10 ms·
Pokemon Go, Security, and Obsolescence
- pwnna 10y agoNow Niantic's decision to disallow root devices, imo, is pretty regretful, as serious botters will likely be able to get around that restriction regardless. This only serves to punish users who are stuck between having a root-enabled custom ROM or a stock ROM where critical root exploits may exist. One thing that I observed is that no one seems to be interested in producing a ROM that is both stable, has a variety of features, do not rely on root, and supports the device for a long time. This is a shame really, because root itself breaks the security mechanism for android and users probably are not fully aware what it means when they grant applications root. I personally got around this problem by compiling a build of CyanogenMod without root enabled, but with things like FDroid (with PrivilegeExtension) and adblock built-in to the ROM itself (albeit the update mechanism is to update the ROM it self). This is not a solution for the mass majority of users. This problem is pretty difficult to solve and it is pretty deep, much deeper than what I'm willing to type in a single comment, so I'll stop here.
- djsumdog 10y agoI wrote this about Android a while back: http://penguindreams.org/blog/android-fragmentation/ http://penguindreams.org/blog/android-fragmentation/ The TLDR is that it'd be nice if Android was more like Windows/Intel: install the OS (i.e. AOSP), drivers (or binary driver package format and an SDK to auto-build it) and boom you're done. Clean, stock, standard. Same with many Linux distros on x86/64. I need to write an update to the article though. Lately I've been struggling with a Clearfog ARM board, and coupled with Torvald's recent comments on Intel vs ARM, I wonder if a huge chunk of the problem is ARM itself. I've noticed for every distro there are really specific images, not just for each ARM chipset, but for individual boards, even when those manufacture patches make it into the mainline kernel. I haven't looked closely at Android and I'm really curious at the build system/workflow used by things like Cyanogen and Omnirom. Are kernels really specialized per device? Does the ARM architecture itself make it difficult to have general purpose kernels that will boot on all of them like in the x86/64 world? Any ARM hardware people care to chime in?
- cheiVia0 10y agoDebian is shipping one Linux kernel build that runs on a bunch of different ARM devices that are supported by the mainline version of Linux: https://wiki.debian.org/DebianKernel/ARMMP https://wiki.debian.org/DebianKernel/ARMMP Unfortunately most mobile devices are not supported by mainline Linux (N900 is best supported, but not fully), usually only server/desktop/laptop vendors have any incentive to mainline their drivers.
- voltagex_ 10y agoThe 2013 Nexus 7 was, at some point, 50 patches away from running mainline [1]. I know, single datapoint, but it gives me hope that there's some way out of the tabletification of computing. 1: https://wiki.linaro.org/LMG/Kernel/FormFactorEnablement https://wiki.linaro.org/LMG/Kernel/FormFactorEnablement
- pjmlp 10y agoIt is like the old days of home computers. We had Z80, 6509, 68000 and so so, but everything else that was plugged into their pins was different. So it doesn't matter if the Assembly is the same, the kernel also needs to talk to the hardware. Also ARM just resells the base designs, each company usually adds they own set of Assembly instructions or fine tunes the designs in some other way. The IBM PC clones were the only ones that had some kind of standardization going on, and even that seems to be gone now, with OEMs going to the same kind of hardware designs we used to have (everything bolted on the board).
