PrivSec-dev / banking-apps-compat-report

Report and track banking app compatibility with GrapheneOS, including which workarounds may be required.
https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/
81 stars 4 forks source link

mBank PL #136

Closed wc2FiCLd closed 2 years ago

wc2FiCLd commented 2 years ago

Is there an existing issue for this?

App name

mBank PL (pl.mbank)

Link to app

https://play.google.com/store/apps/details?id=pl.mbank

App version

3.55

Country of the app

Poland

Build Number

TP1A.220624.021.2022082400

Device

Google Play installed

Google Play services Network permission revoked?

SafetyNet Enforcement

Native code debugging

Stock OS compatibility

Profile app tested in

Description of the app's functionality

SMS activation doesn't work for me (app made an empty SMS with random letters and characters as the sending "number", I use signal as my stock SMS app, did not test without it. Activation of the app done by logging in on the mBank bank website and adding the device with a code works.

BLIK contactless payments work - I can use my phone as a debit card! This didn't work on lineageos (google pay nor BLIK contactless) I don't think this app enforces safetynet, because I used it on lineage with no problem other than blocked contactless debt card.

Are there any extra notes you think users should know about?

No response

ADB logcat of the app if necessary

No response

akc3n commented 2 years ago

Thank you @wc2FiCLd

PatrykMis commented 1 year ago

The app has the following issue not related to GrapheneOS: https://github.com/GrapheneOS/os-issue-tracker/issues/1455

arkadiusz-wieczorek commented 1 year ago

Is there an existing issue for this?

App name

mBank PL (pl.mbank)

Link to app

https://play.google.com/store/apps/details?id=pl.mbank

App version

3.65.0

Country of the app

Poland

Build Number

TQ3A.230705.001.2023071100

Device list

Profile app tested in

Google Play installed

Google Play Services Network permission revoked?

Native code debugging

Exploit protection compatibility mode

Stock OS compatibility

Description of the app's functionality:

SMS activation works (I use a stock message app), biometric logging and transfer acceptance works.

BLIK contactless payments don't work. I see on terminals displays a message: “Please use another card”...

Are there any extra notes you think users should know about?

No response

ADB logcat of the app if necessary

No response