Most important Android setting to avoid being hacked and losing $

  • Have you been Scammed?
    Follow this advisory from National Crime Prevention Council (NCPC) or call ScamShield Helpline 1799. More info

wira

Supremacy Member
Joined
May 6, 2000
Messages
5,772
Reaction score
771
What about using NFC and tapping the bank-issued debit or credit card to the back of a NFC-enabled phone? Banks are issuing those contactless cards already, so the physical cost is already incurred. This has been easier to do with Android, but I think Apple has now opened up its NFC enough to do this.
yeah NFC using credit/debit card is an interesting idea. Trust bank already allow you to activate your credit card by just tapping your new card to back of your phone and activate via app.
could expand on this to use credit card tap for additional 2fa
 

pchan2018

Member
Joined
Jul 11, 2018
Messages
100
Reaction score
21
If you own an Android phone, this is the most important setting to avoid being hacked and losing $.

Disable "install unknown apps" option.

This will prevent accidental installation of malware which allows scammers to gain access to your bank account.

This is how you disable "install unknown apps" option. Go to Settings. Search for "unknown". Then select the appropriate option. Make sure that all apps, especially browsers and messaging apps like WhatsApp/Telegram, are disabled from installing unknown apps.

I did this for all my loved ones. Do this for your elderly parents because they are the most vulnerable group. Tell them to only install apps from official Google Play Store and only apps they need.

Check your phone settings. Do it now. For yourself and your loved ones.

Protect your $

With most banks going for mobile tokens and discarding the physical ones, our daily phones are usually going to be at risks to these kind of scams. Just want to share what i have done to (hopefully) not fall into such tactics. Taking into account all the best practices on safe surfing like just dont click or access random links or download some random apps from even playstore or itunes, or keep your phone OS and apps updated, etc. Another measure you can take is, get yourself another phone, your old phone will do as well if you have a spare one and use it as your digital token phone. That is, factory reset it if it you were using it before, then dont install anything in it, except the iBanking softwares/tokens of your banks. Dont even insert a simcard on it, just use your wifi at home. Yes, dont connect it to public wife as well, thats a big no..no.. I even tried to remove other bloat ware on it that came after the factory reset. And when you're done banking, turn it off. Its a hassle sometimes, but better endure a bit of inconvenience rather than losing your life savings to these tactics. I just hope banks go back to their hard tokens to help avoid these kind of scams out there.
 

szeli

Arch-Supremacy Member
Joined
Mar 24, 2003
Messages
21,480
Reaction score
3,162
banks should implement passkeys asap. it will remove the threat of phishing. that’s 1 less thing to worry about. no ID/password to get tricked out of
 

Nofear40

Senior Member
Joined
Dec 28, 2015
Messages
1,851
Reaction score
142
With most banks going for mobile tokens and discarding the physical ones, our daily phones are usually going to be at risks to these kind of scams. Just want to share what i have done to (hopefully) not fall into such tactics. Taking into account all the best practices on safe surfing like just dont click or access random links or download some random apps from even playstore or itunes, or keep your phone OS and apps updated, etc. Another measure you can take is, get yourself another phone, your old phone will do as well if you have a spare one and use it as your digital token phone. That is, factory reset it if it you were using it before, then dont install anything in it, except the iBanking softwares/tokens of your banks. Dont even insert a simcard on it, just use your wifi at home. Yes, dont connect it to public wife as well, thats a big no..no.. I even tried to remove other bloat ware on it that came after the factory reset. And when you're done banking, turn it off. Its a hassle sometimes, but better endure a bit of inconvenience rather than losing your life savings to these tactics. I just hope banks go back to their hard tokens to help avoid these kind of scams out there.
You do not use paynow or paylah outside?
 

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,609
Reaction score
5,597
You do not use paynow or paylah outside?
If you value security then you shouldn't use those services as they're presently designed (digital token on the same physical device).

Am I the only one getting tired of QR code-based payments? Cash is faster.
 

CrashWire

Supremacy Member
Joined
Nov 28, 2000
Messages
5,950
Reaction score
811
OCBC does not claim that this change in their mobile application is 100% effective in preventing malware scams. OCBC only claims it's helpful, not foolproof.
Probably because they'd be taking on a lot of unnecessary liability for not much benefit.

Then again, I'd heavily advocate for a bank that actually stands by their customer if the customer has taken all good faith measures to prevent getting hacked. I don't think any bank in Singapore is culturally like that, and OCBC most definitely isn't.

yah but i think its very helpful and effective.

according to reports
"OCBC said that since it rolled out the security enhancement on Saturday, the bank has not received any malware scam reports from customers who have updated their app with the new feature. It added this is in contrast to before Aug 5 when the bank received at least one malware scam report a day."
Maybe because customers can't use the app at all. :s13:
 

Nofear40

Senior Member
Joined
Dec 28, 2015
Messages
1,851
Reaction score
142
If you value security then you shouldn't use those services as they're presently designed (digital token on the same physical device).