- cheiVia0 10y agoSome related posts: https://cascardo.eti.br/blog/GNU_on_Smartphones_part_II/ https://cascardo.eti.br/blog/GNU_on_Smartphones_part_II/ http://bonedaddy.net/pabs3/log/2012/12/03/debian-mobile/ http://bonedaddy.net/pabs3/log/2012/12/03/debian-mobile/ https://wiki.debian.org/Mobile https://wiki.debian.org/Mobile
- exDM69 10y ago> Any ARM hardware people care to chime in? It's not really about the CPU architecture, but the peripherals of the devices. In the x86 world, the peripherals are governed by the "PC" standard, which these days is implemented by the chipset on your motherboard. They all have similar functionality, although you still do need some chipset-specific drivers in your kernel. In the ARM world, the landscape is different. There has never been a de facto standard configuration of an ARM computer like the PC was/is for x86. There are ARM computers that are more like a micro controller and there are tablet/mobile devices based on ARM that have a system on chip (SoC) that's got all the peripherals, including GPUs, network adapters, etc. Every SoC is pretty different, there's a bunch of devices connected with i2c, spi and other buses. These are required to control the power and clock management and all the I/O devices. ARM (the company) doesn't really design these, they just license ARM (the architecture) to a SoC manufacturer and call it a day. This leads to a very diverse and fragmented landscape. The ARM world has been making strides to reduce the amount of chip-specific code. One good example is the device-tree configuration which, in theory, allows running the same kernel binary on different devices. With device-tree, you pass a config file from the bootloader to the kernel, which contains configuration (i/o memory maps, etc) of the peripherals (which you'd query from the hw/firmware in a x86 machine). This is a huge improvement over what was before it, but there's still a long way to go. And there's still plenty of older ARM SoCs out there that don't support this. But yes, it's pretty much a mess. There's a lot of duplicate work that every ARM SoC manufacturer has to go through. Given that the mobile world is financed by a planned obsolescence cycle where they expect customers to upgrade every few years, I find it unlikely that this issue will be solved any time soon.
- tedmiston 10y agoThey've gotta stop the GPS spoofers somehow. It's not like this was the first solution they jumped to to stop cheaters. Maybe this was the 80/20 solution over more advanced location anomaly detection methods against their database.
- lini 10y agoThe problem is that you don't need root for GPS spoofing. Botters also don't care about SafetyNet (used to detect root before the game starts), since they reverse engineer the API and make REST calls directly. Furthermore, there are ways around the root check - mostly involving hiding the su binary and some additional tweaks.
- deanclatworthy 10y agoFurthermore, you can buy GPS spoofing devices anwyay which you can just carry around with you in your pocket.
- foota 10y agoTo be fair, that's probably highly illegal if caught by the fcc.
- seszett 10y agoThe FCC only has business in the US though.
- lucb1e 10y agoAlmost every country has something like that. The Dutch Agentschap Telecom will hunt you down for transmitting a fake GPS signal too. The thing is, nobody cares if you send a signal too weak to go beyond a meter of your pocket. That's why it's totally legal to send FM on registered frequencies as long as your output is under a certain amount. Same with WiFi even. I heard about someone looking into GPS spoofing once in the context of catching drones, even nearby ones (e.g. fly near to it). It takes a lot of energy to do that and was basically not practical outside of military settings.
- tombrossman 10y ago> I personally got around this problem by compiling a build of CyanogenMod without root enabled, but with things like FDroid (with PrivilegeExtension) and adblock built-in to the ROM itself... I just bought a Nexus 5x and loaded CopperheadOS on it, and to my dismay I see Ad-Away from F-Droid requires root to function (plus a couple other apps I really like). How much of a hassle is it really, because I absolutely want system wide ad blocking and I worry that I will be defeating the purpose of using a hardened OS in the first place? Do you rebuild and flash each OS update as a new ROM? Is all your data on the phone persistent or backed up & restored each time?
- pwnna 10y ago> How much of a hassle is it really, because I absolutely want system wide ad blocking and I worry that I will be defeating the purpose of using a hardened OS in the first place? Ad-away works by using a host file to block. The hosts file is generally not writable by the user without root as it lives on a read only partition (/system). Another way to block ads is to connect to a VPN that blocks thoses hosts for you, however that is more cumbersome to setup. While hosts blocking is not perfect... my thought on this was to expose a limited API that allows apps to update the hosts file without having root. This could be sketchy and a security risk on its own tho, because you're essentially hijacking DNS... In addition, I don't think the community is interested in this because they all love root.. > Do you rebuild and flash each OS update as a new ROM? Every month, immediately after the security bulletin and a resync. > Is all your data on the phone persistent or backed up & restored each time? So android has a /system partition and a /data partition. When you reflash your system, the data partition (where all your apps, settings, what not are stored) is left untouched. Android will detect this and perform an upgrade operation on the /data partition, if applicable.
