• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login
UBports Robot Logo UBports Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Register
  • Login

The banking situation

Scheduled Pinned Locked Moved Support
28 Posts 13 Posters 5.2k Views 4 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      Emphrath @cliffcoggin
      last edited by 6 Jan 2021, 09:55

      @cliffcoggin Well actually that's what I'm going for in the discussiobs with my bank now, but they seemed to imply something truly scornful like: "this is for old people" and also it seems it works only for checking ur bank account. I'll look into other banks. @Flo This kind of secure environment surely can be replicated in UT, no ?

      1 Reply Last reply Reply Quote 0
      • F Offline
        Fla
        last edited by Fla 1 Jun 2021, 10:06 6 Jan 2021, 10:03

        I am facing a similar situation. I created an account in a bank and then received a letter asking me to download the HID Approve application on the Play Store or App Store.
        I am then supposed to scan the QR code they send me to initiate the app, which will then give me a code each time I want to access my bank account.

        Interestingly, they also gave me an ID, a code invitation and the "Service Address" which is taurus.pbgate.services:443/HIDCAF in case of "Manual synchronization".

        Here is the content of the QR code btw: {"ver":"v4","url":"taurus.pbgate.services:443/HIDCAF","uid":"XXX","did":"XXX","dty":"DT_TDSV4","pch":"CH_TDSPROV","pth":"AT_TDSOOB","sec":"","pss":"XXXX"}

        I searched a bit and found this gnome app which proposes a lot (probably around 500) of providers (@Emphrath maybe yours is in). Unfortunately, no trace of my bank or "HID".

        Still, as I have the information to connect to the server, I feel like something can be done from our side to solve this problem.

        E D 2 Replies Last reply 6 Jan 2021, 11:03 Reply Quote 0
        • E Offline
          Emphrath @Fla
          last edited by 6 Jan 2021, 11:03

          @fla sadly, no qr code for me. Just the bloody app.

          1 Reply Last reply Reply Quote 0
          • D Offline
            domubpkm @Fla
            last edited by 6 Jan 2021, 13:22

            @fla said in The banking situation:

            a lot (probably around 500) of providers

            Can you put the link of supported providers ? I can't find it. Thank you

            F B 2 Replies Last reply 7 Jan 2021, 10:49 Reply Quote 0
            • A Offline
              AppLee
              last edited by 6 Jan 2021, 14:19

              Bank apps probably use TOTP or HOTP that should be no secret to give us (customers) an alternative way to generate this one-time-password so we can configure Authenticator-NG accordingly.

              If I'm correct HOTP uses Android secure environment so this might be an issue for us.

              But compliant solutions exist that we can use on UT, banks just don't like to be transparent about the technical solution they use.

              E 1 Reply Last reply 6 Jan 2021, 17:29 Reply Quote 0
              • E Offline
                Emphrath @AppLee
                last edited by 6 Jan 2021, 17:29

                @applee But the thing is they don't have to release any code at all ! I guess you can publish proprietary software on the openstore, can't you ?

                F 1 Reply Last reply 6 Jan 2021, 19:14 Reply Quote 0
                • F Offline
                  flohack @Emphrath
                  last edited by 6 Jan 2021, 19:14

                  @emphrath You could, yes. At least we would find a way, there is no technical limitation.

                  My languages: πŸ‡¦πŸ‡Ή πŸ‡©πŸ‡ͺ πŸ‡¬πŸ‡§ πŸ‡ΊπŸ‡Έ

                  1 Reply Last reply Reply Quote 0
                  • F Offline
                    flohack @cliffcoggin
                    last edited by 6 Jan 2021, 19:16

                    @cliffcoggin EU made it so that banks can choose which 2FA they offer. Some German banks still deliver physical devices as an alternative (which you have to pay), then my house bank still uses SMS.

                    But 95% of all banks in Austria moved to Android/iOS Apps, they are the cheapest form for them, no device, no SMS to pay for. The user pays for himself basically πŸ˜‰

                    So I must say, I cannot really change to another bank, and hope that mine will not stop SMS codes soon...

                    My languages: πŸ‡¦πŸ‡Ή πŸ‡©πŸ‡ͺ πŸ‡¬πŸ‡§ πŸ‡ΊπŸ‡Έ

                    E 1 Reply Last reply 7 Jan 2021, 00:43 Reply Quote 0
                    • J Offline
                      Josele13
                      last edited by Josele13 1 Jun 2021, 22:17 6 Jan 2021, 22:02

                      Is it possible that Morph can connect to a 2FA authentication key to validate with the bank?

                      Or would the banks not accept it?

                      https://mightygadget.co.uk/yubico-launches-lightning-compatible-hardware-2fa-security-key-the-yubikey-5ci/

                      https://www.yubico.com/

                      Regards...

                      Xiaomi Redmi Note 9 pro
                      Oneplus Nord 100
                      Xiaomi Redmi Note 7
                      Nexus 5
                      Bq E4.5 Ubuntu edition .... is dead

                      1 Reply Last reply Reply Quote 0
                      • G Offline
                        Giiba
                        last edited by 6 Jan 2021, 22:18

                        Wouldn't it be possible for banks to do this the same way so many sites do? We have two authenticator apps on the store for UT, they work fine for Mozilla, Google, and other sites that do 2FA.

                        I'm able to use my bank's website through Morph to do my banking without issue.

                        F 1 Reply Last reply 6 Jan 2021, 22:40 Reply Quote 0
                        • F Offline
                          flohack @Giiba
                          last edited by 6 Jan 2021, 22:40

                          @giiba Somebody told the banks that if its not executed in a trusted, secured environment its not safe. So, a web TOTP or whatever will not be accepted. And they have a point with that. The Secure Execution Environment in Qualcomm SoCs is much better than doing nothing. Also signed app, signed OS, signed everything xD

                          My languages: πŸ‡¦πŸ‡Ή πŸ‡©πŸ‡ͺ πŸ‡¬πŸ‡§ πŸ‡ΊπŸ‡Έ

                          1 Reply Last reply Reply Quote 0
                          • E Offline
                            Emphrath @flohack
                            last edited by 7 Jan 2021, 00:43

                            @flohack well, after some calls with my bank it seems i'm going with one of these physical gadgets ^^

                            1 Reply Last reply Reply Quote 1
                            • F Offline
                              Fla @domubpkm
                              last edited by 7 Jan 2021, 10:49

                              @domubpkm I didn't find the list either, but I still have the app installed, tell me the one you are looking for and I'll confirm to you if it's there.

                              1 Reply Last reply Reply Quote 0
                              • B Offline
                                bodqhrohro @domubpkm
                                last edited by 12 Jul 2021, 23:14

                                @domubpkm https://2fa.directory/

                                L 1 Reply Last reply 13 Jul 2021, 04:17 Reply Quote 0
                                • K Offline
                                  Keneda @domubpkm
                                  last edited by 12 Jul 2021, 23:57

                                  @domubpkm
                                  Sorry for such late answer...
                                  Disabling uAdblock worked for website, however, soon they'll force customers to use their banking app to pay online so, i'll be in this "banking situatiin" the OT thread describes.

                                  2015-2023 : Meizu MX4 ☠️⚰️✝️
                                  2023-2024 : Nexus 5 ☠️⚰️✝️
                                  2024-***** : FPOS Fairphone 5 waiting UT for freedom πŸ˜‰
                                  πŸ‡²πŸ‡«πŸ‡¬πŸ‡§

                                  D 1 Reply Last reply 13 Jul 2021, 07:21 Reply Quote 0
                                  • L Offline
                                    Lakotaubp @bodqhrohro
                                    last edited by Lakotaubp 13 Jul 2021, 04:17

                                    @bodqhrohro Hello and welcome to UBports. Just a quick point, posting a link without any explanation looks a bit like spam. You might also find this link useful https://ubports.com/meet-the-community

                                    1 Reply Last reply Reply Quote 0
                                    • D Offline
                                      domubpkm @Keneda
                                      last edited by 13 Jul 2021, 07:21

                                      @keneda Multiple responses (in no particular order):

                                      • Change bank;
                                      • Change phone;
                                      • Hope the new anbox (will be useful for the COVID app in France...) will work on one of your current phones.
                                      • maybe another answer to your problem..

                                      This reflects the current climate for french where we are/will be ..... everywhere (replace the dots with your favorite word), if you guess (a clue, I DON'T SPEAK of UT..) πŸ˜‰

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post