Skip to content

Comment on Technical Analysis – Improper Use of Private iOS APIs in Vietnamese Banking Apps

Comments

Sadly, it goes well beyond BIDV and Agribank as well. There is a lot of similar hacky fingerprinting done by all the Vietnamese banking apps.

My understanding is it's because there was some regulatory change in the last 1-2 years requiring identity fingerprinting using banking apps, and partially related with the new biometrics rollout [0]

[0] - https://xaydungchinhsach.chinhphu.vn/huong-dan-cai-dat-sinh-...

So the law is now requiring that you find zero day exploits in iOS in order to make a banking app? Are there banking websites you can use instead? Are criminals incapable of using these websites for malicious purposes?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.