Now my Pb bank and mae app I see gave such warning.
How can developer mode and USB debugging mode breach bank app security?
How will android developer mode breach bank app?
How will android developer mode breach bank app?
|
|
Mar 3 2025, 04:26 AM, updated 9 months ago
Show posts by this member only | Post
#1
|
![]() ![]() ![]()
Junior Member
345 posts Joined: Aug 2021 |
Now my Pb bank and mae app I see gave such warning.
How can developer mode and USB debugging mode breach bank app security? |
|
|
|
|
|
Mar 3 2025, 04:29 AM
Show posts by this member only | IPv6 | Post
#2
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,506 posts Joined: Apr 2020 |
|
|
|
Mar 3 2025, 06:11 AM
Show posts by this member only | IPv6 | Post
#3
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,974 posts Joined: Dec 2011 |
if use Samsung, can use Samsung Knox.
|
|
|
Mar 3 2025, 06:24 AM
Show posts by this member only | IPv6 | Post
#4
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
5,968 posts Joined: Jan 2003 From: KL, Malaysia |
Maybe it is used by scam app to read certain details like key logging to work…
|
|
|
Mar 3 2025, 07:25 AM
Show posts by this member only | IPv6 | Post
#5
|
![]() ![]() ![]()
Junior Member
429 posts Joined: Jun 2005 From: Cyberjaya |
Buy another phone lah...haha
|
|
|
Mar 3 2025, 08:24 AM
Show posts by this member only | IPv6 | Post
#6
|
![]() ![]() ![]() ![]()
Senior Member
590 posts Joined: Jan 2007 From: Ranau, Sabah |
last time bank rakyat apps also refuse to login when detect dev mode. only cimb don't mind, but that shitty app is in a league of it's own.
as the name imply, developer mode is for developer to test and modify the system. for normal mode of operation, any admin right or modification to the system should not be allowed at all. otherwise, rogue app can potentially exploit them. in short, they are a potential security risk. the most risky element is still the user 🤣 PEBKAC |
|
|
|
|
|
Mar 3 2025, 08:34 AM
Show posts by this member only | IPv6 | Post
#7
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,623 posts Joined: Oct 2010 |
|
|
|
Mar 3 2025, 08:48 AM
Show posts by this member only | Post
#8
|
![]() ![]() ![]() ![]()
Senior Member
545 posts Joined: Mar 2006 From: The Weirdo River O_o |
Keyword = USB. Don't plug into unknown charging port, always use your single factory out charger, and don't install app outside of play store. You will be fine. Been using dev mode on android for the past 10 years, still safe
|
|
|
Mar 3 2025, 09:50 AM
Show posts by this member only | Post
#9
|
![]()
Newbie
30 posts Joined: Oct 2011 |
QUOTE(MrBaba @ Mar 3 2025, 04:29 AM) Yr like putting yr wallet at places where every one can see and access , when yr wallet kena stolen shock Pikachu pulak QUOTE(WhatMan @ Mar 3 2025, 08:34 AM) Actually disagree with this example, even usb debugging is enabled, you still need to trust the device first to access, so there is still one more security layer to go through.QUOTE(Paradigmata @ Mar 3 2025, 04:26 AM) Now my Pb bank and mae app I see gave such warning. developer mode usually not the issue but the usb debugging/wireless debugging, but some developers just simply choose to checking for developer mode instead of specific feature block.How can developer mode and USB debugging mode breach bank app security? I would say it's for prevention and to cater for "don't know what they are doing" person and this affect legit users. Banks probably use owasp-mastg as guideline. - to reduce attack vector (to the bank app or the user). - harmful / unknown sources app can still trick user to make it as trusted device. - someone has your unlocked device access and install harmful apps. - if there is a new exploit to bypass trusted access. - unknown charging/usb port that try to gain trusted access and some people will just simply click trust it because it disturb what they are doing and don't know what is it. - unauthorized screen mirroring/remote/key-logging (after gained trusted access). - and probably more |
|
|
Mar 3 2025, 11:03 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,573 posts Joined: Apr 2006 |
It looks like the myPB bank app also thinks the apps/updates installed by the phone maker via regular OS updates (but not via Playstore) are red flags. Hint...Oppo. Not sure about other phones but should be the same.
This post has been edited by yeeck: Mar 3 2025, 11:04 AM |
|
|
Mar 3 2025, 11:31 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,068 posts Joined: Oct 2009 From: Kuching, Sarawak |
|
|
|
Mar 3 2025, 11:32 AM
Show posts by this member only | IPv6 | Post
#12
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,030 posts Joined: Jan 2022 |
QUOTE(Paradigmata @ Mar 3 2025, 04:26 AM) Now my Pb bank and mae app I see gave such warning. Why do you turn on your developer mode permanently, TS?How can developer mode and USB debugging mode breach bank app security? Can't you just turn it off under settings, developer options and only enable it when you need to do debugging? |
|
|
Mar 3 2025, 11:42 AM
Show posts by this member only | IPv6 | Post
#13
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,030 posts Joined: Jan 2022 |
QUOTE(yeeck @ Mar 3 2025, 11:03 AM) It looks like the myPB bank app also thinks the apps/updates installed by the phone maker via regular OS updates (but not via Playstore) are red flags. Hint...Oppo. Not sure about other phones but should be the same. They do that because they want to force install their malicious apps in your phone and don't want you to remove them on purpose.Some of these telemetry apps even steals your surfing habits, data which you use daily and many of your personal inputs reporting them back to the manufacturers servers claimed for improvement purposes.It actually work both ways. Those ad blocker apps actually do you good but the content ad-tracking companies such as Google and Meta don't like you blocking their ads for loss of revenues. So they include those apps as illegal/security risks tools in their security patches. Knowledgeable users of course know what they're doing, those ad-blocking/telemetry apps are not security risk apps but are revenue loss to Google/Meta. But why do you think these corporations include them as illegal risky security apps under their security patches? |
|
|
|
|
|
Mar 3 2025, 11:49 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,757 posts Joined: Mar 2007 From: _|_ |
my in law punya phone dev mode is not even on also keep triggering this issue.
the only way for me to bypass this is to turn on and off again the dev mode. then it will appear again after a week or two on random interval. |
|
|
Mar 3 2025, 11:55 AM
Show posts by this member only | IPv6 | Post
#15
|
![]() ![]() ![]() ![]() ![]()
Senior Member
982 posts Joined: Sep 2005 From: Selangor |
Techincally speaking, the developer for bank don't want to risk anything.
