under Android camp, the following few items are critical to safeguard yourself..
1. understand the risk, never install unknown app from unknown sources.
default, install unknown app is disabled for most suppliers.
2. understand the phone source, do not use custom ROM,rooted ROM.
even if is open source, the complexity is beyond public can comprehend.back door can be planted there.
watchout to buy phones from China sources that repacked the Google services to the China ROM.
3. app permissions.
a. strictly no sms read /whitepermission given.
this is given up the right of one of your default SMS app, the malicious app can hijack,suppress notification and read the OTP and rerouted it out.
b. screen overlay
this allows the malicious app to away occupies the screen top layer. it can create fake screen to lead victim user to key in passcode As if using the real app
4. how to check fake website.
for this part, most paper security expert will fail to provide proper guidance. unfortunately this is the most common hack deployed.
current phone app that providing 2nd authentication is with flaw, as it does not provide mutual authentication to validate the website user login is a genuine valid site.
current phone app just provide a single button to accept is with weak security. a single button event can be generated randomly to trigger acceptance, user may slip and trigger the acceptance.
since bank is not helping, user need to learn to deter this fake website.
a. manually check the URL, make sure the domain is right, religiously write down the domain suffix, e,g for dbs, it is always end with xxx.dbs.com.dg , the dbs.com.sg is the part user need to know.
take a picture of it and save it in computer desktop page to refer to
b. check the locked icon, double click down to trace to the digital certificate, make sure the digital certificate is bearing the same domain ,e.g dbs.com.sg
c. detect fake websites
purposely key in wrong id/wrong passcode one time. wrong website will give way, if you see screen flickers with weird behavior, stop there and check the URL one more time.
d. do not use copy and paste function
use your visual aid and manually typing in passcode..
keyboard copy/paste is common butter, most apps can read this keyboard common buffer.
wish list
1. banks to implement bi-directional authentication over the phone app and the web site.
a simple watch dog secured stream of synchronize messages appear on both phone app and the bank website throughout the usage session will lock out fake website which can't catch up with the watch dog stream deployed by bank server.
personally,I have a Chromebook that Google keep maintaining its to the latest, my banking access mostly going though this Chromebook that 99% time is offline till I wanna access. strictly no extension installed.
Chromebook doesn't need virus scan rubbish..
Read HWZ Forum Rules!