- nradov 10y agoApple added specific ad blocking features to iOS 9, and I don't think those rely on editing the hosts file. So in principle a similar design could work for Android, although I doubt Google would ever support that.
- legulere 10y agoA few botters don't hurt Pokémon go. But when it's easy to bot, lots of people will bot. It's easy to circumvent anti root, but it's impossible to use the same way for lots of devices without niantic being able to block it again. So it really makes sense for them to go this way IMO.
- Drdrdrq 10y agoNot really. It doesn't matter if the phone is rooted or not, what matters is whether it is feeding false gps data or not. Bots will soon find a way around this (non-rooted) restriction anyway. That said, proper protection against cheating would involve using markers (other phones?) in vicinity, so it should be possible too.
- rickyc091 10y agoYes, bots will most likely always find a way, but I think it's more about thwarting the casual users. If you could gps hack by simply installing an app more people would do it. By making it extremely tedious, the causal user won't be as inclined to do it since the time it takes to figure it out won't be worth it. I don't condone Niantic's behavior, but I understand it.
- mynameisvlad 10y agoTo me, it would make more sense if they weren't also banning users their auto-detection system thinks are spoofing GPS. A system which is fairly overzealous, might I add. I was banned for being in Japan, for example. One day out of the blue on my vacation, got the ToS violation notification which still hasn't been reversed, two weeks later.
- evilDagmar 10y agoThe spoofers have had a way around this for some time now, as GPS spoofing simply does not require root privileges. Niantic is not actually making any attempt to look for GPS spoofing software. They simply invoke Android's SafetyNet which doesn't care about GPS at all but does care about other things which happen to coincide with what's on some cheater's phones. It will never be anything like an effective measure against GPS spoofing.
- on_and_off 10y ago> This is not a solution for the mass majority of users. root is not used by the mass majority of users.
- lewisl9029 10y agoI honestly would be very happy with a ROM that copies stock Android entirely, without any added features or customizations, rather focusing solely on stability, security, supporting a wide range of devices, and tracking the official Android release schedule as closely as possible. Can someone point me to a ROM like this if one already exists?
- RDaneel0livaw 10y agoI was going to point you to the Pure series of roms by Beanstown, but I don't understand your question... You don't want ANY custom stuff at all or features, then what's the point? Just install stock android...?
- ferbivore 10y ago"Stock Android" is only stock Android on Google-branded devices.
- RDaneel0livaw 10y agoI don't understand this sentence. Google only has a single phone that has only been out for like 1 day now, the Pixel. And it's not even stock Android, it's got extra features that the stock Nougat doesn't have. Again though, I think this whole thing is moot, because lots of phones have roms on xda that is basically just stock android with no customizations, so just install that and be done with it.
- ferbivore 10y agoI said Google-branded, not Google-manufactured. The Nexus line is what people typically understand by "stock Android". The point isn't that there are no vanilla AOSP ROMs for most devices. The point is that they usually suck, and a reputable well-supported one that actually worked properly would be a massive innovation.
- nucleardog 10y ago
- evilDagmar 10y agoYou literally didn't need to do any of this (and I'm astonished someone would wait through a CM build rather than do ten minutes of research). Also, I'd like to remind you that SEAndroid (i.e., SELinux) doesn't give a fig about "root" so your statements about that are quite wrong. You can simply rename your su binaries through the recovery environment to disable them, which neatly disables "root access" and makes the SafetyNet check Niantic is invoking pass with flying colors. Should you need them again, they're only a reboot and couple of mv invocations away.
- pwnna 10y ago> You literally didn't need to do any of this. For me personally, this is not the reason for me to build CyanogenMod. I will occasionally modify certain things inside android to suit my needs and there are enough of these things that are not merged upstream that it's more convenient for me to just build my own version every month/week/whenever. > Also, I'd like to remind you that SEAndroid (i.e., SELinux) doesn't give a fig about "root" so your statements about that are quite wrong. This is an area i'm not quite informed, so maybe you can elaborate further. The core issue that I wanted to express is that barely any community ROMs are CTS compliant, which is ultimately what SafetyNet checks. > You can simply rename your su binaries through the recovery environment to disable them, which neatly disables "root access" and makes the SafetyNet check Niantic is invoking pass with flying colors. Should you need them again, they're only a reboot and couple of mv invocations away. Doing a bunch of mv's is a hassle (esp over multiple devices) as I rarely ever need root on my phone. The only times when I need it nowadays is host based ad blocking, which I just integrated into my ROM. So this way I can just get rid of root all together, which is one more step towards CTS compliance.
- xorcist 10y agoHow do you non-root using people backup your phones, without running the backup software as root?
- colejohnson66 10y agoIf you never change any files outside of the ones you own (i.e. the ones owned by "root"), you don't need to back them up, right? For example, if I never touch any of the files under C:\Windows, I have no need to back up that folder (especially the files owned by SYSTEM that you can't access).
- lern_too_spel 10y agoYes, the author makes the fundamental mistake of thinking that custom ROMs and having root access are the same thing. It is possible to have a custom ROM that does not give the user root access, and such a configuration is more secure for the user.
- kyled 10y agoRoot by itself does not break security entirely. Selinux policies and capabilities assigned to binaries can be used to drastically mitigate privileged processes from doing much harm.
- curiousgal 10y agoSurprised people are still playing Pokemon Go. Niantic made all the wrong moves.
- minimaxir 10y agoPokemon Go may not have been the superstar everyone expected much later, but it still drives more revenue than most mobile games. (Nintendo is probably OK with that since it will no longer detract from Sun/Moon)
- keyle 10y agoMe too. Kids still do. They seem to jump on/off the latest craze a lot slower. It gives them something to do while walking with their parent, which is inherently boring to them.
- Kiro 10y agoHow so? I play Pokémon Go and can't think of a single thing they've done that has spoiled the experience for me. Neither can my friends. We love the game as it is. Bear in mind we are casual players, like most are.
- curiousgal 10y agoGranted it's not the most representive sample but a glance through https://www.reddit.com/r/pokemongo https://www.reddit.com/r/pokemongo shows that the majority of people are complaining. I live by a park where there are 3 Pokestops and a Gym and it used to be mildly crowded, now it's empty. It's obvious that the game has died down and it all can be traced back to when Niantic broke the tracking system and proceeded to go after Maps. Every "anti-cheat" measure they introduced (Detecting movement speed and root) netted a large number of false positives and they refuse to listen to their active and vocal community. Not to mention the inherently broken Gym battle system where anyone can take over a Gym even if you were the one to beat the Gym owners. That was the one aspect I found too frustrating.
- Kiro 10y ago
- minimaxir 10y agoSee also, a comment from a Pokémon GO map developer on the latest API changes/rootblocking: http://www.twitlonger.com/show/n_1sp6pkg http://www.twitlonger.com/show/n_1sp6pkg
- shadowmint 10y agoFor all I want a good tracker, and the sympathy I have for friends I have with rooted devices who can no longer play... Niantic is not beholden to anyone to release anything, add any features, or do anything. Its their game. If you don't like it, either a) don't play, or b) make something better. It's a testament to the compellingness of the AR game genre, and the brand recognition that Pokemon has they so many people are willing to put so much time and effort into the game despite how primitive it is. People calling for an open API are fooling themselves. Why on earth would they give away the keys to the kingdom? Hacking the protocol and the cheaters created this situation. They have only themselves to blame for it. Cry. Me. A. River. You might say that serious cheaters can bypass the restrictions / measures, but clearly from the fuss (and that fastpokemap is still down), its doing the intended job pretty much spot on. Realistically, nothing is going to change, unless someone starts offering a compelling alternative to drive innovation.
