boot, which makes sure that malware can’t persist on your system partition, even after your device gets infected. I recommend this video if you want to learn more about mobile device security: https://youtu.be/yTeAFoQnQPo

              • delirious_owl
                arrow-up
                1
                arrow-down
                2
                ·
                8 months ago
                link
                fedilink

                QubesOS and TAILS solve this issue. If people dont use those, then I recommend a distinct computer for finances only. Thats more secure than using an Android app for banking.

                • EpicVision
                  arrow-up
                  2
                  arrow-down
                  0
                  ·
                  8 months ago
                  link
                  fedilink

                  No, Tails doesn’t solve this issue at all. It’s built for maximum anonymity, not security. It also uses Tor for all connections, which will get your bank account locked immediately. Qubes is a good option for security, but it’s way too complicated for most users. Stop making up some random shit and accept that mobile devices running modern operating systems are reasonably secure and definitely more secure than your ordinary desktop.

                  • delirious_owl
                    arrow-up
                    1
                    arrow-down
                    0
                    ·
                    8 months ago
                    edit-2
                    8 months ago
                    link
                    fedilink

                    You can’t get persistent malware if all browser history and installed apps disappear every time you reboot. Yes, TAILS was designed for security. Yes, TAILS was also designed for privacy. Obviously its no longer anonymous if you log into your bank.

                    Tor Browser is by far the most hardened & secure web browser. If a bank is blocking Tor, that bank probably doesn’t understand security and its a red flag. Choose another bank. Or, better, use monero. Its way more secure than banks.

                    Disclaimer: I used to work in info security for a bank in Europe.