How can I defend myself from banking apps?

Hi, I’m in a tough situation because I’m currently looking to switch my banks. I’ve found this new bank that operates solely through an app and that requires to give some data up, I.e. the IMEI of my phone.

Right now I’m using a Pixel 8a with Graphene OS installed. I am a that my custom ROM may give me some problems in the future due to the Integrity API.

My current banking app is a privacy nightmare anyway but I don’t think it has access to my IMEI. Would GrapheneOS defend me from this kind of data collection?

Thanks for the attention!

If you can even avoid using the app and only use the website for your online banking, that’s best. Otherwise, with banking, you do what you need to use to app.

This question however is really for the GOS forum though. But others can answer this better. I have limited know how about banking apps on GOS. I only use the website.

Like JG said, it’s best to ask their forum, but my guess is NO because GrapheneOS might be able to stop apps from extracting hardware identifiers, but if you give them your IMEI number, then they will have your IMEI number. And is this new bank anymore private then your current bank? I’m assuming they will ask for the same PII and an IMEI on top of that due to being an app-only bank.

Apps don’t have access to hardware identifiers like the IMEI number.

1 Like

@CM2 is using a neo-bank that is app only. Although I have an account with such a bank, it is not my default account, and I would advise anyone against using an app only bank as their main bank. Especially if you travel regularly, but even if you don’t. The advantage of a traditional bank is that you can physically go to their branch if there is ever an issue. You can also call them.

That being said, a lot of traditional banks these days will require you use their app as 2FA. Meaning that if you try to do a transaction via web, they will ask you to confirm it on your phone via their app.

I don’t know the answer to your question, OP, but if I were in your shoes, I would not rush things. Ask the neo-bank why they need the IMEI of your hone and if there is an option to opt-out.

1 Like

I thought user installed apps didn’t have access to IMEI since Android 10?

From direct experience, find a bank that works via a web browser only. If they require an app, find a new bank.

If you tell the bank you don’t have a spy/smartphone and they cannot help you, then find a new bank.

I don’t use a mobile phone. I’ve had zero issues with banking.

3 Likes

Not sure it’s part of the topic directly but you can check ahead of time if your future bank is compatible with GOS here: Banking Applications Compatibility with GrapheneOS | PrivSec - A practical approach to Privacy and Security

1 Like

Sadly, I cannot avoid that, in that case. The bank service is designed to push the usage of the app, they don’t have a web app.

Thanks for the exhaustive answer mate.

1 Like

The privacy policy states they will actually get the IMEI code, if I start using the app.

There is no way they do not have a website like every other bank in the world. A bank cannot exist just with an app as far I know. This is very odd.

I mean, to be more precise, they have a webapp. But if you want to open a new account you must do so through the app.

Odd. If a bank has such peculiar requirements, I would consider another one. But that’s just my opinion.

1 Like

In EU, it is quite a popular thing to go through the mobile app for security reasons.
Very common tbh (especially for neo-banks, not the case for classic old school ones). :smiling_face:

Some apps don’t even allow you to login into a Web version to check your account.
Or they at least try to hide it as much as possible.

2 Likes

I see. I have never been to your continent. I’m familiar with North America, Middle East and South Asia.

Wow. Every time I think I’m liking EU more and more, shit like this stops me. Every place has its pros and cons I suppose.

1 Like

Then the privacy policy is outdated. Regular Android apps can’t get your phone’s IMEI.
I don’t understand this dystopia where you have to use a bank’s phone app. You can’t call them or go to a branch to open the account and then just use the web app?

Hahaha, maybe people will understand why Revolut isn’t that bad in comparison now. :joy:
Banks in EU are…very KYC and annoying. Sometimes you also just don’t have a choice…

1 Like

Apparently, neo banks are not this and work differently.

I will stick with my brick and mortar even if the accounts have monthly fees on there.

1 Like

Buy a separate phone for invasive apps.

3 Likes