- minitech 10y ago> Hacking the protocol and the cheaters created this situation. > They have only themselves to blame for it. Cry. Me. A. River. What does this have to do with the article, written by someone who didn’t cheat? > If you don't like it, either a) don't play, or b) make something better. Yes, everyone affected by this is rather forced to pick (a). Occasionally, they may write articles. If you don’t like them, a) don’t read them.
- shadowmint 10y agoThe article is basically saying that because of Niantic, we have to choose to compromise between security and pragmatism of using apps. The choice between running the software you want, like Pokemon Go, and the quick road to obsolete devices in the Android ecosystem, at best forces users to make a choice between security and functionality. I think it's pretty obvious from the comments in here that there's plenty of blame being poured on Niantic for whats happening. I'm just pointing out that the root cause and people who should be shouldering the blame here aren't necessarily Niantic... but more importantly, whinging about it won't change anything.
- 10y ago
- rotub 10y agohttps://www.instagram.com/p/BLm2lNxgXco/ https://www.instagram.com/p/BLm2lNxgXco/
- staticelf 10y agoI bought 3 times from the in game store and then later got banned. I later requested a refund but they don't even answer any mail. Classic piece of shit company.
- jsmeaton 10y agoWere you "cheating" according to their definition? Why should they reply or give you your money back? Classic entitlement.
- DanBC 10y agoI guess they bought something with the (reasonable) assumption they'd be allowed to keep using the thing they bought. > Your last, two word, sentence is rude, and your comment doesn't need it.
- Kirth 10y agoIn one of their past banwaves, getting off a high speed train or airplane and then killing some time at the airport playing Pokemon Go often got you banned because of "teleporting". (Not always a temporary shadowban) Getting support to even respond to your mails (even when they're related to other issues) seems to be a matter of waiting for the right stars to align.
- evilDagmar 10y agoMillions of users, seventy employees. Stars can't help that.
- Ensorceled 10y agoWait. When did expecting delivery of the product or service you paid for become "classic entitlement"?
- jsmeaton 10y agoMaybe my comment was unnecessarily rude, but demanding a refund and calling a company a piece of shit because you got banned for cheating is absolutely entitlement. Just because you spend money on a service does not entitle you to have unlimited access against TOS.
- raimue 10y agoAfter all, the root blocking in Pokémon Go is pretty weak. All I had to do was to rename/move the 'su' binary and then it worked again.
- puddintane 10y agoThis did not work for every user - for example my buddy bought an Asus Zenfone 2 (ZE551ML) specifically to play this game. I warned him not to buy from a China seller but he proceeded because he was finding guides that told him it was a great phone for the game - he literally bought this phone to play this game. I attempted to remove root however this has now forced the phone to be stuck on Edge network (he can play but now only on WiFi :/) I have attempted to re-flash the physical ROM's (as well as the recovery matching those ROMs) from ASUS (successfully) and it still is stuck on edge. I've contacted his phone company (T-mobile) - insured the proper bands were being requested, 5x checked the APN settings and yet the phone still doesn't want to connect past edge. Here is the kicker, I scan for nearby cellular networks and T-Mobile (LTE) shows up, the phone registers, yet still won't obtain the connection. Honestly that issue is probably due to some other restriction but it shows the frustration some users have had to deal with because of this move. I even tried re-rooting the phone just to get his network back because he'd rather have his phone than Pokemon GO yet the phone had something special done to it to allow the network to work under root. No one should have to go to those extremes especially when they aren't cheating and they are a paying customer. In all honesty I don't believe the ban on root was done to deter hacking - my belief is that it was done because on average users only root because they want paid apps for free (a lot claim it's to tweak the UI and remove bloatware, but as more and more phone's get released we are starting to see this less and less of a requirement). While many rooted players (due to pre-rooting) are actually paying customers it still doesn't outweigh the paying customers who are not rooted and therefore it was more then likely a move to remove users who are less likely to put money into the game. Every move they have done really reflects that they only want more money with the least amount of work and that is why I only keep the game installed to keep my 1 star reviewed from being weighted down due to being a