Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm from Brazil, where as is known many robberies and assaults happen on the street, and ever since the whole process of putting essential life services into smartphones started, many people are adopting a scheme of having 2 smartphones (if not 3 or 4 for other reasons! ) :

1) The House smartphone → it is where you install everything truly vital, like the main bank app (started mainly because of this), 2FA apps like authy google microsoft equivalents, passwords, streaming apps (to do their 2FA), etc. This phone NEVER NEVER leaves the house, except ONCE if the bank app requires on location authentication of the phone for the bank app to function, which is common practice with traditional banks.

2) The Street Smartphone → you essentially create a ''street bank account'', deposit sufficient money for day-to-day transactions for some days or weeks, install the app, and only keep this app installed for any money use (many people also avoid even using the same bank as the main bank app, as the main bank usually is a traditional bank with physical locations to get help - and has tons of personal information stored - and the street bank usually is a fin-tech bank that people do not really trust like old banks, either economically or for security, but it has less personal data anyways). It also has the essencial social media like Whatsapp, instagram, some password manager like bitwarden or the apple-google cloud, and 2FA (the ones who actually use it) is avoided in this device.

3) the thief smartphone → many people like to take some old phone around to give to a thief if the need arises, this way even the street smartphone is saved. Might not work if the thief smartphone is too old or clearly broken though.

4) the work smartphone → the only mostly chill 2nd smartphone on the list, useful to keep private life separate from the professional life, and also is useful to avoid the boss sneaking into the worker's private life and devices. There was a scandal here when a provincial government out of the blue installed a whole app in the smartphones of teachers AND students with no warning or any control whatsoever, and many people got scared that the administrative google service app being used by all (google education or some s*t) pretty much allowed the devices to be remotely controlled and viewed by the employer , be it private or public, so many people assumed any work devices is or can be done the same.



"... This phone NEVER NEVER leaves the house, except ONCE if the bank app requires on location authentication of the phone for the bank app to function ..."

Can you elaborate ?

What does this "on location" process look like ? What do they ask you to do ?


Not sure what he means, but some banking apps in Brazil have a "geofencing" feature like "only allow transactions when phone is inside this area". Presumably you set your home and work addresses as trusted.


Pardon for the delay. I'm surprised , i did not know this was not usual in other places. The biggest bank here is Bank of Brazil (state bank), and it has a lot of local physical sites in all over the country, with multiple units in bigger cities. A client ALWAYS has a main physical unit associated with their account, according to the address, and the person is required to physically go there to do many actions. There is a 2nd floor or rear area where there is a few bureaucrats or even the local manager, and the client has to appoint a meeting with them (usually by entering and waiting in a line at the moment, no internet pre-arranged way) to do stuff like big financial transactions, close or open the account, buy dollars or euros, seek advice about and start to use financial services of the bank like insurances retiremensts, etc. The front area of the 1st floor is where the money machines are located, where people usually get physical cash, pay bills, etc. The person has to use both a fingerprint and a password to authorize the operations, and of course there is cameras both in and out of the bank registering everything, and usually morning to afternoon there is a local security staff of 1 or a few (depending on the unit size). Now with the context, finally to the on location authentication mechanism: The client can download the bank app, and login, but to actually DO anything in the app, the client first has to physically go to her-his main physical unit with the smartphone to be used, and go to a money machine. There, she-he has to login in the machine using both the fingerprint and password, and do the operation of authorizing the smartphone to be associated with the account, confirm by SMS on the smartphone, and voilá. ONLY NOW can the bank app properly be used. That is why i called it 'on location authentication', the client has to go personally with the smartphone itself to a physical unit in order to authenticate the phone , so that the bank app can be used. The fin-tech banks by contrast are 100% freestyle in every way, having no physical units and not demanding any sort of protocol to do equivalent actions, and that is loved by many, but there also the issue of less security, even much less security i dare to say, which was proved by a history of many crimes and frauds happening now that used them as instruments. Many people were victims of fraudsters that created bank accounts in their names exactly in these fin-tech banks, and did shenigans like taking 5 digit loans, buying physical goods, etc.


Thanks!


I'm guessing it means you have to walk inside the bank branch, and show ID and your phone with the installed bank app to an employee who somehow authorizes the phone to use the app?


Even that doesn't seem like enough to me. You need not just multiple devices, but multiple distant locations. A fire, flood, car accident, or theft can result in the total loss of multiple devices unless one is sufficiently far away and also secure. Then there's keeping that remote device up to date. This is beyond the patience, finance, and understanding of virtually everyone.


Total security does not exist, as the saying goes. These are several counter-measures that emerged in the social sphere of common people, to increase security a few levels and hopefully avoid the worst scenarios at least. I don't think almost anyone has all 4 smartphone categories i listed, but if you ask around, most would recognize the measures you are talking about.

A disaster scenario in practice means you are screwed either way here, tons of physical documents can be lost or destroyed too, but that is a calamity that by definition is exceedingly rare.

Most are worried about common thiefs, a scenario of robbery or assault that can happen anytime anywhere and frequently, repeatedly. The overall threat here is far larger that the rare scenario.

Now, to the complexity. Usually the thief smartphone is some old phone still around, might not even be working, and no one puts anything in there, it is literally a throw-away device. It has no complexity or hassle, and usually is free. The house smartphone, people usually repurpose some old smartphone or buy a cheap android. I still have an iphone 6 for this purpose, and if the app is up to date, it usually is safe enough. People will not be using the phone for anything else, it will not leave the house, so exposition is severely reduced.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: