Mobile/online Banking: Android app

Android users and KCB customers : https://play.google.com/store/apps/details?id=Com.kcb&hl=en What's your experience with this app? ./bernard

how safe is it? what if your android gets stolen? On Wed, May 9, 2012 at 10:43 PM, Bernard Mwagiru <bmwagiru@gmail.com> wrote:
Android users and KCB customers : https://play.google.com/store/apps/details?id=Com.kcb&hl=en
What's your experience with this app?
./bernard
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke

Why would someone use an application for banking that is not from the actual bank? On Thu, May 10, 2012 at 10:37 AM, Joseph Maina <mainasoft00@gmail.com>wrote:
how safe is it? what if your android gets stolen?
On Wed, May 9, 2012 at 10:43 PM, Bernard Mwagiru <bmwagiru@gmail.com>wrote:
Android users and KCB customers : https://play.google.com/store/apps/details?id=Com.kcb&hl=en
What's your experience with this app?
./bernard
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke

Hey Rad - Good question! To reduce your chances of falling victim to fraud when you bank online via your smart phone you should:Only download mobile applications directly from your bank, they are free to use and you can download without any reservations about the software.Download any free security software provided by the bank, we all know that having to enter additional passwords can be frustrating but if it prevents an attempted fraud then it could be worth the inconvenience.Install quality security software. Often if you have it installed there is a remote deletion option that means you can delete any data stored on the phone if you discover it’s lost or stolen.Set up your smart phone to be more secure. Use a PIN or password to lock your phone when you’re not using it.Make sure your phone’s browser doesn’t automatically input your passwords or usernames for you......... Read more: http://www.money.co.uk/article/1005729-is-banking-on-your-smart-phone-safe.h... Date: Thu, 10 May 2012 10:40:06 +0300 From: conradakunga@gmail.com To: skunkworks@lists.my.co.ke Subject: Re: [Skunkworks] Mobile/online Banking: Android app Why would someone use an application for banking that is not from the actual bank? On Thu, May 10, 2012 at 10:37 AM, Joseph Maina <mainasoft00@gmail.com> wrote: how safe is it? what if your android gets stolen? On Wed, May 9, 2012 at 10:43 PM, Bernard Mwagiru <bmwagiru@gmail.com> wrote: Android users and KCB customers : https://play.google.com/store/apps/details?id=Com.kcb&hl=en What's your experience with this app? ./bernard _______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------ Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke _______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------ Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke _______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------ Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke

Seems to connect to the online portal for web banking but still,i wont dare login with it.Its not from KCB and I haven't got a response from them over the app.

I think its insane to install a banking app that is not officially from the bank or at least endorsed by it. What will stop the app from capturing your passwords and authorization codes? Deducting a shilling from each transaction? Mining your information? Whoever is brave/misguided enough to install and use this software - may the Force be with you On Thu, May 10, 2012 at 2:25 PM, Daniel Ndeti <dantoz@gmail.com> wrote:
Seems to connect to the online portal for web banking but still,i wont dare login with it.Its not from KCB and I haven't got a response from them over the app. _______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke

There's a change KCB is announcing this Sunday regarding their mobile banking platform - they could have an app for smartphones in the pipeline but I don't see USSD being trashed given its universal appeal. Probably http://www.iridiuminteractive.com/ should answer to the queries above, since they're the app's developers. It would be extremely FOOLISH to try the app without a word from the bank.

Wait, someone said Iridium Interactive?

I have installed the app to investigate it. The app is mainly a webview linked to the kcb - online banking link ( https://onlinebanking.kcbbankgroup.com/kcbonline/ ). Insecure considering you can pull the application db and harvest data e.g browse the plain text passwords .See attached image. @Rad Incidentally, app does not intercept transactions. yet! Insane to use this app! On 10 May 2012 14:55, Rad! <conradakunga@gmail.com> wrote:
I think its insane to install a banking app that is not officially from the bank or at least endorsed by it.
What will stop the app from capturing your passwords and authorization codes? Deducting a shilling from each transaction? Mining your information?
Whoever is brave/misguided enough to install and use this software - may the Force be with you
On Thu, May 10, 2012 at 2:25 PM, Daniel Ndeti <dantoz@gmail.com> wrote:
Seems to connect to the online portal for web banking but still,i wont dare login with it.Its not from KCB and I haven't got a response from them over the app. _______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke

Here's the official KCB mobile app *https://mbanking.kcbbankgroup.com*<https://mbanking.kcbbankgroup.com> ./bernard On Thu, May 10, 2012 at 11:08 PM, Geoffrey Mimano <soyfactor@gmail.com>wrote:
I have installed the app to investigate it. The app is mainly a webview linked to the kcb - online banking link ( https://onlinebanking.kcbbankgroup.com/kcbonline/ ).
Insecure considering you can pull the application db and harvest data e.g browse the plain text passwords .See attached image.
@Rad Incidentally, app does not intercept transactions. yet!
Insane to use this app!
On 10 May 2012 14:55, Rad! <conradakunga@gmail.com> wrote:
I think its insane to install a banking app that is not officially from the bank or at least endorsed by it.
What will stop the app from capturing your passwords and authorization codes? Deducting a shilling from each transaction? Mining your information?
Whoever is brave/misguided enough to install and use this software - may the Force be with you
On Thu, May 10, 2012 at 2:25 PM, Daniel Ndeti <dantoz@gmail.com> wrote:
Seems to connect to the online portal for web banking but still,i wont dare login with it.Its not from KCB and I haven't got a response from them over the app. _______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke
_______________________________________________ Skunkworks mailing list Skunkworks@lists.my.co.ke ------------ List info, subscribe/unsubscribe http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks ------------
Skunkworks Rules http://my.co.ke/phpbb/viewtopic.php?f=24&t=94 ------------ Other services @ http://my.co.ke
participants (8)
-
Bernard Mwagiru
-
Daniel Ndeti
-
Dennis Kioko
-
Geoffrey Mimano
-
Haggai Nyang
-
Joseph Maina
-
Rad!
-
Vee Legrandchef