Having the app install from Official store (Play Store/ Huawei Store/ Samsung Store), is the only best bet they can trust for security. Usually those app that content malicious intent / trojan will get flag and not able to publish in official store. Unless it is so new, that is able to goes under radar.. "happen before". Having developer mode is not an issue, as I'm using it to change some settings on the phone. e.g: Animation / Transition Speed. USB Debugging Mode is the real backdoor. In order to use USB Debugging Mode, developer mode need to be turn ON. So to say, the developer for banking app just playing it safe below limit. *Some banking app did flag some app installed from Samsung Store / Huawei Store.. the developer need to do better filtering, or there's no API to check that* This post has been edited by shinichi88: Mar 3 2025, 12:01 PM |
|
|
Mar 3 2025, 11:55 AM
|
![]()
Newbie
30 posts Joined: Oct 2011 |
QUOTE(petpenyubobo @ Mar 3 2025, 11:42 AM) They do that because they want to force install their malicious apps in your phone and don't want you to remove them on purpose.Some of these telemetry apps even steals your surfing habits, data which you use daily and many of your personal inputs reporting them back to the manufacturers servers claimed for improvement purposes. I think you misunderstanding this, he mean the bank apps check for apps that not installed from Google Play Store, but some chinese phone manufacturer (xiaomi, poco, oppo, etc) come with preloaded apps that are not downloaded from Play Store.It actually work both ways. Those ad blocker apps actually do you good but the content ad-tracking companies such as Google and Meta don't like you blocking their ads for loss of revenues. So they include those apps as illegal/security risks tools in their security patches. Knowledgeable users of course know what they're doing, those ad-blocking/telemetry apps are not security risk apps but are revenue loss to Google/Meta. But why do you think these corporations include them as illegal risky security apps under their security patches? The android developer usually either, many of them are iphone user or using those samsung, etc, company didn't provide variety of testing phone brand to test or any cloud devices service. The developers will need to whitelist those preloaded apps if they are implementing this mechanism. |
|
|
Mar 3 2025, 11:56 AM
Show posts by this member only | IPv6 | Post
#17
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,030 posts Joined: Jan 2022 |
Why do you think Chrome intentionally block plugins such as uBlock recently few months back? Are they actually improving your security by not allowing you to block their ad-trackers? Or they are actually trying to protect their own revenues/interests? People need to have some common sense. The devil will not tell you that he's feeding you poison, he will say this is nourishment for you to take regularly and so are their security patches which will block you from taking away their revenues. Get it? evilhomura89 and adamw liked this post
|
|
|
Mar 3 2025, 12:20 PM
Show posts by this member only | IPv6 | Post
#18
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,030 posts Joined: Jan 2022 |
QUOTE(kelvinng92 @ Mar 3 2025, 11:55 AM) I think you misunderstanding this, he mean the bank apps check for apps that not installed from Google Play Store, but some chinese phone manufacturer (xiaomi, poco, oppo, etc) come with preloaded apps that are not downloaded from Play Store. There was once, when I used ad-blocker on my phone those banking apps wouldn't load.I think it's still happening occasionally..The android developer usually either, many of them are iphone user or using those samsung, etc, company didn't provide variety of testing phone brand to test or any cloud devices service. The developers will need to whitelist those preloaded apps if they are implementing this mechanism. What does that mean? Our online bank portals have been known to use malicious domains that are being abused by ad trackers? Do the banks prefer you to receive malicious ads and are encouraging you not to install ad-blockers for "their" security reasons of protecting their ads revenues side businesses? |
|
|
Mar 3 2025, 01:13 PM
|
![]()
Newbie
30 posts Joined: Oct 2011 |
QUOTE(petpenyubobo @ Mar 3 2025, 12:20 PM) There was once, when I used ad-blocker on my phone those banking apps wouldn't load.I think it's still happening occasionally.. I think your reply already out of the topic and not relevant, suggest you to reread what he said again. What does that mean? Our online bank portals have been known to use malicious domains that are being abused by ad trackers? Do the banks prefer you to receive malicious ads and are encouraging you not to install ad-blockers for "their" security reasons of protecting their ads revenues side businesses? 1. Public bank apps flagged one of his installed apps as red flag (which most likely mean from unknown source or not from Google Play Store) 2. The apps actually pre-installed or downloaded through the OS update from Oppo (can be Oppo Camera/Gallery apps or whatever, I not sure as I not using Oppo), but Public bank app only check for apps that installed/downloaded from Play Store which disqualified these apps. 3. I didn't use public bank so I assume the user blocked from using the public bank app. |
|
|
Mar 3 2025, 01:49 PM
|
![]() ![]() ![]() ![]()
Junior Member
596 posts Joined: Dec 2010 |
i use dev mode to remove the stock system animations, all my android devices load and transition between apps very smoothly without the stock animations |
| Change to: | 0.0143sec
0.20
5 queries
GZIP Disabled
Time is now: 2nd December 2025 - 08:37 PM |