Capitec Bank - Issues with latest update (Rooted Handset)

PaulB_

Senior Member
Joined
Sep 25, 2012
Messages
547
Reaction score
112
Location
/\/‾‾‾‾‾\/\
Hi all.

Was wondering if I can get some advice as the title says my handset is rooted, but this has never been an issue before with Capitec.

I've always used a banking token, but due to the token being no longer supported, I was forced to move over to Cellphone Banking.

Due to family related issues, and personal anxiety related issues - I was forced to temporarily relocated overseas. I actually had the cellphone banking set up at Sandton City the day I left SA, this was in November last year I have not had an issue with it up untill now.

Fast forward to this morning (NZ Time) I needed to a funds transfer only for app to crash whenever I attempted to open it. Going into the Google Store store a mention that on the 26th of August an update was released which claimed "Major security and stability improvements" which raised alarm bells. Capitec No longer seems to have a Facebook presence, and the only way to potentially solve this would be for a costly international phone call.

I did download the older version released in May, as well as an App downgrader which allowed me to downgrade the app without much fuss, and access to my banking app was restored immediately, and I was able to continue banking..

Firstly I do understand that if it is due to my phone being rooted, I don't have issue with that. Banks are quite within their rights, to keep their apps as secure as possible. I do have a NZ Banking app, they make it clear that Rooted Phones are not supported - I've managed to work around that, but that is a seperate issue.

I just don't appreciate my banking app crashing without warning - if it is due to due to my rooted handset the very least they can do, is tell me.. Not simply crash the app. I'm not sure if is due to my rooted app, or some idiot not debugging code before releasing it to the general public.
 
Hi Paul

I noticed the same problem today on a couple of phones. I am fairly sure one of them is not rooted as I have just checked that in a couple of different ways . However both devices are de-Googled. Perhaps someone at Capitec has a new hammer and now every problem is a nail...


Reading through the Capitec app log I can spot a couple of crashes:

--------- switch to crash
08-28 07:43:40.331 17738 17738 F DEBUG : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***
08-28 07:43:40.331 17738 17738 F DEBUG : Build fingerprint: 'google/lynx/lynx:14/AP2A.240805.005/2024082200:user/release-keys'
08-28 07:43:40.331 17738 17738 F DEBUG : Revision: 'MP1.0'
08-28 07:43:40.331 17738 17738 F DEBUG : ABI: 'arm64'
08-28 07:43:40.331 17738 17738 F DEBUG : Timestamp: 2024-08-28 09:43:39.669722061+0200
08-28 07:43:40.331 17738 17738 F DEBUG : Process uptime: 2s
08-28 07:43:40.331 17738 17738 F DEBUG : Cmdline: capitec.acuity.mobile.prod
08-28 07:43:40.331 17738 17738 F DEBUG : pid: 17570, tid: 17613, name: DefaultDispatch >>> capitec.acuity.mobile.prod <<<
08-28 07:43:40.331 17738 17738 F DEBUG : uid: 10171
08-28 07:43:40.332 17738 17738 F DEBUG : tagged_addr_ctrl: 0000000000000001 (PR_TAGGED_ADDR_ENABLE)
08-28 07:43:40.332 17738 17738 F DEBUG : signal 11 (SIGSEGV), code 2 (SEGV_ACCERR), fault addr 0x0000c859060e6b00
08-28 07:43:40.332 17738 17738 F DEBUG : x0 0000000000000001 x1 000000000000005c x2 0000c792dea995f0 x3 b400c985a960c000
08-28 07:43:40.332 17738 17738 F DEBUG : x4 0000c7c3421a1c88 x5 0000c792de0f8ba5 x6 3b676e697274532f x7 0000c791f83beaef
08-28 07:43:40.332 17738 17738 F DEBUG : x8 9bfa9e4082b41800 x9 9bfa9e4082b41800 x10 0000000000000000 x11 0000000000000000
08-28 07:43:40.332 17738 17738 F DEBUG : x12 000000003fffffff x13 0000000000000030 x14 0000cac866738a2c x15 000000007045d848
08-28 07:43:40.332 17738 17738 F DEBUG : x16 0000cac846f6d0e8 x17 0000cac846f041e0 x18 0000c791f6654000 x19 0000c791f8433440
08-28 07:43:40.332 17738 17738 F DEBUG : x20 0000c7928029a620 x21 9bfa9e4082b41800 x22 0000000000005c00 x23 b400c885927e9700
08-28 07:43:40.332 17738 17738 F DEBUG : x24 0000000000000000 x25 0000c79240201f10 x26 0000000012d7dc50 x27 00000000135ab320
08-28 07:43:40.332 17738 17738 F DEBUG : x28 00000000135a0bb8 x29 b400c985a960c000
08-28 07:43:40.332 17738 17738 F DEBUG : lr b400c859060e6b00 sp 0000c7928029a5c0 pc 0000c859060e6b00 pst 0000000060001000
08-28 07:43:40.332 17738 17738 F DEBUG : 1 total frames
08-28 07:43:40.332 17738 17738 F DEBUG : backtrace:
08-28 07:43:40.332 17738 17738 F DEBUG : #00 pc 0000000000000b00 <anonymous:c859060e6000>
--------- switch to main



--------- switch to crash
08-28 07:43:33.919 17517 17517 F DEBUG : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***
08-28 07:43:33.919 17517 17517 F DEBUG : Build fingerprint: 'google/lynx/lynx:14/AP2A.240805.005/2024082200:user/release-keys'
08-28 07:43:33.919 17517 17517 F DEBUG : Revision: 'MP1.0'
08-28 07:43:33.919 17517 17517 F DEBUG : ABI: 'arm64'
08-28 07:43:33.919 17517 17517 F DEBUG : Timestamp: 2024-08-28 09:43:33.579815523+0200
08-28 07:43:33.919 17517 17517 F DEBUG : Process uptime: 3s
08-28 07:43:33.919 17517 17517 F DEBUG : Cmdline: capitec.acuity.mobile.prod
08-28 07:43:33.919 17517 17517 F DEBUG : pid: 17350, tid: 17395, name: DefaultDispatch >>> capitec.acuity.mobile.prod <<<
08-28 07:43:33.919 17517 17517 F DEBUG : uid: 10171
08-28 07:43:33.919 17517 17517 F DEBUG : tagged_addr_ctrl: 0000000000000001 (PR_TAGGED_ADDR_ENABLE)
08-28 07:43:33.919 17517 17517 F DEBUG : signal 11 (SIGSEGV), code 2 (SEGV_ACCERR), fault addr 0x0000d2d33d4cf800
08-28 07:43:33.919 17517 17517 F DEBUG : x0 0000000000000001 x1 000000000000005c x2 0000d2117c24f5f0 x3 b400d404824afc00
08-28 07:43:33.919 17517 17517 F DEBUG : x4 0000d2449323a4a8 x5 0000d2117b8aeba5 x6 3b676e697274532f x7 0000d2109d526aef
08-28 07:43:33.919 17517 17517 F DEBUG : x8 6729e309a3ddaf00 x9 6729e309a3ddaf00 x10 0000000000000000 x11 0000000000000000
08-28 07:43:33.919 17517 17517 F DEBUG : x12 000000003fffffff x13 0000000000000030 x14 0000d53cc113ea2c x15 000000006f8f7848
08-28 07:43:33.919 17517 17517 F DEBUG : x16 0000d53c9b14f0e8 x17 0000d53c9b0e61e0 x18 0000d2109aaac000 x19 0000d2109d59b440
08-28 07:43:33.919 17517 17517 F DEBUG : x20 0000d2109b133670 x21 6729e309a3ddaf00 x22 0000000000005c00 x23 b400d303aeed66c0
08-28 07:43:33.919 17517 17517 F DEBUG : x24 0000000000000000 x25 0000d211001fb030 x26 0000000012d798a8 x27 000000001364b320
08-28 07:43:33.919 17517 17517 F DEBUG : x28 0000000013648bb8 x29 b400d404824afc00
08-28 07:43:33.919 17517 17517 F DEBUG : lr b400d2d33d4cf800 sp 0000d2109b133610 pc 0000d2d33d4cf800 pst 0000000060001000
08-28 07:43:33.919 17517 17517 F DEBUG : 1 total frames
08-28 07:43:33.919 17517 17517 F DEBUG : backtrace:
08-28 07:43:33.919 17517 17517 F DEBUG : #00 pc 0000000000003800 <anonymous:d2d33d4cc000>
--------- switch to main


I can't take it further than this. I'll have to go and do some reading to try and improve my understanding first. An Android developer could be useful right about now...


Capitec has WhatsApp as an option on their contact page:

Please report back with what they say as I'll be interested to learn what they say.
 
The app does a request to see if the kernel reported any funky **** like changes in the file checker and also check if SELinux report changes. The Kernel itself also does a image check while booting and the moment it deals with a modified image it stats locking out secure apps. I can't imagine a banking app taking any chances and will probably bug out and that is what it is suppose to do.
 
Hi Paul

I noticed the same problem today on a couple of phones. I am fairly sure one of them is not rooted as I have just checked that in a couple of different ways . However both devices are de-Googled. Perhaps someone at Capitec has a new hammer and now every problem is a nail...
Capitec has WhatsApp as an option on their contact page:

Please report back with what they say as I'll be interested to learn what they say.
I've reported the issue to Capitec via Hellopeter - they responded a few hours ago saying the relevant people will contact me within the next 2 business days.. I use ChatGPT to try to dechiper logs, and the reasoning behind them - also went through logs early, although I couldn't understand the majority of it, nothing caught my eye that would have appeared to be rooting related.

Will be interesting to know your phone brand, and if there's some sort of a connection. I'm using a Redmi Note 12 4G
 
I highly doubt it is hardware but the phone brands are Nokia and Google. They both run Android 14 if that helps. One LineageOS with MicroG instead of Google Apps and the other GrapheneOS.

When I wrote "not rooted", I meant that the device is not rooted. Additionally the boot-loader is locked, OEM unlocking is disabled and Developer Options are not enabled so there is no USB debugging. It also has the latest security patches from earlier this month. This is what I would term a secure phone.

I chatted to Capitec over WhatsApp and they are advising things like force stop the app and asking if I have enough storage space... They do not seem interested in the log files. They advised me to go into the bank but I doubt they will be able to help either.

I have tested the Capitec App on an ancient Redmi test phone running Android 12 (LineageOS) with Google Apps installed and it does not crash. This was when installing via either Play Store or Aurora Store thus ruling out which app store is used to install the app as the problem. This phone has an unlocked boot loader and has the "USB debugging" developer option enabled. It was also last patched two years ago. This is what I would term a far less secure phone.

I see that the first thing the Capitec application does when starting up after installing the latest version is that it updates itself.
I am starting to suspect that this new built in updater is what is breaking. Perhaps it requires Google Apps Play services?
 
interesting you cant switch on Magisk hide and play around with that,
problem is banking apps are fickle and will detect it and simply not work,

Samsung apps do this as well, why Ive given up trying to crack them, and simply gone Stock with the Efuse still enabled.

might give it another bash, when I have a backup phone that allows me to try out Magisk hide features.
 
How are you testing these phones? You do know that your APP verify the phone you are using and that if you change your phone that you need to go into the bank to link that phone to that APP. You can't just use any phone with your SIM card and install the app. It does not work like that. The APP links to several security layers within both the Kernel and hardware. That gets stored on your profile. If that change they lock the app out. The APP needs to link to a new device and that can only happen if you visit the bank.
 
How are you testing these phones? You do know that your APP verify the phone you are using and that if you change your phone that you need to go into the bank to link that phone to that APP. You can't just use any phone with your SIM card and install the app. It does not work like that. The APP links to several security layers within both the Kernel and hardware. That gets stored on your profile. If that change they lock the app out. The APP needs to link to a new device and that can only happen if you visit the bank.
Not needed to go into bank anymore... I switched phones last week and activated in-app. YMMV
 
1724847249531.png

ET is calling home and home is going WTF who is this? The command line capitec is invoking here OS identifier then it fails your uid is kind of like the app's install history. I suspect that it is trying to figure out if it is a new install or an update. Both seems to fail. Next identifier is the tagged_addr_ctrl is then evoked. I am not an expert but in this case it might be trying to figure out your uid is changed and because it is a new image there is no history and that should flag it and the app should just crash at this point. ET phoned home and because ET is drunk home cannot figure out if it is a prank call or real. Because they your bank needs to keep you safe they are going to want to relink your device maybe.
 
Not needed to go into bank anymore... I switched phones last week and activated in-app. YMMV
This would normally be true BUT lately if you do like 3 phone swaps in a single day they might flag you and need you to come in. Because that is suspicious behavior?
 
View attachment 1753666

ET is calling home and home is going WTF who is this? The command line capitec is invoking here OS identifier then it fails your uid is kind of like the app's install history. I suspect that it is trying to figure out if it is a new install or an update. Both seems to fail. Next identifier is the tagged_addr_ctrl is then evoked. I am not an expert but in this case it might be trying to figure out your uid is changed and because it is a new image there is no history and that should flag it and the app should just crash at this point. ET phoned home and because ET is drunk home cannot figure out if it is a prank call or real. Because they your bank needs to keep you safe they are going to want to relink your device maybe.
Well the app is freaking out so it is not liking its new home.
 
I'd agree that could look sus
I don't like this idea of not having to go into the bank to have the phone linked. That is just looking for trouble. If anyone grabs your SIM and has a insider at whatever mobile company. They can do whatever the **** they want and no one will be able to stop them.
 
I don't like this idea of not having to go into the bank to have the phone linked. That is just looking for trouble. If anyone grabs your SIM and has a insider at whatever mobile company. They can do whatever the **** they want and no one will be able to stop them.
You have to activate with stored PIN.
 
It's 2024. Why muck about with a rooted device? They also don't need to tell you jack nothing. It'll be common sense.
Because I
I highly doubt it is hardware but the phone brands are Nokia and Google. They both run Android 14 if that helps. One LineageOS with MicroG instead of Google Apps and the other GrapheneOS.

When I wrote "not rooted", I meant that the device is not rooted. Additionally the boot-loader is locked, OEM unlocking is disabled and Developer Options are not enabled so there is no USB debugging. It also has the latest security patches from earlier this month. This is what I would term a secure phone.

I chatted to Capitec over WhatsApp and they are advising things like force stop the app and asking if I have enough storage space... They do not seem interested in the log files. They advised me to go into the bank but I doubt they will be able to help either.

I have tested the Capitec App on an ancient Redmi test phone running Android 12 (LineageOS) with Google Apps installed and it does not crash. This was when installing via either Play Store or Aurora Store thus ruling out which app store is used to install the app as the problem. This phone has an unlocked boot loader and has the "USB debugging" developer option enabled. It was also last patched two years ago. This is what I would term a far less secure phone.

I see that the first thing the Capitec application does when starting up after installing the latest version is that it updates itself.
I am starting to suspect that this new built in updater is what is breaking. Perhaps it requires Google Apps Play services?
The phone which it crashes on has Play services, and all updated so not that.
 
Hope the version I have installed doesn't stop working anytime soon till this is patched up at least.... I'm currently temporarily residing in New Zealand, and I cannot simply just walk into a Capitec Branch to sort this. That's one thing these tech companies don't seem to get. Why **** with something that's working find, and therefor breaking it.
 
Hope the version I have installed doesn't stop working anytime soon till this is patched up at least.... I'm currently temporarily residing in New Zealand, and I cannot simply just walk into a Capitec Branch to sort this. That's one thing these tech companies don't seem to get. Why **** with something that's working find, and therefor breaking it.
Which ironically is the perfect question to ask regarding your phone and its ROM
 
how do I root a tablet? I have an old Samsung that I want to use with my CCTV but it is so old it can't even access the play store anymore.
 
Top
Sign up to the MyBroadband newsletter
X