Security Weakness

Count yourself lucky. I’d be down a face :scream:

And I only have one other spare. :joy:

5 Likes

So you have access to a phone which has for some reason no pin/pattern/thumb/face lock enabled and also has the email account unprotected with again no thumb/face or the username/password saved.

Well you have three scenarios lost phone, random stolen phone, and a targeted attack on a high profile person.

In the lost phone, 99+% of people aren’t dicks and think oh now I have the phone I’ll try and access it, oh they have Monzo, I’ll see if I get into their email account, excellent, I’ll go through a magic link attack so I can see their account balance to see if I should be asking for a reward in finding it.

If you have your phone mugged/lost then you can obviously report to Monzo that is the case. You got to be an unlucky sod for someone to try it on before you notice it’s lost.

The third scenario we aren’t living in the Bourne Identity. The likelyhood they are using Monzo and for some unknown reason are logging out and also have no pin/pattern/thumb/face to unlock their phone, and for some reason don’t keep their savings in a separate savings account is slim. You can establish their account balance to see if they are worth kid napping / phishing to get the other credentials in the hope you can make a transfer away and hope the FBI don’t look into it.

3 Likes

You have it in one, but they don’t accept it’s a bug. It’s deliberate.

Interesting, how do they interface with the biometrics?

Lets keep it really really simple.

My issue is that when I set a security setting I don’t expect it to be unset, and if it’s really really necessary, I expect to be warned.

1 Like

Hmmmph

Lets assume everyone took the Monzo approach, which you appear to be defending.

Every time I powered down my phone it would unset its security.

Every time I logged out of my email it would unset its security.

How do you defend that?

Monzo should not be relying on other independent businesses to get its security right.

Developers use an API supplied by Apple/Google which takes over the process. The API returns essentially either “Yes, Authenticated” or “No, not authenticated”.

2 Likes

What are the parameters to the API? (Android)

I’m not an Android dev, so not my area of expertise, but assuming it’s reasonably similar to iOS, pretty much all I can set as a dev is flavour text.

What are you asking me to defend? That’s not a monzo specific way of doing things that’s how things have been for the last decade. You lock your phone either pin/pattern/thumb/face, if you have a confidential app on your phone you also have a pin/thumb/face to get into that single app. You don’t log in / log out of that single app unless it’s something where you are switching accounts where that makes sense.

Whenever you access your email you should be providing auth be that with thumb/face or username password. If you are leaving your phone without a lock, and don’t access your email via an app that requires thumb/face and then saving your username/password in your browser so you aren’t needing to type it that’s a security fail on your part.

What about powering down your phone? You shouldn’t be powering down your phone for starters, if you do and power on it’ll ask you to auth if you had a pin/pattern/thumb/face like 99.9% of people.

If you are doing banking via your phone it’s a sensible idea to turn on the lock regardless of what bank you use, otherwise you are leaving your house with the front door open. Especially if it’s trivial to access your email account.

3 Likes

I wonder if Monzo should add more friction to the ‘log out’ option, to dissuade people from using it in an unintended way. Perhaps a clear message saying “By logging out you remove your account and all settings from this device, are you sure?” and then “Are you really sure?”

I think there are a lot of people who are used to legacy banking apps where ‘log out’ and ‘remove account’ are entirely different options, or there’s overlap between the two rather than then being exactly the same.

I know my other banking/credit card apps require authenticaion to log in, and in roughly half of them if I close the app and come back later, there’ll be a message saying “You’ve been logged out because you’ve been idle.” But in Monzo’s case, if you’ve got authentication turned on, that’s equivalent to Monzo making you use biometrics to unlock the app again. Even though Monzo doesn’t say you’ve been ‘logged out’, the ultimate behaviour is the same.

I quite like the Monzo way of doing it. Much better than one of my CC apps which makes me reauthenticate every time I switch focus even if I’ve only popped back into email for two seconds to get an account number.

2 Likes

Sometimes, it’s just this simple…:blush:

3 Likes

You’re OK with monzo reverting it’s security settings why? If your email did that you’d be horrified.

Phones get turned off for all sorts of good reasons. Sometimes they just run out of power, sometimes you’re away from a power source and you want to conserve what you have. They make to remember that you have security set.

“If you’ve logged out you’ve disassociated your account with the app. Why would it keep settings when you’ve deliberately removed your account from the device?”

I think this may be the nub of it. I haven’t deliberately removed my account from the device. In fact most times Monzo has done it automatically when I have had a problem with fingerprint recognition.

Perhaps Monzo should distinguish between logging out and removing the account from the App.

Pretty sure that turning my phone off has never caused my Monzo settings to be lost. And for a while I was using I dodgy phone that I had to turn off several times a day. Android phone. If I can find which box I threw it in I’ll dig it out and try again today.

Logging out clears settings because you’re removing your account from your device. I’d expect my email app to also forget settings if I removed my email account from my device.

1 Like

On the security thing, I hide my app do it’s not even a thing initially and would have to be discovered, although I know this is relativly easy to achieve, I then set the app to open with a gesture of which there are no shortage of options, this along with my other monzo and phone security features is a pretty good option. :slight_smile:

“The solution is to fix your own security or use another bank.”

Yup.

I have set up Bitdefender to protect the App for now because it clearly isn’t likely to get fixed anytime soon. Meanwhile the other bank option looks increasingly likely. Shame. I invested in Monzo. I want to see them succeed.

Not so easy. :frowning: Bitdefender isn’t cutting it.

But there is nothing to be fixed. It is working exactly as intended. Just because you use non-standard behaviour does not mean the app is broke .

3 Likes

Having had a quick read through this guide:

And this documentation:
https://developer.android.com/reference/androidx/biometric/BiometricPrompt.PromptInfo

As @BenLeo stated, it’s pretty much only flavour text that can be added to the biometric authentication process by a dev. So it’s very, very strange if you’re only having biometric authentication issues with Monzo.

Thanks, I’ll have a browse.

What I’m getting is a message that says my finger moved too quickly and honestly it didn’t. I’m not seeing that on anything else. :frowning: