this post was submitted on 30 Dec 2025
61 points (96.9% liked)
Hacker News
3393 readers
381 users here now
Posts from the RSS Feed of HackerNews.
The feed sometimes contains ads and posts that have been removed by the mod team at HN.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Let me start by saying how stupid that is…. But, if I had to come up with a reason, it may be because Bitwarden can store passkeys which can then make them portable as opposed to device specific which technically is a security bypass.
Yeah I would say almost assuredly they have seen scams abusing this enough to have to implement a countermeasure
I believe they are just indiscriminately checking for the installed source (an information available from Android). If the installed source is not from Google Play Store, it will attempt to block. In this case, app is installed from f-droid.
this is not just HSBC, a lot of Asian banks implemented this, likely as a reaction to the scam cases.