Am I the only one getting tired of QR code-based payments? Cash is faster.
I do not have nearby atm
I think the government is pushing us towards cashless
 

010919

Junior Member
Joined
Sep 1, 2019
Messages
43
Reaction score
13
Would appreciate if you don’t quote him.
I have blocked him ages ago.
I see a green box whenever you quote him. Thanks.

Aiyoh, why you keep going back on this? As TS say, the important thing is to check that the dangerous setting is disabled lah.
 

bagyidaw

Senior Member
Joined
Feb 19, 2012
Messages
2,425
Reaction score
191
how about those security vault like samsung secure folder ? it's totally isolated from the rest of systems. install critical applications inside there and lock with passcode.
 

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,609
Reaction score
5,597
how about those security vault like samsung secure folder ? it's totally isolated from the rest of systems. install critical applications inside there and lock with passcode.
Once an attacker "owns" a device all bets are off.
 

bagyidaw

Senior Member
Joined
Feb 19, 2012
Messages
2,425
Reaction score
191
AFIAK most of the *hack* are not technically sophisticated but rather social engineering, guiding victim to disarm all locks/security measures. education is more important..:)
 

BBCWatcher

Arch-Supremacy Member
Joined
Jun 15, 2010
Messages
24,609
Reaction score
5,597
Depends on what you mean by own?
Unless attacker got passcode for the vault, unless they somehow cracked it. But it shouldn’t be that easy
If you have key/tap logging and can view the display, you're at least pretty close.
AFIAK most of the *hack* are not technically sophisticated but rather social engineering, guiding victim to disarm all locks/security measures. education is more important..:)
That's part of the problem, but the other part is design. You can't win if the systems are security defective by design.

The banks and government got rid of physical tokens because they were "expensive." But that's a step backwards in terms of security.☹️
 

duhduhduh

Arch-Supremacy Member
Joined
Sep 5, 2009
Messages
14,971
Reaction score
1,161
Depends on what you mean by own?
Unless attacker got passcode for the vault, unless they somehow cracked it. But it shouldn’t be that easy
With people saving their password in Notes app that is unencrypted... not difficult to crack, even if they put things into the vault
 

HMAN

Supremacy Member
Joined
Jan 6, 2002
Messages
5,359
Reaction score
721
under Android camp, the following few items are critical to safeguard yourself..

1. understand the risk, never install unknown app from unknown sources.
default, install unknown app is disabled for most suppliers.

2. understand the phone source, do not use custom ROM,rooted ROM.
even if is open source, the complexity is beyond public can comprehend.back door can be planted there.
watchout to buy phones from China sources that repacked the Google services to the China ROM.



3. app permissions.
a. strictly no sms read /whitepermission given.
this is given up the right of one of your default SMS app, the malicious app can hijack,suppress notification and read the OTP and rerouted it out.


b. screen overlay
this allows the malicious app to away occupies the screen top layer. it can create fake screen to lead victim user to key in passcode As if using the real app


4. how to check fake website.
for this part, most paper security expert will fail to provide proper guidance. unfortunately this is the most common hack deployed.

current phone app that providing 2nd authentication is with flaw, as it does not provide mutual authentication to validate the website user login is a genuine valid site.

current phone app just provide a single button to accept is with weak security. a single button event can be generated randomly to trigger acceptance, user may slip and trigger the acceptance.

since bank is not helping, user need to learn to deter this fake website.
a. manually check the URL, make sure the domain is right, religiously write down the domain suffix, e,g for dbs, it is always end with xxx.dbs.com.dg , the dbs.com.sg is the part user need to know.

take a picture of it and save it in computer desktop page to refer to

b. check the locked icon, double click down to trace to the digital certificate, make sure the digital certificate is bearing the same domain ,e.g dbs.com.sg



c. detect fake websites
purposely key in wrong id/wrong passcode one time. wrong website will give way, if you see screen flickers with weird behavior, stop there and check the URL one more time.

d. do not use copy and paste function
use your visual aid and manually typing in passcode..
keyboard copy/paste is common butter, most apps can read this keyboard common buffer.

wish list
1. banks to implement bi-directional authentication over the phone app and the web site.

a simple watch dog secured stream of synchronize messages appear on both phone app and the bank website throughout the usage session will lock out fake website which can't catch up with the watch dog stream deployed by bank server.

personally,I have a Chromebook that Google keep maintaining its to the latest, my banking access mostly going though this Chromebook that 99% time is offline till I wanna access. strictly no extension installed.


Chromebook doesn't need virus scan rubbish..










Read HWZ Forum Rules!
 

BBQ99

Member
Joined
Jul 29, 2003
Messages
330
Reaction score
63
Depends on what you mean by own?
Unless attacker got passcode for the vault, unless they somehow cracked it. But it shouldn’t be that easy
U can record pw in vault but add another manual encryption that is easy for u to remember. Example remember 9 is actually another # or A is actually ABC and is not just A. Or your password always starts or ends with a letter or #. So even if they get access to your password vault it is actually not the actual full or correct pw. Result is likely your account getting lock after multiple attempts.
 
Last edited:
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top