7 ms·
Interesting, I am guessing there is some kind of learning net behind SafetyNet API - Harvesting all the device infos.
by crudbug 10y ago
Interesting, I am guessing there is some kind of learning net behind SafetyNet API - Harvesting all the device infos.
- evanreichard 10y agoSafetyNet is pretty flexible. It actually isn't implemented inside any APK - "The SafetyNet service reaches out to a Google server and downloads a binary package with the code. It goes to great lengths to validate the integrity of the package, for example using hardcoded certificates (pinning). This binary package is essentially a JAR file that contains a classes.dex file with java bytecode. Play Services caches it in dalvik-cache (snet.dex) and loads it dynamically using reflection." [1]. I think right now the only way "around" it has been Magisk [2]. [1] https://koz.io/inside-safetynet/ https://koz.io/inside-safetynet/ [2] https://forum.xda-developers.com/apps/magisk/official-magisk-v7-universal-systemless-t3473445 https://forum.xda-developers.com/apps/magisk/official-magisk...
- cprecioso 10y agoAnd suhide [1], but that one's a cat and mouse game, as acknowledged by the developer. [1]: https://forum.xda-developers.com/apps/supersu/suhide-t3450396 https://forum.xda-developers.com/apps/supersu/suhide-t345039...
- cprecioso 10y agoI don't think that'd be necessary. Google's stated that SafetyNet's purpose is not excluding power-users, but ensuring the security model of the OS has not been compromised, in order to activate certain sensitive functions (e.g. Android Pay). Given that developments in the root community are few but well-known, it'd only take a weekly visit to the XDA Developers forum by an intern to learn about any new rooting method, and not many resources to successfully block them. No need for a complicated (and expensive) information gathering and mining rig _for SafetyNet_. Could they be gathering that information with other purposes? Given that Play Services de-facto has root powers within Android, maybe.