review for an older version. One of the big guys who is involved in creating a usable tracking system via a third-party map has made a wonderful statement about the many failures of Niantic [1]. From unnecessary obfuscation that only slows down older models, to banning the devices that aren't the reason cheating is happening, to not creating a good way to achieve feedback (apart from "critical errors" which is built into the app - maybe I should start complaining about the critical "Niantic" bug and that it needs to be fixed ASAP, but complaining won't really get anywhere if the company isn't listening to those problems) Niantic truly is on a path to destruction and I hope Nintendo doesn't let this amazing idea die if Niantic falls. It really doesn't make sense to why they are making these decisions. The developers should know that banning rooted devices won't deter hackers - in fact I would have to say it's grown a few hackers/cheaters due to the frustration of dealing with lack of communication and oddly made decisions. [1] http://www.twitlonger.com/show/n_1sp6pkg http://www.twitlonger.com/show/n_1sp6pkg
- pja 10y agoYou can unroot CyanogenMod running on the Nexus 4 & Pokemon Go will run just fine. You have to give the SuperSU app root privileges in order to unroot ironically, but it works just fine & you can always root your system from the bootloader in the future if it turns out that you need root for some reason. There’s an app in the Play Store that runs the tests the Google library that Niantic is using to check whether a phone is rooted or not (it’s the same tests used by the Google Pay infrastructure IIRC).
- brbsix 10y agoThis is the app I've used in the past: https://play.google.com/store/apps/details?id=com.scottyab.safetynet.sample https://play.google.com/store/apps/details?id=com.scottyab.s... Also I was under the impression that SafetyNet would only pass on stock ROMs (to include official CyanogenMod builds lacking root). Is that not true? Will it also pass on any custom ROM lacking root? Edit: According to http://androiding.how/use-android-pay-cm14-cm13/ http://androiding.how/use-android-pay-cm14-cm13/, SafetyNet (the tamper detection API in use by Android Pay and Pokemon Go) will only pass on official stable (non-nightly) releases of CM13/CM14 that have root disabled in the Developer options. It will not pass on debug releases of firmwares/ROMs, including Android 7.0 Nougat based CM14 and Android 6.0 Marshmallow based CM13 ROMs.
- pja 10y agoSafetyNet passes on my Nexus 4 running an unrooted currentish CyanogenMod nightly build. Haven’t tried any other Android custom roms.
- delroth 10y agoThe SafetyNet API returns multiple booleans. The stricter version of the detection enforces that the system is an Android CTS-compliant device, but there are several levels below that. Apps using SafetyNet can decide how much they enforce. Unfortunately this testing app you linked doesn't seem to surface this at all and only shows the highest level (CTS).
- evilDagmar 10y agoWell, it's not like you haven't seen bloggers talking through their hats before, right? The amount of cargo cult nonsense in Android "news" kills me. SafetyNet is completely fine with a nightly of CM13 (on Samsung Galaxy S5) after the su binary and it's accompanying symlink are renamed to get them out of sight (and effectively disabled). You don't have to touch the settings in developer options at all because SafetyNet isn't going on some extended search to look for the setting. It's just looking for the presence of an su binary in the filesystem in a few places during that phase of its checks.
- brbsix 10y agoIt should be pretty easy to get around this by using Magisk[0] systemless root, is it not? Magisk is able to pass Google's SafetyNet tamper detection API which IIRC is what Pokemon Go uses to detect root. Works for Android Pay at least, which also prevents use of the app on rooted devices. [0]: http://forum.xda-developers.com/apps/magisk/official-magisk-v7-universal-systemless-t3473445 http://forum.xda-developers.com/apps/magisk/official-magisk-...
- Kenji 10y agoWhen I have a choice between Pokemon Go or root, I choose root every single time. I loathe Niantic for this stupid decision. The equivalent would be if Riot decided that League of Legends can only be played on PCs with a guest account and not an admin account. Completely pointless and dumb. I can't believe I bought some stuff in the Pokemon Go store, I want a refund. They robbed me, a legitimate and paying customer, of the ability to play the game on my device. This borders on fraud. This practice needs to be stopped. There needs to be a simple app that can be installed that completely shields from, blocks and stumps this fascist SDK that detects root. And every custom ROM should have it installed by default. The problem is obviously bigger than Niantic. The problem is that people think we shouldn't fully own our phones and that such a mindset is acceptable.
