Configuring one’s system to always login as root in Linux is significantly easier than rooting an Android phone. One needs to know their way to root their phone and spend significant amount of time tinkering with it so that everything works properly.
As for malicious apps, there are many such apps on the Play Store as well. In fact, I would argue that the safest distribution channel is F Droid and not Play Store.
I can’t speak for foreign banks but for banks in my country, they have a problem that is way way worse than any Android stuff can solve ( read: giving access to your account only via SINGLE password and only asking for SMS OTP when transaction is done; and of course no hardware key support). I don’t wish my banking data to be less secure than a WordPress account!
In fact, I would argue that the safest distribution channel is F Droid and not Play Store.
I agree with this too! I don’t think I’ve seen any other app stores (on any platform) focus on reproducible builds.
giving access to your account only via SINGLE password and only asking for SMS OTP when transaction is done
This was a problem with US and Australian banks too. It’s still an issue in Australia, but some of the major banks in the USA have moved to sending 2FA requests to their mobile app, and either allowing OAuth or app-specific passwords to allow other services to get data from your bank account.
Configuring one’s system to always login as root in Linux is significantly easier than rooting an Android phone. One needs to know their way to root their phone and spend significant amount of time tinkering with it so that everything works properly.
As for malicious apps, there are many such apps on the Play Store as well. In fact, I would argue that the safest distribution channel is F Droid and not Play Store.
I can’t speak for foreign banks but for banks in my country, they have a problem that is way way worse than any Android stuff can solve ( read: giving access to your account only via SINGLE password and only asking for SMS OTP when transaction is done; and of course no hardware key support). I don’t wish my banking data to be less secure than a WordPress account!
relevant xkcd
Should browser startups be authenticated by biometrics?
I agree with this too! I don’t think I’ve seen any other app stores (on any platform) focus on reproducible builds.
This was a problem with US and Australian banks too. It’s still an issue in Australia, but some of the major banks in the USA have moved to sending 2FA requests to their mobile app, and either allowing OAuth or app-specific passwords to allow other services to get data from your bank account.