4 ms·
You can try lots of things, detecting su binaries, UI applications, checksumming the entire filesystem, etc. But ultimately if the user doesn't want you to know
by problems 10y ago
You can try lots of things, detecting su binaries, UI applications, checksumming the entire filesystem, etc. But ultimately if the user doesn't want you to know, you won't know.
Rooting or jail breaking your device is taking control of your device into your own hands, if you use something like Magisk, you can fully bypass root detection, even via the nastiest methods on Android.
Detecting it as a security problem is moronic. In fact, I'd argue it's actually a security improvement due to things like XPrivacy.
- nissimk 10y agoI'm curious to hear other people's opinions about this. I feel like the smartphone security model provides security for the OS developers, the app developers and their advertising customers at the expense of usability for the users. But it also provides real security to the users. I generally choose usability over security, but maybe I should be more paranoid. I do not have android pay enabled on my phone but I'm not sure I'd be comfortable with it even if I wasn't rooted. I insist on root because I want to block ads and install themes. It's possible to do these things without root, but it's harder. Please comment people with deeper knowledge of security.
- problems 10y agoThe sandbox has been good in that it hasn't let the Windows model of apps running rampant with admin privileges do whatever they want with your data. It's mostly prevented cross-app data access. But that's not where it stops. You see, there's still plenty of great data they can grab when you blindly click accept on that permissions dialog. Contacts are grabbed by many applications, unique device identifiers, loading your app with ads, even grabbing GPS location are pretty much standard practice now. These practices which used to be labeled spyware or adware and hunted down and removed are now the norm. These apps grab this data and then throw it out onto the open internet, often over unencrypted connections to parties who you don't know or trust, who are often unrelated to the app developer almost entirely, most often just so some advertiser knows you play a certain game or live in a certain city. It depends on your definition of security - if it's strictly clicking on an ad and getting malware - it's great - but if it includes things like leaking contacts, locations and identifying information - it's terrible. XPrivacy is the only solution I've seen to really hit back at it. Rooting your device does NOT immediately lose all sandbox benefits. It only selectively bypasses it. If you don't approve EvilMalware to bypass the sandbox - it still can't break out. As for Android Pay? Go ahead and use it. Rooted or not, to my understanding, you're not liable for fraud on it, your credit card company will still reverse transactions no problem.
- deadcell 10y agoInterestingly, it's how Pokemon Go detects whether or not you're trying to 'cheat' the game, and flat-out refuses to run the game if you're in either a rooted OS or are running anything non-vanilla (I lost access to the game after they decided to block cyanogenmod in the same update).
- problems 10y agoYeah, so it depends on the way they detect it. You can bypass anything, even Google SafetyNet with stock ROM + magisk + systemless Xposed + phh su and using Magisk Hide if you're determined enough. CM ships pre-rooted - you just enable it in the settings, but the su binary is present and can be detected by any app looking for it. So that's a very common way to detect it on CM.
- twodayslate 10y ago> Detecting it as a security problem is moronic. In fact, I'd argue it's actually a security improvement By definition a jailbroken device is vulnerable to something as that is how it was jailbroken in the first place. Having the most up to date version is usually the safest thing for a user.
- problems 10y agoSure, so detect that as the problem. That's not true of rooted Android devices though, most Android devices allow you to enable a developer mode which will allow you to replace the ROM entirely if you like with no need to exploit anything.
- kodroid 10y agoI think your talking about bootloader unlocking rather than dev mode
- Godel_unicode 10y ago> Detecting it as a security problem is moronic That's an interesting stance, you don't care about rootkits? What about malware, which has been found in the wild, which abuses root privileges to steal account information? That malware is extremely difficult to detect directly.
- literallycancer 10y agoPresumably you use something to manage which apps get root access. Or is there actually malware that doesn't require any user screw ups?
- kodroid 10y agoDepends on the method of rooting
- Godel_unicode 10y agoFor instance, if you get a malicious application which roots your phone and doesn't bother to tell you (the nerve!). You might have a security problem with your phone whose most easily detectable sign is the presence of root.
- problems 10y agoOn Android, the standard root system most people apply to their device prompts you when you launch an application if you want to allow it root access. This makes it trivial to block malicious applications - that new game you downloaded probably doesn't need root for any good reason. Just hit deny. The sandbox is still fully in place, just now you can poke holes in it for certain applications of your choosing. What you're thinking of are things which use exploits to gain root - this may be done by some users, but most often Android devices are rooted via bootloader unlocking these days, which does _not_ use an exploit. Exploits however are used by malware - and not having your device rooted won't prevent them. They gain root via exploitation, whether you want them to or not. Not to mention that the kind of root detection done is by looking for things that only the legitimate sort of root leaves behind, like a su binary which prompts the user if they want to permit root or not. Often times, rooting your device legitimately may allow you to flash a custom ROM and get updates that your original vendor hasn't released for your device, allowing you to actually _prevent_ exploitation by malware, even after your vendor has long abandoned the device.
- kodroid 10y agoNot moronic. If your front door is open, how do I know who opened the door?