- puddintane 10y agoThere is it's called Magisk (it's not as simple as installing but it does exist!)
- Kenji 10y agoI know about Magisk and it's a hassle. Not worth doing for pokemon go.
- Fiahil 10y agoAfter Niantic's move to "encrypt" API calls (which was broken a few days after, btw), I'm not surprised they would arbitrarily block some devices based on phony explanations. Bear in mind, bots have little to no effects on the game itself because you have little to no virtual interactions with other players. It's not like you were able to trade Pokémons you caught with someone else.
- rsheridan6 10y agoYou do interact with other players via gym battles, and if gyms are dominated by cheaters it ruins the game for everyone else.
- slavik81 10y agoIt is a problem that cheaters will fill gyms with ridiculously strong pokémon. Unfortunately, if you started playing significantly after release, even legit players are so much stronger that the game experience is the same. Alas, the underlying problem is bad game design.
- nommm-nommm 10y agoYou battle against other players who are holding down gyms.
- nfriedly 10y agoI stopped playing Pokemon go when they put out the no-root update. I have never cheated, I even purchased some coins - I was a paying user. But they don't seem to want my money, and I'm not going to unroot my phone for a stupid game. I uninstalled it and ask for a refund. (They haven't granted it yet but I'm not giving up. I believe I'm in the right here and they owe me a refund since they've removed the functionality after I paid.)
- evilDagmar 10y agoYes, Niantic was very lazy in their attempts to stop spoofers and botters. Rather than write some code to actually look for the few pieces of software the cheaters are using, they just started invoking Android's SafetyNet. Notably, very little was accomplished. The problem? SafetyNet does not care about game spoofers/cheaters. That's literally not what it was designed to do. Pokemon Go does not represent "planned obsolescence". It represents Niantic being too damn lazy to search an array result for "Xposed" and instead invoking something that will make it look like they expended some effort. It takes about five minutes to make a stock CyanogenMod device "compatible" with SafetyNet. All you have to do is rename two files, specifically /system/xbin/su and /system/bin/su. Boot into recovery (TWRP or whatever you have), and start a terminal from there (where you are as "root" as root gets, and this will always be so) and type `mount /system` to start. Next, rename those two files. Lastly unmount /system and boot normally. SafetyNet will be happy, which means Pokemon Go and Android Pay will also be happy. If you want "root access" back on your phone, all you have to do is go back into recovery and rename those two files back to what they were.
- nradov 10y agoI find it both hilarious and disappointing how much effort is going into an escalating arms race between video game cheaters and cheat detection. Considering that the players can't even win anything of real value. I think future archaeologists will see this whole thing as a bizarre ritual and struggle to understand what was really going on. "A strange game. The only winning move is not to play. How about a nice game of chess?"
- FilterSweep 10y agoIt is a relevant quote, but both the cheaters and the developers tasked to combating the cheaters both learn a great deal in the process. That, I feel is the true value-added. The real value is knowledge gained. And I've seen some pretty crafty solutions created.
- nradov 10y agoTo what end? This is ultimately nothing more than a bunch of little kids playing cops and robbers. There's nothing wrong with playing the game, but let's not pretend that it actually counts for anything.
- evilDagmar 10y agoThis is literally how the chaos of EFNet in the 90's gave rise to a whole slew of new security methods and techniques, not to mention bug fixes. Just be glad this fight isn't happening over human organs or oil rights or something.
- deleted 10y ago[deleted]
- nayuki 10y agoThis story hits close to home - I have the exact same problem as the blogger. I own a Nexus 4, run the latest CyanogenMod 13, played Pokémon GO for a while, and was blocked in the September update. I never used the root features of my phone, and tried some attempts to remove the root without success. Shame on Niantic for being so heavy-handed on its users.