3 ms·
> If you are using the phone for work, you shouldn't be opening up access to a local admin account. Rooting/jailbreaking is a double edged sword. You get more c
by problems 10y ago
> If you are using the phone for work, you shouldn't be opening up access to a local admin account. Rooting/jailbreaking is a double edged sword. You get more control over the device but you also open up access to malicious applications.
It only "opens up access" to applications I allow explicitly. And I run things like XPrivacy which allow me to hook privacy compromising applications.
In reality it's much better for security to be rooted if you know what you're doing.
It's only a problem if you're allowing root for say, random games you download... and I don't think many people are doing that. Generally if you're rooted or jailbroken, you know what you're doing.
- Bjartr 10y ago> if you know what you're doing And if you don't, it's potentially much worse security. If your device is rooted, that's an attack vector that didn't previously exist. Since this tool is about informing and not enforcing, then if you really do know what you're doing then you can choose to take no action. If, however, you're not aware of the risks rooting a device exposes you too, then the tool provides an opportunity to learn that. Further, this tool wasn't made with protecting an individual so much as protecting an organization. Yeah, you know what you're doing, but are you willing to bet your organization's security on that being true for everyone now and in the future? One compromised device can be all it takes for an attacker to get in. Not everyone who roots really knows what they're doing, it's very easy to root some phones, a quick download on a PC, run an app, click a button, and tada! Also, what about the non-techie person that asks their tech-savvy friend to root because they want to be able to <any single one of the things rooting allows>? Do you trust the judgement of every person tech-savvy enough to do this to never root another's phone without them really understanding the consequences? </rambling>
- problems 10y agoRooting a device doesn't immediately expose you to risk, you must manually allow that. There's very little malware around if you stick to the standard app stores like most users will too. Ads that push malware - a major problem on Windows - practically don't exist on mobile because the impact would be so small. Especially if they're trying to target only rooted users. Phones don't seem to be very popular attack vectors and many main attack methods could be performed without the need to root the device at all. All in all, I'd be very surprised if rooting a device ever resulted in a significant compromise which couldn't have been done without root. Exploitation excluded obviously.