Where I bank is sensitive information. It has value, most especially to debt collectors, hackers, and adversaries. Hackers would love to have that info not necessarily to attack the acct but to write a convincing ransom demand. Google ties downloads to identities. The app can only be exclusively jailed in a walled garden if the source code is secret (and it is).

So users & the public can't audit the code. The bank is also untrustworthy. Perhaps you can trust your EU bank, but US banks are like a fusion between surveillance capitalism & police agencies. The only way to have a fighting chance at a trustworthy app is if it's signed on .

Show thread

@wswartzendruber credit unions are a big bump up in trustworthiness, but even US CUs are jailing their closed-source apps in 's untrustworthy , so Google knows where you bank, as well as any insiders happy to sell that data.

@wswartzendruber Regarding EU banks, they are much more of a gestapo as far as keeping your place of residency on file. So I could envision them using the location tracking to check consistency. They would probably use an ATM locator service as a cover story for why the app needs your location.

@wswartzendruber Some European banks have started closing down web access to force customers to use their proprietary app exclusively from Playstore, which means customers without GSM service or who are unwilling to share their phone number with Google are denied online access to their account.

@wswartzendruber These ppl cannot do gratis money transfers, and they must either pay a fee for mailed statements or they must make a trip to their bank once a month.

Follow

@wswartzendruber And if you think you can get the app from some dodgy APK downloader and run it in a sandboxed Android VM, the answer is no. Some (if not all) bank apps are very good at detecting whether they are running on a VM, and the app refuses to launch.

@wswartzendruber And what about innovation? When the app is proprietary closed source, I can't add features. I can't code it to automatically grab my statement, sync with my ledger, and file it where I want it, and I can't port that code to my other banks.

Sign in to participate in the conversation
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!